⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7
Somebody has resigned and their Microsoft 365 account is now your problem. It is a routine administrative job, it is not difficult, and almost all of the trouble comes from doing the right things in the wrong order.
Here is the order, what each step actually does, and the three or four places where a reasonable-sounding decision quietly costs you something later.
If you have arrived here because somebody left months ago and you have just discovered their account is still live, that is a different conversation and a faster one. Emergency Microsoft 365 support covers it. Everything below assumes you have time to do this properly, which is the better position to be in.
For a planned departure this happens on their last afternoon. For a sudden one it happens now. Either way it is these four things, in this order.
Everyone reaches for Block sign-in first, because it sounds the most final. Microsoft's own documentation says blocking an account can take up to 24 hours to take effect, and that to stop access immediately you reset the password instead. So the fastest lock is the password, the most complete one is signing out of all sessions, and blocking is the thing that makes it stick. You want all three, in that order.
Step 1
This is first, and it is first for a reason that surprises people. It is the only action that takes effect straight away. Everything else on this list is either slower or narrower.
Step 2
On the same screen, on the Account tab. A password change does not close a session that is already open. An access token lasts about an hour, so without this step somebody can keep working in a browser tab that is already signed in. This is the step almost everyone skips.
Step 3
Do it, but do not rely on it as the fast one. Microsoft states that blocking an account can take up to 24 hours to take effect, and points you at the password reset if you need to stop access immediately. It is the durable lock, not the quick one.
Step 4
A work mailbox on a personal phone keeps a cached copy of everything already downloaded. Wipe the company data from the device and block it, which is a separate action from anything above and lives in the Exchange admin centre or Intune.
Closing the account does not close everything the account set up. These four keep working afterwards and none of them are obvious from the Users page.
A rule quietly copying mail to a personal address survives everything above, because it runs on the server rather than in Outlook. Check both the mailbox forwarding setting and the inbox rules, which are two different places. Inbox rules are also preserved when the mailbox is later converted to a shared one, so a rule missed now is a rule still running in six months.
Anything that authenticated once and kept a token: a phone mail app, a third-party add-in, a scheduling tool, a personal note-taking app that was granted access to their calendar. Signing out of all sessions handles most of it. The consents themselves are worth a look in Entra ID, and this is the one place where a short list of what your business actually uses saves a lot of guessing.
The other direction, and the one nobody checks. What did this person have access to? A shared mailbox, a finance folder, a client site, another person's calendar. Removing their account eventually handles it, but between now and then those permissions are live, and the list is also a useful record of what the next person will need.
If they set up guest access for a contractor or a client, that guest is still there when they go. There is more on why that matters in the piece on guest access, linked below.
The 24-hour version of all of this, for when somebody has walked out rather than worked a notice period, is in what to do in the first 24 hours when a staff member leaves unexpectedly, and the guest access point is covered properly in the piece on guest accounts.
This section sits here rather than at the end on purpose. It is the only decision on the page that cannot be revisited, and the moment to make it is before anything is touched.
The question is simple: is there any prospect of a dispute with this person, a claim, an investigation, or a regulator wanting to see something? An unfair dismissal, a customer complaint they handled, an insurance claim in progress, a professional obligation to keep records. If the answer is anything other than a clear no, preserve first and decide later. Preserving costs you almost nothing. Not preserving is irreversible.
When you delete a Microsoft 365 account, the mailbox contents are kept for 30 days and you can get them back by restoring the account. After 30 days they are gone. That is the default, and for most departures it is fine.
If a hold is applied to the mailbox before the account is deleted, the mailbox instead becomes what Microsoft calls an inactive mailbox and is preserved for as long as the hold lasts. If the hold is not applied, or is applied but has not taken effect yet, the conversion does not happen. Microsoft is explicit that you should confirm the hold has applied before deleting the account, and that is the whole game: the option exists right up until the account is deleted, and not for one minute afterwards.
A related trap worth knowing. Once files have moved through to the recycle bin at the end of their retention window, they are still technically there for a while, but the recycle bin is not indexed. A search cannot find content in it, which means a hold cannot reach it either. "It is probably still in there somewhere" is not the same as being able to produce it.
If mail has already gone missing from the mailbox, whether cleared out on a last afternoon or deleted earlier, the windows and what can still be reached are set out on the deleted email recovery page. The short version is that it is usually recoverable for longer than people assume and for less long than they need.
There are several ways to hold a mailbox and they behave differently. Microsoft's current recommendation for this purpose is a retention policy rather than the older litigation hold, and specifically not an eDiscovery case hold, because when the case is closed the inactive mailbox is permanently deleted along with it. If you are already in a dispute rather than anticipating one, the tooling and the process are on the email investigation and eDiscovery page.
Customers, suppliers and colleagues will keep writing to that address for a year. The tidy answer is to convert the mailbox to a shared mailbox: all the mail and calendar stay exactly where they are, several people can be given access, and once the licence comes off it costs nothing.
This order is not optional and it catches people constantly, because the instinct on a departure is to stop paying for the seat immediately. The option to convert does not appear on an unlicensed mailbox. Remove the licence first and you have to put one back on before you can convert, which usually means buying a seat you had just stopped paying for.
The other condition is size. An unlicensed shared mailbox holds up to 50 GB. If theirs is bigger than that, the licence cannot come off until it is smaller, so a large mailbox needs either some tidying or a licence that stays on it.
Do not delete the user account. The shared mailbox needs it as an anchor and deleting it means restoring the account and starting over. But leaving it there has a consequence people miss: unless you reset the password, the original username and password keep working on the converted mailbox. Reset it, leave sign-in blocked, and leave it blocked permanently. A shared mailbox is never meant to be signed into directly.
