⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Identity & Security7 min read

Your M365 Tenant After a Staff Member Leaves Unexpectedly, What to Do in the First 24 Hours

By Jamie Hamilton · Published

Somebody resigns without notice, is let go, or leaves under difficult circumstances. The Microsoft 365 tenant should be among the first things you deal with, because the gap between somebody leaving and their access ending is the whole of the risk.

What follows is the order I work in. The order matters more than any individual step, and one of these steps has to happen before the others or you lose the ability to do it at all.

If the departure is contested, preserve before you change anything

This is the exception to everything below and it comes first because it is the only step that cannot be done later.

If there is any prospect of a dispute, an insurance claim or a police report, put the mailbox on hold before you start changing settings. Once you begin deleting rules, reassigning ownership and converting mailboxes you are editing the record you may later need to produce, and some of what you edit is not recoverable. A hold costs nothing to apply and can be removed afterwards.

If none of that applies, and usually it does not, start at step one.

Step 1: Block sign-in, do not delete

In the Microsoft 365 admin centre, find the user and select block sign-in. This stops new sign-ins while leaving the account and everything in it intact.

Deleting is the instinct and it is the wrong move today. A deleted account is recoverable for 30 days and then it is not, and you will almost certainly need something out of it in the first fortnight. Deletion is a decision for week four.

Step 2: Revoke active sessions

This is the step almost everybody misses, and skipping it means step one did very little.

Blocking sign-in prevents a new sign-in. It does nothing to a session already running. Somebody with the mail app open on a personal phone keeps that access until the token behind it expires, and that is not minutes. In Entra ID, open the user and revoke sessions. Do this immediately after step one, not at the end of the list.

Step 3: Reset the password

Belt and braces. It closes the case where the sign-in block is lifted later by somebody who does not know why it was applied, and it invalidates the credential if it turns up in a breach dump.

Step 4: Check for forwarding rules before you touch anything else

Open the mailbox and look at the inbox rules, and check mailbox forwarding separately in the Exchange admin centre, because they are two different settings and a rule can hide in either.

Forwarding survives a sign-in block. The rule runs on the server, so it keeps copying mail to a personal address long after the account cannot be signed into, and it never appears in a sign-in report because nobody signs in. Note what you find before you remove it, particularly if the departure was difficult.

Step 5: Remove admin roles

If they held any administrative role, remove it now. An account that is blocked but still carries Global Administrator is one lifted block away from being the worst possible account to lose control of, and blocks do get lifted by whoever is on shift when somebody says they need one file.

Step 6: Reassign ownership before removing access

Groups, Teams and SharePoint sites where the departing person was the only owner are the trap here. Remove them first and you get an ownerless resource, which is harder to fix than it sounds and tends to be discovered months later when somebody needs to change a permission and finds nobody can.

Add the new owner, confirm it took effect, then remove the old one.

Step 7: Preserve and transition the mailbox

Convert the mailbox to a shared mailbox so a colleague can monitor it without a licence being consumed. Check the size first: an unlicensed shared mailbox is capped at 50GB, and a mailbox above that, or one with an archive or a hold, still needs its licence.

Set an automatic reply if customers wrote to that address, and decide who is answering it. This is the step that protects the revenue rather than the data.

Step 8: Audit recent activity, if warranted

If the departure was acrimonious, review what happened in the days before it. The Microsoft Purview and Defender portals hold the audit record: file downloads, mailbox exports, sharing links created, and mass deletions.

Do it promptly. Audit log retention is finite and varies by licence, so the question you can answer easily this week may not be answerable at all next quarter. If you think you might need this, run it now even if you are not sure what you are looking for.

What to do in week two

The urgent work is done in the first day. The rest is not urgent and still needs doing, and it is the part that decides whether this becomes an orphaned account.

  • •Transfer their OneDrive files to their manager, before the retention window after account deletion becomes relevant
  • •Remove them from distribution lists, which nothing forces you to do because nothing breaks
  • •Reclaim the licence once the mailbox is safely converted
  • •Write down what you decided about the account, so the person who finds it in a year knows it was a decision

Frequently asked questions

What is the first thing to do in Microsoft 365 when someone leaves suddenly?

Block sign-in, then revoke their active sessions. Those are two separate actions and the second is the one that gets missed. Blocking sign-in stops a new sign-in but does nothing to a session already running on a phone or a laptop, which continues until its token expires. If the departure is contested, put a hold on the mailbox before you touch anything, because that is the only step you cannot do later.

Should I delete the account straight away?

No. A deleted account is recoverable for 30 days and then it is gone, along with the mailbox and the files, and you will almost certainly need something from it within the first fortnight. Block sign-in, revoke sessions, and leave the account intact. Deleting is a decision for week four once the mailbox has been converted and the files transferred.

Does blocking sign-in stop someone accessing email on their phone?

Not immediately. Blocking prevents a fresh sign-in; an app that is already signed in keeps working until its token expires, and that can be a long time. Revoking sessions in Entra ID is what actually ends it. If you only do one of the two, the mail app on a personal phone keeps receiving.

Can a departed employee still receive our email?

Yes, if a forwarding rule was set up before they left. Rules run on the mail server rather than in their mail app, so they keep operating after sign-in is blocked, and they generate no sign-in activity for anyone to notice. Check both the inbox rules and the mailbox forwarding setting, which are two different places, and note what you find before removing it.

How long are Microsoft 365 audit logs kept?

It depends on your licence, and the point that matters is that it is finite. A question you can answer easily this week may be unanswerable next quarter. If a departure was difficult and you think you might need to know what was downloaded, exported or shared in the days beforehand, pull that record now rather than waiting until somebody asks for it.

What happens to their OneDrive files?

They stay accessible while the account exists. Once the account is deleted the files are retained for a configurable period and then removed, and the default is shorter than most people assume. Transfer ownership to their manager during the first fortnight rather than relying on the retention window, because the window is a safety net rather than a plan.

Need help managing a departure in your Microsoft 365 environment, including outside business hours?

Offboarding, done right

or call 0403 401 250