
A colleague leaving creates two separate jobs: end their access at the agreed time, and keep necessary business information available to the right people. This Microsoft 365 employee offboarding checklist is a planning aid for the person coordinating that handover. It does not replace your organisation’s retention decisions or the administrator’s current runbook.
Before the leaving date: assign owners
Start with a named manager, an authorised administrator and a person responsible for checking completion. Agree the effective leaving time, including the time zone. Write down which work needs handing over and who should receive it. Do not let a vague request to “delete the account” stand in for those decisions.
Build a leaver access checklist from actual records: the work account, devices, business applications, shared resources and supplier portals. Include privileged accounts and accounts outside Microsoft 365. Ask the manager to identify ongoing customer conversations, recurring tasks and files that only this person knows about.
At the agreed time: remove access deliberately
Microsoft’s current guidance covers resetting the password, signing out sessions and blocking sign-in. These actions do not necessarily terminate every existing session instantly; follow the documented behaviour and verify the result. An authorised administrator should use the appropriate role rather than sharing a highly privileged login. See Microsoft’s access-removal instructions.
Record who performed each action and when. Keep passwords, tokens and recovery codes out of the handover document. Where another application has its own login, give its owner a separate task; completing the Microsoft 365 work is not evidence that every other account has been closed.
Arrange an employee mailbox handover
Agree what the successor needs before changing or removing licences. Microsoft describes options for preserving mailbox contents, forwarding email, converting a mailbox and handing over OneDrive information. The suitable route depends on the organisation’s needs and configuration. Follow the official offboarding sequence, including relevant retention requirements, before deleting the account.
Give handover access only to the approved recipient. Ask that recipient to check representative work: a customer thread, a shared document and the location of an active project. Knowing that permission was granted is less useful than knowing the person can actually continue the work.
Close the operational loose ends
- Record returned equipment, chargers and security keys against the asset list.
- Confirm who now owns shared calendars, recurring reports and supplier relationships.
- Check that any agreed customer contact message names the correct replacement.
- List outstanding tasks with an owner and deadline.
- Ask the responsible manager to approve the completed record and its storage location.
A useful completion record has five columns: system, required action, owner, completion time and evidence. Evidence can be a ticket reference or confirmation from the new owner; it should not be a copy of sensitive mailbox contents.
Make the next handover easier
Note which missing records caused delays. Update your joiner and role-change processes so future departures are easier to coordinate. Secure business account offboarding works best as a repeatable responsibility, not an improvised task for whoever is available.
For ongoing account administration, explore our managed IT services. For a specific access problem, see helpdesk support. Please do not send passwords in an enquiry.
