Practice · 20 August 2026 · 5 min
Offboarding that actually finishes
Accounts still enabled months after the leaving date are the most common finding in a first directory scan. The cause is almost never carelessness.
Run a read-only scan of almost any mid-sized tenant and the same finding comes back first: accounts that are still enabled, still licensed and occasionally still signing in, long after their owner left.
It is tempting to read that as sloppiness. It is more often a handover problem. HR records the leaving date in one system, the manager assumes IT is notified, and IT is notified only when someone remembers.
Offboarding is a sequence, not a switch
Disabling the account is the easy part. What follows is longer: reassign the mailbox, transfer ownership of shared files, remove group memberships, release the licenses, collect or wipe the device, and revoke access to line-of-business applications that were granted outside the directory.
Each step has a different owner and a different deadline. Without one record holding the whole sequence, partial completion is invisible — and partial completion is the normal state.
Attach the money
Unused licenses give the cleanup a budget line. Twenty-three licenses assigned to accounts with no sign-in for sixty days is a number a finance controller reacts to in a way that "directory hygiene" never achieves.
That is also the honest reason offboarding gets funded: not risk, cost. Use it.
Close it like an order
Treat the departure as one order with named steps, an owner per step and a completion state. When the last step closes, the record shows the whole sequence, with timestamps, and the question "did we finish?" has an answer that is not a spreadsheet.
Related reading
- One console, many tenants: what MSPs actually need from Entra ID tooling
Practice · 6 min
- Standing admin rights are a reporting problem before they are a security problem
Practice · 6 min
- The audit trail is no longer internal — it is something your clients buy
Managed service providers · 4 min