Onboarding gets attention because it is visible — a new hire without a working laptop is an obvious failure. Offboarding gets far less, because nothing appears to go wrong when it is done badly.
That asymmetry is the problem. Incomplete offboarding is one of the most common findings in security audits and one of the most exploitable gaps in a small business, and it produces no symptom until it does.
Onboarding — before the first day
Everything below should be finished before the person arrives. A new hire spending their first morning waiting for an account is an avoidable and memorable start.
- Device provisioned, encrypted, patched, and enrolled in device management
- Account created with a role-appropriate permission set, not a copy of an existing user's access
- MFA registered, or a defined process for first-login enrolment
- Email, calendar and file access configured
- Licences assigned and recorded against the person
- Line-of-business application accounts created
- Group and distribution list membership set
- Phone or extension configured if required
- Physical access — badge, keys, alarm code — arranged with whoever owns it
The permission point deserves emphasis. Copying an existing user's access is fast and it propagates whatever excess that person accumulated. Over a few years this is how everyone ends up with access to everything, which is precisely what an attacker exploits after a single compromise.
Onboarding — the first week
- Security awareness training delivered and recorded, before broad access if practical
- Acceptable use and data handling policies acknowledged in writing
- Password manager provisioned, if you use one, which you should
- Backup and file storage explained — where work belongs, so it is protected
- Support process explained: how to raise a ticket, what counts as urgent
- Documented confirmation that everything above is complete
That last item is what turns a process into evidence. Under HIPAA and the FTC Safeguards Rule, training should be documented, not merely delivered — and an auditor will ask for records rather than assurances.
Offboarding — the same day
Access removal should be simultaneous with the person's departure, and for involuntary departures it should be immediate — ideally during the conversation.
- Disable rather than delete the primary account. Deleting immediately can destroy data you still need and break shared resources. Disable, then remove after a defined retention period.
- Terminate all active sessions. Disabling an account does not always end sessions already authenticated — this is the step most commonly missed, and it can leave someone with working access for hours or days.
- Revoke MFA registrations and any app passwords.
- Remove from all groups and distribution lists.
- Redirect or delegate email, and set expectations with whoever inherits it.
- Transfer file ownership, particularly anything in personal cloud storage.
- Reclaim and reassign licences.
- Revoke access to every line-of-business application, including anything managed outside IT.
- Wipe or reclaim devices, including any personal device holding company data.
- Revoke VPN and remote access certificates.
- Remove physical access.
| Offboarding step | Why it matters |
|---|---|
| Disable, don't delete, the account | Keeps data and shared resources intact |
| Terminate active sessions | Disabling alone may leave existing sessions working |
| Revoke MFA and app passwords | Removes secondary sign-in routes |
| Transfer files and redirect email | Keeps work accessible to the business |
| Reclaim licences and devices | Stops cost and removes cached data |
| Revoke VPN, app and physical access | Covers access outside the main directory |
The offboarding steps almost everyone misses
- Shared and service accounts. If the departing person knew a shared administrative password, that password must change. This is the single most-skipped step.
- External and vendor accounts. Software portals, domain registrars, cloud consoles, payment platforms, social media, the phone system administration panel. These sit outside the main directory and are rarely on anyone's checklist.
- Accounts registered in their name. Services signed up for with their work email, where the account itself belongs to them rather than the business. Discovering this after departure is painful.
- API keys and tokens they generated. These survive account disabling and are invisible unless specifically audited.
- Personal devices with cached company data — phones with mail profiles, home machines with synced files.
- Documentation only they held. Not a security step, but the point at which institutional knowledge leaves, and worth capturing during a notice period rather than after.
| Often missed | Action |
|---|---|
| Shared and service account passwords | Change any password the person knew |
| External and vendor accounts | Remove from registrars, portals, consoles, social media |
| Accounts registered in their name | Transfer ownership to the business |
| API keys and tokens | Audit and revoke; they survive account disabling |
| Personal devices with company data | Remove mail profiles and synced files |
| Knowledge only they held | Capture during the notice period |
Why this is a compliance matter
Terminated employees retaining access is a common finding in HIPAA compliance reviews, and access management is an explicit requirement under the FTC Safeguards Rule.
Cyber insurance applications also ask about offboarding process, and a dormant account belonging to a former employee is a favoured route for attackers precisely because nobody is monitoring it for unusual behaviour.
Two practices make this durable: run a quarterly access review comparing active accounts against your current staff list, and keep a documented record of each offboarding. Both are straightforward, and both are what turns a good intention into something you can evidence.
Sources
- Legal Information Institute, Cornell Law School (text of the federal regulation) — 16 CFR 314.4 – Elements (FTC Safeguards Rule)
- Federal Trade Commission — FTC Safeguards Rule: What Your Business Needs to Know
- Legal Information Institute, Cornell Law School (text of the federal regulation) — 45 CFR 164.308 – Administrative safeguards (HIPAA Security Rule)
- Microsoft Learn — Revoke user access in an emergency in Microsoft Entra ID


