Skip to content
Hernandez Solutions, home
Operations

The Employee Offboarding Checklist for Microsoft 365

A practical, step-by-step IT offboarding checklist for companies on Microsoft 365, Entra ID and Intune, covering what to do on the last day and in the weeks after.

By Benicio Hernandez · September 27, 2026 · 6 min read

Offboarding is one of the most overlooked security processes in growing companies. Onboarding gets attention because a new hire is waiting. Offboarding often gets done halfway, and a former employee keeps access to email, files or SaaS tools for weeks or months.

This checklist assumes you use Microsoft 365, Microsoft Entra ID and ideally Microsoft Intune. Adapt it to your environment, and write your version down so it happens the same way every time.

Before the last day

  • Confirm the exact date and time access should end with HR or the employee's manager.
  • Decide who takes ownership of the employee's mailbox, OneDrive files and shared resources.
  • List the SaaS applications the employee uses, especially any not connected through single sign-on.
  • Identify company devices to be returned, and any personal devices with company data on them.
  • Check whether the employee holds any administrative roles, shared credentials or API keys.

At the moment access should end

  • Block sign-in for the user in Entra ID.
  • Revoke active sessions so existing sign-ins on phones and browsers stop working.
  • Reset the password (it prevents reuse if sign-in is re-enabled by mistake).
  • Remove or disable MFA methods registered to the account.
  • Remove the user from administrative roles and privileged groups.
  • Disable or remove access in any applications not covered by single sign-on.
  • Rotate any shared passwords, API keys or credentials the employee knew.

Mailbox and data

  • Convert the mailbox to a shared mailbox, or delegate access to the manager, based on your policy.
  • Set an automatic reply or mail forwarding if customers may still email the address.
  • Transfer OneDrive files the business needs to keep to their new owner.
  • Reassign ownership of Teams, SharePoint sites and Microsoft 365 groups the user owned.
  • Apply your retention approach before deleting anything.

Devices

  • Collect company-owned laptops, phones and accessories.
  • Wipe or reset company devices through Intune before reassigning them.
  • For personal devices, remove company data with a selective (app-level) wipe.
  • Update your device inventory.

Licenses and cleanup

  • Remove Microsoft 365 and other licenses once data has been handled, so you stop paying for them.
  • Remove the user from distribution lists and security groups.
  • Record what was done and when.
  • Delete the account after your defined retention period.

Make it repeatable

The goal isn't a perfect checklist. It's a process that runs the same way every time, whoever performs it. Group-based access in Entra ID makes removal predictable, single sign-on means one account controls access to many apps, and much of the checklist above can be automated with PowerShell and Microsoft Graph.

Next step

Let's talk about your IT.

Tell us how your company works today. We'll tell you honestly what we'd change, what we'd leave alone, and whether we're the right fit.