When a member of staff leaves a business, their IT access should be disabled on or before their last day. This includes their email account, Microsoft 365 or Google Workspace login, There’s any shared passwords they knew, their access to cloud services and software subscriptions. Leaving accounts active after someone has left creates a security risk that is voidable, and in some cases has led to former employees accessing business systems, reading emails, and causing significant damage long after their departure. A clear IT offboarding process removes that risk and takes far less time to put in place than most small business owners assume.
The Truth Of The Matter
Staff leave. It’s one of those facts of business life that nobody particularly enjoys dealing with, whether the departure is amicable, mutual, or the kind that involves a strongly worded conversation on a Tuesday afternoon. There’s the handover to think about, the farewell card to organise, and approximately fourteen administrative tasks that seem to land on someone’s desk all at once.
What often gets lost in that process, or pushed to “we’ll sort it later,” is the IT side of things. And “we’ll sort it later” has a habit of quietly becoming “we never sorted it,” which is when it starts to become a problem.
A former employee with active accounts and valid credentials is not just a loose end. It’s an open door.
Why This Matters…
It’s easy to assume that most departing employees have no interest in causing harm to a former employer, and for the most part that’s probably true. But good IT security isn’t built on assumptions about people’s intentions. It’s built on removing the opportunity regardless, because intentions can change, circumstances can change, and an account that nobody is monitoring is also an account that someone else entirely could get into if those credentials ever ended up in the wrong place.
There’s also the more mundane reality that active email accounts continue to receive messages. If a former sales person’s inbox is still open six months after they left, every customer email that arrives there is effectively disappearing into a void that nobody is checking.
What Good Offboarding Looks Like
The core principle is simple: on the day someone leaves, their individual access to business systems should end. Not the following week, not whenever someone gets round to it, on the day.
In Microsoft 365, this means blocking the sign-in on their account immediately, which prevents them from accessing email, Teams, SharePoint, OneDrive, and any other Microsoft services. This is different from deleting the account, which is an important distinction. Blocking sign-in preserves all of their emails, files, and data so you can access it, redirect it, or hand it to whoever is picking up their work. Deletion removes it, which is rarely what you want to do straight away, if ever.
Email redirection should follow quickly. In Microsoft 365 you can set up a redirect so that any emails arriving to the former employee’s address are automatically forwarded to someone still in the business. You can also set up an out-of-office message that lets senders know the person is no longer with the company and gives them an alternative contact. This keeps communication flowing, protects customer relationships, and stops anything important disappearing into an inbox nobody is watching.
Beyond Microsoft 365, think about everything else that person had access to. Were they an admin on your social media accounts? Did they have the password to the company Wi-Fi, and was that password shared verbally rather than managed through a system? Were they named on any software licences or subscriptions that are billed to a personal email address? These are the things that sit just outside the obvious checklist and have a habit of causing problems later.
If the person used a company-owned device, getting that back on the day they leave is important, both to recover the hardware and to ensure that any business data on it is under your control again. If Microsoft 365 Business Premium is in place, Intune gives you the ability to remotely wipe a device if it isn’t returned or if the situation is less than straightforward.
Shared Passwords Are a Problem
If your business has any accounts where the login is shared across the team, a departure is a useful prompt to change those passwords straight away. Shared credentials are already not ideal from a security perspective, and a former employee knowing a password that multiple people use is the kind of thing that tends not to cause a problem right up until it does.
The longer-term answer is to move away from shared credentials entirely, using a password manager that allows individual logins or a proper access management system, but in the short term, changing the shared password when someone leaves is a straightforward and sensible step.
Build the Process Before You Need It
The businesses that handle this well are the ones that have a short, clear checklist of IT tasks to run through every time someone leaves, regardless of the circumstances. It doesn’t need to be complicated. It just needs to exist, be written down somewhere accessible, and be the responsibility of a specific person to action on the leaving date.
Having that process in place means it gets done consistently, quickly, and without anyone having to figure it out from scratch while also dealing with everything else that comes with a staff departure.
If you’d like help putting an IT offboarding process together for your business, or you’re not sure how your current setup handles leaver access, get in touch with the team at Lucid Computer Solutions and we’ll help you get it right.
FREQUENTLY ASKED QUESTIONS
Should I delete a former employee’s Microsoft 365 account immediately when they leave?
Generally no, at least not straight away. Blocking their sign-in on the day they leave stops them from accessing anything, but preserves all of their emails, files, and OneDrive data so you can access it and hand over anything important. Microsoft 365 lets you keep a blocked account active for as long as you need to, or convert it to a shared mailbox (which doesn’t require a paid licence) so the email address remains accessible without the account taking up a user subscription. Deletion should usually wait until you’re confident nothing important needs to be retrieved.
What is email redirection and how does it work in Microsoft 365?
Email redirection, or email forwarding, automatically routes any incoming messages addressed to a former employee’s email account to another person in the business. In Microsoft 365, this is set up through the admin centre once the account has been blocked. You can also set an out-of-office reply that tells senders the person has left and provides an alternative contact. This keeps communication flowing, prevents important emails from going unread, and protects relationships with customers and suppliers.
What if a former employee refuses to return a company laptop or phone?
If the device is enrolled in Microsoft Intune, which is included in Microsoft 365 Business Premium, you can remotely wipe the device to remove all business data from it. This doesn’t resolve the question of getting the hardware back, which may involve a conversation with a solicitor depending on the circumstances, but it does ensure that business data on the device is no longer accessible. Having devices enrolled in a device management system before this kind of situation arises is exactly why IT professionals recommend it.
How do we handle accounts that were set up in the employee’s personal name or email address?
This is a common problem, particularly in smaller businesses where things were set up quickly and practically rather than formally. If a business account, a software subscription, a social media profile, or any other service is registered to a personal email address belonging to someone who has left, access to that account may be lost entirely when the relationship ends. The best prevention is making sure all business accounts are registered to a business email address from the start. If you’re in this situation already, it’s worth auditing which accounts this applies to and working to transfer them to business-owned credentials before a departure makes it an emergency.
Should we change the office Wi-Fi password when someone leaves?
If the Wi-Fi password was shared with the employee in a way they could have noted down, changing it when they leave is sensible, particularly if you don’t have a guest network set up separately from the main business network. It’s a small step and a minor inconvenience for the team to update their devices, but it removes a potential access route that there’s no reason to leave open.
Gavin Moorhouse is the CEO of Lucid Computer Solutions, a leading Worcestershire-based IT Services business. Give them a call on 01527 908646.