Skip to the main content.

6 min read

How to Offboard an Employee Without Leaving Your Business Exposed

How to Offboard an Employee Without Leaving Your Business Exposed
10:29

When an employee leaves your business, the HR side gets handled: final paycheck, badge returned, maybe an exit interview. What often doesn't get handled — or gets handled incompletely — is IT.

Every account that employee had access to is still active. Their email still receives messages. Their VPN credentials still work. If they knew any shared passwords, those still work too. Until someone deliberately closes each of those doors, they're open.

This isn't a hypothetical risk. It's the most common access control problem we find when auditing new clients' environments — and we covered it specifically in the context of manufacturing here.

Good IT offboarding closes those doors systematically, the same way every time, starting on the employee's last day — not eventually.

What a Complete IT Offboarding Covers

When an employee leaves — voluntarily or not — your IT partner should be working through a checklist that covers every access point that person had.

Account deactivation is first and non-negotiable. Disabling their Active Directory account, revoking Microsoft 365 access, deactivating their email, removing them from shared mailboxes and distribution lists. This should happen on their last day, not when someone gets around to it.

If your business runs on Google Workspace instead of — or alongside — Microsoft 365, the checklist looks similar but has a few Google-specific details worth calling out. Gmail deactivation, removal from Google Groups and Shared Drives, and — critically — transferring Google Drive file ownership before the account is deleted. Google doesn't recover data from a deleted account, so the order of operations matters.

Application access is where things get missed most often. Every piece of software the employee used — your ERP, your accounting platform, your project management tools, your industry-specific software — needs to be reviewed and access removed.

AI tools are an increasingly common gap — Microsoft Copilot, ChatGPT for Teams, Claude, or any other company-subscribed AI platform. These tools often retain conversation history that includes sensitive business context, and per-user licenses don't cancel themselves. If your business uses AI tools, they belong on the offboarding checklist the same as any other application. A managed IT partner who knows your environment knows which applications each role uses. A pay-by-the-hour technician guessing at the list will miss things.

VPN and remote access need to be revoked immediately. Remote access credentials that stay active after termination are a significant exposure — particularly for employees who had administrative or elevated permissions.

Cloud services — SharePoint, OneDrive, shared drives, any SaaS platforms — need access removed and file ownership transferred before the account is deleted. Deleting the account first and losing the data is a common mistake.

Shared credentials the employee may have known — shared email accounts, shared service logins, any passwords they had access to — should be rotated. This is one of the strongest arguments for not sharing credentials in the first place, but when it happens, offboarding is the time to clean it up.

MFA devices associated with the employee's accounts need to be removed so that access can't be recovered through their personal phone after they've left.

Email forwarding or archiving depending on the role — a sales employee's email may need to be forwarded to their replacement; a finance or legal employee's account may need to be preserved for compliance before it's closed.

Done right, all of this happens through a single request to your IT partner, who works through the checklist on your behalf.

A Note on Mac Offboarding

If your business uses Macs — exclusively or alongside Windows machines — there are a few Apple-specific items that regularly get missed.

Apple ID and iCloud. If the employee signed into a company Mac with their personal Apple ID, that account needs to be signed out before the device is returned. A personal Apple ID left on a business machine can activate Apple's Find My lock, making the device difficult or impossible to wipe and redeploy without the employee's cooperation.

FileVault. If FileVault disk encryption is enabled — and it should be — the recovery key needs to be rotated after the employee leaves. A former employee who still knows the recovery key has a potential path back to data on that machine.

MDM and Apple Business Manager. If your Macs are enrolled in device management, the device needs to be properly removed from the departing user's profile in your MDM platform before being wiped and reassigned — not just reset at the OS level.

Getting Mac offboarding right requires knowing how Apple's ecosystem works alongside your broader IT environment. It's one of the reasons TotalCare IT offers dedicated Mac management as part of our managed IT services.

