top of page
it support sheffield

IT Support & Strategy

What should happen to Microsoft 365 when an employee leaves?

By Steve Harper  |  8 min read  | Last updated:

7 August 2026 at 14:56:24

Microsoft 365 Employee Offboarding

TL;DR

When an employee leaves, their Microsoft 365 access should be blocked promptly, active sessions revoked and company data preserved before the account or licence is removed.


Email, OneDrive files, Teams ownership, shared documents and automated processes should be transferred to authorised employees. The business should also recover company devices, remove third-party access and document every action.


Deleting the account immediately without checking its data and dependencies can result in lost information and disrupted business processes.


Key Takeaways

  • Coordinate the exact access-removal time with HR or management.

  • Block sign-in and revoke active sessions.

  • Preserve required email and OneDrive data before deletion.

  • Transfer ownership of files, Teams, groups and automated processes.

  • Recover or remotely secure company devices.

  • Review third-party applications and shared credentials.

  • Remove the licence only after its effect on data and services is understood.

  • Keep a documented leaver checklist for every employee.

Would your business know every system an employee can still access after leaving?


IT Desk can manage employee onboarding and offboarding across Microsoft 365, devices and business applications. We help block access promptly, preserve company data, transfer ownership and keep a clear record of every completed action.



Should a former employee’s Microsoft 365 account be deleted immediately?

Usually not.


The employee’s access may need to be blocked immediately, but deleting the account before reviewing its data can create avoidable problems.


The account may contain or control:

  • Business email

  • Customer correspondence

  • OneDrive files

  • Shared calendars

  • Microsoft Teams membership

  • Microsoft 365 groups

  • Forms and survey results

  • Power Automate workflows

  • Shared mailboxes

  • Bookings calendars

  • Power BI content

  • Application registrations

  • Access to third-party services


The correct first step is normally to stop the employee accessing the account. The business can then preserve and transfer the required information before deciding when the account should be deleted.


When should access be removed?

The timing should be agreed between the authorised manager, HR and IT.


For a planned and amicable departure, access may be removed at the employee’s agreed finishing time.


For an immediate dismissal, suspected misconduct or elevated security risk, access may need to be removed at the same time the employee is informed—or immediately beforehand, under the organisation’s authorised process.

IT should receive clear instructions covering:

  • The employee’s identity

  • The exact date and time access must end

  • Who authorises the action

  • Which manager will receive business information

  • Whether devices are being returned

  • Whether email forwarding or an automatic reply is required

  • How long data must be retained


Access should not depend on someone remembering to send an informal message after the employee has already left.


How is a former employee blocked from Microsoft 365?

An authorised Microsoft 365 administrator can block sign-in to prevent the account from accessing organisational services.


A proper access-removal process may also include:

  • Resetting the password

  • Revoking active sign-in sessions

  • Blocking the account

  • Removing registered authentication methods where appropriate

  • Reviewing recent sign-in activity

  • Disabling access from mobile devices

  • Removing the user from security groups

  • Revoking application access

  • Removing remote-access permissions

  • Reviewing mailbox rules and forwarding

  • Checking for delegated access


Blocking the account does not necessarily terminate every existing session immediately unless sessions and tokens are also revoked.


Can a former employee still access Microsoft 365 after their password is changed?

Potentially, if an existing authenticated session remains active.


Microsoft 365 applications use tokens and sessions so users do not need to enter their password every time they open an application. Changing the password alone may not immediately end every authenticated session.


The offboarding process should therefore include revoking sessions and checking:

  • Microsoft 365 web sessions

  • Outlook and Teams access

  • Mobile devices

  • OneDrive synchronisation

  • Remote desktops

  • VPN access

  • Third-party applications

  • Password-manager access

  • Browser sessions on personal devices


The company should also retrieve or remotely secure managed devices.


What happens to the employee’s email?

The business should decide whether the mailbox needs to be preserved and who may access it.


Possible options include:

  • Granting an authorised employee access

  • Converting the mailbox to a shared mailbox

  • Forwarding new messages for a defined period

  • Setting an automatic reply with an alternative contact

  • Preserving the mailbox under a retention or legal-hold requirement

  • Exporting required information where appropriate


Converting a mailbox into a shared mailbox can allow authorised employees to manage ongoing correspondence without continuing to work as the former employee.


