Module 9 of StartCloud's Microsoft 365 Security Essentials learning pathway, in five short units with a knowledge check: why the ex-employee account nobody closed is a live security risk, setting up new starters by role rather than copying an existing user, the six-step leaver checklist in the correct order (block sign-in and sign out sessions first, convert the mailbox to shared, hand over files, then reclaim the licence), and the awkward cases including personal phones, shared logins, contractors and sudden departures.
Starters and Leavers: Closing the Door Properly
The account nobody closed
Every module before this one has been about keeping the wrong people out. Strong sign-in, protected admins, filtered mail, controlled sharing, shaped access, classified data. All of it points outward.
This module is about a door that opens from the inside, and it is the one most businesses forget to close. Somebody leaves. Their laptop comes back, their farewell card gets signed, and their account keeps working perfectly. Mail still arrives. Files are still reachable. The phone in their pocket still syncs company email on the drive home.
A live login with a password that has not changed, sitting outside your building and outside your control. If that password turns up in a breach at their next employer, or on a personal service where they reused it, an attacker gets a working account with real permissions and nobody watching it.
The opposite mistake, and it costs just as much. Delete the account on the last day and you have started a 30 day clock on their mailbox and their OneDrive. Miss it, and the client history, the quotes and the half-finished handover go with it, permanently.
It usually lives on somebody's mental checklist somewhere between the exit interview and returning the parking pass, which is exactly why it gets missed on a busy fortnight. Treat it the way you treat MFA: written down, done the same way every time, and not dependent on anyone remembering.
The good news is that the fix is not complicated. It is a short list done in the right order, and the order genuinely matters. Most businesses that get this wrong are not lazy, they simply do the right steps in the wrong sequence and lose something along the way.
We will do starters first, because a tidy leaver process is much easier when the account was set up sensibly in the first place.
A good starter process is really just one idea repeated three times: decide it once, apply it every time. Everything that gets improvised on the day is something that will need untangling in a year.
Access by role, never by "copy Sarah's permissions"
Copying an existing user is the single most common way businesses end up with wildly oversharing accounts. Sarah has been here nine years. She has picked up access to payroll, three old projects and a finance folder she has not opened since 2023. Copy her and your new hire inherits all of it on day one.
- Define what each role actually needs, once, and reuse it
- Put people in groups, and give the groups the access
- New starter joins the group, and that is the whole job
- It also makes the leaver step trivial later
MFA registered on day one, not "when they settle in"
The riskiest window in an account's life is the gap between the password being created and MFA being switched on, and that gap is entirely avoidable. New starters are also the most likely target for a well-timed phishing email, because they do not yet know who normally emails them or how the boss writes.
- Set MFA up as part of the first sign-in, with someone sitting beside them
- Do not hand out a temporary password over unencrypted email
- Point them at the Cyber Hygiene pathway in week one
Licence, device and groups sorted before the first morning
This is the unglamorous half, and getting it right buys goodwill you cannot buy later. Somebody who spends their first day watching a laptop enrol and waiting on an email address forms a lasting opinion about how the place is run.
- Licence assigned and mailbox live before they arrive
- Device enrolled and compliant (Module 10 covers this properly)
- Added to the right groups, distribution lists and Teams
- Written down as a checklist, so it survives whoever is on leave
The copy-Sarah's-permissions habit is how a five-person business ends up with an access map nobody can explain. It also quietly undermines Module 5 and Module 6, because sensible sharing controls and Conditional Access cannot help much when half the company already has access to everything.
Here is the order. It is worth following exactly, because the first two steps protect the business and the next four protect the data, and swapping them around is how businesses lose things.
The most common mistake is doing step 6 first. Deleting the account on the last day feels decisive and tidy. It is also how a mailbox full of client history quietly evaporates 30 days later.
