Most businesses can describe their leaver process, but far fewer can produce a dated record showing what happened to the last person who left.

That gap is where Microsoft 365 offboarding fails. Three months on, the leaver’s mailbox is still forwarding to a manager who left last quarter, their OneDrive files sit inside a locked account, and the licence has been billing since March. A Cyber Essentials assessor will ask for the log and, equally, a cyber insurer will ask for the same thing.

The process that does exist covers HR paperwork, the ID card and a farewell drink. The Microsoft 365 side gets left, and it is where the data risk, the compliance evidence and the wasted licence spend all sit.

What most businesses get wrong on day one of a leaver

The mistake is an HR-first sequence, so HR sends the goodbye email, and someone remembers to tell IT the following Monday. In the gap between the resignation being announced and access being revoked, the leaver still has everything: email, OneDrive, Teams, and any application tied to their Microsoft 365 identity.

What happens in that gap is rarely sinister. Someone copies a contact list to a personal drive, sets an auto-forward so customer emails keep arriving, or shares a folder with a personal Google account. None of it needs malicious intent to become a data protection problem later.

What good looks like: IT hears the same day HR does, sign-in is disabled before the goodbye email goes out, and every action is logged with a timestamp. On a documented process the first-hour sequence takes under thirty minutes.

The seven-step Microsoft 365 offboarding checklist

Run these in order. Each takes a few minutes in the admin console. Microsoft’s own guidance covers the mechanics; what follows is the sequence and the reasoning behind it.

  1. Disable sign-in immediately in Entra ID. Before the goodbye email, before the last day. Use the block sign-in toggle. This is the most important action on the list and the one most often delayed.
  2. Revoke active sessions and reset MFA. Blocking sign-in stops new logins and leaves existing sessions alive. Revoke sessions in Entra ID, then reset the leaver’s MFA methods. Anyone who registered a passkey on a personal device keeps that credential until you revoke it explicitly.
  3. Convert the mailbox to a shared mailbox. Conversion itself does not remove the licence, but it prepares the mailbox to run without one once the licence is released later in this sequence (see the licence-reclaim step below). Shared mailboxes are free up to 50 GB after that release, with one exception worth knowing: putting a shared mailbox on litigation hold, or giving it an archive, requires a licence whatever its size. If the mailbox needs to be held for a dispute, budget for the licence separately. Delegate access can be granted to colleagues so late-arriving business messages still land somewhere.
  4. Transfer OneDrive ownership. Assign the line manager or an operations account as the new owner while the account still exists. Doing this before any deletion keeps the files reachable through the normal interface.
  5. Reassign Teams and channel ownership. Any Team the leaver owned needs a new owner or the group orphans. Personal Teams chats holding business conversations should be exported to a shared location if you need to retain them.
  6. Rotate shared credentials the leaver knew. Service account passwords, shared application logins, the Wi-Fi key if it was ever handed out, VPN keys. This is the step most SMEs skip because it is inconvenient, and it matters most for credentials the leaver knew about without directly owning.
  7. Document every action with timestamps. Screenshot or export the audit log. This is the evidence pack a Cyber Essentials assessor and a cyber insurance underwriter both ask for.

The BYOD question: what to do about their phone

If the leaver used a personal phone for work email or Teams, the sequence changes. UK data protection and employment law both limit what a business may do to a personal device, and a full remote wipe of someone’s own phone is almost always the wrong action.

What you can do depends on what was in place beforehand. With Intune app protection policies, which is the current standard for personal devices, a selective wipe removes work apps and cached company data and leaves personal files, photos and apps untouched. A fully enrolled device offers the same option.

With nothing in place, negotiate a handover of the specific files the business needs and leave the device alone.

In every case, revoke the leaver’s Microsoft 365 sessions from Entra ID. That invalidates the cached credentials on the phone without touching the device itself.

Offboarding a Copilot user and the agents they leave running

The seven steps close the account. They do not close what the account built. Where a leaver held a Microsoft 365 Copilot licence, three things survive the offboarding, and none of them appear on a standard checklist.

The Copilot licence is separate, and so is the cost. Copilot is an add-on sitting on top of the base subscription, billed per user per month. Removing the base licence does not remove it. Check the add-on column in the admin centre, because this is the line most often left running on an account nobody uses.

Revoking the licence does not delete the history. A leaver’s Copilot interaction history stays tied to the account. Prompts, responses and the context of previous sessions persist after the licence is pulled and after sign-in is blocked. Clearing it is therefore a deliberate action through Purview rather than a side effect of offboarding, and for a business handling a subject access request later that distinction matters.

Agents carry on without an owner. A Copilot Studio agent the leaver built keeps running after they go, and an agent on a scheduled trigger keeps firing on its own. Because agents are usually pointed at SharePoint sites and external connectors to be useful, an unowned agent is a live process holding real access with nobody accountable for it.

Power Automate flows behave the same way. A flow owned by the leaver either breaks quietly, so an approval chain or a reporting job stops without anyone noticing, or it keeps running with the leaver’s permissions behind it. Neither outcome is one you want to discover during an assessment.

