Why this matters
Former staff who still have access are a real security risk, whether through misuse or because their unused accounts are taken over by attackers. A structured offboarding closes every door on the right day.
What you'll need
- The leaving date
- A list of systems the person used
- Admin access or your IT provider
Step-by-step instructions
Step 1
Plan the timing
Agree with the manager when access should end, usually at the end of the final day, or immediately for unplanned departures.
Step 2
Disable the main account
Block sign-in for Microsoft 365 or Google Workspace, reset the password and sign out all sessions.
Step 3
Preserve email and files
Convert the mailbox to a shared mailbox or delegate it to a manager, and move important files to a shared location.
Step 4
Remove access to other systems
Work through your asset register and remove access to accounting, CRM, VPN, Wi-Fi, building access and social media accounts.
Step 5
Rotate shared passwords
Change any shared passwords or alarm codes the person knew, such as Wi-Fi, admin accounts or supplier portals.
Step 6
Collect and wipe devices
Collect laptops, phones, keys and security tokens. Back up anything needed, then wipe devices before reissuing.
Step 7
Record completion
Note what was done and when in your offboarding checklist for your records.
Summary
A consistent offboarding process protects business data and makes sure nobody keeps access they should not have.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.