Six months. One active account. Zero good reasons.
A former employee can still have access to:
- Microsoft 365 email and OneDrive
- Shared mailboxes and Teams channels
- Client files and document-management systems
- E-signature platforms
- Accounting, billing, and practice-management applications
- Saved passwords in a browser
- A firm-issued laptop sitting at home
This is one of the most overlooked compliance gaps facing law firms, medical practices, accounting firms, and other professional-services organizations.
You may have MFA. You may have endpoint security. You may even have a written security policy.
But if your former employees are still active in your directory, your client data may still be within reach.
The “Hey Margaret!” Problem
“Hey Margaret! Can you pull the Henderson matter and send me the signed engagement letter?”
Margaret left the firm six months ago.
Her Microsoft 365 account is still active. Her mailbox still receives messages. Her account remains a member of the litigation SharePoint site. Her e-signature account has not been disabled. The laptop issued to her was never returned because she worked remotely.
No one intended to create a security incident.
The offboarding process simply consisted of forwarding her email to a supervisor and removing her from the office schedule.
That is not identity governance. That is administrative hope.
A former employee does not need malicious intent to create risk. A compromised personal device, an old browser session, a stolen password, or an attacker using an abandoned account may be enough to expose confidential information.
For a law firm, that could mean privileged client files. For a medical practice, protected health information. For an accounting firm, tax returns, Social Security numbers, and financial records.
Why Offboarding Is a Compliance Control
Regulators and professional standards increasingly focus on a basic question:
Who can access sensitive information right now, and why?
The FTC Safeguards Rule requires covered financial institutions to maintain a written information security program with administrative, technical, and physical safeguards. That program includes access controls, periodic review, activity monitoring, and an accurate inventory of systems, devices, and personnel.
The Rule does not treat your directory as a static employee list. It expects you to know what you have, where customer information is stored, and who has a legitimate business need to access it.
Similarly, HIPAA’s Security Rule addresses workforce access, authentication, audit controls, and device and media safeguards. HIPAA compliance is not achieved simply because a former employee’s badge was collected.
GLBA compliance, including FTC Safeguards requirements, also depends on limiting access to nonpublic personal information and monitoring how authorized users interact with it.
Not every law firm or medical practice is automatically subject to every framework. Coverage depends on your activities and regulatory status. But the underlying security principle is consistent:
When someone leaves, their access must end, and your organization must be able to prove it.
The Accounts That Commonly Get Missed
A Microsoft 365 account is only one piece of the offboarding problem.
Former employees may remain connected to:
-
Microsoft 365 and Entra ID
Email, OneDrive, SharePoint, Teams, security groups, and application assignments may continue operating after employment ends. -
Shared mailboxes
A former employee may retain access to intake, billing, referrals, scheduling, or matter-specific mailboxes. -
E-signature tools
DocuSign and similar platforms may contain contracts, medical authorizations, tax forms, and client correspondence. -
Practice-management and document systems
Case-management, electronic health record, accounting, and tax platforms often have separate user directories. -
Cloud applications added without IT approval
“Shadow IT” accounts may not appear in your standard onboarding or offboarding checklist. -
Shared passwords
A departing employee may know credentials for vendor portals, social media, bank platforms, remote-access systems, or office equipment. -
Personal devices and browser sessions
Disabling a corporate account does not automatically remove downloaded files or active sessions from unmanaged devices.
This is why identity governance and IT asset management must work together. You need to know both who has access and what devices and applications they can use to reach it.

Departing Employees Are Not the Only Risk
The most complicated offboarding situations often involve departing partners, practice-group leaders, executives, or owners.
A partner may have:
- Access to every client matter
- Administrator privileges
- Ownership of SharePoint sites and Teams
- Authority over shared mailboxes
- Access to billing and trust-account systems
- Saved credentials for vendors and financial platforms
- Copies of client data on personal devices
- Forwarding rules connected to a personal email address
A partner may also leave under sensitive circumstances. The firm may delay technical action while leadership negotiates the departure.
That delay creates an exposure window.
You need a documented process for both cooperative and urgent departures. Legal, HR, and leadership should determine the timing and scope, while IT executes the technical controls immediately and records the evidence.
A Practical Employee Offboarding Checklist
Your checklist should be triggered by HR or leadership, not by someone remembering to open a helpdesk ticket.
Before the departure
- Confirm the departure date and exact cutoff time.
- Identify the employee’s role, access level, and sensitive systems.
- Review ownership of files, matters, calendars, mailboxes, and workflows.
- Identify firm-issued laptops, phones, tablets, tokens, and other assets.
- Identify shared passwords the employee may know.
- Coordinate with legal counsel when litigation holds, investigations, or unusual activity are involved.
