Skip to content

How to Add or Remove Users in Microsoft 365 Admin Center

Applies toMicrosoft 365
25 min fix Updated 9 Aug 2026
Quick Answer

In the Microsoft 365 admin center, go to Users > Active users. To add someone, select Add a user. To offboard someone, reset their password and select Sign out of all sessions first — blocking sign-in alone can take up to 24 hours.

Checked against Microsoft 365 Roadmap, Microsoft Learn - new Outlook for Windows and between 5 Aug 2026 and 12 Sep 2026. Nothing published in that period has been linked to this guide.

Estimated Time to Fix: 25 minutes

Summary

When you hire a new employee or part ways with an old one, managing their IT access is critical. Adding a user gives them a professional email address and access to company files.

Offboarding is the half people get wrong, and usually in the same way: they block the account and move on. Blocking is a slow lock, not an off switch. This article walks the removal sequence in the order that actually protects the business — end the live sessions, deal with the device, decide the mailbox, strip the MFA methods, then check for the forwarding rule everyone forgets. Sections 2 to 7 are that sequence, and the order is the point.

If you are on the other side of this — leaving a job rather than running the offboarding — Understanding What to Do When You Leave or Change Jobs covers the same event from the employee's side.

In this guide

Before You Start

  • You need Global Admin or User Admin rights in your Microsoft 365 tenant. Resetting passwords and signing users out needs at least the User Administrator or Helpdesk Administrator role; signing out another administrator needs Global Administrator.
  • Clearing someone's MFA methods happens in the Microsoft Entra admin center and needs at least the Authentication Administrator role.
  • Wiping or retiring a computer or phone needs Microsoft Intune, which comes with Business Premium and the E3 and E5 plans. Understanding Microsoft 365 Licensing and Plan Differences shows which plans include it.

Instructions

1. How to Add a New User

When you add a user, Microsoft creates their inbox, sets up their OneDrive, and assigns them a software license.

If this is your first visit to the portal and the left navigation looks overwhelming, Understanding the Microsoft 365 Admin Center for Non-IT Owners explains what each section is for before you start clicking.

  1. Sign in to the Microsoft 365 Admin Center.
  2. On the left menu, click Users > Active users.
  3. Click the Add a user button at the top of the list.
  4. Fill out the Basic info: First name, Last name, Display name, and the username (which will become their email address).
  5. For the password, you can let Microsoft auto-generate one, or you can create one yourself. Leave "Require this user to change their password when they first sign in" checked.
  6. Click Next.
  7. In the Product licenses section, select the license you want to assign them (e.g., Business Standard). If you don't have any available, it will tell you how much it costs to buy a new one.
  8. Click Next, skip the "Optional settings" by clicking Next again, and then click Finish adding.

2. Sign Them Out of Every Session, Then Block Sign-In

Blocking a departing person's account and ending the sessions they are already signed into are two different actions, and only one of them takes effect today.

Here is the difference, in Microsoft's own terms:

ActionWhat it doesHow fast
Reset passwordInvalidates the credentials they know. Microsoft names this as the first step to preventing unauthorized access.Immediate
Sign out of all sessionsInvalidates the access tokens keeping them signed in right now.Within an hour, or as soon as they leave the page they are on
Block sign-inStops the account being used at all, permanently, until you unblock it.Microsoft documents this as taking up to 24 hours to take effect

That last row is why order matters. An account blocked at 9am on someone's last day can still be a signed-in Outlook on the web tab at 4pm. Do all three, in this order.

Nothing in this section deletes data. Every action here is reversible: you can send the person the new password, and you can unblock the account by clearing the same checkbox.

  1. Sign in to the Microsoft 365 Admin Center and go to Users > Active users.
  2. Select the person's name, then select Reset password. Choose whether to auto-generate the password and whether to require a change at next sign-in, then select Reset password and Close. The panel offers to print the new password before you close it.
  3. Select the person's name again. On the Account tab, select Sign out of all sessions. A confirmation appears; from here their existing sessions expire rather than continuing.
  4. Select the person's name once more and select Block sign-in. On the Block sign-in page, select Block this user from signing in, then Save changes. The user's card now shows sign-in as blocked.

If they used Outlook on the web, the mailbox does not always close the instant you sign them out. As soon as they select a different tile such as OneDrive, or refresh the browser, the service signs them out.

To close the mailbox off completely, go to the Exchange admin center and select Recipients > Mailboxes, select the mailbox, and under Email apps & mobile devices select Manage email apps settings. Turn Off every option: Outlook desktop (MAPI), Exchange web services, Mobile (Exchange ActiveSync), IMAP, POP3 and Outlook on the web. Select Save. Turning these back on restores access; no mail is removed.

3. Wipe or Retire Their Device

A wipe and a retire remove different things, and choosing a wipe on a phone the person owns personally erases their family photos alongside your company data.

