Remote Employee Offboarding Checklist

September 24, 2026
September 25, 2026
Use this remote employee offboarding checklist to revoke access, recover company devices, protect business data, and document every step.
No items found.

Remote employee offboarding requires HR and IT to close digital access, preserve business information, and recover company property from off-site locations.

The device-recovery problem is larger than it may appear. In Capterra’s 2022 survey of nearly 300 HR workers involved in offboarding, 71% said at least one departing employee had failed to return company equipment. Remote and hybrid employees were 17% more likely than on-site employees to keep equipment, and respondents estimated that each employee who retained equipment took an average of $1,963 in company property.

A reliable process should cover access and assets. NIST’s personnel-termination control calls for organizations to disable system access, revoke authenticators and credentials, retrieve security-related property, and retain access to information previously controlled by the departing employee.

What Is Remote Employee Offboarding?

Remote employee offboarding is the coordinated process of removing a departing worker’s access, transferring their responsibilities and business data, recovering company-owned equipment, and completing HR and legal requirements.

The remote element changes the logistics. A laptop may be hundreds of miles from IT, the employee may be signed into multiple cloud applications, and equipment recovery may depend on packaging, shipping labels, couriers, and follow-up.

Step-by-Step Remote Offboarding Process

  • ☐ Confirm the employee’s final working day and access cutoff
  • ☐ Inventory accounts, applications, and privileged access
  • ☐ Inventory company-owned devices and equipment
  • ☐ Transfer files, projects, and business responsibilities
  • ☐ Arrange device return and shipping
  • ☐ Revoke accounts, sessions, MFA, and credentials
  • ☐ Confirm or escalate outstanding device returns
  • ☐ Wipe and reconfigure returned devices
  • ☐ Complete HR, payroll, benefits, and legal requirements
  • ☐ Audit and document the completed offboarding process

As Soon as the Departure Is Confirmed

  • Confirm the employee’s last working day and the time access should end.
  • Assign owners across HR, IT, security, finance, legal, and the employee’s manager.
  • Inventory every account, including SSO, email, VPN, cloud storage, CRM, finance systems, code repositories, password managers, and administrator roles.
  • Inventory company property, including laptops, phones, security keys, SIM cards, access cards, chargers, and specialized equipment.
  • Record serial numbers, asset tags, assigned users, device-management status, and current check-in information.
  • Identify active projects, client relationships, recurring tasks, shared credentials, and files that need new owners.
  • Send equipment-return instructions, prepaid labels, packaging guidance, and a clear deadline.

During the Final Week

  • Transfer ownership of files, calendars, dashboards, shared mailboxes, documents, and application records.
  • Reassign open projects, tickets, approvals, clients, and vendor relationships.
  • Complete handover documents and record walkthroughs for hard-to-document processes.
  • Confirm that company devices are still enrolled and communicating before the employee leaves.
  • Review privileged access separately, including local administrator accounts, API keys, service accounts, SSH keys, and OAuth connections.
  • Prepare the access-removal sequence so HR and IT act at the agreed time.

On the Final Day

  • Disable the employee in the identity provider and core directory.
  • Revoke active sessions and refresh tokens.
  • Remove VPN, remote desktop, email, collaboration, and business-application access.
  • Disable MFA methods, device registrations, and password-vault access.
  • Rotate shared passwords, API keys, or credentials the employee knew.
  • Transfer business data before deleting or archiving the account.
  • Confirm whether each assigned device has been returned, shipped, or escalated for follow-up.
  • Record who completed each action and when.

During the First Seven Days

  • Review sign-in and audit logs for failed or unexpected access attempts.
  • Check applications that require manual deprovisioning.
  • Track outstanding equipment shipments and contact the former employee when deadlines are missed.
  • Match returned serial numbers and accessories against asset records.
  • Preserve required business data, then wipe and reconfigure returned devices.
  • Complete payroll, benefits, legal notices, and exit documentation according to applicable requirements.
  • Keep unresolved access or device cases open until they have a named owner and documented outcome.

Why Disabling an Account May Not End Every Session

Offboarding should go beyond changing a password or disabling a directory account.

CISA documented a 2024 incident in which a threat actor used a former employee’s administrator account to access a state government environment through its VPN. The organization confirmed that the account had not been disabled immediately after the employee left. The organization later posted information accessed during the compromise on a dark-web brokerage site.

