IT Offboarding Checklist Template

Leaver access rarely survives because nobody removed it. It survives because the steps ran in the wrong order: the account disabled the day after a dismissal, the licence released before the mailbox was saved, the laptop wiped before anyone checked what was on it.

This free IT offboarding checklist is the IT team’s side of every leaver, run with HR and the line manager. It confirms the last day and leaver type, cuts single sign-on and email at a set time, closes accounts, rotates the secrets the person could see, moves their data, wipes their devices, reclaims licences and ends with a final access review. Due dates count from the last working day, and an involuntary exit gets a cut-off task only the IT owner can open.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Where IT Offboarding Sits Among the Leaver Checklists

A departure touches three teams, and each needs a list it can finish. HR owns the person, IT owns the access and the equipment, and dozens of apps sit in between. One HR form gives IT a single line saying “remove access”, which is how a dismissed employee keeps a working VPN profile for a week.

HR-wide

Employee offboarding

Covers: notice, final pay, knowledge handover, the exit interview and team communication.

Owner: HR, with the manager.

IT’s part: one phase that hands off to a technical checklist.

This checklist

IT offboarding

Covers: identity and email cut-off, accounts, secrets, data, devices, licences, groups and the on-call rota.

Owner: IT, triggered by HR, with the manager confirming the handover.

Done when: a final access review finds nothing active and the approver signs off.

App by app

SaaS access offboarding

Covers: every app the leaver used, including shadow IT, OAuth grants and personal tokens.

Owner: IT or the SaaS owner, with each app admin.

Used when: the app estate is too big for one task row.

Pay and the exit interview stay in the Employee Offboarding Checklist, and apps outside single sign-on go to the SaaS Access Offboarding Checklist. Remote leavers add courier returns and time zones, covered by the Remote Employee Offboarding Checklist. Someone changing roles needs the Internal Transfer & Role Change Checklist, because their access changes rather than ends.

What the IT Offboarding Checklist Covers

Seven phases run once per leaver, in the order that keeps access closed. The leaver type picks the cut-off task, scope answers add privileged-access and legal-hold tasks, and the checklist halts at the cut-off, the handover decision and the sign-off.

Phase 1

Phase 1: Leaver, Type & Cut-off Time

The people picked on the first task are assigned the later tasks. An involuntary exit hides the file request, so nothing tips the leaver off.

  • Record the leaver, the leaver type and the owners — Voluntary, Involuntary or Contractor, plus the line manager, HR contact, IT owner and sign-off approver
  • Confirm the last working day and the access cut-off with HR — a date and a local time; for an involuntary exit, the minute the meeting starts
  • Answer the scope questions — whether the leaver held admin or privileged access, and whether a legal hold or investigation applies
  • List the leaver’s accounts, devices and shared secrets — from the identity provider, the asset register and the password manager’s sharing report
  • Hand over on-call shifts that fall after the last day — swap them now, so nobody pages a disabled account at 3am
  • Ask the leaver to move working files to shared locations — during the notice period, while they can still say what matters
Phase 2

Phase 2: Identity, Email & Hand-in

The first task appears only for an involuntary exit: assigned exclusively to the IT owner, due at the cut-off minute, and halting the checklist. Other leavers get the scheduled block in the second task, which also halts.

  • Cut all access while the termination meeting is under way — block sign-in, revoke sessions and disable remote access in one sitting, at the agreed minute
  • Block sign-in at the identity provider at the agreed cut-off — the end of the leaver’s last working day, not the end of IT’s shift
  • Revoke refresh tokens, sign-in sessions and app passwords — access tokens already issued keep working until they expire, one hour by default in Entra ID
  • Reset the password and remove MFA methods and passkeys — so the leaver’s phone no longer approves anything; in a hybrid directory, reset it twice
  • Disable VPN, remote desktop and the leaver’s registered devices — certificates and device trust can outlive the account
  • Collect the laptop, phone, security keys and badge at the exit meeting — check each serial against the Phase 1 list and disable the badge
  • Check the sign-in logs the morning after the cut-off — no successful sign-ins after it, from any location or app
Phase 3

Phase 3: Accounts in Each Tool

The guest-account task appears only for a contractor.