ActionWhat it removesUse it for
WipeFactory-resets the device. Microsoft's wording: it removes all personal and organizational data, apps, and configurations.A laptop or phone the company owns and is taking back or reissuing
RetireRemoves company data without a full wipe or factory reset. It unenrolls the device from Intune and removes managed apps, settings and profiles pushed by your policies, while preserving personal data.A device the employee owns personally

Microsoft names Retire as the action for personally owned devices. A wipe cannot be undone. On a phone the employee bought themselves, a wipe destroys their photos, personal apps and personal accounts with no way to restore them, and no business reason requires it — their work data is what Retire takes.

  1. Sign in to the Microsoft Intune admin center and select Devices > All devices.
  2. Select the device from the list.
  3. At the top of the device overview pane, find the row of action icons and select Wipe or Retire. For Retire, confirm by selecting Yes.
  4. Check the device's status in the list afterwards. Retire runs the next time the device checks in with Intune, so it can keep appearing in the admin center for a while.

On a Windows laptop, retire with care. Once the Retire command runs on a device that is Microsoft Entra joined, nobody can sign in to it with a work account any more. Back up the BitLocker recovery key and any local administrator credentials before you send the command, or the machine becomes an expensive brick on a shelf.

No Intune on your plan? You can still clear company mail off a phone. In the Exchange admin center, go to Recipients > Mailboxes, select the user, and under Email apps & mobile devices select Manage mobile devices. On the Mobile Device Details page, select the device, choose Account Only Remote Wipe Device, then select Block access and save. This removes the mailbox from the phone and stops it reconnecting; it leaves the rest of the phone alone.

4. Choose What Happens to the Mailbox

You have two ways to keep a departing person's email address working, they keep different things, and they cost different amounts.

OptionWhat it keepsLicense costThe catch
Manage email forwardingOnly new mail sent to the address reaches the colleague taking over. The old mail stays where it is.The account keeps its licenseThe account has to stay — it anchors the forwarding
Convert to shared mailboxAll existing email and calendar, in a mailbox several people can openFree while the mailbox stays under 50 GB; above that, assign a licenseThe mailbox needs a license at the moment you convert, or the option does not appear. Remove it afterwards
Delete the account outrightNothing long-term. Email, contacts and calendar are kept for 30 days, then deleted permanentlyLicense is freed immediatelyBreaks both options above; 30 days is the whole window

The quiet trap in converting: Microsoft states plainly that if you do not reset the account password, the original username and password keep working on the shared mailbox after the conversion finishes. Section 2 is what closes that door. Do it first, and this stops being a problem.

To convert the mailbox:

  1. In the Microsoft 365 admin center, go to Users > Active users.
  2. Select the user. On the Mail tab, select Convert to shared mailbox, then select Convert.
  3. If the mailbox is under 50 GB, remove the license from the user afterwards to stop paying for it. Do not delete the user account — the shared mailbox needs it as an anchor.

To forward the mail instead:

  1. In the Microsoft 365 admin center, go to Users > Active users.
  2. Select the person's name, then select the Mail tab.
  3. Under Email Forwarding, select Manage email forwarding.
  4. Select Forward all emails sent to this mailbox. In the Forwarding email address box, type the address of the colleague taking over, and choose whether to keep a copy in the original mailbox.
  5. Select Save changes. Do not delete the account afterwards.

Neither option works on a mailbox that is inactive for compliance reasons — a litigation hold, for example. If the commands are missing or refuse to save, that is usually why.

Also cancel any meetings the person organized. Rooms and equipment they booked stay unavailable until those meetings are cancelled.

5. Remove Their MFA Methods

Until you clear the authentication methods registered to the account, the phone in a departed employee's pocket can still approve a sign-in prompt for your organization.

  1. Sign in to the Microsoft Entra admin center with at least the Authentication Administrator role.
  2. Go to Entra ID > Users and select the person.
  3. Select Authentication methods. The registered methods are listed — phone numbers, Microsoft Authenticator registrations, and any hardware or software tokens.
  4. At the top of the window, select Require re-register MFA. This deactivates the user's hardware OATH tokens and deletes their phone numbers, Microsoft Authenticator apps and software OATH tokens. If the account is ever used again, the person is asked to set up a new method at next sign-in — nothing in the mailbox or in OneDrive changes, so running this on the wrong account costs that person one re-registration and nothing else.
  5. While you are on the same page, select Revoke sessions. This invalidates the account's refresh tokens and forces reauthentication across active sessions and applications — the same job as step 3 of section 2, from the identity side.

6. Check the Mailbox for Forwarding Rules

The forwarding switch on the user's Mail tab is not the only one in the building — a rule the person created inside their own mailbox keeps sending mail out after the account is blocked, and nothing on the user card shows it.