Application sessions can also outlive the initial account action. Microsoft explains that Entra access tokens last for 1 hour by default, while an application’s own session token may remain valid until the application reevaluates access or revokes the session. Microsoft therefore recommends blocking sign-in, revoking refresh tokens, disabling registered devices, and maintaining a process for applications that require manual deprovisioning.

For each departure, IT should verify five layers:

  1. The central identity account is disabled.
  2. Revoke refresh tokens and active sessions.
  3. Direct application accounts are deprovisioned.
  4. IT rotates shared secrets and privileged credentials.
  5. Review sign-in logs after the departure.

Recover and Secure Remote Company Devices

When a remote employee leaves, closing their accounts does not resolve what happens to the physical device. IT still needs to confirm whether the laptop or phone has been returned, whether it is still communicating, and what to do if the equipment remains outstanding.

HRIS and identity platforms manage employee records and access, while MDMs handle device enrollment, configuration, and applications. Senturo adds device location, status, and recovery workflows, alongside platforms such as Microsoft Intune, Jamf, Google Admin Console, and Cisco Meraki.

For remote offboarding, Senturo can help IT:

  • Review last-reported location, location history, and device status when company equipment has not been returned.
  • Place a device in Missing Mode to increase location-reporting frequency and enable recovery actions.
  • Apply a remote lock with a customized return message and contact details on supported devices.
  • Wipe user files from supported Windows and macOS devices when the organization determines that data protection takes priority over recovery.
  • Use geofencing, IP fencing, and phone-home policies to flag devices that move, connect, or stop communicating in ways that require attention.

Employee privacy should remain part of the workflow. With Senturo’s Privacy-First Geotracking, organizations can keep location hidden during normal use and reveal it after a device is reported missing. They can also require approval from a second administrator before location becomes visible.

Senturo supports the device-recovery stage of offboarding once account access has been secured. IT can identify outstanding equipment, check whether a device is still communicating, and take actions such as locating, locking, messaging, or wiping it according to company policy.

Create a Documented Equipment-Return Process

Send return materials before the employee’s final day whenever possible. The instructions should identify every item, the return deadline, the approved shipping method, and the contact person if collection fails.

When equipment arrives:

  • Match the serial number and asset tag.
  • Record its condition and any missing accessories.
  • Save courier tracking and proof of delivery.
  • Document who received and handled the device.
  • Escalate missing or damaged property according to the organization’s written policy.

This record supports asset accounting, security investigations, and any later dispute about whether the equipment was returned.

Complete the Human and Legal Handover

The manager should confirm that another employee can access the departing worker’s files, contacts, workflows, and recurring responsibilities before access ends.

HR should complete final compensation, benefits information, property acknowledgments, confidentiality reminders, and any jurisdiction-specific notices. NIST also includes security topics in exit interviews and the retrieval of security-related property within its personnel-termination control.

Measure Offboarding Performance

Instead of publishing arbitrary universal targets, organizations should build internal baselines and track:

  • Time from the approved cutoff to completed access removal
  • Percentage of applications deprovisioned automatically
  • Number of active accounts discovered after departure
  • Percentage and value of company property recovered
  • Average time required to recover remote devices
  • Percentage of sanitization actions with complete records

These measures reveal where the process is breaking down and whether ownership, automation, or policy needs to change.

‍

Recover Devices That Don’t Come Back
When company equipment is still outstanding after an employee leaves, Senturo helps IT check device location and status, investigate what happened, and take recovery actions such as locking, messaging, or wiping supported devices.

‍

Frequently Asked Questions

When should a departing employee’s access be removed?

The organization should define the timing in advance. For a routine resignation, schedule access to end at the agreed end of the employee’s final working day. Sensitive or involuntary terminations may require HR and IT to coordinate access removal during the termination meeting.

What should IT do when a remote employee does not return a laptop?

Confirm the device assignment, resend return instructions, track the shipment, and escalate the case under the organization’s asset policy. When authorized, IT can use available device-management and recovery tools to locate, lock, message, or wipe the device.

Where does Senturo fit in remote offboarding?

Senturo supports the device-recovery portion of the process. It works alongside identity, HR, and MDM platforms by helping IT investigate outstanding devices and take recovery or security actions when equipment is not returned.

‍

Björn Hall, Co-Founder & CEO @ Senturo

Björn Hall is an experienced software entrepreneur in mobile security fleet management. As Co-Founder & CEO, he has led Senturo’s evolution into a powerful enterprise solution, delivering advanced geo-tracking, compliance automation, and security enforcement across macOS, Windows, iOS, Android, and Chrome OS. More about Björn

‍