Common problem

Somebody left. Can they still get in?

Closing the mailbox is where most offboarding stops. Sign-in, sessions, forwarding rules, shared passwords, devices and licences all continue working until somebody deals with each one.

Turning off the mailbox does not turn off access. The account can often still sign in, existing sessions can stay alive on a phone that was never handed back, and anything the person reached with a shared password is untouched, because that password has not changed.

None of this requires anyone to behave badly. The usual outcome is not theft. It is an account nobody watches, still licensed, still able to sign in, sitting there until something else finds it.

,

What to check, in this order

The order matters more than the list. Deleting the account first is the most common way businesses lose a mailbox they later need.

  • Sign-in is blocked, not just the mailbox. Blocking sign-in in Entra ID is the step that actually stops the account being used. Hiding it from the address book does not.
  • Active sessions are revoked. A signed-in session on a phone or laptop can survive a password change. Revoking sessions is a separate action and it is the one most often missed.
  • Forwarding and inbox rules. Check for forwarding to an outside address and for rules that move mail into a folder. Both persist after the person has gone.
  • Shared passwords they knew. The bank portal, the supplier account, the shared login four people use. None of those are in Microsoft 365, and none of them change on their own.
  • Devices still enrolled or syncing. A personal laptop with OneDrive still signed in keeps company files current. If devices are managed, this is a wipe. If they are not, it is a conversation.
  • Application consent. Anything the person connected to their work account with an OAuth grant may still hold access. Consent given once stays given.
  • Mailbox and files handed over. Convert the mailbox or delegate it, and move the OneDrive content to a manager, before the licence is removed.
  • The licence, last. Removing the licence first is what causes data loss. It is the final step, not the first.
,

Why it usually happens

Nothing here is negligence. It is the predictable result of offboarding being owned by whoever is free that week.

The list lives in somebody's head

There is no written record of what a person could reach, so the offboarding covers what is remembered, which is email and the building keys.

The systems outside Microsoft 365 have no owner

Vendor portals, the payroll site and the booking system were each set up by whoever needed them first. They are not in anybody's leaver process because nobody wrote a leaver process.

Nobody wants to break something

Removing access feels risky when you do not know what depends on it, so the account stays "just in case" and the case never comes.

,

If you think somebody still has access right now

  1. Block sign-in on the account

    This is reversible and takes a minute. Do it before investigating, not after.

  2. Revoke the active sessions

    Otherwise a device that is already signed in carries on working.

  3. Look at the sign-in logs

    Whether the account has been used since the leaving date, and from where. This is the question you actually want answered.

  4. Check forwarding and rules on the mailbox

    If mail is being copied out, this is the point at which it becomes urgent rather than untidy.

  5. Change the shared passwords they knew

    Starting with anything that touches money or customer data.

  6. Then tidy up properly

    Mailbox, files, devices, applications and the licence, in that order.

,

Who this is for

  • Somebody has left and you are not certain what they could reach.
  • People have left over several years and nobody kept a record.
  • You are being asked, by an insurer or a customer, to show that access is removed.
  • A licence bill looks higher than the number of people who work there.

When this is not the right fit

  • You believe an account is being actively misused right now. That is an incident, and the first calls are to your bank and your insurer, not to a review.
  • You need somebody to give evidence or investigate a dispute with a former employee. That is a forensic job and a different profession.
,
,

What Tech True Point can help with

Where this usually goes next:

  • Working through every leaver properly, rather than the ones somebody remembers.
  • A joiner and leaver process short enough that it actually gets followed.
  • Access reviews on a schedule, so this does not rebuild over the next two years.
  • Licence cleanup, which frequently pays for the work.
,

Common questions

We deleted their account. Is that enough?

Usually not on its own, and deleting is often the wrong first move. Deleting an account can take the mailbox with it, along with anything only that person had in OneDrive, and it does not touch access that lives outside the account: shared passwords they knew, applications they consented to, or a personal device still syncing company files.

The safer order is to block sign-in first, revoke the active sessions, deal with the mailbox and files deliberately, then remove the licence.

How would we even know if they still have access?

Sign-in logs in Entra ID will tell you whether the account has been used and from where. Mailbox rules and forwarding will tell you whether mail is still being copied somewhere. Device records will tell you what is still enrolled and syncing.

All of it is visible to an administrator who knows where to look, which is most of what a review is.

They left on good terms. Does this still matter?

Mostly this is not about the person. An account that nobody uses and nobody watches is an easier target than an account somebody signs into every day, because nothing looks unusual when it is used.

The other reason is administrative rather than dramatic: a licence assigned to somebody who left eleven months ago is a bill you are still paying.

How long does this take to fix?

For one recent leaver, an hour or two of an administrator's time. For several years of leavers where nobody is sure who has gone, it is a piece of work rather than a task, because the first job is establishing who those people were.

That is the situation the Security and Cost Review is built for.

,
Get a Quote

Not sure who still has access

If the honest answer covers several people over several years, that is the normal starting point rather than an embarrassing one. The review works through it properly.

Call now Request a quote