However, licensing and retention requirements depend on mailbox size, configuration and the features being used. The business should confirm these before removing the licence.


Microsoft also warns that some forwarding and shared-mailbox arrangements require the associated account to remain as an underlying object. Do not delete it without checking the chosen configuration.


Should email automatically be forwarded to the employee’s manager?

Not automatically in every case.


Forwarding may be helpful for maintaining customer and supplier communication, but it should be authorised and proportionate.


The business should consider:

  • Whether the manager genuinely needs every incoming message

  • Whether the mailbox contains private or sensitive information

  • Legal and HR requirements

  • How long forwarding should continue

  • Whether a shared mailbox is more appropriate

  • Whether an automatic reply can redirect senders instead

  • Who will review and respond to incoming messages


An indefinite forwarding arrangement can create unnecessary access and make the mailbox difficult to retire.


The decision should follow an agreed retention and privacy policy rather than being left to the administrator’s judgement.


What happens to the employee’s OneDrive files?

When a Microsoft 365 user is deleted, their OneDrive enters a retention and deletion process.


Microsoft allows organisations to configure how long a deleted user’s OneDrive is retained. Microsoft’s default configuration may retain it for a limited period, but administrators can configure a different period within supported limits.


Businesses should not rely on the default retention window as their offboarding strategy.


Before the account is deleted:

  • Identify important business files.

  • Give an authorised person temporary access.

  • Move team-owned documents into SharePoint.

  • Review files shared through the employee’s OneDrive.

  • Replace links that may stop working later.

  • Check who owns collaborative documents.

  • Separate personal material from company records appropriately.

  • Confirm required information has been preserved.


Documents that belong to a department, client or project should normally be stored in a team-controlled location rather than left indefinitely in a former employee’s OneDrive.


Will shared OneDrive links stop working?

They may be affected when the user’s account and OneDrive are deleted.


Even if colleagues previously had access to particular files, the content remains connected to the departing employee’s OneDrive.


Important documents should be transferred into an appropriate SharePoint library or another authorised company-owned location. New sharing links may then need to be issued.


This is one reason why ongoing team documents should be placed in SharePoint rather than stored in one employee’s OneDrive.


Our OneDrive versus SharePoint guide explains the ownership distinction. Add this internal link after that Quick Answer page is published.


What happens to Microsoft Teams when an employee leaves?

Removing the user from Microsoft 365 removes their ability to access Teams, but the organisation should check whether they own or manage anything important.


Review:

  • Teams where they are the only owner

  • Microsoft 365 groups

  • Private or shared channels

  • Meeting recordings

  • Shared files

  • Recurring meetings

  • Team-linked SharePoint sites

  • Planner plans

  • Forms

  • Shared calendars

  • External guest access


Each important Team or group should have more than one appropriate owner before the employee leaves.


If the departing employee is the only owner, another authorised user should be assigned so the workspace can continue to be managed.


What happens to Power Automate flows and other automated processes?

Automations can fail when their owner leaves, their licence is removed or their account loses access to a connected service.


A leaver review should look for:

  • Power Automate flows

  • Scheduled reports

  • Power BI workspaces

  • Microsoft Forms

  • Bookings pages

  • Power Apps

  • Shared mailboxes

  • Service credentials

  • Website forms

  • CRM integrations

  • API connections

  • Recurring calendar processes


Ownership and connections should be transferred to an appropriate service account or authorised employee where the platform supports it.


Business-critical automation should not depend entirely on one person’s user account.


What should happen to the employee’s laptop and phone?

Company-owned devices should be returned, recorded and processed securely.


The business may need to:

  • Lock or remotely wipe the device

  • Remove company information from a personally owned device

  • Recover laptops, phones, security keys and access cards

  • Back up authorised business data

  • Remove the device from management systems

  • Inspect its condition

  • Securely reset or rebuild it

  • Update the asset register

  • Prepare it for reassignment or disposal


A device should not be issued to another employee without an approved reset and setup process.


If a company device has not been returned, the business should treat this as both an asset and information-security issue.