This is the step that gets skipped, and it is the one that leaks. Inbox rules are preserved when a mailbox is converted to a shared mailbox, so a rule set up months ago quietly survives every other step in this article.

  1. In the Microsoft 365 admin center, go to Users > Active users, select the person, and open the Mail tab. Under Email Forwarding, select Manage email forwarding and confirm it is off, or that it points where you intended. This covers admin-configured forwarding only.
  2. To see rules the user made themselves, give yourself access to the mailbox. In the Exchange admin center, go to Recipients > Mailboxes and select the mailbox. In the Delegation section, add your own account under Read and manage (Full Access).
  3. Open the mailbox in Outlook on the web, go to Settings > Mail > Rules, and read every rule. Delete any rule that forwards or redirects mail to an address outside your organization. Deleting a rule stops the copying; every message already in the mailbox stays exactly where it is.
  4. Remove your own Read and manage (Full Access) delegation afterwards if you no longer need the mailbox open.

7. Remove the License Before Deleting the Account

Removing the license stops the monthly charge, and doing it before you delete the account is what keeps your options open.

  1. In the Microsoft 365 admin center, go to Users > Active users and select the person's row.
  2. In the right pane, select Licenses and Apps.
  3. Expand the Licenses section, clear the boxes for the licenses you are taking back, then select Save changes. The license returns to your pool for someone else immediately.

Removing a license is not the same as deleting the account, and the two lose different things:

  • Removing the license holds the Exchange Online data for 30 days, after which it is deleted and cannot be recovered.
  • Files in OneDrive are not deleted by removing a license — only by deleting the user.
  • Once the license is gone, the mailbox stops being searchable with eDiscovery tools.
  • If they still have Office apps installed, those apps start showing "Unlicensed Product" errors.

Convert to a shared mailbox before you remove the license, not after. The convert option only appears while a license is assigned, and putting one back to convert costs you a month.

Delete the account last, and only if you are not using it as an anchor:

  1. Go to Users > Active users and select the person.
  2. In the flyout panel, select the Delete user icon at the top.
  3. In the wizard, choose whether to give another user access to their OneDrive and their email before the account goes.
  4. Select Delete user. The content in their OneDrive and Outlook is retained for 30 days. Restore the account inside that window and you get the content back — and once restored, the OneDrive content stays accessible to you past the 30 days.

If you set up forwarding or converted the mailbox in section 4, stop here and leave the account in place. Deleting it breaks both.

Troubleshooting

WARNING

If you delete a user but forget to clear their assigned license during the deletion wizard, Microsoft continues to charge your card for that spare license every month until you cancel it in the Billing section.

Symptom / ErrorPotential CauseSolution
I don't see the "Users" tabLack of admin rightsYou are signed in with a standard user account. Sign in with an account that holds Global Administrator or User Administrator rights.
New user can't log inPassword typo or replication delayIt can take up to 15 minutes for a new account to become active. Check you sent the correct temporary password.
Blocked the account, but they are still reading mailBlocking takes up to 24 hoursReset their password and use Sign out of all sessions on the Account tab. See section 2 — that pair is what ends access today.
"Convert to shared mailbox" is missing from the Mail tabThe license was removed firstReassign a license to the account, convert the mailbox, then remove the license again.
Mail is still arriving at somebody's personal addressAn inbox rule the user createdAdmin-side forwarding is not the only route. Work through section 6 and delete the rule inside the mailbox itself.
Forwarding and shared-mailbox options refuse to saveThe mailbox is on holdA mailbox held for compliance reasons accepts neither. Check Litigation hold in the Exchange admin center under the mailbox's Others section.
Retired a Windows laptop and now nobody can sign inEntra join was removed with itStart the PC in Safe mode and sign in with a local administrator account to reach the data. If you have no local account and no BitLocker key, open a support request in the admin center under Support > New service request with the text: Microsoft Entra joined device retired via Intune, no local administrator account, need recovery options for user data.

Last updated:

Frequently asked questions

Do I have to pay for a new license when I add a user?
Yes, unless you have an unassigned license sitting in your account. The wizard prompts you to purchase a new license if you don't have a spare.
Does blocking sign-in kick a departing employee out straight away?
No. Microsoft documents that blocking an account can take up to 24 hours to take effect. To end access the same day, reset the person's password and then use Sign out of all sessions on the Account tab, which invalidates their tokens. They are prompted to sign in again within an hour, or as soon as they leave the page they are on.
What happens to a user's OneDrive files when I delete them?
After you delete the account, the content in their OneDrive and Outlook is retained for 30 days. During that window you can restore the account and get to the content. If you restore the account, their OneDrive content stays accessible to you even after the 30 days.
Does a shared mailbox need a paid license?
Not while it stays under 50 GB. Above 50 GB you have to assign a license to it. The mailbox does need a license assigned at the moment you convert it, or the convert option does not appear, and you can remove that license afterwards.