Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should organisations do with Microsoft 365 mailboxes…
Cyber Security

What should organisations do with Microsoft 365 mailboxes and files after an employee leaves?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Organisations should preserve business-critical content before deletion by archiving mailbox data, transferring OneDrive files, and exporting Outlook contacts, calendars, or tasks where needed. If the role still requires continuity, the mailbox can be forwarded or converted to a shared mailbox. The goal is to retain necessary records while removing the former employee’s access.

Preserve the records, then remove the account’s live access

Offboarding Microsoft 365 content is a records and access decision, not just a deletion task. Organisations should first decide what must be retained for continuity, legal hold, audit, or operational handover, then preserve that content in a controlled place before access is withdrawn. That usually means mailbox archiving, OneDrive transfer, and selective export of personal productivity data.

Where continuity matters, preserve the communication path without preserving the person. A mailbox can be converted to a shared mailbox or forwarded under a controlled ownership model so the business keeps receiving messages while the former employee’s authentication path is removed. For identity-driven handover risk, see NHIMG’s Coupang Signing Key Breach for a concrete offboarding failure pattern, and the Ultimate Guide section on Non-Human Identities for lifecycle and revocation context.

The practical question is whether the mailbox or file store is still a business asset after departure. If yes, retain it in a form that is searchable, governed, and owned by the organisation; if no, dispose of it in line with retention policy and regulatory obligations. Treat calendars, contacts, and tasks as potentially business-relevant records when they contain customer commitments, meeting history, or operational dependencies.

How offboarding Microsoft 365 data usually breaks

The most common failure is assuming account disablement is the same as data preservation. It is not. Once access is removed, organisations can still lose business context if the mailbox, OneDrive, or local Outlook data were never exported or reassigned. The result is usually not a headline breach, but a productivity and governance gap: missing customer threads, unowned files, and incomplete records.

Another failure mode is keeping access alive too long because someone needs a final answer from the departed employee’s mailbox. That should be handled through delegation, forwarding, shared mailbox conversion, or a formal handover process, not by leaving a personal account active as an informal business dependency. For a comparable lifecycle-and-access lesson, NHIMG’s Microsoft Midnight Blizzard breach illustrates how legacy or poorly governed access paths can remain exploitable well beyond their intended use.

Files need the same discipline. OneDrive content often contains drafts, working documents, and embedded business knowledge that never made it into a shared repository. If ownership is not transferred before deletion, teams may discover too late that the departed employee’s folder was the only complete copy of a project artifact or client-specific working set.

Risk and Threat Considerations

Leaving offboarding incomplete creates two distinct problems: business records can disappear, and the former account can remain a reachable access path if disablement, forwarding, or delegated access is handled loosely. That combination is especially risky when mailboxes contain approvals, credentials, or sensitive conversations that can be mined after departure.

Failure mechanism: The organisation removes the person but fails to preserve or rehome the content, or it preserves the content while leaving an active access path, stale forwarding rule, or overbroad shared mailbox permission in place.

Impact: Missing records undermine continuity and auditability, while residual access can expose sensitive mail, business files, and collaboration history to misuse, accidental disclosure, or post-departure compromise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlOffboarding requires removing former-user access while preserving needed business data.
PR.DS — Data SecurityMailbox and file transfer decisions are data handling and retention controls.
PR.IP — Information Protection Processes and ProceduresOffboarding mailboxes and files should follow repeatable retention and transfer procedures.
Recommendation — Revoke the departed user's access and reassign ownership to an authorised business owner. Preserve required records in controlled storage before deleting the user account. Use a documented handover procedure for mailbox archiving and file transfer.
CIS Controls v85.3 — Disable Dormant AccountsEmployee departure is a lifecycle event that should terminate active access promptly.
6.1 — Establish and Maintain a Data Management ProcessMailbox, OneDrive and exported items must be retained or disposed of by policy.
Recommendation — Disable the former employee's account and remove all associated access paths immediately. Classify and retain business-critical mailbox and file content according to policy.
NIST SP 800-63AAL — Authentication Assurance LevelDeparture handling depends on ensuring the old authenticators no longer confer access.
IAL — Identity Assurance LevelOffboarding is a lifecycle control over the identity's continued authority.
Recommendation — Invalidate the employee's authenticators and any sessions tied to the account. Treat the employee identity as decommissioned once ownership and retention actions are complete.

Practitioner Guidance

What to prioritise: Separate the retention decision from the access decision. First identify what content must survive the employee’s departure, then decide who owns it, where it lives, and who can access it after handover.

What to verify: Confirm that mailbox retention, shared mailbox conversion, OneDrive transfer, and any export of contacts, calendars, or tasks are completed before the account is retired. Also verify that forwarding rules, delegated permissions, and group memberships are removed or reassigned under a current owner.

Practitioner takeaway: The safest offboarding outcome is preserved business knowledge with zero personal access remaining, not a deleted user and a pile of unreconciled data.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org