Identity Security6 min read

The day an employee leaves: a secure off-boarding checklist for Israeli SMBs

Hiring gets a process. Leaving often does not, and the forgotten account is where the risk sits. A practical checklist for cutting off access cleanly when someone moves on.

#Offboarding#Identity Security#Microsoft 365#SMB

Every small business has a routine for bringing someone on: set up the email, order a laptop, add them to the right groups. Far fewer have a routine for the reverse. When an employee leaves, the focus is on the handover and the goodbye, and the quiet technical work of closing accounts gets done from memory, if it gets done at all. Weeks later there is still an active mailbox, a VPN login that works, and a saved password in a system nobody thought about. Most of the time nothing happens. The times it does happen are expensive, and they are entirely avoidable with a checklist.

Why Leftover Access Is a Real Risk

A dormant account that still works is a liability whether or not the former employee ever misuses it. It is one more login an attacker can target, protected by a password that will never be changed again and watched by nobody. Departures that end on bad terms add a second, sharper risk: someone who knows exactly where the valuable data sits and still has the keys to reach it. And even an amicable leaver can cause damage by accident, if a personal device keeps syncing company files long after the last day. There is a quieter cost too, because an account no one owns is one no one is checking, so unusual activity on it can run for weeks before anyone notices. The point of off-boarding is not to assume the worst about people. It is to make sure the door actually closes.

Start Before the Last Day

Good off-boarding begins before the person walks out, not after. As soon as a departure is known, agree a plan between whoever handles HR and whoever handles IT: what gets disabled, when, and who confirms it is done. Timing matters. Cutting access too early creates a scramble, cutting it too late leaves a window. For a planned, friendly departure the aim is usually to disable everything at the end of the final working day. For a difficult exit, access should be revoked at the moment the person is informed. Deciding this in advance, rather than improvising, is what keeps the process calm.

Disable the Microsoft 365 Account First

For most Israeli SMBs, the Microsoft 365 account is the master key, so it comes first. Block sign-in rather than deleting the account outright, because deleting immediately can destroy data you still need. Then reset the password and, importantly, revoke the active sessions and sign-in tokens. This last step is the one people miss: simply changing a password does not always kick out a device that is already signed in, so a phone with the mailbox open can keep working until you explicitly force it out. Blocking sign-in and revoking sessions together is what actually severs access in the moment.

Catch the Hidden Access: Forwarding Rules and App Grants

Cutting the main login is not the whole job, because access can be quietly wired to survive it. Check the departing user's mailbox for auto-forwarding rules that send copies of mail to an outside address, a simple trick that keeps information flowing after the account is gone. Review the third-party apps and OAuth permissions the account has granted, since a connected app can hold access independently of the password. Look for any legacy app passwords, which bypass multi-factor authentication entirely. These are exactly the paths that get overlooked when off-boarding is done in a hurry, and they are the ones worth slowing down for.

Revoke Remote Access: VPN and ZTNA

Anyone who worked from home almost certainly had a way in from outside the office, and that path needs closing too. Remove the person from the VPN or, if you use a Zero Trust model, revoke their access to the specific applications they were granted. The same applies to any remote desktop or remote support tool. It is easy to disable the email and forget that a separate remote-access login still opens a door straight into the network. If you are still relying on an older VPN setup, an off-boarding is a good moment to confirm that removing a user really does cut them off, a question worth understanding before you need the answer.

The Accounts That Live Outside Microsoft 365

Company data does not all sit in one place. Between the accounting package, the CRM, the payroll system, the design tools, and whatever industry software the business runs, most SMBs have a scattering of separate logins that Microsoft 365 knows nothing about. Each one needs closing individually. The practical safeguard is to keep a simple, current list of every service the business uses and who has access, so that off-boarding is a matter of working down a list rather than trying to recall every system from memory. The account you forget is always the one that matters later.

Shared Passwords Are the Weak Point

The awkward reality in many small offices is the shared login: one account for the bank portal, one for a supplier site, one for the social media pages, with the password known to several people. When someone who knew those passwords leaves, changing them is not optional, and it is easy to forget precisely because no single account is being disabled. This is one of the clearest arguments for a proper password manager, which lets you share access without sharing the secret and revoke one person cleanly. Until that is in place, a departure means sitting down and rotating every shared credential the person could have known, and making a note of which ones so the same list is ready the next time someone moves on.

Recover the Data Before You Delete Anything

A leaving employee takes knowledge with them, and sometimes the only copy of an important file sits in their mailbox or personal OneDrive. Before anything is deleted, preserve what the business needs. A common approach in Microsoft 365 is to convert the mailbox into a shared mailbox so colleagues can still reach past correspondence, and to reassign ownership of the person's files to their manager. Handle this deliberately and keep it in proportion to what the role actually touched. The goal is simply to make sure that closing an account does not quietly take a piece of the business with it.

Collect the Devices and Close the Physical Doors

Off-boarding is not only digital. Company laptops and phones should be returned and, before reissue, wiped so no old credentials or cached data carry over to the next person. If a personal device was used for work, this is the moment to remove company data from it using the app protection controls described in our guide to mobile device security. Do not overlook the ordinary things either: building access cards, keys, and any alarm codes the person knew. A leaver who can still badge into the office at the weekend is a gap that no amount of account management closes.

Make It a Repeatable Checklist, Not a Memory Test

The reason off-boarding goes wrong is almost never that a business does not care. It is that the steps live in one person's head and something gets missed under time pressure. The fix is unglamorous and effective: write the process down as a checklist, keep it current as your systems change, and have one named person confirm each item is done and dated. NetFortress helps Israeli SMBs build and run this off-boarding process inside their existing Microsoft 365 and remote-access setup, so that when someone leaves, access closes completely and on time. If your leaving routine is currently improvised, ask us to help turn it into something you can rely on.

Frequently asked questions

What is the first thing to do when an employee leaves?

Close the Microsoft 365 account, because for most SMBs it is the master key. Block sign-in rather than deleting the account (deleting immediately can destroy data you still need), reset the password, and revoke the active sessions and sign-in tokens. Blocking sign-in and revoking sessions together is what actually severs access in the moment, since changing a password alone does not always kick out a device that is already signed in.

Should we disable access before or after the last working day?

It depends on the departure. For a planned, friendly exit, the usual aim is to disable everything at the end of the final working day. For a difficult exit, access should be revoked at the moment the person is informed. Agreeing this in advance between whoever handles HR and whoever handles IT keeps the process calm rather than improvised.

What access gets forgotten most often during off-boarding?

The hidden paths that survive a password change: mailbox auto-forwarding rules sending copies to an outside address, third-party apps and OAuth grants that hold access independently of the password, legacy app passwords that bypass multi-factor authentication, and remote access through a separate VPN or ZTNA login. Accounts outside Microsoft 365, such as accounting and CRM systems, and any shared passwords are the other common gaps.

How do we handle a departing employee's mailbox and files?

Recover what the business needs before deleting anything. In Microsoft 365, a common approach is to convert the mailbox into a shared mailbox so colleagues can still reach past correspondence, and to reassign ownership of the person's files to their manager. Handle it deliberately and in proportion to what the role actually touched.

Why do we need a written off-boarding checklist?

Because off-boarding fails when the steps live in one person's head and something gets missed under time pressure. A written checklist, kept current as your systems change, with one named person confirming and dating each item, is what turns a good intention into access that closes completely and on time. It also covers the physical side: returning devices, wiping them before reissue, and collecting access cards and keys.

Ready to secure your business without building an internal IT team?

Book a free consultation and get a practical first look at your IT and Microsoft 365 security posture.