Microsoft 365 offboarding checklist work is the part of a resignation that nobody puts in the calendar. HR runs the exit interview, the manager collects the laptop, and somewhere in the middle a support ticket says “please disable Sarah’s account” with no indication of what that actually means in a tenant holding mail, files, chats, licences and devices.

The gap between “disabled” and “properly offboarded” is where the problems live. A licence keeps billing for months. A mailbox nobody converted quietly vanishes with the account. A OneDrive full of the only copies of client work hits a deletion clock that started the day IT ticked a box. Meanwhile the former employee’s phone still has a valid refresh token, because resetting a password does not end a session that was already established.

None of this is difficult. It is simply detailed, and detail is exactly what gets lost when the request arrives as a one-line message on someone’s last afternoon. This guide sets out the whole sequence in the order it should happen — the first hour, the mailbox, the files, the collaboration residue, the licences, the devices, the compliance evidence — and finishes with the FAQ questions that come up every time. It assumes a UK business on Business Premium or E3, and it pairs with our broader IT onboarding and offboarding checklist for everything that sits outside the tenant.

Why a Microsoft 365 offboarding checklist is not the HR version

microsoft 365 offboarding checklist departing employees b signpost two blank arrows

HR’s leaver process is about people: notice periods, final pay, the exit interview, the return of a door pass. A Microsoft 365 offboarding checklist is about state — dozens of small pieces of configuration that each need a decision, and that behave badly when left alone.

The licence keeps billing until somebody acts

Nothing about a disabled account stops the subscription. The seat is still assigned, still counted, still invoiced at the next renewal. Across a year of ordinary turnover this is one of the largest sources of avoidable spend in the tenant, and it is invisible unless someone reconciles seats against headcount — which is exactly what a Microsoft 365 licence audit is for.

The data sits in five places, not one

Mail, OneDrive, SharePoint, Teams and any per-user app data all hold different content with different retention behaviour. A Microsoft 365 offboarding checklist that only addresses the mailbox leaves four of those untouched, and OneDrive is usually where the genuinely irreplaceable material is.

Access outlives the last working day

Session tokens, registered devices, app passwords, guest memberships in partner tenants and personal-device Outlook profiles all survive a password change. Access is not a single switch; it is a set of them, and they have to be thrown deliberately.

The first hour: block access without destroying anything

microsoft 365 offboarding checklist departing employees c padlock closing above plinth

This is the phase where mistakes are expensive in both directions. Move too slowly and a disgruntled leaver has a window. Move too aggressively — deleting the account outright — and you lose the data you were trying to protect. Every Microsoft 365 offboarding checklist should therefore separate blocking access, which is urgent and reversible, from removing data, which is neither.

Reset the password and revoke the sessions together

Resetting the password alone is the single most common error in the whole process. Existing sessions carry a refresh token that stays valid, so a phone that was already signed in keeps working. Reset the password and revoke the sign-in sessions in Entra ID, then confirm no active sessions remain. Doing one without the other is worse than doing neither, because it produces false confidence.

Disable the account — do not delete it

Sign-in blocked, licence still attached, data intact: that is the correct state on day one. Deleting a user starts a 30-day countdown after which restoration is no longer possible, and it removes the account from places where you may still need it referenced. The Microsoft guidance on removing a former employee sets out the supported sequence in full, and it is worth following rather than improvising.

Strip the MFA methods and app passwords

Remove the registered authenticator, the phone number and any legacy app passwords. App passwords are the ones people forget: they bypass modern authentication entirely and will keep a mail client connected long after everything else is closed. A wider Microsoft 365 security audit will usually surface a handful of these still in existence tenant-wide.

Check what devices are still registered

Look at the leaver’s registered and joined devices before you touch anything else. A personal phone showing as Entra-registered is a live access path, and you want it identified now rather than during the device stage of the Microsoft 365 offboarding checklist a week later.

Remember the tenants where they are a guest

Staff who work with clients or partners accumulate guest accounts in other organisations’ tenants. Blocking sign-in at home does nothing to those, because they are separate identities living somewhere you do not administer. List the external tenants the leaver had access to, then email each one asking for removal. It is the least satisfying item on the Microsoft 365 offboarding checklist, because you cannot complete it yourself — but leaving it undone means a former employee still has a working route into a client’s environment carrying your company’s name.

