Your Employee Returned Their Keys. But Did They Return Their Digital Keys?
When an employee leaves a company, there are usually some obvious things that need to happen.
Keys are returned.
Company property is collected.
Payroll and HR paperwork are completed.
Maybe there's an exit interview.
But there's another set of keys that can be much easier to forget:
Their digital keys.
Email.
Microsoft 365.
Cloud applications.
VPN access.
Shared files.
Company computers.
Business phones.
And increasingly, even the credential that opens the front door.
When someone leaves your company, removing access to these systems shouldn't be an afterthought.
Employee offboarding is a cybersecurity process.
The Employee Left. Did Their Access?
Consider everything an employee may gain access to during their time with a company.
It usually starts with email and a computer.
Then comes Microsoft 365.
Shared folders.
Cloud applications.
Internal systems.
VPN access.
Company databases.
Phones.
Security systems.
Door access.
And perhaps passwords or credentials for services that aren't formally assigned to an individual employee.
Over several years, that access can add up.
Then one day the employee leaves.
The physical key gets handed back.
But unless someone has a process for removing everything else, some of those digital doors may remain open.
Why Former Employee Accounts Matter
An active account belonging to someone who no longer works for your business creates unnecessary risk.
That doesn't mean former employees are automatically a threat.
The bigger problem is that an account nobody is actively using or monitoring can become an unnecessary point of access into the business.
If credentials are compromised later, an attacker may potentially find an account that's still active.
And because nobody is supposed to be using it, suspicious activity may be harder to notice.
The safest account for a former employee is generally one that can no longer log in.
Start With Email and Microsoft 365
For many businesses, Microsoft 365 is one of the first places an employee receives access—and one of the most important places to address when they leave.
Depending on the employee and the business, offboarding may include:
- Blocking sign-in
- Resetting credentials
- Ending active sessions
- Removing or changing licenses
- Preserving the mailbox
- Providing appropriate mailbox access to another employee
- Handling email forwarding when required
- Preserving OneDrive or other business data
- Reviewing group memberships and permissions
The goal isn't necessarily to immediately delete everything.
Quite the opposite.
The business may need information from that mailbox or OneDrive long after the employee has left.
The important distinction is:
Preserving business data does not require preserving the former employee's access to it.
What About Cloud Applications?
Microsoft 365 may only be the beginning.
Think about how many web-based services your employees use.
Accounting.
CRM.
Project management.
File sharing.
Scheduling.
Marketing.
Vendor portals.
Security systems.
Remote support.
Industry-specific software.
An employee who has been with the company for several years may have accumulated access to dozens of different systems.
That's why offboarding from memory isn't a great strategy.
You need to know what the employee had access to before you can reliably remove it.
Shared Passwords Make Offboarding Harder
Shared accounts create another challenge.
Imagine several employees all know the same password for a vendor portal.
One employee leaves.
You can disable their individual Microsoft 365 account—but they may still know the shared password.
Now what?
The password may need to be changed for everyone.
This is one reason individual user accounts and proper password management are preferable whenever possible.
They make it easier to answer a very important question:
Who currently has access to this system?
If the answer is:
“We're not completely sure.”
That's a security issue worth addressing before someone leaves.
Don't Forget VPN and Remote Access
Remote work has made offboarding more complicated.
Employees may have access to company systems without ever entering the building.
That can include:
- VPN credentials
- Remote desktop access
- Remote support software
- Cloud applications
- Mobile devices
- Company laptops
- Saved credentials
- Authentication applications
Removing access to the physical office doesn't address any of those.
A complete offboarding process should account for both onsite and remote access.
Company Devices Need a Plan Too
If an employee has a company laptop, phone, tablet, or other device, simply getting the hardware back isn't always the end of the process.
The device may contain:
- Company data
- Saved passwords
- Browser sessions
- VPN configurations
- Business applications
- Locally stored files
Before handing that computer to the next employee, it should be properly reviewed and prepared.
The goal is to protect both the company's information and the next user's environment.
Who Owns the Employee's Files?
This is one of the reasons offboarding needs to happen before accounts are simply deleted.
