
Deleting a former employee’s cloud account too soon can erase mail, files, calendars, and customer history; leaving it active can leave a door open to the business. The safe answer is not “delete immediately” or “keep paying forever.” It is a controlled sequence: stop access, preserve business records, redirect future work, verify the handoff, and only then remove the account or license.
This guide focuses on the part that a short offboarding checklist cannot fully cover: preserving and transferring company data in Microsoft 365 or Google Workspace without accidentally extending the former employee’s access.
The costly problem: security and data loss happen in opposite directions
A rushed departure creates two competing risks:
- Security risk: an old account, mobile session, VPN credential, app password, or delegated connection may still work after the person leaves.
- Continuity risk: deleting the account can remove access to email conversations, customer files, scheduled meetings, cloud documents, or a mailbox address customers still use.
CISA documented a real incident in which a threat actor used a former employee’s account with administrative privileges to enter an organization through its VPN. The account had not been disabled immediately after departure. That is why access should be blocked promptly—even when the departure is friendly—while data preservation is handled as a separate, deliberate task.
Who is affected—and who is not?
This guide applies if your business uses:
- Microsoft 365 business email, Exchange Online, OneDrive, SharePoint, Teams, or Entra ID accounts;
- Google Workspace Gmail, Drive, Calendar, or managed Google accounts;
- a custom business domain where customers keep emailing a departing employee’s address;
- shared projects or records that only one user owns;
- remote staff, company phones, personally owned devices with work data, or third-party applications connected to the work account.
This guide is not enough by itself if:
- you use on-premises Active Directory or a hybrid identity system that synchronizes users to the cloud;
- the account is under a legal hold, litigation hold, investigation, records-retention rule, or regulated-industry requirement;
- the employee used accounting, payroll, banking, domain registrar, VPN, line-of-business, or social-media accounts outside Microsoft 365 or Google Workspace;
- there is evidence of account compromise, intentional data removal, or unauthorized forwarding.
In those cases, coordinate with your IT provider, HR, legal counsel, and any relevant compliance owner before deleting data. Do not use this article as permission to erase records that must be retained.
The safe order of operations
1. Open a written offboarding record
Record the user’s name, role, manager, last work time, devices, cloud account, groups, shared mailboxes, delegated access, important applications, and who will receive the data. Include separate decisions for:
- old email and calendar;
- new messages sent to the old address;
- OneDrive or Google Drive files;
- team-owned content in SharePoint, Teams, shared drives, or shared folders;
- scheduled meetings, room reservations, and recurring appointments;
- mobile devices, authenticator methods, security keys, and app passwords;
- legal or business retention.
Assign a named owner for every transfer. “The manager can find it later” is not a preservation plan.
2. Block access before you reorganize data
At the agreed departure time, block sign-in and revoke active sessions. Remove administrative roles and high-risk group memberships. Revoke or remove authentication methods, security keys, app passwords, recovery methods, and managed-device access as appropriate. Disable VPN, remote desktop, password-vault, accounting, payroll, support-desk, website, registrar, and other non-cloud accounts separately.
Important: changing only the password is not a complete offboarding action. Existing sessions, application tokens, delegated connections, and other services may remain usable. Do not sign in as the employee or give their password to a replacement worker; use administrative delegation and transfer features instead.
3. Decide what must remain reachable
Separate historical content from future communication:
- Historical content includes existing mail, calendars, OneDrive/Drive files, contacts, and project records.
- Future communication includes new mail to the old address, recurring meetings, customer replies, and ownership of ongoing work.
Forwarding solves only future mail. It does not automatically give a manager access to old messages. Likewise, transferring files does not preserve every service or account relationship. Make each decision explicitly.
Microsoft 365: preserve mail and OneDrive safely
Microsoft publishes a seven-step former-employee workflow: block access, save mailbox contents, handle mobile devices, redirect or convert email, give another employee access to OneDrive and Outlook data, remove the license, and delete the account. The exact controls available depend on your licenses, roles, retention settings, and whether your identity is cloud-only or synchronized from on-premises Active Directory.
A practical Microsoft 365 sequence
- Block sign-in and revoke sessions. Confirm the user can no longer authenticate. If the account is synchronized from local Active Directory, make the authoritative change there rather than assuming the cloud-only control is sufficient.
- Remove privileged access. Remove admin roles, VPN access, and unnecessary group memberships. Review app registrations, mailbox delegates, forwarding rules, and other persistent access paths.
- Preserve the mailbox. If several people need the existing mail and calendar, converting the mailbox to a shared mailbox is often cleaner than giving one replacement worker the old identity.
- Choose forwarding only when it fits. Microsoft notes that forwarding sends new messages; it does not provide the old mailbox history. Keep a copy in the former mailbox only if your retention and handoff plan calls for it.
- Transfer OneDrive responsibility. Grant an appropriate employee access, then move the business files that must remain into a durable team-owned location such as the correct SharePoint site or Teams-connected library. Do not leave the company’s only copy buried in a former user’s personal OneDrive.
- Cancel or re-create meetings. Recurring meetings and room reservations owned by the former employee can continue causing confusion or block resources.
- Test the handoff. The successor should open required mail, files, and calendars using their own account. Send a test message to the old address and confirm it follows the approved route.
- Remove the license or account only after verification. Microsoft warns that retention behavior changes when licenses or accounts are removed. Its current guidance says mailbox data is retained for 30 days after license removal and that deleted users’ OneDrive and Outlook content can be restored during a 30-day window. Treat those periods as emergency recovery windows—not as your migration plan.
Shared mailbox or forwarding?