  • Confirm connected apps have deprovisioned the account — automatic provisioning runs on a cycle, every 20 to 40 minutes in Entra ID, so check each app
  • Disable or transfer accounts in apps outside single sign-on — one row per app in the table: disable, transfer ownership or keep with a reason
  • Move admin and owner roles to a named successor — domain registrar, DNS, cloud console, billing and social accounts where one person holds the only login
  • Remove the contractor’s guest accounts and sponsor links — guest access in your tenant and any client or partner portals they were given
  • Send the app-by-app long tail to the SaaS offboarding checklist — OAuth grants, personal tokens and tools found on expense claims
Phase 4

Phase 4: Shared Passwords, Secrets & API Keys

The last three tasks appear only when the leaver held admin or privileged access.

  • Rotate every shared password the leaver could see — vault items shared with them, team logins, Wi-Fi keys and alarm codes; assume they kept a copy
  • Revoke the API keys and personal access tokens they created — and move integrations that run as the leaver to a service account first
  • Rotate break-glass and admin credentials — emergency access accounts, local administrator passwords and network device logins
  • Rotate cloud access keys, SSH keys and deployment secrets — anything in a pipeline or vault the leaver could read or create
  • Review the admin audit log for the 30 days before the cut-off — new admins, new keys, mail forwarding rules and bulk exports
Phase 5

Phase 5: Data, Files & Mailbox

The hold task appears only under a legal hold or investigation. The checklist halts at the manager’s Approved or Not approved decision, so no device is wiped and no licence released before the handover is confirmed.

  • Place the mailbox and files on hold before anything is deleted — a hold applied after deletion preserves nothing
  • Transfer file ownership to the manager or successor — personal drive files, team sites, recordings and documents shared from the leaver’s account
  • Convert the mailbox to a shared mailbox or set forwarding — Microsoft 365 needs the licence still assigned to convert; under 50 GB it then runs without one
  • Set an automatic reply that names the new contact — for the period your email policy sets, then remove it
  • Apply the retention period to the mailbox and files — keep what the schedule requires and give the rest a deletion date
  • Confirm the handover is complete — line manager: Approved or Not approved, with anything missing listed
Phase 6

Phase 6: Device Wipe & Asset Register

A legal hold shows the preserve task instead of the wipe. The own-device task is for contractors only.

  • Copy any local data the handover flagged before the device is touched — downloads, local mail archives and anything the manager listed as missing
  • Preserve the device unwiped under the legal hold — label it do not wipe, lock it away and log every handover
  • Wipe and reimage the device, or send it to disposal — reissue it from the standard build, or send old kit to IT asset disposal
  • Get written confirmation of deletion from the contractor’s own devices — under the contract’s data clause, signed by the contractor or their agency
  • Update the asset register for every item on the Phase 1 list — status, location and next owner, with the wipe or custody record attached
Phase 7

Phase 7: Licences, Groups, On-Call & Sign-off

The sign-off approver records Approved or Not approved on the last task, with the evidence attached.

  • Reclaim or cancel each licence — reassign the seat to the next joiner first; a suspended Google Workspace user is still charged
  • Remove the account from groups, distribution lists and shared channels — group membership is what quietly grants access to the next new system
  • Remove the leaver from the on-call tool and escalation policies — and from runbooks, supplier contact lists and emergency call trees that name them
  • Run a final access review two weeks after the last day — sign-in logs, the app table and privileged roles all show nothing active
  • Sign off the IT offboarding — approver: Approved or Not approved, recording any access deliberately kept and its end date

How the Leaver Type Changes the Timing

The steps barely change between leavers. Their timing does. A resignation gives IT weeks; a dismissal gives minutes; a contractor often leaves on a date nobody told IT about.

