Employee Offboarding IT Checklist: Closing Access Without Losing the Work

Onboarding gets a checklist because a new starter is waiting. Offboarding gets forgotten, because the person has left and nothing visibly breaks.

Part of our guide to New Office IT Setup.

Laptop closed on a cleared office desk beside an empty chair
Quick answer

An employee offboarding IT checklist covers four things in order: revoke access on the last day, preserve the mailbox and files rather than deleting them, recover and wipe the equipment, and find the accounts that were never on the list. Done in that order, nothing is lost and nothing stays open.

Key takeaways

  • Disable, do not delete. A removed account takes its mailbox and files with it, often past the point of recovery.
  • Access should end on the last working day, not when someone remembers.
  • The dangerous accounts are the ones IT never knew about: shared logins, SaaS tools, WhatsApp groups.
  • The laptop is company data until it has been wiped, however it looks.
  • A leaver process is also a provisioning process: the returned device is the next starter's.

Why does employee offboarding go wrong more often than onboarding?

A new starter is standing at a desk with nothing to work on, so onboarding gets done. A leaver has gone. Their laptop is in a drawer, their account still signs in, and nothing looks broken, which is exactly why it stays that way for months.

The cost shows up later and in two directions. Access left open is the most common way a former employee, or someone who has obtained their password, gets back into company systems. And data deleted in a rush to free a licence is the most common way a firm loses the contract history it needs a year later. A written employee offboarding IT checklist prevents both, and it takes an hour to run.

What should happen before the last day?

The useful work starts when the leaving date is known, not when it arrives. Two things need to happen in that window: find out what the person actually has access to, and decide who inherits what.

The first is harder than it sounds. The Microsoft 365 account is obvious. The accounting system, the CRM, the design tool, the supplier portals, the company social media, the shared mailbox they monitored, and the WhatsApp groups with customers in them are not, and none of them are in the directory. Ask the person and their manager directly, and keep the list; it becomes the template for the next leaver in that role.

The second is a management decision that IT cannot make: who takes over the customers, the files, the mailbox, and the recurring tasks. Decide it before the last day so the handover happens with the person still available to explain things.

  • List every system, tool and group the person uses, including the ones outside IT's control.
  • Confirm who inherits the mailbox, files, customer relationships and recurring jobs.
  • Check whether they hold any administrator role, shared password or company phone number.
  • Arrange the return of the laptop, phone, access card and any keys.

Employee offboarding IT checklist: what happens on the last day?

The last day is about closing access cleanly and quickly, in an order that does not lose anything. The order matters, because some steps make others impossible.

Start by disabling sign-in on the Microsoft 365 account and revoking active sessions, so an open laptop or a phone with the mail app still signed in stops working immediately. Then reset the password, remove the multi-factor authentication method, and remove the account from groups and distribution lists so mail stops arriving in a mailbox nobody reads. Do not delete the account. Deletion is the step that destroys the mailbox and the OneDrive after a short grace period, and it can wait.

Then work through the list from the previous section. Every SaaS tool, every portal, every shared password the person knew. Shared passwords are changed, not just noted, because the person's memory does not expire with their access card.

Employee offboarding IT checklist: the last day, in order
StepWhat to doWhy this order
1Block sign-in and revoke sessionsStops every device at once, including the ones you cannot see
2Reset password and remove MFA methodPrevents re-entry if sign-in is re-enabled by mistake
3Remove from groups, lists and TeamsMail and messages stop landing in a dead mailbox
4Revoke SaaS, portal and shared accountsThese are outside the directory and will not be caught otherwise
5Change every shared password they knewKnowledge does not expire with access
6Collect laptop, phone, card and keysCompany data stays company property

What should you keep, and for how long?

The instinct after someone leaves is to tidy up, and tidying up is how firms lose things. The mailbox holds the negotiation with a supplier that is now in dispute. The OneDrive holds the only copy of a proposal. Neither should be deleted to save a licence fee.

In Microsoft 365, the clean approach is to convert the mailbox to a shared mailbox, which keeps the contents readable by the person who inherited the role without needing a licence, and to transfer OneDrive files to the manager or a shared library before the account is removed. Give the manager access for a defined period, then archive.

