Employee offboarding IT checklist for small businesses
What to switch off, hand over and check when someone leaves a small business, in the order that matters, from email and passwords to laptops and phones.
When someone leaves a small business, the paperwork gets done and the IT usually doesn't. Six months later their email still works, the shared Wi-Fi password is the same, and nobody is sure who has the login for the supplier portal. Most of the time nothing bad comes of it. When it does, it's because an account nobody remembered was still open. This is the checklist we work through when a client tells us someone is leaving, written so you can do it yourself.
Before the last day: make the list
Offboarding fails because nobody knows everything the person had. Spend fifteen minutes writing it down before anything gets switched off:
- Accounts in the company's name: email, the accounting software, payroll, the bank portal, the point of sale, supplier and parts portals, the website host, social media.
- Shared logins they knew: the Wi-Fi password, the alarm code, the door code, any password that lives on a sticky note or in a group chat.
- Things they own on the company's behalf: a domain registered to their personal email, a social media page they created, a Google account the shop's reviews are tied to. This is the one that hurts later.
- Hardware: laptop, phone, tablet, keys, badges, security keys, the USB drive in their desk.
If they're leaving on good terms, ask them to check the list. They'll remember things you won't.
On the day: the order matters
Do these in this order, ideally while they're in their exit conversation or right after.
1. Email first
Email is the reset button for everything else. Whoever controls the mailbox can click "forgot password" on every other account it's tied to. So the mailbox goes first.
Change the password and sign out every session. In Microsoft 365 that's Revoke sessions on the user in the admin center; in Google Workspace it's Sign-out under the user's security settings. Changing the password alone often leaves the phone still syncing mail for a while.
Then remove their phone or tablet from the account's device list, and check two quiet settings people miss: forwarding rules and the recovery phone and email. A forwarding rule to a personal address keeps working after the password changes.
2. Don't delete the mailbox yet
Deleting the account is tempting, and it's usually wrong on day one. Customers will keep emailing that address for months, and the old mail is often the only record of a quote or an agreement.
In Microsoft 365, convert the mailbox to a shared mailbox and give the manager access. That frees the paid license and keeps the mail. In Google Workspace, use the data transfer option to move their Drive files to someone else before you delete, and set up an alias so their address keeps delivering. Either way, set an auto-reply that points people to whoever is taking over.
3. Everything else they could sign in to
Work down the list from earlier. For each account, either remove their user or, if it was a shared login, change the password. Shared logins are why this step takes the longest: one password known by five people means five changes when one of them leaves, which is the strongest argument for a password manager with shared vaults and separate logins for everyone.
Turn off their two-step sign-in methods as you go. If their personal phone is the only second factor on a company account, that account is still theirs until you change it.
4. Money
Remove them from the bank portal, revoke any company card, and cancel or reassign subscriptions billed to a card in their name. Check payroll and expense tools for pending reimbursements so their last check isn't a surprise to either side.
5. Shared codes
Change the Wi-Fi password if they knew it, and the alarm and door codes. Yes, every device on the Wi-Fi has to be reconnected. That's an argument for a separate guest network, not for skipping the change.
The hardware
Collect every device on the list, then decide what happens to each one.
A laptop that's going to another employee should be wiped and set up fresh, not handed over with the old user signed out. Before the wipe, copy off anything the business needs and confirm the copy opens. A laptop you're retiring should be wiped too, and if you can't wipe it (a dead machine, a failed drive), pull the drive and destroy it rather than recycle it whole.
Company phones get the same treatment: sign out of the Apple ID or Google account first, or the phone stays locked to that account and is useless to the next person.
If they used a personal phone for work email, removing the account from the email admin center is enough. You don't need, and shouldn't ask for, access to the rest of their phone.
A week later
Come back once and check:
- Are any of their accounts still showing sign-ins?
- Is mail to their address reaching the right person?
- Did any bill fail because it was on their card?
- Are they still listed as an owner on the domain, the Google Business Profile or the social accounts?
That last one is worth doing even for someone who left years ago. Plenty of businesses find out their website domain is registered to a former employee's personal email only when it fails to renew.
Make the next one easier
Every offboarding is quicker if onboarding was written down. When someone starts, keep a short list of every account you create for them and every code you tell them. When they leave, that list is your checklist.
This is part of what we do for clients. Onboarding and offboarding runbooks are included in our managed IT plans, and we work through them the same day you tell us someone is starting or leaving. If you're in Seminole County or the Orlando area and want someone to look at what you have today, we start with a free written audit, and the report is yours whether you sign or not. For the basics every account should have, see one hour of security for people who don't do IT.