Schedule DemoStart Free Trial

Unified Observability Platform for Modern IT Operations

Summarize with AI what Motadata does:

ObserveOps

  • Network Observability
  • Network Configuration & Compliance Management
  • Hybrid Infrastructure Monitoring
  • Log Monitoring
  • Application Performance Monitoring
  • Real User Monitoring

ServiceOps

  • Service Management
  • IT Asset & Configuration Management
  • Patch & Deployment Management
  • Agentic AI & Orchestration
  • MSP Edition

By Use Cases

  • Data Centre Monitoring
  • Docker Monitoring
  • Enterprise Service Management
  • IT Service Desk
  • ITSM MSP
  • Enterprise Network Monitoring

By Technologies

  • AWS Monitoring
  • Azure Monitoring
  • Kubernetes Monitoring
  • DevOps Observability
  • REST API Monitoring
  • Storage Monitoring

Resources

  • Getting Started
  • Documentation
  • Integrations
  • IT Glossary
  • Whitepapers
  • Ebooks & Guides
  • Product Brochures
  • Success Stories
  • Comparison
  • Features

Community

  • Blog
  • Press Releases
  • Events
  • Webinar
  • Become a Partner

Company

  • Company
  • Careers
  • Contact Us
  • Customer Support

Get in Touch

  • Request Demo
  • sales@motadata.com
  • support@motadata.com
© 2026 Mindarray Systems Limited. All rights reserved.
Privacy PolicyTerms of Service
Back to Blog
Serviceops
9 min read

IT Offboarding and How to Revoke Access Without Leaving Security Gaps

Written by

Poonam Lalani

Content Strategist

Reviewed by

Keertan Zala

Product Manager

Published

September 25, 2026

9 min read

When someone leaves your organization, how sure are you that every account they could reach was closed? Most IT offboarding starts by disabling the employee's main login account, and that step usually works. The risk comes from the other accounts, tools and devices the person used that the main account does not control.

These include personal API tokens, shared vendor portal logins, laptops still with a courier and SaaS tools bought on a department card. None of them appear on the HR exit form, and none of them close when the main account is disabled. Each one stays active until someone takes responsibility for removing it, and until then it can lead to a data leak, wasted spend or an audit finding.

IT offboarding works best when it runs with the same discipline as employee onboarding: one trigger, named owners and a record of every step. In this blog, you will see how to sequence the IT offboarding process, which access to revoke first, what gaps in the process cost the business, how contractors and privileged users differ, and how to prove afterward that nothing was left behind.

What is IT Offboarding?

IT offboarding is the process of removing a departing employee's or contractor's access to systems, data and devices, and handing anything the business still needs to a new owner. In this article, the directory means the central system that stores user accounts and controls who can sign in, such as Active Directory or a cloud identity provider. The process starts when HR confirms a departure and ends when IT can show that every account, license and asset tied to that person has been closed, reassigned or recovered.

It covers five areas:

  1. Identity: The directory account, single sign-on (SSO), email, VPN and multi-factor authentication (MFA)

  1. Application access: SaaS tools, internal apps, admin consoles and API keys

  1. Data: Mailboxes, shared drives, file ownership and retention holds

  1. Devices and licenses: Laptops, phones, security keys and paid seats

  1. Evidence: A record of what was removed, by whom and when

Offboarding also covers more than terminations. It applies to resignations, retirements, contract end dates and internal transfers, where access from the old role should be removed once the handover is complete, following the zero trust principle that people should only have the access their current role needs. Getting it right affects the whole business.

Why does IT Offboarding Matter to the Business?

