When someone leaves a small business, the farewell lunch gets organised. Their access often doesn't get removed.
It's rarely malicious. It's just that nobody owns it. Months later their email still works, the laptop is in a drawer still signed in, and they're still in the shared drive.
Here's the checklist we use. Print it, adapt it, and run it on the person's last day, not "sometime next week".
Before their last day
- Agree the date and time access ends. Usually the end of their final day. For a difficult departure, it might be the moment the conversation happens.
- Find out what they own. Shared mailboxes, social media accounts, supplier portals, domain registrations, anything signed up with their personal email. That last one is the one that bites.
- Plan the handover. Who takes over their email, files and open jobs?
On the day: accounts
- Block sign-in to their work account in Microsoft 365 or Google Workspace. Blocking first, rather than deleting, keeps their mail and files while cutting off access.
- Sign them out of every session. Both Microsoft 365 and Google let an admin revoke active sessions. Without this, a phone that's already signed in can keep syncing.
- Reset their password and remove their MFA methods, so an old authenticator app or phone number can't be used to get back in.
- Forward or delegate their email to their manager, and set an auto-reply pointing people to the right contact.
- Transfer their files. Move ownership of documents and shared drives before the account is eventually deleted, or the files can go with it.
- Remove them from shared mailboxes, groups and distribution lists.
On the day: everything outside email
- Business apps: accounting, CRM, project management, design tools, cloud consoles and code repositories. Each one is a separate account.
- Shared passwords: if they knew the Wi-Fi password, the alarm code or a shared login, change it. A password manager makes this a five-minute job instead of a scavenger hunt.
- Social media and ad accounts: remove their admin access and make sure the business, not the person, owns the account.
- Licences: reassign or cancel their paid seats. These quietly cost money every month.
On the day: devices
- Collect company laptops, phones, keys, cards and tokens.
- For their own phone (BYOD): if your device management is set up for it, remove the work profile. That deletes work data without touching their personal photos.
- For company devices: wipe and re-provision them before handing them to the next person. Don't just create a new user on the old setup.
The week after
- Check sign-in logs for any attempts on the blocked account.
- Keep the mailbox for a while, then delete or archive the account once everything is transferred. Many teams keep it for 30 to 90 days.
- Write down anything you missed and add it to the checklist for next time.
How device management makes this a 10-minute job
Done by hand, offboarding means remembering a dozen systems. With mobile device management (MDM), such as Microsoft Intune, Jamf, Kandji or Google's endpoint management, most of the device side becomes one action:
- Company laptops can be locked or wiped remotely, even if they're never returned.
- Work data on personal phones can be removed without touching personal data.
- New starters get laptops that set themselves up on first sign-in, so the onboarding side gets faster too.
If your current answer to "how long until a leaver loses access?" is "we'd have to check", that's what we fix. Our managed IT plans start at $49 per user per month with no lock-in, and we're happy to do a one-off clean-up of an existing setup at a fixed price.