Account and record
Disable the account and retain the related ticket number and reason when those fields are available to the operator.
Platform capabilities
Manage Microsoft cloud services, Windows devices, security, documentation, backup, and support from one self-hosted platform.
Microsoft 365 identity lifecycle
Use an ordered checklist to block access, preserve business data, hand off the mailbox, remove permissions and licenses at the right time, and record what happened for each customer.
For MSP technicians and Microsoft 365 administrators. Confirm customer retention, legal, licensing, HR, and hybrid-identity requirements before destructive changes.
Direct answer
Microsoft 365 user offboarding is the controlled process of ending a departing user’s access while preserving the business data, communication paths, and records the customer still needs. A reliable process identifies the authoritative account, records approvals and current access, blocks sign-in, revokes supported sessions, handles devices and mailbox access, preserves OneDrive and retention requirements, removes permissions and licenses in the correct order, and verifies every result.
Ordered checklist
The exact order can change for an urgent termination, a planned departure, or a legal hold. The sequence below keeps immediate access containment separate from data-preservation and deletion decisions.
Record the customer, user principal name, departure time, approver, manager or data owner, urgency, ticket, and whether the identity is cloud-only, synchronized, or federated.
Record roles, group membership, licenses, mailbox delegation, forwarding, devices, applications, and business-owned data before removing access that may be difficult to reconstruct.
Disable the account, reset credentials, and revoke supported sessions. For hybrid identities, apply the change at the authoritative source and verify synchronization.
Disable supported user-device access and complete any separate MDM or physical-asset process. Do not treat a directory device action as proof that every endpoint was wiped or recovered.
Apply the customer’s retention decision, convert or delegate the mailbox when required, configure forwarding or out-of-office separately, and grant successor access to OneDrive through the appropriate Microsoft workflow.
After preservation and ownership decisions are complete, remove group memberships, supported sharing links, and licenses. Verify downstream applications and unsupported services separately.
Confirm sign-in state, task results, mailbox and OneDrive access, group and license state, ticket notes, exceptions, owners, and follow-up dates before scheduling deletion under customer policy.
Verified MSPControl scope
MSPControl’s extended Disable User workflow groups common containment and cleanup options around the selected organization user. Choose only the actions approved for that customer, then review the task result and resulting Microsoft state.
Disable the account and retain the related ticket number and reason when those fields are available to the operator.
Reset the password and revoke supported Microsoft sign-in and RDS sessions when selected.
Disable supported user devices and remove supported rules without claiming universal endpoint wipe or application cleanup.
Remove all group memberships and hide the user from supported address lists when those actions are selected.
Remove supported OneDrive sharing links and licenses after the data-preservation and ownership decisions are complete.
Keep the disable operation in the object audit log and review task errors instead of assuming every requested change succeeded.
Current boundary: this is an extended user-disable workflow, not a single wizard for every offboarding responsibility. Mailbox conversion, forwarding, out-of-office settings, and delegation are separate MSPControl actions. OneDrive ownership transfer, legal hold and retention decisions, unsupported SaaS access, physical asset recovery, and final deletion remain separate administrative work.
Action ownership
A useful checklist says where the work happens. This table prevents a selected Disable User action from being mistaken for complete mailbox, OneDrive, retention, or endpoint offboarding.
| Offboarding action | Operating surface | What to verify |
|---|---|---|
| Disable the account; record ticket and reason | Disable User | Correct customer and identity, final disabled state, task result, and audit entry. |
| Reset password; revoke supported sessions | Disable User | Microsoft-side result and any application sessions that follow their own token or cookie lifecycle. |
| Remove groups, rules, supported device access, sharing links, and licenses | Disable User | Preservation completed first, selected options, business errors, and final service state. |
| Convert mailbox; set forwarding or out-of-office; grant delegation | Separate MSPControl action | Mailbox type, target recipient, delivery behavior, delegate permissions, retention, and licensing. |
| Schedule a future account deactivation | Separate MSPControl action | The scheduled date and account state. This path does not schedule the full cleanup option set. |
| Transfer OneDrive ownership or grant successor access | Microsoft/admin workflow | New owner or delegate, data availability, links, retention, and deletion timing. |
| Apply legal hold, retention, backup, and final deletion policy | Customer policy | Approval, licensing, jurisdiction, retention period, data recovery, and documented deletion date. |
| Recover assets and remove unsupported application access | Manual/other systems | Physical device custody, local accounts, application ownership, tokens, keys, and vendor-specific access. |
Automation with guardrails
The current source includes an access-controlled automation request for disabling a user. It can carry the supported disable options and follow the configured approval policy, including auto-approval where the organization permits it.
Pass the organization, account, ticket, reason, and supported disable options instead of relying on an unstructured departure message.
Process the request through the configured approval behavior. Availability depends on the deployed build, integration access, and organization settings.
Inspect task errors and the resulting Microsoft state. Automation does not make retention, ownership, deletion, or unsupported-application decisions for the customer.
Common questions
Confirm the authorized request and exact identity, record the current access that may need to be preserved, then block sign-in promptly. For an urgent termination, containment can take priority, but group, role, license, mailbox, OneDrive, retention, and ownership decisions still need to be recorded and verified.
Not automatically. Decide how mailbox and OneDrive data will be retained or handed off, confirm legal and customer-policy requirements, and understand the service impact before removing licenses. Verify data access after the change.
No guarantee should be made. Microsoft Entra can revoke supported refresh sessions, while applications can issue their own session cookies or tokens. Effective access loss depends on token lifetime, application behavior, and synchronization, so verify the important applications separately.
The verified Disable User option removes supported OneDrive sharing links; it does not transfer ownership or grant successor access. Complete OneDrive handoff and preservation through the appropriate Microsoft administrative workflow.
Mailbox type conversion is available as a separate Exchange Online mailbox action when supported. Forwarding, out-of-office behavior, and mailbox delegation are also separate actions rather than part of the single Disable User transaction.
MSPControl can schedule a future account-state deactivation. The verified scheduling path disables the account but does not automatically schedule the complete selectable cleanup set, so plan and verify the remaining steps separately.
The current source supports an access-controlled disable-user request with supported options and configured approval behavior. This can automate part of the process, but it is not evidence of a universal HR-to-Microsoft 365 workflow or automatic completion of mailbox handoff, OneDrive transfer, retention, assets, and every SaaS application.
Continue the workflow
Open the MSPControl or Microsoft guidance that owns the next step, then verify permissions, licensing, hybrid identity, retention, and the resulting tenant state.
Self-hosted. Free license available. No credit card required.