Security

Bad Onboarding Is Why Offboarding Becomes a Nightmare

employee onboarding office

The Exit Is Decided on Day One

By the time someone hands in their notice, the decisions that will make their departure clean or chaotic have already been made — usually in their first few weeks, when everyone was too busy to pay attention. A shared login here, a quick SaaS sign-up there, a personal laptop used ‘just until the company hardware arrives.’ Six months later, none of that feels like a decision. It feels like how things are.

The result? What should be a 90-minute IT task stretches into three weeks of manual cleanup, awkward conversations with the departing employee, and the occasional vendor still charging your card months after they’ve gone.

What Good Offboarding Actually Looks Like

When onboarding is done properly, offboarding is straightforward. The account is disabled in Entra ID, which cascades access revocation across every tool connected via single sign-on. The device — enrolled in Intune from day one — is remotely wiped or collected. Email is forwarded to a manager or converted to a shared mailbox in M365. A handover document that was templated at onboarding gets filled in and filed.

Total IT time: about 90 minutes.

The messy version starts with a manual list of tools nobody can fully remember — which usually means asking the departing employee to help reconstruct it. You find accounts set up independently, with passwords sitting in their personal password manager. The laptop is at their house. A client emails to say they received a strange message from a personal address. Six weeks later, a vendor invoice lands for a seat you thought you cancelled.

This is what Microsoft and the identity management world call the joiner”“mover”“leaver lifecycle. A rushed joiner phase compresses months of identity debt into the two weeks after a resignation lands.

Four Onboarding Shortcuts That Guarantee a Messy Exit

Letting staff sign up for SaaS tools on their own

When someone signs up for a tool independently — using their work email and a password only they know — that account is functionally theirs. You may not know it exists until a vendor invoice appears, or until a client project breaks after they’ve left.

Every SaaS tool should be provisioned through a central identity system and connected to single sign-on before the first user logs in. That’s how Entra ID and M365 are designed to work.

Tolerating personal devices ‘until we get them sorted’

Personal devices used for work don’t stay temporary. Files get downloaded, client systems get accessed, and what started as a short-term fix becomes permanent. When that person leaves, you have no ability to wipe company data from a device you never enrolled in Intune.

Issue company-owned devices on day one and enrol them properly. Where personal devices are unavoidable, require managed app access through Intune App Protection Policies — this allows selective wipe of company data without touching personal content.

Shared logins to avoid per-seat costs

Shared credentials are the worst offender at offboarding. When five people use the same login, you can’t remove one person’s access without changing the password for everyone. The savings from shared logins reappear at offboarding as wasted hours and exposed access. Per-seat licensing is the cost of doing this properly.

Letting client relationships live in one person’s inbox

This one hits agencies and professional services hardest. When a senior consultant or account manager leaves, their client relationships often leave with them — the email history, the context, the half-finished threads. From the client’s perspective, your business suddenly doesn’t know who they are.

Set up a shared M365 mailbox or alias for client-facing communication, and use a CRM where contact history is logged. Even a shared mailbox with a clear expectation that client threads are CC’d to it is a meaningful improvement over what most small businesses have today.

How to Retrofit Good Hygiene on Your Existing Team

You can’t re-onboard people who are already there, but you can audit what exists and close the gaps before the next departure.

  • SaaS audit: Pull three months of business credit card statements. List every recurring SaaS charge, who set it up, and whether anyone else can access it if that person left tomorrow.
  • Device register: List who has what, when each device was issued, and whether it’s enrolled in a management system. Ask every staff member to confirm the devices they use for work — personal ones included.
  • Client communication: Identify any client relationships that live primarily in one person’s inbox or on their mobile. Set up shared mailboxes or CRM logging for the highest-risk accounts first.

Most of this is an operational task, not a technology project. A spreadsheet and an honest afternoon will cover the bulk of it.

What Your IT Provider Should Be Doing at Onboarding

Most IT providers get called when someone resigns. They show up, disable the account, collect the laptop if they can find it, and do their best with whatever documentation exists. That’s the wrong end of the lifecycle to be involved in.

A good IT partner is present at onboarding too — setting up the account in Entra ID, enrolling the device in Intune, provisioning access through single sign-on, and maintaining a handover document for each staff member. When that’s in place, offboarding becomes a checklist and an hour rather than a three-week excavation.

Ask your IT provider what they do at onboarding. If the answer is ‘not much,’ that’s worth a conversation.

Ready to Tighten Up Your People Lifecycle?

If your offboarding process feels harder than it should, that’s a reliable signal your onboarding needs attention. We can help you map the gaps, clean up what’s already there, and build a process that works at both ends of the lifecycle. Get in touch with the team at IT TechNinjas or learn more about our Safe to Scale programme.

Ready to scale safely?

Book a discovery call and we'll map out where you stand and what comes next.