forumNew topic

An employee resigned, should I close all their accounts immediately? How much should I rush?

ZZafer P***MemberCommunity member
Joined
Dec 2024
Message
411
#1

On Monday morning an employee said 'I'm resigning' and notified HR. I'm IT, I don't know how much I should rush. Should I close it in an hour a day, or over the weekend? The employee has access to all files and the customer portal. I'm thinking about who to close and who to keep.

If I close their email account, do other apps linked to the account (Slack, GitHub AWS) automatically log out? Or do I need to close them one by one? The files are on their computer, are they encrypted can someone else open them?

The employee gave 2 weeks notice so that the drama stays outside, what should be closed during this period? Or all at once when they leave? Is there a legal obligation regarding this?

HHalil T***VeteranCommunity member
Joined
Oct 2023
Message
47
Most Helpful#2

Offboarding process should be planned and step-by-step: 1) During notice period (2 weeks): someone else takes over the work, knowledge transfer, data backup, 2) Before last day (24 hours): review credit cards, company data, VPN access, 3) After last day (within hours): a) Disable email (set up forwarding beforehand), b) Disable Active Directory user (Windows login), c) Revoke VPN/SSH keys, d) Remove AWS/Cloud account access, e) Disable Slack/Teams, f) Remove GitHub collaborator, g) Revoke billing account (credit card), h) Collect physical badge/security key. If the employee is problematic (conflict, competitor): immediate termination (access closed quickly). Files: take backup of company data, transfer from employee's personal computer (encrypted rbir antivirüs ürünü), transfer database backup and all accesses to another admin. Email forwarding: can be set up for quitting day + 90 days (so important mails get forwarded). Legal: employee is required to hand over company data when leaving (KVKK compliant).

OOsman K***VeteranCommunity member
Joined
Feb 2026
Message
279
#3

close it immediately, don't wait at all. you'll close all access within an hour after the last day. disable AD, revoke VPN set up mail forwarding, take backup but if the employee is problematic it's even more urgent. btw close github/aws all one by one...

KKoray E***Expert
Job title
Software developer
Sector
Packaging
Organization type
chain store
Joined
Sep 2023
Message
25
#4

Offboarding checklist: 1) Active Directory: disable user + reset password, remove from antivirus product, 2) Email: set up forwarding rule (to manager or archive), 3) Cloud resources: delete/revoke AWS IAM user, suspend Google Workspace, disable Azure AD, 4) VPN/SSH: remove public key, revoke certificate, 5) Third-party apps: revoke Slack workspace admin, remove GitHub collaborator, 6) Physical: deactivate badge, collect laptop/phone, revoke SIM. Automation: identity management platform (Okta, Azure AD) single sign-off (disabling user automatically revokes all app access). Knowledge transfer: documentation, code repo handoff, escalation contacts.

OOzan M***New member
Job title
Music Instructor
Joined
Aug 2024
Message
34
#5

hurry up, whenever the employee leaves all access will be cut off that day (end of day)... set up email forwarding to another admin, take a file backup this is mandatory. i mean if company data stays on their device it'll be a problem, they might have copied the whole company...

JJülide S***MemberCommunity member
Joined
Nov 2025
Message
3
#6

Offboarding phases: 1) Pre-departure (notice period): knowledge transfer, asset inventory, data backup, 2) Departure day: access revocation, asset collection, device wipe 3) Post-departure: access audit, data archive, email retention (compliance). Ceremony: exit interview (departing employee survey) compliance checklist signature. Automation: SIEM log monitoring (flagging former employee activity) alerting. Audit trail: access logs retained for 6-12 months (compliance investigation).

ZZerrin S***Member
Job title
Quality Assurance Manager
Sector
Insurance
Organization type
chain store
Joined
Jun 2024
Message
388

Doki · Backup setup · 2025

#7

15 years in IT management, I've made this mistake many times. Late access revocation when an employee leaves = risk of data theft. Best practice: restrict access even during the notice period, remove access by end of the departure day, no delays whatsoever. Keep email forwarding for 1 year, then delete. Company must keep a backup of files.

LLevent A***MemberCommunity member
Joined
Oct 2024
Message
40
#8

The opposite happened to me, that's why I'm writing. Trying to do this alone is the most expensive way.

If I were you, I'd go this route.

RRamazan K***MemberCommunity member
Joined
Jan 2025
Message
33
#9

I went through the same thing two years ago. Forgotten test environments are more often the entry point than live systems.

If I were you, I'd go this route.

FFiliz Ö***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
cooperative
Joined
Jan 2026
Message
88
#10

It's rare to find an explanation this clear. When we decide without measuring, we always end up in the same place.

Correct me if I'm wrong.

OOsman K***MemberCommunity member
Joined
Mar 2024
Message
117
#11

Let me speak from the other side; I'm on the supplier side. Don't hesitate to ask; those who don't ask always pay more.

If you have questions, write them; I'll answer as best I can.

FFurkan M***Member
Job title
Product Manager
Sector
Construction
Organization type
medium-sized business
Joined
Dec 2024
Message
20
#12

this approach has a cost which isn't discussed... when you try to change everything at once, nothing settles.

trying to do this alone is the most expensive way then this is my opinion, I'm not claiming it's absolute truth.

FFurkan U***Member
Job title
Administrative manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
84
#13

You're right.

AAli A***ExpertCommunity member
Joined
Aug 2024
Message
287
#14

We need to make a distinction here. The answer varies greatly by industry; there is no one-size-fits-all rule.

Of course, it varies if your situation is different.

TTuğçe M***Member
Job title
Operations manager
Sector
Logistics
Organization type
two-branch business
Joined
Jan 2023
Message
362
#15

Exactly like that. The real issue isn't the number, but what it's based on.

Correct me if I'm wrong.

FFatma T***Member
Job title
Store associate
Sector
Energy
Organization type
8-person team
Joined
Jul 2024
Message
190
#16

I've been down this road, let me tell you. People defend habits, not processes. Resistance comes from there.

Forgotten test environments are more often the entry point than live systems. Correct me if I'm wrong.

HHilal P***MemberCommunity member
Joined
Jun 2024
Message
284
#17

I'll try it. Having backups accessible on the same network and with the same identity makes them part of the target.

The answer varies greatly by industry; there is no one-size-fits-all rule. If you post the result here, it will help others too.

EEmre K***Member
Job title
Courier coordinator
Sector
Law
Organization type
cooperative
Joined
Feb 2025
Message
1
#18

There's a part I don't understand. Start with a small trial; don't commit to everything at once.

Payment information changes are never verified through the channel they came from. Of course, it varies if your situation is different.

RRecep K***MemberCommunity member
Joined
Mar 2023
Message
41
#19

Just a heads-up. An untested backup is not a backup.

Everyone rushing into closing access when employee leaves gets stuck at the same point. Good luck with that.

KKemal K***Veteran
Job title
Software developer
Sector
Furniture manufacturing
Organization type
family business
Joined
Feb 2023
Message
57

Doki · Interface design · 2026

#20

Let me clarify the technical side. If you scold false alarms, nobody will report again.

Reply