In this guide
Appearance
Appearance
By Scot, 10+ years in IT support and helpdesk ·How these guides are checked
In the Microsoft 365 admin center, go to Users > Active users. To add someone, select Add a user. To offboard someone, reset their password and select Sign out of all sessions first — blocking sign-in alone can take up to 24 hours.
Checked against Microsoft 365 Roadmap, Microsoft Learn - new Outlook for Windows and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.
When you hire a new employee or part ways with an old one, managing their IT access is critical. Adding a user gives them a professional email address and access to company files.
Offboarding is the half people get wrong, and usually in the same way: they block the account and move on. Blocking is a slow lock, not an off switch. This article walks the removal sequence in the order that actually protects the business — end the live sessions, deal with the device, decide the mailbox, strip the MFA methods, then check for the forwarding rule everyone forgets. Sections 2 to 7 are that sequence, and the order is the point.
If you are on the other side of this — leaving a job rather than running the offboarding — Understanding What to Do When You Leave or Change Jobs covers the same event from the employee's side.
In this guide
When you add a user, Microsoft creates their inbox, sets up their OneDrive, and assigns them a software license.
If this is your first visit to the portal and the left navigation looks overwhelming, Understanding the Microsoft 365 Admin Center for Non-IT Owners explains what each section is for before you start clicking.
Blocking a departing person's account and ending the sessions they are already signed into are two different actions, and only one of them takes effect today.
Here is the difference, in Microsoft's own terms:
| Action | What it does | How fast |
|---|---|---|
| Reset password | Invalidates the credentials they know. Microsoft names this as the first step to preventing unauthorized access. | Immediate |
| Sign out of all sessions | Invalidates the access tokens keeping them signed in right now. | Within an hour, or as soon as they leave the page they are on |
| Block sign-in | Stops the account being used at all, permanently, until you unblock it. | Microsoft documents this as taking up to 24 hours to take effect |
That last row is why order matters. An account blocked at 9am on someone's last day can still be a signed-in Outlook on the web tab at 4pm. Do all three, in this order.
Nothing in this section deletes data. Every action here is reversible: you can send the person the new password, and you can unblock the account by clearing the same checkbox.
If they used Outlook on the web, the mailbox does not always close the instant you sign them out. As soon as they select a different tile such as OneDrive, or refresh the browser, the service signs them out.
To close the mailbox off completely, go to the Exchange admin center and select Recipients > Mailboxes, select the mailbox, and under Email apps & mobile devices select Manage email apps settings. Turn Off every option: Outlook desktop (MAPI), Exchange web services, Mobile (Exchange ActiveSync), IMAP, POP3 and Outlook on the web. Select Save. Turning these back on restores access; no mail is removed.
A wipe and a retire remove different things, and choosing a wipe on a phone the person owns personally erases their family photos alongside your company data.
| Action | What it removes | Use it for |
|---|---|---|
| Wipe | Factory-resets the device. Microsoft's wording: it removes all personal and organizational data, apps, and configurations. | A laptop or phone the company owns and is taking back or reissuing |
| Retire | Removes company data without a full wipe or factory reset. It unenrolls the device from Intune and removes managed apps, settings and profiles pushed by your policies, while preserving personal data. | A device the employee owns personally |
Microsoft names Retire as the action for personally owned devices. A wipe cannot be undone. On a phone the employee bought themselves, a wipe destroys their photos, personal apps and personal accounts with no way to restore them, and no business reason requires it — their work data is what Retire takes.
On a Windows laptop, retire with care. Once the Retire command runs on a device that is Microsoft Entra joined, nobody can sign in to it with a work account any more. Back up the BitLocker recovery key and any local administrator credentials before you send the command, or the machine becomes an expensive brick on a shelf.
No Intune on your plan? You can still clear company mail off a phone. In the Exchange admin center, go to Recipients > Mailboxes, select the user, and under Email apps & mobile devices select Manage mobile devices. On the Mobile Device Details page, select the device, choose Account Only Remote Wipe Device, then select Block access and save. This removes the mailbox from the phone and stops it reconnecting; it leaves the rest of the phone alone.