What about passwords shared with the former employee?

All shared access should be reviewed.


This may include:

  • Supplier portals

  • Social-media accounts

  • Website administration

  • Wi-Fi credentials

  • Door-entry systems

  • Finance platforms

  • Marketing tools

  • Domain and hosting accounts

  • Shared password vaults

  • Backup systems

  • Remote-support tools


Where individual accounts are available, businesses should use them rather than sharing one password between employees.


If shared credentials were used, change them and review recent activity. Removing the Microsoft 365 account will not automatically remove access to unrelated services.


When can the Microsoft 365 licence be removed?

The licence can generally be removed after the required data and services have been reviewed and preserved.


Removing a licence may affect:

  • Mailbox availability

  • OneDrive access

  • Application activation

  • Retention

  • Security and compliance features

  • Teams functionality

  • Telephone numbers and calling services

  • Device-management capabilities


The business should document what will happen before removing it.


Once it is safe to do so, the licence may be reassigned to another eligible user or removed from the subscription, subject to the applicable licensing arrangement.


How long should a former employee’s data be kept?

There is no single retention period that suits every organisation.


The decision may depend on:

  • Legal obligations

  • Contractual requirements

  • Regulatory rules

  • Limitation periods

  • Employment matters

  • Customer commitments

  • The type and sensitivity of the information

  • Existing company retention policies

  • Ongoing investigations or legal holds


Data should not be kept forever merely because storage is available. Equally, it should not be deleted before the business has confirmed that it is no longer required.


The organisation’s retention policy should define who makes this decision and how it is implemented within Microsoft 365.


What should be included in a Microsoft 365 leaver checklist?

A useful checklist should cover:

  1. Confirm the authorised departure time.

  2. Block sign-in and revoke active sessions.

  3. Secure company devices.

  4. Preserve and transfer required email.

  5. Transfer OneDrive files into company-owned storage.

  6. Assign new owners to Teams, groups and workspaces.

  7. Transfer automated processes and application connections.

  8. Review third-party accounts and shared credentials.

  9. Remove access from groups and external services.

  10. Remove or reassign licences at the correct time.

  11. Delete the account according to the retention policy.

  12. Record who completed and approved each action.


The checklist should be repeatable and used for every employee, including temporary workers, contractors and senior administrators.

Related Insights

So, why IT Desk?

deceleration.png

Proactive & Reactive Support

In 2024, we achieved an average response time of 13 seconds. Most IT support providers respond anywhere between 30 seconds and 1 minute.

Not only this, 99.5% of our feedback we received was rated 4 out of 4, making this one of our best years yet!

trophy.png

Award Winning

Recognised by Three Best Rated as one of the 'Three Best Rated' IT Service Providers in the Rotherham area. Our feedback definitely reflects this!

Acknowledged by Barnsley & Rotherham Chamber of Commerce over the years for Excellence in Customer Service and Commitment to People Development.

certified.png

Experienced & Certified

Awarded the 'Investors in People' certification, which is an industry standard that shows IT Desk as being actively committed to developing and supporting it's employees.

 

From apprentices to managers to solution engineers, our team of people is truly unique - often described by them as a 'family'!

Reliable & Consistent

Founded in Rotherham in 2006, we started out offering IT support to local businesses. Over the years, we've expanded to serve clients throughout the UK.

With over a decade of experience, we offer exceptional localised IT support, particularly in South Yorkshire, and specialise in assisting SMEs.

Innovative Solutions for Businesses

20+

Years of Experience

A legacy of excellence in digital solutions.

100%

Zero Carbon

Doing our part for the environment.

Certified by British Gas.

99.9%

Client Satisfaction Rate

Trusted by businesses across all sectors for superior service.

1200+

Projects Completed

Delivering cutting-edge solutions for a seamless digital future.

Chris W.png
Steve Harper.png
BG---Name---Chloe-Day.png
BG---Name---Morgan-C.png

Experts in the field. Driven by success.

Speak to our team today.

IT Desk are a leader in business growth through consultancy. Contact us today for a no-obligation chat. Your Success, We’re Part of IT.

Book a meeting with our team.

Click below to see our live calendar and book a meeting with our team of experts.

bottom of page