IT offboarding matters to the business because every account, device and license left behind after an exit carries a cost, whether as security exposure, wasted spend or an audit finding. The main business risks are:

  • Data exposure: A former employee, or anyone holding their credentials, can still reach customer records, pricing or source code

  • Wasted spend: Paid SaaS seats and unreturned laptops keep costing money after the person has gone

  • Audit findings: Frameworks such as SOC 2, ISO 27001 and NIST SP 800-53 expect timely access removal, and auditors ask for proof of it

  • Lost work: Files, mailboxes and automations owned by one person can disappear if the account is deleted too early

  • Customer trust: If a former employee is found using company systems after leaving, the organization has to explain it to customers and regulators

Because offboarding happens every time someone leaves, a small weakness in the process repeats with every exit. On the positive side, a well-run process is easy to prove to an auditor or a board, because each exit leaves its own record. Most of the risk comes from a few predictable gaps, covered next.

Why does Access Revocation Leave Gaps During Offboarding?

Access revocation leaves gaps because offboarding often stops at the directory account, while employees gain access to many systems the directory does not control. The usual weak points look like this:

  • Delayed handoff: IT learns about the exit late, sometimes days after HR recorded it or only on the employee's last day

  • Live sessions: Disabling an account does not always end browser sessions, mobile app sessions or OAuth tokens, the credentials that let connected apps keep acting for a user

  • Apps outside SSO: Tools a department signed up for directly, often called shadow IT, keep their own usernames and passwords

  • Shared and service credentials: Logins for vendor portals, social accounts and network devices keep working, as do scripts that run under the person's account and service accounts that applications use

  • Contractors outside the HR system: People who were never entered in the HR information system (HRIS) never get an exit request from HR

  • Devices returned late: Remote staff can hold laptops with saved credentials and local files for weeks after their final day, often reaching the network through remote access tools

Consider a regional sales lead who resigns on good terms. Their directory account is disabled on the last day, yet a CRM integration they connected with a personal token keeps copying sales pipeline data into a spreadsheet tool the company never approved. No one intended any harm, but company data still left the organization.

Before the next exit, sort your access into two groups: what the directory controls and what it does not. The diagram below shows which access closes with the main account and which stays open until someone removes it.

Each item on the dashed side needs a named person responsible for removing it, so ownership is the next thing to settle.

Who Owns Each Part of the IT Offboarding Process?

The IT offboarding process has six owners, and gaps appear when one owner assumes another has already done the work. Naming every owner at the start prevents that.

Owner

Responsible for

Hands off to

HR

Confirming exit type, final day and any legal hold

IT service desk

Line manager

Listing apps, shared accounts and handover needs

IT service desk and app owners

IT service desk

Opening the offboarding request and tracking every task

All task owners

Identity or security lead

Disabling identity, ending sessions, rotating shared credentials

IT service desk

IT asset manager

Recovering devices, wiping data, reclaiming licenses

IT service desk

Application owners

Removing access in apps outside SSO

IT service desk

The service desk is the natural coordinator because it already tracks work against deadlines, and many organizations already route HR requests through it as part of enterprise service management. When the offboarding request lives there, each owner gets a task, and the request stays open until the last task closes. Once owners are named, the next question is the order of the work.

What are the Steps in the IT Offboarding Process?

The IT offboarding process runs in six steps, and the full sequence matters. Doing one step quickly helps little if a later step is missed.

Manage all six steps under one request so none of them is handled in isolation. The timeline below shows when each step should happen during the exit.

1. Trigger the Offboarding Request from HR

Offboarding should start the moment HR confirms a departure, with a single service request that gives IT everything it needs to plan. For a resignation with notice, that gives IT the full notice period to prepare. For an involuntary exit, the request should arrive before the conversation with the employee takes place.

