The IT Leader's 10-Point Remote Offboarding Checklist
A blueprint for secure, scalable and frictionless hardware recovery. Ten steps across three phases, in the order they should happen.
Most offboarding checklists stop at the account. Disable the SSO, archive the mailbox, remove them from Slack, done. The access half is well covered because it happens inside systems your team already controls.
The other half leaves the building. A laptop, sometimes a monitor, a keycard, a token, and a set of licenses still being billed. Those steps depend on a person who no longer works for you doing something, which is why they are the ones that slip.
Here is the whole list, both halves.
The digital perimeter
Close the access before you think about the hardware.
Identity and access revocation
Immediately disable the user's login via your SSO. Ensure you aren't just suspending the account, but revoking all active sessions across all devices to prevent unauthorized access post-exit.
Communication archiving
Set up an auto-responder for the employee's email and delegate their inbox to their manager. Do this before the account is fully deleted to ensure no critical client or vendor threads are lost during the transition.
Shadow IT and password audit
Check for any company-related accounts the employee may have created outside of your main SSO, for example Canva, Otter.ai, or specific developer tools. Revoke access to shared folders or departmental cloud storage.
Hardware and logistics
The part that leaves your building and does not come back on its own.
Full-kit inventory audit
Cross-reference your records. Are you expecting just a laptop, or were there secondary monitors, headsets, or tablets issued? Knowing the full kit ensures you do not leave expensive peripherals behind.
The instant logistics trigger
Initiate the recovery request within 24 hours of the employee's last day. The likelihood of recovery drops significantly after 30 days; the faster the box arrives at their door, the higher your success rate.
Remote device lock
Use your MDM to lock the device. This prevents any usage while the device is in transit and ensures it remains clearly identified as company property until it reaches your hands.
Reclamation and records
The cleanup that decides whether next year’s audit is easy.
SaaS license reclamation
Unassign high-cost licenses, for example Salesforce or Adobe, so they can be immediately redeployed to new hires. This stops zombie subscription costs from eating your IT budget.
Physical security recovery
Do not forget the small items. Ensure office keycards, building fobs, or physical MFA tokens are included in your review of what may need to get returned.
Financial and expense reconciliation
Close out corporate credit cards and audit any pending home-office stipends. Confirm which items were company-owned versus stipend-owned to avoid confusion during the hardware return process.
Final inventory reconciliation
Once the device is received, update your internal records and mark the asset as recovered. Maintaining a clean audit trail helps you accurately plan your hardware refresh budget for the following year.
We handle one of these ten.
Step 5. That is the honest answer. Your MDM, your SSO and your finance team own the other nine, and no vendor should tell you otherwise.
Step 5 is also the one that consumes the most calendar time, because it is the only step that depends on someone who has already left. We send the kit, run the email and SMS follow-ups, and give you the tracking and the record at the end, so the step that used to stay open for weeks closes without your team chasing it.
Common questions
- How quickly should a device recovery request go out after someone leaves?
- Within 24 hours of the employee's last day. The likelihood of recovery drops significantly after 30 days, and the faster the return kit arrives at their door, the higher the success rate.
- What should be on a remote offboarding checklist besides the laptop?
- Identity and session revocation across all devices, inbox delegation and archiving, shadow IT and shared-folder access, the full hardware kit rather than just the laptop, an MDM lock on the device, SaaS license reclamation, keycards and physical MFA tokens, corporate cards and home-office stipends, and a final inventory reconciliation once the device is back.
- Why is disabling the account not enough?
- Suspending an account is not the same as revoking active sessions, and neither one addresses accounts created outside your SSO or the hardware itself. A device still holds local data and still represents company property until it is physically back in your possession.
- Who owns remote offboarding, IT or HR?
- Both, which is why it breaks. HR owns the exit and the employee experience, IT owns the access and the asset. The steps in the middle, particularly the hardware, are the ones that fall between the two.
Take step 5 off the list.
Across our most recent 10,000 returns, 92.5% of the devices came back. Your first return is free. Run it on a real device and see how long the step actually stays open.