An IT Offboarding Checklist for Small and Midsize Businesses

When an employee leaves, disabling one email account is not enough. That person may also have active sessions, company devices, shared passwords, cloud applications, vendor portals, building credentials, and ownership of files or workflows that the business still needs.

A good IT offboarding checklist does three things in the right order: it removes access, preserves business information, and transfers operational ownership. The process should be coordinated by HR, the employee’s manager, and whoever manages IT. For higher-risk or involuntary departures, the timing of those steps matters as much as the checklist itself.

Before the employee’s departure

Start with a complete view of the person’s access. A directory account is usually only the beginning.

Create or confirm an inventory that includes:

  • Microsoft 365 or Google Workspace
  • line-of-business applications
  • accounting, payroll, banking, and expense platforms
  • CRM and project-management systems
  • password managers and shared vaults
  • remote-access and VPN tools
  • vendor, domain, hosting, and social media accounts
  • physical keys, badges, alarm codes, and company devices
  • administrator roles and service accounts

The employee’s manager should also identify the information and work that must remain available after departure. That may include a mailbox, OneDrive files, customer records, shared documents, recurring reports, automations, calendars, and vendor relationships.

Do not delete the user simply because deletion feels final. First, decide what must be retained, who should receive access, and whether legal, contractual, or regulatory requirements apply. Retention is a business decision with technical consequences.

Decide the timing and owners

HR should confirm the effective departure time. IT should know which actions must happen immediately and which can wait until data and ownership are transferred. The manager should name the person taking over the active work.

For a planned, low-risk departure, some transfer work can happen before the final day. For an involuntary departure or a situation involving sensitive access, the business may need to revoke access at the same time it notifies the employee. The exact sequence should be agreed in advance rather than improvised during the meeting.

At the point of departure

Block sign-in and invalidate active sessions

Disable the primary identity account, block sign-in, and revoke active sessions. Changing a password alone may not immediately end every authenticated session. Microsoft documents separate steps for resetting a password, signing a user out of sessions, and blocking access to Microsoft 365. Ensuring this is done properly maintains account security and overall cybersecurity best practices.

If the departing employee has an administrator account, elevated permissions, or access to financial systems, treat those access paths as a priority. Remove delegated access, app passwords, authentication methods, API tokens, and privileged roles that could provide another way back in.

Disable access beyond the main directory

Not every business application is connected to Microsoft Entra ID or another central identity provider. Review the access inventory and disable accounts in systems that require their own login.

Pay special attention to tools purchased directly by a department or employee. A corporate card charge or browser bookmark may reveal a business-critical application that never made it into the official software list.

Secure devices and remote access

Collect company laptops, phones, tablets, security keys, storage devices, and network equipment. If a device cannot be returned immediately, use the available management controls to block or retire it and protect company data.

Remove the user from VPN, remote desktop, mobile device management, and any remote-support tools. Changing the user’s primary password does not automatically remove all certificates, local accounts, or device credentials.

Preserve the information the business needs

Offboarding should protect company information without turning a former employee’s account into a permanent storage strategy.

Assign an owner for the person’s mailbox and files. Decide whether email should be forwarded, whether the mailbox should become shared, and how long any automatic reply should remain active. Transfer ownership of OneDrive files, shared folders, forms, dashboards, automations, and recurring meetings.

Check for work that is technically owned by the departing account but operationally belongs to the business. Common examples include:

  • a Power Automate flow that sends customer notifications
  • a calendar used to book a shared resource
  • a spreadsheet connected to a recurring report
  • a domain or software subscription registered to the employee’s email
  • a shared mailbox or Teams channel with the employee as the only owner
  • encryption keys, certificates, or recovery codes held by one person

Document the transfer. The goal is not merely to keep the data; it is to make sure the next owner can find, understand, and use it.

Rotate shared credentials and verify ownership

If the employee knew a shared password, rotate it. This applies even when there is no concern about the person’s intentions. Offboarding is the point at which the business can no longer know where a shared credential may have been saved.

Review password vault membership, shared administrator credentials, Wi-Fi credentials, alarm codes, door codes, and vendor support PINs. Whenever possible, replace shared logins with named user accounts and role-based access. Named access makes future offboarding faster and leaves a clearer audit trail.

Also, confirm that at least two appropriate people control critical business assets such as domain registration, DNS, website hosting, cloud subscriptions, password vaults, and financial platforms. A departure should not expose a single-owner dependency.

Finish the process after access is removed

An offboarding ticket should not close the moment sign-in is blocked. Complete a short verification pass:

  1. Confirm that the account is disabled and that active sessions have been addressed.
  2. Confirm that company devices and physical credentials were returned or remotely secured.
  3. Confirm that business data and recurring workflows have a new owner.
  4. Confirm that licenses can be reclaimed without deleting information the company still needs.
  5. Confirm that shared credentials and privileged access were changed where necessary.
  6. Record who performed each action and when.

The manager should verify that customers, vendors, and internal teams are aware of the new point of contact. IT should retain the offboarding record in accordance with the company’s documentation and compliance requirements.

Build a repeatable offboarding process

The best time to design offboarding is before someone leaves. Use a standard request form, access inventory, a role-based checklist, and a clear division of responsibility among HR, management, and IT.

Review the process after a complicated departure. If an unknown application, an unreturned device, an orphaned workflow, or a shared password caused a delay, add that item to the standard process. Over time, offboarding becomes faster because the business has better documentation and fewer accounts that depend on memory.

For many SMBs, the largest improvement is simple: HR notifies IT through a defined process, includes an exact departure time, and names the manager responsible for data transfer. That gives the technical team enough information to protect access without interrupting legitimate business work.

Need help standardizing user access?

Parried helps growing businesses manage users, devices, Microsoft 365, security controls, and the documentation behind reliable onboarding and offboarding. If your current process relies on a last-minute email or on one person’s memory, a technology strategy session can help you identify gaps and build a workable process.

Get expert advice for your business

Book a free strategy call to improve IT, boost security, and make smarter tech decisions with confidence.

A clear next step for your technology

Let’s solve what’s getting in the way

Tell us what you’re dealing with, where your business is headed, and what you need from your technology. We’ll help you identify the right next step — whether that means ongoing IT support, stronger cybersecurity, a specific project, or strategic guidance.

Get expert advice for your business

Book a free strategy call to improve IT, boost security, and make smarter tech decisions with confidence.

Trusted IT resources

Looking to sharpen your IT strategy? Here are some trusted sources our team follows for both managed IT services and cybersecurity insights:

Microsoft Learn
Practical guides on Microsoft 365

TechRepublic
IT news, strategy tips, and tech insights

CISA
U.S. cybersecurity and infrastructure

NIST
National standards for IT management

CompTIA
Trusted IT education and business tech