The Importance of Properly Offboarding Employees

Employers and employees part ways for all sorts of reasons. People move on when a contract ends, to take a new job, or to retire. They also leave through layoffs or terminations. Whatever the reason, offboarding, the process of managing an employee’s departure, is essential. I help businesses with this regularly, because getting it wrong carries real risk.

Without a systematic offboarding protocol, organizations face serious risks around data security, device mismanagement, operational disruption, and compliance. In one troubling example, a fired employee allegedly hacked Disney World’s menu creation system, changing prices, adding profanity, and most dangerously, altering allergen information in ways that could have caused someone with a peanut allergy to order food containing peanuts.

Offboarding has administrative, HR, and legal dimensions, and those matter. But my focus here is the technical side: the three parts every offboarding plan needs are revoking access, retrieving devices, and preserving the organization’s data.

Revoke digital access

The most urgent step is cutting off the departing employee’s digital access to things like email, your shared password manager, and core service accounts. For someone retiring or staying on to train a replacement, you can phase this out on a schedule, which gives everyone time to transition projects and communications.

In most cases, though, I advise revoking access immediately. That is especially true for involuntary departures, layoffs, performance-based terminations, or misconduct, and for high-security roles like IT administrators, legal team members, or senior executives. Even when a departure is friendly, the risk of data leaking out is too high to leave access open.

This is much easier if you use Apple Business Manager with an MDM platform. Apple Business Manager supports federated Apple Accounts, so revoking someone’s access to iCloud and other Apple services is straightforward, and it keeps personal Apple Accounts and their data separate, so employees can move their personal data off a company device cleanly.

MDM, mobile device management, matters even more. It lets you revoke access to company email, VPNs, Wi-Fi networks, and cloud services from one place. If a device is never returned, MDM can remotely lock, wipe, or reset it. For BYOD setups, where employees use their own devices, a properly configured MDM removes company data and profiles without touching anything personal.

An identity provider like Google Workspace, Microsoft Entra ID, or Okta, paired with single sign-on, makes this simpler still. These services tie access to all your apps and devices to one login, so deactivating the departing employee’s account cuts off everything at once. Without that, you end up doing the tedious dance of deactivating Google, then Adobe, then Slack, one by one, which is slow and error-prone.

Finally, MDM combined with single sign-on can help you watch for unusual activity during the offboarding window. You want to know if a terminated employee logs into a confidential database they have no reason to touch right after being let go.

Retrieve organization devices

Your plan should also cover getting company-owned devices back. Even with MDM in place, you need the hardware returned so it can go to other employees or be held as spares. Apple Business Manager helps here too, since it tracks every registered company device and can reassign them to new users.

The real win is that Apple Business Manager lets you turn off Activation Lock on all supervised devices, whether it was enabled with a federated Apple Account or a personal one. Without it, you may have to work with the former employee to regain access, or ask Apple Support for help with proof of purchase and ownership.

To avoid that awkward situation entirely, follow these best practices with Apple Business Manager:

  • Purchase Apple devices through Apple Business Manager-compatible channels.
  • Use Automated Device Enrollment so devices arrive supervised and MDM-managed out of the box.
  • Use federated Apple IDs so the organization keeps control of company content in Managed Apple Accounts.

Preserve organization data and communications

Finally, think about what the departing employee was actually doing. You will want to transfer or archive everything they worked on, including their company email account. In most cases someone else takes over their responsibilities and will need access to emails, files, contacts, and more.

An identity provider can transfer ownership of cloud files and data in Google Workspace or Microsoft 365 automatically. Without one, you will have to review their online files and reassign ownership by hand.

Email needs extra thought. You will probably want to forward the departing employee’s email to whoever takes over. If that is not practical, set up an auto-reply explaining that the employee is no longer with the company and listing alternative contacts. Either way, it is worth scanning incoming mail periodically to make sure nothing essential slips through.

Next steps

If you do not have a formal offboarding policy, I recommend developing one soon. It is one of those tasks that is easy to postpone until it is too late, at which point you are scrambling. You can find offboarding policy templates and other resources online, and I am happy to walk through the tech-specific pieces with you when you are ready.

And if you are not already using Apple Business Manager with an MDM solution, getting started is even more urgent. Schedule a session with me to talk through what is involved.


← Back to all posts