Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› How should security teams handle former employee email…
NHI Lifecycle Management

How should security teams handle former employee email accounts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: NHI Lifecycle Management

They should disable access, remove forwarding rules, and confirm that the mailbox cannot continue to receive or relay organisational mail. Email offboarding is a trust control because stale accounts can be abused for impersonation, data exposure, or deceptive correspondence after employment ends.

Why Former Employee Mailboxes Need a Deliberate Offboarding Process

A former employee mailbox is not just an abandoned account. It can still receive messages, expose historical conversations, and act as a believable channel for internal or external correspondence if it remains reachable. The core security issue is trust continuity: once employment ends, the organisation must make sure the mailbox no longer functions as an active identity or messaging path.

That means security teams should treat mailbox closure as part of the joiner-mover-leaver lifecycle, not as a help desk cleanup task. The practical question is whether the account can still accept mail, forward mail, or be reused in a way that preserves access to organisational information or impersonates the former employee.

In practice, the mailbox state should match the business purpose. Some organisations preserve a mailbox for retention, legal hold, or delegated monitoring, but that should be a controlled archive state rather than an active inbox with ordinary delivery rights. If the mailbox must remain available, access should be tightly restricted and separately justified.

What Must Be Removed or Controlled

The first control is to disable interactive access and remove any route that allows the mailbox to keep functioning as a live communication endpoint. Forwarding rules are especially important because they can silently redirect mail outside the organisation, including sensitive messages that arrive after departure.

Security teams should also check for delegated access, shared mailbox membership, application bindings, calendar delegation, and any auto-reply or transport rule that keeps the account relevant after termination. If the mailbox name will be reused or the address is kept active as an alias, that decision needs explicit ownership and a clear rule for who can send on behalf of it.

Where the mailbox is retained for recordkeeping, the retained state should be read-only or heavily constrained. A retained mailbox should not be allowed to authenticate as a user account, relay mail broadly, or keep hidden forwarding destinations. The practical standard is simple: retention is acceptable, but continued trust is not.

How to Verify the Account Is Really Offboarded

Good offboarding is verified, not assumed. Teams should confirm that the account cannot sign in, cannot send as the former employee without approval, and cannot receive mail in a way that bypasses retention or supervision controls. They should also check that mailbox rules, connected apps, and legacy access paths have been removed rather than merely hidden from the user interface.

This is where cross-checks matter. The identity record, mailbox state, forwarding configuration, and mail flow policy should all agree. If any one of those still permits messaging, the account can remain a trust risk even after HR closure and directory deactivation.

When organisations retain mail for continuity, they should document the retention owner, the purpose, the duration, and the review point for eventual deletion or conversion to archive status. That prevents indefinite drift, where an employee mailbox quietly becomes a standing exception with no current business justification.

Risk and Threat Considerations

Former employee mailboxes are attractive because they preserve trust, history, and contact patterns. If they remain active, an attacker or insider can exploit that residual trust to impersonate the ex-employee, intercept sensitive correspondence, or use old workflows to request payments, credentials, or confidential files.

Failure mechanism: The mailbox still receives mail, forwards messages, or retains delegated access after employment ends, which lets someone abuse an account that recipients still recognise as legitimate.

Impact: Organisations can suffer impersonation, disclosure of confidential mail, misrouted business communication, and phishing or fraud that is harder to detect because the sender address looks familiar.

Practitioner Guidance

What to verify: Confirm four states before closing the ticket, sign-in blocked, forwarding removed, send-as or delegate paths removed, and any retention or archive mode explicitly approved. If the mailbox must stay live for a business reason, treat that as an exception with an owner and review date.

Common mistake: Disabling login but leaving mail flow untouched. That leaves a mailbox that still receives, forwards, or appears trustworthy to recipients, which is often enough for abuse.

Practitioner takeaway: The right outcome is not just account deactivation, it is eliminating the mailbox’s ability to function as a trusted communication channel unless there is a documented, controlled reason for it to remain available.

FRAMEWORK_REFS--- [{"framework_code":"CIS-CONTROLS","control_ref":"CIS-5","control_ref_label":"Account Management","relevance_note":"Former employee mailbox handling is an account lifecycle and access removal control.","framework_summary":"Remove or disable departed-user accounts and verify no residual mail access remains."},{"framework_code":"NIST-800-53","control_ref":"IA-5","control_ref_label":"Authenticator Management","relevance_note":"Mailbox offboarding depends on revoking credentials, tokens, and access paths tied to the account.","framework_summary":"Revoke credentials and related access material when an employee leaves."},{"framework_code":"ISO-27001","control_ref":"A.5.18","control_ref_label":"Access rights","relevance_note":"Mailbox offboarding is fundamentally about timely removal of departed-user access rights.","framework_summary":"Remove access rights promptly and confirm any retained mailbox state is explicitly authorised."},{"framework_code":"NIST-CSF","control_ref":"PR.AA-05","control_ref_label":"Identity Management, Authentication, and Access Control","relevance_note":"The issue is persistent identity access after termination and the controls that stop it.","framework_summary":"Enforce termination and access revocation so departed identities cannot keep using mail services."},{"framework_code":"OWASP-NHI","control_ref":"NHI-01","control_ref_label":"Improper Offboarding","relevance_note":"A former employee mailbox is a classic offboarding failure when it remains reachable or trusted.","framework_summary":"Remove dormant mail access, forwarding, and delegated paths as part of offboarding."} ]---TERM_META--- {"domain":"Lifecycle"}

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org