Microsoft 365 offboarding
Microsoft 365 offboarding best practices
The deprovisioning half of an offboarding is a checklist. The data half is where organisations get it wrong. Here is the full sequence, and the part almost every guide skips.
The correct order, and why
Almost every Microsoft 365 offboarding guide — including Microsoft's own — covers deprovisioning: block sign-in, revoke sessions, reset the password, convert the mailbox, remove the licence. That is necessary and it is not the risky part.
The risky part is that none of it touches the data the person owned. Their OneDrive, their SharePoint sites, their group ownerships and any files shared with other people keep existing independently of the account. Kill the account first and you have stranded all of it.
Step 1 — revoke access
- Block sign-in and revoke active sessions and refresh tokens immediately — before any data work begins.
- Convert the mailbox to a shared mailbox or set forwarding, so the team does not lose contact history.
- Remove the account from privileged groups and roles.
Step 2 — the part guides skip: the data
Establish what the departing user actually owns before moving anything. This is the step that distinguishes a complete handover from a partial one, because items already owned by somebody else never show up in a naive "what did they own" export.
- Enumerate OneDrive files, folders and drives the leaver owns — not just the account.
- Enumerate SharePoint sites and libraries they own or administer.
- Identify anything shared with external or anonymous links; a handover does not revoke those.
- Move or deliberately archive each item to the successor, recording the outcome per item.
The full walkthrough is in our guide to transferring OneDrive ownership when an employee leaves.
Step 3 — SharePoint ownership
Site collection admins are a different list from owners. The most common miss in Microsoft 365 offboarding is changing the primary owner and assuming the site is clean — while library owners, folder ownership and leftover admin entries still point at someone who has left. For the mechanics, see ownership transfer with verification.
Step 4 — delete last
Only once the data is verified should the account be deleted — and deletion is effectively one-way for OneDrive content once the retention window closes. Teams that delete out of habit lose files permanently; teams that disable and never finish accumulate licences and unmanaged accounts.
Keeping the evidence
If you will be asked to evidence what happened during an audit, the checklist above produces none by itself. What moved, who approved it, what failed, and when — reconstructed from tickets afterwards, weeks too late.
- Record per-item outcomes, including failures and skips, at the time they happen.
- Enforce separation of duties — whoever runs the transfer should not approve it.
- Export signed evidence from the operation itself rather than assembling it later.
Votra covers steps 2 through 4 with approval, per-item verification and a signed export. It does not deprovision accounts — for that, follow Microsoft's own guidance in step 1. See how the metadata-only architecture works and how this compares to a manual run.
Common questions
- What is the correct order for Microsoft 365 offboarding?
- Revoke first, then transfer, then close. Block sign-in and revoke active sessions so nothing moves while you work; move the data; and delete the account last. Deleting before the transfer is complete is the one irreversible mistake, because the OneDrive content is unrecoverable once the retention window closes.
- Should you disable or delete a departing employee's account first?
- Neither, until the data is safe. Disable and revoke sessions at the start of the process so the person cannot act on anything, but defer deletion until ownership and file transfer are verified. Many teams delete immediately out of habit, which is what strands data in a recycle bin.
- How long do you have to transfer a departing employee's files?
- Not indefinitely. Once an account is fully deleted, the OneDrive content moves to a recycle bin for a limited window and is then purged. There is no supported recovery afterwards, so the transfer has to complete before deletion, not after.
- Do offboarding checklists need to be different for Microsoft 365?
- Yes, because M365 splits identity from data. Blocking sign-in is a few clicks, but the departing user's OneDrive, SharePoint sites, libraries and group ownership are separate records that do not follow the account. A generic HR checklist covers the account and none of the data.
Run the data half properly once
One departing employee, end to end, with signed evidence at the end.
Trial runs 7 days from account creation; see pricing for plan detail.
