Guide

How to off-board an employee in Microsoft 365 without losing data

Off-boarding done badly leaves an ex-employee with live access, or destroys files nobody knew they owned. The order matters: cut access first, preserve data second, reclaim the licence last.

What you'll see

  • Someone is leaving today and nobody is sure what they had access to
  • A former employee's mailbox is still receiving customer email
  • You are paying for licences belonging to people who left months ago

The procedure

Step by step

  1. Step 01

    Block sign-in and revoke sessions

    In the Microsoft 365 admin centre, open the user and set Block sign-in, then revoke their sessions. Blocking alone leaves existing refresh tokens valid for a period, so the revoke is the step that actually ends access on their devices.

  2. Step 02

    Reset the password and remove MFA methods

    Reset the password to a value nobody knows and clear the registered authentication methods. This closes off any self-service password reset route back into the account.

  3. Step 03

    Set up mail flow for their address

    Either delegate the mailbox to a colleague or add a forwarding rule to the person taking over their work, and add an automatic reply if customers write to them directly. Decide this before you convert anything.

  4. Step 04

    Preserve OneDrive and reassign ownership

    Before deleting the account, transfer OneDrive ownership to a manager and reassign ownership of any Teams, SharePoint sites, Power Automate flows or shared calendars they created. Orphaned flows failing silently three weeks later is the classic aftermath of a rushed off-board.

  5. Step 05

    Convert the mailbox to shared and remove the licence

    Convert the user mailbox to a shared mailbox, which keeps up to 50 GB of mail accessible without a paid licence, then remove the licence to stop the billing. Do this in that order; removing the licence first starts a 30-day deletion clock on the data.

  6. Step 06

    Clean up everything outside Microsoft 365

    Remove them from your other SaaS tools, password manager, VPN, code repositories and any shared external accounts. Wipe or retire their managed device through Intune. Record the date each item was completed.

When to stop and escalate

Escalate if the departure is contentious, if the person had administrative privileges, or if you suspect data was copied before they left. Preserve evidence and place a legal hold before making changes — some of the steps above are destructive.

How AlwaysOnIT handles it

AlwaysOnIT can run the whole sequence from a single chat request, in the safe order, with an admin approval prompt before each destructive step and a full record of what was changed.

More walkthroughs in the guides index, terminology in the glossary.

Get started

Open a chat. The AI picks up before the second ring — every time.

No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.