Mailbox steps on the Microsoft 365 offboarding checklist

microsoft 365 offboarding checklist departing employees d sealed envelope on plinth

The mailbox is where the business risk and the business need pull hardest against each other. Colleagues want continuity; compliance wants preservation; finance wants the licence back. A good Microsoft 365 offboarding checklist satisfies all three, in that order.

Convert to a shared mailbox and free the licence

Converting the user mailbox to a shared mailbox preserves every message, folder and calendar item, and a shared mailbox under 50 GB needs no licence at all. Colleagues who need continuity get delegated access without anyone logging in as the leaver. This single step is the most useful item on any Microsoft 365 offboarding checklist, and it is routinely missed.

Forwarding needs a visible end date

Forwarding a leaver’s mail to their manager is reasonable for a handover window and unreasonable as a permanent arrangement — it quietly redirects personal correspondence and confuses external contacts who think they are still emailing the same person. Set forwarding with an agreed end date, record it, and actually remove it when the date arrives.

The auto-reply and the calendar

An auto-reply naming the correct replacement contact prevents weeks of unanswered enquiries, and costs two minutes. Transfer or cancel the leaver’s recurring meetings as well; a departed organiser’s series is a familiar source of confusion months later when nobody can amend the invitation.

Delegate access, never share the password

If a manager needs the mailbox, grant them delegated permissions on the shared mailbox. Sharing the leaver’s credentials destroys the audit trail, defeats conditional access and turns any subsequent investigation into guesswork. This distinction matters enormously if the departure later becomes a dispute.

OneDrive, SharePoint and the files nobody inherits

microsoft 365 offboarding checklist departing employees e stack of blank document sheets

OneDrive is the highest-consequence part of the Microsoft 365 offboarding checklist, because it holds work that only one person ever touched — and because deletion is on a timer.

Nominate a delegate before the account is disabled

Assign the leaver’s manager as a delegate to their OneDrive at the point of offboarding. They get access to the whole library, can move what the team needs into a shared location, and can do it while the content is still comfortably in place rather than under time pressure.

Move what matters into a team site

Anything the business depends on should not have been in a personal OneDrive in the first place. Offboarding is a natural moment to relocate it to a SharePoint team site where ownership is collective. If you are still running a hybrid estate, the same logic applies to whatever remains on the server — see our file server to SharePoint migration guide.

Know the 30-day and 93-day clocks

When a user is deleted, their OneDrive is retained for a configurable period — 30 days by default, up to ten years — and the account itself is recoverable for 30 days. The OneDrive retention and deletion documentation explains exactly which clock starts when. Check your tenant’s configured value rather than assuming the default; a great many organisations have never looked.

Find what was shared externally

Departing staff leave behind sharing links to clients, contractors and personal addresses. Enumerate the external shares on their OneDrive and revoke the ones that no longer have a business justification. This is one of the few Microsoft 365 offboarding checklist steps that reduces risk for people other than the leaver.

Teams, groups and the collaboration residue

microsoft 365 offboarding checklist departing employees f hub sphere with four cubes

Teams is where a Microsoft 365 offboarding checklist quietly fails, because the content is owned by groups rather than by the person, and group ownership is rarely tidy.

Ownerless Teams and Microsoft 365 groups

If the leaver was the sole owner of a Team or group, disabling them leaves it ownerless — members carry on working, but nobody can manage membership, settings or lifecycle. Enumerate every group they owned and reassign each one. Microsoft’s ownerless-group policy can automate the request, but only if you have configured it in advance.

Where private chat history actually lives

One-to-one and group chat messages are stored in a hidden folder within each participant’s mailbox, so they follow the mailbox conversion and remain discoverable through eDiscovery. They are not visible to a manager browsing Teams, which surprises people who assume converting the mailbox has made everything readable.

