⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Identity & Security12 min read

What Happens to Your M365 Accounts When Staff Leave? The Identity Lifecycle Problem Most SMBs Ignore

Picture this: a staff member leaves your business, maybe on good terms, maybe not. HR processes the paperwork, IT disables their computer login, and everyone moves on. Three months later, their Microsoft 365 account is still active. Their email is still receiving messages. Their OneDrive files are still accessible. And if they left on bad terms, there’s a reasonable chance they still know their password.

This isn’t a hypothetical. It’s one of the most common security gaps I find when reviewing M365 tenants for small and medium businesses in Brisbane.

What Is an Orphaned Account?

An orphaned account is any user account in your Microsoft 365 environment that is no longer actively managed, typically because the person it belonged to has left the organisation, changed roles, or never existed as a real employee in the first place.

Orphaned accounts come in several forms:

  • Active user accounts with no active user. The account exists, the licence is assigned, and someone with the right credentials can sign in and access everything that person had access to
  • Shared mailboxes with no owner: things like accounts@ or support@ that accumulate with no clear ownership
  • Distribution lists with departed members still included
  • Guest accounts from former contractors or vendors

Why Orphaned Accounts Are a Genuine Security Risk

  • Disgruntled former employees: the majority of insider threat incidents occur within 30 days of someone leaving
  • Credential stuffing attacks: if a former employee reused their work password on a breached service, attackers will try it against your M365 tenant
  • Licence costs you’re not aware of: every active licence assigned to a departed user is wasting $10 to $60/month
  • Compliance exposure: retaining active accounts for departed staff can create issues under the Australian Privacy Act

The Shared Mailbox Problem

Most small businesses create shared mailboxes organically. Over time, the person responsible leaves, another person half-manages it, and eventually nobody is sure who owns it. The risks are twofold: customer communications landing in an unmonitored mailbox are being missed, and misconfigured shared mailboxes can give broad access to sensitive communications.

What Good Offboarding Actually Looks Like

On the day of departure:

  • Convert the user account to a shared mailbox
  • Remove from all distribution groups, M365 Groups, and Teams
  • Revoke all active sessions, because simply disabling an account does not immediately terminate them
  • Remove access to SharePoint sites and shared resources
  • Review and remove any admin roles immediately

Within the first week:

  • Audit what data the user had access to
  • Check for forwarding rules on their mailbox
  • Reassign ownership of any files, SharePoint sites, or M365 Groups

Within 30 days:

  • Decide on long-term account status: archive, delete, or retain
  • Review whether shared mailboxes still need to exist and assign clear ownership

Is Your Tenant Affected?

Open the Microsoft 365 Admin Centre and look at your active users list. Sort by last sign-in date. If you see accounts with no sign-in activity in the last 90 days that are still licensed and active, you have orphaned accounts worth investigating.

Not confident your M365 tenant reflects who actually works for your business today?

or call 0403 401 250