How to offboard departing staff without leaving accounts open

A 2026 offboarding security checklist for Australian teams: revoke access same-day, rotate shared logins, recover devices and keep the evidence trail.

A departing employee who still holds a working login after their last day is one of the quietest security failures an Australian business can have. This guide gives managers a same-day offboarding sequence that closes every door — email, finance systems, shared vaults, devices — and the dated record that proves it happened.

Key takeaways

Who this is for

This is for owners, HR and office managers at Australian organisations between roughly 5 and 200 staff, and for MSPs who run offboarding on behalf of clients. You do not need an IT department — every step here uses an admin console you already pay for, and the whole sequence fits inside about 60 minutes.

Why this matters

When someone leaves, the instinct is to focus on handovers and final pay. The accounts they hold are the last thing anyone touches, and that gap is exactly what attackers and departing grudges exploit. An active mailbox on a departed employee's name keeps receiving company mail; an unrecovered laptop holds client files; a shared vault password the leaver memorised still opens the Xero login.

The broader habit that makes offboarding work is training. If staff already know how to report a suspicious email and why security awareness matters day to day, closing their access is a short, low-drama conversation. If not, offboarding becomes the only security ritual the company performs, and it shows.

The 60-minute offboarding sequence

Step 1: Disable the account — do not delete it

In your email or directory console, suspend the account rather than deleting it. Deletion destroys mail, files and audit history you may legally need to keep; suspension closes the door while preserving everything. Set a calendar reminder to review deletion against your record-keeping obligations after 12 months.

Step 2: End active sessions and revoke MFA enrolment

Changing a password does not log the person out of mail apps, phone mail clients or saved sessions. In the admin console, force sign-out of all sessions and revoke the account's multi-factor authentication enrolment. The Australian Signals Directorate describes MFA as one of the most effective protections against unauthorised account access — and the same is true in reverse: an enrolled device a leaver still holds is an open door even after a password change. The relevant guidance lives at cyber.gov.au's MFA advice.

Step 3: Rotate shared credentials

List every shared login the person could reach: the Xero or MYOB account, the courier portal, social media, the subscription tools, the team password vault. Rotate each of those passwords during offboarding and confirm the new credentials landed with the people who now own them. If you keep a shared vault, this step is one revoke-and-rotate action; if shared logins live in a spreadsheet, this is the week to fix that.

Step 4: Transfer ownership

Reassign what the leaver owned before their access dies: file ownership in cloud drives, email delegation and auto-replies to a real colleague, calendar ownership, and any integrations or API tokens tied to their account. An integration that authenticates as a departed employee is an outage waiting for three weeks' time.

Step 5: Recover devices and company data

Collect the laptop, phone, tokens and keys on or before the final day. Confirm backups and cloud sync are current first, then wipe devices as part of your standard cyber security gap assessment process rather than shelving them unwiped in a cupboard.

Step 6: Update forwarding, mailing lists and door lists

Check for email forwarding rules the leaver may have set — an auto-forward to a personal address that survived into offboarding is a data leak running quietly in the background. Remove them from distribution lists, client mailing aliases, building access and after-hours door codes the same day.

Step 7: Close third-party seats

Count the software subscriptions that bill per seat. Revoke or reassign the leaver's seat in each within 24 hours; most vendors charge for an open seat whether or not anyone uses it, and a paid but unused seat is a dangling account too.

Step 8: Log the record

Write one dated line per action: what was closed, by whom, when, and any exception that could not be completed. When a cyber insurer, an auditor or an acquiring party asks for offboarding evidence in 2026, this log is the document they mean.

What to rotate — the quick table

Credential typeActionOwner
Personal loginDisable, preserve, review in 12 monthsIT or office manager
Shared logins and vault entriesRotate password, confirm handoverDepartment lead
MFA enrolmentRevoke enrolled devicesIT or office manager
Email forwarding rulesAudit and removeIT or office manager
Per-seat softwareRevoke or reassign within 24 hoursBudget holder
Physical devices and keysRecover, back up, then wipeOffice manager

Special cases

What to avoid

FAQ

What is a secure employee offboarding checklist? A dated sequence that disables the account, kills sessions and MFA enrolment, rotates shared credentials, transfers ownership, recovers devices and records each action on the employee's final day.

How fast should a departing employee lose access? Within 24 hours of their last day — ideally during it. The 60-minute sequence above fits a normal business morning.

Should we delete or disable a departed employee's mailbox? Disable first, delete later. Suspension closes access while preserving mail and history your record-keeping obligations may require.

Do we need to change passwords the employee knew? Yes — every shared credential they could reach, not just their own login. Session tokens and remembered passwords outlive the account itself.

What about personal devices used for work? Remove work data and app access from personal devices the same day, and record what was removed. Do not factory-reset a personal device without the owner's consent.

Who should own offboarding in a small business? One named person — usually the office manager or an MSP — with HR triggering the checklist. Offboarding fails when everyone assumes someone else did it.

What evidence should we keep? A dated log of each closure action and any exception. Insurers, auditors and procurement checks increasingly ask for it, and it costs nothing to maintain.

One last thing

The cheapest audit of your offboarding process costs nothing: pick a staff member who left in the last six months and try their email address in your systems. What happens next tells you more than any policy document.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.