Skip to main content

    The Employee Offboarding IT Checklist

    By Jason MartinoApril 27, 2026Security7 min read

    Most small businesses know what to do when someone leaves. Badges get collected, final payroll is closed out, HR records are updated, all on the last day. The IT side of the same event is rarely as thorough, and it often slips by days or weeks. Cutting off access is the one part of offboarding that can't wait. During assessments, we routinely find active accounts belonging to people who left months earlier, along with SaaS licenses the company was still paying for. That gap is one of the easiest ways to leave yourself exposed, and it's almost always a process problem rather than a tooling problem.

    Why the quiet risk is the real risk

    Most business owners picture offboarding risk as a departing employee walking out with data. That happens, but in our experience it's rarely the real problem. In Ponemon's 2025 study, 55% of insider incidents traced to negligence rather than a bad actor1. The more common scenario looks like this: an account nobody is watching gets compromised through a password-reuse breach, or a former contractor's VPN credentials turn up months later in a list traded on the dark web. The attacker doesn't need to be sophisticated. The account simply needs to still exist.

    Lingering access is more common than most businesses realize, and it's mostly a process gap rather than a technical one. More than half of organizations still don't automate granting and removing access, so when someone leaves, whether they actually get cut off comes down to someone remembering to do it by hand2. Once an environment has any meaningful number of users, it's safe to assume at least one of those forgotten accounts is a way in.

    What a complete offboarding looks like

    The work breaks down into access and authentication, devices and physical assets, data preservation, and license cleanup. None of it is technically difficult. The discipline is in doing every item, every time, on the day the person leaves rather than later in the week. The sequencing also matters. Cut authentication first, capture data second, clean up licenses and inventory last. Collecting a laptop before the account is disabled leaves a window where the credentials are live and the device is in transit.

    Access

    • Disable the single sign-on account and revoke active sessions. Microsoft 365 or Google Workspace is usually the identity behind everything connected through single sign-on, so disabling it closes the front door to all of those at once. Disabling stops new logins, but the refresh tokens already issued to the user's phone and laptop can keep working for hours unless you explicitly sign them out everywhere. In Microsoft 365 that's the Revoke sessions action. In Google Workspace it's Sign out user. Skipping the session revocation is the most common technical miss we see in offboarding.
    • Cut VPN and remote access right away. If remote access is tied to single sign-on, disabling the account above already closed it. But many small-business VPNs and remote tools use their own credentials, and those keep working until you cut them explicitly. Any path into the network from outside the office should be closed before the badge is.
    • Keep the mailbox, don't delete the account. You'll often need access to the mailbox for business continuity. Convert it to a shared mailbox or set delegation, and forward incoming mail to the manager using a server-side rule rather than one that depends on the client running.
    • Revoke access on every system that isn't behind single sign-on. Disabling the identity account above only cuts off the apps that authenticate through it. Anything with its own separate login keeps working until you turn it off. The misses are usually the CRM, the accounting system, the project management tool, the file sync service, the marketing platform, and any vendor portals, especially the ones a single team set up on their own.
    • Rotate any shared credentials the user had access to. Shared admin logins, social accounts, vendor portals, conference room screens. If the password was known to the departing user, it's no longer a secret.
    • Remove the user from group mailboxes, distribution lists, and team accounts. These are easy to miss because they aren't tied to a single license.

    Devices and data

    • Remove company data from any personal device that touched the environment. A mobile device management tool can scope the wipe to corporate data without touching personal photos and contacts.
    • Collect every company-issued device against an asset inventory. Laptops, phones, tablets, external drives, security keys. That inventory can be a simple spreadsheet, or the asset list your device-management tool maintains for you. If you don't know what was assigned, you can't confirm what was returned.
    • Preserve the user's data before wiping any device. Mailbox, OneDrive or Google Drive, local files that weren't synced. Move what the business needs to a known location before reformatting.
    • Reclaim or reassign the software licenses. A disabled user can still hold a paid seat in a dozen apps, quietly billing every month until someone reclaims it.

    Documentation and review

    • Record what was done and when. The log should note which accounts were disabled, which devices came back, and who handled each step. Months later, if someone asks whether a system was really closed off, that record is what answers it.
    • Review access logs for the period leading up to their last day. Look for large file downloads, new mailbox forwarding rules, or access to systems outside the person's normal pattern. None of it is conclusive on its own, but all of it is worth a second look.
    • Update the asset inventory in the same pass. Once the data is off the device, it either gets re-imaged and made ready for the next hire, or, if it's reached the end of its useful life, marked for retirement or recycling. Either way, the inventory only stays accurate if you update it as part of the work.

    The gaps we see most often

    A few patterns show up repeatedly when we audit offboarding during a Technology Confidence Assessment.

    The first is incomplete SaaS coverage. The provider disables email and considers the job done. Meanwhile the departing user is still a licensed seat in eight other applications, several of which hold customer or financial data. Most small businesses run more software than anyone has written down, so without an authoritative list of what each user had access to, the offboarding was never really finished.

    The second is delay. Offboarding gets queued behind other work and slides from Friday to Monday to Wednesday. Every day an unused account stays active is a day a credential-stuffing attack can succeed against it without anyone noticing. Credential abuse shows up in 39% of the breaches Verizon analyzed in 20263. The discipline that matters is doing the access revocation on the last day, even when nothing else can happen on the same timeline.

    The third is forgetting non-employees. Contractors, agency staff, bookkeepers, fractional executives, and outside consultants frequently end up with credentials that outlast the engagement by years. They need the same treatment as a W-2 employee, and the process should be triggered by the end of the engagement rather than by HR.

    The fourth is the absence of a master access list in the first place. If nobody can produce a definitive document of which systems each user is in, the offboarding will always miss something. Building that list is one of the most useful things a small business can do, and it ties directly back to the essential security baseline for small business.

    What a managed provider should be doing

    If you pay a managed IT provider, offboarding should be a documented, repeatable workflow that runs the same way every time, triggered by a single notification from your side. You shouldn't be reminding them to disable accounts. You shouldn't be asking whether the VPN was closed. The completed offboarding should arrive in your inbox as a ticket summary with a list of what was done and why.

    What a provider does the rest of the time matters just as much. A good provider maintains the access inventory continuously so that offboarding is small and predictable instead of a scramble. If your current provider's offboarding feels improvised, or if it depends on you remembering to mention the smaller applications, the issue is rarely the technician. It's the absence of a process. The MSP Frustration Quiz is a useful read on whether that gap is isolated or part of a broader pattern.

    Audit your offboarding before the next exit.

    A Technology Confidence Assessment includes a review of how access is granted when someone joins and removed when they leave. We surface the gaps in writing and give you a process you can run consistently.

    Schedule a Technology Confidence Assessment

    Get Professional Guidance

    Schedule a free Technology Confidence Assessment to get personalized recommendations for your business.

    Book your assessment