
When an employee leaves, data security risks remain through active accounts, synced devices, shared credentials, and copied files. Strong access management closes live access and helps identify company data that still needs protection.
An employee departure creates several data security tasks at once. The business needs to secure active accounts, preserve company records, recover devices, and identify any access that still connects the former employee to business systems.
Access management also needs to account for information that has already moved. A file saved to a personal device does not disappear when IT disables the employee’s main login. IT needs to close live access and check where company data may still exist.
Table of Contents
What Access Does a Former Employee Still Have After Their Last Day?
A former employee can retain access when the business closes only the most obvious account. An employee’s email account may be closed while a separate CRM login remains active.
Good access management starts with a complete record of the systems the employee uses. IT can then complete account deactivation without overlooking a separate login.
Email, Cloud Storage, SaaS, Shared Drives, and CRM Access Can Stay Active
Closing a Microsoft 365 account does not automatically close a separate CRM login. IT needs to remove access from each supported system where required.
Company email can also contain records the business still needs. Authorized administrators can preserve or transfer mailbox information according to company requirements before they remove the account. Microsoft 365 allows authorized administrators to provide another employee with access to a former user’s Outlook and OneDrive data when needed, as outlined in Microsoft’s guidance for removing a former employee.
Personal Devices, Active Sessions, and Shared Credentials Create Additional Access
An employee who used a personal phone for company email may still have an active session or company information stored through an approved work profile. IT needs to revoke the session or remove managed business access where the company’s device controls and policies support that action.
Shared credentials require separate attention. If a departing employee knows a password used by several people, IT needs to rotate that password and update any recovery or authentication method tied to the employee.
Why Company Data Can Remain Exposed After an Employee Leaves
Account deactivation stops future access to a system. It cannot remove every copy of company information that an employee has already downloaded, forwarded, or synced elsewhere.
Data loss prevention rules can restrict sensitive files from being emailed or shared outside approved locations. Activity records can help IT see what happened before the employee left.
Forwarded Emails and Downloaded Files Are Harder to Take Back
Consider an employee who downloaded a customer pricing file to a personal laptop while working from home. Closing that employee’s cloud account prevents another login, but the downloaded copy may still exist on the laptop.
Before access closes, IT can review activity logs for unusual downloads or external sharing. That review can show whether company data needs follow-up after the employee leaves.
Offboarding Breaks Down When Nobody Owns the Process
If HR records a Friday departure but IT receives the request on Monday, the employee’s account may stay active all weekend.
A documented process prevents that gap. Management or HR gives one responsible owner the departure date and authorized cutoff time, and IT completes the technical checklist against that instruction. Clear ownership keeps account deactivation tied to the employee’s actual departure.
IT Offboarding Checklist: What Needs to Happen and in What Order
An IT offboarding checklist gives HR, management, and IT one sequence to follow. The order matters because the business needs to preserve required data before access closes.
The IT Offboarding Checklist in the Correct Sequence
- Confirm the final working date and access cutoff time. Management or HR tells IT exactly when the employee’s authorized access ends.
- Identify every account, device, and credential connected to the employee. Review email, cloud accounts, SaaS applications, CRM access, shared drives, VPN access, administrator permissions, company devices, and shared credentials.
- Preserve and transfer required business information. Move required email, files, contacts, ownership, and company records before the account closes when the departure circumstances allow preparation.
- Deactivate the primary account at the approved cutoff. Remove access to the main user account and company email, then revoke active sessions.
- Remove access from separate business systems. Close SaaS, CRM, cloud storage, shared-drive, VPN, and other supported accounts that the primary account does not control.
- Rotate shared credentials. Change passwords the employee knew and remove recovery methods or authentication settings connected to them.
- Recover and secure devices. Collect company-owned equipment and wipe or reset it before reassignment. For approved personal devices, remove managed company access or business data where the company’s management tools and policies allow.
- Review activity and document completion. Check relevant login activity, forwarding rules, external sharing, unusual downloads, and remaining permissions. Record the completed steps.
Account Deactivation Should Be Planned Around the Employee’s Actual Departure
For a planned departure, IT can prepare data transfers and account changes before the employee’s final day. IT should deactivate the employee’s access at the cutoff time authorized by the business.
For an immediate termination, IT should be ready to remove access when management gives the authorized instruction. CISA guidance on departing employee access recommends that organizations disable departing employees’ accounts and access to organizational resources by the day of departure.
What Should Your IT Provider Do When an Employee Gives Notice?
Centurion can prepare the technical offboarding steps before an employee’s final day and carry them out at the time approved by the business. Centurion already supports Microsoft 365 environments and related access controls.
Centurion Coordinates Access Removal Across Business Systems
When an employee gives notice, management can provide Centurion with the departure date and approved cutoff time. Centurion can then prepare the account changes in advance and identify required business information that needs to remain available.
At the cutoff, the Centurion team can deactivate supported accounts across the systems it manages. This keeps the technical work tied to the employee’s actual departure instead of relying on separate requests afterward.
Centurion Checks the Remaining Data, Devices, and Credentials
After the main account closes, Centurion can check for permissions or shared credentials that still give the former employee access.
Centurion also supports Microsoft Intune device management for managed laptops and phones. The final review confirms that the supported accounts, credentials, and devices included in the offboarding process have been addressed.
Secure Employee Offboarding With Centurion
Contact Centurion to make sure company accounts, data, devices, and access are secured when an employee leaves.
Frequently Asked Questions
+ What are the steps in the offboarding process?
IT offboarding starts by confirming the employee’s final date and access cutoff. IT then identifies accounts and devices, preserves required business data, disables access, rotates shared credentials, secures devices, reviews activity, and documents completion.
+ What are common offboarding mistakes?
Common mistakes include notifying IT too late, using no documented procedure, and failing to assign one person to own the checklist. Those gaps can leave access active after the employee leaves.
+ What is an offboarding checklist?
An offboarding checklist is a documented sequence of tasks used when an employee leaves. The IT portion covers company data, account deactivation, access management, credentials, devices, and final verification.
+ How to protect company data from employees?
Give each employee only the access they need and remove it as soon as their authorized access ends. Use data loss prevention where sensitive information needs extra controls.
+ Can my company access my emails after I leave?
In a business-managed email system such as Microsoft 365, authorized administrators can often retain or transfer work email after an employee leaves, depending on company policy and applicable requirements.
+ How quickly should you disable an employee’s accounts after termination?
For planned departures, account deactivation should align with the exact cutoff time on their final day. For immediate terminations, accounts should be disabled immediately upon instruction, ideally on the day of departure.
+ Can a former employee access company data through personal devices?
Yes, if sessions remain active or data was downloaded locally. IT must revoke active sessions and remove managed business access or profiles using mobile device management tools.
+ Who is responsible for IT offboarding in a small business?
While HR or management initiates the process and provides authorization, a single owner—typically an internal IT lead or a managed IT service provider—must own and execute the technical offboarding checklist.
