How we work
What happens to the accounts of an employee who leaves the company
An IT offboarding guide: what you close in the first hour, what happens to their email and their files, and the access that never shows up in your user list.
In short
Deleting the account doesn't close the subject, it starts a clock. In Microsoft 365, a deleted user's mailbox can usually be recovered for 30 days. Files follow different rules and a different calendar. And if you want to keep the correspondence for longer, the retention rule has to be applied before you remove the licence.
The harder part is the access that sits in no company account at all: services they signed up for themselves, authentication codes on their phone, portals where they are the registered contact.
And alongside the risk everyone pictures, the former employee still getting in, sits a less discussed one: the company can end up locked out of its own accounts.
A colleague resigns on a Friday. On Monday their password is changed, on Tuesday they hand back the laptop, and with that the subject looks closed.
Three months later, somebody goes looking for an old quote in their correspondence and finds it no longer exists. Six months later, the company can't get into the account with its hosting provider, because the recovery address was theirs.
None of this happened out of bad intent. It happened because the departure was treated as a one-day event.
When the risk starts: at notice, not on the last day
Conversations about departures focus on the last day, because that's when the laptop comes back. In practice the risk spreads across three periods, and each one needs something different.
The notice period. The colleague is still employed, still hold every right, and if they intend to take something with them, this is when they do it. Not on the last day, when everyone is watching.
The day they leave. This is when access gets closed. It is the most visible part and, oddly, the simplest.
The first 30 days after. This is when data gets lost, quietly, because nobody is looking any more. It is also when someone asks „do we still have his emails somewhere?", usually just after the deadline expired.
The practical conclusion: handing over what only they know belongs in the notice period. The last day is for closing things, not for knowledge transfer. „Let's sit down Friday and you'll show me where everything is" never happens.
What you close in the first hour
Order matters, because some steps block the others.
Active sessions first, then the password. „I changed his password" does not mean he is out. Changing the password does not guarantee that every session already open on the laptop, the phone or the browser is closed immediately, so revoking them is a separate step. Otherwise, on paper the access is closed, and in practice the mailbox stays open on their personal phone.
Then two-step authentication. The codes go to their device. As long as the confirmation method is tied to their phone, every password reset runs through it.
Then remote access and network access, including any connections set up on their personal equipment.
What is not urgent in the first hour: deleting the account. That is the step that starts the clocks described below, and once started they don't stop.
What happens to their email and files after 30 days
There is a confusion here that costs people often: the mailbox and the files don't expire the same way, and the clock doesn't even start at the same moment.
The mailbox
Three different situations, with three different outcomes.
- You delete the account. The mailbox usually stays recoverable for 30 days. After that, the content can be permanently deleted.
- You only remove the licence, to stop paying for it. The data is retained for 30 days as well, this time counted from licence removal. If you don't reassign it by then, the content can be removed.
- You want to keep the correspondence for longer. You apply a retention rule to the mailbox, which is simply a setting telling the system not to delete. When the account is deleted, the mailbox becomes inactive: the content stays accessible for as long as the rule is in place, and it no longer consumes a licence.
The third option is the one that helps companies with long contracts or disputes, where correspondence may be needed two years later.
The detail that changes everything: the retention rule has to be applied before you remove the licence. It cannot be applied to an unlicensed mailbox.
The correct order, in short: apply the rule, confirm it took effect, and only then deal with the licence and the account. The other way round, you are left depending on a short recovery window, after which the content can be gone for good.
Files run on a different calendar
Compared with email, there are three differences, all of them important:
- The clock starts differently. Counting begins when the account is deleted from the organisation's user list. Blocking sign-in or removing the licence triggers nothing.
- The period can be changed. By default, files are kept for 30 days, but an administrator can set any value between 30 and 3,650 days.
- There is still a window afterwards. Once that period expires, their space moves into a deleted state for a further 93 days, from which only an administrator can restore it.
One detail worth checking in your own company: by default, when the account is deleted, the person's manager is automatically given access to their files. If no manager or secondary owner is set, nobody gets access and nobody is warned that the files are about to disappear.
Who receives the email sent to their address
Clients don't find out they left. They will write to the same address for months.
The usual answer is converting the mailbox into a shared one, accessible to the colleagues taking over the relationship. It keeps the history, so the colleague taking over can see what was discussed, and it generally does not consume a licence.
What you don't do: automatic forwarding to the former employee's personal address, „so nothing gets missed". That is a continuous leak of data to someone who no longer has any right to it.
The access that never shows up in your user list
The hard part of offboarding is not the accounts you administer. It's the ones you don't.
Services they signed up for themselves, with their work address. An invoicing tool, a newsletter platform, a file transfer subscription. The company pays or paid for them, but the account is in their name.
Portals where they are the registered contact. At suppliers, at large clients, on tender platforms. The notifications keep going to them, and you don't see them.
Admin accounts they opened. The company domain, the website hosting, the account with the telecom provider. If they created it, the recovery address is theirs.
Passwords shared verbally. The social media account, the security cameras, a platform used once a year. Nobody wrote them down anywhere. „Ask Andrei" was, for years, the entire procedure.
