DEV Community

AdminPackStudio
AdminPackStudio

Posted on

An offboarding checklist for M365 + Intune admins — disable vs delete, license reclaim, and the device decision

Offboarding in M365 + Intune: a leaver checklist that doesn't lose data or leave doors open

Offboarding usually goes wrong in one of two ways:

  1. Too slow. The account stays usable for days, an old phone still syncs mail, or a SaaS admin login nobody tracked keeps working.
  2. Too fast. Someone deletes the user or pulls the license on day one, and the manager loses the mailbox and OneDrive files they needed.

This is the short version of a leaver process for Microsoft 365 + Entra ID + Intune, for admins authorized to manage their tenant. Follow your HR, legal, and retention policies first. Retention periods and admin-center labels change over time, so check the current Microsoft docs before you rely on any number here.


1. Disable first, delete much later

Disable (block sign-in) Delete the user
What it does Stops new sign-ins. Data, groups, and licenses stay put until you change them Soft-deletes the account; it can be restored for a limited window (30 days by default), then it's gone for good
Reversible? Yes, right away Only during the soft-delete window
Mailbox / OneDrive Still there Start their own retention clocks; data is lost when those run out unless a hold or retention policy keeps it
When Last day, at the agreed time After handoff is done and retention/legal requirements are met (often 30+ days)

Default rule: disable on the last day, delete only after the handoff is finished. A disabled account costs you almost nothing for a few weeks. An early delete can lose data you can't get back.

Hybrid tenants: if the account syncs from on-prem AD, disable it in AD. If you only block it in the cloud, the next sync can turn it back on. (It's one of the most common "leaver still signing in" causes.)


2. The last-day sequence

Order matters. Use this as a starter, then adjust to your policy:

Before last day:  Confirm date/time with HR. Flag privileged or VIP accounts.
                  Agree who receives mailbox + OneDrive + Teams/SharePoint ownership.
                  Check for legal hold / litigation requirements.
Last day (agreed time):
  1. Block sign-in (on-prem AD first if hybrid).
  2. Revoke sessions / refresh tokens (Entra admin center → user → Revoke sessions).
  3. Remove privileged roles and PIM eligibility.
  4. Reset the password if your policy requires it.
  5. Review MFA methods; remove ones tied to shared or company phones per policy.
  6. Remove from groups, except license groups until mailbox handoff is done.
  7. Mailbox: convert / delegate / auto-reply per HR (section 3).
Day +1..7:        Check sign-in logs for failed attempts or other surprises. Make the device decision (section 4).
                  Disable non-SSO SaaS accounts. Rotate shared secrets the user knew.
Day +30 / policy: Reclaim the license if it isn't already gone, delete the account, close the ticket with evidence.
Enter fullscreen mode Exit fullscreen mode

Two things to know:

  • Revoking sessions isn't instant everywhere. Some apps hold access tokens until they expire (often up to about an hour), and apps using continuous access evaluation react faster. Block sign-in and revoke sessions, then check the sign-in logs the next day.
  • Rotate secrets as work items. If the leaver knew a shared admin password, a Wi-Fi key, or an API key, track the rotation in your ticket system. Never paste the secret into the ticket.

3. Mailbox and OneDrive handoff (high level)

Mailbox: common options are:

  • Convert to a shared mailbox and give the manager or team access. Convert before you remove the license. Shared mailboxes have size limits without a license (check current docs), and hold or archive features may still need one.
  • Delegate access (Full Access / Send As) for a fixed period with an end date.
  • Auto-reply pointing senders to the right contact. Avoid forwarding to external addresses; many orgs block it on purpose.

OneDrive:

  • Set the manager (or named delegate) to receive access. In many tenants, deleting the user gives the manager access automatically for the OneDrive retention period. Confirm your tenant's retention setting so nobody gets surprised.
  • Tell the receiver what to move and the deadline. Files that matter to the team belong in a SharePoint/Teams site, not in a former user's OneDrive.

Teams / SharePoint: if the leaver was the only owner of a Team, group, or site, add a new owner first. Ownerless groups turn into cleanup work later.


4. The device decision: retire vs wipe (it's a judgment call)

Intune gives you device actions in the admin center. Pick one based on who owns the device and what policy and legal holds require:

Situation Usual direction Notes
Personal (BYOD) phone or PC Retire Removes company data, managed apps, and profiles. Leaves personal data alone
Corporate device, returned to IT Reset for reuse, per your reimage process Check legal hold first. Keep the Autopilot record if the hardware stays in the fleet
Corporate device, not returned Escalate per policy; a remote wipe may be appropriate Get documented approval. Lost/stolen handling differs from "employee kept the laptop"
Device under legal hold / investigation Don't touch it until counsel clears it Wiping evidence is a serious problem
Hardware leaving the org for good Remove it from Autopilot / Intune after the reset Otherwise the next owner hits your enrollment

Treat retire and wipe as deliberate, approved actions done by an authorized admin in the Intune admin center, with the ticket ID recorded. Don't fire them off from a quick script at 5pm on a Friday. Confirm ownership (corporate vs personal) in the device record before you click.


