An employee left with our laptop, what do we do?
Disable the account first, then revoke every active sign-in session: a password change on its own leaves the person signed in. Remove their MFA methods, change shared logins, convert or forward the mailbox, and arrange the laptop's return or wipe it remotely. Check the audit log for data copied out, and write down what you did. In Dallas I can run this remotely the same day.
Answered by Anthony Omini, Cross River Tech, Dallas

Key takeaways
- Disable the account and revoke active sessions before you do anything else. A password change alone leaves a signed-in phone or laptop working for hours.
- Remove the person's MFA methods and app passwords, or they can still get back in even after the password is reset.
- Shared logins are the real problem: every login two or more people knew has to change, and that list is usually longer than anyone expects.
- A laptop enrolled in device management can be wiped or locked remotely. A laptop that was never enrolled can only be asked for politely.
- Write the whole thing down as you go. If this turns into a dispute or an insurance question, the record is what you will be asked for.
An employee just left with the laptop. What do you do in the first hour?
Lock the accounts before you chase the hardware. The laptop is a physical object you can usually recover later; the accounts are live right now, and every minute they stay live is a minute somebody can read email, download files or send a message as your business. Work through this list in order, top to bottom, and do not skip ahead to the interesting parts.
- Disable the user account. In Microsoft 365 or Google Workspace, block sign-in on the account. Do not delete it. Deleting destroys mail, files and the audit trail you may need later.
- Revoke active sessions. This is the step almost everyone misses. Blocking sign-in stops new logins; it does not always kill the session already running on a phone or laptop. In Microsoft 365 there is a "sign out of all sessions" action on the user; in Google Workspace it is "sign out user". Use it.
- Reset the password anyway, to something nobody in the office knows, and store it in a password manager rather than a sticky note.
- Remove their MFA methods. Delete the authenticator app registration, the phone number and any app passwords. A leftover authenticator on a personal phone is a working key.
- Change every shared login the person knew. Bank portal, payroll, the point-of-sale system, the alarm code, the Wi-Fi password, social media, the domain registrar. More on how to prioritize this below.
- Deal with the mailbox. Convert it to a shared mailbox or forward it to a manager so client email keeps arriving and nothing bounces.
- Retrieve or wipe the device. If it is enrolled in device management, lock or wipe it now. If it is not, send a written request for its return today, not next week.
- Check what left with them. Look at the sign-in and audit logs for bulk downloads, new mail forwarding rules and files shared to outside addresses.
- Write it all down. Date, time, what you changed, who did it.
If nobody in the office is comfortable doing this, call me at (214) 612-7080. Emergency offboarding is almost entirely remote work, which means it is the cheaper of my two rates and it can start while you are still on the phone.
Why is disabling the account better than just changing the password?
Because modern cloud accounts do not sign you out when the password changes. When someone signs in to Microsoft 365 or Google Workspace, the service hands their device a token, which is a small file that says "this person already proved who they are." That token keeps working on its own schedule. Change the password and the phone in their pocket may keep pulling email for the rest of the day, because it never has to log in again.
That is why the order matters. Blocking sign-in stops any new login attempt. Revoking sessions invalidates the tokens that are already out there, which forces every device that person owns to ask for credentials it no longer has. Doing both closes the door and the window.
Deleting the account looks decisive and usually causes harm. In most plans the mailbox and the personal cloud storage go with it after a grace period, along with the sign-in history you may need if a client later asks whether their file was accessed. Disable, do not delete. Once the dust settles and the mail has been handed over, you can release the license and keep the record.
The same logic applies to the person's phone if it was reading company mail. Blocking the account and revoking sessions handles it without you ever touching their handset, which matters when the phone is personally owned and you have no right to wipe it.
Which passwords actually have to change, and in what order?
Every login two or more people knew is now a company problem, and the honest starting point is that you probably do not have a complete list. Work outward from money and identity. This is the priority order I use during an emergency offboarding, and it is worth keeping as a template.
| What | Why it is on the list | When |
|---|---|---|
| Banking, payroll, card portals | Direct financial loss, and often no second approver | First hour |
| Microsoft 365 or Google admin accounts | Whoever holds these can undo everything else you just did | First hour |
| Domain registrar and DNS | Control of the domain is control of your email | First hour |
| Line-of-business software (practice management, case management, agency system) | Client data, and often no per-person accounts | Same day |
| Remote access, VPN and firewall admin | A way back into the network from anywhere | Same day |
| Shared mailboxes, social accounts, review profiles | Reputational damage is fast and public | Same day |
| Office Wi-Fi, alarm codes, door codes, printer admin | Physical and network access from the parking lot | Within the week |
| Vendor portals, shipping accounts, ad platforms | Spending authority and customer lists | Within the week |
Two practical notes. First, change the recovery details as well as the password: a personal phone number or private email sitting in the recovery slot of a bank portal is a password reset waiting to happen. Second, if you find yourself unable to answer "who else knew this one?", that is the strongest possible argument for a shared password manager, which lets you see exactly which credentials a person could open and revoke them all at once.
