OKTO Solutions

An employee hands in their resignation, or you have to let someone go. Within hours, the same question comes up: does this person still have access to your emails, your files, your systems? For a lot of SMBs in the Mauricie region, the honest answer is yes, sometimes for weeks, because nobody has a clear list of everything that needs to be cut off.

This security gap is more common than you’d think. A former employee who keeps access to the company mailbox, Microsoft 365, or file shares represents a real risk of data leaks, fraudulent billing, and non-compliance with Law 25. Here’s a practical checklist for handling an employee’s departure without leaving a door open behind them.

Quick answer: When an employee leaves, disable their Microsoft 365 account the same day, change their passwords, revoke active sessions, collect their devices, and transfer their files and emails to a manager. A written procedure, tested in advance, prevents the oversights that end up costing you.

1. Why an employee’s departure is a real security risk

When someone leaves, they take passwords, access, and sometimes frustration with them. Most former employees will never do anything malicious. The problem is the small percentage who do, and especially the accounts left active that an attacker can hijack without anyone noticing.

The Canadian Centre for Cyber Security ranks insider threats among the risks organizations underestimate the most. A forgotten account is an easy target: no monitoring, no password changes, and often no up-to-date two-factor authentication. Here’s what most often gets left behind after a poorly managed departure:

  • The Microsoft 365 or Google mailbox, still synced to a personal phone
  • Access to shared files (SharePoint, OneDrive, local server)
  • External application accounts: accounting, CRM, banking, social media
  • Remote access (VPN, remote desktop) still open
  • A company laptop or cellphone never returned

2. Cut Microsoft 365 access the same day

The first priority is the digital identity. As long as the Microsoft 365 account stays active, the person can read their emails, sign into applications, and see your documents. Microsoft recommends blocking sign-in immediately rather than deleting the account right away, which gives you time to recover the data.

Here’s the order to follow on departure day:

  1. Block sign-in to the account in the Microsoft 365 admin center
  2. Reset the password to end any session already open
  3. Revoke active sessions and access tokens (otherwise the employee stays signed in on their phone)
  4. Remove any administrator roles they had
  5. Convert the mailbox to a shared mailbox if colleagues need to keep responding to clients

This step takes a few minutes when it’s planned ahead, and half a day of scrambling when it isn’t. If your team doesn’t have a dedicated IT person, a managed IT services partner can run this procedure the same way every time someone leaves.

Technician overseeing an SMB's devices in Quebec during an employee departure

3. Recover and secure the devices

A company laptop holds a lot more than an operating system: local files, passwords saved in the browser, open sessions. Ideally, the device is collected on the employee’s last day. When that’s not possible, say the person works remotely from another city, you need a plan.

A few useful habits for devices:

  • Physically collect laptops, cellphones, USB keys, and access cards
  • Remove the device from company accounts remotely if you use a management solution (MDM)
  • Wipe data remotely on a personal cellphone that held work emails
  • Confirm the drive was encrypted (BitLocker) before reassigning the device to someone else

For a team spread between Trois-Rivières and the rest of Quebec, remote device management changes everything: you no longer have to wait for the hardware to come back before cutting off access.

4. Protect and transfer the data

Once access is cut, the next step is making sure nothing gets lost. Documents, emails, and the conversation history with clients belong to the company, not the person who’s leaving. That’s especially true for a sales or customer service role, where all the information on client files lives in a single mailbox.

Before closing the account for good:

  • Transfer OneDrive files to a manager or a shared drive
  • Reassign documents the person owned in SharePoint
  • Set up an auto-reply that redirects clients to the right person
  • Keep the mailbox accessible for a while, depending on your legal obligations, before deleting it

Never delete an account on day one out of reflex. Deletion also erases the data, and you might need it later for a client file or an audit. Block first, transfer next, delete last.

Employee departure plan and IT access review for an SMB in the Mauricie region

5. Law 25: your obligations in Quebec

In Quebec, protecting personal information is no longer optional. Law 25 requires businesses to limit access to personal information to only those who need it for their work. A former employee who still has access to a customer database is exactly the kind of situation the law is meant to prevent.

In practice, handling an employee’s departure properly helps you meet several of the law’s principles:

  • Remove access as soon as the business need for it disappears
  • Keep a record of who had access to what, and when that access was removed
  • Reduce the risk of a confidentiality incident, which may need to be reported

A documented departure procedure then becomes concrete proof that you take data protection seriously. In the event of an audit or an incident, that record makes the difference.

6. Automate offboarding so nothing falls through the cracks

The real problem with a manual checklist is forgetting something. Under the pressure of a departure, you cut off email but forget the accounting account, or the VPN access. A few months later, nobody knows which accounts are still lying around.

That’s why a written procedure you reuse every time beats a good memory. An up-to-date inventory of every account tied to each role, combined with centralized identity management, lets you cut everything off at once. If you don’t have that structure in-house, it’s one of the first wins an IT partner brings to an SMB. You can reach out to OKTO Solutions to build a procedure suited to your business.

Frequently asked questions

Should you delete a departing employee’s Microsoft 365 account?

Not right away. Block sign-in first and reset the password, then transfer the data. Convert the mailbox to a shared mailbox if colleagues need to keep responding to clients. You can delete the account later, once everything has been recovered.

How long should you keep a former employee’s emails?

It depends on your obligations and your industry. Many SMBs keep the mailbox accessible in read-only mode for a few months so they don’t lose the history of client files. What matters is setting a clear rule and applying it the same way every time someone leaves.

What if a remote employee refuses to return their laptop?

Cut off their access to company accounts immediately and, if the device is managed, wipe or disconnect it remotely. Document the request to return it in writing. A device management solution set up in advance lets you regain control without depending on the person’s goodwill.

Securing employee departures in Trois-Rivières and the Mauricie region

A well-managed departure takes a few minutes when the procedure already exists, and becomes a real risk when you improvise. If you want an offboarding checklist suited to your SMB, a clear inventory of your access points, and fast execution every time someone leaves, check out our managed IT services or contact our team in Trois-Rivières. We put in place the structure that protects your data, even when someone walks out the door overnight.

Leave a Reply

Your email address will not be published.Required fields are marked *

Gravatar profile