Employee Offboarding: The 7 Access Gaps That Outlive a Departure

Oct 8, 2026

0 Comments

Employee Offboarding: The 7 Access Gaps That Outlive a Departure

An employee’s last day is not the end of your security risk. It is the start of the highest-risk 48-hour window in the offboarding process.

Accounts may remain active. Shared passwords may still work. Email forwarding rules may continue sending messages outside the company. A former employee may still have a VPN profile, SaaS token, door badge, or recovery method tied to their identity.

That does not mean every departure is hostile. It means your process should not depend on goodwill, memory, or a rushed checklist.

We recommend treating offboarding as a controlled access-revocation project. The goal is simple: remove access, preserve business continuity, protect company data, and leave a clear record of what happened.

This is a core part of cybersecurity consulting, IT infrastructure management services, and reliable managed IT support.

WHY THE FIRST 48 HOURS MATTER

The highest-risk period begins when an employee’s departure becomes effective. That may be a scheduled separation, an unexpected termination, or a resignation with a notice period.

During that window:

  • The employee may still know current passwords.
  • Active sessions may remain open on personal devices.
  • Admin privileges may not be visible in the main directory.
  • Third-party applications may not be connected to your SSO.
  • Physical access may continue until a badge or door code is disabled.
  • Business-critical files and accounts may still be owned by one person.

A good process begins before the last day. It also continues after the account is disabled.

Atlassian’s offboarding guidance and SHRM’s security recommendations both point to the same principle: HR, management, and IT must work from one documented workflow.

THE 7 ACCESS GAPS THAT OUTLIVE A DEPARTURE

Seven access pathways connected to a fading employee identity

1. ACTIVE DIRECTORY AND SSO ACCOUNTS REMAIN ACTIVE

Disabling an email account does not always disable every connected account.

An employee may still have access through:

  • Active Directory or Microsoft Entra ID
  • Google Workspace
  • Okta or another identity provider
  • SSO-connected applications
  • Local accounts on servers or workstations
  • Administrative groups
  • Cloud consoles and file shares

The first action should be disabling the primary identity. Then revoke active sessions, refresh tokens, group memberships, delegated permissions, and administrative roles.

Do not assume that removing a user from one system removes access everywhere. That only happens when your applications are properly connected to centralized identity management.

2. SHARED AND SERVICE ACCOUNT CREDENTIALS ARE STILL KNOWN

Shared accounts create a common offboarding problem. The account may belong to the company, but the departing employee may know the password.

Examples include:

  • Vendor portals
  • Shared administrator accounts
  • Social media accounts
  • Network equipment
  • Accounting platforms
  • Password vaults
  • Service accounts used by automation
  • Local administrator accounts

Rotate credentials when the employee had access. Do not simply change the employee’s personal password and consider the job complete.

Also review service accounts and integrations they created or managed. A service account can continue operating long after its human owner leaves.

3. MFA DEVICES AND RECOVERY METHODS STAY TIED TO THE PERSON

Multi-factor authentication protects an account only if the company controls the authentication methods.

Check whether the departing employee’s account includes:

  • A personal phone number
  • An authenticator app on a personal device
  • A personal recovery email
  • Backup codes
  • Security questions
  • A hardware security key
  • A trusted device or remembered browser

Remove those factors and confirm that at least two authorized administrators can recover the account.

For shared administrative accounts, re-enroll MFA under company-controlled devices or hardware tokens. Store backup codes in a managed password vault, not in an employee’s personal notes.

4. EMAIL FORWARDING AND DELEGATION CONTINUE QUIETLY

Email access can survive an employee’s departure through rules and delegation.

Review:

  • External forwarding rules
  • Inbox rules that redirect messages
  • Mailbox delegation
  • Shared mailbox permissions
  • Calendar delegation
  • Mobile mail sessions
  • Connected email applications

External forwarding should be disabled by default. If the mailbox needs to remain active, convert it to a monitored shared mailbox or route messages to a team address for a defined period.

Avoid forwarding business email permanently to one individual. Shared ownership is more resilient and easier to audit.

5. THIRD-PARTY SAAS SEATS AND API KEYS ARE MISSED

Small and mid-size businesses often use more applications than they realize. A departing employee may have access to tools that are not managed by IT.

Look beyond your primary email and file systems:

  • CRM platforms
  • Accounting and payment tools
  • Project management software
  • Marketing platforms
  • HR systems
  • Code repositories
  • Cloud hosting
  • Domain registrars
  • DNS providers
  • Customer support systems
  • Vendor portals

Remove the user’s seat, transfer ownership, and revoke API keys or personal access tokens. Check whether they created integrations under their own account.

This is where a current access inventory pays for itself. If you do not know which applications exist, you cannot reliably remove access.

6. VPN AND REMOTE ACCESS REMAIN AVAILABLE

Remote access tools can create a direct path into your environment.

Disable or remove:

  • VPN accounts and profiles
  • Remote desktop permissions
  • SSH keys
  • Remote management tools
  • NAS access
  • Firewall rules tied to the user
  • Personal devices registered for remote access
  • Saved credentials on company endpoints

If a company device is not returned, lock it remotely when possible. Confirm that full-disk encryption is enabled and remove the device from trusted access lists.