How long to keep it depends on what the person handled. Client correspondence and anything touching contracts or money generally needs to outlive the project. Confirm the retention your accountant or legal adviser expects, and make sure the copy exists outside the tenant too, which is where a separate Microsoft 365 backup earns its keep.

What happens to the laptop and phone?

A returned laptop is company data in a bag until it has been wiped, and it should be treated that way regardless of who returned it or how amicably. The same applies to a company phone with the mail app on it, and to a personal phone that had company mail configured, which is the case most firms forget.

The process is simple: confirm the device is enrolled and managed, preserve anything on it that the business needs, then wipe it fully and record the date. A managed device can be wiped remotely, which also covers the one that is never returned. A personal phone should have the company account removed, which a management policy can enforce without touching the person's own data.

Then the device is provisioned for the next person. A leaver process is also an IT equipment provisioning process, because the returned laptop is the next starter's laptop. Our guide to new employee laptop setup covers that side.

  • Confirm the device is managed and can be wiped remotely if needed.
  • Preserve business data from the device before wiping.
  • Wipe fully, record the date and serial number, and re-image to the standard build.
  • Remove the company account from any personal phone that had it.

Which accounts does IT never know about?

Every business has accounts outside the directory, and they are the ones that stay open. A marketing manager holds the Instagram login. A salesperson has customers in a WhatsApp group on a company number. An office manager set up the courier account, the stationery portal and the utilities login with their own email. An administrator created a Microsoft 365 global admin for a supplier three years ago.

None of these show up in a standard leaver process, and each one is a way back in or a way to lose something. The fix is the list from before the last day, kept per role and updated with every departure, so that the fifth person to leave a role gets a complete checklist rather than a fresh guess.

Employee access management, done properly, is just this: knowing what each role can reach, granting it deliberately, and removing it completely.

What is different about offboarding in the UAE?

The mechanics are the same as anywhere, with a few local details worth building in. Company mobile numbers are often registered in the business's name and used for customer WhatsApp; the number needs to be reassigned, not just the phone returned. Notice periods and final settlement sometimes mean a person is on garden leave with a laptop at home for weeks, which is a period to plan for rather than ignore.

Visa and labour processes run on their own timetable and are not IT's business, but the leaving date they produce is the date the checklist works from. Get it from HR the day it is known.

How Listonics handles leavers for Dubai businesses

For firms on managed IT support, offboarding is a standard request: tell us the name and the date, and the checklist runs on the day, with mailbox conversion, file transfer, device wipe and a written record of what was closed. The per-role access list is built up over time so it gets more complete with every departure.

If you have leavers whose access was never properly closed, an audit of active accounts, admin roles and unmanaged devices is a normal part of a free office IT assessment, and it is usually where the surprises are.

Frequently asked questions

Not immediately. Disable sign-in, revoke sessions and remove MFA on the last day, then convert the mailbox to a shared mailbox and move OneDrive files to the manager. Deleting the account starts a short grace period after which the mailbox and files are gone, so it should be the last step, taken deliberately.

On the last working day, ideally within the hour they finish. Blocking sign-in and revoking sessions takes minutes and stops every signed-in device at once. Leaving it until the next week is the most common gap we find, and it is the one that matters most.

A managed device can be wiped remotely, which protects the data whether or not the hardware comes back. That is the strongest argument for enrolling every device in management from day one. Recovering the hardware itself is an HR and legal matter; protecting what is on it is not.

Remove the company account from the device rather than wiping the phone. A mobile device management policy can do this without touching personal data, which is why it should be set up before the account is added, not after the person has left.

Both, with HR triggering it and IT running the technical steps. HR knows the leaving date and the notice arrangements; IT knows the systems. The list of accounts outside IT's view, such as social media and supplier portals, needs the manager's input, which is why it is built per role.

Keep the mailbox and files, converted to shared or transferred to the manager, for as long as the work they cover might be needed. Contract and client correspondence generally outlives the project. Confirm the retention your accountant or legal adviser expects, and keep a copy outside the tenant as well.

Published Sep 20, 2026 · Last reviewed September 13, 2026 · 1,700 words

Talk to an engineer about managed it services & amc for your office.

contact us
Chat on WhatsApp