5. License reclaim without breaking things

Pulling licenses too early is the most common way offboarding causes data loss.

  • Order: convert the mailbox / finish handoff → then remove the license. Removing an Exchange license starts a countdown on the mailbox data unless a hold or a shared-mailbox conversion protects it.
  • Group-based licensing: if licenses come from groups like LIC-M365-E3, removing the user from the group removes the license. Keep that membership until handoff is finished, then remove it on purpose.
  • Weekly orphan check: look for accounts that are disabled but still licensed. That's money spent on nobody. A read-only Graph query is enough:
Connect-MgGraph -Scopes 'User.Read.All'

Get-MgUser -All -Filter 'accountEnabled eq false' -Property 'displayName','userPrincipalName','assignedLicenses','accountEnabled' |
  Where-Object { $_.AssignedLicenses.Count -gt 0 } |
  Select-Object DisplayName, UserPrincipalName, @{n='LicenseCount';e={$_.AssignedLicenses.Count}}
Enter fullscreen mode Exit fullscreen mode

It only reads. Review the list with whoever owns licensing before you change anything. Some disabled accounts are kept licensed on purpose, for holds or shared mailboxes over the size limit.

Conditional Access and break-glass awareness

  • CA exclusion groups: if the leaver was in a Conditional Access exclusion group (travel exceptions, legacy-app exceptions, "temporary" bypasses), remove them. Exclusions outlive the people they were made for.
  • Break-glass accounts: don't disable or delete your emergency-access accounts as part of someone's offboarding. If the leaver knew or held break-glass credentials (password, FIDO key, safe combination), rotate them and record that you did, using your normal break-glass procedure.
  • Admins leaving: check what they owned: app registrations, service principals with their own credentials, automation accounts, scheduled flows running as them. Reassign ownership before those quietly break or stay unowned.

If your CA exclusions and break-glass setup have drifted, the Entra ID Conditional Access Starter Pack ($29) covers exclusion hygiene and emergency-access patterns: https://cashflow4375.gumroad.com/l/nhuyrc


6. Evidence: close the ticket like an auditor will read it

A few lines per leaver saves a painful audit later:

Leaver ticket / Last day / Sign-in blocked (time) / Sessions revoked (time) /
Roles removed / Groups removed / Mailbox action / OneDrive delegate /
Device action + approver / License removed (date) / Account deleted (date) /
Performed by (role) / Verified by (role)
Enter fullscreen mode Exit fullscreen mode

Record roles, not personal names, if the evidence gets shared widely.


Common mistakes

Mistake What happens Fix
Delete on day one Manager loses mail/files; restore window runs out Disable first; delete after handoff + retention
License removed before mailbox conversion Mailbox data starts expiring Convert/delegate first, then reclaim
Cloud-only block on a synced account Account comes back after the next sync Disable in on-prem AD
Leaver was sole Team/site owner Ownerless groups, nobody can manage access Add new owners before the last day
Wiping a device under legal hold Evidence destroyed Check holds; get approval for any wipe
Forgetting CA exclusions / break-glass knowledge Old exceptions and known secrets linger Remove exclusions; rotate what they knew
Non-SSO SaaS logins ignored Access continues outside Entra Keep a SaaS inventory in the checklist

Want the full joiner / mover / leaver checklists?

The Entra ID Joiner-Mover-Leaver Ops Pack ($29) from Admin Pack Studio turns this into repeatable checklists: joiner day-1 definition of done, a mover access-diff worksheet, leaver timeline lanes and a revoke checklist, group-based licensing and orphan hunts, plus audit evidence and JML break/fix cards. The one bonus script writes a blank local checklist CSV. It makes no tenant calls and takes no account or device actions.

👉 https://cashflow4375.gumroad.com/l/vljmze

Managing the device side too? The Intune & M365 Admin Starter Pack ($19 during launch week; normally $29) covers enrollment hygiene, compliance baselines, inventory snapshots, and break/fix cards, with read-only PowerShell scripts: https://cashflow4375.gumroad.com/l/joonf


Admin Pack Studio. Not affiliated with Microsoft. Operational guidance for admins authorized to manage their tenant and devices. Follow your HR, legal hold, and retention policies, and check current Microsoft documentation for retention periods and admin-center steps.

Top comments (0)