Channel files follow the SharePoint site

Files posted in a Teams channel live in the underlying SharePoint site, so they survive the leaver entirely. That is the good news. The bad news is that anything shared inside a private chat lives in the sender’s OneDrive, which is on the deletion clock described above — another reason the OneDrive stage of your Microsoft 365 offboarding checklist matters more than it looks.

The accounts Microsoft cannot see for you

Every business runs software that has nothing to do with the tenant: the accounting package, the CRM, the courier portal, the domain registrar, the social accounts. None of it appears in any admin centre, and none of it is touched by disabling an Entra ID account. Keep a per-role list of these alongside the Microsoft 365 offboarding checklist and work through it in the same ticket. Shared logins are the worst case here, because the only real remediation is changing a password that several people are still using.

Licences and the money your Microsoft 365 offboarding checklist saves

Reclaiming licences is the part of the Microsoft 365 offboarding checklist with a number attached, which makes it the easiest part to get signed off.

Reclaim, do not stockpile

Once the mailbox is shared and the OneDrive content is relocated, unassign the licence. Teams commonly hold seats “in case somebody joins”, which converts a variable cost into a fixed one. Unassign now; reassign when there is an actual person.

The annual commitment trap

Unassigning a licence stops it being consumed, but on an annual commitment it does not stop the invoice — you keep paying until the renewal date. Track the surplus and reduce the quantity at renewal, or the saving exists only on paper. Our Business Premium, E3 and E5 comparison is a useful sanity check while you are in there.

Add-ons hide in the per-user column

Copilot seats, Power BI Pro, telephony plans, Defender add-ons and third-party SaaS billed per user all need removing separately. The base licence is the obvious one; the add-ons are where the residual spend accumulates, and a Microsoft 365 offboarding checklist that stops at the primary seat leaves most of the saving behind.

Devices, Intune and the hardware coming back

Physical return and logical decommissioning are different tasks, and only one of them is on the manager’s mind. The hardware stage of a Microsoft 365 offboarding checklist is the half that gets forgotten once the laptop is back in the cupboard.

Retire, wipe and the difference that matters

In Intune, retire removes company data and management while leaving personal content; wipe returns the device to factory state. Company-owned hardware being reissued should be wiped and re-enrolled. Getting this wrong on a personal device is a genuine problem, so confirm ownership before you issue the command — if you are still deciding how to manage this estate, our Intune versus RMM comparison covers the trade-offs.

BYOD and selective wipe

Where staff use personal phones for mail, a selective wipe removes the company account and its cached content without touching photographs or personal messages. Make sure your BYOD policy says this will happen at offboarding, in writing, before you need to rely on it.

Get the device ready for the next person

Wipe, confirm the Autopilot registration is intact, and return the machine to stock. A laptop that sits in a drawer half-decommissioned becomes an unmanaged device the moment somebody hands it to a new starter in a hurry, which is precisely how gaps appear in an otherwise disciplined device management process.

Compliance: holds, eDiscovery and UK GDPR

A Microsoft 365 offboarding checklist is where retention obligations and data protection obligations meet, occasionally in opposition.

Apply the hold before you touch the account

If there is any prospect of litigation, an employment tribunal or a regulatory enquiry, apply a litigation hold to the mailbox before the offboarding steps begin. A hold applied afterwards cannot recover what a retention policy has already removed. When in doubt, hold — it is reversible, and the alternative is not.

Retention labels are not the same as keeping the account

Retention policies preserve content independently of whether the account exists, which is what makes account deletion survivable. They are not a backup, and they will not help with accidental deletion of a live user’s working files — a distinction our guide to Microsoft 365 data retention versus backup sets out in detail.

Storage limitation cuts both ways

UK GDPR’s storage limitation principle says personal data should not be kept longer than necessary. Keeping a leaver’s entire mailbox indefinitely because it was easier than deciding is a defensible-sounding habit with no actual defence. Set a review date at the point of offboarding.

Keep the evidence that the Microsoft 365 offboarding checklist ran

Record who did what and when: the ticket, the timestamps, the confirmation that sessions were revoked. In an incident or an audit, “we always do this” carries no weight and a dated log carries a great deal. This is the item most often skipped and most often needed.

