Date Published: 

September 18, 2026

How to Build a Secure Employee Offboarding Checklist

Employee offboarding is one of those business processes that can feel routine until something goes wrong. A former employee still receives email. A laptop comes back weeks late. A shared password remains unchanged. A cloud account stays active long after the last paycheck.

For small and medium sized businesses, these gaps create real risk. Customer records, financial data, contracts, employee information and internal conversations often live across Microsoft 365, cloud apps, mobile devices and shared drives. If access is not removed in a controlled way, your business may be exposed to data loss, privacy issues, insurance problems and unnecessary confusion.

A secure employee offboarding checklist gives HR, management and IT a repeatable process. It helps employees leave cleanly, protects company information and gives business owners confidence that nothing important was missed.

Why secure offboarding matters

Employee offboarding is not just an HR task. It is a security process, a data protection process and a business continuity process.

Most employees have more access than leadership realizes. Even a nontechnical staff member may have email, shared file access, accounting software, payroll portals, project tools, CRM records, vendor systems, mobile apps, WiFi access and saved passwords in a browser. Managers, bookkeepers, attorneys, executives and operations staff often have even broader access.

Secure offboarding is not about assuming bad intent. Many former employees would never misuse access. The issue is that open accounts create unnecessary exposure. A personal device could be lost. A password could be reused on another website. A former employee could accidentally receive confidential messages. In some situations, a frustrated employee may try to download data before access is removed.

The goal is simple. When an employee leaves, your business should know what they could access, who approved the access changes, when access was removed and where their business data went.

Assign one owner for the offboarding process

A checklist only works if someone owns it. In many smaller organizations, that person might be an office manager, HR lead, operations manager or department head. IT should handle the technical steps, but management should own the business decision.

The checklist owner should confirm the final work date, coordinate with the employee’s manager, notify IT with enough time to prepare and verify that all steps are complete. If the departure is sensitive, such as an involuntary termination or a role involving financial authority, the checklist owner should coordinate timing carefully so access changes happen at the right moment.

Documentation matters. Keep a record of who requested the offboarding, when IT was notified, which systems were changed, which devices were returned and who approved data transfers. These records can be useful for audits, internal reviews and insurance discussions. They also support the access control documentation covered in VM Tech’s guide to preparing for a cyber insurance review.

A secure employee offboarding checklist you can use

Use the following checklist as a practical starting point. A law firm, accounting office, manufacturer, nonprofit or local service business will each have different systems, but the core security steps are the same.

1. Confirm the departure details and risk level

Start with the basics. Confirm the employee’s last working day, final hour of work, personal contact information, manager name and reason for departure. You do not need to overcomplicate this step, but the timing matters.

A planned retirement with two weeks of notice is different from an immediate termination. A remote employee is different from someone who works only in the office. A staff member with access to payroll, bank portals or administrative systems needs more careful handling than someone with limited access.

The checklist should identify whether the departure is routine, time sensitive or high risk. That decision helps IT determine when to remove access, whether to monitor activity before departure and how quickly devices need to be recovered.

2. Identify every system the employee can access

Do not rely on memory. Most businesses add tools over time, which means employee access spreads across more systems than expected.

Review Microsoft 365, Outlook, Teams, SharePoint, OneDrive, file servers, VPN, WiFi, accounting software, payroll platforms, timekeeping tools, CRM systems, project management tools, cloud storage, phone systems, vendor portals, bank portals, building access, security camera systems and password managers. Also check any industry specific platforms, such as legal case management software, tax preparation tools, donor management systems or manufacturing scheduling systems.

If your company does not have a current access list, create one during offboarding. Over time, this becomes one of the most useful security documents your business has.

3. Decide exactly when access should change

Access timing should be intentional. For a routine departure, it may make sense to remove sign in access at the end of the employee’s final workday. For an involuntary departure, access should often be removed during the termination meeting or immediately before it begins.

Avoid removing access too early without telling the manager. If files, email or project notes still need to be transferred, sudden account changes can interrupt work. At the same time, avoid waiting until later in the day because someone is busy. If the risk is high, access removal should be treated as a scheduled business event.

