Global Workforce, EOR & Cross-Border OperationsPlaybook3 min readUpdated September 2026

Deprovisioning Remote Employees: A Device and Access Runbook

Deprovisioning a remote employee is a different problem than walking to someone's desk and collecting a badge. Hardware might be in another country, access spans a dozen systems, and the window between a termination decision and the person's last logged-in minute needs to be short and coordinated.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

When should you revoke access in a remote employee offboarding?

The single most important operational detail is timing: access to email, code repositories, shared drives, and any customer-facing systems should be revoked at, or within minutes of, the termination conversation, not at the end of the day or the next morning. Build a checklist tied to your identity provider so revoking one central login cuts off connected systems automatically, rather than requiring someone to manually disable a dozen separate accounts under time pressure.

How do you get company hardware back from an employee abroad?

Getting a laptop back from someone in another country takes real logistics: a prepaid shipping label in their local postal system, clear instructions on packaging, and a defined deadline. Build this into your offboarding process as a standard step with a tracked deadline, and have a policy for what happens if hardware isn't returned, including whether the cost is deducted from final pay where local law allows, which varies significantly by country and should be confirmed with your EOR or local counsel rather than assumed.

Step three: remote-wipe before, not instead of, physical return

If your device management tooling supports remote wipe, trigger it as part of the same access-revocation sequence, don't wait for the physical hardware to arrive back at your office. A laptop sitting in transit for two weeks with an active company login and cached credentials is a real exposure window, not a theoretical one. Remote wipe and physical recovery are two separate controls; use both rather than treating the wipe as optional if you're getting the hardware back anyway.

Step four: don't forget the access that isn't centrally managed

Single sign-on covers most modern tools, but check for the accounts that slip through: a personal device enrolled in your mobile device management, a shared password for a legacy vendor tool, API keys or service accounts tied to that person's identity, and any local admin access on shared infrastructure. Maintain a standing checklist of these non-SSO systems so offboarding doesn't rely on someone remembering them under pressure.

For example, an engineer leaves and their single sign-on account is disabled within minutes, but a service account they created for a reporting script still runs under their name, and a shared password for a legacy vendor tool is still known to them. Neither appears in the identity provider, so neither gets cut off. The fix is a standing inventory of non-SSO access, with a named owner for each item, reviewed whenever someone with admin or integration duties joins or leaves. Then offboarding means working through a list rather than recalling each account from memory while the termination conversation is already under way.

Step five: confirm local termination process before executing any of this

In many countries, the process and required notice for terminating employment is itself regulated, and access revocation timing needs to fit within what's legally permitted, not just what's operationally convenient. Coordinate the technical deprovisioning sequence with whoever is managing the local termination process, usually your EOR, so the security steps don't inadvertently create a separate employment law problem.

Step six: run a post-offboarding audit, not just the initial sequence

A week or two after an offboarding, check that nothing was missed: confirm the hardware shipment was received and wiped, verify no access re-appears through a synced personal device or a forgotten integration token, and check whether any shared accounts the person knew the password to (a legacy vendor login, a shared social media account) were rotated. Offboarding rarely fails at the checklist step; it fails at the thing nobody thought to put on the checklist, which is exactly what a short follow-up audit is designed to catch.

A short follow-up audit should confirm that:

  • The hardware shipment was received and the device was wiped.
  • No access has reappeared through a synced personal device or a forgotten integration token.
  • Shared accounts the person knew the password to, such as a legacy vendor login or a shared social media account, have been rotated.
  • Anything the checklist missed is added to it, so the next offboarding starts from a better list.

Treating this differently for a routine departure versus a contentious one

Most departures are routine, and a standard checklist executed calmly is enough. For a termination that's likely to be contentious, a security incident, a performance dispute, or anything where the person might react badly, move the access-revocation timing earlier relative to the conversation itself, and involve IT and legal in planning the sequence in advance rather than improvising it in the moment. The extra coordination cost is small compared to the risk of an upset departing employee having live access for even a few extra minutes, and having a pre-agreed elevated-risk version of the checklist means nobody has to design one under pressure.

Executive Capability Standard

What Good Looks Like

The standard is a documented deprovisioning runbook that revokes access within minutes of termination and tracks hardware recovery to a defined deadline, for every country you employ in.

Building The Capability (5-Stage Skill Ladder)

1. Learn:List every system a departing employee could access that isn't covered by your central single sign-on.
2. Do Manually:Write a step-by-step deprovisioning checklist covering access revocation, remote wipe, and hardware shipping logistics.
3. Delegate:Assign IT and people ops joint ownership of executing the checklist together at every termination, with a signed-off completion record.
4. Automate:Connect your identity provider so revoking one central account automatically cuts off connected systems rather than requiring manual steps per tool.
5. Buy:Bring in a device management or IT security vendor if you're managing hardware across more countries than your internal IT team can track manually.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Should access be revoked before or during the termination conversation?

Immediately at, or within minutes after, the conversation is the general best practice for most roles, coordinated so it doesn't happen visibly mid-conversation in a way that feels adversarial. For roles with elevated access risk, some companies revoke access at the exact start of the conversation; confirm the approach with your local employment process so it doesn't conflict with required termination procedures.

What if a former employee doesn't return company hardware?

Have a written policy in advance covering next steps: a formal request with a deadline, and depending on local law, a potential deduction from final pay or a separate recovery process. Whether a deduction is legally permitted varies significantly by country, so confirm with your EOR or local counsel before relying on it as your default remedy.

Does remote wipe replace the need to get the physical device back?

No. Remote wipe protects the data and credentials on the device, but the hardware itself still has value and, in some cases, contains components you're contractually or legally required to recover or dispose of properly. Treat wipe and physical recovery as two separate steps in the same process, not substitutes for each other.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides