When ex-employees still have access, organisations lose control over who can read, modify, or forward corporate data. Email continuity can also become messy if mailbox ownership is not transferred cleanly, and unmanaged mobile devices can keep synced content available. The practical failure is stale privilege, which undermines both security and operational continuity.
What actually fails when access is not removed cleanly
The first breakage is control. Once a departed employee can still sign in, the organisation no longer has a reliable boundary around who can read inboxes, download files, approve workflows, or forward data out of Microsoft 365. That stale access also turns every retained mailbox, shared folder, and synced device into a continuing exposure point, which is why offboarding must be treated as a security control, not just an HR task.
Microsoft 365 makes that exposure broader because access is often distributed across Exchange, OneDrive, SharePoint, Teams, and device sync. If one account or token remains valid, the former employee may still reach more than email, including content caches and collaboration history. In practice, the question is not whether the person is still employed, but whether any live path still grants authority to corporate data.
- Mailbox ownership and delegation can remain active after departure.
- Forwarding rules and shared access can preserve data flow outside the business.
- Mobile and desktop sync can keep locally cached content available even after a password change.
Why stale Microsoft 365 access becomes an operational problem, not just a security one
Operationally, incomplete offboarding creates confusion about who owns the mailbox, who can respond to business mail, and who can preserve records needed for legal, client, or audit reasons. If the mailbox is disabled too late, too early, or without transfer planning, teams may lose continuity or duplicate important correspondence. That is especially problematic when the account still receives external mail or still participates in Teams and shared document workflows.
This is also where access governance and email continuity collide. Organisations need to separate account retirement from record retention, because legal retention and business continuity do not require the former employee to remain able to authenticate. A clean handoff should preserve the content and ownership of work products while removing the departed person’s ability to act inside the tenant. Ultimate Guide to NHIs — Key Challenges and Risks is useful here because the same stale-privilege pattern shows up wherever access is not reviewed, rotated, or revoked on time.
For evidence-based remediation, Microsoft 365 offboarding should also be paired with credential and token review, not only password reset. If sessions, app passwords, OAuth grants, or device registrations remain intact, a removed user can sometimes keep access through a side channel even after the primary account state changes. Coupang Signing Key Breach and Microsoft OAuth Breach both reinforce the broader lifecycle lesson: access removal has to cover the whole trust chain, not only the visible login account.
Risk and Threat Considerations
Stale Microsoft 365 access is attractive because it often blends in with normal business activity. A former employee with valid access can quietly read mail, harvest attachments, preserve forwarding, or access shared documents without triggering an obvious failure, especially if monitoring is weak and device sync remains active. The main risk is not only deliberate abuse, but also accidental exposure when forgotten access paths outlive the employment relationship.
Failure mechanism: Unrevoked access, persistent sessions, delegated mailbox rights, and synced devices keep a former employee inside the tenant after departure, allowing continued data access or unauthorized action.
Impact: Confidential data exposure, mailbox misuse, missed business correspondence, retention and audit complications, and a larger blast radius if the old account is later compromised or reused by an attacker.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Lifecycle and Deprovisioning | Offboarding and stale access are central to the departure risk described. |
| NHI-02 — Least Privilege and Entitlements | The core failure is excessive residual access after an employee leaves. | |
| NHI-03 — Secrets and Credential Management | Residual sessions and tokens can preserve access after the account change. | |
| Recommendation — Revoke departed-user access paths promptly and verify every credential, token, and delegation is removed. Reduce retained permissions to the minimum needed for record retention and continuity. Rotate or invalidate any credential or token that can still authenticate after offboarding. | ||
| CIS Controls v8 | 6 — Access Control Management | Managing and removing access for former users directly matches the issue. |
| 5 — Account Management | Account lifecycle handling is the main control problem in offboarding. | |
| Recommendation — Disable and remove access for departing users across all systems and shared resources. Track account status changes and ensure termination triggers prompt access revocation. | ||
| NIST CSF 2.0 | PR.AC — Access Control | The question is about preventing continued access after departure. |
| GV.OV — Oversight | Offboarding failure is a governance and accountability gap as well as an access issue. | |
| Recommendation — Enforce access restrictions so only approved users can reach Microsoft 365 data. Assign ownership for offboarding controls and review termination outcomes for completion. | ||
| MITRE ATT&CK | T1098 — Account Manipulation | Persisting mailbox rules, delegation, or account settings can preserve access. |
| T1114 — Email Collection | Continued mailbox access enables collection of corporate email and attachments. | |
| T1021 — Remote Services | Retained Microsoft 365 sessions and remote access paths can be abused after departure. | |
| Recommendation — Monitor for post-departure account setting changes and suspicious delegation persistence. Detect and investigate continued mailbox access or forwarding after termination. Hunt for lingering remote access paths that still authenticate as the departed user. | ||
Practitioner Guidance
What to verify: Treat offboarding as a verification exercise, not a checklist of account closure. Confirm that mailbox delegation, forwarding rules, device registrations, app consents, session tokens, and shared-folder permissions are removed or reassigned, and verify that the former employee cannot still reach content through a secondary route.
Decision rule: If the account still has any path to production mail or shared data, prioritise revocation and transfer of ownership before worrying about archive convenience. If business continuity is the concern, preserve the data and workflow separately from the user’s ability to authenticate.
Practitioner takeaway: The failure is rarely “the account still exists”; it is that the tenant still cannot distinguish preserved business records from preserved personal authority.
Related resources from NHI Mgmt Group
- Who is accountable when former employees still have Microsoft 365 access?
- Who is accountable when a former employee still has access after offboarding?
- Who is accountable when a former employee still has access after leaving?
- What breaks when a former employee still has access to shared cloud root credentials?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org