Emergency server help: get in touch

Employee Offboarding Checklist: Secure AD, M365 and Workspace Steps

A practical leaver checklist covering Active Directory disable and group cleanup, Microsoft 365 session revocation and mailbox conversion, Google Workspace suspension and data transfer, Zoho user deactivation, plus shared credentials, devices and verification steps.

Published Updated 5 min read

Offboarding is where most organisations leak access. Accounts stay enabled for weeks, a personal phone keeps syncing mail, a shared password in a wiki is never rotated, and a SaaS seat keeps billing. A written checklist executed the same way every time, ideally on the day HR confirms the departure, closes those gaps. The steps below are ordered so that access is cut first and data is handled afterwards, and they cover the four platforms most small and mid-sized businesses run together: on-premises Active Directory, Microsoft 365, Google Workspace and the Zoho suite.

Short answer: Disable the account and revoke active sessions everywhere on the leaver’s last day: Disable-ADAccount and a password reset in AD, Revoke-MgUserSignInSession and a sign-in block in Microsoft 365, user suspension in the Google Admin console, and deactivation in the Zoho admin panel. Then convert or delegate the mailbox, transfer files and calendars, remove the user from groups and shared credentials, wipe or reclaim devices, and after the retention period delete the accounts and release the licences.

Day one: cut access

In Active Directory, disable rather than delete, reset the password to something random, move the object to a Leavers OU and note the date in the description:

Disable-ADAccount -Identity jdoe
Set-ADAccountPassword -Identity jdoe -Reset -NewPassword (ConvertTo-SecureString (New-Guid).Guid -AsPlainText -Force)
Get-ADPrincipalGroupMembership jdoe | Select-Object -ExpandProperty name | Out-File C:\offboarding\jdoe-groups.txt
Get-ADPrincipalGroupMembership jdoe | Where-Object name -ne "Domain Users" | ForEach-Object { Remove-ADGroupMember -Identity $_ -Members jdoe -Confirm:$false }
Move-ADObject -Identity (Get-ADUser jdoe).DistinguishedName -TargetPath "OU=Leavers,DC=corp,DC=example,DC=com"

Saving the group list first makes a reversal possible if the departure is postponed. Force a sync if Entra Connect is in use with Start-ADSyncSyncCycle -PolicyType Delta. In Microsoft 365, revoke tokens and block sign-in, because a disabled AD account does not end an existing cloud session immediately:

Connect-MgGraph -Scopes "User.ReadWrite.All","Directory.AccessAsUser.All"
Revoke-MgUserSignInSession -UserId jdoe@example.com
Update-MgUser -UserId jdoe@example.com -AccountEnabled:$false

In the Google Admin console open the user, choose Suspend user, and under Security reset sign-in cookies; also remove any app passwords and connected apps listed under the user’s security settings. In Zoho, deactivate the user in the Zoho One or Mail admin panel rather than deleting, which preserves their mail and CRM ownership for reassignment. Rotate the wireless pre-shared key, VPN credentials and any shared service passwords the person knew, and revoke their MFA devices.

Mail, files and calendars

Set an auto-reply on the mailbox naming a colleague, then either convert the Microsoft 365 mailbox to shared with Set-Mailbox -Identity jdoe@example.com -Type Shared and grant the manager Full Access, or place it on litigation hold if policy requires retention before the licence is removed. In Google Workspace, use Data migration or the transfer option under the user to move Drive ownership and calendar events to the manager before deletion; suspended accounts keep their data but a deleted one loses it after the grace period. Forward the Zoho mailbox and reassign CRM records, projects and Desk tickets to another agent. Export anything the business needs from personal OneDrive or Drive folders that were never shared.

Devices and physical access

Reclaim laptops and phones, and for company-managed devices trigger a remote wipe or retire action from Intune or Google endpoint management, and a selective wipe of work data on personal phones. Remove the person from the MDM, revoke certificates issued to them, disable building access badges, and check the RMM or remote support tool for an agent registered under their name. On the file server, reassign ownership of home directories and check for scheduled tasks or services running under their credentials with Get-ScheduledTask | Where-Object { $_.Principal.UserId -like "*jdoe*" }.

Groups, apps and shared credentials

Remove the user from distribution groups, Teams, Google Groups and Zoho teams, so lists stop routing mail to a dead mailbox. Audit SaaS tools that use SSO and those that do not; the second category is where orphaned accounts hide, so keep an inventory. Search the password manager for entries shared with the leaver and rotate them. Check DNS registrars, hosting control panels and cloud consoles for API keys or tokens created under their name; a WHM API token or a cloud access key outlives the user account that created it unless explicitly deleted.

Verify and close out

Attempt to sign in as the user to each platform and confirm the block, then check sign-in logs a day later for any successful authentication. Confirm the manager can open the mailbox and files, that group memberships are gone, and that devices show as retired. After the retention period, typically 30 to 90 days, delete the accounts and release licences. The common pitfall is deleting a Google or Microsoft account before transferring data, which destroys it, or leaving the AD object enabled because the request came by chat rather than through the ticket queue; make the ticket mandatory.

Related reading: Microsoft 365 shared mailbox vs distribution group vs Microsoft 365 Group and Zoho Cliq Networks: set up external partner collaboration for external members who also need removing.

Employee offboarding checklist at a glance

Employee Offboarding Checklist summary card: Disable the account and revoke active sessions everywhere on the leaver's last day: Disable-ADAccount and a password…
In short: Disable the account and revoke active sessions everywhere on the leaver’s last day: Disable-ADAccount and a password reset in AD, Revoke-MgUserSignInSession and a sign-in block in Microsoft 365, user suspension in the Google Admin console…

Official documentation: Active Directory Domain Services docs, Microsoft 365 documentation, Google Workspace Admin Help.

Related guides: Disable RDP drive, clipboard and USB redirection with Group Policy · Set up Windows LAPS on Windows Server 2025 and Windows 11 · Configure fine-grained password policies (PSOs) in Active Directory.

Frequently asked questions

Does disabling an Active Directory account also sign the user out of Microsoft 365?

Not immediately. Existing access and refresh tokens remain valid until they expire, so run Revoke-MgUserSignInSession and block sign-in in Entra to end cloud sessions on the day.

How long does a full employee offboarding take?

The access-removal steps take under an hour when scripted. Data transfer and device collection depend on volume and logistics and usually complete within the first week.

Can I undo an offboarding if the person returns?

Yes, provided you disabled and suspended rather than deleted. Re-enable the accounts, restore group memberships from the saved list, reassign the licence and remove the auto-reply; a converted shared mailbox can be changed back to a regular mailbox.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.