Back to blog
CompliancePublished on September 17, 20268 min read

Offboarding an Employee: Securing Access in Practice

Revoke access, wipe the device, transfer data: the complete procedure to offboard an employee without leaving a door open.

An employee's departure is the weak link in many organisations. Too often, accounts stay active for months after they leave, devices never come back, and sensitive data walks out with the employee on a phone or personal cloud. The problem is rarely bad intent; it is the absence of a clear, repeatable process that anyone can follow under time pressure. A clear, fast offboarding procedure closes these doors immediately, protects the company and meets a direct requirement of NIS2 and GDPR.

Cut access without delay

Speed is the key factor. Every hour an access stays open after departure is a risk, especially in a contentious separation. These actions must be carried out on the same day, ideally at the time the departure takes effect.

  • Disable the account and reset the password on the departure day itself.
  • Revoke active sessions and authentication tokens to cut access immediately on all devices.
  • Remove the account from all groups, then reclaim licenses after data transfer.
  • Check delegated access, shared mailboxes and third-party apps connected to the account.

An often-overlooked point: disabling the account is not enough if sessions stay active. An employee still signed in on their phone can keep reaching email until their tokens are revoked. Revoking sessions is therefore the action that actually cuts access, immediately and on every device.

Handle the device and the data

Once the identity is neutralised, you still need to handle the hardware and the data it holds, without losing information useful to the company for continuity.

  • Remotely wipe the device via Intune: full wipe for a corporate device, selective wipe for a personal BYOD device.
  • Transfer OneDrive files and mailbox content to the manager before any deletion.
  • Convert the mailbox to a shared mailbox if needed to ensure service continuity.
  • Physically recover or block the device if it belongs to the company.

Order matters: transfer the data before wiping, never the other way around. Reclaiming licenses or wiping a device too early can lose files the company still needs. The selective wipe, reserved for BYOD, removes only corporate data while leaving the employee's personal data intact, respecting both security and privacy.

Track and document

  • Keep a timestamped log of departure actions for compliance and audit purposes.
  • Verify after a few days that no residual access remains on the account or devices.
  • Use the onboarding documentation so no access granted over time is forgotten.
Revoke identity, wipe the device, transfer the data: in that order.

The step-by-step procedure

To forget nothing on the day, it helps to run offboarding as a single sequence, each action following logically from the previous one.

  1. 1Disable the account and reset the password at the time of departure.
  2. 2Revoke all sessions and tokens to cut access on every device.
  3. 3Transfer OneDrive and mailbox to the designated manager.
  4. 4Trigger the appropriate device wipe via Intune, full or selective.
  5. 5Record every action in a timestamped log and verify no residual access remains.

A worked example

A developer leaves the company on a Friday at 5 pm. At exactly 5 pm, his account is disabled and his sessions revoked: his phone immediately loses access to email. His OneDrive files and mailbox were transferred to his manager that morning, and his mailbox was converted to a shared mailbox for continuity. His returned corporate laptop undergoes a full wipe via Intune. Each step is timestamped in a log. A few days later, a check confirms no residual access remains. No door was left open.

Common mistakes to avoid

  • Handling offboarding several days after departure, in the window where incidents occur.
  • Disabling the account without revoking active sessions, leaving access open on devices.
  • Wiping a device or reclaiming a license before transferring the data.
  • Forgetting delegated access, shared mailboxes and connected third-party apps.
  • Keeping no record of the actions taken, which is a problem during an audit.

The most common mistake is treating offboarding as an administrative formality handled several days after departure. Yet it is precisely in that window that incidents occur: data exfiltration, access to still-connected apps, or the loss of an unwiped device. Discipline and speed are worth far more than a sophisticated tool used poorly, and a written procedure everyone follows beats improvised action every time.

The special case of a contentious departure

Not all departures are alike. A dismissal or a tense resignation calls for heightened rigour: cutting access must precede, or exactly accompany, the announcement to the employee. If access is cut too late, the window between the announcement and the revocation is the moment of greatest risk, when file exfiltration or deliberate data deletion can occur.

Coordinating HR, management and IT

A safe offboarding assumes that human resources, management and whoever handles IT act in a coordinated way, to the minute. A written, shared procedure avoids misunderstandings: everyone knows who cuts what, and when, without depending on an informal last-minute exchange that is easy to forget under pressure.

Preparing before the day itself

Data transfer, mailbox conversion and wipe preparation can often be anticipated, so that the departure day comes down to a few quick cut-off actions. This preparation reduces stress and the risk of oversight, and ensures service continuity is preserved without any rush or improvisation.

How AuPoint helps

AuPoint simplifies device wipe and compliance checks through Intune, without PowerShell. You trigger a wipe in a few clicks, confirm at a glance that no non-compliant device still reaches company data, and keep a clear record of every action for your audits.

  1. 1Trigger the appropriate device wipe in a few clicks.
  2. 2Confirm no non-compliant device still reaches company data.
  3. 3Combine identity revocation and device management in a single interface.
  4. 4Keep a documented record of every action for your audits.
Speed and documentation beat a complex tool used poorly.

FAQ

Is disabling the account enough at departure?

No. As long as active sessions and tokens are not revoked, an already-connected device can keep reaching resources. Revoking sessions is the step that actually cuts access, immediately and everywhere.

What is the difference between full and selective wipe?

A full wipe entirely resets a corporate device. A selective wipe, reserved for BYOD, removes only corporate data while preserving the employee's personal data, reconciling security with privacy.

Why keep a log of departure actions?

Because it is the evidence, required by NIS2 and GDPR, that access was cut and data handled correctly. In an audit or dispute, this timestamped log demonstrates the procedure was followed.

By combining identity revocation and device management in a single interface, you avoid the classic oversights of an offboarding done by hand across several consoles. Fast, complete and documented offboarding thus becomes a simple reflex rather than a source of risk for your organisation. With AuPoint, every departure ends with closed doors and a clear record, aligned with ISO 27001, NIS2 and GDPR.

Secure your tenant in 15 minutes

Free trial