An employee is leaving:
what should IT do on the same day?

The user account has been disabled and the laptop returned. It looks finished — until you remember VPN access, shared passwords, private devices, cloud applications and data still tied to the former employee.

Published Reading time 5 min All guides

The biggest mistake is disabling only email

An employee has left, their user account is blocked and the job appears to be done.

But the same user may still have access to:

  • VPN
  • CRM
  • accounting software
  • web hosting
  • social media
  • cloud services
  • shared passwords
  • a company phone
  • files synchronised to a private device

Offboarding is not the deletion of one account.

It is the process of closing the user's identity everywhere that identity existed.

Block sign-in first. Do not immediately delete the account.

Deleting an account on the first day can create more problems than it solves.

It is generally safer to block sign-in and terminate active sessions first.

The user can no longer access the system, while the administrator still has time to:

  • review data ownership
  • transfer documents
  • deal with the mailbox
  • review licences
  • retain required business data

Once everything has been transferred, the account can be archived or removed according to company policy.

Email needs a new owner

An automatic reply alone is often not enough.

Decide:

  • who should receive future messages
  • who may access existing mail
  • whether the address should remain active
  • for how long
  • who takes ownership of contacts and calendars

Be careful not to leave a former employee's mailbox forwarding to one person for years simply because they happened to be the first replacement.

That quickly becomes an invisible rule nobody fully understands.

Documents have ownership too

In Microsoft 365, Google Workspace and other cloud environments, documents are often associated with a specific user account.

Deleting that account without preparation can lead to lost data or complicated permissions.

Before doing so, check:

  • OneDrive or personal cloud storage
  • shared folders
  • SharePoint or Shared Drives
  • documents the user shared with others
  • automations running under that user's identity

The last case is particularly easy to miss.

A process may continue to run for weeks and then suddenly fail when the account is removed or its token expires.

Terminate active sessions

Changing a password is not always enough.

Modern cloud services use tokens and already authenticated sessions that may remain valid for some time.

When a user leaves, active sessions should be revoked where the platform allows it.

The same applies to:

  • VPN
  • administration portals
  • remote access tools
  • business applications

Do not forget shared passwords

If the employee knew a password used by several people, disabling their personal account does nothing to remove that access.

Examples include:

  • Wi-Fi administration
  • hosting
  • domain registrar accounts
  • social media
  • shared administrator accounts
  • local network equipment

Those passwords should be changed.

Even better, systems should use individual user accounts wherever possible — and you should be able to say who still knows your company password.

Company equipment is more than a laptop

An equipment return checklist often contains only a laptop and charger.

It is also worth checking:

  • company phone
  • SIM card
  • monitor
  • docking station
  • security token
  • access card
  • keys
  • external drives
  • special adapters or peripherals

If asset assignments are documented only when somebody leaves, it is already too late.

The record should exist from the day the device is issued.

A checklist is better than good memory

Good offboarding does not need to be complicated.

A simple checklist with ten items is better than a process that has to be reconstructed from memory every time.

A minimum checklist:

  1. Block the user account.
  2. Terminate active cloud sessions.
  3. Revoke VPN and remote access.
  4. Transfer email and documents.
  5. Review external SaaS applications.
  6. Change shared passwords the user knew.
  7. Collect company equipment.
  8. Check automations and services tied to the account.
  9. Record what was done.
  10. Only then archive or remove the account.

Ideally, the process starts before the employee's final day

The best version of offboarding starts when IT receives the employee's leaving date.

Then it is known in advance:

  • when access will be disabled
  • who takes ownership of data
  • what equipment must be returned
  • what must remain available

Offboarding then becomes a routine process rather than an incident.

What you can check today

Choose one employee who left the company during the last year.

Try to answer:

  • is their account still active anywhere
  • did they use any services with shared passwords
  • who took ownership of their business data
  • is any device still assigned to them
  • is an automation still running under their account

If you cannot answer at least one of these quickly, you have already found something worth documenting.

Sources and further reading

Related service

IT support and systems maintenance

Management of users, access, devices and day-to-day IT environments, including documented processes for employees joining and leaving.

IT support and system maintenance

Dealing with a problem like this?

Describe the situation and we will suggest the first sensible step. If it can be solved without us, we will tell you that too.

Book a conversation