When an employee leaves, the business needs two things at once: stop their access and keep the information their colleagues need. Deleting the account first can make a routine handover harder. For a UAE SME using Microsoft 365, the safer approach is an approved sequence: secure access, preserve the required data, transfer responsibility, then review licences and account deletion.
This guide is for owners and operations managers coordinating with an authorised administrator. It covers Microsoft 365 business accounts; hybrid identity, retention requirements and device-management settings can change the exact procedure. Technical references were checked on 2 October 2026. The header image is an illustration, not a client installation.
1. Agree the handover before changing the account
Create one offboarding record with the employee's account, approved cutoff time, manager, IT owner and person receiving business information. List their mailbox, OneDrive, team sites, company devices and business applications. Ask which customer conversations and documents remain active, and who is authorised to see them.
For example, a departing sales coordinator might own quotations in OneDrive, receive customer replies in Outlook and maintain a separate CRM login. A replacement's access to Outlook alone will not complete that handover. Record each destination separately, with a named person who will test it.
Confirm preservation requirements with the person responsible for records before deleting or moving information. Microsoft's former-employee overview separates access removal, mailbox preservation, mobile-device actions and OneDrive access. Use it as the administrator's starting point, not as a reason to apply one retention period to every workload.
2. Stop sign-in and address existing sessions
At the approved cutoff, have the administrator block sign-in, reset the password and sign the user out of existing sessions. Microsoft's access-blocking instructions describe these as distinct actions. Changes can take time to propagate, and an already-open session may not end immediately. Record the actions and verify the resulting state instead of promising instant removal everywhere.
Use an administrator role with only the permissions needed. If the identity is synchronised from on-premises Active Directory, coordinate changes at the authoritative identity source. Separately revoke access to VPNs, CRM, hosting, shared credentials and other systems that are outside Microsoft 365. Collect company equipment and arrange any managed-device action under the company's approved process; do not assume a sign-in block erases downloaded files.
3. Choose how colleagues will handle email
Decide whether the address should continue receiving messages, who should answer them, and when that arrangement ends. For ongoing team access, a shared mailbox can be appropriate. For a short transition, an approved forwarding arrangement may be sufficient. Neither decision should automatically grant the whole team access to sensitive historical correspondence.
Microsoft's conversion guidance says to convert the mailbox while the user is licensed and retain the associated account afterwards. Keep direct sign-in blocked; authorised colleagues use their own accounts and delegated access.
A shared mailbox can hold up to 50 GB without its own licence, but delegates need licensed Exchange Online mailboxes. Larger mailboxes, archiving, holds and some advanced features can require additional licensing. Check Microsoft's shared-mailbox requirements before removing a licence. Conversion is not a substitute for a records-preservation decision.
Have the successor confirm access to relevant folders and the intended reply permissions. Use an approved test message to check the delivery route, and put a review date on temporary forwarding or delegation so it does not continue unnoticed.
4. Move working documents out of personal ownership
Ask the manager to identify active business documents, assign an approved recipient and arrange an authorised transfer to the appropriate team location, often a SharePoint library. Test that the successor can open the documents with their own account. Check important sharing links, document permissions and any workflow that points to the old location.
Do not leave this step until months after removing the licence. Microsoft's current unlicensed OneDrive guidance describes default read-only status after 60 unlicensed days and archiving after 93 days, with tenant settings and account status affecting the outcome. It also describes a cumulative nonpayment deletion policy beginning on 1 July 2026. These are not safe handover deadlines. Check the tenant's actual retention, billing and storage settings before relying on future access.
Keeping a shared mailbox does not settle what happens to OneDrive. Treat mailbox licensing and document ownership as separate decisions, with separate evidence that the needed data remains accessible.
5. Close only after the successor can work
- Access: the administrator has recorded sign-in, session and non-Microsoft application actions.
- Email: the approved recipient can access the required history and handle new messages through the agreed route.
- Files: the successor has opened representative documents from the intended long-term location.
- Ownership: team resources and business workflows have a continuing owner.
- Records: retention requirements and any preservation decision are documented.
- Licences: remaining mailbox and storage needs have been checked before removal.
Keep the offboarding record free of passwords. Record exceptions, an owner and a completion date; an unresolved document handover is a task to finish, not a reason to mark the whole process complete.
Turn the checklist into a repeatable process
A small business does not need a complicated tool to begin. Use a controlled checklist and a short manager sign-off, then review the process after each departure. Include the same ownership questions when new staff join so shared business records do not accumulate under one person's account.
ITZ's Microsoft 365 service can help review your account lifecycle and handover process. Request a Microsoft 365 offboarding review and describe your user count, identity setup and main handover concerns—without sending passwords or employee records. For wider continuity planning, read the backup restore test checklist.