How to offboard former employees in Microsoft 365 and preserve mailbox data
When an employee leaves, the goal is not simply to delete an account. A secure Microsoft 365 offboarding process must stop access quickly, preserve business-critical email and files, maintain mail flow where needed, and meet retention or legal requirements without wasting licenses.
Start with the right offboarding decision
Before deleting anything, decide what the organization needs to preserve and who needs access. In most cases, former employee mailboxes fall into one of four paths:
- Convert the mailbox to a shared mailbox for business continuity.
- Preserve the mailbox as an inactive mailbox for compliance, legal, or investigation purposes.
- Restore or migrate selected content to another employee's mailbox.
- Delete the mailbox after retention requirements are satisfied.
Coordinate with HR, legal, compliance, and the employee's manager before making the final choice. Deleting a Microsoft 365 user too early can remove access to the mailbox, OneDrive, Teams ownership, group ownership, Power Platform assets, and other business data.
Immediate access shutdown checklist
The first priority is to stop the former employee from accessing company resources. Use Microsoft Entra ID, the Microsoft 365 admin center, Microsoft Intune, and security tooling as appropriate.
Recommended steps:
- Block sign-in for the user account.
- Reset the password if there is any chance the employee still knows it.
- Revoke active sessions and refresh tokens so existing browser, Office app, and mobile sessions are forced to reauthenticate.
- Review and remove administrator roles, privileged group memberships, delegated mailbox access, and application permissions.
- Remove or review MFA methods, app passwords, passwordless credentials, and registered devices where appropriate.
- Retire or wipe company-owned devices in Microsoft Intune.
- For BYOD devices, remove corporate data using app protection policies where configured.
- Review Conditional Access exclusions and emergency access policies so the former employee is not bypassing normal controls.
- Rotate shared passwords, service credentials, or application secrets the employee may have known.
If the departure is sensitive or suspicious, also review sign-in logs, audit logs, mailbox rules, external forwarding, OAuth app grants, and recent file-sharing activity.
Option 1: Convert the mailbox to a shared mailbox
For many organizations, converting the former employee's mailbox to a shared mailbox is the best option for business continuity. A shared mailbox lets authorized users read historical email, respond to customers, and continue using the mailbox address without keeping a full user license assigned in many scenarios.
Important 2026 guidance:
- Convert the user mailbox to a shared mailbox before removing the Exchange Online license.
- Block sign-in for the associated Microsoft Entra ID account.
- Do not delete the associated user object if you intend to keep the shared mailbox. A shared mailbox is still tied to a directory object; deleting it can delete or soft-delete the mailbox.
- Assign only the required users Full Access, Send As, or Send on behalf permissions.
- Review mailbox rules, forwarding settings, and delegates before handing the mailbox to another team.
- Document who owns the shared mailbox after conversion.
Licensing clarification: a shared mailbox generally does not need an Exchange Online license if it is 50 GB or smaller and does not use an archive mailbox. A license is required when the shared mailbox needs more than 50 GB, an archive mailbox, Litigation Hold, or other licensed compliance or advanced features.
Option 2: Preserve the mailbox as an inactive mailbox
Use an inactive mailbox when the mailbox must be preserved for compliance, legal hold, investigation, or retention reasons, but normal users do not need day-to-day mailbox access.
An inactive mailbox is created by placing the mailbox on an eligible hold or retention policy before the user account is deleted. Common options include:
- Litigation Hold.
- Microsoft Purview retention policies or retention labels that preserve Exchange content.
- Microsoft Purview eDiscovery holds for legal or investigation cases.
Licensing requirements must be reviewed before the hold is applied. Common eligible licensing includes Exchange Online Plan 2, Microsoft 365 E3/E5 plans that include the required Exchange and compliance capabilities, or Exchange Online Plan 1 with an Exchange Online Archiving add-on where applicable. After the mailbox becomes inactive, the user license can usually be reassigned, but the organization must keep the appropriate service licensing for compliance features in accordance with Microsoft licensing terms.
Inactive mailboxes are not shared mailboxes. They are intended for preservation and discovery. Authorized compliance users can search and export content through Microsoft Purview eDiscovery or Content search, depending on permissions and licensing.
Mail flow options after the employee leaves
Decide how new email should be handled before removing licenses or deleting accounts.
