Device Lifecyle ManagementIT Asset Management

IT Offboarding Checklist for Global IT Teams

15 minutes read
blog

An employee’s last day is easy to plan when they sit in your office. You collect the laptop, disable the account and wave goodbye. Now picture the same exit when the employee is in Lisbon, the laptop is in a flat with no courier access, and your IT team is asleep in Bengaluru.

That is the everyday reality for global teams, and it is where offboarding goes wrong. Accounts stay active for weeks, laptops vanish into drawers, and nobody can say with confidence who still holds what. This guide covers the basics of IT offboarding, shows where it sits in the device lifecycle, and gives you a detailed checklist you can run for every exit, in every country.

Key Takeaways

  • IT offboarding has three jobs: close access, recover devices and data, and leave an audit trail.
  • Offboarding is the retrieval stage of the device lifecycle. Teams that treat it separately lose track of hardware.
  • Start before the last day. Inventory devices and accounts first, then act in a fixed order on the day.
  • Wipe and verify every device before reuse, using a documented standard such as NIST SP 800-88 Rev. 2.
  • Decide redeploy, resell or recycle by condition and age, and record the outcome.

What is IT offboarding?

IT offboarding is the process of removing a departing person’s access to company systems, recovering the devices and data they hold, and recording that it was done. It starts when an exit is confirmed and ends when the last device is wiped, reassigned or retired and the paperwork is closed.

It differs from HR offboarding, which covers final pay, benefits and exit interviews. The two run in parallel, and HR usually triggers the IT process. The business case for offboarding rests on both sides working together, even though managers rarely think about the IT consequences.

A complete IT offboarding process covers four areas:

  • Access: identity, email, SaaS apps, cloud consoles, code repositories, shared credentials, VPN and building access.
  • Devices: laptops, phones, tablets, monitors, security keys and accessories.
  • Data: files, mailboxes and application data that must be handed over, retained or deleted.
  • Records: the inventory, license and audit entries that prove each step happened.

Skip any one and you create a gap: an active account is a security risk, an unreturned device is a cost and data risk, and a missing record is an audit problem.

Why offboarding is harder for global teams

  • Time zones: The exit happens in one region while the person who can act is in another. If your process depends on one admin being online at 5 p.m., access will stay open for hours or days.
  • Logistics: Getting a laptop back from another country means couriers, customs paperwork and sometimes a person who is unwilling or unable to ship it. Each leg adds days.
  • Local rules: Employment law, data protection and works-council requirements differ by country. What you may access or retain from a departing employee’s mailbox in one country may be restricted in another.
  • Unmanaged corners: Remote staff sign up for tools and store files in places IT never sees. Those gaps only appear when someone leaves.

The cost of getting this wrong is real. IBM’s 2025 breach cost report puts the global average cost of a data breach at $4.44 million. Not every breach starts with an ex-employee, but a forgotten account or an unwiped laptop is exactly the type of preventable opening that attackers and careless insiders use.

The fix is not heroics. It is a process that works the same way regardless of where the employee is, triggered automatically, and run in a fixed order.

Offboarding as part of device lifecycle management

Every device passes through the same stages: procure, provision, manage, retrieve, then redeploy or dispose. Offboarding is the retrieve stage, and it is the point where the lifecycle either closes cleanly or breaks.

This matters because most offboarding failures are really lifecycle failures. If procurement never recorded the serial number, you cannot prove which laptop left with the employee. If provisioning never tied the device to a person, retrieval has no owner. If nothing feeds the returned device back into inventory, it sits on a shelf and gets bought again.

Treating offboarding as one stage of a connected loop fixes those gaps. Retrieved devices return to the pool, enter a wipe-and-verify step, and then go back out or leave service. That is the core idea behind effective device lifecycle management: each of the five stages feeds the next, so a retrieved device never falls out of view. A device lifecycle management platform makes that loop run without manual hand-offs.

Who owns what

Offboarding fails most often in the handoff between HR, IT, the manager and the employee. Agree on ownership before the first exit.

In practice:

  • HR notifies IT as soon as an exit is confirmed, including the date and whether it is voluntary.
  • IT revokes access, coordinates device return, wipes and records.
  • The manager is accountable for data and work handover, and decides who inherits files, shared mailboxes and app ownership.
  • The employee returns the device and accessories and confirms handover.

Write these roles into a device lifecycle policy so that nobody has to guess who acts when an exit is confirmed.

The IT offboarding checklist

Run this checklist for every departure. It is organised by time window, because order matters: you gather information first, close access at a controlled moment, then recover and process hardware.

