Employee Offboarding Checklist
(IT Access Removal)

A practical checklist to reduce “lingering access” risk when staff leave.

Why this matters

Many “small business breaches” are caused by old accounts, shared passwords, and unrevoked access after staff or contractors leave.

1) Same-day offboarding (do within 2 hours)

ItemStatusOwnerNotes
Disable user account (M365 / Google / AD)
Revoke sessions / sign-out everywhere
Reset shared passwords (Wi‑Fi, vault, shared accounts)
Remove MFA methods / recovery email / phone
Disable remote access (VPN / RDP / remote tools)
Collect company devices (laptop/phone) or lock/remote wipe

2) Within 48 hours

ItemStatusNotes
Transfer mailbox/OneDrive ownership (manager or shared mailbox)
Review shared folders/SharePoint permissions
Remove from distribution lists, Teams, groups, shared calendars
Remove access to line-of-business apps (accounting, payroll, POS, CRM)
Check vendor portals / banks / payment systems access

3) Within 7 days

ItemStatusNotes
Audit logs: confirm no suspicious forwarding rules or recent sign-ins
Confirm licence reclaim / remove paid app seats
Update documentation: “who owns what” and key contacts

4) Offboarding email template (internal)

Copy/paste to HR / manager / IT contact:

Staff member leaving: __________
Last day/time: __________
Systems used (if known): __________
Device(s) to collect: __________
Mailbox/OneDrive to transfer to: __________
Any shared accounts they knew: __________

5) “Gotchas” (common misses)

Note: This document is general operational guidance and does not replace legal advice. It helps you establish a practical baseline and reduce common privacy risks.
👉 Free 30-minute consultation

No hard sell - just clarity and practical next steps.

hello@virtusgroup.biz
virtusgroup.co.nz
0800 847 887 (VIRTUS)

Book now