Orphaned accounts are a standing security and identity risk. Here is the IT offboarding checklist Texas SMBs use to revoke access, kill authentication tokens, and recover devices.
When someone leaves your company, the exit interview gets scheduled, the final paycheck gets cut, and the laptop maybe comes back. What often does not happen is a clean, complete IT offboarding — and that gap is one of the most reliable ways a Texas SMB gets burned. An orphaned account is a working set of credentials attached to a person who no longer answers to you: no manager watching it, no one noticing the logins, and no reason for it to exist. Industry reporting consistently ties a meaningful share of security incidents back to employees who were never properly deprovisioned. The fix is not expensive software. It is a checklist you run the same way every single time.
Offboarding rarely fails because someone is careless. It fails because it is spread across three departments and owned by none of them. HR knows the termination date. The manager knows which systems the person actually touched. IT knows how to revoke access — but usually finds out last, sometimes days later, occasionally from a Slack message that says "hey, is Dave still in the shared drive?"
The second failure is scope. Disabling one Microsoft 365 account feels like the job is done, but the modern employee accumulates far more than one login: the CRM, the accounting platform, the shipping portal, the marketing tool a department bought on a credit card, the vendor site where they are the only registered contact. Anything outside your identity provider survives the account disable untouched. That is the same shadow IT and BYOD sprawl that makes inventory hard on a good day, and it is exactly what an offboarding checklist is designed to surface.
Run these in order, ideally within the first hour after the departure is effective. For an involuntary termination, run them during the conversation, not after.
Every step above depends on knowing what the person had access to, and most Texas SMBs cannot answer that question quickly. Build the answer before you need it. Start with a simple per-role access map: for each job function, list the systems, the level of access, and who approves it. New hires get provisioned from that map, and departures get deprovisioned against it.
Two habits keep the map honest. First, route new app purchases through IT so nothing lands outside the inventory. Second, run a quarterly access review where managers confirm their team's access is still appropriate. That review does double duty: it enforces least-privilege access control for current staff and it catches the accounts that survived a past offboarding. If you have ever run a review and found a login belonging to someone who left eight months ago, you already know why this matters.
Manual checklists work until you are doing three departures in a week. Wherever possible, let the identity platform carry the load. Single sign-on is the highest-leverage investment here: when every app authenticates through one identity provider, disabling the account genuinely closes most doors at once. Layer on Conditional Access policies that block sign-in from disabled or non-compliant accounts, and automated group-based provisioning so removing someone from a group removes their app access as a side effect rather than a separate task.
Automation does not eliminate the checklist — the apps that refuse to support SSO will always need a human — but it shrinks the manual list to something a person can finish in one sitting without missing anything.
Auditors ask about this directly. Timely access termination is an explicit expectation under SOC 2, and equivalent requirements appear across HIPAA, PCI DSS, and the frameworks most Texas SMBs get measured against. The evidence they want is not your intent — it is your ticket history showing that access was revoked, by whom, and how fast.
There is a risk dimension too. Most departing employees are not malicious, but the ones who are tend to act in the window between resignation and revocation: copying a client list, forwarding files to a personal address, keeping a login "just in case." A documented offboarding process is a core piece of any insider threat program, and pairing it with monitoring in your broader cybersecurity stack means unusual activity from a departing account gets noticed while there is still time to act.
This week, do one thing: write down every system your last departing employee had access to, then go verify their access is actually gone. Most teams find at least one live account. Turn that list into a reusable offboarding ticket template with a checkbox per system, and make "notify IT" a required step in your HR termination process so the clock starts on time instead of three days late. From there, work toward SSO so the list gets shorter every quarter. If you would rather have offboarding, access reviews, and license reclamation handled as standing process, our managed IT support and Microsoft 365 managed services teams build it into onboarding and offboarding runbooks — and if you are still evaluating partners, our guide to choosing a Houston MSP covers what to ask. A full Houston managed IT engagement covers the identity, device, and documentation side together.
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.