An Employee Leaves Tomorrow: Who Still Has Access to Your Data?0%
    Back to blog
    Security·8 Sep 2026

    An Employee Leaves Tomorrow: Who Still Has Access to Your Data?

    By Helion Cloud Team

    Removing the licence does not cut off access. A badly closed departure leaves doors open for months.

    Share

    In most companies, an employee's departure triggers a well-drilled checklist on the HR side and a much vaguer one on the IT side. The account is disabled, the laptop comes back, and the matter is considered closed. It is not always closed, and the gap between the two is measured in months of residual access.

    01

    The departure is not the risk, the oversight is

    Nobody leaves intending to do harm, and that is not what this is about. The real risk is elsewhere: an access that stays active is an access nobody is watching. It appears on no dashboard, triggers no alert, and if that credential is one day compromised somewhere else, it becomes a way into your systems under the name of a person you can no longer reach.
    02

    What stays open when you only disable the account

    Disabling an account is not enough, because an account is not the only entry point. What often stays active: sessions already open on a personal phone or browser, membership of shared mailboxes and chat groups, the external sharing links that person created on documents, and the third-party applications they had connected to their work account. Every one of those survives the disabling.
    03

    The two things to do the same day

    There are two, and the order matters little as long as both are done. The first is to block sign-in for the account. The second, the one almost always forgotten, is to revoke all active sessions. Without that second action, a session already open on a personal device can keep working for a while, because the device does not need to sign in again to carry on reading mail. Microsoft in fact documents both operations as the very first step when an employee leaves, before anything else.
    04

    And the person's data?

    This is the part that gets expensive when handled too late. Before releasing the licence, you need to decide what happens to the mailbox and the work files: hand them to a manager, convert the mailbox to a shared one, or archive them. Once the account is deleted a countdown starts, and at the end of it the content is no longer recoverable. The order to remember is therefore simple: cut access first, recover data second, release the licence last.
    05

    Write the procedure once, apply it every time

    Good practice is not to memorise everything but to write the list down once, with the name of the person responsible for each line and the expected timeframe. That list fits on one page. It should be triggered by HR, not by IT, because HR know the leaving date first. That trigger, more than the list itself, is what separates a written procedure from an applied one.

    Summary

    A departure closed properly takes about fifteen minutes on the right day, and becomes a painful piece of work six months later, when nobody remembers what the person had access to. If you cannot say today how many inactive accounts still exist in your tenant, that is the first thing to look at. Helion Cloud can produce that picture and leave you a leaver procedure ready to apply.

    Need support

    Our team of experts based in Lille supports companies across France, Belgium and Europe. Available Monday to Friday.