Someone leaves the business, you do the obvious bits, collect the laptop, change a few passwords, and move on.
Then, two weeks later, you find out their phone is still signed into Outlook. Or a shared mailbox password is still saved in their browser. Or they can still open a folder in OneDrive because it was shared directly.
Offboarding is one of those processes that looks simple until you do it under time pressure. The fix is not “try harder”. It is a runbook you can follow, and where possible, automation.
What you’re really trying to prevent
You are not just closing an account. You are cutting off every practical way a former employee could still touch company data.
That usually means dealing with four different kinds of access:
- Interactive sign-in. Can they log in again with their username and password?
- Existing sessions. Are they already logged in on a phone, a browser, or a desktop app?
- Data ownership. Where do their files and email live now, and who can access them?
- Shared secrets. Shared mailbox passwords, vendor portals, Wi-Fi passwords, any “everyone knows it” credential.
If your offboarding only covers the first one, you are leaving the most common “ghost access” behind.
The 15-minute “stop the bleeding” sequence
When someone’s last day is today, or you are doing an urgent termination, speed matters. Your goal is to block new sign-ins and reduce the value of any existing sessions.
Use this order.
- Block sign-in first. In the Microsoft 365 admin centre, block the user from signing in so they cannot authenticate again, even if they know the password.
- Revoke sessions. In Microsoft Entra, revoke the user’s refresh tokens (often described as revoking sessions). This forces reauthentication in many places and helps knock out “still logged in” access.
- Reset the password (even if you blocked sign-in). Blocking sign-in stops new logins to Microsoft 365, but a password reset is still a sensible belt-and-braces step, especially if you suspect the password was reused elsewhere.
If you do just those three things quickly, you have usually bought yourself time to do the careful handover work without guessing who is still signed in where.
Handover runbook: email and OneDrive, without breaking work
Most growing businesses have the same requirement: keep work moving, keep the history, and don’t pay for an unused licence forever.
Here is a practical path that works well for many Microsoft 365 tenants.
Email: keep the mailbox, forward what you need
Decide what “done” looks like for email. Typically it is one of these:
- Manager needs access for a while. Give the manager access to the mailbox contents and calendar so they can pick up threads.
- New emails need to go somewhere. Set forwarding and an automatic reply so customers are not emailing a dead end.
- You want to free the licence. Convert the mailbox to a shared mailbox, then remove the licence from the user.
A few practical notes that save pain:
- Convert before you remove the licence. Microsoft’s guidance is clear that the mailbox needs a licence before you convert it to a shared mailbox.
- Be deliberate about forwarding. Forwarding everything forever can create messy ownership and privacy issues. If you do it, set a review date.
OneDrive: transfer ownership, then move what matters
OneDrive is where offboarding often goes wrong because “the files are in the cloud” can feel like “someone else has it”. In reality, they are tied to a user.
What you want is simple:
- Assign a responsible owner. Usually the manager, sometimes a department lead.
- Move business files into a Team or SharePoint site. If the files matter to the business, they should live somewhere that is not one person’s personal drive.
Microsoft has been improving the process here, including a simplified transfer experience for departing employees and automatic access delegation options. The key is making sure you have a named person who receives access and then actually moves the business-critical content to a shared location.
Don’t forget the shared passwords (the real “ghost access”)
If you do everything perfectly in Microsoft 365 but ignore shared secrets, you will still have a gap.
Make this a standard step in your runbook:
- Shared mailboxes with passwords. If you still have any shared mailbox set up as “everyone signs in as this user”, treat that password as compromised on departure and rotate it. Better, move to proper shared mailbox access with permissions.
- Vendor portals and banking tools. Remove the person’s user account if it exists, then rotate any shared admin passwords.
- Local admin passwords. If you use local accounts for emergencies, rotate those passwords after use and after staff changes.
This is also where documentation pays off. If you do not have a list of “shared accounts we must rotate on offboarding”, you will miss one.
How to automate the repeatable parts (without making it fragile)
Automation works best when it triggers the same steps every time, and still leaves room for judgement calls like “should we forward email for 30 days or 90?”
Two practical automation layers in Microsoft 365 are worth considering:
- Microsoft Entra Lifecycle Workflows (Leaver workflows). These are designed for joiner, mover, leaver processes and can automate common offboarding tasks like disabling the user, removing licences, and deleting the account on a schedule.
- A simple internal offboarding form and checklist. Even if you automate the account actions, you still need human inputs: last working day, manager, who owns the mailbox, where files should go, and which shared accounts to rotate.
A good pattern is:
- Automation handles the predictable directory actions.
- Your runbook handles the handover, shared secrets, and sign-off.
Make it auditable: the one-page offboarding record
If you want a process that stays consistent as you grow, write down what happened each time. Keep it short.
For each offboarding, capture:
- Who requested it and when. Name, date, and last working day.
- Account actions completed. Block sign-in, revoke sessions, password reset.
- Mailbox plan. Converted to shared mailbox, access granted to who, forwarding and auto-reply details, review date.
- OneDrive plan. Who received access, where key folders were moved.
- Shared credential rotations. Which accounts were rotated, and when.
That record turns “we think we did it” into “we can prove we did it”, and it makes the next offboarding faster.
Want a runbook you can hand to your team?
Offboarding is one of those processes that gets easier the moment it is written down and owned. If you would like help building a Microsoft 365 offboarding runbook and automation that fits your business, the Flexnet Networks team can put that in place for you.
Sources
- Remove a former employee - Overview, Microsoft Learn
- Step 1 - Prevent user sign-in and block access to Microsoft 365, Microsoft Learn
- Revoke user access in Microsoft Entra ID, Microsoft Learn
- Convert a user mailbox to a shared mailbox, Microsoft Learn
- Simplified file transfer for departing employees, Microsoft Support