- 1
Block sign-in and sign them out of everything
Reset the password and then explicitly sign out of all sessions. Both, in that order. Resetting alone is not enough, because an existing session keeps working on the token it already holds. Worth knowing: sign-out is not instant either. A token can stay valid for up to an hour, so do this at the start of the process rather than the end.
- 2
Wipe and block their mobile device
The phone in their pocket is the step people forget, because it never appears on a desk to be handed back. If company mail was on a personal phone, remove the company data from it now. Module 10 makes this a two-click job.
- 3
Deal with the mailbox before you touch the account
Convert it to a shared mailbox and the whole history stays available to the team, with no licence cost while it is under 50 GB. The catch that trips everyone up: a shared mailbox still needs the original user account to exist as its anchor. Convert first, then keep the account.
- 4
Hand the files to a real person
Give their manager or successor access to the OneDrive while the account still exists. Anything genuinely shared should have been in SharePoint or Teams all along, so treat whatever is sitting in a personal OneDrive as a hint about where your file habits need work.
- 5
Reclaim the licence, once the data is safe
Now you can stop paying. Be aware that removing the licence starts its own 30 day clock on the mail, so this comes after the mailbox is converted and the files are handed over, not before.
- 6
Remove them from groups, and only then consider deleting
Strip them out of Teams, distribution lists and any shared access. If you converted the mailbox to shared, do not delete the account at all. If you did not, you have 30 days to change your mind before it is permanent, so there is no prize for rushing.
Access should stop the moment employment does. Data handover is a considered job that benefits from not being rushed, and it can happen calmly the following week. Separating the two is the single biggest improvement most businesses can make here, and it costs nothing.
Everything above assumes you catch it inside 30 days. If you read Module 8, you already know what happens when a departure is discovered late: without a real backup, the safety net has expired and there is nothing to go back to. The two modules solve the same problem from different ends.
The tidy version assumes a friendly resignation, a four week notice period and a full handover. Real businesses get the other kind too, and these are the four that come up most often.
You cannot ask for the phone back, and you should not try to wipe the whole thing. This is exactly the problem app protection policies solve: remove the company data and leave their photos, messages and personal apps completely untouched. Without that in place, your only options are all bad ones.
The reception account, the accounts@ mailbox, the login for the supplier portal that four people use. When someone leaves, that password walks out with them and there is no per-person switch to flip. Give shared mailboxes proper delegated access instead of a shared password, and put anything genuinely shared in a password manager.
They get accounts, they rarely get offboarded, because nobody is quite sure whose job it is. Set an end date on the account when you create it, so it closes itself if everyone forgets. The engagement ending is the trigger, not somebody remembering three months later.
A dismissal, a walkout, a resignation that turns sour. This is the only scenario where speed genuinely beats process: block sign-in and sign out all sessions immediately, then do everything else calmly afterwards. Having the checklist written down in advance is what makes a fast, clean job possible on a bad day.
- List every active account and name the human behind each one
- Anything you cannot name is a finding, not a mystery to shrug at
- Check for accounts that have not signed in for 90 days
- Write the starter and leaver checklists down, even roughly
- Accounts belonging to people who left last year
- Nobody can say who uses the accounts@ password
- Offboarding lives entirely in one person's head
- A contractor account from a project that finished in autumn
- learn.microsoft.com: Overview: remove a former employee and secure data
- learn.microsoft.com: Step 1: prevent sign-in and block access to Microsoft 365
- learn.microsoft.com: Convert a user mailbox to a shared mailbox
- learn.microsoft.com: Delete a former employee's user account, and the 30 day window
Steps and retention windows were current at the time of writing (August 2026). If your accounts sync from an on-premises Active Directory, some of these steps happen there rather than in the Microsoft 365 admin centre.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. A new starter joins the sales team. What is the best way to give them access?
2. Someone resigns today. What are the first two things you do on their last day?
3. You want to keep a departed employee's email available to the team without paying for a licence. What do you do?
4. Why is deleting a leaver's account on their last day a risky move?
5. A departing employee has company email on their personal phone. What is the right approach?