An employee may have important business information stored in:
- Their mailbox
- OneDrive
- Shared folders
- Teams
- Local computer storage
- Cloud applications
Someone needs to determine whether that information should be transferred, preserved, archived, or made accessible to another employee.
Otherwise, a well-intentioned attempt to secure an account can accidentally make important business information difficult to retrieve.
Disable access first. Handle the data intentionally.
Digital Access Isn't the Only Access
This is an area where the line between IT and physical security is becoming increasingly blurry.
Many modern access-control systems use:
- Cards
- Key fobs
- Mobile credentials
- PINs
- User accounts
When an employee leaves, those credentials need to be removed too.
You wouldn't intentionally allow a former employee to keep a working key to your building.
Their digital access shouldn't be treated differently.
The employee's physical and digital access should leave with them.
Timing Matters
Offboarding isn't something that should happen whenever IT eventually gets around to it.
HR, management, and IT should coordinate the timing.
For a normal departure, access might be scheduled to end at an agreed time on the employee's final day.
Other situations may require access to be removed immediately.
The exact process will vary by company and circumstance.
What's important is that everyone knows:
Who tells IT?
What needs to be disabled?
When should it happen?
Without those answers, offboarding can easily fall through the cracks.
Build an Offboarding Checklist
The easiest way to make this process more reliable is also one of the simplest:
Use a checklist.
A basic IT offboarding process might include:
- Disable the employee's primary account.
- End active sessions where appropriate.
- Remove Microsoft 365 and application access.
- Disable VPN and remote access.
- Transfer or preserve company data.
- Recover company-owned devices.
- Remove phone and communication access.
- Disable physical door-access credentials.
- Change shared credentials the employee knew.
- Document that offboarding was completed.
Not every employee will have every type of access.
That's okay.
The checklist exists so you check, rather than assume.
Offboarding Actually Starts With Onboarding
Here's the interesting part:
A good offboarding process begins on the employee's first day.
If your company knows exactly what access was provided during onboarding, it becomes much easier to determine what needs to be removed later.
Employee joins:
Grant appropriate access.
Employee changes roles:
Review and adjust access.
Employee leaves:
Remove access.
That creates an employee technology lifecycle rather than a collection of unrelated IT tasks.
Don't Forget Employees Who Change Roles
People don't have to leave the company for access to become outdated.
An employee moves from one department to another.
They receive access to the systems needed for their new position.
But does anyone remove the permissions they needed for their old position?
Over time, employees can accumulate more access than their current job requires.
That's why access management should follow the employee throughout their time with the business.
The principle is straightforward:
The right access. For the right people. At the right time.
HR and IT Need to Talk
Many offboarding failures aren't really technology failures.
They're communication failures.
IT can't disable an account if nobody tells IT that the employee is leaving.
HR may not know every application the employee uses.
A manager may know which files need to be preserved but not how to preserve them.
That's why employee onboarding and offboarding work best when HR, management, and IT follow an agreed process.
It doesn't need to be complicated.
It needs to be consistent.
Employee Access Under the Umbrella
Employee access touches many different pieces of business technology.
Email.
Microsoft 365.
Computers.
Applications.
Networks.
Phones.
Files.
Security.
Door access.
That's why onboarding and offboarding fit naturally within Umbrella IT.
Rather than treating each system as a separate problem, HardConnect can help businesses create a more consistent process for managing technology as employees join, change roles, and leave.
Because access management isn't just about turning accounts on and off.
It's about protecting the business while making sure employees have the technology they need to do their jobs.
Ask Yourself One Question
Think about the last employee who left your company.
Can you confidently say that every account, application, remote connection, device, and door credential they had access to was addressed?
If the answer requires some thought, that's exactly why an offboarding process matters.
You shouldn't have to remember every digital key after someone walks out the door.
You should already have a process for collecting them.
Their Access Should Leave With Them
Employees come and go. Roles change. Businesses grow.
Your access controls need to change with them.
A good offboarding process helps protect company data, reduce unnecessary access, preserve important information, and make employee transitions more predictable.
Because you wouldn't let a former employee keep the keys to your building.
Their digital keys shouldn't be any different.
☂️Umbrella IT
The right access. For the right people. At the right time.
Connected. Protected. Productive.
📞650.444.5556
🌐hardconnect.com




