This article outlines the necessary steps required to initiate an employee termination. This process is sometimes referred to as offboarding and is based on level of urgency. Some tasks will also require elevated permissions to complete. Many of the answers to the questions found in this article will require guidance from the user's manager. Those answers should be captured in the Employee Termination service request. If they are not, reach out to the Reporting Manager for clarification. This procedure/process is implemented using the ‘Employee Termination’ Service Request in the Service Catalog.
A service request for user termination is initiated by HR, IT, or the Employee Manager upon notification that the user is being terminated. IT will contact the submitting HR personnel and the terminated employee’s manager to gather answers to key questions. Some of this information may already be captured in the submitted Service Request.
Key Information:
- Timing of departure.
- Timing of service cut off.
- Equipment return handling.
Note: IT will provide a list of items inventoried to the user. HR will then communicate this list to the termed employee. If local return is needed, HR and IT will coordinate a day and time to drop off equipment in the office. If the user is remote, HR and IT will coordinate equipment return with the employee. Please refer to
- Who requires access to the employee’s data including mailbox, OneDrive for Business, and/or local computer data files?
- Is an auto-reply message required?
Critical Priority Action Items - These tasks should be completed within 15 minutes of the timing of departure. Actions are to be performed by A Billmeier or B Stephens.
-
On-Premise Local Active Directory
- Disable the user account.
- Change account password.
-
Microsoft 365
- Block user sign-in.
Note: Once the account is disabled, block user sign-in will be enabled. If you see that sign-in is already blocked for the user, this is the reason why. If not, please proceed with blocking sign-in for this user as sync may have not occurred yet.
2. Sign the user out of all Office 365 sessions.
3. Remove all Office activations.
-
Exchange Online
- Perform selective wipe to remove access to the employee’s email.
- Disable Exchange ActiveSync/OWA for Devices.
- Enable Litigation Hold.
- Change message size restrictions (Sent Messages) to 0.
- Convert user mailbox to Shared Mailbox.
- In the Exchange Admin Center select Recipients > Mailboxes.
- Locate and select the user mailbox you want to convert. Under Convert to Shared Mailbox, select Convert.
- Set an automatic reply on the user mailbox indicating the user is no longer with the organization and to direct to the new contact, if requested on the 'Employee Termination' Service Request.
Note: For additional information on how to convert a user mailbox to a shared mailbox, please review the article below.
Convert a user mailbox to a shared mailbox - Microsoft 365 admin | Microsoft Docs
-
Azure
- Revoke MFA Sessions.
- Remove user from cloud security groups: SSPR, CSE, and MFA.
-
Exchange On-Prem
- Hide mailbox from Address Lists.
-
Livelink
- Disable user log-in.
-
Equipment
- Recover laptop.
- Recover Landmark issued iPhone and/or iPad.
- Check-in recovered hardware.
- Update hardware status in inventory.
- Remove termed employee’s name from hardware.
- Make a note in the asset comments of when hardware was returned.
Note: User may have been issued a printer, docking station, headset, monitors and/or webcam. Please recover all Landmark issued hardware. Keyboard/Mouse are not significant. To see a list of items assigned to the user, please check inventory and the Employee Onboarding ticket for the user if issued items were not inventoried.
High Priority Action Items - These tasks should be completed within 1 business day.
-
Microsoft 365
- Remove all M365 licenses.
- Create outgoing auto-reply message, if requested.
- Grant access to user's OneDrive, if requested.
-
Exchange Online
- Grant Access to Mailbox
Note: Everyone will have access to mailboxes for 90 days. Accounting/HR will have access for a minimum of 6 months. Project Managers have access for a minimum of 1 year.
2. Full: Use GUI to grant full control.
3. Forward messages to a different user, if requested.
-
DID and/or Extension
- Route calls to designated employee, if requested.
Note: Default is to forward for 90 days
2. Remove user from PBX directory, if applicable.
3. Clear voicemail greetings and voicemails.
Low Priority Action Items - These tasks should be completed within 1 week.
- Disable Bria license or Teams license
- Grant access to user's profile in Azure Files, if requested
-
On-Premise (Local) Active Directory
- Remove user from legacy distribution and security groups.
- Move user account to Users Held for Clean-Up OU.
- Delete GFI Fax user account, if applicable
-
Equipment
- If hardware has not been received, confirm with HR all issued hardware is pending recovery and document the ticket.
Clean-Up Items - These tasks may take anywhere from 30 days to a year and should not be marked as complete unless the tasks have been completed. Please do not close out the ticket until all assigned tasks assigned have been completed or closed.
Note: Some tasks may not apply. Please note accordingly within the specified task and close.
-
Delete user's local Active Directory account
- Permanently deletes user's mailbox and OneDrive files
Note: Content within the user mailbox is recoverable via an E-Discovery. One Drive files are available for 30 days after an account is deleted unless a policy is set to retain files for longer.
-
Remove DID/extension forwarding
- Mark DID/Ext as available for use
-
Confirm returned hardware check-in
- Confirm hardware status has been updated.
- Confirm termed employee’s name has been unassigned from the hardware.
Note: If hardware has been received but not checked in, please perform the above steps to include logging a note of when hardware was checked in.