The request should capture four details:

  1. Exit type: Voluntary, involuntary, contract end or internal transfer

  1. Timing: Final day and the agreed cutoff point for access

  1. Handover: Who receives the mailbox, files and open work

  1. Holds: Any legal or compliance retention requirement

2. Disable the Primary Identity and End Active Sessions

Disabling the primary identity is the first technical action, because it blocks new sign-ins to every app connected through SSO at once. Organizations running Active Directory or a cloud identity provider should complete these actions at the same time:

  • Disable the account and hold off on deletion, so mailboxes, files and sign-in history stay available for later questions

  • Sign the user out of all sessions and revoke the tokens apps use to stay signed in

  • Remove MFA methods and registered devices

  • Remove mail forwarding rules, along with any mailbox access the person gave to others or received from them

  • Reset the password, in case some connected systems only check account status periodically

3. Sweep Access Outside the Identity Provider

This step covers every system the directory does not control, which is where leftover access is usually found. Use the manager's list of apps and accounts to check each category:

  • Non-SSO applications: Accounts with local usernames, especially department-bought SaaS

  • Privileged accounts: Cloud consoles, firewalls, domain admin groups and database logins

  • Keys and tokens: Personal API keys, SSH keys used to reach servers, code repository access, secrets stored in build pipelines and credentials given to AI assistants or automations the person set up

  • Shared credentials: Vendor portals, social media, Wi-Fi and device admin passwords the person knew

  • Physical access: Badges, keys and building systems

Organizations that grant permissions through role-based access finish this sweep faster, since removing a role removes the bundle of permissions attached to it. Change shared passwords even when you trust the departing person, so there is no doubt about who can still use them.

4. Transfer Data Ownership and Reclaim Licenses

Data transfer protects the work a person leaves behind, and license reclamation stops the business paying for seats nobody uses. Complete these before any account is deleted:

  • Transfer file and drive ownership to the manager or successor

  • Convert the mailbox to a shared mailbox, or set an auto-reply and forward to the successor for a defined period

  • Apply retention or legal holds

  • Reassign scheduled reports, automation jobs and recurring meetings the person owned

  • Release paid seats back to the pool in line with your license management policy

5. Recover and Sanitize Devices

Device recovery covers the physical side of offboarding, and it matters most for remote staff whose laptops come back by courier. The answer to how to recover IT assets during offboarding starts when devices are first issued. If every device is recorded against a named user throughout its asset lifecycle, recovery is simply a matter of checking that list.

  • Match every device assigned to the person against the asset record

  • Collect security keys, badges, phones and peripherals

  • Lock or remotely wipe any device not returned by the agreed date

  • Sanitize storage before reissue or retirement, following your asset disposal process

  • Update the asset record with condition, location and new status

6. Verify Revocation and Close with Evidence

Verification confirms that access is gone, and the record proves it to anyone who asks later. Close the request only after these checks pass:

  • Run an access review against the person's identity across major systems

  • Check sign-in activity for anything after the cutoff

  • Confirm every task on the request is closed with a named owner and timestamp

  • Store the record where auditors can retrieve it

If sign-in and system logs are already collected in one place, a quick search with centralized log analytics can show any activity after the cutoff, and log compliance reporting turns the same data into evidence for auditors.

Auditors often ask for exactly this evidence. NIST SP 800-53 control PS-4, for example, calls for disabling system access within an organization-defined period, revoking credentials and retrieving organizational property when employment ends. A timestamped audit log of each action gives auditors that proof quickly.

Want Fewer Security and Audit Risks Every Time Someone Leaves?

Reduce data exposure after exits, cut spend on unused licenses, and give auditors clear proof of every departure.

Book a Demo

When Should Each Type of Access be Revoked?

Each type of access should be revoked based on its risk, with the highest-impact access removed first. Use the timing below as a baseline to revoke access in a predictable order.

Access type

Examples

When to revoke

Privileged and admin access

Domain admin, cloud console, firewall

Before or during the exit conversation for involuntary exits; at the cutoff for voluntary exits

Primary identity and sessions

Directory, SSO, email, VPN

At the agreed cutoff on the final day

Apps outside SSO

Department SaaS, local logins

Same day as the identity cutoff

Shared credentials

Vendor portals, social accounts, device admin

Within one business day of the cutoff

Devices and licenses

Laptop, phone, security key, paid seats

By the return date agreed at exit

Data and mailbox

Files, mailbox, retention holds

Transferred first; deleted only after the retention period

Verification

Access review, sign-in check

After the final day and again after 30 days

Voluntary exits give IT the notice period to prepare, and most access can stay open until the final day so handover work continues. Involuntary exits reverse that order, with privileged access removed first and the rest following immediately. Some groups need extra steps on top of this schedule.

