
Yes. A former employee may still have access if even one account, device, shared password, remote login, or vendor portal is missed during offboarding.
That can leave company email, customer files, financial systems, and business applications accessible long after the employee has left.
CISA recommends promptly terminating accounts and privileges when someone leaves an organization. In one documented incident, a threat actor gained access through a former employee account that had not been disabled after departure.
The solution is a repeatable offboarding process involving management, HR, and IT, with clear responsibility for every account and device.
What access should be removed when an employee leaves?
Start with every system the employee used to do their job, not only their main email account.
A practical offboarding review should include:
Microsoft 365 and company email
Cloud applications and file storage
CRM, accounting, payroll, and industry software
VPN and remote access
Shared passwords
Vendor and supplier portals
Website and social media accounts
Administrator privileges
Company computers, phones, and tablets
Physical keys, badges, and access cards
Microsoft’s own offboarding guidance includes blocking Microsoft 365 access, protecting mailbox and OneDrive data, wiping company data from mobile devices, and deciding what happens to the employee’s email after departure.
The most common problem is not that nobody removes access. It is that everyone assumes someone else already did.
Offboarding works best when management, HR, and IT each have a defined role.
Management should confirm the employee’s final working time, identify who will take over their responsibilities, and tell IT which business systems the employee used.
HR should coordinate the departure, collect company property, document the process, and make sure the appropriate people know when access must end.
IT should disable accounts, revoke active sessions, remove remote access, recover devices, review permissions, and confirm that access has actually been removed.
The timing matters. For a planned departure, these steps can be prepared in advance. For an immediate termination, access may need to be removed at the same time the employee is notified.
CISA’s identity and access management guidance says user accounts and privileges should be promptly terminated when someone leaves through resignation, termination, retirement, or the end of a contract.
Disabling the Microsoft 365 account is only part of the process.
Administrators should also:
Block new sign-ins
Revoke active sessions
Review registered devices
Remove unnecessary administrator roles
Decide who needs access to the former employee’s files
Review email forwarding
Preserve the mailbox when the business still needs the information
Microsoft recommends blocking the user and revoking sessions when access needs to be removed. Existing sessions can otherwise remain active for a period depending on how the application handles its authentication tokens.
If customers still email the former employee, Microsoft also allows the business to forward new messages or convert the mailbox into a shared mailbox rather than simply deleting it.
This is where offboarding often becomes harder.
An employee may know passwords to a shared social media account, vendor website, office Wi-Fi network, marketing platform, or other system that does not use their individual company login.
Those credentials should be changed when necessary, especially if the employee had direct access to them.
Also review applications that may not appear in the main company directory, including:
Vendor portals
Banking and payment platforms
Website administration
Social media
File-sharing services
Scheduling platforms
Remote-support tools
Industry-specific cloud applications
Removing Microsoft 365 access does not automatically remove access to every third-party platform. Microsoft recommends automated deprovisioning where possible because some applications maintain their own sessions or allow direct sign-in outside Microsoft Entra ID.
Company-owned laptops, phones, security keys, and other devices should be returned and checked before being reassigned.
IT should confirm that company information is protected and that the former employee cannot continue using stored credentials or remote-access tools.
For mobile devices that contained company information, Microsoft includes wiping or blocking the device as part of its former-employee process.
Remote access deserves its own check. Disable VPN accounts, remote desktop permissions, remote-support tools, and any saved authentication methods that allowed the employee to connect from outside the office.
Do not assume returning the laptop means remote access has disappeared.

A simple checklist makes the process much easier to repeat.
Before closing the offboarding ticket, confirm:
The employee's company accounts are disabled.
Active sessions have been revoked.
Administrator permissions are removed.
VPN and remote access are disabled.
Company devices and security keys are returned.
Shared passwords have been changed where necessary.
Third-party and vendor accounts are removed.
Email forwarding and mailbox access are reviewed.
Business files have been transferred to the right person.
IT has confirmed that no known access remains.
Microsoft provides a dedicated former-employee process because disabling a single user account does not cover email, files, mobile devices, forwarding, and other business data on its own.
For businesses with regular staff changes, the same checklist should be used every time. That reduces the chance that one forgotten application becomes an unexpected access point months later.