What happens to their email, files and phone number?
Nothing should bounce and nothing should disappear. Handle the three in this order.
Email. Convert the mailbox to a shared mailbox so a manager can open it without paying for another license, or set forwarding to whoever is covering the role. Add an auto-reply naming the new contact if the person dealt with clients. Read the mailbox rules before you do any of this, because a departing employee sometimes leaves a rule that quietly copies mail somewhere else.
Files. In Microsoft 365, a departed user's OneDrive can be handed to a manager for a limited period, so grab anything that only lived there. In Google Workspace, transfer Drive ownership before the account is removed. Anything in a shared team site or shared drive is already safe, which is the argument for not letting people work out of personal cloud storage in the first place.
Phone. Forward the extension, remove them from ring groups and hunt groups, and change the voicemail greeting. If the mobile number is on a company account and clients call it, start the number transfer now rather than after the contract renews. If the number is personal and clients have it, that is a business problem no IT step fixes; the practical answer is a mail-out and a new contact on the website.
This is routine work in Microsoft 365 and Google Workspace administration, and it goes much faster when someone already knows how your tenant is arranged.
How do you get the laptop back, or wipe it if they keep it?
Whether you have any technical option at all comes down to one question you cannot answer after the fact: was that laptop enrolled in device management?
A managed Windows laptop, enrolled in something like Microsoft Intune, can be locked or wiped remotely the next time it touches the internet. If the drive is encrypted with BitLocker and you hold the recovery key, the data is unreadable to anyone who takes the disk out. A Mac in a management platform behaves the same way. This is the difference between "the laptop is gone" and "the laptop is now a brick with nothing on it".
An unmanaged laptop that someone bought at a big-box store and never enrolled is a different story. You can disable the accounts on it, which strips out email and cloud files over time, but anything already saved to the local disk stays there and you have no remote control at all. In that case the steps are practical, not technical: a written request for return with a date, an offer to collect it or pay for shipping, a note in the final pay conversation if that is still open, and if it is a valuable machine and the person goes quiet, a police report and a conversation with your attorney. Do not attempt anything clever with remote software you installed after the fact.
- Enrolled and online: lock, then wipe, then confirm the wipe completed in the console.
- Enrolled and offline: queue the wipe. It runs when the machine next connects.
- Encrypted but unmanaged: the data is protected if they never had the login. Keep the recovery key.
- Neither: assume everything saved locally is now outside the business, and plan around that.
Getting devices enrolled is a small project you can do in an afternoon for a typical office, and it is included in ongoing managed IT support rather than being an extra line item.
How do you tell whether data was copied out before they left?
Look at the logs while they still exist. Most small businesses discover only after a departure that their audit logging retention is short, so this is a same-week job, not a next-month one.
The places worth checking, in the order that usually pays off:
- Mail forwarding rules and mailbox rules, including forwarding set at the mailbox level rather than in Outlook. A rule sending copies to a personal address is the single most common finding.
- Bulk file activity. In Microsoft 365 the unified audit log shows file downloads and sync events; in Google Workspace the Drive audit log does the same. A person who downloaded four hundred files in one evening leaves an obvious shape.
- Sharing links created to outside addresses, especially links set to "anyone with the link".
- Sign-in locations and new device registrations in the weeks before they left.
- Sent items and deleted items, for attachments mailed to a personal account.
- Removable storage, if endpoint software was recording it. Without that software there is no record of a USB stick, which is worth knowing before you assume the logs tell the whole story.
Be measured about what you find. Someone syncing their own working documents is not the same as someone exporting a client list, and the difference matters if you end up talking to a lawyer. Preserve what you find rather than acting on it in the moment: export the log entries, note the timestamps, and keep the mailbox intact. If your business handles regulated data, such as a dental practice or a medical office under HIPAA, treat a suspected export as a potential reportable incident and get advice before you decide it was nothing.
What does a written offboarding checklist look like for a small business?