How does Offboarding Differ for Contractors, Privileged Users and Involuntary Exits?

Offboarding differs for these three groups because each carries a risk that the standard employee process can miss, so each needs a few extra steps.

Offboarding Contractors and Vendor Staff

Contractors are often not recorded in the HR system, so an offboarding request that starts from HR is never created for them. Give every contractor account an end date at creation, tie it to a named internal sponsor, and review sponsored accounts on a fixed schedule.

Consider an implementation partner whose project wraps up early. The sponsor moves to other work, nobody raises an exit request, and the partner's VPN account stays active for months. An end date set at account creation would have closed it automatically, with no request needed.

Offboarding Privileged and Admin Users

Administrators often have access that keeps working after their own account is disabled, such as service accounts they created, scripts running under their name and passwords only they knew. Add these steps for anyone with admin rights:

  • Inventory service accounts and scheduled jobs the person owns

  • Transfer ownership of automation before disabling the account, so jobs keep running

  • Rotate every credential the person could have seen

Handling Involuntary Exits Safely

Involuntary exits need the tightest sequence, since insider threat risk is highest when a departure is unexpected. Agree the timing with HR and legal ahead of the meeting, prepare the full request in advance, and start privileged access removal the moment HR confirms. Handling all of these cases the same way every time is much easier with automation.

How do You Automate Employee Offboarding Across IT?

You automate employee offboarding across IT by turning each exit into a templated service request that assigns tasks to every owner, with deadlines and one shared record. For anyone working out how to handle employee offboarding IT tasks at scale, a good request template works like this:

  • Single trigger: HR raises one offboarding request from the service catalog, or an HR system opens it through an integration

  • Templated tasks: The request creates tasks for identity, apps, data, assets and verification, each routed to its owner through workflow automation

  • Parallel deadlines: Tasks run at the same time, each with its own service level agreement (SLA) and escalation path

  • Linked assets: Devices and licenses assigned to the person appear on the request and are tracked individually

  • Recorded exceptions: Requests such as extended mailbox access go through an approval that stays on file

  • Closure rule: The request closes only when every task is complete

Most ITSM workflows already support this pattern. Automation takes care of routing tasks and sending reminders. People still need to decide things such as which shared credentials someone knows and which scripts depend on their account.

This is what one of our clients says about Motadata ServiceOps on G2:

What Should an IT Offboarding Checklist Template Include?

An IT offboarding checklist template should list every task by phase, with an owner and a completion check, so it can be copied straight into a service request. Use the IT offboarding checklist below as a starting point.

Before the final day:

  • Confirm exit type, final day and holds with HR

  • Use the exit interview to confirm devices, accounts and data the person still holds

  • List apps, shared accounts and handover needs with the manager

  • Identify privileged access, service accounts and scheduled jobs

  • Pull assigned devices and licenses from the asset record

At the cutoff:

  • Disable the primary identity and end all sessions

  • Remove MFA methods, mail forwarding and delegated access

  • Remove admin rights and privileged group memberships

  • Disable accounts in apps outside SSO

Within one business day:

  • Rotate shared and service credentials

  • Transfer file ownership and convert the mailbox

  • Reassign scheduled jobs and integrations

  • Deactivate badges and physical access

Within the return window:

  • Recover and log every device and security key

  • Lock or wipe unreturned devices

  • Reclaim unused software licenses

After the final day:

  • Review access and sign-in activity for anything after the cutoff

  • Close the request with evidence attached

  • Repeat the access review after 30 days

HR usually owns the wider employee offboarding checklist, which covers final pay and benefits. This IT list can be added to that offboarding checklist or to any employee offboarding template HR already uses, and keeping an IT onboarding and offboarding checklist together means every access item granted at onboarding has a matching removal item at exit.

