How to offboard a user in Microsoft 365

When someone leaves your business, you need to remove their access carefully, not just delete their account. Done right, you protect company data, keep what colleagues still need, and stop paying for accounts you no longer use. The safe order is always the same: secure the account first, preserve the data, remove the licence, and only delete the account last.

Before you start: you'll need Global Admin or User Admin access to the Microsoft 365 admin center. It helps to confirm the person's exact leaving date and time, who takes over their emails and files (usually their manager), which shared mailboxes, groups and sites they had access to, any external apps tied to their account, and whether the mailbox needs to be kept. For most business roles, it does.

The offboarding steps in order

1

Block sign in immediately

This is the first and most important step. Do it the moment their access should end. It instantly stops them logging in from anywhere, on any device, while you handle the rest at your own pace.

  • Go to admin.microsoft.com and sign in.
  • Select Users, then Active users.
  • Click the departing person's name.
  • Select Block sign in and confirm.
Active users page in the Microsoft 365 admin center with the departing user selected Block sign in confirmation toggle on the user's account page
2

Reset the password

As an extra safeguard, reset their password so no one, including the former employee, can access the account during offboarding.

  • On the user's page, select Reset password.
  • Set a new password. You don't need to share it with anyone.
Reset password option on the user's account page in the Microsoft 365 admin center
3

Sign the user out of all sessions

Blocking sign in stops new logins, but active sessions can linger. Force them out everywhere.

  • On the user's page, select Sign out of all sessions.
  • This revokes their access tokens across email, Teams, and mobile apps.
Sign out of all sessions option on the user's account page
4

Back up or transfer OneDrive files

The departing person's personal work files live in their OneDrive. Preserve them before the account is removed.

  • Give the manager or a colleague access to the leaver's OneDrive so they can retrieve what's needed. Do this from the user's page under OneDrive settings, or in the OneDrive admin center.
  • Move important files into a shared SharePoint location or the manager's OneDrive.
OneDrive settings for the departing user's account in the admin center Granting a manager access to the departing user's OneDrive files OneDrive admin center file retrieval settings
Don't wait too long. Once a user account is deleted, the person you gave access to has 30 days by default to download the files they need, then the OneDrive moves toward permanent removal. You can extend this default in the SharePoint admin center if you need more time.
5

Handle the mailbox

Their email often contains information colleagues still need. Don't just delete it. Choose one of these two approaches.

Convert to a shared mailbox Recommended

This keeps all the emails accessible to colleagues, and a shared mailbox under 50 GB does not need a paid licence. Give the manager or relevant team access so the business keeps receiving and reading mail sent to that address.

Converting a user mailbox to a shared mailbox in the admin center
Set up email forwarding

If you just need incoming mail redirected, forward from their address to a colleague. You can combine this with an auto reply letting senders know who to contact instead.

Setting up email forwarding for a departing user's mailbox
6

Remove from groups, Teams and shared access

Clean up everything the account was connected to.

  • Remove the user from all Microsoft 365 groups and distribution lists.
  • Remove them from Teams and channels.
  • Remove their access to SharePoint sites and shared mailboxes.
  • Revoke access to any third party apps or services they signed into with their work account.
7

Remove the licence

Once the mailbox and files are handled, free up the licence so you stop paying for it. You can then reassign that licence to a new hire.

  • On the user's page, select Licences and apps.
  • Uncheck the assigned licence and save.
Removing an assigned licence from a user in the Microsoft 365 admin center
Order matters: only remove the licence after converting the mailbox to shared in step 5. Removing the licence first can put the mailbox on a deletion countdown.
8

Delete the account, when ready

Only delete once you're confident nothing more is needed from the account.

  • On the user's page, select Delete user.
  • The account moves to a deleted users state and can be restored for 30 days if you made a mistake. After 30 days it's permanently removed.
Delete user option on the account page in the Microsoft 365 admin center
Tip: many businesses wait a few weeks before deleting, keeping the blocked account as a safety net in case something was missed.

Offboarding quick order

  1. Block sign in
  2. Reset password
  3. Sign out of all sessions
  4. Back up or transfer OneDrive files
  5. Convert mailbox to shared, or forward
  6. Remove from groups, Teams, shared access
  7. Remove the licence
  8. Delete the account, when ready
Offboarding is a security event, not just admin housekeeping. A former employee with lingering access is a real risk. Always block sign in first, revoke sessions, and double check that no access was left open through shared mailboxes, third party apps, or forwarding rules the person set up themselves.

Offboarding correctly, preserving data, protecting security, and avoiding wasted licence costs, matters more than most businesses realise. If you'd like this handled for you, or want a proper joiner and leaver process set up for your team, MStack360 can take care of it.

Book a call with MStack360

Leave a Comment

Your email address will not be published. Required fields are marked *