Offboarding an M365 User
Purpose
Ensure that when an employee leaves, their access is fully revoked, their data is preserved according to retention policy, and their license is reclaimed in a timely manner.
Scope
Applies to all full-time and contract staff with Microsoft 365 accounts.
Prerequisites
- Global Admin or User Administrator role in Entra ID
- Access to Microsoft 365 Admin Center
- Knowledge of the departing user’s manager
Procedure
1. Block sign-in immediately
- Open Entra ID admin center
- Navigate to Users > All users
- Select the departing user
- Under Properties, set Account enabled to No
- Click Save
Blocking sign-in invalidates all active sessions within the hour. For immediate revocation, also go to Authentication methods and select Revoke sessions.
2. Reset the password
Change the password to a randomly generated value that no one retains. This prevents any cached credentials from being used.
3. Remove from all groups and roles
- Under the user’s profile, open Groups
- Remove from all security groups, M365 groups, and Teams
- Check Assigned roles and remove any admin roles
4. Forward email and set out-of-office
- In Exchange Admin Center, go to Recipients > Mailboxes
- Select the user, open Manage mailbox delegation
- Add the user’s manager under Read and manage (Full Access)
- Optionally configure a mail forwarding rule or auto-reply
5. Preserve the mailbox
Do not delete the account immediately. Convert the mailbox to a shared mailbox to preserve data without consuming a paid license:
- In Exchange Admin Center, select the user’s mailbox
- Choose Convert to shared mailbox
- Remove the assigned M365 license from the user account
Shared mailboxes do not require a license as long as they are under 50GB.
6. Transfer OneDrive access
- In M365 Admin Center, go to Users > Active users
- Select the user, choose OneDrive
- Under Get access to files, set the manager as the delegate
- The manager will receive an email with a link to the files
7. Reclaim the license
Once the mailbox is converted to shared and OneDrive is delegated:
- Go to Users > Active users, select the user
- Open Licenses and apps
- Uncheck all assigned licenses
- Click Save changes
8. Document and close
Record the offboarding in your IT ticket system with:
- Date of offboarding
- Who authorized it
- Whether a litigation hold was applied
- License reclaimed and date
Notes
- If the user is subject to a legal hold, do not convert to shared mailbox or delete any data. Consult legal before proceeding.
- Review after 90 days whether the shared mailbox is still needed.