Most employee departures are entirely routine, and treating every one as a security event would be both exhausting and corrosive to trust. But a small number of departures carry real risk — a contested exit, access to sensitive data, a move to a competitor — and those are precisely the ones where organizations tend to react late, after access is already gone and questions are harder to answer.
The solution is not suspicion. It is a consistent, proportionate process applied the same way every time, so that when a departure does turn sensitive, the groundwork is already in place. This article outlines what to review and when. It is general guidance, not legal advice; involve HR and counsel for anything approaching a dispute.
Decide the sensitivity early
Before touching any systems, make a deliberate call about how sensitive the departure is. A useful frame is to ask three questions: What access did this person have? What would it cost the business if data left with them? And is there any sign the exit is contentious?
The answers place a departure somewhere on a spectrum from ordinary to high-risk, and that placement should drive how much of the following you do. Applying the full process to everyone is overkill; applying none of it to a high-risk exit is how organizations get surprised.
Preserve access before you remove it
The most common and consequential mistake is deleting the departing user’s account too quickly. A deleted account can take mailbox content, file ownership, and audit context with it — or make them far harder to reach.
For anything above routine, the safer sequence is to disable access rather than delete it, and to preserve the mailbox and files before making changes. Microsoft 365 provides ways to retain a departed user’s content, including converting or holding mailboxes and preserving files the person owned in OneDrive. What is appropriate depends on your licensing and retention configuration, but the principle holds: keep the ability to look before you remove the ability to.
Deletion can happen later, on a schedule, once you are confident nothing of value or relevance is being discarded.
Know what “normal” looked like
Concerns about a departure almost always come down to activity: did this person take, forward, or delete things they shouldn’t have? Those questions are only answerable if the relevant activity was being recorded, and if you can distinguish unusual behavior from this person’s ordinary pattern.
This is why baseline logging matters before anyone gives notice. Microsoft 365 audit records can show mailbox activity, file access and sharing, and mass-download or mass-deletion patterns — but only within the retention and licensing you had in place at the time. Reviewing whether that logging is adequate is a task for a quiet afternoon, not for the day someone resigns.
A departure review checklist
- Classify the departure's sensitivity before acting.
- Disable, don't immediately delete, access for anything non-routine.
- Preserve the mailbox and owned files before removing the account.
- Reset or revoke shared credentials, tokens, and app access the person could still use.
- Review recent file sharing, downloads, forwarding, and deletions for the relevant window.
- Reassign ownership of business-critical files and mailboxes.
- Document what you did and when, in case questions arise later.
Keep technical findings separate from conclusions
If a review surfaces something concerning — a large export the night before resignation, sensitive files shared to a personal address — resist the urge to leap to a verdict. Technical activity shows what happened in the system. It does not, by itself, establish intent, authorization, or wrongdoing, all of which may have innocent explanations and all of which are ultimately questions for HR and counsel, not for IT.
The useful contribution from the technical side is a careful, factual account: here is what the records show, here is the timeframe, and here is what the evidence does and does not support. Keeping that line clear protects both the business and the individual.
The quiet version is the strong version
Done well, a departure review is unremarkable. It runs the same way for the friendly retirement and the acrimonious exit, it does not require accusing anyone of anything, and it means that on the rare occasion something is genuinely wrong, you are not starting from zero. If your current process only kicks in once there is already a problem, that is the gap worth closing — calmly, and before the next resignation letter lands.