Devices, patching, joiners and leavers

Employee Offboarding Checklist: How Should Access Be Removed?

A calm checklist for removing access, transferring ownership, recovering devices, and recording what happened when someone leaves.

6 min readOperations teams, managers, internal admins

The short answer

Offboarding should block sign-in, revoke sessions where available, remove groups and admin roles, transfer ownership, recover or wipe devices according to policy, remove third-party access, and record completion.

The takeaways

  • Do not rely on changing one password or asking a manager to remember every system.
  • Treat account access, data ownership, and device recovery as one process.
  • Keep a completion record so offboarding is auditable and repeatable.

What should you confirm before the leaving date?

  • Leaving date, access removal time, manager, and HR or operations owner.
  • Company devices, accessories, security keys, and any personal devices with work data.
  • Microsoft 365, finance, CRM, HR, password manager, code, and supplier systems.
  • Mailbox, OneDrive, SharePoint, Teams, calendar, and shared mailbox handover needs.
  • Whether the account should be disabled immediately or at a scheduled time.
  • Any admin roles or privileged access that must be removed first.

How should account access be removed?

  • Block sign-in, suspend, or disable the account at the agreed time.
  • Revoke active sessions where the platform supports it.
  • Remove group memberships, shared mailbox access, delegate access, and privileged roles.
  • Transfer file, mailbox, calendar, or shared drive ownership where needed.
  • Remove third-party application access and connected OAuth apps where applicable.
  • Remove password manager access and rotate shared credentials if the leaver had access.
  • Document completed steps and any exceptions.

What should happen to devices and data?

Device recovery should be part of offboarding, not a separate afterthought. If a device cannot be returned quickly, decide whether remote lock or wipe is appropriate for your policy, employment context, and tooling.

Data handling should be practical and deliberate. Preserve what the business needs, transfer ownership before deleting accounts, and avoid keeping old active accounts just because nobody is sure what they own.

What should be reviewed after offboarding?

  • Exceptions

    If access remains open for a business reason, name the owner and review date.

  • Device status

    Mark devices as returned, wiped, reissued, missing, or retired.

  • Template gaps

    Add any missed systems, suppliers, or handover steps to the next leaver checklist.

Where are Kindura's remote-only limits?

Kindura can help with remote account changes, session revocation routes, Microsoft 365 access review, device status checks where tooling supports them, and completion records.

Collecting devices, packaging equipment, shipping hardware, physical wiping, legal HR decisions, and forensic incident response are outside the core remote service.

Questions to ask any provider

Use these on any offboarding process - including ours. Good offboarding should be repeatable under pressure.

  1. What happens at the exact access removal time?
  2. How are active sessions, groups, admin roles, and third-party apps handled?
  3. Who decides what to preserve, transfer, or delete?
  4. Who recovers the physical device and accessories?
  5. What completion record will the business keep?

Where Kindura fits

Kindura can support the remote access workflow

Kindura can help with remote account changes, Microsoft 365 access review, session revocation routes, device status checks where tooling supports them, and completion records. Device collection, packaging, shipping, HR decisions, and forensic response remain separate. Whether or not that suits you, offboarding should leave an auditable trail.