One page, in a shared folder, with a name next to each line. The value is not the technology, it is that nobody has to remember anything on a stressful morning. Here is a structure that works for an office of five to fifty people.
| Stage | Tasks | Who |
|---|---|---|
| Before the last day (planned exits only) | Confirm the device list, agree the return date, note what only this person knows, identify who inherits their clients | Manager |
| Hour zero | Block sign-in, revoke sessions, reset password, remove MFA methods | IT |
| Hour zero | Change shared and financial logins in the priority order above | Owner or office manager |
| Same day | Convert or forward the mailbox, transfer file ownership, update the phone system | IT |
| Same day | Collect the laptop, phone, keys, badge and any hardware token; lock or wipe if not returned | Manager and IT |
| Within the week | Review audit logs, remove from vendor portals and mailing lists, release or reassign licenses | IT |
| Within the week | File the completed checklist with dates and initials | Owner |
Keep the finished sheets. If a client, a carrier or an attorney ever asks how you handled a departure, a dated checklist with initials is a far better answer than a memory. The same page, run backwards, is your onboarding process, which is exactly the point I make in the IT onboarding checklist for a first employee.
How do you make the next departure boring instead of frightening?
Every painful offboarding I see traces back to the same three decisions made years earlier. Fix them once and a resignation becomes a fifteen-minute administrative task.
- Per-person accounts, everywhere. No shared logins for the practice software, the bank portal or the front desk computer. If five people share one login, you cannot disable one of them, you cannot tell who did what, and every departure means changing a password five people have to relearn.
- A password manager the business owns. Credentials live in a company vault, shared to people by role. When someone leaves you remove them from the vault and you can see exactly which secrets they could open, which turns the "what did they know?" question into a list instead of a guess.
- Devices enrolled and encrypted from day one. Enrollment at setup costs nothing. Enrollment after the laptop has walked out is impossible.
If your business runs on Microsoft 365, the settings that make all three of those practical, including sign-in logging and conditional access, are covered in Microsoft 365 security for a small business.
Add two habits. Review your admin accounts twice a year and remove anyone who does not need that level of access, including former IT providers, which is the failure behind being locked out of your own Microsoft 365 tenant. And make sure at least two people, one of them an owner, can get into everything, so a departure is never also a lockout.
If a departure has already turned into an incident, with mail going somewhere it should not or logins you cannot account for, treat it the same way you would treat a hacked business email account and work through that sequence too. The overlap is large and the cost of doing both is small.
Who handles this in Dallas, and what does it cost?
I do, and it is priced by the hour with no contract. My name is Anthony Omini and I run Cross River Tech, a small owner-led IT company in Dallas. An emergency offboarding for a typical small office is remote work: I connect, run the account and session steps, help you order the password changes, set up the mail handover and pull the audit logs, and you get a written record of everything at the end.
Rates are published so nobody has to negotiate on a bad morning. Business hours, Monday to Friday, 8 AM to 5 PM Central, are $100 per hour remote and $150 per hour onsite. After hours, weekends and holidays are $150 remote and $225 onsite. There is a one-hour minimum. Most offboardings of one employee fit comfortably inside that hour unless the shared-password list turns out to be long.
I work with businesses across Dallas–Fort Worth onsite and support offices remotely anywhere in Texas, which for this kind of work makes no practical difference. If you would rather never have this conversation under pressure, get in touch and I will build the checklist for your specific setup while nothing is on fire. That is a much shorter and cheaper conversation than this one.
Questions people ask
Should I delete the former employee's account?
No. Block sign-in and revoke sessions instead. Deleting the account eventually destroys the mailbox, the personal cloud storage and the sign-in history, and that history is what proves whether anything was accessed after they left. Disable it, hand the mail and files over to a manager, and only release the license once you are sure nothing is still needed.
Can you wipe a company laptop remotely if the person will not return it?
Only if the laptop was enrolled in device management before it left. An enrolled Windows or Mac laptop can be locked or wiped the next time it connects to the internet, and a queued wipe will wait until it does. A machine that was never enrolled cannot be reached remotely, so the options become a written request for return and, if necessary, a police report.
Does changing the password lock a former employee out immediately?
Not on its own. Cloud services hand each signed-in device a token that keeps working after a password change, so a phone can carry on receiving email for hours. You have to revoke the active sessions as well, and remove the person's multi-factor methods, or they may still be able to approve a sign-in from their own phone.
How do I find out if a departing employee copied client data?
Check the audit logs quickly, because retention is often short. Look for mailbox forwarding rules, bulk file downloads or sync events, sharing links created to outside addresses, unusual sign-in locations, and attachments in sent items. Export what you find rather than acting on it immediately, and take advice before deciding whether it counts as a reportable incident.
What should be on a small business offboarding checklist?
Block sign-in, revoke sessions, reset the password, remove MFA methods, change shared and financial logins, convert or forward the mailbox, transfer file ownership, update the phone system, collect or wipe the device, review audit logs, remove vendor portal access, release licenses, and file the completed sheet with dates and initials. One page, one owner per line.
How long does an emergency offboarding take?
For one departing employee in a small office with per-user accounts, the technical steps take under an hour of remote work. What stretches it is shared logins: if six systems use one password that four people know, each of those has to be changed and redistributed. That is why the shared-password habit costs far more than it saves.



