Someone is leaving. Here is the order to do things in

Why the order matters more than the steps

Most small businesses get the individual jobs right and get the sequence wrong, and the sequence is where the damage is. Delete the account too early and you lose the mailbox. Convert the mailbox without one extra step and the person who left can still read it. Remove the licence first and you start a clock you did not know about.

Microsoft publishes a seven step sequence for removing a former employee, and it is worth following in its order (Microsoft, remove a former employee).

  1. Stop them signing in.
  2. Save the contents of their mailbox.
  3. Wipe and block the business data on their phone or tablet.
  4. Forward the email or convert the mailbox to a shared one.
  5. Give someone else access to the OneDrive and Outlook content.
  6. Remove the licence.
  7. Delete the account.

Notice that deleting the account is last, not first. That is the single most useful thing on this page.

The two mistakes that cost people their email

These are the ones we get called about, and both are avoidable in a minute.

Converting the mailbox without resetting the password. Turning a leaver's mailbox into a shared mailbox is the usual move, and it is a good one. But Microsoft is explicit about what carries over: you do not need to reset the account password, and if you do not, the original username and password will continue to work on the shared mailbox after the conversion is finished (Microsoft, convert a user mailbox to a shared mailbox).

So the person who left can still sign in and read everything the team now puts in that mailbox, including the invoices and the customer correspondence. Block the sign in and reset the password as part of the conversion, not as a tidy up later.

Deleting the account after converting the mailbox. The other half of the same trap. Microsoft's guidance says not to delete the old user's account, because the account is required to anchor the shared mailbox. It looks like a leftover. It is load bearing.

What the 30 day clock actually covers

People remember there is a 30 day grace period and misremember what it applies to. Microsoft sets out three different situations, and they behave differently.

What you didWhat happens to the data
Removed or deleted the licence, kept the accountEmail, contacts and calendar are retained for 30 days and then deleted permanently. The OneDrive content stays accessible to you even after 30 days
Deleted the accountOneDrive and Outlook content is retained for 30 days. You can restore the account in that window and get the content back
Restored the account inside 30 daysThe OneDrive and Outlook content stays accessible to you, even after the 30 days are up

The practical reading: keeping the account and dropping the licence is the gentler option, because the files stay reachable. Deleting the account starts a hard 30 day countdown on the mail side.

If there is any prospect of a dispute, a claim or an audit involving this person, do not rely on any of that. Microsoft lists eDiscovery holds as the tool for retaining a departing employee's data for legal or compliance purposes, and a hold is a decision to make before the clock starts, not after.

If your accounts come from a local server

Worth knowing before you start clicking, because the buttons will not behave the way the guides describe.

If your organisation synchronises user accounts to Microsoft 365 from a local Active Directory, Microsoft states you must delete and restore those accounts in your local Active Directory, and that you cannot delete or restore them in Microsoft 365. Doing it in the cloud first creates a mess that syncs straight back.

If you do not know whether that applies to you, that is itself the answer to check first.

A short version to keep

  1. Agree the timing and who authorises it. Ideally before the last day, not during it.
  2. Block sign in and reset the password. Both, not one.
  3. Decide whether anything needs a legal or compliance hold, and apply it before anything else changes.
  4. Save or hand over what is needed: the mailbox contents, and access to the OneDrive files.
  5. Deal with business data on their phone or tablet.
  6. Convert the mailbox to shared, or set forwarding, depending on whether the address needs to keep receiving.
  7. Remove the licence.
  8. Leave the account in place if it is anchoring a shared mailbox. Otherwise delete it, knowing the 30 day clock has started.
  9. Work through the non Microsoft accounts, which is usually the longer list.
  10. Write down what you did, so the next departure takes a fraction of the time.

Ask us to run the handover with you

Frequently asked questions

Can we just delete the account and be done?

You can, but it is the step that costs people data. Deleting the account stops mail being received at that address, and it starts a 30 day window after which the OneDrive and Outlook content is gone. Work through the handover first and leave deletion until last.

If we convert the mailbox to shared, can the person who left still get in?

Yes, unless you reset the password. Microsoft states that if you do not reset the account password, the original username and password will continue to work on the shared mailbox after the conversion. Block the sign in and reset the password as part of the conversion.

Why should we keep the old account at all?

Because a shared mailbox created by conversion needs it. Microsoft's guidance says not to delete the old user's account, since the account anchors the shared mailbox. Removing the licence is the part that stops the cost.

How long do we have to get the files back?

It depends what you did. Remove the licence but keep the account, and the OneDrive content stays reachable beyond 30 days while mail, contacts and calendar are kept for 30 days then permanently deleted. Delete the account, and OneDrive and Outlook content is retained for 30 days, during which restoring the account brings it back.

We are in a dispute with this person. Does the 30 days matter?

Treat the standard retention as insufficient. Microsoft lists eDiscovery holds for retaining a departing employee's data for legal or compliance reasons, and that decision needs making before licences and accounts change, not afterwards. Take advice on what you are required to keep.

Our logins come from a server in the office. Is this different?

Yes. If accounts synchronise from a local Active Directory, Microsoft says you must delete and restore them there, not in Microsoft 365. Doing it in the cloud gets undone by the next sync.

What about everything that is not Microsoft?

That is usually the bigger list and the one that gets forgotten: the password manager, the accounting package, the website and hosting, the domain registrar, social accounts, any supplier portal, the alarm code and anything with a shared login. Write it down once while you can still ask the person, and reuse it every time.