April 26, 2026

Employee Offboarding Checklist for Security and Support

Employee Offboarding Checklist for Security and Support

When an employee leaves, the work does not end with HR paperwork. Offboarding is also a security, access control, and support task, and the details matter if you want to avoid lingering access, missing devices, and avoidable help desk surprises.

Featured image placement: The publisher will insert the featured image here.

Why offboarding needs an IT checklist

Most small businesses keep a lot of operational knowledge in people’s accounts and devices. Email access, file sharing, password managers, phone systems, remote tools, and cloud subscriptions can all remain active after a departure if no one owns the process.

That creates three common problems. First, former employees may still be able to reach business data. Second, the company may lose track of hardware or software licenses. Third, the next person who inherits the role may spend days untangling old settings, shared mailboxes, and device confusion.

A clean offboarding process reduces those risks and gives managers a predictable handoff. It also helps your IT partner close the loop on backups, documentation, and account cleanup before the change becomes an incident.

Start with a clear offboarding owner

Every departure should have one person coordinating the checklist. In some businesses that is HR, in others it is an office manager, operations manager, or practice manager. The key is not the title. The key is that one person owns the sequence and confirms completion.

If IT is involved, make sure IT receives notice early enough to prepare. A same-day notice may be unavoidable in some cases, but planned departures are much easier to handle when access changes, device collection, and mailbox decisions are coordinated in advance. If your business needs a more structured approach to user lifecycle management, managed IT services can help standardize the process.

Review every account tied to the employee

The first offboarding pass should identify every system the employee used, not just email. For many small businesses, the real exposure is in the “extra” tools that no one thinks about until a login fails or a former user is still receiving alerts.

Common account types to review

  • Email and calendar accounts
  • File sharing and cloud storage
  • Line-of-business software
  • Password managers and shared credentials
  • VPN, remote access, and admin portals

Do not rely on memory alone. Review the user’s assigned apps, browser password stores if managed, shared mailboxes, delegated access, and any integrations that were approved for the role. If the employee had elevated permissions, those should be removed or reassigned immediately.

For businesses using Microsoft 365 or similar cloud platforms, account review should include mailbox access, delegation, shared folders, OneDrive or similar storage, and any forwarding rules that may have been set up. Microsoft documents multiple ways to manage access and retention, but the practical point is simple: know what the user could reach before you disable the account.

Decide what happens to email and shared data

Email is often where offboarding becomes messy. The business may need to preserve records, transfer responsibilities, or allow a manager to review the mailbox for a short transition period. Those decisions should be made deliberately rather than by accident.

Shared data should also be reviewed with the same care. If the employee owned project files, contact lists, templates, or operational notes, assign a new owner and confirm the data is accessible to the team that needs it. A missing folder after someone leaves can look like a simple inconvenience, but it often becomes a productivity problem for the next person in the role.

If your team needs a better way to protect business records and reduce recovery risk, backup and disaster recovery planning should be part of the offboarding conversation, especially when key operational files live in cloud systems or local devices.

Collect and verify company devices

Offboarding is also a hardware control issue. Laptops, phones, tablets, docks, smart cards, and security keys should all be accounted for before the employee’s access is fully closed out. If devices are not returned promptly, the business may lose track of assets or delay secure wipe and reissue steps.

It helps to confirm not only that a device was returned, but that it is the correct device and in the expected condition. A laptop with a damaged drive, missing charger, or unknown login state may need special handling before it can be reassigned.

Device questions worth answering

  • Was every company device returned?
  • Are chargers, adapters, and accessories included?
  • Has the device been inventoried and labeled?
  • Does the device need a wipe, reimage, or replacement?
  • Is the device assigned to a new user or retired?

For a business that manages multiple endpoints, this step is easier when the asset inventory is current. If your team needs help keeping devices organized and support-ready, IT support can help maintain the records that make offboarding cleaner.

Disable access in the right order

Access removal should be deliberate. Some businesses disable everything at once, which can be appropriate for an immediate termination. Others need a short transition period to retrieve information or manage handoff tasks. Either way, the order matters.

Start by removing privileged access, then disable the user’s ability to sign in to business systems, and then address any shared access, forwarding, or delegated permissions. If the employee used multifactor authentication, remove those tokens or device registrations as part of the process.

This is also the point to reset or rotate shared credentials that the employee knew, especially if those credentials were used for vendor portals, equipment dashboards, or service accounts. If a password was shared informally, assume it needs to be changed.

Check phones, VoIP, and call routing

Phone systems are easy to overlook during offboarding, especially in businesses that use cloud calling or shared reception workflows. If the employee had a direct line, voicemail, call queue role, or softphone app, those settings should be reviewed before the number is left pointing at a dead mailbox or an inactive device.

For VoIP environments, update call routing, voicemail greetings, extensions, auto attendants, and any hunt groups that referenced the departing employee. If the number is being reassigned, confirm that the old voicemail and app access are removed before the new user takes over. If your phone system is part of the broader support stack, VoIP services planning can help avoid dropped calls and confusing handoffs.

Review security logs and alerts after departure

Once access is removed, the work is not quite done. Review recent sign-in activity, admin changes, and any alerts tied to the former employee’s account. This is especially important if the employee had access to financial systems, customer records, or administrative tools.

In some cases, you may find legitimate residual activity such as mailbox forwarding or shared folder access. In other cases, you may find a forgotten login path that needs to be closed. The goal is not to create alarm. The goal is to confirm that the offboarding steps worked the way they were supposed to.

If your business wants a more proactive review of account control and exposure, network security services can help identify weak points before they turn into support calls or security incidents.

Update documentation so the next handoff is easier

Offboarding is one of the best times to improve documentation. If a former employee had to be chased for device returns, account passwords, or file ownership, that is a sign the process needs better records.

Update the following after each departure: who approved the offboarding, what systems were touched, what devices were returned, which accounts were disabled, and what still needs follow-up. This creates a cleaner history for future departures and helps your IT partner spot recurring gaps.

For firms that want fewer surprises and more predictable support, a documented process can be as valuable as any tool. It also makes it easier to ask the right questions during a broader review of your environment. If you are looking for ongoing support rather than one-off cleanup, managed IT services can bring consistency to user onboarding and offboarding alike.

Use this simple offboarding sequence

If you want a practical starting point, keep the process short and repeatable. The exact order may vary by role, but the core steps should stay consistent.

  1. Confirm the departure date and ownership of the checklist.
  2. Identify every account, device, and system the employee used.
  3. Transfer files, email responsibilities, and shared resources.
  4. Disable access, rotate shared credentials, and remove MFA tokens.
  5. Collect devices, verify inventory, and close out documentation.

That sequence will not solve every situation, but it will reduce the most common risks: lingering access, missing hardware, and support confusion after the employee is gone.

When offboarding should involve your IT partner

Some offboarding tasks are simple. Others involve cloud permissions, security controls, phone routing, backups, or administrative access that should be handled carefully. If your internal team is not confident about the sequence, or if you want a repeatable process that does not depend on one person remembering every step, bring in your IT partner early.

IronGate IT Service helps small businesses build practical processes around access control, support handoffs, device management, network security, and backup readiness. If you want help tightening the process, talk with an IT partner about a cleaner offboarding workflow.

Employee departures do not have to create lingering access or support surprises. With a clear checklist and the right follow-through, offboarding becomes a controlled process instead of a loose end.