Checklist

Employee offboarding in Microsoft 365, in the right order

Five checks before anyone blocks sign-in, removes a licence or deletes the account. Most offboarding damage is not a missed step, it is the right steps run in the wrong order.

Before removing a leaver's Microsoft 365 licence, run five checks: the mailbox outcome is decided, the OneDrive files are preserved, sign-in is blocked and sessions are revoked, ownership is handed over, and all of it is recorded. Licence removal and deletion close doors that were open a minute earlier, which is why the order matters more than the individual steps.

This is the short version of the process our free one-page Risk Gate and the full offboarding kit walk through. It is written to be usable on its own, whether or not you ever buy anything.

If somebody has already left

This checklist is for doing it properly next time. When the question is whether a person who left months ago can still get in, that is former employee access, and the order of the steps changes.

The five checks, in order

Work through these before anything is removed or deleted. Each one is quick while the account still exists, and slow or impossible after it does not.

  • Decide the mailbox outcome while the licence is still assigned. If the mailbox is becoming a shared mailbox, Microsoft's conversion process expects the user mailbox to still be licensed when you convert it, and after conversion an unlicensed shared mailbox is limited to 50 GB. An archive or a legal hold still needs Exchange licensing. Remove the licence first and you are recovering options instead of choosing between them.
  • Preserve the OneDrive files before the account goes. A leaver's OneDrive belongs to the account, not the business. Grant a manager access or move what matters into a shared library the business owns before deletion, because once the account's retention window runs out the files are permanently deleted.
  • Block sign-in, then revoke sessions. They are two separate actions. Blocking sign-in stops new sign-ins; it does not end the sessions and tokens that already exist, so revoking sessions is its own step. Even then, Microsoft notes that token and application behaviour can delay how quickly revocation takes effect, so verify by checking sign-in activity rather than assuming an instant universal logout.
  • Hand over what the person owned, not just what they used. Calendars, shared mailbox access, Teams and group ownership, Power Automate flows and other automations, and every vendor or SaaS login that lives outside Microsoft 365 entirely. An automation owned by a disabled account is the classic quiet failure: nothing breaks on day one, then an invoice reminder or a report simply stops.
  • Record what was done, by whom, and when. The approver, the cutoff time, and what happened to the mailbox, the files, the licences and the devices. If a dispute, an audit or an insurance question turns up months later, the evidence log is the difference between an answer and a shrug.

Why the order matters

The individual actions in an offboarding are simple. The damage comes from sequencing. Removing the licence feels like the natural first step because it is the one that saves money, and it is exactly the step that complicates the mailbox decision and puts the data on a countdown.

So the safe order is: decide and hand over first, cut access second, remove licences and delete last. If the identity source, a legal hold, privileged access or data ownership is genuinely unknown, the right move is to pause the destructive steps until someone authorized has answered, not to press on. Blocking sign-in is reversible; deletion after the retention window is not.

Take it with you

The checklist as a working document

Both of these are ours. The Risk Gate is free, and the kit is the complete system this page is drawn from.

Microsoft 365 Employee Offboarding Risk Gate

A free one-page gate: five questions to answer before blocking sign-in, removing a licence, converting a mailbox or deleting a user, with a stop rule for the cases where the right move is to pause.

  • Printable one-page PDF
  • Covers authority, identity source, legal holds, privileged access and data ownership
  • Free, delivered through Gumroad

Microsoft 365 Employee Offboarding Kit

The complete working system: secure access, preserve data, transfer ownership and close the exit with evidence, as a repeatable process rather than a memory exercise.

  • 10-page editable runbook plus printable PDF
  • Excel control workbook: dashboard, 30-step checklist, evidence register and manager intake
  • Communication templates and guarded PowerShell examples
  • $59, or $39 for the first 10 buyers with code FOUNDING10

Who this is for

  • Owners and office managers handling an employee exit this week
  • IT generalists who inherited offboarding along with everything else
  • Businesses replacing an informal HR checklist, email thread or memory-based process
  • Teams that want a recorded, repeatable exit rather than a one-off scramble

When this is not the right fit

  • Anyone looking for one-click automated deletion. This is a decision process, not a script that does it for you.
  • Legal, HR, compliance or security advice. The checklist tells you what to decide, not what your obligations are.
  • Complex hybrid identity or regulated retention without qualified internal review.
  • An active security incident or account takeover. That is emergency response, not offboarding.

What Tech True Point can help with

The checklist is genuinely usable on your own. Where businesses ask for help is the tenant they inherited, the leaver from two years ago nobody fully removed, and the automations no one can name an owner for.

Common questions

Can we just delete the account and be done?

Deletion is the last step, not the first. Deleting the account starts retention clocks on the mailbox and the OneDrive files, and once those windows run out the data is permanently gone. It also removes the user object that a converted shared mailbox depends on.

Nothing about deleting first is faster in practice. Every option you would have wanted, converting the mailbox, moving the files, checking what the person owned, is easier while the account still exists.

We already removed the licence. Can the mailbox still become a shared mailbox?

Microsoft's conversion process expects the user mailbox to still be licensed when you convert it. If the licence has already been removed, reassign one, run the conversion, and then review whether the shared mailbox still needs it.

After conversion, an unlicensed shared mailbox is limited to 50 GB. If the mailbox is larger than that, or it has an archive or a legal hold, it still needs Exchange licensing, so the licence saving is sometimes smaller than expected.

Does blocking sign-in log the person out?

No. Blocking sign-in stops new sign-ins. Sessions and tokens that already exist are a separate problem, which is why revoking sessions is its own step and not a side effect of the block.

Even after revocation, Microsoft notes that token and application behaviour can delay how quickly it takes effect everywhere, so verify by checking sign-in activity rather than assuming an instant universal logout.

What is the difference between the free Risk Gate and the paid kit?

The Risk Gate is a free one-page gate: five questions to answer before anyone blocks sign-in, removes a licence, converts a mailbox or deletes a user, with a stop rule for the cases where the right move is to pause. It is genuinely usable on its own.

The kit is the complete working system behind it: a 10-page editable runbook, an Excel control workbook with a 30-step checklist and evidence register, manager intake, communication templates and guarded PowerShell examples. Buy it when you want the repeatable process, not just the gate.

Free download

Start with the free Risk Gate

One printable page: the five questions to answer before anyone changes access, with a stop rule for the cases where the right move is to pause.

Call now Request a quote