Phase 1: Before the last day

  • Do these as soon as the exit is confirmed. Most of the work is preparation, and doing it early removes pressure from the final day.
  • Confirm the exit details with HR. Get the last working day, the type of exit (voluntary, redundancy, dismissal), and any legal hold or data-preservation requirements.
  • Build a full inventory of what the person holds. List every device, accessory, license, SaaS account, shared credential and physical access item. Pull this from your IT asset management records, not from the employee’s memory.
  • Identify what they own. Find shared documents, calendar series, group mailboxes, admin roles, scheduled jobs, service accounts and apps where they are the sole owner. Reassign ownership before access is removed so nothing breaks.
  • Schedule the device return. Choose pickup or a prepaid return kit, check courier availability in their country, and give a clear deadline. Send instructions in writing.
  • Agree the data handover. The manager confirms which files and mailbox content move to whom, and by when. 
  • Decide the access cut-off time. For involuntary exits it is usually immediate and coordinated with HR. For voluntary exits it is typically the end of the last working day. Convert it to the employee’s local time zone and put it in the ticket.

Regular user access reviews also shrink the list you build here, because stale permissions are removed long before anyone leaves.

Phase 2: On the last day, revoke access

Access removal should happen at the agreed time, in a fixed order, and be recorded step by step. Work from the identity outward.

  • Suspend the identity account. Using identity and access management, disable the SSO or directory account, end active sessions and revoke tokens. Suspension, not deletion, keeps the data available for handover and legal needs.
  • Remove MFA methods and registered devices. Clear authenticator registrations and security keys tied to the person.
  • Convert or secure email. Move the mailbox to a manager, set forwarding or an auto-reply, or convert it to a shared mailbox, according to policy and local law.
  • Remove SaaS access. Work through every app in the inventory, remove the user and reclaim the license. Apps outside SSO need manual steps, so check them individually.
  • Revoke cloud and code access. Remove console roles, personal access tokens, SSH keys and repository permissions. Rotate any secret the person could read.
  • Rotate shared credentials. Change shared passwords, API keys and service-account credentials the person knew.
  • Disable network and physical access. Remove VPN or zero-trust profiles, device certificates, Wi-Fi profiles, badges and any building or locker access.
  • Remove delegated and OAuth access. Check third-party apps the person authorised against company data and revoke them.
  • Record each step with the time, the person who did it and the system affected.

A frequent blind spot is software nobody on the IT team approved. The risks of unmanaged SaaS show up sharply at exit, because an app IT never knew about cannot be revoked by a checklist.

Phase 3: Retrieve the device

This is the stage where global teams struggle most. The aim is simple: get every device back, wherever it is, with a record of each step.

  • Notify the employee. Send the return steps, the deadline, and who to contact for help. Be clear and polite. Most people want to return equipment correctly.
  • Provide the means to return it. Send a prepaid label, a packaging kit or a courier pickup, depending on the country. Include accessories, chargers and security keys in the list.
  • Track the shipment. Record the tracking number against the asset and follow it until delivery. Escalate if it stalls.
  • Receive and inspect. On arrival, check the serial number against the record, inspect condition and note missing accessories.
  • Escalate non-returns. If the deadline passes, send a reminder, then involve HR and, if needed, legal. Meanwhile lock the device remotely if it is managed.
  • Log the outcome. Mark each device as returned, lost or unrecoverable, with the date and evidence.

Teams that get devices back reliably send the kit early and track it, rather than chasing at the end. That habit makes retrieving devices from anywhere far less painful.

Phase 4: Wipe and verify

Do not reassign a laptop until the data on it is gone and you can prove it. A wipe has two parts: running it and verifying it.

  • Remove the device from management after the wipe, not before: A wipe command needs the device to be reachable and managed. The Intune wipe action, for example, restores a device to factory settings and removes personal and organisational data, apps and configurations. On Windows you can also choose a wipe that continues even if the device loses power.
  • Choose the method that matches the risk: A standard factory reset suits redeployment inside the company. Higher-risk devices or end-of-life hardware need a stronger, verified erase. The current reference is NIST SP 800-88 Rev. 2, published in September 2025, which describes clear, purge and destroy sanitization methods and covers cryptographic erase.
  • Note what Rev. 2 changed: It states that degaussing no longer counts as a destroy technique on its own, so check any vendor certificate that relies on it.
  • Verify and document: Keep the wipe report, the device serial number, the date and the method.
  • Check manufacturer locks: Confirm Apple Activation Lock or Android Factory Reset Protection will not block reuse, and clear any personal-account lock before redeployment.
  • Deregister from provisioning services: For Windows, remove the device from Intune first and then deregister it from Autopilot. Microsoft’s registration guidance says to follow that order to avoid orphaned or unrecoverable records.