For companies with an IT provider, notify them in advance whenever possible. The request should include the employee’s name, final access time, systems involved, device details and the manager who should receive data access.

4. Preserve business data before accounts are closed

One common mistake is disabling an account before deciding what to do with the employee’s data. That can create delays, lost files and confusion for the person taking over their work.

For Microsoft 365, review Outlook, OneDrive, SharePoint and Teams. Decide whether the mailbox should become a shared mailbox, whether an automatic reply is needed and who should have access to the former employee’s files. Do not forward all messages to a personal account. Keep business communication inside company controlled systems.

For local computers, confirm that important files are not stored only on the desktop or in personal folders. For cloud apps, check for reports, documents, client notes and saved templates. The manager should confirm that essential business records have been transferred before the account is deleted or fully retired.

5. Revoke sign in access across Microsoft 365 and cloud apps

Once the right time arrives, IT should remove the employee’s ability to sign in. This usually includes resetting the password, signing out active sessions, removing multi factor authentication methods, blocking sign in and removing the user from groups.

If the employee had administrative permissions, those should be removed immediately. This includes admin roles in Microsoft 365, accounting systems, cloud services, phone platforms, website tools, security systems and any vendor portals.

Licenses should not always be removed instantly. In some cases, keeping a Microsoft 365 license temporarily makes it easier to preserve data, manage retention and transfer ownership. The important part is blocking the former employee from signing in while your business keeps the data it needs.

6. Recover company devices and physical items

Access is not only digital. The checklist should include laptops, desktops, tablets, phones, security tokens, keys, badges, credit cards, parking passes, paper files, backup drives and any company owned equipment.

For remote employees, send clear return instructions and track the shipment. If the role involved sensitive data, do not wait weeks to recover the device. If a device cannot be returned quickly, IT may need to lock it, remove company data or take other protective steps if the tools are already in place.

Before a returned computer is assigned to another employee, IT should inspect it, install updates, remove personal information, verify security tools are working and wipe or reset the machine when appropriate. Reusing a laptop without review can pass old problems to the next person.

A business owner, office manager, and IT consultant review an employee offboarding checklist on a laptop in a conference room.

7. Secure passwords and shared accounts

Shared accounts create offboarding problems. If several employees use the same password for a vendor portal, social media account, phone system or software login, removing one person’s access becomes much harder.

The best practice is to use named accounts whenever possible. Each employee should have their own sign in, and access should be based on their role. If shared credentials still exist, change those passwords immediately after the employee leaves. Update the company password manager, remove the former employee’s access to it and confirm that recovery email addresses and phone numbers are company controlled.

Pay close attention to accounts tied to money, client data or public reputation. This includes bank portals, payroll, accounting tools, domain name accounts, website hosting, social media profiles and payment systems.

8. Remove access from communication and collaboration tools

Email is only one communication channel. Former employees should also be removed from Teams, shared calendars, distribution groups, voicemail, phone systems, messaging apps, video meeting tools, project boards and client portals.

Check call forwarding and voicemail routing. If the employee had a direct phone number, decide whether calls should go to a manager, shared line or replacement employee. If the employee appeared on shared calendars or recurring meetings, clean those up so clients and coworkers are not confused.

For mobile devices, verify whether business email, Teams, file access or other apps remain active. If the company allows personal phones to access business systems, make sure your mobile access policy allows company data to be removed when someone leaves.

9. Transfer responsibility to the right manager or replacement

A secure offboarding checklist should protect the business without interrupting operations. The employee’s manager should confirm who will take over open work.

For a law firm, that may mean active matter files, court dates, client communications and document templates. For an accounting firm, it may include tax documents, client portal access, workpapers and filing deadlines. For a manufacturer, it could involve vendor contacts, production schedules, maintenance records and purchasing approvals. For a nonprofit, it might include donor records, grant documents, volunteer schedules and event plans.

This step is not just about files. It is about business continuity. Someone should know which projects are open, which clients need follow up, which deadlines are approaching and which systems require reassignment.

10. Document completion and keep the record

The final step is confirmation. The checklist owner should record that access was removed, devices were returned, data was transferred and the manager approved completion.

Keep the completed checklist with the employee’s departure records. Include dates, times, systems, assigned owners and any exceptions. If something could not be completed, such as a missing device or delayed vendor access change, document the reason and assign a follow up owner.

This audit trail helps your business answer a simple but important question. If someone asks what happened after the employee left, you can show the steps you took.

Special offboarding situations that need extra care

Not every departure should follow the same pace. Some situations require faster action and closer coordination.

For involuntary departures, HR or management should coordinate with IT before the conversation happens. Access should be removed at the agreed time, not hours later. The employee should not retain access to email, files or business apps after the decision has been communicated.

For employees with elevated access, review permissions more carefully. This includes executives, finance staff, IT administrators, office managers, HR personnel and anyone with access to confidential client records. These users often have access in places that are not obvious, such as vendor portals, financial systems or approval workflows.

For remote employees, device recovery and data protection need planning. Confirm where company equipment is located, how it will be returned and whether the business can lock or manage the device if needed. Remote work makes convenience easier, but it also makes offboarding discipline more important.

For contractors, interns and seasonal workers, do not treat temporary access casually. Short term workers often receive access quickly, then get forgotten when the engagement ends. Add contractor end dates to your access review process so accounts do not remain open indefinitely.

How to make offboarding easier next time

The best offboarding process starts before anyone leaves. If your business has clear policies, current user records and consistent access controls, departures become much easier to manage.

Keep a simple inventory of your core applications and who approves access to each one. Review user access at least quarterly, especially for financial systems, HR platforms, cloud file storage and administrative accounts. Require unique user accounts instead of shared logins. Make multi factor authentication standard for business systems.

Put expectations in writing. Employees should understand how company devices, passwords, data and business accounts are handled. If your business is still relying on informal rules, VM Tech’s guide to IT policies every growing business should have is a helpful place to start.

It also helps to create a standard offboarding form that managers can submit to IT. The form should capture the employee’s name, title, department, last access time, manager, devices, key systems and data transfer instructions. A consistent request prevents last minute emails that miss important details.

Common offboarding mistakes to avoid

One common mistake is focusing only on email. Email matters, but it is rarely the only risk. Cloud apps, shared drives, mobile devices, saved passwords and vendor portals often contain sensitive information.

Another mistake is deleting accounts too quickly. Blocking sign in is usually urgent, but deleting the account may not be. Your business may need to preserve email, files or records for operational, legal or compliance reasons.

A third mistake is forgetting physical access. Keys, badges, alarm codes and office entry systems should be part of the same checklist as digital accounts. If building access is managed by a property manager, assign someone to confirm the change.

Finally, do not assume managers will remember every system an employee used. Managers know the work, but IT often knows the access. The strongest process combines both perspectives.

Frequently Asked Questions

Who should own the employee offboarding checklist? A business owner, HR lead, office manager or operations manager should own the process. IT should complete the technical access changes, but management should decide timing, data ownership and business handoff responsibilities.

When should employee access be removed? For routine departures, access is often removed at the end of the final workday. For involuntary departures or sensitive roles, access should be removed during the termination meeting or immediately before it begins.

Should we delete the former employee’s Microsoft 365 account right away? Not usually. It is often better to block sign in first, then preserve email and files, transfer ownership and confirm retention needs before deleting or fully retiring the account.

What systems are most often forgotten during offboarding? Businesses often forget shared mailboxes, mobile apps, password managers, vendor portals, WiFi, VPN, phone systems, building access, social media accounts and industry specific software.

How often should we update our offboarding checklist? Review it at least once or twice a year, and any time your business adds a major new system. You should also update it after a departure if the process revealed missing steps.

Need help building a safer offboarding process?

Secure offboarding is easier when HR, management and IT follow one repeatable process. VM Tech helps businesses across Southern California with managed IT services, Microsoft 365 support, cybersecurity, cloud solutions, server and network management, backup and disaster recovery, IT consulting and technology projects.

If you want help tightening access controls or building a practical offboarding workflow, contact VM Tech to start the conversation.