Phone readers: swipe the comparison table left to see every column.
| Option | Good points | Bad points / cautions |
|---|---|---|
| Convert to a shared mailbox | Retains existing mail and calendar; supports access by multiple authorized users; Microsoft says a license is generally not required while the shared mailbox is under 50 GB. | Requires correct permissions and ongoing ownership; larger mailboxes or certain features may require a license; do not delete the underlying account while it is needed to anchor the shared mailbox. |
| Forward new mail | Simple way to route new customer messages to a successor. | Does not provide old mail; can hide where messages are going; must be documented and reviewed; Microsoft says not to delete the former account while it is needed to anchor forwarding. |
| Export to a PST | Can create a point-in-time copy for a defined business or legal purpose. | Easy to lose, duplicate, or expose; hard to search collaboratively; not a substitute for a documented retention system. |
Google Workspace: transfer before deletion
Google’s administrator guidance is direct: if you need to keep Gmail messages or Drive files in the organization, transfer the data to another user. Google says untransferred data is deleted with the user, although some data can be recovered by restoring the user within 20 days. Again, that recovery window is not a substitute for a verified transfer.
A practical Google Workspace sequence
- Suspend the account or otherwise stop access. Reset sign-in, revoke sessions, security keys, app passwords, and recovery access according to your edition and policy.
- Remove elevated roles and third-party access. Check administrator roles, groups, OAuth-connected apps, delegated Gmail access, mobile devices, and any external systems that use the Google identity.
- Choose a destination owner. Use an active managed user with enough storage and a clear business role. Avoid transferring everything to an owner’s personal account.
- Transfer Gmail and Drive data. During the deletion workflow, super administrators can select supported data to transfer. Google warns that private or oddly nested Drive content can become difficult to browse if ownership and folder structure are not handled carefully; verify the recipient can find the transferred material.
- Move long-lived team files to shared drives when appropriate. Shared drives are owned by the organization rather than one user, which reduces the same problem at the next departure. Confirm your Workspace edition and sharing policy support the design you intend.
- Handle the old email address. Decide whether it becomes an alias, group address, delegated mailbox workflow, or other documented route. Test inbound and outbound behavior without sharing the former employee’s credentials.
- Verify before deletion. Open representative messages and files, search for private files, check calendars and recurring events, and confirm the successor has access using their own account.
- Delete, archive, or retain according to policy. Google offers suspension and, on eligible subscriptions, archived-user options. Choose based on legal, operational, and licensing needs rather than convenience.
A real-world example
A five-person contractor has an estimator leave. Customers still email [email protected], the employee owns proposal files, and recurring site meetings are on their calendar.
- Bad approach: delete the account immediately, then discover that proposals and calendar details are missing; or leave the account active for months so someone can “check it when needed.”
- Better approach: block access at departure time, revoke sessions, remove privileged roles, preserve the mailbox or transfer Gmail, move proposal files into a team-owned library/shared drive, route the old address to the new estimator, reassign meetings, test with the new estimator’s account, document the result, and then remove the license or account under the company’s retention policy.
Verification checklist before you click Delete
- The former employee cannot sign in, and active sessions have been revoked.
- Administrative roles, VPN access, security keys, app passwords, mobile access, and third-party accounts were reviewed.
- A named owner can open required old mail, files, and calendars using their own account.
- New mail to the old address reaches the approved destination.
- Important files are in a durable team-owned location, not only a former user’s personal cloud drive.
- Recurring meetings and resource bookings have been canceled, transferred, or re-created.
- Legal hold, retention, HR, and privacy requirements were checked.
- The transfer was documented with date, administrator, destination owner, exceptions, and test results.
- A follow-up review is scheduled to remove temporary forwarding, delegates, or access that is no longer needed.
Frequently asked questions
Can I just change the password?
No. A password change alone may not revoke every active session, application token, security key, app password, VPN credential, or third-party connection. Use the platform’s access-blocking and session-revocation controls, then audit connected services.
Should I log in as the former employee to retrieve files?
Usually no. Use administrative access, delegation, transfer, retention, and eDiscovery features. Sharing or resetting the old password for routine access weakens accountability and can create privacy or legal problems.
Does email forwarding preserve old messages?
No. Forwarding normally handles new incoming mail. Historical mail needs a separate mailbox-access, conversion, transfer, export, or retention decision.
Can I remove the Microsoft 365 license immediately?
Do not do it blindly. Microsoft’s current guidance describes 30-day retention behavior for mailbox data after license removal and for deleted users’ OneDrive and Outlook content, but configuration and compliance settings matter. Preserve and test the handoff first.
How long can Google restore a deleted user?
Google’s current administrator guidance says a deleted user can be restored within 20 days. Untransferred data can become unrecoverable. Transfer and verify business data before deletion rather than relying on restoration.
What if the employee used a personal Google or Microsoft account?
That is a different and often harder problem. A business administrator may not control a personal account. Preserve company records through authorized business systems, ownership transfers, contracts, and HR/legal procedures. Do not attempt to access a personal account without authorization.
Related guidance from The IT Guys
- Make a same-day employee offboarding checklist for the wider device, password, vendor, and access inventory.
- Review The IT Guys small-business IT services if you need help designing repeatable account and data handoffs.
Official sources
- Microsoft Learn: Remove a former employee and secure data
- Microsoft Learn: Forward email or convert to a shared mailbox
- Microsoft Learn: Give another employee access to OneDrive and Outlook data
- Google Workspace Admin Help: Delete or remove a user
- Google Workspace Admin Help: Maintain data security after an employee leaves
- CISA: Threat actor leveraged a former employee account
Your next step
Before the next departure, create a one-page account-and-data map showing who owns email, cloud files, shared applications, domains, VPN access, and recovery methods. If someone has already left and you are unsure what can be safely disabled or deleted, stop making destructive changes and schedule an IT review. The cheapest recovery is the transfer you verify before the deletion.
