Why a process, not a favour
Joiners and leavers are where security and productivity meet. A joiner without the right access on day one costs a week of productivity; a leaver with access on day two costs whatever they, or whoever gets their password, decide it costs. Both are solved by the same thing: an agreed process with an owner in HR and an owner in IT, triggered by a single message rather than a chain of them.
The process below assumes Microsoft 365 with Intune, because that is what makes most of it a click rather than a job.
Joiners: ready on day one
Two weeks before (HR to IT): name, start date, role, manager, which team, whether a laptop or phone is needed, and who they should be modelled on for access.
One week before (IT):
- Create the account, assign the licence, add to the groups that grant access (never copy another user's permissions by hand; use the group).
- Register MFA on their first day, in person or on a call, with a phishing-resistant method where possible.
- Order or prepare the device: with Windows Autopilot the laptop ships from the supplier and configures itself when they sign in; no engineer needed.
- Prepare the welcome: helpdesk contact, how to report a suspicious email, the acceptable-use one-pager, how to work securely from home.
Day one: they sign in, the device enrols, Office and Teams install, the right SharePoint sites and Teams appear. The manager checks access is right within the first week, and IT adjusts through group membership.
Movers: the step everyone skips
Someone moves from sales to operations and keeps every sales permission they ever had, plus the new ones. Five years later they can see everything. This is how "permission creep" happens and why Copilot rollouts find so much overshared data.
The fix is the same trigger as a joiner: HR tells IT of the role change, IT moves them between groups rather than adding to them, and the old manager confirms what should go. Fifteen minutes.
Not sure which of these applies to your business? Ask an engineer.
Book a Discovery CallLeavers: the same-day checklist
Timing is agreed with HR: at the exit meeting, at close of business, or in a planned leaver's case at the end of the notice period. Whichever, on the day:
| Step | Why |
|---|---|
| Disable the account and revoke all sessions (not delete) | Cuts access immediately, including on phones and browsers that were already signed in. Keeps the mailbox and files. |
| Reset the password and remove MFA methods | Belt and braces; stops a saved password or a registered device being used. |
| Wipe company data from personal devices (selective wipe via app protection) and wipe or retire company devices | The phone keeps its photos; the company data goes. |
| Convert the mailbox to shared or set an auto-reply and delegate it to the manager | Customers get a reply; nothing is lost; the licence is freed. |
| Transfer OneDrive ownership to the manager before the retention window ends | Deleted-user OneDrive content is kept for 30 days by default; the backup guide explains the windows. |
| Remove from groups, Teams, shared mailboxes and third-party apps | The CRM, the accounts package, the social media logins and the supplier portals do not know about Microsoft 365. Keep a list. |
| Recover devices and keys; change any shared passwords they knew | Door codes, the Wi-Fi, the alarm. |
| Record it | Who did what, when, for the audit trail and for the day someone asks. |
For an unplanned or hostile departure, the first two steps happen in minutes, then the rest. For a planned one, tell the person what will happen and when; it is more decent and it avoids the "I was locked out mid-handover" complaint.
How Black Sheep Support runs it
Joiners, movers and leavers are included in our managed support: one message to the helpdesk from HR triggers the process, with a checklist per person and confirmation back when it is done. Devices are Autopilot-ready so a new starter's laptop needs no engineer, and leavers are handled the same day. [TO CONFIRM: any notice requirements for same-day leaver processing outside business hours.]
The device side is described in the Intune and BYOD guide; the wider configuration that makes it possible is in Is your Microsoft 365 actually secure?.
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Frequently asked questions
Should we delete a leaver's account or disable it?
Disable it and revoke sessions on the day. Deleting starts retention clocks on the mailbox and OneDrive (30 days by default); disabling keeps everything while access is cut. Convert the mailbox to shared and transfer files, then delete later.
How quickly should a leaver lose access?
The moment agreed with HR, and within minutes of that moment. Disabling the account and revoking sessions takes two clicks when the process exists.
Can we wipe company data from a leaver's personal phone?
Yes, if app protection policies were in place: a selective wipe removes company email and files from the work apps and leaves personal content alone. Without them, you can only cut access and ask.
How do we stop permission creep?
Grant access through groups, move people between groups when roles change, and review group membership quarterly. Never grant permissions to individuals by hand.
What about accounts outside Microsoft 365?
Keep a list of every system with its own login (CRM, accounts, banking, social media, supplier portals) and who has access. The leaver checklist walks the list. Single sign-on through Entra ID shrinks the list over time.
Improve your joiner and leaver process
We will map what happens today when someone joins or leaves, find the accounts and devices that fall through the gaps, and set up a process HR and IT can run without thinking about it.
- A review of current joiner and leaver handling, including systems outside Microsoft 365.
- A same-day leaver checklist for your business.
- Autopilot and group-based access so joiners are productive on day one.
- How it fits your managed support.
Sources
Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.
- 1.Microsoft Learn: OneDrive retention and deletion (deleted user content, 30 days default) · accessed 10 September 2026
- 2.Microsoft Learn: App protection policies overview (selective wipe) · accessed 10 September 2026
What has changed on this page
- 10 September 2026Page published.

