OffboardingIT-beheerKMO

An employee leaves: the IT offboarding checklist most SMEs forget

Accounts that stay active for months, shared passwords that never change, data on private devices. A departure is a security risk when there is no list. This is that list: before, on and after the last day, plus what you set up in advance so it runs smoothly.

Ian

Ian

Co-Founder & CEO

21 September 20265 min read
Illustration of a badge and a checklist, offboarding theme

An employee leaves. There is a farewell drink, the laptop is handed in and everyone gets back to work. Months later it turns out their Microsoft 365 account is still active, they are still in the shared Dropbox and the social media password was never changed. We come across this at almost every new client, and it is rarely bad intent. There simply was no list. Below is that list, split into before, on and after the last day.

Why offboarding is a security risk

In an SME of fifteen people there is rarely an HR department watching over the process. The owner handles what they remember, and the rest lingers. For a long time.

  • Accounts that stay active for months are an open door. Usually the former employee is not the problem, but the attacker who finds their old password on a leaked list and hits an account nobody is watching anymore.
  • Shared passwords, from the wifi to supplier portals, are by definition known outside the company after a departure.
  • Data on private devices: email on a personal phone, files in a personal Dropbox, customer lists once forwarded to a private address. You have no visibility and no control over it.
  • Licences that keep running cost money, and a mailbox nobody reads leaves customers unanswered.

The checklist

Print it or put it in your task list. Not every item applies to every company, but go through all of them deliberately.

Before the last day

  1. Together, make a list of all access: accounts, tools, portals, customer environments, keys and badges. Ask explicitly, because most people forget half.
  2. Arrange the handover of data: files from OneDrive or the personal folder to a shared location, open files to a colleague.
  3. Agree who follows up the mailbox and prepare an automatic reply with the new contact person.
  4. Decide what happens to the phone and the number, especially if customers know that number.

On the last day

  1. Block the accounts instead of deleting them, in Microsoft 365 or Google Workspace, and end all active sessions. Deleting comes later, blocking happens now.
  2. Unlink the MFA devices and the authenticator app, so a recovery code does not end up with the former employee.
  3. Collect the laptop, phone, badges and keys, and note what you received.
  4. Change the passwords of shared accounts: wifi, shared mailboxes, admin logins, printer and camera management.
  5. Revoke access to the bank, accounting, social media, webshop and every SaaS tool that does not run through your central login. Do not forget the supplier portals.

After the last day

  1. Convert the mailbox to a shared mailbox and give the successor access, with an agreed end date.
  2. Release the licences, so you do not keep paying for them.
  3. Wipe the laptop completely and reinstall it before handing it to someone else.
  4. Delete the account permanently after the agreed period, a few months is usually more than enough, and note that it was done.

One more note on that mailbox. Under the GDPR, a personal mailbox is not something you keep open and read indefinitely. Agree on a short period, tell the former employee what will happen, and then let the automatic reply do the work. We do not give legal advice, but the practical rule is simple: the shorter you keep the mailbox open, the less discussion.

When the departure is not on good terms

In case of a dismissal or a conflict, the order changes. You prepare everything quietly and run the entire 'last day' list while the conversation takes place, not afterwards.

  • Ask your IT partner in advance to prepare the list of access, without the employee noticing.
  • Block the accounts and sessions during the conversation. An angry former employee with another hour of access can do a lot of damage.
  • In the days after, check for login attempts on the blocked accounts, and look at whether unusually large amounts of data were downloaded or forwarded in the last weeks.

What you set up in advance so it runs smoothly

The checklist above takes half a day if you are well prepared, and a week full of surprises if you are not. Three things make the difference.

  • An inventory of accounts per person. A simple table: who has access to what. Add to it when someone starts, and it is ready when someone leaves.
  • One central login (SSO). If your tools sign in through Microsoft 365 or Google, blocking one account instantly blocks dozens of accesses.
  • A password manager with shared vaults. Shared passwords then sit in a vault where you revoke access per person, instead of in an Excel everyone has. Why that is no longer a luxury is covered in A password manager for your team.

Do the same when onboarding: whoever is given access properly can also be disconnected properly.

Want offboarding, onboarding and the inventory of access to simply be taken care of, without having to think about it yourself? That is exactly what an IT partner for your SME does. Book a call and we will look together at how you handle it today.