Skip to content

Employee Offboarding: The IT Deprovisioning Checklist for Texas SMBs

By Donovan Brown
July 20, 2026
8 sections
Employee Offboarding: The IT Deprovisioning Checklist for Texas SMBs

Orphaned accounts are a standing security and identity risk. Here is the IT offboarding checklist Texas SMBs use to revoke access, kill authentication tokens, and recover devices.

01

Introduction

When someone leaves your company, the exit interview gets scheduled, the final paycheck gets cut, and the laptop maybe comes back. What often does not happen is a clean, complete IT offboarding — and that gap is one of the most reliable ways a Texas SMB gets burned. An orphaned account is a working set of credentials attached to a person who no longer answers to you: no manager watching it, no one noticing the logins, and no reason for it to exist. Industry reporting consistently ties a meaningful share of security incidents back to employees who were never properly deprovisioned. The fix is not expensive software. It is a checklist you run the same way every single time.

02

Why Offboarding Fails at Most Small Companies

Offboarding rarely fails because someone is careless. It fails because it is spread across three departments and owned by none of them. HR knows the termination date. The manager knows which systems the person actually touched. IT knows how to revoke access — but usually finds out last, sometimes days later, occasionally from a Slack message that says "hey, is Dave still in the shared drive?"

The second failure is scope. Disabling one Microsoft 365 account feels like the job is done, but the modern employee accumulates far more than one login: the CRM, the accounting platform, the shipping portal, the marketing tool a department bought on a credit card, the vendor site where they are the only registered contact. Anything outside your identity provider survives the account disable untouched. That is the same shadow IT and BYOD sprawl that makes inventory hard on a good day, and it is exactly what an offboarding checklist is designed to surface.

03

The Core Deprovisioning Checklist

Run these in order, ideally within the first hour after the departure is effective. For an involuntary termination, run them during the conversation, not after.

  1. Disable the identity account — do not delete it. Deleting destroys mailbox data, file ownership, and the audit trail you may need later. Disable, then retain per your policy.
  2. Revoke active sessions and refresh tokens. This is the step almost everyone misses. A disabled account can stay signed in on a phone or browser for hours or days because the session token is still valid. Force a global sign-out so the credential change actually takes effect.
  3. Reset the password and remove MFA methods. Strip registered authenticator apps, phone numbers, and passkeys so no self-service recovery path remains.
  4. Remove them from every group, role, and shared vault. Group membership is how access quietly persists; so is a shared password vault. Revoke their password manager access and rotate any shared credentials they could have memorized or exported.
  5. Terminate admin and privileged access first. If the person held elevated rights, treat this as the highest-priority item and confirm it independently — the controls in privileged access management exist precisely for this moment.
  6. Handle the mailbox and files. Convert the mailbox to shared or delegate it to the manager, forward incoming mail, and transfer ownership of documents, sites, and calendars before anything gets archived out from under the team.
  7. Deprovision every SaaS app on the list. Work from an inventory, not memory. Each app gets an explicit removal, and licenses get reclaimed while you are in there.
  8. Kill non-user access paths. VPN certificates, API keys, service accounts they created, OAuth app grants, SSH keys, and any building or alarm codes tied to their name.
  9. Recover and wipe the device. Retrieve company hardware and issue a remote wipe or retire command; for personal devices under BYOD, wipe only the corporate profile. This is where Intune device compliance earns its keep.
  10. Document the whole thing. Who was removed, from what, by whom, on what date. That record is your evidence during an audit or an incident.
04

The Inventory Problem You Have to Solve First

Every step above depends on knowing what the person had access to, and most Texas SMBs cannot answer that question quickly. Build the answer before you need it. Start with a simple per-role access map: for each job function, list the systems, the level of access, and who approves it. New hires get provisioned from that map, and departures get deprovisioned against it.

Two habits keep the map honest. First, route new app purchases through IT so nothing lands outside the inventory. Second, run a quarterly access review where managers confirm their team's access is still appropriate. That review does double duty: it enforces least-privilege access control for current staff and it catches the accounts that survived a past offboarding. If you have ever run a review and found a login belonging to someone who left eight months ago, you already know why this matters.

05

Automating the Parts You Should Not Do by Hand

Manual checklists work until you are doing three departures in a week. Wherever possible, let the identity platform carry the load. Single sign-on is the highest-leverage investment here: when every app authenticates through one identity provider, disabling the account genuinely closes most doors at once. Layer on Conditional Access policies that block sign-in from disabled or non-compliant accounts, and automated group-based provisioning so removing someone from a group removes their app access as a side effect rather than a separate task.

Automation does not eliminate the checklist — the apps that refuse to support SSO will always need a human — but it shrinks the manual list to something a person can finish in one sitting without missing anything.

06

Offboarding Is a Compliance and Insider-Risk Control

Auditors ask about this directly. Timely access termination is an explicit expectation under SOC 2, and equivalent requirements appear across HIPAA, PCI DSS, and the frameworks most Texas SMBs get measured against. The evidence they want is not your intent — it is your ticket history showing that access was revoked, by whom, and how fast.

There is a risk dimension too. Most departing employees are not malicious, but the ones who are tend to act in the window between resignation and revocation: copying a client list, forwarding files to a personal address, keeping a login "just in case." A documented offboarding process is a core piece of any insider threat program, and pairing it with monitoring in your broader cybersecurity stack means unusual activity from a departing account gets noticed while there is still time to act.

07

Where to Start

This week, do one thing: write down every system your last departing employee had access to, then go verify their access is actually gone. Most teams find at least one live account. Turn that list into a reusable offboarding ticket template with a checkbox per system, and make "notify IT" a required step in your HR termination process so the clock starts on time instead of three days late. From there, work toward SSO so the list gets shorter every quarter. If you would rather have offboarding, access reviews, and license reclamation handled as standing process, our managed IT support and Microsoft 365 managed services teams build it into onboarding and offboarding runbooks — and if you are still evaluating partners, our guide to choosing a Houston MSP covers what to ask. A full Houston managed IT engagement covers the identity, device, and documentation side together.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call