← Back to insights

Practice · 20 August 2026 · 5 min

Offboarding that actually finishes

Accounts still enabled months after the leaving date are the most common finding in a first directory scan. The cause is almost never carelessness.

Run a read-only scan of almost any mid-sized tenant and the same finding comes back first: accounts that are still enabled, still licensed and occasionally still signing in, long after their owner left.

It is tempting to read that as sloppiness. It is more often a handover problem. HR records the leaving date in one system, the manager assumes IT is notified, and IT is notified only when someone remembers.

Offboarding is a sequence, not a switch

Disabling the account is the easy part. What follows is longer: reassign the mailbox, transfer ownership of shared files, remove group memberships, release the licenses, collect or wipe the device, and revoke access to line-of-business applications that were granted outside the directory.

Each step has a different owner and a different deadline. Without one record holding the whole sequence, partial completion is invisible — and partial completion is the normal state.

Attach the money

Unused licenses give the cleanup a budget line. Twenty-three licenses assigned to accounts with no sign-in for sixty days is a number a finance controller reacts to in a way that "directory hygiene" never achieves.

That is also the honest reason offboarding gets funded: not risk, cost. Use it.

Close it like an order

Treat the departure as one order with named steps, an owner per step and a completion state. When the last step closes, the record shows the whole sequence, with timestamps, and the question "did we finish?" has an answer that is not a spreadsheet.

RELEVANT SOLUTION

See how this is handled in practice: