Employee Offboarding Checklist for Small Business IT
The day someone leaves, the account they used is the most dangerous thing in the building, and deleting it is the wrong first move. Here's the list we run, in the order that keeps the data, closes the doors and doesn't strand anyone.
Offboarding is where small businesses lose data and keep risk, usually at the same time. The mailbox gets deleted before anyone saved the client threads in it, while the former employee's phone keeps syncing the calendar for another week. Both come from the same instinct: clean it all up fast. The right order is slower for about an hour and safer for years.
The Short Version
Disable, don't delete. Revoke every open session. Capture the mailbox and the files. Wipe the devices. Rotate the shared passwords. Then, after the retention window, decide what to delete. Most of the mess we see comes from running that list backwards.
Why “Just Delete the Account” Backfires
Deleting drops the mailbox, the files and the calendar, sometimes past the point of getting them back. It also doesn't reliably end a session that's already signed in on a personal phone; the phone keeps syncing until its token expires, which can take days. Disabling and revoking does both jobs and keeps the data.
The Same-Day List
Block sign-in and reset the password
Microsoft 365: block sign-in. Google Workspace: suspend the user. Reset the password as well, so nothing cached anywhere still works.
Revoke sessions and MFA
Microsoft: revoke sessions and reset the MFA methods. Google: sign the user out of all sessions and reset sign-in cookies. This is what actually ends the access on a personal phone.
Capture the mailbox
Microsoft 365: convert it to a shared mailbox, which keeps every message without a license, then set an auto-reply or forward to the manager. Google: export or transfer the mail, then downgrade the account. Decide the retention window now; 30 to 90 days is typical, longer if a dispute is possible.
Transfer the files
OneDrive: give the manager access before anything is deleted. Google Drive: transfer ownership. Check SharePoint, Teams and shared drives for documents they owned, and any client folders on their laptop that never synced.
Remove from groups and channels
Distribution lists, Teams and Slack, shared calendars, security groups, and the customer-facing aliases like info@ and support@.
Revoke app access and tokens
Third-party apps the account authorized, app passwords, API keys, automation tools, the CRM, Dropbox, the company social media pages, Canva, Adobe, and their QuickBooks user.
Collect and wipe devices
The laptop, with its BitLocker key already on file. The phone, through Mobile Device Management: wipe the work data on a personal phone, the whole device if company-owned. Keys, badges, hardware tokens. Then remove the devices from MDM.
Rotate what they knew
The Wi-Fi passphrase, alarm and door codes, shared logins for vendor portals and social accounts, the office Amazon account, the shared vaults in the password manager, voicemail PINs.
Remove from money and admin
Bank and merchant portals, payroll, company cards, the domain registrar and DNS (see who owns your domain), hosting, Microsoft or Google admin roles, the backup console, and the phone system.
Look for forwarding rules and exports
Before locking the mailbox down further, check its rules and recent activity: forwarding to a personal address, or a large download from OneDrive in the last week. If you find either, that's a conversation with counsel, not a shrug.
Week One and After
- Reclaim the license once the mailbox is shared or exported.
- Update the website, org chart and email signature templates; reassign the phone number or extension.
- Tell key vendors and clients who their contact is now, before the auto-reply does it for you.
- Take them off the incident-response contact list and the after-hours call tree.
- Delete the account only after the retention window, and only if there's no litigation hold.
- Review who else holds admin rights while you're in there.
| Where they had access | Same day | Later |
|---|---|---|
| Email and files | Block, revoke, convert to shared | Delete after the retention window |
| Personal phone with work email | Revoke sessions; MDM work-profile wipe | Remove from MDM |
| Company laptop | Collect; keep it encrypted; reimage | Reassign |
| Shared passwords | Rotate | Audit the shared vault |
| Admin roles | Reassign, then remove | Review quarterly |
| Banking, payroll, registrar | Remove today | Confirm in writing |
The Bad-Exit Version
For an involuntary termination, run steps one and two while the conversation is happening, not after it. For the weeks that follow, identity threat detection on our Advanced plan flags any sign-in attempt against a disabled account, or an old session waking up, so a former employee's access is a logged event rather than a surprise. Our wire fraud guide covers the other reason to care: a still-open mailbox is the starting point for most invoice fraud.
Quick Self-Check
| Question | If “no” or “not sure”... |
|---|---|
| Is there a written offboarding list, or does it live in someone's head? | Copy this one |
| Could you cut off a former employee's phone access in five minutes, without their phone? | Worth a call |
| Does anyone still know the Wi-Fi password from three hires ago? | Rotate it |
| Who else holds admin, registrar and bank access if the owner is out? | Write it down |
Have Us Run the List
Offboarding is a help-desk ticket on our Premium and Advanced business plans: we block, revoke, capture and wipe the same day, and keep the record for your files.
Frequently Asked Questions
Can I read a former employee's mailbox?
It's the company's account, and for business purposes the answer is usually yes; converting it to a shared mailbox is the clean way to do it. If there's a dispute or the person handled anything sensitive, ask your attorney first.
How long should I keep the mailbox?
Thirty to ninety days covers most handoffs. Regulated industries and anything that might end up in litigation call for longer, and a shared mailbox in Microsoft 365 costs nothing to keep.
They used a personal phone for work email. How do I get it off?
Revoking sessions and resetting the password (steps one and two) ends the access. With Mobile Device Management in place, IT can also wipe the work profile remotely, which is the reason MDM is included on our Premium plans.
What if the person leaving was the administrator?
Move the global admin role, the registrar and DNS logins, hosting, the bank tokens and the backup console first, then run the list. Every business should also keep a break-glass admin account that isn't tied to any one employee.
Do contractors need this too?
Yes. Same list, usually shorter. Contractors are the accounts most often forgotten, because nobody thinks of a project ending as a departure.
More Guides
How business email compromise moves real money, and the callback rule that stops it.
The registrant on record owns it, not the person who pays the invoice. How to check.
The sign-in method a fake login page can't steal, and how to set one up.
Why a stolen password is now the most common way in, and how it's stopped.
What carriers ask about MFA, backups and EDR, and how to get to an honest yes.
Lock it, protect the accounts on it, and suspend the line, in the right order.
📞 727-579-4335 · ✉️ support@baygeeks.com · Privacy Policy · Terms of Service