Before the account is disabled, list every agent and flow the leaver owns. Business-critical ones move to a service account with a named human owner behind it, so the next departure does not repeat this. Everything else gets unpublished, its triggers turned off, and deleted, then reclaim the Copilot licence alongside the base one.

All of it belongs in the same timestamped record as the rest of the offboarding, an assessor asking how you control access will treat an agent with no owner much as they treat an account with no owner.

What Cyber Essentials expects on leavers

The user access control area of Cyber Essentials asks specifically how a business handles leavers. Assessors want to see a documented process, a timestamped log of leavers over the past twelve months, and evidence that access was revoked at each step. An assurance that accounts get disabled carries little weight without a dated record behind it.

The evidence pack can be modest. A one-page process document, plus an export from the Entra ID audit log showing the block-sign-in action per leaver (the sign-in log is a separate report that only records sign-in attempts, not admin actions taken on the account), satisfies most assessors. Businesses that cannot produce it get flagged, and it returns as a repeat item at the following year’s assessment. Our summary of what changed in Cyber Essentials v3.3 covers the wider user access control expectations.

The thirty-day settle, and the trap in releasing the licence

The first hour closes the immediate risk. The following weeks handle the loose ends, and this is where the current guidance most often goes wrong.

Two different clocks run on OneDrive, triggered by two different actions.

Deleting the account from Entra ID starts the cleanup process. The OneDrive is retained for 30 days by default, the manager or secondary owner is notified, a reminder follows seven days before expiry, and the site then moves to the recycle bin for a further 93 days before permanent deletion.

Removing the licence starts something different. Microsoft’s documentation is explicit that removing a licence does not trigger cleanup, and neither does blocking sign-in. What it starts instead is a nonpayment clock. The OneDrive becomes read-only at day 60, is archived and inaccessible to users at day 93, drops out of eDiscovery at day 275, and becomes subject to deletion at 365 cumulative unpaid days.

That last clock is new. From 1 July 2026, unlicensed OneDrive accounts that remain unpaid run against a cumulative 365-day limit. Accounts already unlicensed before that date face deletion risk no earlier than 1 July 2027.

There is a cost attached as well. Once unlicensed-account billing is switched on, reactivating an archived account carries a one-off fee per gigabyte, and a monthly storage charge then applies across every unlicensed account in the tenant that has passed 93 days. Releasing licences without transferring the data first can turn a saving into a bill.

The practical order: transfer the OneDrive files and convert the mailbox before you release the licence. If ownership is transferred before the licence is removed, the day 60 read-only clock never starts and the day 93 archive is not a concern. The day 60 deadline only matters as a recovery window if the licence was released before files were moved.

Mailbox and Teams retention need the same attention. Set an auto-forward on the shared mailbox so late invoices, purchase orders and customer replies reach the right person. Individual Teams chats carry their own retention rules, so export business-critical conversations to a shared location while the account is still live. Where longer retention is needed, apply a Purview retention policy or move the files into a SharePoint library the business owns permanently.

Exchange Online retains permanently deleted items in the Recoverable Items folder (the hidden Deletions subfolder Outlook uses after Shift-Delete or after the Deleted Items folder is emptied) for 14 days by default, up to a configurable maximum of 30 days. That is separate from deleted-mailbox retention, which holds a soft-deleted mailbox for 30 days before it is purged. Both windows matter for offboarding.

When to reclaim the licence

Once the mailbox is shared and the OneDrive files are transferred, release the licence back to the pool. Every licence left on a former employee costs money each month, and across several leavers the total accumulates quietly. A business keeping one leaver licence for four months is paying four months of subscription for an account nobody uses.

The rule of thumb: shared mailbox first, free up to 50 GB. OneDrive files transferred to the manager or into a retention policy. Then release the licence, working to the day 60 deadline above. Where the role is being filled quickly, the licence can transfer straight to the replacement.

Six ways offboarding goes wrong

  1. Service accounts get forgotten. If the leaver held the admin password for the accounts system or a shared support inbox, rotate it the same day.
  2. Connected applications keep their tokens. Any third-party app the leaver linked to their Microsoft 365 account may still hold a valid token. Review and revoke through Entra ID enterprise applications.
  3. Logins outside Microsoft 365 get missed. LinkedIn business accounts, marketing platforms, payment systems. Keep a per-user inventory so nothing slips.
  4. The licence gets kept just in case. That reflex costs money every month, and shared mailbox conversion already covers the recovery scenario.
  5. No audit trail exists. Nothing dated, nothing signed off. This fails the Cyber Essentials evidence test and leaves the business exposed if a leaver later disputes what was accessed.
  6. Auto-forward rules go unchecked. A leaver quietly forwarding mail to a personal address is a real exfiltration pattern. Check the mailbox rules before you disable the account.

Where to start

The seven steps take under thirty minutes on a documented process, and any competent administrator can run them. The part that takes longer is the evidence: a dated record, per leaver, showing which action happened when, in the form an assessor accepts.

As a Cyber Essentials certification body we see what passes and what gets flagged, and as your IT partner we can produce the log itself. If an assessment or an insurance renewal is coming up, we can pull your leaver audit trail for the past twelve months and show you where the gaps are.

Talk to us about your leaver evidence pack, or read what changed in Cyber Essentials v3.3 first if your assessment is the trigger.