IT Offboarding: How to Remove Access Without Missing a Single Tool
Complete offboarding closes every account a departing employee held, moves their work to the right people, and leaves an access trail you can show an auditor. One pass through the checklist below covers it:
- End sessions and block sign-in at your identity provider first
- Deactivate the accounts that live outside single sign-on
- Transfer email and files, recover the device, then release the license
Verified against Microsoft 365, Google Workspace, and Slack admin consoles on 2026-07-28.
Prerequisites
- Microsoft shops: an account with the User Administrator or Helpdesk Administrator role
- Google shops: an admin account with the User management privilege
- A current inventory of every tool the employee could sign in to. Your SSO dashboard, password manager, and billing statements are the fastest sources for building one
Step 1: End Every Session and Reset the Password
Start at the identity provider, because most of your other tools trust it for sign-in.
Microsoft 365:
- In the Microsoft 365 admin center, go to Users → Active users.
- Select the user's name, then select Reset password. Let it generate a new password and keep it to yourself.
- Select the user's name again, and on the Account tab, select Sign out of all sessions.
Access tokens last about an hour, so active sessions expire quickly once both actions are done.
Google Workspace: resetting the password from Directory → Users covers new sign-ins; the suspension in Step 2 closes existing sessions.
Step 2: Block Sign-In at the Identity Provider
Microsoft 365:
- Go to Users → Active users and select the user's name.
- Select Block sign-in.
- Select Block this user from signing in, then Save changes.
Microsoft notes the block can take up to 24 hours to fully apply, which is why the password reset in Step 1 comes first.
Google Workspace:
- In the Google Admin console, go to Menu → Directory → Users.
- Point to the user and click More options → Suspend user.
- Click Suspend to confirm.
Suspension blocks access to Gmail, Drive, and Calendar without deleting anything, and you can restore the account at any time if you need something from it.
Step 3: Sweep the Tools That Live Outside SSO
Every app connected to your identity provider through SCIM deprovisioning shuts off on its own when the account is disabled. The rest need a manual pass. Work through your inventory and deactivate each one. In Slack, for example:
- From your desktop, click Admin in the sidebar.
- Select Workspace settings, then click People.
- Click the three dots icon next to the member and select Deactivate account.
Slack removes the person from all channels and signs them out on every device, while their messages and files stay put. Repeat the equivalent step in each remaining tool, and note the ones you had to touch by hand: those are your candidates for SCIM provisioning, which is worth configuring for scale from day one and is straightforward to add even if your stack is already established.
Step 4: Transfer Email and Files
- Email: in Microsoft 365, forward the former employee's email to a teammate or convert the mailbox to a shared mailbox so the address keeps receiving customer mail.
- Files: grant another user access to the departing employee's OneDrive, or transfer Drive ownership in Google Workspace, before any account deletion. Microsoft retains OneDrive and Outlook content for 30 days after an account is deleted; ownership transfers beat retention windows every time.
Step 5: Recover the Device and Release the License
- Collect company hardware, or use your device management tool to wipe company data from personal devices. Microsoft shops can wipe a mobile device from the Exchange admin center.
- Remove the license once data transfer is complete. In Google Workspace, suspended accounts still bill at the full rate, so archive or delete the account when you no longer need it live.
Verify
- Try the user's address on your identity provider's sign-in page and confirm it is refused.
- Search each tool's member list for the employee's email address and confirm the account shows deactivated or suspended.
- Send a test message to the former employee's address and confirm it reaches the teammate or shared mailbox you set up.
- Check next month's SaaS invoices for seats that should have dropped.
Troubleshooting
Mail still arrives on the former employee's phone: the sign-in block can take up to 24 hours in Microsoft 365. Reset the password and sign out all sessions first, and turn off the mailbox's email apps under Recipients → Mailboxes → Manage email apps settings in the Exchange admin center.
A shared document went dark for the team: ownership was never transferred before deletion. Restore the account within the retention window, transfer ownership, then delete again.
Stray accounts keep surfacing weeks later: the tool inventory is incomplete. Rebuild it from billing statements and your password manager, and move the stragglers behind SSO so the next offboarding is one switch instead of a scavenger hunt.
Make Offboarding a Non-Event
An offboarding that runs from a checklist takes minutes and holds up under a security review. ScaleIt builds and runs this process for startups and SMBs as part of managed IT, from the identity provider settings to the SCIM connections that make most of the checklist automatic. Book a free call and we will map it to your stack.
Verified against Microsoft 365 admin center, Google Workspace Admin console, and Slack workspace administration on 2026-07-28. Vendor docs: learn.microsoft.com/microsoft-365, support.google.com/a, slack.com/help.