Someone is leaving.
Keep control.
Ending a working relationship takes more than changing one password. Transfer responsibility, remove access that is no longer needed and check that your business can still use its data and workflows.
At a glance
- List personal, shared and service accounts.
- Transfer ownership before disabling access.
- Verify the change in each important system.
First establish what the access controls.
Start with the person’s or supplier’s responsibilities: customer service, application maintenance, billing or publishing. List the systems and sign-in methods used for each. A company account may open several services, while separate keys and local accounts can continue working independently.
- For each access entry, record the system, owner, permissions and person approving the change.
- Include API keys, service accounts, remote access and recovery arrangements. Do not put secrets in an ordinary spreadsheet.
What must stay with the business?
Transfer documents, repositories, administration panels and integration ownership to the person taking responsibility. Check that the business has its own recovery route. Control of a domain, email or hosting account should not depend solely on the departing person’s private address.
Illustrative example: a supplier maintained an application and its backup job used the supplier’s account. Deleting that account immediately would stop backups. Establish a replacement service account and test the job, then remove the supplier’s access. If misuse is suspected, immediate restriction and preservation of evidence may take priority.
Disabling sign-in is part of the work.
Agree the timing, operator and order of changes. Depending on the system, you may need to disable an account, remove roles, end sessions or rotate a shared key. Do not assume that changing a password immediately ends every active session.
Microsoft distinguishes tokens from application sessions. An application controls the session it issues. Checking the main identity directory therefore does not replace access checks in other services.
How do you confirm completion?
Record what changed, when and with what result. Confirm removal of the specified permissions and operation of important processes afterwards. A note saying “done” without a system list will not show which access routes remained.
- Can the new owner sign in and recover access?
- Do backups, integrations and jobs still work?
- Which systems remain unchecked and who will finish the work?
Sources and next step
These sources describe mechanisms and good practices. They do not confirm your company’s configuration or compliance. The examples in this guide are illustrative.
To apply these questions to your business, explore the related service. A description of your situation is enough for an initial discussion; do not send passwords or confidential data through the form.
Explore our cybersecurity services