← All insights

Practical checklist or tool

The 20-Minute Former-User Access Review for a Small Office

Use this review after an employee, contractor, or service provider leaves to find lingering access across email, cloud apps, devices, and vendors.

Veterinary practice manager and IT technician reviewing former-user badges and physical keys in a Central Florida clinic.

What this checklist is for

A departing employee or contractor may still have active browser sessions, mobile applications, saved credentials, shared-mailbox access, vendor accounts, or access through a device that nobody remembered. Turning off one directory account is important, but it may not close every path.

Microsoft explains that access revocation depends on the application. Entra can block new sign-ins and revoke refresh tokens, but applications may issue their own session tokens. Those application sessions may require separate action. This checklist is designed for a small office using Microsoft 365 or another cloud identity system. It is a review aid, not a substitute for the provider’s documentation or professional incident response.

Minute 0–3: Record the departure facts

Write down:

  • User’s full name and account name.
  • Departure date and exact access-cutoff time.
  • Whether the departure is routine, disputed, or connected to a security concern.
  • Devices assigned to the user.
  • Company phone number and mobile device, if applicable.
  • Systems the person administered or accessed.
  • The manager responsible for business continuity.

Do not delete evidence before deciding whether legal, human-resources, insurance, or incident-response preservation is required. A routine departure and a suspected compromise should not be handled identically.

Minute 3–7: Block identity access and active sessions

For Microsoft Entra ID, Microsoft’s emergency-access guidance identifies disabling the user and revoking sessions as core actions. Microsoft’s Microsoft 365 offboarding documentation also describes resetting the password and signing out all sessions.

Check each item:

  • [ ] Account disabled or sign-in blocked.
  • [ ] Refresh tokens or sessions revoked.
  • [ ] Password reset when appropriate.
  • [ ] MFA methods and registered devices reviewed.
  • [ ] Authentication phone numbers and alternate email addresses reviewed.
  • [ ] Shared accounts or emergency credentials changed if the user knew them.

Important limitation: Microsoft states that access-token and session-token timing can vary. An application may continue to honor its own session token until it expires or is separately revoked. Do not promise an immediate universal sign-out unless the relevant application confirms it.

Minute 7–11: Review cloud applications and data

Create a quick application list from the user’s role, browser history if authorized, password manager records, expense reports, and vendor invoices. Look for systems outside the central identity provider.

Review:

  • Email and calendar.
  • OneDrive, SharePoint, and shared drives.
  • Accounting, payroll, and payment systems.
  • Customer relationship management.
  • Scheduling and practice-management systems.
  • Project-management tools.
  • File-transfer services.
  • Social-media and website administration.
  • Remote-support or remote-desktop tools.
  • Industry portals and customer systems.

For each application, record one result: removed, transferred, disabled, pending, or unknown. “Unknown” is a finding that needs an owner—not a reason to close the review.

Check for:

  • Direct logins that do not use the company identity provider.
  • Personal email addresses used as recovery addresses.
  • API keys, app passwords, service accounts, or automation tokens.
  • Delegated mailbox or calendar access.
  • External sharing links created by the departing user.
  • Files synchronized to personal devices.

Minute 11–15: Review devices and physical access

Recover company laptops, phones, tablets, security keys, access cards, keys, and removable media. If a device cannot be recovered, ask the IT provider whether it can be locked, wiped, or removed from management.

  • [ ] Device ownership and management status recorded.
  • [ ] Company data separated from personal data where applicable.
  • [ ] Local administrator access reviewed.
  • [ ] Browser-saved passwords addressed according to policy.
  • [ ] VPN, Wi-Fi, printer, and remote-support access reviewed.
  • [ ] Building, alarm, storage, and server-room access removed.

Avoid improvising a device wipe when litigation, investigation, or evidence preservation may apply. Coordinate with counsel, the insurer, or an incident-response provider first.

Minute 15–18: Review vendors and shared access

A former employee may have been the only person listed with a vendor. The vendor may still recognize the person as an authorized contact, especially for billing, domain registration, payroll, banking, or technical support.

Contact the highest-impact vendors and request:

  • Removal of the former user.
  • Transfer of ownership to a current employee.
  • Rotation of shared credentials or API keys.
  • Confirmation of active sessions and devices.
  • Updated emergency contacts.

Prioritize accounts that can move money, change DNS, reset email, access sensitive data, or administer technology.

Minute 18–20: Save the record and assign follow-up

Record:

  • Person conducting the review.
  • Date and time of each action.
  • Systems checked.
  • Unresolved items and assigned owners.
  • Whether an incident was suspected.
  • Whether counsel, the insurer, law enforcement, or a technology provider was contacted.

Keep the record in a restricted location. It should be useful without exposing unnecessary personal or employment information.

When the checklist is not enough

Escalate immediately if there are signs of mailbox forwarding, unusual downloads, suspicious sign-ins, payment changes, deleted logs, ransomware, threats, or deliberate data removal. Do not rely solely on account disabling. Preserve relevant evidence and follow the organization’s incident plan.

Run this review for employees, contractors, interns, temporary staff, and technology providers. The objective is not punishment. It is lifecycle management: access should be granted deliberately, reviewed periodically, and removed completely when the relationship ends.

Human-reviewed draft. Administrative steps vary by tenant configuration and application. Confirm the correct procedure with the organization’s Microsoft 365 administrator, IT provider, legal counsel, and human-resources adviser.

Sources