Employee technology problems often begin before the employee’s first day. The laptop is ordered late, the wrong license is assigned, access is copied from someone with a different role, multifactor authentication is rushed, and no one confirms which files or customer systems the person should own. When someone leaves, the same lack of process can leave active accounts, unreturned devices, forgotten vendor access, and business information with no new owner.
A repeatable joiner, mover, and leaver process connects the manager, HR, operations, IT, security, facilities, and application owners. It gives the employee what is approved, records who made the decision, and produces evidence that access changed when employment or responsibilities changed.
1. Start with a complete, approved request
Collect the employee name, manager, title, department, location, start date and time, employment type, remote-work needs, required applications, shared resources, phone needs, equipment, and any special data or regulatory requirements. Identify who approves each type of access and how exceptions are recorded.
2. Build role-based access instead of copying a coworker
Define standard access packages for common roles, then approve exceptions separately. Copying another employee’s permissions can reproduce old mistakes or grant access the new person does not need. Use groups where practical so access remains understandable and can change consistently.
3. Create unique accounts and secure authentication
- Create a named account for each person; avoid shared sign-ins.
- Assign only the required Microsoft 365 and application licenses.
- Require MFA and register approved authentication methods.
- Separate privileged administrator access from ordinary work.
- Configure password, recovery, and sign-in policies according to the environment.
- Record who owns service, shared, and emergency accounts.
4. Prepare and record the device
Record asset tag, serial number, model, warranty, assigned user, location, operating system, and expected return. Apply approved configuration, updates, encryption, endpoint protection, screen lock, remote support, business applications, and device-management policies. Test the camera, microphone, dock, monitors, printer access, VPN, and other role-specific functions.
5. Decide where business information belongs
Show the employee where individual work, team files, customer information, templates, and records belong. Clarify approved cloud storage, external sharing, removable media, personal-device use, and data-handling rules. Assign owners for Teams, SharePoint sites, shared mailboxes, vendor portals, and important workflows.
6. Validate on the first day
Confirm identity before issuing credentials or helping with MFA. Test sign-in, email, collaboration, required applications, files, printers, phones, remote connectivity, and support channels. The manager should verify that access matches the role. Record unresolved items and owners instead of allowing informal workarounds to become permanent.
7. Treat role changes like controlled onboarding and offboarding
Promotions, transfers, leaves, contractor changes, and location moves require review. Add newly approved access, remove permissions no longer needed, update groups and licensing, reassign equipment, transfer ownership, and document the effective date. Do not let old access accumulate indefinitely.
8. Coordinate offboarding around an exact time
HR and the manager should provide the effective date and time, whether the departure is planned or urgent, who receives business information, which devices must return, and any legal or investigative hold. IT should have a verified list of cloud, local, remote-access, vendor, phone, building, and specialized application accounts.
9. Block access and revoke active sessions
Microsoft’s current guidance begins by resetting the former employee’s password, signing out active sessions, and blocking access. Timing and behavior can vary across services, devices, tokens, and connected applications, so organizations should understand their environment and not assume one button instantly reaches every system.
- Disable or block identity and application access at the authorized time.
- Revoke sessions, tokens, VPN access, and remote-support access.
- Remove administrative roles, groups, shared credentials, and vendor portals.
- Change codes or secrets the departing person knew when individual revocation is not possible.
- Secure or wipe organizational data from managed mobile devices where appropriate.
10. Preserve and transfer business information
Determine how mailbox, OneDrive, files, application records, contacts, documentation, and workflow ownership will be retained or transferred. Convert or forward mail only with authorized business rules and a defined end date. Preserve required information before removing licenses or deleting accounts.
11. Recover equipment and close physical access
Collect laptops, desktops, phones, tablets, tokens, keys, badges, storage media, chargers, docks, and other accessories. Record condition and missing items. Remove personal information through an approved process, preserve required business data, then securely reset, reassign, store, or dispose of equipment.
12. Complete a final verification
Use a second-person or manager review to confirm access removal, data ownership, equipment status, licenses, forwarding, shared credentials, vendor access, and open tasks. Keep a completion record with approvals, timestamps, exceptions, and follow-up dates.
Minimum fields for your checklist
- Employee, manager, department, location, status, and effective date/time.
- Approved role and exception approvers.
- Accounts, groups, licenses, applications, vendors, and administrative roles.
- Device identifiers, configuration, delivery, recovery, and condition.
- MFA, remote access, phone, shared resources, and physical access.
- Data, mailbox, file, site, workflow, and customer ownership.
- Completion evidence, unresolved exceptions, reviewer, and follow-up date.
Odyssey provides business IT support, Microsoft 365 administration, computer setup, remote support, device management, and onboarding/offboarding coordination for Greater Houston organizations.
Official Microsoft guidance
- Microsoft: Prevent a Former Employee from Signing In
- Microsoft Entra: Revoke User Access
- Microsoft Entra: Govern External User Lifecycle
Exact steps depend on licensing, applications, device management, retention, legal requirements, and identity architecture. Coordinate employment actions with authorized HR and legal decision-makers.


