What Happens to Your M365 Accounts When Staff Leave? The Identity Lifecycle Problem Most SMBs Ignore
By Jamie Hamilton · Published · Updated
A staff member leaves. HR processes the paperwork, somebody disables their computer login, and everyone moves on. Three months later the Microsoft 365 account is still active, the mailbox is still receiving, the OneDrive files are still there, and if they left on bad terms there is a reasonable chance they still know the password.
This is the most common finding when reviewing a Microsoft 365 tenant for a small business, and it is almost never negligence. It happens because offboarding is split across people who each think somebody else owns the tenant.
Why the account survives the person
Three separate things have to happen when somebody leaves, and in most small businesses only the first two have an owner. HR closes the employment. Whoever manages the computers takes the laptop back and disables the local login. Nobody owns the tenant, so the Microsoft 365 account, which is the one that actually holds the email and the files and can be reached from any device in the world, is the one left running.
It survives because nothing complains. A licensed account with no user generates no error, no alert and no bill line item that reads differently from the others. It just keeps working.
What is an orphaned account?
An orphaned account is any account in your Microsoft 365 environment that is no longer actively managed, usually because the person it belonged to has left, changed roles, or never was a person in the first place.
They come in four forms, and they need different answers:
- •Active user accounts with no active user. The licence is assigned, sign-in works, and anyone with the credentials reaches everything that person could reach.
- •Shared mailboxes with no owner. The accounts@ and support@ addresses that accumulate until nobody is certain who reads them.
- •Distribution lists still containing people who left, so internal mail keeps being addressed to them.
- •Guest accounts belonging to contractors and vendors whose engagement finished. These sit in a different part of the directory and are covered separately.
Why they are a genuine risk rather than untidiness
Four reasons, in the order they tend to matter.
The first is simply that a live account is a live key. It does not need the former employee to do anything malicious. It needs one reused password to appear in somebody else's breach, and credential stuffing does the rest. An account nobody is watching is also an account whose unusual sign-in nobody questions.
The second is the mailbox rather than the account. Inbox rules keep running after a sign-in block, so a forwarding rule set up before somebody left continues to copy mail out of the business indefinitely, and it does not show in any sign-in report because no sign-in occurs.
The third is cost, and it is the one that gets attention fastest. Every licence assigned to somebody who left is billed monthly until it is reclaimed, and the money is only the visible part. The licence count is also what tells you how big the business is when you next negotiate, so it distorts the number you plan against.
The fourth is that under the Australian Privacy Act you are responsible for personal information you hold, including whatever sits in a mailbox nobody has looked at in a year. Holding it in an account you have stopped managing is harder to defend than holding it deliberately.
The shared mailbox problem
Most shared mailboxes are created in a hurry and never revisited. The person responsible leaves, somebody else half-manages it, and eventually nobody is sure who owns it.
Two things go wrong. Customer mail arrives in a mailbox nobody is actually reading, which is a commercial problem rather than a security one and usually the more expensive of the two. And permissions granted to make it work in the first place, often full access for everyone who might need it, quietly outlive the reason for them.
A shared mailbox with no owner named anywhere is the default state. Naming one, in writing, is most of the fix.
The licence and the data are two separate decisions
This is the part that catches people, because removing the licence feels like the tidy ending and it is the step that destroys things.
Converting a departed user's mailbox to a shared mailbox lets a colleague keep reading it without a licence, which is usually the right answer. It has a limit: an unlicensed shared mailbox is capped at 50GB, and if the mailbox is larger than that, or has an archive, or is under a hold, it still needs a licence. Checking the size before you convert takes a moment and saves an argument later.
Removing a licence without converting first starts a clock. The mailbox contents become unavailable and are then removed, and past that point the recovery options get expensive or stop existing. Deleting the user account itself is recoverable for 30 days in Entra ID and not after. Their OneDrive is retained for a period after the account is deleted, which is configurable and shorter than most people assume.
None of that matters until the day somebody asks for a document the departed person owned, at which point all of it matters at once.
What good offboarding actually looks like
On the day of departure:
- •Block sign-in, then revoke active sessions, in that order. Blocking alone does not end a session already running.
- •Reset the password, so an old credential cannot be reused if the block is ever lifted.
- •Check the mailbox for forwarding rules before doing anything else to it.
- •Remove admin roles immediately, ahead of everything else if they had any.
- •Reassign ownership of any group, Team or SharePoint site where they were the only owner, before removing them from it.
Within the first week:
- •Work out what they actually had access to, which is usually more than anybody remembers
- •Convert the mailbox to a shared mailbox, after checking it is under the unlicensed size limit
- •Reclaim the licence once the mailbox is safe
- •Transfer ownership of their OneDrive files to their manager
Within 30 days:
- •Decide whether the account is archived, deleted or retained, and write the decision down
- •Review whether the shared mailbox still needs to exist, and name an owner if it does
- •Remove them from distribution lists, which is the step that gets missed because nothing breaks when it is skipped
Is your tenant affected?
Open the Microsoft 365 admin centre, go to active users, and add the last sign-in column. Sort by it. Any licensed, unblocked account with no sign-in in 90 days is worth a look, and in most tenants that list is longer than the owner expects.
Do the same for shared mailboxes and ask a simpler question of each one: who reads this? If the answer takes more than a few seconds, that mailbox is the one to start with.
Frequently asked questions
What is an orphaned account in Microsoft 365?
It is an account nobody is actively managing any more, most often because the person it belonged to has left. It still has a licence, it can still sign in, and it still holds whatever email and files that person had. It generates no error and no alert, which is exactly why it survives: nothing in Microsoft 365 complains about an account that simply is not being used.
Should I delete a departed employee Microsoft 365 account?
Not straight away, and usually not at all in the first instance. Convert the mailbox to a shared mailbox so a colleague can keep reading it, transfer the OneDrive files, and only then reclaim the licence. Deleting the account is recoverable for 30 days in Entra ID and not after that, and the mailbox and files go with it. The tidy-looking step is the one that destroys things.
Does blocking sign-in log someone out of Microsoft 365?
No, and this is the step most often missed. Blocking sign-in stops new sign-ins. A session already running continues until its token expires, which can be a long time. You have to revoke the sessions explicitly, in Entra ID, as a separate action. Until you do, somebody with an open session on a phone still has access to mail and files.
Do inbox rules keep working after an account is disabled?
Forwarding rules keep operating even when the account cannot be signed into, because the rule runs on the mail server rather than requiring the user to be present. A forwarding rule set up before somebody left will keep copying mail out of the business, and it will not appear in any sign-in report because no sign-in happens. Check the mailbox rules before you do anything else to it.
Can I keep a departed employee mailbox without paying for a licence?
Usually yes. Converting it to a shared mailbox means it can be read without a licence, which is the normal answer for a departed staff member whose mail still needs monitoring. The limit is 50GB. Above that, or if the mailbox has an online archive or is under a legal hold, it still needs a licence, so check the size before converting rather than after.
How do I find orphaned accounts in my tenant?
In the Microsoft 365 admin centre, open active users and add the last sign-in column, then sort by it. Any account that is licensed, not blocked, and has not signed in for 90 days is worth investigating. Do the same review for shared mailboxes, asking who reads each one. Guest accounts sit in a different place again, in Entra ID, and need their own pass.
Related Articles
Not confident your Microsoft 365 tenant reflects who actually works for your business today?
Offboarding, done rightor call 0403 401 250