September 16, 2026

The account nobody closed: Microsoft 365 offboarding gaps

When someone leaves, the laptop comes back and the HR record is closed. In the tenant, the account often stays licensed, still owns a SharePoint site, and still forwards mail to a personal address. What a complete Microsoft 365 offboarding actually involves.
Geometric rail of connected account nodes with one severed, disconnected node

The short answer

Blocking sign-in is not offboarding. An account is only closed when the sign-in is blocked and active sessions are revoked, the licence is reclaimed, the mailbox is converted or delegated, forwarding rules are removed, OneDrive and SharePoint ownership is transferred, and the registered multi-factor authentication methods are cleared. Miss any one of those and the account is still doing something in your tenant.

What actually stays open when someone leaves

The visible parts of offboarding almost always happen. The laptop is returned, the HR record is closed, the desk is cleared, and the email signature stops appearing on outgoing mail. The parts that stay open are the ones nobody can see from outside the tenant.

Months after a final day, it is common to find the same account still holding a paid licence, still a member of several Teams, still the sole owner of a SharePoint site that no remaining administrator can manage, still running an inbox rule that forwards to a personal address created years earlier, and still carrying multi-factor authentication registered to a mobile number the organisation does not control.

None of that is exotic. It is the ordinary residue of a process that ended at the HR system rather than at the directory.

Why nothing alerts on it

A dormant account does not generate failed sign-ins, does not trigger malware detection, and does not appear in a security dashboard as an incident. It is simply an account that has stopped being used, and there is no meaningful difference, from the platform's point of view, between an employee on extended leave and an employee who left in March.

That is why offboarding gaps surface at inconvenient moments: during an audit, during a breach investigation when investigators ask who had access at the time, or during a client's procurement review when someone asks how access is removed.

The licence bill is the cheapest symptom

Unreclaimed licences are the easiest gap to quantify and the least serious. If ten accounts sit licensed for six months after their owners left, the waste is real but recoverable, and the finance conversation is straightforward.

The expensive version is the forwarding rule. An inbox rule that quietly copies mail to an outside address does not stop working when someone resigns, and it is invisible to everyone except an administrator who goes looking. The same applies to a former employee who remains the only owner of a SharePoint site containing contracts, or who still holds a guest invitation into a client's tenant.

What a closed account looks like

Work through these in order. The first two stop access immediately; the rest prevent the account from becoming a problem later.

  1. Block sign-in and revoke active sessions and refresh tokens, so existing signed-in sessions do not continue working.
  2. Reset the password and remove registered multi-factor authentication methods, so the account cannot be recovered to a personal device.
  3. Review and remove inbox rules, particularly forwarding and redirect rules, before touching the mailbox itself.
  4. Transfer OneDrive content to the manager or successor, and confirm the transfer completed before the retention window expires.
  5. Reassign ownership of SharePoint sites, Teams, Planner plans and shared mailboxes where the departing person was the only owner.
  6. Convert the mailbox to a shared mailbox if colleagues still need the history and the correspondence must keep arriving.
  7. Remove the licence and confirm it returns to the available pool rather than staying assigned.
  8. Remove group and distribution list memberships, and revoke guest access held in other organisations' tenants.
  9. Record what was done and when, so the account has an auditable end rather than simply going quiet.

Shared mailboxes, and when the licence can go

A shared mailbox under the usual size limit does not need its own licence, which is why converting a departed employee's mailbox is both the tidier and the cheaper outcome. The order matters: convert first, confirm the conversion, then remove the licence. Removing the licence first starts a deletion clock on the mailbox contents, and organisations discover this at the point where the contents are already gone.

Where offboarding breaks in small organisations

In companies of fifteen or thirty people, offboarding is usually a memory rather than a procedure. One person knows which systems the leaver touched, and that knowledge works reliably until the person holding it is the one leaving, or until three people leave in the same quarter.

The fix is not complicated. A written checklist owned by someone other than IT, a quarterly review of accounts that have not signed in for sixty days, and an agreement that licence reclamation is checked against payroll rather than against recollection will catch almost all of it.

Frequently asked questions

How long should we keep a former employee's mailbox?

Long enough to satisfy your retention obligations and any live matters the correspondence relates to. Converting to a shared mailbox lets you keep it without a licence, so cost is rarely the deciding factor.

Is deleting the account better than blocking it?

Not immediately. Deleting removes the account from view but also removes the audit trail and the ability to recover attached content cleanly. Block, strip access, transfer what matters, and delete on a schedule.

What about accounts that belong to contractors or auditors?

Guest accounts are the most commonly forgotten category, because they were never on the payroll and so never enter the leavers process. Review guest access on its own cycle.

How do we know which accounts are already dormant?

Sign-in activity, last licence assignment date and mailbox activity together give a reliable picture. A review of these across the tenant usually takes less time than organisations expect, and the first run almost always finds something.

Where to start

If nobody can say with confidence how many accounts in your tenant belong to people who have left, that is the finding, and it is worth resolving before it is discovered by someone else.

Onprem2Cloud IT Solutions Co. is a Microsoft Cloud Solution Provider partner based in Muntinlupa City, working with businesses, local government units and national agencies across Metro Manila and the wider Philippines. We review Microsoft 365 and Azure tenants for dormant and orphaned accounts, unreclaimed licences, forwarding rules, guest access and ownership that has been left behind, and we hand back a findings report ranked by risk rather than volume. You can see the scope of that work on our cybersecurity services page.