Never rely on a quick delete, because basic deletion leaves data recoverable. Incomplete wipes are one of the most common device offboarding compliance risks found in audits.

Phase 5: Redeploy or dispose

Once a device is clean, decide where it goes next. Make the decision by condition and age against your refresh policy, not by who happens to ask.

  • Redeploy devices in good condition and within the refresh cycle. Re-enroll them, assign them to the next person and update the asset record.
  • Resell or donate working devices past their refresh cycle, after verified erasure and a cosmetic check.
  • Recycle or destroy damaged devices, failed erasures and end-of-life hardware, using certified processes and keeping the certificate.
  • Keep the evidence. Store erasure reports and certificates of destruction with the asset record.

Reuse is where offboarding pays for itself. Automating asset retrieval and redeployment shortens the gap between a laptop coming back and the next employee receiving it. For devices that must leave service, a certified IT asset disposal route keeps the paperwork clean, and the best IT asset disposal platforms compare on exactly that.

Phase 6: Close the audit record

The last step is the one people skip. Without it, you cannot prove the process ran.

  • Confirm every item in the inventory is resolved. Each device, account and license should show a final state.
  • Reclaim and reallocate licenses. Return paid seats to the pool.
  • Archive or delete data per policy. Apply the retention period for mailboxes and files, and delete when it ends.
  • Store the checklist. Keep the completed checklist with timestamps, approvers and evidence.
  • Schedule a spot check. A short review 30 days later confirms no account or device slipped through.

Special cases to plan for

Standard exits are manageable. These variations need a decision in advance, because there is no time to debate policy while an account is still live.

1. Involuntary exits

Access must be removed at the moment the person is told, not after. Agree the timing with HR beforehand so the account is suspended just before or as the conversation ends, and lock any managed devices at the same point. Prepare the device return in advance too, because the employee will not be in the mood to chase a courier.

Do not ask the departing employee to hand over files. Route data and work handover through the manager, who can pull what is needed from shared drives and the suspended mailbox. Keep a short written record of the exact time access was removed.

2. Contractors and temporary staff

Contractors often hold access through guest accounts, vendor logins or shared credentials that sit outside your main directory, so a directory-driven checklist can miss them entirely. Include them in your inventory from day one and treat them as people with devices and accounts, not as an afterthought.

The simplest control is an expiry date. Set one when you grant access, tie it to the contract end date, and let the account lapse automatically. Then the exit does not depend on someone remembering to ask. Check at the end that any company-owned equipment they held has come back.

3. Bring your own device

A personal phone or laptop cannot be wiped like a company laptop, and you should not try. Remove only company data and company app access, using managed app policies or work profiles that separate corporate and personal data.

Then close the loop in writing. Ask the employee to confirm that company files, email and cached credentials have been deleted, and revoke any tokens or profiles tied to the device. Your policy should explain this at the start of employment, so the exit conversation does not feel like a surprise.

4. Devices lost or unreturned

Some devices will not come back. Once the deadline passes, lock the device remotely, wipe it if your policy and local law allow, and keep a record of every attempt to recover it: emails, courier tracking and calls.

Then escalate through HR and legal, and mark the asset as lost with the date and evidence. If the device held personal data, some regions require organisations to notify data protection authorities within a set time after a loss, so involve legal early rather than after the deadline has passed. Also review whether the device had full-disk encryption, since that shapes the risk assessment.

5. Internal transfers

A move between teams or countries is a partial offboarding, and it is easy to overlook because nobody is leaving. The danger is access creep: the person keeps every permission from the old role and adds new ones, until they hold far more than they need.

Remove access tied to the old role, update app licences and group memberships, and confirm who owns the device now. If the move crosses borders, check whether the device can travel and whether local data rules change. Keep the same audit trail you would for a full exit.

6. Legal holds

If a legal hold applies, the rules reverse: preserve data, do not wipe or reassign the device, and do not delete the mailbox until legal confirms in writing. Wiping too early can destroy evidence and create a legal problem larger than the one you were avoiding.

Build this check into Phase 1 of the checklist, so HR or legal flags a hold before any step runs. Keep held devices and accounts in a clearly labelled state, and set a review date so they do not stay frozen forever.

Whatever the case, the goal is a secure offboarding process that does not depend on who is on shift.

