Date
June 5, 2026
Topic
IT Management
Employee
Offboarding
IT
Checklist:
10
Steps
to
Protect
Your
Business
When an employee leaves your company, the work does not end when they hand in their badge. Every account, device, and permission they had still exists until someone closes it out.
Employee Offboarding IT Checklist: 10 Steps to Protect Your Business

When an employee leaves your company, the work does not end when they hand in their badge. Every account, device, and permission they had still exists until someone closes it out. A solid employee offboarding IT checklist makes sure nothing gets missed and your business stays protected.

Skipping steps in the IT offboarding process can leave former employees with active access to sensitive systems, company email, or cloud data. That is a serious security risk. Whether you are a five-person team in Raleigh or a growing company across the Triangle, following a structured process protects your data and keeps you compliant.

Why IT Offboarding Steps Matter for Every Business

IT offboarding is the process of systematically removing a departing employee’s digital access, recovering company assets, and securing your systems. It is not just an HR task. It sits at the heart of your cybersecurity posture.

Studies consistently show that a large share of data breaches involve insiders, including former employees with credentials that were never revoked. Even well-meaning departures can turn risky if access lingers. A repeatable checklist removes the guesswork and protects everyone.

Step 1: Notify IT Before the Last Day

The offboarding process needs a head start. HR should notify your IT team or managed service provider as soon as a resignation or termination is confirmed. Waiting until the last minute creates gaps where access stays open longer than it should.

Ideally, IT gets 48 to 72 hours of advance notice for a planned departure. For sudden terminations, the process needs to move within hours. Setting up a formal handoff process between HR and IT is one of the simplest ways to reduce offboarding risk.

Step 2: Disable Active Directory and SSO Accounts

Active Directory (a centralized system that controls who can log into your network and computers) and single sign-on (SSO) platforms are the master keys to your environment. Disabling these accounts first cuts off the widest path of access in one move.

This step should happen at or before the employee’s final hour on the job. Disabling rather than deleting the account initially lets you preserve audit logs while still blocking access. Deletion can come later once you have confirmed all data has been transferred.

Step 3: Revoke Email Access and Set Auto-Reply

Email is often the most sensitive account a departing employee holds. It contains client conversations, internal decisions, and potentially confidential data. Revoking access on the last day is essential, but do not just shut it down cold.

Set an auto-reply that directs incoming messages to the right person. Then forward the inbox to a manager for a defined period, typically 30 to 90 days. This keeps business continuity intact while closing off the former employee’s direct access.

Step 4: Remove Employee Access to Cloud Apps

Modern businesses run on cloud applications. Project management tools, file sharing platforms, CRM systems, and communication apps all hold sensitive business data. Removing employee access from each of these is a core part of the IT offboarding steps.

Create a master list of every cloud app your company uses. Map which roles access which tools. This makes offboarding faster and reduces the chance of missing an app. If your team uses an identity management platform, most of this can be automated.

  • Cloud file storage (Google Drive, OneDrive, SharePoint)
  • CRM and sales platforms
  • Project and task management tools
  • Communication and video apps
  • Finance and HR software
  • Industry-specific platforms your team relies on

Step 5: Recover and Wipe Company Devices

Any laptop, desktop, phone, or tablet issued to the employee needs to come back to your IT team. Do not assume remote workers will mail them back on their own. Have a clear return policy written into your offboarding agreement.

Once the device is returned, IT should perform a full wipe to remove all personal and company data before reassigning or repurposing it. For mobile devices enrolled in a mobile device management (MDM) system, a remote wipe can be triggered even before the device is physically returned. Keep an asset inventory so no device falls through the cracks.