If you are not certain a shared mailbox is even the right destination for this address, that is worth settling first. Microsoft 365 Groups, distribution lists and shared mailboxes compares all three, including what each one costs you in licensing and what happens to them over the following five years.
Give access to whoever is genuinely picking up the work, usually one person and their manager, not the whole team because it is easier. Set an out of office that tells senders who to write to now, so the shared mailbox becomes a safety net rather than a destination.
Then the question that almost never gets asked: for how long? Access granted at an offboarding is access that is still there in three years, because nothing ever prompts anybody to remove it. Write a date down, six months is usually right, and put it somewhere you will see it. That single habit is most of what governance means at this scale, and there is more on it at the end of this page.
Anything in a SharePoint site or a Teams channel is owned by the site rather than by the person, so it stays put and nothing needs doing. OneDrive is the opposite, and OneDrive is where the work-in-progress lives: the quote that was nearly finished, the spreadsheet nobody else has a copy of.
Move what matters somewhere owned, into a SharePoint site or Teams, before the account is deleted. Doing it in that order costs a few minutes. Doing it afterwards means working against a clock.
The retention countdown on a OneDrive starts when the account is deleted from Entra ID. Blocking sign-in does not start it and removing the licence does not start it, which is genuinely useful to know: an account that is blocked and unlicensed is not losing anything.
Once deleted, the default retention is 30 days, and it is adjustable at tenant level. By default the person's manager is automatically given access to the OneDrive and emailed about it, with a reminder seven days before the end. That default only works if the manager field is filled in on the account. If it is empty and no secondary owner has been configured, nobody is given access and nobody is warned, and the first anyone knows is that the files have gone.
After that the OneDrive goes to a site collection recycle bin for 93 days, from which recovery needs PowerShell rather than a button. It is a real second chance and it is not one you want to be relying on.
This changed on 1 July 2026 and it undoes the most common informal habit in small business offboarding, which is to strip the licence, leave the account sitting there, and deal with it never.
An unlicensed OneDrive now goes read-only at 60 days and is archived at 93, at which point neither you nor anybody else can get at the contents without an admin taking a deliberate step. At 275 days it stops being available to eDiscovery. At 365 cumulative unpaid days it becomes subject to deletion.
The part to read twice concerns accounts that are unlicensed and unpaid, meaning no licence and no billing enabled for unlicensed OneDrive storage. Microsoft's wording is worth reading directly rather than through me:
"the unlicensed accounts will be subject to deletion 365 days after being unlicensed even if retention policies, settings, or holds exist on the OneDrive account"
So a hold you were relying on is not a guarantee if the account underneath it is neither licensed nor paid for. If you are keeping something, keep it somewhere it is actually being kept.
This section is current as at July 2026. The policy took effect on 1 July 2026 and Microsoft's page is new enough that it may still be revised, so check the link above against your own situation before relying on the dates.
Once the mailbox is converted and under 50 GB, the licence comes off and the shared mailbox carries on without one. That is the whole saving, and it is why offboarding done properly and licensing done properly are the same job seen from two directions.
There is one more step, and it is the single most common piece of wasted spend I see. Taking the licence off the person does not reduce your bill. It returns the seat to your pool, where it carries on billing exactly as before. To actually stop paying you have to lower the licence count on the subscription itself, which is a different screen in a different part of the admin centre. Do it, or a year of departures becomes a row of paid-for seats that nobody holds.
It compounds quietly, because nothing about it looks wrong. The invoice goes up by one seat at a time and never comes back down. There is a fifteen-minute self-check for exactly this on the licensing review page, and leavers are the first thing it looks for.
Short enough to hand to whoever does your HR admin, and in the order that matters. Copy it, put it in your offboarding folder, and it stops being something anybody has to remember.
Steps one to four are the same whether somebody resigned politely or was walked out. Everything after that can wait until the next working day.
A checklist handles the departure in front of you. It does nothing about the residue, and the residue is what actually accumulates: delegated access granted three departures ago, a shared mailbox nobody has opened since 2023, four accounts parked unlicensed because it seemed safer than deleting them.
Alongside this work I design and run automated lifecycle governance for thousands of shared mailboxes in an environment of around 200,000 users. Access is granted for a defined period rather than indefinitely, so it expires on its own and somebody has to make a decision to renew it. Hold and audit settings are enforced by policy rather than applied by hand, so a mailbox cannot quietly end up outside them. Archiving is driven by actual usage, so nothing sits unowned for years because no one remembered it existed.
The reason that is worth mentioning is not the size of it. It is that the discipline scales down almost perfectly, and at twenty people it costs an afternoon.
Delegated access to a departed person's mailbox granted with an end date rather than forever. The default answer at the review is remove, and somebody has to argue for keeping it.
Twice a year, a list of who still has access to what. Fifteen minutes. The value is not the list, it is that the list exists at all and somebody has to look at it.
Every blocked, unlicensed account either has a reason to still exist or is finished with. Since July 2026 the second kind quietly degrades on its own timetable.
The longer version of the reasoning, and why identity lifecycle is worth treating as a process rather than a series of favours, is in the article on offboarding and identity lifecycle.
Two sensible options, depending on which problem you actually have.
If the question is what state your tenant is in after a few years of departures handled ad hoc, that is the Microsoft 365 Health Check, $599 GST inclusive and fixed. Stale access, parked accounts and licensing waste are three of the things it looks at, and offboarding residue tends to show up in all three at once.
If you just want the current one done properly by somebody who has done it a few hundred times, that is ordinary Microsoft 365 support and it is usually an hour.
Including the awkward ones. If it is a five-minute answer you will get a five-minute answer, not a proposal.
Prefer to talk it through? Call 0403 401 250 or email jamie@hamilton365.com.au