VPN access is only one part of the review. Also check server-level permissions and tools that may allow remote control outside the main VPN.

7. PHYSICAL ACCESS IS NOT DISABLED

Digital access is only half of offboarding.

Recover or disable:

  • Building badges
  • Office keys
  • Door codes
  • Alarm credentials
  • Server-room access
  • Security tokens
  • Company credit cards
  • Laptops and mobile devices
  • USB drives
  • Printed credentials

Update door codes when they were shared with the departing employee. For remote employees, confirm the return or remote lock of company equipment.

Physical access should be included in the same offboarding ticket as digital access. Separating the two makes missed steps more likely.

A PRACTICAL OFFBOARDING TIMELINE

A secure operations dashboard organized by offboarding dates and completed access reviews

DAY -7: PLAN AND INVENTORY

For a planned departure, begin at least seven days ahead.

  • Confirm the effective departure date and time.
  • Identify the manager responsible for the handoff.
  • Export or review the employee’s access list.
  • Identify files, customers, projects, and accounts requiring ownership transfer.
  • List company devices, badges, keys, and tokens.
  • Identify shared credentials that must be rotated.
  • Confirm who will approve and verify the work.

For an unexpected termination, move directly to the day-zero process.

DAY -1: PREPARE THE CHANGES

Before the final day:

  • Prepare account-disable actions.
  • Confirm administrator access and break-glass accounts.
  • Prepare mailbox and file ownership transfers.
  • Schedule badge and door-code changes.
  • Prepare password rotations.
  • Confirm device-return arrangements.
  • Notify only the people who need to know.

The goal is to remove avoidable decisions from the most sensitive part of the process.

DAY 0: REVOKE AND RECOVER

At the agreed departure time:

  1. Disable the primary identity in your directory or identity provider.
  2. Revoke active sessions, tokens, VPN access, and remote access.
  3. Remove privileged roles and group memberships.
  4. Disable forwarding and delegation.
  5. Remove SaaS access and transfer ownership.
  6. Rotate shared passwords, API keys, and service credentials.
  7. Disable badges, keys, and door codes.
  8. Recover or remotely lock company devices.
  9. Record each completed action.

For an involuntary termination, coordinate the sequence carefully. Access revocation and the employee meeting may need to happen at the same time.

DAY +7: VERIFY AND CLEAN UP

A completed checklist is not the same as a verified checklist.

Within seven days:

  • Review sign-in and VPN logs for unexpected activity.
  • Check for continued use of former credentials.
  • Search for orphaned SaaS accounts.
  • Confirm file, mailbox, and project ownership transfers.
  • Review new forwarding rules and admin changes.
  • Confirm all physical assets were returned.
  • Remove the former employee from distribution lists and contact records.
  • Close the offboarding ticket only after verification.

Proton’s business guidance and Kaspersky’s offboarding recommendations both emphasize post-departure review. That follow-up catches the access gaps that a same-day checklist misses.

KEEP YOUR ACCESS INVENTORY CURRENT

Offboarding becomes a scramble when your inventory is outdated.

Maintain one controlled record showing:

  • Employee and contractor identities
  • Job role and department
  • Primary identity provider
  • Applications and groups
  • Privileged access
  • VPN and remote access
  • Hardware assignments
  • Badge and key assignments
  • Shared accounts they can access
  • Service accounts they own or manage
  • MFA and recovery ownership
  • Last access review date

Review the inventory at least quarterly and whenever someone changes roles. Use SSO where practical. Assign application owners. Require managers to approve access changes.

For a small business, the scope can be manageable:

  • A basic checklist and access map can be created in one to two weeks.
  • A broader identity and application inventory often takes two to six weeks, depending on the number of systems.
  • Ongoing access reviews can run monthly or quarterly through an internal team or managed IT services provider.

The exact effort depends on your environment. We will be direct about that. A simple Microsoft 365 environment is different from a business with multiple cloud platforms, legacy servers, and dozens of SaaS applications.

WHEN TO GET HELP

You may need support if:

  • No one owns the offboarding process.
  • Employees have broad administrative access.
  • You cannot identify all business applications.
  • Shared passwords are common.
  • Former employees still appear in active-user reports.
  • HR and IT use separate systems.
  • Your team cannot verify VPN, cloud, or physical access.
  • You need to improve identity controls without disrupting operations.

Five 9 can help with the access inventory, workflow design, identity review, and ongoing managed IT services for small business. We focus on reliable controls and knowledge transfer. Our goal is not to make you dependent on us. Your team should understand the process and know what happens at every stage.

START WITH AN HONEST CONVERSATION

You do not need a perfect environment before improving offboarding.

Start by answering three questions:

  1. Who triggers the offboarding process?
  2. Where is the complete access inventory?
  3. Who verifies that access was actually removed?

If the answers are unclear, that is the first issue to fix.

Contact Five 9 LLC for a no-pressure conversation about your current process. We can review your environment, explain the gaps, and outline practical next steps for your budget and timeline. No hard sell. Just an honest assessment and a plan you can maintain.

Five 9 Assistant

Automated · not a live person