When someone leaves a small business, the farewell card gets organized faster than the accounts get closed. Weeks later the ex-employee can still read email on their phone, the shared passwords they knew are still in use, and a mailbox nobody watches is still accepting password reset links.
None of that requires bad intentions to become a problem. Old accounts show up in breach dumps (run the domain breach check and you will likely find some of yours), stay signed in on personal devices, and give an attacker a quiet door nobody is watching. And when a departure is not friendly, the gap between walking out and locking out is exactly when bad things happen.
Here is the checklist, in order. The first section happens the same day, ideally within the hour for an involuntary exit.
Same day: cut the access
- Disable sign-in, do not delete the account. In Microsoft 365 or Google Workspace, block sign-in and revoke all active sessions, which kicks the account off every logged-in phone and browser immediately. Deleting comes later, after data is preserved.
- Revoke app passwords and OAuth grants. Session revocation misses some older connections. Check the account for app passwords and third-party app access and remove them.
- Collect or wipe devices. Company laptop and phone come back same day. If a personal phone had company email on it, use your mobile management tools to remove the work profile. If you have no such tooling, that is a gap worth fixing before you need it.
- Remove remote access. VPN accounts, remote desktop users, and any remote-support tools they used. These are exactly the doors that show up in our exposure check guide.
- Change the shared passwords they knew. Wi-Fi, alarm codes, the social media accounts, the bank portal if they had a login, the software licenses that live under one shared account. If the team uses a password manager, this is one report: everything shared with them, rotated in an afternoon.
Same week: preserve the data and reroute the traffic
- Convert the mailbox to a shared mailbox with sign-in blocked. Their history stays searchable, incoming mail goes to whoever takes over, and you stop paying for the license. Set a professional auto-reply with the new contact.
- Transfer file ownership. Move their OneDrive or Drive contents to their manager before any deletion timer starts counting.
- Reassign what they owned. Recurring meetings, scheduled reports, automations that ran under their account, and any vendor relationships where they were the named contact.
The ones everyone forgets
- Third-party SaaS. Canva, Mailchimp, the shipping portal, the CRM, the booking system. These do not live in your Microsoft admin panel, so they get missed. Keep a running list of every service the business uses and who has seats; the password manager’s audit view often is that list.
- Accounts registered to a personal email. The classic disaster: the domain name, the Google Business Profile, or the company Facebook page was set up years ago under someone’s personal address. Audit these now, while everyone is friendly, and move them to a company-owned address.
- MFA methods on their phone. If any shared or service account sends its codes to the departing person’s phone, move those methods the same day, or the next person to need that login is calling someone who no longer works for you.
- Bank and payroll access. Remove their user from the bank portal and notify payroll. Pair this with the verification rules in our invoice fraud guide, because payroll diversion scams love stale access lists.
Make it a checklist, not a memory
The difference between businesses that offboard cleanly and businesses that find surprises a year later is not skill, it is a written checklist with an owner. Copy this post into a document, adapt it to your stack, and assign every line to a name with a deadline. For involuntary exits, the access section runs while the exit conversation is still happening, not after.
Then close the loop: once a quarter, list every active account in Microsoft 365, the password manager, and your SaaS list, and ask one question about each: does this person still work here? That ten-minute review catches everything the busy weeks missed.
Key Takeaways
- Offboarding is a security event. Same-day, block sign-in, revoke sessions, collect devices, and rotate every shared password they knew.
- Disable first, preserve data second, delete last. Shared mailboxes keep history without keeping risk.
- The dangerous leftovers live outside your admin panel: third-party SaaS seats, accounts under personal emails, and MFA codes going to a departed phone.
- A written checklist with named owners beats memory, and a quarterly does-this-person-still-work-here review catches the rest.
Want a second set of eyes on your account hygiene? Take the free cyber-risk self assessment, or book the free 30-minute team security session at /free-training/, in English, Spanish, or Portuguese.
LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.