A longtime employee puts in their two weeks. You’re focused on transition: redistributing their workload, finding a replacement, making sure clients are notified. There’s a lot to manage, and IT is rarely the first thing on anyone’s mind during an offboarding.
But while you’re handling the people side of things, there’s a separate set of risks quietly building. Who still has access to your systems? Has their email been turned off? Can they still log into your cloud apps from home?
At Sirius, we see the fallout from incomplete offboarding more than most people expect. The risks are real, and they’re not limited to disgruntled employees. Even the most amicable departures can leave security gaps that persist for months if no one takes ownership of the process.
The Real Risk of a Poor Offboarding Process
When an employee leaves your business, they take something with them: knowledge of your systems, your passwords (if they were ever shared), and potentially access to your data through accounts that were never deactivated.
Here’s what that actually looks like in practice:
- A former sales rep who can still log into your CRM and download client contact lists
- An ex-employee who has a copy of shared credentials for a cloud platform your team uses daily
- A manager who left with full admin rights to your Microsoft 365 environment still intact
- A contractor whose VPN credentials were never revoked
These aren’t edge cases. They’re the norm for businesses that don’t have a formal IT offboarding process. And the consequences can range from minor (an old account sitting idle) to serious (data theft, account compromise, or even sabotage).
What Should Happen on the Day Someone Leaves
Offboarding from an IT perspective needs to happen fast, ideally on the same day the employee’s last day is confirmed. The longer you wait, the longer the exposure window stays open.
Immediate Steps (Day of Departure)
- Disable or suspend the account in your directory service (Active Directory, Azure AD, Google Workspace) before the employee finishes their last shift
- Revoke access to email and forward or archive their mailbox according to your data retention policy
- Sign out active sessions across all cloud apps so any existing login tokens are invalidated
- Remove MFA devices registered to their account, including authenticator apps and phone numbers
- Change any shared passwords the employee had access to, including Wi-Fi, shared application logins, and admin accounts
- Recover company-issued devices and confirm they are wiped or re-imaged before being reused
Within the First Week
- Review and reassign any third-party app permissions tied to the employee’s account
- Remove them from any distribution groups, shared calendars, or team channels
- Audit their file access history for anything unusual in the days leading up to departure
- Confirm their access has been removed from all cloud platforms, not just the primary directory
Use this as a starting point for every employee departure, planned or unexpected.
| Task | Timing | Owner |
|---|---|---|
| Disable account in Active Directory, Azure AD, or Google Workspace | Day of departure | IT |
| Revoke email access and archive or forward mailbox | Day of departure | IT |
| Force sign-out of all active Microsoft 365 and cloud app sessions | Day of departure | IT |
| Remove registered MFA devices (authenticator app, phone number) | Day of departure | IT |
| Change all shared passwords the employee had access to | Day of departure | IT / Manager |
| Recover and wipe all company-issued devices | Day of departure | IT / HR |
| Audit and remove third-party app permissions tied to their account | Within 1 week | IT |
| Remove from distribution groups, Teams channels, and shared calendars | Within 1 week | IT |
| Review file access logs for unusual activity or bulk downloads in final 30 days | Within 1 week | IT |
| 30-day access audit: confirm no lingering access in any system | Day 30 | IT |
Where Businesses Get This Wrong
The most common failure mode we see is relying on a manual, informal process. A manager emails IT to say someone is leaving. IT disables the main account. But no one checks the dozen other systems the employee had access to, and nobody audited whether they downloaded anything in their final days.
Common gaps that get missed:
- Shadow accounts: Employees often create their own accounts in apps the IT team doesn’t know about (project management tools, file-sharing services, etc.)
- Personal device access: If employees used personal phones for email or business apps, those devices still have cached credentials that may not be wiped by a remote account disable
- Shared logins: Teams that share login credentials (a common workaround in smaller businesses) can’t simply disable one account without affecting the whole team
- Contractor and vendor access: External workers are frequently forgotten in offboarding checklists because they’re not in the regular HR workflow
The solution to most of these problems is a proper identity and access management (IAM) framework, which is something our managed IT services clients have built into their environment from the start.
What Happens When Offboarding Is Rushed or Skipped
The scenarios aren’t always dramatic, but they can be costly.
Data exfiltration before departure
A departing employee who knows they’re leaving has time to prepare. In some cases, that means downloading customer lists, project files, financial data, or proprietary information before their last day. Without endpoint monitoring and file access auditing, you may not even know it happened until months later when a competitor shows up with your client list.
Account takeover after departure
Dormant accounts that are never deactivated are an easy target. If an attacker compromises a former employee’s credentials (through a data breach or credential stuffing), they can use those accounts to access your systems. Because the account belongs to someone who no longer works for you, there’s no one internally who would notice unusual activity.
Insider threat (even unintentional)
Not every risk is malicious. A former employee who genuinely forgets they still have access and logs in to grab an old file can trigger compliance issues or data exposure, depending on what they access. Honest mistakes still carry consequences.
Building an Offboarding Process That Actually Works
The goal is a documented, repeatable checklist that HR and IT both follow every time someone leaves, regardless of the circumstances. This isn’t just good IT practice. For businesses in regulated industries, it may be a compliance requirement.
A solid offboarding process should include:
- A shared checklist that HR triggers when an employee’s end date is set
- Clear ownership for each step (who disables the account, who handles devices, who audits access)
- A system of record for when each step was completed and by whom
- An access audit at the 30-day mark to catch anything that was missed
If your business doesn’t have this today, it’s worth building. We can help you create the framework and, more importantly, make sure it’s backed by the right technical controls so that deactivating an account in one place actually removes access everywhere.
The Broader Picture: Access Management as an Ongoing Practice
Offboarding is actually a subset of a larger discipline called access management. The principle behind it is simple: employees should only have access to what they need for their current role, and that access should be reviewed and adjusted as their role changes.
That means:
- New hires are provisioned with the minimum access needed to do their job (least-privilege principle)
- Access levels are reviewed when employees are promoted, change teams, or take on new responsibilities
- Access is revoked promptly when someone leaves, changes roles, or no longer needs a system
Businesses in the Phoenix metro area that have implemented structured access management with our team find that offboarding becomes much less stressful because the framework is already in place. There’s no scrambling on someone’s last day because the process is clear and the tools are already doing most of the work.
If you’re running Microsoft 365, there are built-in tools for managing this centrally, including conditional access policies, automated offboarding workflows, and audit logs that track everything. Most businesses we talk to aren’t using these tools to their full potential.
Your Next Step
If someone left your company in the last 90 days, it’s worth asking: are we confident all of their access has been removed? If you can’t answer that with certainty, that’s a starting point for a conversation.
At Sirius, our cybersecurity team can run an access audit to identify dormant accounts, overprivileged users, and gaps in your current offboarding process. We’ll give you a clear picture of what’s active in your environment and help you build a process that protects your business going forward.
Contact us to schedule a free access audit for your business. It’s a straightforward review that can surface real risk, and it’s a lot easier to address it now than after something goes wrong.
We work with businesses throughout Scottsdale, Glendale, and the greater Phoenix area. Let’s make sure your offboarding process is protecting your business the way it should.

