HomeInsightsMicrosoft 365 operations

Microsoft 365 Offboarding: Data Handoff and Acceptance

A good Microsoft 365 offboarding record proves two things: the departing employee's access has been addressed, and the right people can continue the work. Removing a licence by itself does not document either outcome.

This guide is for the business owner, office manager and administrator coordinating one departure. Use the handoff template to agree who may receive which data, record the technical actions and test the result. It is a planning procedure, not permission to inspect an employee's entire mailbox or erase their personal device.

Agree purpose, timing and authority first

Record the departure time and time zone, the person authorising access changes, the data owner and the successor responsible for active work. Ask whether any preservation instruction, investigation or legal hold changes the plan. Give the technical operator a precise, approved request rather than "delete the user today".

Canadian workplace privacy obligations can continue after employment ends. The Office of the Privacy Commissioner explains that applicable requirements depend on the employer and jurisdiction, and that employee information should be accessed on a need-to-know basis. Do not assume PIPEDA's employee provisions apply identically to every Canadian SMB. Read the OPC's workplace privacy guidance.

For this workflow, ask your privacy or employment adviser to resolve uncertainty about mailbox review, retention, notice or personal-device handling. A technical administrator can implement an approved access decision; the presence of an admin button does not decide the lawful scope of that decision.

Treat access, data and licensing as separate decisions

Microsoft's offboarding guidance covers preventing sign-in, preserving required content, device handling, mail continuity, OneDrive handoff, licensing and account deletion. Use its current instructions for the tenant you actually operate. Hybrid identities also require attention to the on-premises directory. See Microsoft's offboarding overview.

Decisions to record before closing the request
DecisionWhat the business decidesWhat IT records
AccessWhen access ends and which connected services are in scope.Actions, timestamps, identity source and verification evidence.
PreservationWhich records must be retained and who authorises any hold or deletion.Applied settings, approved storage and outstanding questions.
Mail continuityWho handles new requests and whether historic mail access is necessary.Chosen configuration, delegate access and test-message outcome.
Files and workWhich active projects need a successor and where shared records should live.Inventory, transfer method, destination and successor acceptance.
DeviceWho owns it and what collection, return or wipe action is authorised.Asset reference and approved action, with exceptions documented.
Licence and accountWhen prerequisites are satisfied and who approves the final change.Current feature requirements, remaining dependencies and scheduled follow-up.

For access removal, follow Microsoft's current procedure for password/session handling and blocking sign-in. Allow for the documented behaviour of the service rather than promising every session ends instantly. Also inventory applications that use separate identities or vendor-specific sessions; put unresolved checks in the handoff record. Microsoft's sign-in and access-blocking instructions.

Choose the destination for the work, not just the account

Mailbox: new requests and old records are different needs

Microsoft distinguishes forwarding new incoming messages from converting a mailbox so authorised delegates can access existing mail. Shared-mailbox licensing depends on the configuration, including size and required features, so confirm the actual requirements before removing a licence. Microsoft's forwarding and shared-mailbox guidance.

Record an owner and review date for temporary continuity. An address that quietly forwards forever is easy to forget. The test should confirm that a clearly labelled test message reaches the intended recipient and that the recipient understands what to do with it. Avoid sending real customer data as a test.

OneDrive: identify the active project records

Microsoft documents ways to give another employee access to a departing user's OneDrive content. Use the documented procedure before relying on account removal to trigger a handoff. Microsoft's OneDrive and Outlook handoff instructions.

Ask the project owner for the files required to continue work: the current estimate, source workbook, signed deliverable or working project folder. Record the chosen destination, relevant sharing restrictions and who will check it. If a permanent team location is appropriate, plan it with the SharePoint file-management guide. Do not move everything into another person's private folder simply because it is quick.

Do not use a remembered "30-day rule" as the deletion plan. Verify your actual retention settings, account state, licence requirements and preservation obligations. Put the verified date and source in the record rather than assuming that every Microsoft 365 workload has the same recovery window.

Owned workflows: find the dependencies that are not files

Ask who receives renewal notices, owns recurring meetings, approves supplier requests and maintains automations. Record each dependency separately with its replacement owner. Moving documents does not prove a scheduled workflow or third-party service will continue. Where the required administrator is not available, keep the task open and use a documented escalation route.

Test the blocked path and the working path

Arrange verification with your administrator using the service's supported checks. Do not ask a former employee to share their password for testing. For a rehearsal, use an authorised synthetic account with sample content and no production customer information.

  • Access: the operator records the configured state and the agreed verification result, including any pending or separate application sessions.
  • Mail: a labelled incoming test request follows the approved continuity route.
  • Files: the successor opens the required project records using their own account and the intended permissions.
  • Dependencies: a named owner accepts each recurring task, integration or external account that needs continuity.
  • Privacy: delegated access matches the approved scope, and temporary access has a review date.
  • Closure: licence removal or account deletion waits for its documented prerequisites; exceptions have owners and due dates.

Download the handoff and acceptance record

Download the Microsoft 365 handoff template

The plain-text template separates approvals, access actions, required data, mail routing, devices, dependencies and acceptance. It can live in your existing ticket system. Keep the completed record restricted; use links to approved evidence instead of attaching entire mailboxes or copying employee documents into the checklist.

A hypothetical handoff decision

A project coordinator leaves while an estimate remains in their OneDrive. The manager needs that project workbook, and customers still email the coordinator's address. The business approves a named successor for the project and a defined mail-continuity arrangement. IT records the access change, gives the successor the approved content and tests the incoming mail route. The successor then confirms the workbook opens and the required references are usable.

If the workbook points to a missing source file, continuity is not accepted yet. Record the missing dependency and its owner rather than closing the ticket because the account was blocked. This is a fictional example, not a reported client outcome or a claim that this template has been tested in your tenant.

Make the next departure easier to handle

Review the Microsoft 365 security baseline for the wider tenant configuration. If a departure could leave the business without an available administrator, prepare an emergency-access drill before that dependency becomes urgent.

Use the completed record to identify recurring ownership gaps. Store shared work in an agreed team structure, keep a current asset and application inventory, and define who can approve access to former-employee records. The IT procurement guide, provider-exit checklist and recovery plan cover related ownership questions.

For help implementing a reviewed handoff, see managed Microsoft 365 support or contact North Star. Use an approved secure channel for employee information and account details.