An employee’s last day is easy to plan when they sit in your office. You collect the laptop, disable the account and wave goodbye. Now picture the same exit when the employee is in Lisbon, the laptop is in a flat with no courier access, and your IT team is asleep in Bengaluru.
That is the everyday reality for global teams, and it is where offboarding goes wrong. Accounts stay active for weeks, laptops vanish into drawers, and nobody can say with confidence who still holds what. This guide covers the basics of IT offboarding, shows where it sits in the device lifecycle, and gives you a detailed checklist you can run for every exit, in every country.
IT offboarding is the process of removing a departing person’s access to company systems, recovering the devices and data they hold, and recording that it was done. It starts when an exit is confirmed and ends when the last device is wiped, reassigned or retired and the paperwork is closed.
It differs from HR offboarding, which covers final pay, benefits and exit interviews. The two run in parallel, and HR usually triggers the IT process. The business case for offboarding rests on both sides working together, even though managers rarely think about the IT consequences.
A complete IT offboarding process covers four areas:
Skip any one and you create a gap: an active account is a security risk, an unreturned device is a cost and data risk, and a missing record is an audit problem.
The cost of getting this wrong is real. IBM’s 2025 breach cost report puts the global average cost of a data breach at $4.44 million. Not every breach starts with an ex-employee, but a forgotten account or an unwiped laptop is exactly the type of preventable opening that attackers and careless insiders use.
The fix is not heroics. It is a process that works the same way regardless of where the employee is, triggered automatically, and run in a fixed order.
Every device passes through the same stages: procure, provision, manage, retrieve, then redeploy or dispose. Offboarding is the retrieve stage, and it is the point where the lifecycle either closes cleanly or breaks.

This matters because most offboarding failures are really lifecycle failures. If procurement never recorded the serial number, you cannot prove which laptop left with the employee. If provisioning never tied the device to a person, retrieval has no owner. If nothing feeds the returned device back into inventory, it sits on a shelf and gets bought again.
Treating offboarding as one stage of a connected loop fixes those gaps. Retrieved devices return to the pool, enter a wipe-and-verify step, and then go back out or leave service. That is the core idea behind effective device lifecycle management: each of the five stages feeds the next, so a retrieved device never falls out of view. A device lifecycle management platform makes that loop run without manual hand-offs.
Offboarding fails most often in the handoff between HR, IT, the manager and the employee. Agree on ownership before the first exit.

In practice:
Write these roles into a device lifecycle policy so that nobody has to guess who acts when an exit is confirmed.
Run this checklist for every departure. It is organised by time window, because order matters: you gather information first, close access at a controlled moment, then recover and process hardware.

Regular user access reviews also shrink the list you build here, because stale permissions are removed long before anyone leaves.
Access removal should happen at the agreed time, in a fixed order, and be recorded step by step. Work from the identity outward.

A frequent blind spot is software nobody on the IT team approved. The risks of unmanaged SaaS show up sharply at exit, because an app IT never knew about cannot be revoked by a checklist.
This is the stage where global teams struggle most. The aim is simple: get every device back, wherever it is, with a record of each step.

Teams that get devices back reliably send the kit early and track it, rather than chasing at the end. That habit makes retrieving devices from anywhere far less painful.
Do not reassign a laptop until the data on it is gone and you can prove it. A wipe has two parts: running it and verifying it.
Never rely on a quick delete, because basic deletion leaves data recoverable. Incomplete wipes are one of the most common device offboarding compliance risks found in audits.
Once a device is clean, decide where it goes next. Make the decision by condition and age against your refresh policy, not by who happens to ask.

