IT support
What should you switch off when an employee leaves?
Disable the account rather than delete it, revoke the active sessions as well as resetting the password, and get the devices back. The step almost everybody misses is the sessions: changing somebody’s password does not sign them out of the phone in their pocket.
Disable the account rather than deleting it, revoke the active sessions rather than only resetting the password, and get the hardware back. That covers most of the risk on day one.
The sessions are the bit that catches people. Resetting somebody’s password feels like locking the door, and it is not. If they are already signed in on a phone or a home laptop, that session carries on working, because the token it is holding was issued before you changed anything. In Microsoft 365 you have to revoke it, or disable the account, which does the same job.
What goes on the checklist?
Same day, before they leave the building:
- Disable the account. Not delete. Disabling kills the sign in and keeps everything else intact.
- Revoke active sessions across every device, so the phone and the home laptop stop working too.
- Reset the password on anything shared. The info@ mailbox, the social accounts, the router, the alarm, the account somebody set up in 2018 with a password everybody knows.
- Turn off remote access. VPN, remote desktop, any support tool.
- Check for mail rules. Auto-forwarding out of the business is a favourite, and it survives an account being disabled if you have not looked.
- Take back the devices. Laptop, phone, tokens, keys.
In the first week:
- Move the files. OneDrive and the mailbox both need an owner before the licence goes.
- Redirect the email to their manager for a defined period, then stop. Thirty to ninety days is normal, and it should have an end date rather than becoming permanent.
- Transfer anything they own in your other systems. CRM records, the accounting login, the domain registrar, the account with your telecoms provider.
- Look at the sign in logs for the fortnight before they left. It takes ten minutes, and it is the only time you will ever have a reason to look.
Within the month:
- Remove the licence once the data is safe.
- Cancel what they alone used. This is where the money is. Every SaaS subscription nobody has cancelled is billing monthly for a person who has gone.
Why does disabling beat deleting?
Because deletion starts a clock you did not ask for. In Microsoft 365, deleting a user puts the mailbox and the OneDrive behind it on a countdown, and a business that finds out three weeks later that the only copy of a contract was in there is a business having a very bad week.
Disabled costs you a licence fee for a month or two. Deleted costs you whatever was in there.
What about the phone in their pocket?
If it is a company phone, take it back and wipe it. If it is their own phone with company email on it, you need to remove the company data from it without touching their photographs, which is exactly what mobile device management is for. If you have never set that up, the honest answer is that you cannot cleanly remove your data from a personal device, and the leaver keeps whatever was cached on it until the session dies.
That is worth knowing before somebody resigns rather than after.
What does skipping this actually cost?
Two things, and the boring one is more common.
The boring one is money. Licences and subscriptions carry on billing. We routinely find businesses paying for people who left years ago, plus a handful of tools somebody signed up for and forgot.
The other one is the account nobody disabled. When we take over an IT environment, one of the first things we audit is who still has access, and it is normal to find live accounts belonging to people who left the business years ago, in some cases still holding everything they could reach on their last day. Nobody left them on purpose. There was no process, so nothing happened.
The same audit usually turns up external sharing links created for a one off job three years ago that are still live, and a list of global administrators that is three times longer than it should be. None of it is malicious. It is the normal state of a business that has grown and never had anyone go back and tidy up.
How do you make it happen every time?
Write it down and give it to one person.
Mark, our technical director, builds the automation that runs this for our clients, so a leaver is a form rather than a memory test. That is the version we would recommend, but the version that matters more is simply that it exists. A one page checklist that somebody owns beats a clever system that nobody runs.
Starters, leavers and moves are inside the monthly fee on every level of our support, which you can see on the pricing page along with everything else we publish. It is included rather than billed by the hour on purpose, because a leavers process that costs money each time it runs is a leavers process that gets skipped.
What to do next
If you have never audited who has access to what, that is the place to start, and it is usually uncomfortable reading. It is step 4 of our free 15 minute security check, which also covers admin accounts and multi factor authentication, and a working leavers process is part of the user access control section of Cyber Essentials. Managed IT support covers the process side of this, and cyber security covers what to do about the accounts you find.
If you would rather just have somebody look, get in touch and we will tell you what we find, whether or not you go any further with us.
Questions
The questions people ask us about this
Should we delete the account or keep paying for the licence?
Disable it, keep the licence for now, and delete it later once you are certain nothing else depends on it. Deleting a Microsoft 365 account starts a 30 day clock on the mailbox and the OneDrive behind it, and businesses regularly discover on day 31 that something important was in there.
Once the data is moved and the account has been disabled for a couple of months, remove the licence. Leaving it on is a bill you are paying for nobody.
How quickly does this need to happen?
Access should be gone before they are, or within the hour if the departure is a surprise. Everything else can follow over the next few days.
Does any of this matter for Cyber Essentials?
Yes. User access control is one of the five controls, and a leavers process you can describe and evidence is part of it. A business that cannot say who has access to what will struggle with that section.