IT Operations & Asset Management4 min readUpdated September 2026

IT Offboarding: Revoking Access on an Employee's Last Day

IT offboarding means removing a departing employee's access to company systems, data and devices on their last day, in a set order: identity and email first, then shared credentials, apps, devices and data ownership. The reliable way to do it is to work from a list of every access grant recorded at onboarding, not from memory.

Access left open after someone leaves is a real exposure: a former employee can still read files, approve payments or log in to a customer system without anyone noticing. The runbook below covers a planned exit and a sudden one.

What should you prepare before the last day?

For a planned departure, you have time, so use it. When HR confirms the last day:

  • Pull the employee's access list: identity provider groups, applications, shared mailboxes, admin roles, API keys and any systems they set up.
  • Identify data and accounts they own that someone else must take over, such as shared documents, customer accounts and scheduled jobs.
  • Agree with the manager who receives forwarded mail and who takes over each duty.
  • Schedule the revocation for a specific time on the last day, and tell IT and the manager the time.
  • Arrange return of equipment, with a prepaid label for remote staff.

For a sudden departure or a for-cause exit, skip the schedule and revoke immediately once HR gives the go-ahead. The order below is the same either way.

In what order should you revoke access?

Follow this sequence so the most powerful access disappears first:

  1. Disable the person's account in the identity provider or single sign-on, which cuts off every connected app at once.
  2. Sign out all active sessions and revoke tokens, since disabling the account doesn't always end sessions already open.
  3. Reset or remove multi-factor authentication devices tied to the account.
  4. Convert or forward the mailbox to the manager, set an out-of-office reply, and keep the data in line with your retention policy.
  5. Remove access to apps that don't use single sign-on, one by one, from your list.
  6. Rotate any shared passwords, API keys and service credentials the person knew.
  7. Remove them from code repositories, cloud consoles, payment tools and admin roles, and reassign ownership.

Log the time of each step. In an incident review, that record shows you acted promptly.

What about shared passwords, keys and admin roles?

Shared credentials are the gap that a disabled account doesn't close. If the person knew a shared login for a vendor portal, a social account or a database, that password is still valid after they leave. Rotate it the same day and share the new one through your password manager.

Check these places, since they're easy to miss:

  • API keys and tokens the person created for integrations, which may keep working after their account is disabled.
  • Admin roles in SaaS tools where they were the only administrator.
  • Personal accounts used for business, such as a personal email registered with a vendor.
  • Payment cards, expense tools and bank approvals.
  • Domain registrar, DNS and website hosting logins.

A useful habit is keeping a list of which credentials each senior person controls, updated at least yearly. If the list is missing, this is when you feel it.

How do you handle devices and data?

Collect the laptop and any phones, tokens or badges. For remote staff, send a prepaid return label and confirm delivery. Don't power on or browse the device before it's secured; if you suspect misconduct, preserve it as it is and ask counsel how to proceed.

Then handle data deliberately:

  1. Transfer ownership of shared files, calendars and documents to the manager or a named colleague before the account is deleted.
  2. Back up what your retention policy says to keep, such as email and files that may be needed for legal or business reasons.
  3. Wipe the device to factory settings once the data is preserved, and record the wipe.
  4. Remove the device from device management and update the asset register.
  5. Delete the account after the retention period, not on day one, since deleting immediately can destroy files others rely on.

The laptop provisioning checklist uses the same asset register you update here.

How do you check that offboarding actually worked?

Verify, don't assume. A week after departure, review these:

  • The identity provider shows the account disabled, with no active sessions.
  • Each app on the access list confirms the user is removed, or you've checked directly.
  • Sign-in logs show no attempts by the former employee after their last day.
  • Shared credentials have new values, and the old ones no longer work.
  • The asset register shows the device returned and wiped.

Once a quarter, compare your active user lists in key systems with your current headcount from HR. Any account without a matching employee needs an explanation. This catches missed offboardings from any period. To close the loop on the front end of the employee lifecycle, see the 30-day onboarding checklist and first employee hiring checklist. The operations audit checklist can include offboarding as one of its checks, and vendor onboarding covers a similar access-control problem for outside parties. For managing devices at scale, see the device management comparison.

Executive Capability Standard

What Good Looks Like

A good offboarding revokes identity and email access at the agreed time on the last day, rotates shared credentials, recovers and wipes devices and verifies the result a week later.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Learn which systems sit outside your single sign-on and list the shared credentials your longest-tenured employees know.
2. Do Manually:Run the seven-step revocation order for the next departure, logging the time of each step.
3. Delegate:Give IT or operations one owner for offboarding, with HR triggering it and managers confirming what needs transferring.
4. Automate:Trigger revocation in the identity provider when HR marks a termination date, and create tasks for the manual steps.
5. Buy:Adopt identity and device management tools that revoke access across apps and wipe devices from one place.

How to Get Started

Frequently Asked Questions

What should an IT offboarding checklist include?

Include disabling the identity account, ending sessions, resetting multi-factor devices, handling email, removing app access, rotating shared credentials, collecting and wiping devices, transferring data ownership and verifying everything a week later.

How quickly should you revoke access when an employee leaves?

At the time their employment ends, or earlier for a for-cause exit. Schedule the revocation for a specific time on the last day, and have HR and IT agree on it beforehand.

Should you delete a departed employee's account right away?

Usually not. Disable it first, transfer ownership of files and shared items, and delete the account after your retention period. Deleting immediately can destroy data other people depend on.

What is the biggest offboarding mistake?

Forgetting access outside the single sign-on system: shared passwords, API keys, personal accounts used for work and admin roles in individual tools. Keep a per-person list of these so nothing depends on memory.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides