Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Employee departure: the IT checklist to secure your access

Portrait of Antonio Pazzi, president of OKTO Solutions

By ·

President of OKTO Solutions · 6 minute read · updated September 2, 2026

An employee hands in their resignation, or you have to end someone’s employment. The same question always comes up: does this person still have access to your email, your files, your systems? For plenty of small businesses in the Mauricie region, the honest answer is yes, often for weeks, because nobody has a clear list of what to cut off.

This security gap is more common than people think. A former employee who keeps access to the mailbox, to Microsoft 365 or to the file share is a real risk of data leaks, fraudulent billing and non-compliance with Quebec’s Law 25. Here is a practical checklist for handling an employee departure without leaving a door open behind them.

Quick answer: When an employee leaves, disable their Microsoft 365 account the same day, change their passwords, revoke their active sessions, collect their devices and transfer their files and email to a manager. A written procedure, tested in advance, prevents the oversights that cost you dearly.

1. Why is an employee departure a real security risk?

When someone leaves, they take passwords, access and sometimes frustration with them. Most former employees will never do anything malicious. The problem is the small percentage who do, and above all the accounts left active that an attacker can hijack without anyone noticing.

The Canadian Centre for Cyber Security ranks insider threats among the risks organizations underestimate the most. A forgotten account is an easy target: no monitoring, no password change, and often no up-to-date two-factor authentication. Here is what most often gets left behind after a badly handled departure:

  • The Microsoft 365 or Google mailbox, still syncing on a personal phone
  • Access to shared files (SharePoint, OneDrive, local server)
  • Third-party application accounts: accounting, CRM, banking, social media
  • Remote access (VPN, remote desktop) still wide open
  • A company laptop or cellphone that was never returned

2. Cut off Microsoft 365 access the same day

The first priority is the digital identity. As long as the Microsoft 365 account stays active, the person can read their email, sign in to applications and see your documents. Microsoft recommends blocking sign-in immediately rather than deleting the account right away, which gives you time to recover the data.

In practice, here is the order to follow on the day of the departure:

  1. Block sign-in to the account in the Microsoft 365 admin centre
  2. Reset the password to kill any session already open
  3. Revoke active sessions and access tokens (otherwise the employee stays signed in on their phone)
  4. Remove any administrator roles they held
  5. Convert the mailbox to a shared mailbox if co-workers need to keep answering clients

This step takes a few minutes when it is planned, and half a day of panic when it is not. If your team has nobody dedicated to IT, a managed IT services partner can run this procedure the same standardized way at every departure.

A technician monitoring the devices of a Quebec small business during an employee departure

3. Collect and secure the devices

A company laptop holds far more than an operating system: local files, passwords saved in the browser, open sessions. Ideally the device comes back on the last day of work. When that is impossible, for instance with someone working remotely from another city, you need a plan.

A few useful reflexes for devices:

  • Physically collect laptops, cellphones, USB keys and access cards
  • Remove the device from your company accounts remotely if you use a device management solution (MDM)
  • Wipe company data remotely from a personal cellphone that held work email
  • Confirm the drive was encrypted (BitLocker) before reassigning the device to someone else

For a team spread between Trois-Rivières and the rest of Quebec, remote device management changes everything: you no longer have to wait for the hardware to come back before cutting off access.

4. Protect and transfer the data

Once access is cut, the next job is to lose nothing. Documents, email and the history of conversations with clients belong to the company, not to the person walking out. That is especially true for a sales or customer service role, where everything known about a file lives in a single mailbox.

Before you close the account for good:

  • Transfer OneDrive files to a manager or to a shared drive
  • Reassign the documents the person owned in SharePoint
  • Set up an automatic reply that points clients to the right person
  • Keep the mailbox for a while, depending on your legal obligations, before deleting it

Never delete an account the same day out of reflex. Deleting also erases the data, and you may need it for a client file or an audit. Block first, transfer next, delete last.

Employee offboarding plan and IT access review for a small business in the Mauricie region

5. Law 25: your obligations in Quebec

In Quebec, protecting personal information is no longer optional. Law 25 requires businesses to limit access to personal information to the people who need it for their work. A former employee who keeps access to a client database is exactly the kind of situation the law is meant to prevent.

In practice, handling a departure cleanly helps you respect several principles of the law:

  • Remove access as soon as the business need disappears
  • Keep a record of who had access to what, and when that access was removed
  • Reduce the risk of a confidentiality incident, which may have to be reported

A documented departure procedure then becomes concrete proof that you take data protection seriously. In the event of an audit or an incident, that record makes the difference.

6. Automate offboarding so nothing gets missed

The real weakness of a manual checklist is forgetting. Under the pressure of a departure, you cut the email but forget the accounting account, or the VPN access. A few months later, nobody knows which accounts are still hanging around.

That is why a written procedure reused every single time beats a good memory. An up-to-date inventory of every access tied to each role, combined with centralized identity management, lets you cut everything in one move. If you do not have that structure in-house, it is one of the first gains an IT partner brings to a small business. You can reach us at OKTO Solutions to build a procedure that fits your company.

Frequently asked questions

Should you delete the Microsoft 365 account of an employee who leaves?

Not right away. Block sign-in first and reset the password, then transfer the data. Convert the mailbox to a shared mailbox if co-workers need to keep answering clients. You can delete the account later, once everything has been recovered.

How long should you keep a former employee’s email?

It depends on your obligations and your industry. Many small businesses keep the mailbox readable for a few months so they do not lose the history of client files. What matters is setting a clear rule and applying it the same way at every departure.

What if a remote employee refuses to return their laptop?

Cut off their access to company accounts immediately and, if the device is managed, wipe or disconnect it remotely. Put the request to return it in writing. A device management solution configured in advance lets you take back control without depending on the person’s goodwill.

Securing employee departures in Trois-Rivières and the Mauricie region

A departure handled well takes a few minutes when the procedure exists, and turns into a real risk when you improvise. If you want an offboarding checklist built for your small business, a clear inventory of your access rights and quick execution at every departure, take a look at our managed IT services or contact our team in Trois-Rivières. We put in place the structure that protects your data, even when someone leaves overnight.

Complete guide: Law 25 for Quebec small businesses
The obligations by deadline, the official sources, the fines the law provides for and the frequently asked questions, all on one page kept up to date.

An article sets out the principle. Putting it in place happens one workstation at a time: our managed cybersecurity service, backup and disaster recovery and our IT services in Montreal.

A question on this subject, for your own company?

An article explains the principle. A twenty minute call tells you what it changes at your place, with your systems and your constraints.