Why the order matters
When someone leaves, the instinct is to suspend the account and move on. Suspension feels decisive, but done first it works against you: several of the later steps are easier to run, and far easier to verify, while the account is still active.
The safe sequence is the one below: end the person's ability to sign in immediately, put mail continuity in place while the mailbox is still live, move data to named owners, and make suspension the last thing that happens rather than the first. Decide who inherits the mailbox and the files before you start: half of these steps need a name.
1. Cut access
The leaver's ability to get in ends now. The account itself stays active: you still need it for everything that follows.
- Sign the user out everywhere. End every active session so open browser tabs and signed-in device sessions are terminated.
- Reset the password to a long random value that nobody knows. The aim is that no person can sign in as the leaver, so do not hand the new password to a colleague and do not write it down: successor access to the mailbox comes later, through delegation.
- Revoke app passwords. Older clients and devices may hold their own app-specific passwords: revoke them all rather than assuming the reset covered them.
- Revoke third-party app access. Review every application the account has authorised and revoke those grants explicitly: do not assume a password reset is enough on its own.
- Invalidate 2-Step Verification backup codes. Treat printed backup codes as live credentials until they are invalidated: a sheet in a drawer should not remain a way in.
2. Keep the mail flowing
Do this while the mailbox is still active, before any thought of suspension: customers and colleagues will keep writing to the address for months.
- Set an auto-reply. Name the person who has taken over and how to reach them, so senders are redirected rather than ignored.
- Forward incoming mail to a colleague inside the domain. Never forward to a personal address: the moment mail leaves the organisation's own domain you lose control of it, and the customer's data sits in an account nobody governs.
- Delegate the mailbox rather than sharing credentials. Delegation lets the successor work in the leaver's mailbox under their own identity, rather than behind a shared password nobody can be told apart by.
3. Move and transfer
Ownership is the theme here: everything the leaver owned needs a named new owner, and transfers are the reason suspension comes last.
- Record and remove group memberships. List the groups first: the list tells you what the leaver could reach, and who may need adding in their place. Then remove the account from all of them.
- Move the account to a leavers organizational unit. If you keep a dedicated organizational unit for departures, apply it now: it lets you hold leaver accounts under tighter settings for the rest of their life, and makes them easy to find later.
- Transfer Drive and Calendar ownership. Give the files and the events a named owner, and start the transfer before you suspend: transfers take time to finish, and it is far easier to check the result while the account is still active. Do not move on until you have confirmed the transfer completed.
4. Reclaim and close
Only when mail has a destination and data has an owner does the account itself get closed down.
- Reclaim the licence. Check first what your edition does with a mailbox and its files when the licence is removed: reclaim the spend once you are sure nothing you still need goes with it.
- Suspend the account: the final step, not the first. By now nothing is waiting on the account being active, so suspension closes the door without breaking anything.
- Write down what you did and when. Who asked for the offboarding, which steps ran, what each one found, and the time it happened: six months later that record is the difference between an answer and a shrug.
The classic mistakes are all order mistakes: suspending on day one, before mail continuity existed or transfers had finished; forwarding mail to a personal address because it was quick; and nobody writing anything down, so no one can say what was done or when. Every one of them is avoided by running the same steps in the right order and keeping a record.
How CrossTenant helps
CrossTenant runs this checklist as one guided flow: session sign-out, password reset to an undisclosed random value, app-password and third-party token revocation, backup-code invalidation, auto-reply, internal-only forwarding and delegation, group and organizational unit moves, Drive and Calendar transfer, licence reclaim, and suspension. The server re-orders the steps into a safe canonical sequence, so mail continuity runs before suspension and suspension always runs last: the order this guide argues for is enforced, not remembered.
Every step shows a live preview of what it is about to touch before anything executes, running the flow requires typing the leaver's email address back, and the whole run can sit behind an optional second approver (see approvals & audit). Each step's outcome is recorded in a tamper-evident audit trail, so the write-it-down step happens whether or not anyone remembers it.
Related: offboarding a leaver with CrossTenant.
Field guides
Offboard the next leaver with the order built in
The order in this checklist is what CrossTenant's guided offboarding runs as one flow: previewed, confirmed, and audited. There's a free tier for your own tenant while you evaluate.