How do You Measure Whether IT Offboarding is Working?

You measure IT offboarding by tracking how fast access is removed, how complete each exit is and how much leftover access turns up in later reviews. Five measures give a clear picture:

  1. Time to disable: Time from HR confirmation to the primary identity cutoff

  1. On-time task completion: Share of offboarding tasks closed within their deadline

  1. Asset recovery rate: Devices recovered by the return date against devices assigned

  1. Orphaned accounts found: Accounts belonging to departed users that turn up in periodic reviews

  1. Licenses reclaimed: Paid seats returned to the pool after exits

Orphaned accounts are the most useful of the five, because each one points to a step the process missed and shows what to add to the template. For leadership, these five figures show whether offboarding is reducing risk and saving money.

Looking for an Easier Way to Protect Company Data and Spend After Every Exit?

Recover company devices on schedule, reclaim paid license seats, and answer audit questions about any past departure with confidence.

Start a Free Trial

Offboard Every Employee Completely with Motadata ServiceOps

IT offboarding leaves gaps when the work is scattered across emails, spreadsheets and what individual people remember. Motadata ServiceOps manages each exit as one service request: every exit type gets its own catalog template, every task has an owner and a deadline, assigned devices and licenses are tracked through asset management, and every action is recorded.

ServiceOps coordinates and records the offboarding work, while your identity provider still makes the account changes, so the two work best when connected. With both in place, every exit follows the same steps, and any later question about it can be answered from the record.

FAQs

What does access revocation mean?

Access revocation means removing a person's rights to use a system, application, dataset or physical space. In offboarding, it covers disabling accounts, ending active sessions, removing MFA methods and rotating shared credentials the person knew, so nothing they held still works after the cutoff.

Is offboarding the same as termination?

Termination is the HR and legal event that ends employment, while offboarding is the set of tasks that follows any departure, including resignations, retirements and contract end dates. IT offboarding is the part of that process that removes access and recovers company assets.

How soon should IT revoke access when an employee leaves?

Privileged access should end first, before or during the exit conversation for involuntary departures. For voluntary exits, most access can stay open until the agreed cutoff on the final day, with shared credentials rotated within one business day and a follow-up access review after the person has gone.

What software handles automated IT offboarding?

Automated IT offboarding usually combines an identity provider, which disables accounts, with an ITSM platform that runs the process around it. Platforms such as Motadata ServiceOps turn each exit into a templated request with tasks, deadlines, linked assets and a complete record of who did what.

What are common offboarding mistakes?

The most common mistakes are starting late, treating the directory account as the only access and skipping verification. Others include missing contractor accounts, leaving shared passwords unchanged and deleting accounts before data ownership is transferred, which can erase mailboxes and files the business still needs.

PL

Author

Poonam Lalani

Content Strategist

Poonam Lalani is a B2B content strategist and writer with a background in computer engineering and experience across enterprise technology domains, including AI, cloud, DevOps, data engineering, and IT operations. She specializes in creating research-driven content that simplifies complex ideas and supports product education, thought leadership, and business growth.

Share:
Table of Contents
Subscribe to Our Newsletter

Get the latest insights and updates delivered to your inbox.

Related Articles

Continue reading with these related posts

Serviceops

How to Run a Post-Incident Review That Prevents Repeat Outages

Poonam LalaniSep 25, 202611 min read
Serviceops

Top 10 HaloITSM Alternatives That Turn Infrastructure Alerts into Closed Tickets

Poonam LalaniSep 23, 202611 min read
Serviceops

How a Change Advisory Board Works and When to Skip It

Poonam LalaniSep 21, 20269 min read