Could a Former Employee Still Access Your Company Systems?

Could a Former Employee Still Access Your Company Systems?

Could a Former Employee Still Access Your Company Systems?

Charne M.
Charne M.

5 Minute Read

undefined Minute Read

Yes. A former employee may still have access if even one account, device, shared password, remote login, or vendor portal is missed during offboarding.

That can leave company email, customer files, financial systems, and business applications accessible long after the employee has left.

CISA recommends promptly terminating accounts and privileges when someone leaves an organization. In one documented incident, a threat actor gained access through a former employee account that had not been disabled after departure.

The solution is a repeatable offboarding process involving management, HR, and IT, with clear responsibility for every account and device.

What access should be removed when an employee leaves?

Start with every system the employee used to do their job, not only their main email account.

A practical offboarding review should include:

  • Microsoft 365 and company email

  • Cloud applications and file storage

  • CRM, accounting, payroll, and industry software

  • VPN and remote access

  • Shared passwords

  • Vendor and supplier portals

  • Website and social media accounts

  • Administrator privileges

  • Company computers, phones, and tablets

  • Physical keys, badges, and access cards

Microsoft’s own offboarding guidance includes blocking Microsoft 365 access, protecting mailbox and OneDrive data, wiping company data from mobile devices, and deciding what happens to the employee’s email after departure.

The most common problem is not that nobody removes access. It is that everyone assumes someone else already did.

Who should be responsible for employee offboarding?

Who should be responsible for employee offboarding?

Offboarding works best when management, HR, and IT each have a defined role.

Management should confirm the employee’s final working time, identify who will take over their responsibilities, and tell IT which business systems the employee used.

HR should coordinate the departure, collect company property, document the process, and make sure the appropriate people know when access must end.

IT should disable accounts, revoke active sessions, remove remote access, recover devices, review permissions, and confirm that access has actually been removed.

The timing matters. For a planned departure, these steps can be prepared in advance. For an immediate termination, access may need to be removed at the same time the employee is notified.

CISA’s identity and access management guidance says user accounts and privileges should be promptly terminated when someone leaves through resignation, termination, retirement, or the end of a contract.

What should happen to Microsoft 365 access?


Disabling the Microsoft 365 account is only part of the process.

Administrators should also:

  • Block new sign-ins

  • Revoke active sessions

  • Review registered devices

  • Remove unnecessary administrator roles

  • Decide who needs access to the former employee’s files

  • Review email forwarding

  • Preserve the mailbox when the business still needs the information

Microsoft recommends blocking the user and revoking sessions when access needs to be removed. Existing sessions can otherwise remain active for a period depending on how the application handles its authentication tokens.

If customers still email the former employee, Microsoft also allows the business to forward new messages or convert the mailbox into a shared mailbox rather than simply deleting it.

What about shared passwords and outside applications?

What about shared passwords and outside applications?

This is where offboarding often becomes harder.

An employee may know passwords to a shared social media account, vendor website, office Wi-Fi network, marketing platform, or other system that does not use their individual company login.

Those credentials should be changed when necessary, especially if the employee had direct access to them.

Also review applications that may not appear in the main company directory, including:

  • Vendor portals

  • Banking and payment platforms

  • Website administration

  • Social media

  • File-sharing services

  • Scheduling platforms

  • Remote-support tools

  • Industry-specific cloud applications

Removing Microsoft 365 access does not automatically remove access to every third-party platform. Microsoft recommends automated deprovisioning where possible because some applications maintain their own sessions or allow direct sign-in outside Microsoft Entra ID.

What should happen to the employee's devices and remote access?

What should happen to the employee's devices and remote access?

Company-owned laptops, phones, security keys, and other devices should be returned and checked before being reassigned.

IT should confirm that company information is protected and that the former employee cannot continue using stored credentials or remote-access tools.

For mobile devices that contained company information, Microsoft includes wiping or blocking the device as part of its former-employee process.

Remote access deserves its own check. Disable VPN accounts, remote desktop permissions, remote-support tools, and any saved authentication methods that allowed the employee to connect from outside the office.

Do not assume returning the laptop means remote access has disappeared.

What should an employee offboarding checklist include?

What should an employee offboarding checklist include?

A simple checklist makes the process much easier to repeat.

Before closing the offboarding ticket, confirm:

  1. The employee's company accounts are disabled.

  2. Active sessions have been revoked.

  3. Administrator permissions are removed.

  4. VPN and remote access are disabled.

  5. Company devices and security keys are returned.

  6. Shared passwords have been changed where necessary.

  7. Third-party and vendor accounts are removed.

  8. Email forwarding and mailbox access are reviewed.

  9. Business files have been transferred to the right person.

  10. IT has confirmed that no known access remains.

Microsoft provides a dedicated former-employee process because disabling a single user account does not cover email, files, mobile devices, forwarding, and other business data on its own.

For businesses with regular staff changes, the same checklist should be used every time. That reduces the chance that one forgotten application becomes an unexpected access point months later.


Integrate Cyber Takeaway

Integrate Cyber Takeaway

Employee offboarding is not only an HR task. It is also an access-control process.

Management needs to identify what the employee used. HR needs to coordinate when access should end. IT needs to remove that access and confirm that it is actually gone.

Do not stop at disabling email.

Check cloud applications, shared passwords, devices, remote access, forwarding, administrator rights, and vendor portals too.

One missed account can be enough to leave company information accessible after someone has already walked out the door.

Employee offboarding is not only an HR task. It is also an access-control process.

Management needs to identify what the employee used. HR needs to coordinate when access should end. IT needs to remove that access and confirm that it is actually gone.

Do not stop at disabling email.

Check cloud applications, shared passwords, devices, remote access, forwarding, administrator rights, and vendor portals too.

One missed account can be enough to leave company information accessible after someone has already walked out the door.

Know where you’re exposed before someone else does 

Book a scoping call and we’ll help define the right penetration testing approach for your environment. 

Know where you’re exposed before someone else does 

Book a scoping call and we’ll help define the right penetration testing approach for your environment. 

Know where you’re exposed before someone else does 

Book a scoping call and we’ll help define the right penetration testing approach for your environment. 

integrate cyber newsletter

Subscribe To Our Weekly Newsletter

Practical advice, real threats explained, and simple steps to strengthen your security every week.

integrate cyber newsletter

Subscribe To Our Weekly Newsletter

Practical advice, real threats explained, and simple steps to strengthen your security every week.

integrate cyber newsletter

Subscribe To Our Weekly Newsletter

Practical advice, real threats explained, and simple steps to strengthen your security every week.