Guest blog courtesy of Augmentt.
Employee offboarding is one of the most frequent tasks MSPs perform, and one of the most consequential when it goes wrong. A departed employee who retains access to a client's Microsoft 365 environment even for a few days is a live security risk. Former employees with grievances, compromised credentials belonging to accounts nobody is monitoring, and personal data retained in business mailboxes are all downstream problems that trace back to an incomplete offboarding process.The challenge for MSPs isn't knowing what needs to happen. Most teams have a checklist. The challenge is executing that checklist reliably, quickly, and across every client, every time.For clients in regulated industries — healthcare, finance, legal — the list extends further to include audit log preservation, data access reviews, and documentation of the offboarding process for compliance purposes.
Why manual offboarding breaks down
Manual offboarding relies on a chain of communication and execution that has multiple failure points. HR notifies a manager. The manager opens a ticket. The ticket is assigned to a technician. The technician works through a checklist, but the checklist lives in a shared document that was last updated eight months ago, and the client has added two new SaaS applications since then that aren't on it.Under normal conditions, most of the steps get completed. Under deadline pressure — when the departure is sudden, when the technician is handling three other tickets, when the request comes in at 4:45 on a Friday — steps get missed. An account stays active. A license isn't reclaimed. A shared mailbox isn't converted. These aren't systemic failures; they're human ones. And human failures at scale become systemic risks.What a complete offboarding process looks like
A thorough M365 offboarding workflow covers more ground than most checklists account for. The minimum baseline should include:- Disable the user account immediately upon departure (or at end of last day)
- Revoke all active sessions and tokens across all connected apps
- Reset the account password to prevent re-entry via cached credentials
- Remove all admin role assignments
- Convert the mailbox to a shared mailbox and assign delegate access to the appropriate manager
- Set an out-of-office auto-reply directing contacts to the right person
- Remove the user from all distribution groups and Teams channels
- Reclaim the M365 license for reassignment
- Review and revoke any app registrations or OAuth consents the user created
- Preserve mailbox data per the client's retention policy




