Guide · IT security
When an employee leaves: the IT checklist
Onboarding is usually well organised – someone joins and gets a computer, an account and access. The reverse is rarely handled as carefully. The result is accounts that live on for years and access nobody remembers.
Why this regularly goes wrong
When we take over a client's IT, we almost always see the same picture: active accounts belonging to people who left years ago. Sometimes with a valid password, sometimes with remote access, occasionally with administrator rights.
The reason is rarely carelessness but a lack of clear responsibility. HR reports the departure, someone disables the Windows account – and nobody is responsible for thinking about the access that lies outside it: the tax adviser's portal, the login to the supplier's ordering system, the account with the phone provider, the key for remote maintenance.
Then there is a question that quickly becomes awkward: who does the mailbox belong to after the person leaves? Permanently forwarding it to the successor is convenient but problematic under data protection law, because private messages get forwarded too. The clean solution is an out-of-office message pointing to a shared address – then blocking the mailbox but keeping it for the retention periods.
Tool
The checklist to tick off
Go through the items on the last working day. Print, sign and add to the personnel file – then, if in doubt, there is a record of what happened when.
Your entries stay in this browser window. Nothing is stored and nothing is transmitted.
Before the last working day
Things that are hard to do once the person has left.
Accounts and access
Disable rather than delete – because of retention periods and later queries.
Email and phone
This is where the most common data protection mistake happens.
Devices and keys
Document afterwards
The part that counts if there is a dispute.
Nothing ticked yet.
Three cases that work differently
Not every departure is amicable and announced in advance.
- Summary dismissal. Access is blocked before the meeting, not after. That sounds harsh, but it is the only order that works – and it also protects the departing person from suspicion of having taken anything.
- Long-term sickness or parental leave. Not offboarding, but the same question about cover and the mailbox. Access remains in place but should be checked for two-factor protection.
- Contractors and freelancers. Regularly forgotten because they are not on any staff list. Keep a separate record of all access that does not belong to employees – including your IT service provider's.
Frequently asked questions
What we are often asked
May we forward the mailbox to the successor?
Permanent forwarding to a single person is problematic, because private messages sent to the old address get forwarded too. An out-of-office message pointing to a shared address is cleaner. If private use is permitted or tolerated in your company, the question becomes even tighter – in that case you should get advice on the employment-law position.
Should we delete or disable the account?
Disable it first. Deleting an account often takes permissions, file ownership and mailbox contents with it that will be needed later. Only delete once the retention periods have expired – and then deliberately.
How do we find access we do not know about?
In three ways: go through the invoices of the last twelve months, search the mailbox for registration confirmations, and ask explicitly in the handover meeting. You only achieve completeness if access is recorded centrally from the start.
What about our IT service provider's access?
It belongs on the same list. If you change provider, their access must be revoked just like that of a departing employee. A provider who does not answer this question for you unprompted is already telling you something.
Dipl.-Ing. Mohamed Khater
Dipl.-Ing. Mohamed Khater founded INFONET Computer GmbH in Cologne in 1992. This list grew out of IT takeovers: with almost every new client, we find active accounts belonging to people who left long ago.
Further reading
- IT Security – Permissions, endpoint protection and emergency plan
- Managed IT Services – User and device management in day-to-day operations
- NIS2: Does it apply to us? – When access rights become something you must evidence
Free security check
Who actually has access to your systems?
We look at accounts, permissions and remote access and tell you which ones nobody needs any more. In our experience, this is the appointment with the most surprises.
+49 221 984300-0Switchboard and support hotline
[email protected]Reply within 4 hours on working days
Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen
Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement
