When an employee leaves, the obvious steps are disabling sign-in, revoking sessions, handling email and OneDrive, removing group memberships, and reclaiming licenses. But I'm concerned about less visible dependencies, such as Power Apps, Power Automate flows, authentication connections, SharePoint ownership, Power BI workspaces, scheduled tasks, delegated access, and other services tied to the user's account. What does a reliable offboarding process look like, and how do you identify these dependencies without manually checking every Microsoft 365 admin center?
3 Answers
Start with the security basics: confirm the termination request and correct identity, change or reset the password, block sign-in, revoke active sessions and refresh tokens, remove authentication methods, wipe company data from managed or BYOD devices, and disable the account in both on-premises Active Directory and Entra ID when applicable. Remove group memberships, revoke licenses, hide the mailbox from address lists, and remove other product licenses. If there is a mailbox to retain, convert it to a shared mailbox, configure an out-of-office message and approved delegates, and remove personal forwarding. Keep a documented retention period before deleting anything.
The most important part is transferring ownership before the account is disabled. Check Microsoft 365 groups and Teams, SharePoint sites, OneDrive files, Power BI workspaces, Forms, Bookings, shared mailboxes, calendars, contacts, app registrations, RBAC roles, scheduled tasks, scripts, and any third-party identity providers. Power Platform deserves special attention: flows may continue running temporarily through the departing user’s connections, then silently fail when those credentials expire. Reassign orphaned flows and app connections to a service account or group-owned identity, and make sure every important SharePoint site and business process has at least two appropriate owners. Also look for undocumented scripts or scheduled jobs running under the employee’s credentials.
A checklist or automation is much safer than relying on memory. We export the user’s group memberships, ownership, delegated access, licenses, SharePoint permissions, and mailbox access, then send the ownership report to the manager for review. The manager confirms what must be retained, transferred, forwarded, or backed up. We use a staged process: disable access immediately, preserve or transfer data according to legal and retention requirements, leave the mailbox and OneDrive available for an approved period, then remove licenses and delete the account only after the review window expires. Automation can handle the repetitive account changes, but management still needs to identify which business processes depend on the person.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures