Offboarding a departing employee in Microsoft 365: a checklist
The order of operations for removing a former employee's Microsoft 365 access without losing their mailbox, files, or an audit trail.

Offboarding usually goes wrong in one of two directions: either access is cut immediately and something important — a shared mailbox delegation, a file a colleague still needs — gets lost with it, or access lingers for weeks because no one owned the follow-up steps. Microsoft’s own admin documentation lays out a sequence that avoids both. This guide is based on our review of that documentation, adapted into a checklist order.
The sequence, in order
1. Block sign-in immediately. This is the step that actually stops access — do it the moment departure is confirmed, before anything else. It prevents the account signing in without touching email, files, or licensing.
2. Save the mailbox contents you need. If someone is taking over the departing employee’s work, or you have a legal or compliance reason to retain their mail, do this before the mailbox is converted or the license is removed.
3. Wipe and block any company-managed mobile device. If the employee had a phone or tablet enrolled with access to company data, remove that data before the device leaves your control.
4. Forward their email or convert the mailbox to shared. This keeps messages from customers or partners reaching someone, rather than bouncing or disappearing, while the next person picks up the account.
5. Give someone else access to their OneDrive and Outlook data. Do this before deleting the account. Removing a license retains mailbox, contact, and calendar data for 30 days before permanent deletion; deleting the account retains OneDrive content for 30 days as well, but only if you act within that window.
6. Remove and reassign, or delete, the Microsoft 365 license. Reassign it if you have a new hire ready; otherwise it can be deleted once you’re confident everything that needed saving has been saved.
7. Delete the user account. This is the last step, not the first — deleting the account stops any further email from being received at that address permanently, so it should only happen once mailbox and file access have been handled.
A note on hybrid environments
If your organization synchronizes accounts from an on-premises Active Directory, the account has to be deleted (and, if needed, restored) in Active Directory itself — Microsoft 365 can’t delete or restore an account it doesn’t own the source of.
Don’t skip the review afterwards
The checklist above handles one departure. What it doesn’t catch on its own is whether that person had standing access nobody remembered — a shared mailbox delegation, an admin role granted for a one-off project, an app registration tied to their account. That’s the kind of drift a Monthly Security Care cadence is built to catch, and it’s worth checking for explicitly the first time you run this checklist for real.
Where this fits into a broader review
Offboarding is one part of identity and access hygiene — the same area our Microsoft 365 Security Review & Hardening service examines when it looks at administrative roles and who currently holds them.
Sources