Views:

 

Introduction

What can you expect from the Employee Offboarding feature?

 


Introduction

 

We know how stressful employee offboarding can be. When someone leaves your organization, you need to make sure their access is suspended, their data is preserved, and their account is properly closed - all without missing a step. A single oversight can leave your environment exposed or disrupt ongoing work.

 

The Employee Offboarding feature makes this process seamless in Microsoft 365. Instead of juggling manual tasks, you can follow a clear, guided workflow that helps you:

  • Suspend access: instantly block the user from signing in and reaching company resources.
  • Delegate access: secure emails and files before the account is removed.
  • Manage the account: remove roles, licenses, group memberships, then delete the user account once all data has been secured.

 

With everything in one place, you can offboard employees consistently, securely, and without the usual stress.

 


What can you expect from the Employee Offboarding feature?

Access

You can access the Employee Offboarding feature from the side menu. Select the organization and the user you want to offboard. Review the user's details, and click “Start offboarding”.

No action will be performed until you have reviewed and confirmed the actions to be taken at the end of the form.

Actions

  • Suspend Access:
    • Disable user: blocks sign-ins to the user account.
    • Revoke sessions: revokes any active sessions.
    • Remove mailbox forwarding: remove the mailbox forwarding setting.
    • Disable inbox rules: disables all inbox rules in the user's mailbox.
    • Reset password: resets the account's password and sets a temporary password. The temporary password can be sent by e-mail to any user who has access to the tenant in Office Protect (optional).
  • Delegate Access:
    • Forward emails to another mailbox: you can set a new mailbox forwarding configuration to any other user in the tenant.
    • Transform mailbox into shared mailbox: converts the mailbox into a shared mailbox, allowing you to select the users who need access to it. A shared mailbox does not need to be assigned a license.
    • Grant access to the personal OneDrive space: creates a link to access the user’s OneDrive files with view and edit rights. This link will be accessible by and sent by e-mail to the user(s) you will select (any other user in the tenant).
  • Manage Account:
    • Remove admin roles: remove all admin roles assigned to the user.
    • Remove licenses: removes any licenses the user is assigned.
    • Remove user from all groups: revokes the user's membership from all groups they belong to.

 

If an action cannot be performed on the user account, it will be grayed out. E.g.: you cannot disable the mailbox inbox rules if no rules are active.
You can choose to skip a category and apply no actions.

 

After selecting the actions, click on “Review and Confirm”. All actions with an orange icon indicate that you must first log in with a user that has a global administrator on the tenant to initiate the process (example: disabling a global administrator account). This sign-in will be required at the Review & Confirm step.

 

 

If you would like us to develop a new offboarding action, please do not hesitate to contact us at  feedback@office-protect.com.

 

Follow-up and history of actions

After confirming, you will be taken to the “Offboarding operations” tab where you will be able to follow actions that are being applied.

If an error occurs and one of the applied actions fails, you will be guided through applying it in your Microsoft admin portal.

 

Once all selected actions have been completed, you can delete the user account. Please read the warning message carefully (make sure all data has been backed up) before deleting a user account.

 

From this tab, you can also view all ongoing and previous offboarding actions applied on any of your Microsoft 365 tenants.