Why this matters
When someone leaves, their Microsoft 365 account can still access email, files and Teams until it is properly secured. Former employee accounts are a common target because nobody is watching them. A consistent process protects your data and keeps important emails flowing.
What you'll need
- Microsoft 365 admin access
- Manager approval and leaving date
- Who should receive the person’s email and files
Step-by-step instructions
Step 1
Block sign-in
In admin.microsoft.com, go to Users, Active users, select the person and choose "Block sign-in".
Step 2
Reset the password and sign out sessions
Reset the password, then use "Sign out of all sessions" so existing logins on phones and laptops stop working.
Step 3
Remove MFA methods and devices
Remove their registered authentication methods in the Entra admin center, and wipe or retire company devices through Intune if used.
Step 4
Convert the mailbox to a shared mailbox
Under the user’s Mail tab, choose "Convert to shared mailbox" and give the manager access. Optionally set an automatic reply directing people to a new contact.
Step 5
Transfer OneDrive files
Under the OneDrive tab, create a link to their files and give the manager access, or move important files into a SharePoint site.
Step 6
Remove licences and group memberships
Once data is safe, remove licences to stop paying for them and remove the user from groups, Teams and distribution lists.
Step 7
Update other systems
Remove access to accounting software, CRM, line-of-business apps, building access and shared passwords they knew.
Summary
Blocking access first, then preserving email and files, and finally removing licences gives you a secure and tidy offboarding every time.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.