An IT offboarding checklist is a structured list of access revocation and device recovery tasks that IT teams complete when an employee leaves. It covers identity provider deactivation (Okta, Google, Azure AD), SaaS revocation, device wipe or recovery, MFA reset, shared credential rotation, and audit log review — and should be completed on or before the last day.
Why IT Offboarding Is Your Biggest Post-Departure Security Risk
The accounts you forget are the ones that get breached. Former employees with live access — or shared credentials they still know — are a standing risk that compounds with every exit you handle informally. IT offboarding closes that window.
Identity Provider and SSO Checklist (Google Workspace, Okta, Azure AD)
- Suspend the primary identity account first to break SSO downstream.
- Revoke active sessions and OAuth tokens.
- Reset MFA and remove registered devices and security keys.
- Transfer or archive mailbox, calendar, and drive ownership.
- Remove from groups, distribution lists, and dynamic access rules.
SaaS Tool Revocation Checklist: Slack, GitHub, Notion, Salesforce, and 30 More
SSO does not cover everything. Many tools are signed into directly with email and password. Maintain a complete inventory and revoke each:
- Communication: Slack, Zoom, Teams.
- Code & infra: GitHub, GitLab, AWS, cloud consoles.
- Docs & data: Notion, Google Drive, Confluence.
- CRM & business: Salesforce, HubSpot, billing tools.
Device, Hardware, and MDM Offboarding Checklist
- Lock or wipe laptops and phones through MDM.
- Recover hardware, security keys, and access cards.
- Confirm no company data remains on personal devices (BYOD).
Shared Credentials, API Keys, and Admin Access Checklist
- Rotate every shared password the leaver knew.
- Revoke or rotate personal API keys and service tokens they created.
- Reassign ownership of admin accounts and automation.
Data, Files, and Cloud Storage Handover Checklist
- Transfer ownership of documents, repos, and dashboards before deactivation.
- Set an email auto-forward or shared-inbox rule for continuity.
- Preserve anything under legal hold.
IT Offboarding Timeline: What to Do Before, On, and After the Last Day
- Before: inventory access, reduce sensitive permissions during notice.
- On the last day: full deprovisioning, device recovery, credential rotation.
- After: audit log review and a confirmation that nothing was missed.
How to Automate IT Offboarding Without SCIM
Not every app supports SCIM. Offboarding software tracks the full app inventory, assigns each revocation as a task, and confirms completion — closing the gaps SCIM leaves. Track every revocation in OffboardSet.
Pair this with the broader offboarding process and the HR checklist.
FAQs
What is IT offboarding?
The process of revoking system access, recovering devices, and securing data when an employee leaves.
How do I revoke access when an employee leaves without SCIM?
Maintain an app inventory and revoke each tool manually as a tracked task; offboarding software automates this tracking so nothing is missed.
What is a deprovisioning checklist?
A list of every account, credential, and device tied to an employee that must be disabled or recovered when they leave.
How do I offboard an employee from Google Workspace?
Suspend the account, reset sign-in, transfer Drive and mailbox ownership, remove from groups, then delete or archive after the data transfer is confirmed.