StepVoluntaryInvoluntaryContractor
Checklist startsWhen notice is acceptedWhen HR books the meeting, before the leaver knowsWhen the end date is confirmed with the engagement owner
Access cut-offEnd of the last working dayDuring the meeting, at a set minuteThe contract end date and time
Files handed overBy the leaver, during noticeBy the manager and IT, after the cut-offAs the contract’s handover terms require
DevicesHanded in on the last dayCollected in the meetingCompany kit returned; own kit confirmed clean in writing
AccountsMember account disabledMember account disabled at onceGuest or vendor account removed, sponsor link ended
Who can act on the cut-offThe IT ownerThe IT owner only, by exclusive assignmentThe IT owner

NIST SP 800-53 control PS-4, Personnel Termination, asks organisations to disable system access within a period they define, revoke the leaver’s authenticators and credentials, retrieve security-related property and keep access to the information the person controlled. ISO/IEC 27001:2022 covers the same ground in Annex A controls 5.11 (return of assets), 5.18 (access rights) and 6.5 (responsibilities after termination or change of employment). Either way, an auditor wants evidence that each leaver’s access ended when your policy said it would.

In Microsoft Entra ID, access tokens already issued last an hour by default after the account is disabled, so sessions are revoked straight after the block and the logs checked next morning. And a Microsoft 365 mailbox needs its licence while it is converted to a shared mailbox, so licences are reclaimed in Phase 7, not on the last day.

Why Run IT Offboarding in CheckFlow?

1

The order is enforced

The cut-off task halts the checklist, so no account, key or licence step can be ticked before sign-in is blocked. A second halt holds the wipe and the licence until the manager confirms the handover.

2

The dismissal task belongs to the IT owner

For an involuntary exit, the cut-off task is assigned exclusively to the IT owner picked in Phase 1. Only its assignees can open or complete it, others on the checklist see it greyed out, and a Guest sees only their own tasks, so a sensitive step stays with the people doing it.

3

Every date counts from the last day

Dynamic due dates run from the last working day and cut-off time entered in Phase 1. Conditional logic adds contractor, privileged-access and legal-hold tasks only when they apply, and the activity trail records who did each step.

See how CheckFlow’s IT offboarding checklist software coordinates IT, HR and the manager, and read the IT offboarding security guide for the reasoning behind each step. A webhook or Zapier trigger from your HR system can start this checklist the moment a leaver is confirmed.

The quarterly User Access Review Checklist and the Active Directory & Entra ID Account Cleanup Checklist find what slipped through, and devices that will not be reissued continue to the IT Asset Disposal Checklist.

Frequently Asked Questions

What should an IT offboarding checklist include?

+

The leaver’s type and last day, the identity and email cut-off, accounts in each tool, shared secrets and API keys, data and mailbox handover, device wiping, licences, groups and the on-call rota, and a final access review with a sign-off. Each step needs an owner and a due date counted from the last working day.

When should IT disable a leaver’s account?

+

For a resignation, at an agreed time at the end of the last working day. For a dismissal, during the meeting, at a minute agreed with HR beforehand, so nothing can be copied after the news. For a contractor, at the contract end date and time. Revoke sessions straight after the block.

What order should IT offboarding steps run in?

+

Block sign-in and revoke sessions, close accounts in each tool, then rotate the secrets the person could see. Transfer data and convert the mailbox before anything is wiped, wipe devices once the handover is confirmed, and reclaim licences last. A final access review two weeks later catches what was missed.

Should you disable or delete a leaver’s account?

+

Disable first and delete later. Deleting too early can take files, calendars and mail with it, and in Microsoft 365 a converted shared mailbox needs the original account as its anchor. Delete once the data is transferred and the retention period has passed. Note that Google Workspace still charges for a suspended user.

What happens to a leaver’s email?

+

Usually it becomes a shared mailbox the manager can open, or new mail is forwarded to a successor, with an automatic reply naming the new contact. In Microsoft 365, convert while the licence is still assigned; under 50 GB the shared mailbox then needs none. Under a legal hold, place the hold first.

Who owns IT offboarding: IT, HR or the manager?

+

All three. HR confirms the leaver, the type and the last day. IT runs the cut-off, accounts, secrets, devices and licences. The line manager hands over on-call shifts, says which files matter and confirms the handover before anything is wiped. A named approver signs off.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Take Access Away in the Right Order, Every Time

Free trial — no credit card required.