Back to Admin Workflows

The User Left, but Access and Licenses Remain—Prove the Offboarding State

A closed HR ticket does not show tenant state. Build evidence for inactivity, sign-ins, roles, licenses, and approved removal without silently changing accounts.

Offboarding can appear complete in a ticket while the tenant still contains an enabled account, assigned license, privileged role, or recent sign-in. Conversely, immediately removing everything can disrupt legal, mailbox, or data-transfer requirements.

PSForge can generate a Microsoft 365 evidence workflow around the change. It does not infer employment status, approve data handling, or automatically disable users and remove licenses.

Prerequisites and decision boundaries

Start from an authorized leaver list with unique user principal names, effective times, manager or data owner, retention instructions, and exception owner. Confirm Graph and Microsoft 365 permissions and secure the exports.

Separate evidence collection from changes. Legal hold, mailbox conversion, data transfer, and identity dependencies must be resolved manually before disabling accounts or reclaiming licenses.

Collect the before-state

Export inactive users, sign-in logs, license assignments, and admin role assignments for the approved population. Add admin audit logs so the reviewer can identify relevant tenant-side changes and preserve a timestamped baseline.

PSForge generates these PowerShell steps. The operator manually checks identity matching, time zones, guest or shared-account exceptions, and whether the source list is complete.

Approve, change, and verify

After owners clear dependencies, bulk account disablement and license removal can be separately approved. Record who approved each action and why. Then rerun license, role, and sign-in evidence to confirm expected tenant state.

A lack of recent sign-ins does not prove an account is safe to remove, and a report does not establish that all downstream access is gone. Document systems outside Microsoft 365 and unresolved errors explicitly.

Ordered offboarding evidence workflow

  1. Manually validate the HR-authorized user list, timing, owners, holds, and exceptions
  2. Generate inactive-user, sign-in, license, role, and audit exports
  3. Manually resolve mailbox, data, legal, and downstream-access dependencies
  4. Run separately approved account-disable and license-removal actions
  5. Repeat exports, reconcile each identity, and retain evidence with the ticket

Final thoughts

Reliable offboarding evidence connects an authorized identity list to observed tenant state, approved actions, and post-change verification.

Use generated steps for consistency, but keep identity, retention, and access decisions with accountable people.

Related guides