You have two ways to keep a departing person's email address working, they keep different things, and they cost different amounts.
| Option | What it keeps | License cost | The catch |
|---|---|---|---|
| Manage email forwarding | Only new mail sent to the address reaches the colleague taking over. The old mail stays where it is. | The account keeps its license | The account has to stay — it anchors the forwarding |
| Convert to shared mailbox | All existing email and calendar, in a mailbox several people can open | Free while the mailbox stays under 50 GB; above that, assign a license | The mailbox needs a license at the moment you convert, or the option does not appear. Remove it afterwards |
| Delete the account outright | Nothing long-term. Email, contacts and calendar are kept for 30 days, then deleted permanently | License is freed immediately | Breaks both options above; 30 days is the whole window |
The quiet trap in converting: Microsoft states plainly that if you do not reset the account password, the original username and password keep working on the shared mailbox after the conversion finishes. Section 2 is what closes that door. Do it first, and this stops being a problem.
To convert the mailbox:
To forward the mail instead:
Neither option works on a mailbox that is inactive for compliance reasons — a litigation hold, for example. If the commands are missing or refuse to save, that is usually why.
Also cancel any meetings the person organized. Rooms and equipment they booked stay unavailable until those meetings are cancelled.
Until you clear the authentication methods registered to the account, the phone in a departed employee's pocket can still approve a sign-in prompt for your organization.
The forwarding switch on the user's Mail tab is not the only one in the building — a rule the person created inside their own mailbox keeps sending mail out after the account is blocked, and nothing on the user card shows it.
This is the step that gets skipped, and it is the one that leaks. Inbox rules are preserved when a mailbox is converted to a shared mailbox, so a rule set up months ago quietly survives every other step in this article.
Removing the license stops the monthly charge, and doing it before you delete the account is what keeps your options open.
Removing a license is not the same as deleting the account, and the two lose different things:
Convert to a shared mailbox before you remove the license, not after. The convert option only appears while a license is assigned, and putting one back to convert costs you a month.
Delete the account last, and only if you are not using it as an anchor:
If you set up forwarding or converted the mailbox in section 4, stop here and leave the account in place. Deleting it breaks both.
WARNING
If you delete a user but forget to clear their assigned license during the deletion wizard, Microsoft continues to charge your card for that spare license every month until you cancel it in the Billing section.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| I don't see the "Users" tab | Lack of admin rights | You are signed in with a standard user account. Sign in with an account that holds Global Administrator or User Administrator rights. |
| New user can't log in | Password typo or replication delay | It can take up to 15 minutes for a new account to become active. Check you sent the correct temporary password. |
| Blocked the account, but they are still reading mail | Blocking takes up to 24 hours | Reset their password and use Sign out of all sessions on the Account tab. See section 2 — that pair is what ends access today. |
| "Convert to shared mailbox" is missing from the Mail tab | The license was removed first | Reassign a license to the account, convert the mailbox, then remove the license again. |
| Mail is still arriving at somebody's personal address | An inbox rule the user created | Admin-side forwarding is not the only route. Work through section 6 and delete the rule inside the mailbox itself. |
| Forwarding and shared-mailbox options refuse to save | The mailbox is on hold | A mailbox held for compliance reasons accepts neither. Check Litigation hold in the Exchange admin center under the mailbox's Others section. |
| Retired a Windows laptop and now nobody can sign in | Entra join was removed with it | Start the PC in Safe mode and sign in with a local administrator account to reach the data. If you have no local account and no BitLocker key, open a support request in the admin center under Support > New service request with the text: Microsoft Entra joined device retired via Intune, no local administrator account, need recovery options for user data. |
IT Tip Tuesday
Get a short, actionable IT tip in your inbox every week.
Nothing loads from beehiiv until you click. Once it does, the form sets beehiiv's own cookies and loads beehiiv's own analytics.