Removing worker access after departure: Agree on a cut-off time and assign account changes to authorised staff.; Reset passwords, revoke sessions and block sign-ins across all services used.; Transfer work ownership before deleting accounts to prevent access loss.
Image: Small Business Tech Guide

Account Security

Part of Small business account security

Removing access when a worker leaves

Use a service-by-service exit checklist to prevent sign-ins, address sessions and shared passwords, transfer work and verify access removal.

Use the services a departing worker actually accessed as the exit checklist. Agree who will act and when, prevent new sign-ins, address existing sessions and shared credentials, then transfer business work. Collecting a laptop or disabling email does not establish that every online account is closed.

Prepare the service list

Start with the account register and the worker’s current role. Ask their manager which work, supplier relationships and records need a new owner. Include email, file storage, accounting, banking, social media, website administration, remote access and specialist applications. Check separate administrator accounts and access granted by external providers.

Record the agreed cut-off time and the person authorised to change each service. The exact controls depend on the service.

AccessAction to assign
Individual accountPrevent sign-in using that service’s controls.
Session or connected appRevoke access where supported and check the reported state.
Group or administrator roleRemove the permission and assign its work.
Shared credentialChange it if the worker knew it, then update authorised users.
Business recordsArrange authorised access for the new owner before deletion affects them.

A central identity may open many applications, but disabling it does not prove that an independent supplier login or social-media role has ended. Check each service separately.

Service-by-Service Access Removal Process

  1. Individual AccountPrevent sign-in via service controls
  2. Session or Connected AppRevoke access where supported; verify reported state
  3. Group or Administrator RoleRemove permission and assign new owner
  4. Shared CredentialChange password if known; update authorised users
  5. Business RecordsArrange access for new owner before deletion

Prevent sign-in and address sessions

At the agreed time, have an authorised administrator act on each individual account. Where supported, reset credentials, revoke sessions or app tokens and block sign-in. Record what the service confirms and what remains pending. A submitted change may not end an existing session immediately.

Microsoft’s former-employee procedure for Microsoft 365 distinguishes password reset, signing out sessions and blocking sign-in. Its documentation says blocking can take up to 24 hours to take effect and advises a password reset for immediate prevention of a new sign-in.

It also says an existing access token may last up to an hour, depending on the session. These timings describe Microsoft 365, not other services; use the current procedure for the actual account setup.

For a shared account, change the password, review its MFA method and revoke sessions where the service permits it. Removing a person from a password-manager vault cannot erase a password they previously saw. Prefer named service accounts for future access.

Key Timings and Considerations for Access Removal

Existing access token duration
Up to 1 hour (varies by session)
Shared password risk
Cannot be erased from memory once seen
Best practice for future access
Use named service accounts instead of shared credentials

Preventing Sign-In vs. Revoking Sessions – Key Differences

Prevent New Sign-Ins
Immediate action required; reset password for instant effect
Revoke Active Sessions
May not end immediately; depends on service and token expiry
App Tokens & Connected Apps
Must be manually revoked where supported
Admin Controls
Disabling central identity does not affect independent supplier logins

Transfer work before deleting accounts

Assign incoming enquiries, active files and services the worker administered to an authorised replacement. Do this through the business’s account controls before deleting an account if deletion could affect access to its contents. Microsoft’s exit guidance, for example, treats sign-in prevention, mailbox and OneDrive handover, and account removal as separate steps.

Use the business’s records and privacy process to decide what to retain and who may read it. If the departure also raises suspicion of compromise, use the incident process as well as the access-removal checklist.

Confirm what is complete

Have a second authorised person compare the service list with the recorded changes. Check user, group and administrator lists, shared-credential changes and whether the replacement owner can do essential work. Record any session status or delay the service reports.

Keep an item open until its owner can confirm the result. A supplier account awaiting support or a session whose revocation remains uncertain is still an exit task. Update the account register when the checks are complete.

More from Account Security

Account Security

Using a business password manager

Choose and roll out a business password manager using real account needs, controlled sharing, vault protection and a clear process for staff changes.