Appearance
Understanding What to Do When You Leave or Change Jobs — IT Offboarding Checklist
Applies to: Windows 10, Windows 11, Microsoft 365
Article Type: Informational
Last Updated: 2026-06-18
Summary
When you leave a job, your Microsoft 365 account is disabled — often within hours of your departure. This article is your checklist for everything you need to handle yourself before your last day, organised in priority order. It also explains what IT handles so you know what is (and is not) your responsibility.
Prerequisites
- An active Microsoft 365 work or school account. These steps must be completed before your account is disabled. Once IT deactivates your account, you lose access to OneDrive, Outlook, Teams, and all Microsoft 365 services.
- Access to a personal email address or personal device for saving files and transferring account recovery methods.
Instructions
1. Save Personal Files from OneDrive and Desktop
Download anything personal before your account is disabled.
When your Microsoft 365 account is deactivated, you lose access to your OneDrive — including your Desktop, Documents, and Pictures folders if OneDrive folder backup was enabled. Any personal files stored there will be inaccessible.
What you can take:
- Personal files you created or saved for your own reference (notes, templates you built, training materials).
- Files that are unmistakably personal (photos, personal documents accidentally saved to your work OneDrive).
What belongs to the company:
- Work deliverables, client files, shared project documents, and anything created as part of your job duties.
- Check your company's acceptable use policy if you are unsure.
How to save your files:
- Open your browser and go to onedrive.com. Sign in with your work account.
- Navigate to the folders containing personal files.
- Select the files or folders you want to keep.
- Click Download. OneDrive packages them into a ZIP file.
- Save the ZIP file to a personal USB drive, personal cloud storage (personal OneDrive, Google Drive), or your personal computer.
- Check your local Desktop and Documents folders. If OneDrive folder backup is enabled, these folders sync to the cloud — when your account is disabled, those files disappear from your local computer too.
- Copy any personal files from these folders to a personal storage location now.
For more on where your files live, see Understanding Where Your Files Live — OneDrive vs. SharePoint vs. Teams. For backup guidance, see How to Back Up Files and Folders on Windows.
2. Export Your Outlook Contacts
Save your professional contacts before you lose access to your mailbox.
From Classic Outlook (desktop app):
- Open Outlook and go to File > Open & Export > Import/Export.
- Select Export to a file and click Next.
- Select Comma Separated Values and click Next.
- Select Contacts and click Next.
- Choose a save location (your personal USB drive or personal cloud folder) and click Finish.
From Outlook on the web:
- Go to outlook.office.com and sign in.
- Click the People icon (bottom-left).
- Click Manage contacts > Export contacts.
- Select All contacts and click Export.
- Save the CSV file to a personal storage location.
The CSV file contains names, email addresses, phone numbers, and companies. You can import it into your personal email, a new employer's Outlook, or Google Contacts.
3. Transfer MFA and Recovery Methods to Personal Accounts
Make sure your personal accounts are not tied to your work phone number or work email.
This is one of the most overlooked steps. If you used your work email or work phone number as a recovery method for personal accounts (banking, social media, personal email), update them now.
- Check your personal accounts — go to the security or account recovery settings for your personal email (Gmail, Outlook.com), banking, and social media accounts.
- If any recovery email is set to your work email address, change it to a personal email address.
- If any recovery phone is set to a company-issued phone number you are returning, change it to your personal mobile number.
- Microsoft Authenticator app — if you use the Authenticator app for both work and personal accounts, your personal accounts are safe. They stay in the app even after your work account is removed. You do not need to do anything with them.
- Do not remove your work account from Authenticator yet — wait until after your last day. IT will disable it on their end. Removing it early could lock you out of work systems you still need.
For a full guide on moving your MFA, see How to Transfer MFA to a New Phone (Microsoft 365).
4. Forward Important Emails to Your Personal Address
Preserve key information before your mailbox becomes inaccessible.
Once your account is deactivated, you lose access to every email in your inbox — including receipts, confirmations, and reference material.
- Open Outlook (desktop or web).
- Search for emails you want to keep: training certificates, expense approvals, personal correspondence, and professional references.
- Select the emails and click Forward. Send them to your personal email address.
- Do not forward confidential company information — this includes client data, proprietary documents, internal reports, and trade secrets. Forwarding confidential material to a personal account is a policy violation at most organisations and may have legal consequences.
- Focus on items that are genuinely personal or that you may need for tax, legal, or professional reference purposes.
5. Remove Personal Accounts from Work Devices
Sign out of personal services on your work computer before returning it.
Your work computer may have personal accounts signed in — web browsers, cloud storage, social media, and personal email. Remove them before you hand the device back.
- Browser saved passwords — open your browser's password manager and delete any saved passwords for personal accounts (banking, personal email, shopping). See How to Manage Saved Passwords in Your Browser.