Common approaches:
- Configure an automatic reply that informs senders the employee is no longer with the organization and provides a new contact.
- Convert the mailbox to a shared mailbox and give the successor or team access.
- Add the former employee's address as an alias to another mailbox or shared mailbox when appropriate.
- Use mail forwarding carefully and avoid forwarding to external addresses unless there is a documented business reason and security approval.
- Update distribution lists, Microsoft 365 Groups, shared mailbox memberships, and Teams ownership.
- Review transport rules if the employee's address was used in automated workflows.
External forwarding is a common data-loss risk. If it is allowed at all, it should be monitored and governed by security policy.
OneDrive, SharePoint, Teams, and Microsoft 365 Groups handoff
Former employee data is not limited to Exchange Online. A complete offboarding process should also address files, collaboration spaces, and ownership.
Recommended steps:
- Assign a manager or successor access to the former employee's OneDrive.
- Confirm OneDrive deleted-user retention settings in the SharePoint admin center. The default retention period is commonly 30 days, but organizations can configure a longer period, and Microsoft Purview retention policies may also apply.
- Transfer or copy business-critical files to the correct SharePoint site, Team, or department-owned location.
- Review Teams where the employee was an owner and assign at least one active owner.
- Review Microsoft 365 Groups, distribution groups, shared mailboxes, Planner plans, Loop workspaces, Power Automate flows, Power Apps, and Power BI assets for ownership dependencies.
- Remove inappropriate sharing links and external guest access if needed.
The goal is to move business data from a person-owned location to an organization-owned location.
License cleanup under Microsoft NCE
After mailbox preservation and file handoff are complete, remove unnecessary licenses from the former employee account. This frees the license assignment so it can be reused by another user, but under Microsoft New Commerce Experience (NCE), removing a license from a user does not automatically cancel the subscription seat or reduce the subscription commitment.
For cost control:
- Reassign available licenses to new employees where possible.
- Review duplicate or unused licenses regularly.
- Align license reductions with NCE renewal or cancellation windows.
- Keep licenses assigned where they are required for archive, hold, compliance, or mailbox size requirements.
A licensing review is especially important when converting many mailboxes to shared mailboxes or preserving inactive mailboxes for long retention periods.
When should you delete the user account?
Do not treat account deletion as the first step. In many cases, the safer sequence is:
- Block sign-in and revoke sessions.
- Preserve or transfer mailbox and OneDrive data.
- Reassign ownership of Teams, groups, files, and workflows.
- Convert to a shared mailbox or place the mailbox on the correct hold if required.
- Remove licenses that are no longer needed.
- Delete the user account only when you are certain it will not remove data or services you still need.
If the mailbox has been converted to a shared mailbox and the business wants to keep it active, keep the associated directory object blocked from sign-in instead of deleting it. If the goal is compliance preservation only, create an inactive mailbox correctly before deleting the account.
Security and compliance checks after offboarding
After the account is offboarded, perform a short verification pass:
- Confirm the account cannot sign in.
- Confirm sessions were revoked.
- Confirm devices were wiped, retired, or no longer compliant.
- Confirm mailbox permissions were assigned only to authorized users.
- Confirm no unauthorized forwarding, inbox rules, delegates, or OAuth app grants remain.
- Confirm OneDrive and SharePoint content is accessible to the right successor.
- Confirm retention, hold, or eDiscovery requirements are documented.
- Confirm license changes were recorded.
For regulated organizations, keep evidence of the offboarding actions, approvals, and retention decisions.
Key takeaways
- Do not delete a Microsoft 365 user account until mailbox, OneDrive, Teams, groups, and compliance requirements have been reviewed.
- Use a shared mailbox when the business needs ongoing access and mail flow; use an inactive mailbox when the goal is compliance or legal preservation.
- Block sign-in, revoke sessions, review MFA and devices, and remove privileged access immediately when an employee leaves.
- Shared mailboxes usually do not need a license under 50 GB, but licensing is required for archive, hold, larger mailboxes, and certain advanced features.
- Under NCE, removing a license from a user frees it for reassignment but does not necessarily reduce the subscription commitment.
IT Partner can help you build a secure Microsoft 365 offboarding workflow covering Exchange Online, Microsoft Entra ID, Intune, Purview retention, eDiscovery, OneDrive handoff, and license optimization.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.