At the time of departure
- Block Microsoft 365 and Entra ID sign-in.
- Revoke active sessions, refresh tokens, VPN access, and remote-access connections.
- Disable access to document management, e-signature, billing, clinical, accounting, and other cloud applications.
- Remove the user from security groups, Teams, SharePoint sites, shared mailboxes, and privileged roles.
- Rotate shared passwords and service credentials.
- Preserve the mailbox, files, and records according to your retention policy.
- Transfer ownership of client files and business processes to an approved successor.
- Retrieve firm-issued devices or initiate remote lock, selective wipe, or full wipe as appropriate.
After the departure
- Review recent sign-in activity, downloads, forwarding rules, file sharing, and unusual access.
- Confirm that the user is removed from third-party applications and vendor portals.
- Update your IT asset inventory and identity records.
- Document who completed each step, when it was completed, and what exceptions were approved.
- Conduct a follow-up access review to confirm that no orphaned permissions remain.
A managed Microsoft 365 environment can make much of this repeatable. Microsoft Entra ID Governance supports lifecycle workflows, access reviews, entitlement management, and automated removal of identities and access. Microsoft Intune can manage corporate devices, enforce compliance policies, and selectively wipe company data from personal devices when appropriate.
The technology helps. The process still needs an accountable owner.
What About Shared Passwords?
Shared passwords are often the ghost behind the ghost.
Someone leaves, but the firm does not know every system they could access because credentials were shared informally:
“The password is in the spreadsheet.”
Or:
“Ask Margaret. She knows the vendor login.”
That creates a direct control problem. You cannot reliably revoke one person’s access when multiple people use the same credential.
Use a password manager with role-based access, individual accountability, and documented ownership. Eliminate shared accounts where possible. When shared credentials are necessary, rotate them during offboarding and record the change.
Never rely on changing only the employee’s Microsoft 365 password. That leaves every external system untouched.

Managing Offboarding In-House vs. Using Managed IT
Some organizations can manage offboarding internally. If you have experienced IT staff, documented procedures, complete application visibility, and coverage during nights and weekends, internal management can work.
Advantages of managing it in-house
- Direct control over timing and decisions
- Familiarity with internal systems
- Close coordination with HR and leadership
- No external provider handoff
Potential disadvantages
- One employee may become the only person who knows the process
- Application inventories may be incomplete
- Busy periods can delay access removal
- Training and turnover create consistency problems
- Audit documentation may be incomplete
- After-hours departures may not receive immediate attention
- Device recovery and remote-wipe procedures may not be tested
A managed services provider brings standardized workflows, Microsoft 365 support, endpoint security, identity governance, and IT asset management into one operating model. The right outsourced IT partner can also review access across systems that your internal team may not know exist.
Think of offboarding like medical care.
You do not want a treatment plan that depends on one person remembering every medication, allergy, and follow-up appointment. You want a documented process, trained professionals, reliable records, and a response that works when circumstances are stressful.
Your technology deserves the same discipline.
Start With an Access and Asset Review
If you are unsure whether your process is working, begin with an assessment.
Ask:
- How many active accounts belong to former employees?
- Who can access shared mailboxes?
- Which users have administrator privileges?
- Are all laptops and mobile devices recorded in an asset inventory?
- Can you identify every application containing client, patient, or financial information?
- Are guest accounts reviewed regularly?
- Can you prove that access was removed during the last departure?
- Are shared passwords documented and rotated?
- Can your Microsoft 365 tenant enforce access based on identity and device health?
A Microsoft 365 security assessment can help identify weaknesses in identity, devices, email, sharing, and administrative controls.
You can also review the FTC’s guidance on the Safeguards Rule and the Department of Health and Human Services’ HIPAA Security Rule resources.
Final Word
A former employee’s account is not harmless simply because the person left on good terms.
The account may still open a mailbox. A laptop may still contain client files. A shared password may still unlock a vendor portal. A forgotten application may still contain sensitive information that no one remembered to disable.
For law firm cybersecurity, HIPAA compliance, GLBA compliance, and practical risk management, offboarding must be treated as a formal security control, not an administrative afterthought.
Build a repeatable joiner–mover–leaver process. Maintain an accurate identity and asset inventory. Secure Microsoft 365 with least privilege, MFA, Conditional Access, endpoint security, and regular access reviews. Document the work.
A PC of Mind helps law firms, medical practices, accounting firms, and other regulated organizations manage these responsibilities through managed IT services, cybersecurity services, endpoint management, Microsoft 365 support, and outsourced IT leadership.
Your clients trust you with information they cannot afford to lose.
Make sure that trust does not walk out the door with an account that was never disabled.