- Personal Google or Microsoft account — sign out of any personal Google, Microsoft, or Apple accounts in your browser. Go to myaccount.google.com or account.microsoft.com and click Sign out or remove the browser profile.
- Personal OneDrive — if you connected a personal OneDrive account, right-click the OneDrive icon in the system tray > Settings > Account > Unlink this PC.
- Social media and personal apps — sign out of any personal social media accounts, messaging apps, or personal software signed in on the work device.
- Clear browser browsing history — go to your browser's settings and clear browsing data. See How to Clear Browser Cache and Cookies.
6. Remove Work Accounts from Personal Devices
Disconnect your work identity from your personal phone, tablet, or computer.
- Outlook mobile — open the Outlook app on your personal phone > go to your profile > tap the work account > tap Delete Account. This removes only the work account — personal accounts in the same app are unaffected.
- Teams mobile — open Teams > tap your profile > tap Sign out. If prompted, choose to remove the work account.
- Microsoft Authenticator — after your last day, open the Authenticator app, tap the work account, and tap Remove account. The entry will stop working once IT disables your account, but it remains visible until you remove it manually.
- Company Portal / Intune — if your personal device was enrolled in your company's device management (Intune/Company Portal), unenroll it to remove the company's management policies from your device:
- Open the Company Portal app > go to Devices > select your personal device > tap Remove.
- For details, see Understanding Company Portal, Device Management, and Your Privacy.
7. Sign Out of Browser Profiles and Clear Work Data
Remove work browser profiles from personal computers.
If you used a work browser profile on a personal computer (e.g., signed into Edge with your work account or created a Chrome profile for work), that profile may contain saved passwords, autofill data, bookmarks, and browsing history.
Microsoft Edge:
- Click your profile icon in the top-left corner of Edge.
- Click the gear icon (Manage profile settings).
- Find the work profile and click Remove (or the X next to it).
- Confirm removal. This deletes all data associated with that profile.
Google Chrome:
- Click your profile icon in the top-right corner of Chrome.
- Click the gear icon to open profile management.
- Find the work profile, click the three dots, and select Delete.
- Confirm removal.
For more on browser profiles, see How to Set Up Multiple Browser Profiles.
8. What IT Handles — Not Your Responsibility
These tasks are managed by your IT department. You do not need to do any of them yourself.
- Account deactivation — IT disables your Microsoft 365 account, which blocks sign-in and access to all M365 services (email, Teams, OneDrive, SharePoint).
- Email auto-reply or forwarding — IT can set up an automatic reply on your mailbox directing senders to a colleague, or forward incoming mail to your successor.
- Device wipe or reimaging — IT will wipe or reimage the work computer after you return it. You do not need to reset it yourself.
- Revoking access to SharePoint, Teams, and shared mailboxes — IT removes your permissions from shared resources. You do not need to "leave" Teams channels or SharePoint sites manually.
- Reassigning your Microsoft 365 license — IT reassigns the license to your replacement. This is an admin function.
- OneDrive retention — Most organisations retain your OneDrive files for 30–90 days after account deletion, assigned to your manager. If you forgot to save something, contact your former IT team — they may still be able to retrieve it.
Troubleshooting
WARNING
Complete these steps before your last day. Once IT disables your account, you lose access to OneDrive, Outlook, Teams, and all Microsoft 365 services — often within hours of your departure. There is no self-service way to recover access after deactivation.
| Symptom / Error | Potential Cause | Solution |
|---|---|---|
| Forgot to save files and account is already disabled | OneDrive inaccessible after deactivation | Contact your former IT team immediately. Most organisations retain OneDrive data for 30–90 days after account deletion. They may be able to share specific files with you. |
| OneDrive files disappeared from Desktop and Documents | OneDrive folder backup was enabled | Those files lived in the cloud, not locally. They are removed from your device when the account is disconnected. This is why Step 1 is the highest priority. |
| Authenticator still shows work account after leaving | App entry not removed | Open the Authenticator app, tap the work account, and tap Remove account. The entry will not work but remains visible until manually deleted. |
| Personal passwords were saved in the work browser | Browser profile contained personal data | If the device has been returned, change your passwords for those personal accounts from the respective websites immediately. |
| Company Portal still shows personal phone as enrolled | Device not unenrolled before leaving | Open the Company Portal app > Devices > select the device > Remove. If the app was deleted, reinstall it, sign in, and unenroll. |
| Cannot sign in to a personal account — "account locked" | Recovery method was set to work email or work phone | Contact the personal service's support team (Google, Microsoft, bank) and verify your identity to regain access. This is why Step 3 is critical to complete early. |
Related Articles
Understanding What to Do When You Get a New Computer — First-Day IT Checklist
Understanding Where Your Files Live — OneDrive vs. SharePoint vs. Teams
Understanding Company Portal, Device Management, and Your Privacy
Understanding Your Microsoft 365 Account — What You Can (and Can't) Change Yourself
Understanding Microsoft 365 Account Security — What Protects You and Why