The reverse risk: not them getting in, but you being locked out
The company needs to make a payment. The confirmation code goes to a phone that no longer answers.
Nearly all the attention goes to what a former employee could do. A less discussed risk is the exact opposite:
- their phone was the second authentication factor for the company bank account;
- their address was the recovery address for the domain the website runs on;
- their name was the contact at the energy supplier.
None of this is malicious. These are things configured in a hurry, three years ago, by the colleague who handled IT at the time. And when they leave, the company can end up locked out of its own accounts, sometimes for weeks, until it gets resolved with paperwork and patience.
Which is why an access inventory is not a formality for an audit. It is the assurance that the company can operate without any one specific person.
What differs from one departure to another
A colleague in sales versus one in IT
They take different things, so you prepare differently.
A colleague in sales takes relationships and data. The client list, the quotes, the history of the conversations. Usually not through anything dramatic, but by exporting a file in the last week of notice or saving documents to a personal cloud account. The risk is commercial and it shows up three months later, when the same clients call from another company.
A colleague in IT takes keys. Admin accounts, infrastructure passwords, remote access. The risk is different in kind: you don't lose clients, you lose control. And if they were the only one who knew how everything was set up, you also lose the ability to fix things when they break.
For sales, attention shifts to the notice period. For IT, to the infrastructure documentation, written before anyone resigns.
When they leave angry
„Cut everything, now." That is the usual reflex, and it arrives during the conversation itself. It is right in rare cases and hasty in most.
Beyond situations of genuine bad intent, many problems come simply from accounts configured in a hurry and access that was never documented. And if someone does intend to copy data, they do it in the final days of notice, not on the day of the closing conversation.
What actually helps, in order: an identical process for everyone, so closing access doesn't read as an accusation; a list of their access prepared in advance, so you're not improvising under pressure; and a written record of what was closed and when, in case the conversation goes somewhere.
What the law says about former employees' access
Access control is not just good practice, it is a requirement.
The General Data Protection Regulation requires appropriate technical measures for the security of processing, and a former employee's access to your clients' data is exactly the kind of problem it targets.
And for companies in scope of NIS2, access control policies and asset management are listed explicitly among the mandatory measures. If you're not sure whether your company is in scope, we wrote separately about who must comply and by when.
The offboarding checklist, in the order you work through it
Tick as you read. The first two happen during the notice period, the rest on the last day and in the week that follows.
If nobody is leaving today and you still want to do one useful thing, do the second one: write the access list by role, not by individual. When a departure comes, you stop improvising and start ticking.
And if someone in the company handles HR, the list above is more useful to them than to you. Departures reach them first.
A prepared offboarding looks unremarkable: a few things get closed, a list gets handed over, and three months later nobody remembers there was someone. That is the target. Not an impressive process, but one you never notice.
Offboarding questions we get asked most
How long should I keep a former employee's emails?
The law doesn't set one single term, it depends what they contain. Correspondence with contractual or tax implications follows the rules of those areas. The practical approach: set a standard period for the company, apply it consistently, and write down why you chose it. A chosen and respected term is easier to defend than keeping everything forever „just in case".
Can I convert their mailbox into a shared one?
Yes, and it's the most common solution. The colleagues taking over see the history, clients get an answer at the same address, and you generally stop paying a licence for it. Check the mailbox size first, because above a certain limit you still need a licence.
Can I read their emails after they leave?
Access to work correspondence needs a legitimate purpose tied to business continuity, has to match what employees were told in advance, and should be limited to what is strictly necessary. Going through their personal messages is not covered. For sensitive situations, check your internal policy and ask your data protection officer or a legal specialist, before rather than after.
Is it better to delete the account or suspend it?
Suspend it, for the first month. You block access immediately without starting the deletion clocks. There is nothing to gain by rushing it, apart from the licence cost, which can be handled separately.
What if they left three months ago and I need something from their account?
It depends what you're after. For email, if the account was deleted and no retention rule was active, the content is most likely gone. For files there is still a chance: after the retention period, their space stays in a deleted state for a further 93 days and can be restored by an administrator. Check whether a company-wide rule was active, and whether you run a separate archiving system.
About Risksoft
We have managed IT infrastructure for over 70 companies in Romania for 25 years. Most of them have between 10 and 300 employees.
Our own information security management system is certified to ISO/IEC 27001:2022 and externally audited every year. You can check the certificate yourself, in a public database.
Certificate no. RO231109006 · issued by LMS Assessments Limited · verify it in IAF CertSearch
Not sure who has access to what?
That's the normal situation, not the exception. The inventory builds up over time, through different colleagues, and it is rarely written down in one place.
In 45 minutes we look at what you have today: who has access to what, what closes automatically when someone leaves, and what would stay open. You leave with a written list, in the order worth fixing it in.
Book the 45-minute reviewThe conversation is free and commits you to nothing.
This article describes general practice and deadlines valid at the date of publication. Configurations differ from company to company, and vendor documentation can change; for your own situation, check the sources cited or ask a specialist.