The high-risk leaver: resignations, disputes and dismissals

Most departures are ordinary. A small number are not, and the difference should change the sequence of the Microsoft 365 offboarding checklist rather than its content.

Run the Microsoft 365 offboarding checklist before the conversation

For a dismissal, or a resignation to a direct competitor, access should be blocked as the meeting begins rather than at the end of the notice period. Coordinate with HR so the technical work is prepared, timed and executed quietly — not discovered afterwards.

Read the audit log for bulk downloads

Check the unified audit log for large-scale file access, OneDrive sync to a new device, or mass forwarding in the weeks before notice. Findings need to go to HR and legal, not into an informal conversation, and the log is only useful if your retention period is long enough to reach back that far.

Decide in advance what you would do

The worst time to design a response is during one. If a departure looks contentious, the same instincts that drive a business email compromise response plan apply here: preserve first, investigate second, and keep the decision-making documented throughout.

Making the Microsoft 365 offboarding checklist repeatable

A process that depends on somebody remembering is not a process. The goal is that a Microsoft 365 offboarding checklist runs correctly when the person who normally does it is on holiday.

Trigger it from HR, not from a Teams message

The leaver notification should come from HR’s system into a ticket with a defined template and an SLA, not from a manager messaging whoever is online. Most failures are not technical; they are the request arriving late, verbally, or not at all.

Automate the mechanical steps

Session revocation, licence removal, mailbox conversion and group reassignment can all be scripted or driven through a lifecycle workflow. Automate them and the Microsoft 365 offboarding checklist stops varying by who executed it — which is the only way the compliance evidence becomes meaningful.

One named owner, one deadline

Give every offboarding a single accountable owner and a completion deadline measured in days, not “when we get a moment”. Organisations that outsource this to a managed IT services provider get the deadline enforced by contract, which is usually more durable than internal goodwill.

Reconcile against payroll twice a year

The honest test of a Microsoft 365 offboarding checklist is not whether the document exists but whether the tenant matches reality. Twice a year, export the list of licensed users and compare it against payroll. Every name on one list and not the other is a question worth answering: a dormant account nobody disabled, a shared mailbox that quietly reacquired a licence, a contractor who left in March. This reconciliation takes an hour and consistently finds something.

Microsoft 365 offboarding checklist: frequently asked questions

How quickly should access be removed?

Immediately on the last working day for an ordinary resignation, and at the start of the conversation for a dismissal or a move to a competitor. There is no good reason to leave access live through a notice period once the work has been handed over, and a Microsoft 365 offboarding checklist that begins “within five working days” is really an admission that nobody owns it.

Can we just delete the account and be done?

You can, but you should not do it on day one. Deletion starts a 30-day recovery window and a OneDrive retention clock, and it removes options you may want later. Disable, convert the mailbox, relocate the files, then delete once the retention decision has been made deliberately.

What happens to their OneDrive files?

They are retained for your tenant’s configured period after the account is deleted — 30 days by default. During that window a nominated delegate can access and relocate them. After it, they are gone unless a retention policy or a third-party backup is holding a copy, which is why a Microsoft 365 backup decision belongs alongside this process.

Do we have to keep the mailbox at all?

That depends on your retention schedule and your sector. Converting to a shared mailbox costs nothing under 50 GB, so the pragmatic answer for most UK businesses is to keep it for the period your policy specifies, then remove it on a documented date rather than leaving it forever by default.

Who should own the Microsoft 365 offboarding checklist?

IT executes it, HR triggers it, and the line manager makes the content decisions about files, mailbox continuity and group ownership. Name all three in the process document. Offboarding stalls most often at the point where somebody has to decide what to do with the data, and no one has been asked.

Does converting to a shared mailbox really free the licence?

Yes, provided the mailbox stays under 50 GB and you do not need an archive or a litigation hold on it — both of those require a licence. Check the size at conversion, because a long-serving employee’s mailbox can be well over the threshold.

How long should the whole process take?

For a well-prepared tenant, the access-blocking steps take under fifteen minutes and the full Microsoft 365 offboarding checklist takes about an hour of technical work, spread over the days it takes the manager to make the file and mailbox decisions. If it routinely takes longer, the bottleneck is the decisions, not the tooling.