The short answer: New hires should get only the access their role actually needs, set up the same way every time. Departing employees should have every account, device, and credential cut off the same day employment ends — not whenever someone on the team gets to it. A short written checklist for both moments closes the gap that attackers most often find first: an account nobody remembered to turn off.
That's not a hypothetical risk. In one case documented by the Cybersecurity and Infrastructure Security Agency (CISA), a threat actor accessed a state government organization's network simply by signing in with a former employee's VPN credentials — an account the organization had never disabled. The fix isn't complicated technology; it's a consistent process applied every time someone joins or leaves.
7 Steps for Onboarding and Offboarding Staff IT Access
1. Give new hires only the access their role needs
The National Institute of Standards and Technology ( NIST) calls this "least privilege" — restricting each person's access to the minimum needed to do their job. The Federal Trade Commission ( FTC) puts it more plainly for small businesses: "restrict sensitive information access to only those who need it to do their jobs." A new front-desk hire and a new office manager shouldn't get identical access by default just because it's easier to copy the last person's setup.
2. Build a standard access template for each role
Decide in advance what a "standard" front-desk, clinical, accounting, or admin account looks like — which systems, which folders, which software licenses. Working from a template makes onboarding faster and, just as important, makes offboarding complete: you know exactly what to remove because you know exactly what was granted. Revisit the templates whenever you add or drop a piece of software, so the list stays accurate instead of becoming a guess a year later.
3. Require unique logins — never shared accounts
A shared login for a shared mailbox or accounting tool feels convenient until someone leaves and you have to decide whether to change a password everyone else also depends on. Individual logins mean one person's departure never forces a scramble to reset access for the whole team.
4. Revoke access the same day employment ends
CISA's advisory on the former-employee VPN incident recommends that organizations "continuously remove and disable accounts and groups from the enterprise that are no longer needed, especially privileged accounts," and specifically ensure "accounts of offboarded employees are removed and can no longer access the network." Same-day matters — a departing employee's account is most likely to be misused, whether by the person themselves or by an attacker who obtains the credentials later, in the days immediately after it stops being watched.
5. Follow a complete offboarding sequence, not just a password reset
Disabling sign-in is the first step, not the whole job. For a Microsoft 365 environment, Microsoft's own offboarding guidance lays out a full sequence: block the former employee from signing in, secure and reassign their mailbox and OneDrive content, wipe company data from their mobile device, forward or convert their email, then remove the license and finally delete the account. Microsoft also notes that after a license is removed, mailbox and OneDrive content are retained for 30 days before permanent deletion — a useful window if something is needed after someone has already left.
6. Retrieve devices and company property
Laptops, phones, key fobs, badges, and any hardware security keys should be on a short list tied to each employee, so nothing is forgotten in the last conversation. If a device can't be physically retrieved right away, it should still be remotely locked or wiped the same day, not left active "until we get it back." Don't forget accounts that live outside your main systems, too — a company card saved in a cloud app, a personal phone number registered for two-factor codes, or a vendor portal login set up before your standard template existed.
7. Review who still has access on a regular schedule
Even a good process misses something occasionally — a shared app that IT didn't know about, a vendor portal, an old file-share invite. CISA's guidance frames this as a continuous practice, not a one-time cleanup: periodically reviewing administrator and standard accounts to confirm each one is still needed keeps small gaps from becoming the way someone gets back in.
⚠️ A real incident, not a hypothetical: In CISA advisory AA24-046A, an attacker used a former employee's still-active, privileged VPN account — obtained through a separate data breach — to get into a state government network and begin reconnaissance. The account had simply never been disabled after the employee left.
Quick Self-Check: Where Does Your Business Stand?
- New hire access: Is there a defined, role-based list of what a new employee gets access to before their first day?
- Shared logins: Does anyone currently share a login for email, accounting software, or a shared drive?
- Same-day offboarding: If someone left today, could every one of their accounts be disabled before end of day?
- Devices: Is there a list of who has a company laptop, phone, or key fob, so it can be recovered on exit?
- Mailbox and files: Is there a plan for who takes over a departing employee's email and documents?
- Access review: Has anyone checked in the last 90 days for accounts that should have been removed but weren't?
Common Questions
What's the biggest offboarding mistake small businesses make?
Treating it as a single step — "turn off their email" — instead of a sequence. Sign-in, mailbox, files, mobile device, physical property, and license all need their own step, and it's easy for one of them to slip through when it's handled from memory instead of a checklist.
Do we need special software to manage onboarding and offboarding?
Not necessarily. A written role-based checklist covers most small offices. Identity management tools become more useful as the number of systems and employees grows, but the checklist habit matters more than the tool.
What happens to a departing employee's email and files?
That's a decision to make before someone leaves, not during their exit conversation. In Microsoft 365, for example, content can be forwarded, reassigned to another employee, or placed under a legal hold if there's a compliance reason to preserve it — each option is set up differently, so it helps to decide in advance which one applies.
How long should we keep a former employee's data?
That depends on your industry's recordkeeping requirements and any pending legal or compliance needs — this varies by business and isn't something a general article can answer for your organization. It's worth deciding as policy rather than case by case.
Is onboarding and offboarding IT access an HR job or an IT job?
Both. HR usually knows the start and end dates first; IT is the one who actually grants or removes access. The businesses that handle this well treat it as a shared checklist with a clear handoff point — HR notifies IT the moment a date is confirmed, not the morning someone's last day arrives.
How Bridge IT Services Helps Massachusetts Businesses
Bridge IT Services, based in Braintree, MA, supports Massachusetts businesses within about 50 miles of our office with managed IT, network, and security support, including help setting up consistent account access for new hires and closing it out completely when someone leaves. If you're not sure every departed employee's access has actually been removed, that's worth a conversation.
Not sure every former employee's access is really gone?
Book a free consultation by phone at (857) 344-0222 or in person at 400 Franklin St, Suite 203, Braintree.







