IT Offboarding: How to Remove Access Without Missing a Single Tool

Complete offboarding closes every account a departing employee held, moves their work to the right people, and leaves an access trail you can show an auditor. One pass through the checklist below covers it:

Verified against Microsoft 365, Google Workspace, and Slack admin consoles on 2026-07-28.

Prerequisites

Step 1: End Every Session and Reset the Password

Start at the identity provider, because most of your other tools trust it for sign-in.

Microsoft 365:

  1. In the Microsoft 365 admin center, go to Users → Active users.
  2. Select the user's name, then select Reset password. Let it generate a new password and keep it to yourself.
  3. Select the user's name again, and on the Account tab, select Sign out of all sessions.

Access tokens last about an hour, so active sessions expire quickly once both actions are done.

Google Workspace: resetting the password from Directory → Users covers new sign-ins; the suspension in Step 2 closes existing sessions.

Step 2: Block Sign-In at the Identity Provider

Microsoft 365:

  1. Go to Users → Active users and select the user's name.
  2. Select Block sign-in.
  3. Select Block this user from signing in, then Save changes.

Microsoft notes the block can take up to 24 hours to fully apply, which is why the password reset in Step 1 comes first.

Google Workspace:

  1. In the Google Admin console, go to Menu → Directory → Users.
  2. Point to the user and click More options → Suspend user.
  3. Click Suspend to confirm.

Suspension blocks access to Gmail, Drive, and Calendar without deleting anything, and you can restore the account at any time if you need something from it.

Step 3: Sweep the Tools That Live Outside SSO

Every app connected to your identity provider through SCIM deprovisioning shuts off on its own when the account is disabled. The rest need a manual pass. Work through your inventory and deactivate each one. In Slack, for example:

  1. From your desktop, click Admin in the sidebar.
  2. Select Workspace settings, then click People.
  3. Click the three dots icon next to the member and select Deactivate account.

Slack removes the person from all channels and signs them out on every device, while their messages and files stay put. Repeat the equivalent step in each remaining tool, and note the ones you had to touch by hand: those are your candidates for SCIM provisioning, which is worth configuring for scale from day one and is straightforward to add even if your stack is already established.

Step 4: Transfer Email and Files

Step 5: Recover the Device and Release the License

Verify

Troubleshooting

Mail still arrives on the former employee's phone: the sign-in block can take up to 24 hours in Microsoft 365. Reset the password and sign out all sessions first, and turn off the mailbox's email apps under Recipients → Mailboxes → Manage email apps settings in the Exchange admin center.

A shared document went dark for the team: ownership was never transferred before deletion. Restore the account within the retention window, transfer ownership, then delete again.

Stray accounts keep surfacing weeks later: the tool inventory is incomplete. Rebuild it from billing statements and your password manager, and move the stragglers behind SSO so the next offboarding is one switch instead of a scavenger hunt.

Make Offboarding a Non-Event

An offboarding that runs from a checklist takes minutes and holds up under a security review. ScaleIt builds and runs this process for startups and SMBs as part of managed IT, from the identity provider settings to the SCIM connections that make most of the checklist automatic. Book a free call and we will map it to your stack.

Verified against Microsoft 365 admin center, Google Workspace Admin console, and Slack workspace administration on 2026-07-28. Vendor docs: learn.microsoft.com/microsoft-365, support.google.com/a, slack.com/help.