Common offboarding mistakes

  • Starting on the last day. Without an early inventory, you are guessing.
  • Relying on memory. Pull the list from systems of record.
  • Deleting accounts too early. Deleting removes data you may need. Suspend first, then delete per retention policy.
  • Forgetting non-SSO apps. Anything outside single sign-on needs its own step.
  • Skipping verification. A wipe that was never confirmed is only an assumption.
  • Letting devices sit. Returned hardware that is not logged becomes a ghost asset.
  • No owner for shared secrets. Rotate shared passwords and keys every time someone with access leaves.
  • Inconsistent country handling. Run one process with local variations.

How Zenadmin simplifies IT offboarding

Offboarding breaks when information lives in five places. Zenadmin puts it in one. Every device, license and account is tied to a person, so the moment an exit is triggered you know exactly who has what, from laptops and phones to app access. No spreadsheet hunt, no guessing.

From that single view, you revoke access across your connected apps and directory in one flow instead of working through admin consoles one by one. The same steps run for every employee in every country, and every action is logged for audit.

Device recovery works wherever your people are. Zenadmin arranges the return with pre-paid shipping labels, tracks it until it reaches you, and lets you lock or wipe a device remotely if it does not come back. Once received, you decommission the device with certified data erasure, or reassign it instantly to your next hire. Retired hardware leaves with the certificate to prove it.

The result is faster exits, fewer lost laptops, no orphaned access and an audit trail you never had to build by hand. For teams still stitching offboarding together from tickets and spreadsheets, Zenadmin is among the fastest, safest ways to run it. Book a demo and see a full exit run end to end.

Conclusion

IT offboarding comes down to three outcomes: no lingering access, no missing hardware, and a record that proves it. Reaching them is a matter of process. Inventory early, close access in a fixed order at a set time, recover devices with a tracked return, wipe and verify before reuse, and decide redeploy, resell or recycle by condition. Do it the same way for every employee, in every country, and offboarding stops being a scramble.

Turn the checklist above into a ticket template and run your next exit through it. Then connect it to your wider device lifecycle, so the system that knows who has a laptop also brings it back.

FAQs

What should be on an IT offboarding checklist?

A complete checklist covers six areas: confirming exit details, inventorying devices and accounts, revoking access, retrieving devices, wiping and verifying data, and redeploying or disposing of hardware. It ends with closing the audit record. The detailed list above breaks each into steps you can copy into a ticket template.

When should IT start the offboarding process?

As soon as the exit is confirmed. Starting before the last day lets you inventory devices, reassign ownership and arrange device return without time pressure. For involuntary exits, prepare the steps in advance so access can be removed the moment the decision is communicated.

Should you delete or suspend a departing employee’s account?

Suspend first. Suspension blocks sign-in and keeps data available for handover, investigations and legal holds. Delete only once your retention period has passed and the manager has confirmed that nothing is needed.

How do you retrieve a laptop from a remote employee in another country?

Send clear return instructions and a prepaid label or courier pickup, track the shipment, and inspect the device on arrival. If the device is not returned by the deadline, lock it remotely, escalate through HR and legal, and record it as lost. Using a provider with local logistics speeds this up.

How do you securely wipe a laptop before reuse?

Run a managed remote wipe or factory reset, choose the method that matches the device’s risk, and keep the wipe report. NIST SP 800-88 Rev. 2 is the current reference for sanitization levels. Verify the result before the laptop is redeployed, and clear any activation or reset locks.

What is the difference between offboarding and decommissioning?

Offboarding is the full exit process for a person: access, devices, data and records. Decommissioning is the end-of-life process for a device, which may follow offboarding when a returned device is wiped and then retired rather than reused.

How do you handle personal devices during offboarding?

Remove company data and app access through managed app policies rather than wiping the whole device. Confirm in writing that the employee has deleted company data, and revoke any tokens or profiles tied to the device.

Can offboarding be automated?

Yes, in large part. HR triggers can start the workflow, access removal can run across connected apps, device return can be scheduled and tracked, and every step can be logged. Human sign-off still matters for privileged access, legal holds and data handover decisions.

blog

Want results like this?

See how ZenAdmin would run device lifecycle for your team

Tell us your fleet and workforce and we’ll show how the same lifecycle setup would work for you.

  • See how procurement, leasing and ITAM were set up in this story
  • Map it to your fleet size, locations and remote team
  • Get a clear plan for retrieval and refresh cycles

No commitment. No sales pressure.

Get my tailored demo

user-icon
mail-icon
building-icon
users-icon
Number of employees