Your M365 Tenant After a Staff Member Leaves Unexpectedly, What to Do in the First 24 Hours
Someone resigns without notice, is terminated, or leaves under difficult circumstances. Your M365 tenant should be among the first things you deal with, because the window between someone leaving and their access being removed is a window of real risk.
Why the First 24 Hours Matter
The majority of insider threat incidents occur within 30 days of someone leaving. An active M365 account is an active key to your business.
Step 1: Block Sign-In (Not Delete)
In the M365 Admin Centre, find the user and select “Block sign-in.” This prevents new sign-ins but preserves the account and its data. Do not delete the account yet.
Step 2: Revoke Active Sessions
Blocking sign-in doesn’t terminate active sessions. In the Entra ID portal, select the user and click “Revoke sessions.” This step is frequently missed.
Step 3: Reset the Account Password
As an additional safety measure, reset the password to ensure old credentials can’t be used.
Step 4: Check for Email Forwarding Rules
Check for inbox rules forwarding email to personal addresses. These continue to operate even after sign-in is blocked. Remove any forwarding rules and disable auto-forwarding.
Step 5: Remove from Groups, Teams, and Shared Resources
Pay particular attention to Groups or SharePoint sites where the departing person was the sole owner. Assign a new owner before removing them.
Step 6: Check Admin Roles
If the departing person had any admin roles, remove those immediately.
Step 7: Preserve and Transition Email
Convert their mailbox to a shared mailbox so a colleague can monitor it without consuming a licence.
Step 8: Audit Recent Activity (If Warranted)
If the departure is acrimonious, review recent M365 activity in the Microsoft Defender and Purview portals. Conduct the review promptly, because audit logs have retention limits.
Related Articles
Need help managing a staff departure in your M365 environment, including outside business hours?
or call 0403 401 250