Remote Employee Offboarding

Remote employees introduce a few complications that in-office offboarding doesn't have to deal with.

Device retrieval. You can't just collect a laptop at the end of the day. A clear process for returning equipment needs to be established before someone's last day — whether that's a prepaid shipping label, a local drop-off arrangement, or a technician visit. Don't rely on a departing employee to figure out how to get the device back to you on their own timeline.

Home network access. Remote employees often have VPN credentials, remote desktop access, or both. These need to be revoked immediately on their last day — not after the device is returned. The two steps are independent of each other.

Company data on personal devices. If the employee ever accessed company email or files on a personal phone or laptop — which is common for remote workers — those sessions need to be remotely wiped or signed out through your MDM or Microsoft 365 admin tools. You can't physically retrieve a personal device, but you can revoke its access to company data.

The core principle is the same as in-office offboarding: access ends on the last day, regardless of where the device is or whether it's been returned yet.

Seasonal Offboarding: Tax Firms and Law Offices

Seasonal hiring adds a planning layer that makes IT offboarding both more predictable and — if it isn't managed — more likely to leave lingering access problems.

Tax accounting firms bring on additional staff every January and offboard them in April or May. Law offices add clerks, paralegals, and summer associates who roll off at the end of a season or a case. These aren't unexpected departures — they're scheduled, which means offboarding can be planned in advance.

The risk with seasonal staff is that because their departure is expected, it sometimes gets treated as routine and corners get cut. Access gets removed for the obvious accounts and the rest gets left. Those credentials sit dormant for eight months and become exactly the kind of stale access that shows up in a breach investigation.

A few things that make seasonal offboarding work well:

Provision access correctly at the start. Seasonal hires should only have the access their role requires — nothing extra because it was easier to set up. Limited access at onboarding means a shorter, cleaner offboarding checklist at the end.

Process bulk offboarding as a single coordinated request. If ten tax preparers are finishing the same week, your IT partner should handle all ten at once — not ten separate tickets trickling in over three weeks.

Wipe and store devices for next season. If seasonal staff use company equipment, those devices should be wiped and stored so they're clean and ready for the next hire cycle. More on equipment below.

Document who had what. A clean record of which accounts and applications each seasonal employee accessed makes the next offboarding cycle faster and reduces the chance of something being missed.

What to Do with Equipment After Offboarding

Once accounts are closed and access is revoked, there's still the question of what happens to the device. There are three paths, and the right one depends on the situation.

Wipe and redeploy. If the equipment is recent enough to be useful and another hire is coming, wiping the device and redeploying it is the most cost-effective option. Your IT partner should handle the wipe — a standard factory reset isn't always sufficient to fully clear sensitive business data. Once wiped, the device is ready to provision for the next employee.

Store it. If the next hire isn't immediate, devices can be stored — either at your facility or with your IT provider. Storing with your IT provider means devices are maintained, tracked, and ready to provision on demand without taking up space on your end. For seasonal businesses that need a fleet of devices ready every January, this is often the cleanest option.

Recycle it. For equipment that's too old to redeploy, responsible disposal is the right call. That means certified data destruction before the device leaves your hands, and recycling through a proper e-waste program. We cover how to dispose of business equipment properly here.

Whatever path you choose, no device should ever leave your business with data still on it.

The Offboarding-Onboarding Loop

Good IT offboarding isn't just about security — it's about being ready for the next hire. A wiped, stored device. A documented list of which accounts existed. A clean environment with no leftover access. When a new employee starts, your IT partner can provision them quickly and correctly because the previous employee's setup was fully closed out.

That's how onboarding becomes a single request instead of a project — and why the two processes are really one loop. We cover what good IT onboarding looks like for manufacturers and professional services firms here.

If your offboarding process currently relies on someone remembering to call IT at some point, or hoping the departing employee returns their device without being chased, that's a gap worth closing. Contact TotalCare IT to talk about what a consistent offboarding checklist looks like for your business.