Deprovisioning Remote Employees: A Device and Access Runbook
Deprovisioning a remote employee is a different problem than walking to someone's desk and collecting a badge. Hardware might be in another country, access spans a dozen systems, and the window between a termination decision and the person's last logged-in minute needs to be short and coordinated.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
When should you revoke access in a remote employee offboarding?
The single most important operational detail is timing: access to email, code repositories, shared drives, and any customer-facing systems should be revoked at, or within minutes of, the termination conversation, not at the end of the day or the next morning. Build a checklist tied to your identity provider so revoking one central login cuts off connected systems automatically, rather than requiring someone to manually disable a dozen separate accounts under time pressure.
How do you get company hardware back from an employee abroad?
Getting a laptop back from someone in another country takes real logistics: a prepaid shipping label in their local postal system, clear instructions on packaging, and a defined deadline. Build this into your offboarding process as a standard step with a tracked deadline, and have a policy for what happens if hardware isn't returned, including whether the cost is deducted from final pay where local law allows, which varies significantly by country and should be confirmed with your EOR or local counsel rather than assumed.
Step three: remote-wipe before, not instead of, physical return
If your device management tooling supports remote wipe, trigger it as part of the same access-revocation sequence, don't wait for the physical hardware to arrive back at your office. A laptop sitting in transit for two weeks with an active company login and cached credentials is a real exposure window, not a theoretical one. Remote wipe and physical recovery are two separate controls; use both rather than treating the wipe as optional if you're getting the hardware back anyway.
Step four: don't forget the access that isn't centrally managed
Single sign-on covers most modern tools, but check for the accounts that slip through: a personal device enrolled in your mobile device management, a shared password for a legacy vendor tool, API keys or service accounts tied to that person's identity, and any local admin access on shared infrastructure. Maintain a standing checklist of these non-SSO systems so offboarding doesn't rely on someone remembering them under pressure.
For example, an engineer leaves and their single sign-on account is disabled within minutes, but a service account they created for a reporting script still runs under their name, and a shared password for a legacy vendor tool is still known to them. Neither appears in the identity provider, so neither gets cut off. The fix is a standing inventory of non-SSO access, with a named owner for each item, reviewed whenever someone with admin or integration duties joins or leaves. Then offboarding means working through a list rather than recalling each account from memory while the termination conversation is already under way.
Step five: confirm local termination process before executing any of this
In many countries, the process and required notice for terminating employment is itself regulated, and access revocation timing needs to fit within what's legally permitted, not just what's operationally convenient. Coordinate the technical deprovisioning sequence with whoever is managing the local termination process, usually your EOR, so the security steps don't inadvertently create a separate employment law problem.
Step six: run a post-offboarding audit, not just the initial sequence
A week or two after an offboarding, check that nothing was missed: confirm the hardware shipment was received and wiped, verify no access re-appears through a synced personal device or a forgotten integration token, and check whether any shared accounts the person knew the password to (a legacy vendor login, a shared social media account) were rotated. Offboarding rarely fails at the checklist step; it fails at the thing nobody thought to put on the checklist, which is exactly what a short follow-up audit is designed to catch.
A short follow-up audit should confirm that:
- The hardware shipment was received and the device was wiped.
- No access has reappeared through a synced personal device or a forgotten integration token.
- Shared accounts the person knew the password to, such as a legacy vendor login or a shared social media account, have been rotated.
- Anything the checklist missed is added to it, so the next offboarding starts from a better list.
Treating this differently for a routine departure versus a contentious one
Most departures are routine, and a standard checklist executed calmly is enough. For a termination that's likely to be contentious, a security incident, a performance dispute, or anything where the person might react badly, move the access-revocation timing earlier relative to the conversation itself, and involve IT and legal in planning the sequence in advance rather than improvising it in the moment. The extra coordination cost is small compared to the risk of an upset departing employee having live access for even a few extra minutes, and having a pre-agreed elevated-risk version of the checklist means nobody has to design one under pressure.
What Good Looks Like
The standard is a documented deprovisioning runbook that revokes access within minutes of termination and tracks hardware recovery to a defined deadline, for every country you employ in.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Endpoint protection tooling like CrowdStrike can remote-wipe or isolate a device as part of the same sequence as access revocation, closing the exposure window while hardware is in transit.
Vulnerability management tooling like Tenable can confirm a deprovisioned device no longer appears as an active, connected endpoint on your network once offboarding is complete.
Frequently Asked Questions
Should access be revoked before or during the termination conversation?
Immediately at, or within minutes after, the conversation is the general best practice for most roles, coordinated so it doesn't happen visibly mid-conversation in a way that feels adversarial. For roles with elevated access risk, some companies revoke access at the exact start of the conversation; confirm the approach with your local employment process so it doesn't conflict with required termination procedures.
What if a former employee doesn't return company hardware?
Have a written policy in advance covering next steps: a formal request with a deadline, and depending on local law, a potential deduction from final pay or a separate recovery process. Whether a deduction is legally permitted varies significantly by country, so confirm with your EOR or local counsel before relying on it as your default remedy.
Does remote wipe replace the need to get the physical device back?
No. Remote wipe protects the data and credentials on the device, but the hardware itself still has value and, in some cases, contains components you're contractually or legally required to recover or dispose of properly. Treat wipe and physical recovery as two separate steps in the same process, not substitutes for each other.
About the numbers
This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.
Related Guides
Deel vs Remote vs Rippling: Picking an EOR That Fits
A COO's side-by-side look at Deel, Remote, and Rippling for hiring abroad: what each one actually is, where coverage differs, and what to check before you sign.
European Works Councils: What COOs Need to Know Before They Apply
What a European works council does, when the rules apply to a growing company, and how to build employee consultation habits before you're required to.
Running a Four-Day Work Week Pilot Without Losing Output
How to structure a four-day work week trial so you can actually measure the tradeoff, rather than guessing whether output held up.
Permanent Establishment Risk When an Executive Works Abroad
What triggers permanent establishment risk when an executive relocates abroad, and the practical steps that reduce exposure before a tax authority asks.
Planning a Global Team Retreat: Budget, Visas, and Logistics
How to plan an annual retreat for a distributed team across many countries, from a real per-person budget to visa timing and on-site logistics.
Home Office Stipends and VAT Reclaims Across Borders
How home office stipends are taxed differently by country, and what actually qualifies for VAT reclaim on remote work equipment purchases.