Advanced IT Support • Managed IT Services • Jacksonville, FL
The Employee Offboarding IT Checklist Every Business Needs
An employee’s last day should also be their accounts’ last day. Here is what that actually requires
Most of the risk here isn’t a disgruntled former employee logging back in for revenge. It’s simpler and less dramatic than that. Every account that stays active after someone leaves is one more door into your business that nobody is watching. Attackers don’t care whose credentials they find; a forgotten login from someone who left two years ago works just as well as a current employee’s, and it’s far less likely to be noticed if it’s misused.
Why This Gets Missed So Often
Offboarding usually falls into a gap between HR and IT. HR handles the final paycheck, the exit interview, and the paperwork. IT finds out the person is leaving whenever someone remembers to tell them, which is sometimes the day of, and sometimes a week later. Without a shared checklist that both sides follow, individual steps get missed, and nobody notices until an audit, a security incident, or a very awkward moment reveals that a former employee still has access to something they shouldn’t.
The fix isn’t complicated. It’s a written checklist that runs the same way every time, triggered the moment a departure date is known, executed on the employee’s actual last day, no exceptions for how the departure happened or how the relationship ended.
Before the Last Day: What to Prepare
- Compile a full list of every system, application, and account the employee has access to, including shared logins they may know even if they don’t have an individual account.
- Identify what data or files only exist on the employee’s local device or personal accounts, and arrange to get copies before they leave.
- Determine what needs to be reassigned: email forwarding for client-facing roles, ownership of shared documents, admin responsibilities on any platform.
- Decide who takes over day-to-day tasks and make sure that person has appropriate access before the transition, not after.
This preparation step matters most for roles with broad access: office managers, anyone with admin rights on your systems, and anyone who has been with the business long enough to accumulate access to things nobody remembers granting them.
On the Last Day: The Core Checklist
This is the part that should happen the same day employment ends, not the following week. Every item here closes a specific door.
- Disable the employee’s email account. Disable, don’t delete immediately, in case messages need to be reviewed or forwarded during a transition period.
- Revoke or reset multi-factor authentication methods tied to the employee’s phone or authenticator app, so a disabled account can’t be recovered using a device they still own.
- Remove the employee from all group memberships, shared mailboxes, and distribution lists.
- Disable or delete the employee’s user account across every business application: accounting software, CRM, project management tools, industry-specific platforms.
- Revoke VPN and remote access credentials.
- Change any shared passwords the employee knew: shared social media logins, shared vendor portal accounts, shared admin credentials on any system.
- Remove the employee’s devices from mobile device management and, if the device belongs to the company, remote wipe it once data has been backed up if needed.
- Collect all company-owned hardware: laptop, phone, tablet, security badges, keys, USB drives.
- Remove the employee from any cloud storage sharing permissions on individual files or folders they had access to outside their main account.
- Update or remove the employee’s name from voicemail greetings, email signatures templates, and any published staff directories.
Personal devices that were ever used to check company email or access company files, even briefly, may still have cached data on them under a bring-your-own-device policy. If your business allows personal devices to access company email, part of offboarding should include confirming company data is removed from any personal device the employee used, not just company-owned hardware.
After the Last Day: Cleanup and Verification
- Confirm no login attempts have occurred on the disabled account.
- Verify email forwarding, if set up, is working correctly and going to the right person.
- Reassign or archive any files, projects, or ownership roles that were still pending transfer.
- Confirm the account has actually been disabled everywhere it needed to be, not just in the primary email system. It is common for an account to be disabled in Microsoft 365 but still active in a separate line-of-business application that wasn’t part of the initial checklist.
- Fully remove or archive the account per your data retention policy, rather than leaving it disabled indefinitely.
- Confirm the license associated with the account has been reassigned or removed to avoid paying for unused seats.
- Review whether any shared passwords changed during offboarding need a second rotation, particularly for highly sensitive systems like banking or payroll.
What This Looks Like When It’s Skipped
In IT assessments for new clients, finding active credentials belonging to a long-departed employee is one of the most common things we come across. Sometimes it’s an email account still receiving messages. Sometimes it’s a shared password for a vendor portal that hasn’t changed in years, known by everyone who has ever worked there, current or not. Sometimes it’s remote access that was set up for a specific project and simply never turned off once the person left.
None of this usually gets discovered because of an incident. It gets discovered during a security review or a new IT provider’s initial assessment, at which point the business realizes how long the gap has existed and how many people, current and former, have technically had a way into their systems the whole time.
Making This Repeatable
The businesses that handle offboarding well aren’t relying on someone’s memory each time an employee leaves. They have a written checklist, ideally shared between HR and IT, that gets pulled out and followed the same way every time, regardless of whether the departure was a retirement, a resignation, or a termination.
A few practices that make this sustainable over time:
Keep an access inventory that stays current. Knowing what an employee has access to is only possible if that information is tracked as access gets granted, not reconstructed after the fact when someone leaves. A simple running document of who has access to what goes a long way.
Avoid shared logins wherever possible. Every shared password is a password every departing employee still knows. Individual accounts with role-based permissions, even for lower-cost tools, remove the need to change a shared password every time someone leaves.
Treat every departure the same way. It’s tempting to move faster or slower on offboarding depending on how the departure felt. A checklist that runs consistently regardless of circumstances is the only version that reliably closes every gap, every time.
A Checklist Is Only as Good as Its Consistency
Employee offboarding isn’t a complicated technical problem. It’s a discipline problem. The steps are all straightforward: disable, revoke, collect, verify. The businesses that get burned by this aren’t missing the knowledge of what to do. They’re missing a system that makes sure it happens every time, on the actual last day, without depending on any one person remembering to do it.
Not Sure Who Still Has Access to Your Systems?
We’ll review your current accounts, find any stale access from former employees, and help you put a repeatable offboarding process in place. No pressure, no judgment, just a clear picture of where things stand.
Serving Jacksonville, St. Augustine, Green Cove Springs, and surrounding Northeast Florida.