Reuse is where offboarding pays for itself. Automating asset retrieval and redeployment shortens the gap between a laptop coming back and the next employee receiving it. For devices that must leave service, a certified IT asset disposal route keeps the paperwork clean, and the best IT asset disposal platforms compare on exactly that.
The last step is the one people skip. Without it, you cannot prove the process ran.
Standard exits are manageable. These variations need a decision in advance, because there is no time to debate policy while an account is still live.
Access must be removed at the moment the person is told, not after. Agree the timing with HR beforehand so the account is suspended just before or as the conversation ends, and lock any managed devices at the same point. Prepare the device return in advance too, because the employee will not be in the mood to chase a courier.
Do not ask the departing employee to hand over files. Route data and work handover through the manager, who can pull what is needed from shared drives and the suspended mailbox. Keep a short written record of the exact time access was removed.
Contractors often hold access through guest accounts, vendor logins or shared credentials that sit outside your main directory, so a directory-driven checklist can miss them entirely. Include them in your inventory from day one and treat them as people with devices and accounts, not as an afterthought.
The simplest control is an expiry date. Set one when you grant access, tie it to the contract end date, and let the account lapse automatically. Then the exit does not depend on someone remembering to ask. Check at the end that any company-owned equipment they held has come back.
A personal phone or laptop cannot be wiped like a company laptop, and you should not try. Remove only company data and company app access, using managed app policies or work profiles that separate corporate and personal data.
Then close the loop in writing. Ask the employee to confirm that company files, email and cached credentials have been deleted, and revoke any tokens or profiles tied to the device. Your policy should explain this at the start of employment, so the exit conversation does not feel like a surprise.
Some devices will not come back. Once the deadline passes, lock the device remotely, wipe it if your policy and local law allow, and keep a record of every attempt to recover it: emails, courier tracking and calls.
Then escalate through HR and legal, and mark the asset as lost with the date and evidence. If the device held personal data, some regions require organisations to notify data protection authorities within a set time after a loss, so involve legal early rather than after the deadline has passed. Also review whether the device had full-disk encryption, since that shapes the risk assessment.
A move between teams or countries is a partial offboarding, and it is easy to overlook because nobody is leaving. The danger is access creep: the person keeps every permission from the old role and adds new ones, until they hold far more than they need.
Remove access tied to the old role, update app licences and group memberships, and confirm who owns the device now. If the move crosses borders, check whether the device can travel and whether local data rules change. Keep the same audit trail you would for a full exit.
If a legal hold applies, the rules reverse: preserve data, do not wipe or reassign the device, and do not delete the mailbox until legal confirms in writing. Wiping too early can destroy evidence and create a legal problem larger than the one you were avoiding.
Build this check into Phase 1 of the checklist, so HR or legal flags a hold before any step runs. Keep held devices and accounts in a clearly labelled state, and set a review date so they do not stay frozen forever.
Whatever the case, the goal is a secure offboarding process that does not depend on who is on shift.
Offboarding breaks when information lives in five places. Zenadmin puts it in one. Every device, license and account is tied to a person, so the moment an exit is triggered you know exactly who has what, from laptops and phones to app access. No spreadsheet hunt, no guessing.
From that single view, you revoke access across your connected apps and directory in one flow instead of working through admin consoles one by one. The same steps run for every employee in every country, and every action is logged for audit.
Device recovery works wherever your people are. Zenadmin arranges the return with pre-paid shipping labels, tracks it until it reaches you, and lets you lock or wipe a device remotely if it does not come back. Once received, you decommission the device with certified data erasure, or reassign it instantly to your next hire. Retired hardware leaves with the certificate to prove it.
The result is faster exits, fewer lost laptops, no orphaned access and an audit trail you never had to build by hand. For teams still stitching offboarding together from tickets and spreadsheets, Zenadmin is among the fastest, safest ways to run it. Book a demo and see a full exit run end to end.
IT offboarding comes down to three outcomes: no lingering access, no missing hardware, and a record that proves it. Reaching them is a matter of process. Inventory early, close access in a fixed order at a set time, recover devices with a tracked return, wipe and verify before reuse, and decide redeploy, resell or recycle by condition. Do it the same way for every employee, in every country, and offboarding stops being a scramble.
Turn the checklist above into a ticket template and run your next exit through it. Then connect it to your wider device lifecycle, so the system that knows who has a laptop also brings it back.
A complete checklist covers six areas: confirming exit details, inventorying devices and accounts, revoking access, retrieving devices, wiping and verifying data, and redeploying or disposing of hardware. It ends with closing the audit record. The detailed list above breaks each into steps you can copy into a ticket template.
As soon as the exit is confirmed. Starting before the last day lets you inventory devices, reassign ownership and arrange device return without time pressure. For involuntary exits, prepare the steps in advance so access can be removed the moment the decision is communicated.
Suspend first. Suspension blocks sign-in and keeps data available for handover, investigations and legal holds. Delete only once your retention period has passed and the manager has confirmed that nothing is needed.
Send clear return instructions and a prepaid label or courier pickup, track the shipment, and inspect the device on arrival. If the device is not returned by the deadline, lock it remotely, escalate through HR and legal, and record it as lost. Using a provider with local logistics speeds this up.
Run a managed remote wipe or factory reset, choose the method that matches the device’s risk, and keep the wipe report. NIST SP 800-88 Rev. 2 is the current reference for sanitization levels. Verify the result before the laptop is redeployed, and clear any activation or reset locks.
Offboarding is the full exit process for a person: access, devices, data and records. Decommissioning is the end-of-life process for a device, which may follow offboarding when a returned device is wiped and then retired rather than reused.
Remove company data and app access through managed app policies rather than wiping the whole device. Confirm in writing that the employee has deleted company data, and revoke any tokens or profiles tied to the device.
Yes, in large part. HR triggers can start the workflow, access removal can run across connected apps, device return can be scheduled and tracked, and every step can be logged. Human sign-off still matters for privileged access, legal holds and data handover decisions.