The Ex-Employee Who Still Has Access: A Secure Leaver Checklist for Aberdeen Businesses

Quick answer: When someone leaves your business, the real risk is not a single forgotten task. It is an account nobody switched off because nobody told IT the person had gone. A good leaver process disables access straight away, preserves the data, checks for hidden mailbox rules and shared logins, and puts one named person in charge of every departure. This guide walks through what that looks like, and gives you a free checklist to build your own.

The quiet risk sitting in your Microsoft 365 tenant

Most businesses picture a security breach as something dramatic. A hooded figure, a clever piece of malware, an alarm going off at 2am. The reality is usually far more boring. It is an account that belonged to someone who left eight months ago, still live, still licensed, and still able to sign in.

Nobody is watching it. Nobody notices the failed sign-in attempts. Nobody queries the quiet forwarding rule that has been copying invoices to an outside address since spring. That is exactly why attackers like these accounts. A dormant account is an open door in a building everyone assumes is locked.

If you have ever run through the list of accounts in your tenant and found a name you did not recognise, or a leaver who somehow still has a mailbox, this guide is for you.

Why offboarding slips through the cracks

Offboarding is the part of IT that quietly falls over when a business is busy. Onboarding gets attention because a new starter cannot work until their accounts exist. There is pressure, and a clear finish line. Offboarding has neither. The person has already gone. The work still needs doing, but nobody is chasing it.

The gap is rarely about bad intentions. It is almost always about communication. A Friday afternoon departure that nobody thought to mention to IT. A contractor whose end date came and went. A resignation that HR knew about three weeks before anyone told the person who manages the accounts.

If your leaver process depends on someone remembering to send an email, it is not really a process. It is a hope.

If a leaver process depends on someone remembering, it is not a process

What a secure leaver process actually covers

A proper offboarding routine is more than a password change and a wave goodbye. It works through every place a former employee could still reach your systems or your data. In practice that means five areas.

Accounts and access. Disable the account rather than deleting it, so the data is preserved and the change can be reversed if you got the timing wrong. Switch off local and network logins as well as cloud accounts. Remove the account from any group that grants elevated or admin rights, and reset any shared logins the person knew.

Email and Microsoft 365. Block sign-in first. If the mailbox is still needed, convert it to a shared mailbox with a named owner rather than leaving a full account open. Record and remove distribution group memberships, strip out any forwarding rules already on the mailbox, and set an autoreply if customers might still write to the address. Once the mailbox no longer needs to be a full account, unassign the licence so you are not paying for a ghost.

Devices. Confirm whether the laptop or phone is managed through mobile device management. Retire or wipe it, and make sure any physical hardware actually comes back.

Directory and records. Mark the contact inactive in your CRM, remove their direct dial from the phone system, and unlink them from any assets or configuration records tied to their name.

Close out. Check every step against a written list, then tell whoever requested the offboarding that it is done. That last step is what turns a task into a record you can stand behind.

You will notice most of these are quick. That is the frustrating part. Offboarding is one of the cheapest security gaps to close, and one of the most commonly left open.

The single step that matters most

If you only fix one thing, fix this. Give every departure one named point of accountability.

You can have the most thorough checklist in Aberdeen, and it will still fail if IT finds out about a leaver a month after they have gone. The written list matters, but it only works when it is actually triggered. That means a clear handover from whoever knows first, usually a manager or HR, to whoever does the work. One person owns it. One person confirms it is finished.

This is the same principle behind enforcing multi-factor authentication on every account and behind Microsoft Secure Score: security improves most when it stops depending on people remembering, and starts being built into a routine.

One named owner for every leaver

Get the free checklist

We have put together a general Secure Leaver Offboarding Checklist you can use as a starting point. It covers all five areas above, step by step, so you can adapt it to your own systems rather than starting from a blank page.

It is a general example to help any business build its own process. It is not a substitute for advice on your specific setup, and it is deliberately not tied to one particular IT configuration.

Get the checklist emailed to you

Enter your email and we’ll send the PDF straight to your inbox.


We’ll send it straight away. You can unsubscribe at any time.

Keep a copy somewhere your team will actually find it.

Frequently asked questions

Should you delete or disable a leaver’s account?

Disable it, do not delete it. Disabling blocks access immediately while preserving the mailbox, files and settings, so you can recover anything you still need and reverse the change if the timing was wrong. Deleting straight away risks losing data and breaking anything linked to that account. You can delete later, once you are certain nothing depends on it.

How quickly should access be removed when someone leaves?

For a routine, amicable departure, access should end on the person’s last working day. Where there is any sensitivity, for example a dismissal or a move to a competitor, disable access immediately and coordinate the timing with HR. The key is deciding this in advance rather than in the moment.

What is a dormant account and why is it a security risk?

A dormant account is one that still exists and can still sign in, but nobody is actively using or monitoring it. Leavers who kept their mailbox, shared logins nobody owns, and old admin accounts from finished projects are common examples. They are risky precisely because no one is watching them, so a compromise can go unnoticed for months. Reviewing accounts that have not signed in for 90 days is a quick way to find them.

What should a small business include in its offboarding process?

At a minimum: disable accounts and logins, handle the Microsoft 365 mailbox and licence, check for forwarding rules, remove shared and admin access, deal with devices, update your CRM and phone system, and confirm completion with a named owner. Our free checklist covers each of these in order.

Can our IT provider handle leaver offboarding for us?

Yes. A managed IT provider can run the whole process on request, working through a consistent checklist for every leaver and logging each step. The one thing we cannot do is know a person has left if nobody tells us, which is why a clear leaver notification is the foundation everything else sits on.

Closing the door properly

Offboarding will never be the most exciting part of running a business. But the account you forget about is the one that causes the problem, and closing that gap costs almost nothing compared to cleaning up after it.

If you would like help building a leaver process that runs the same way every time, or you want a second pair of eyes on the dormant accounts already sitting in your tenant, our team in Aberdeen can help. It is a small piece of housekeeping that quietly removes one of the easiest ways into your business.

Start with the cyber security basics for business, and if your team uses their own phones and laptops, read our guide on keeping company data safe on your team’s devices next.

Recent case studies

Cloud Machine Management

Cloud Machine Management

We worked with Aberdeen oil service company, Unity Well to migrate the management of their devices from on-site infrastructure to Microsoft’s cloud based Azure Active…
Read more
Sharepoint Data Migration

Sharepoint Data Migration

We completed a data migration project for an Aberdeen engineering company, Caledonia Services. We migrated their corporate data from on-site infrastructure to cloud based storage…
Read more

Discover Hidden Gaps in Your IT Security

✓ Takes 3 minutes ✓ No obligation ✓ Instant results
Get a comprehensive analysis of your IT infrastructure and security posture. See exactly where you're vulnerable and how much it's costing your business.