.png)
Remote employee offboarding requires HR and IT to close digital access, preserve business information, and recover company property from off-site locations.
The device-recovery problem is larger than it may appear. In Capterra’s 2022 survey of nearly 300 HR workers involved in offboarding, 71% said at least one departing employee had failed to return company equipment. Remote and hybrid employees were 17% more likely than on-site employees to keep equipment, and respondents estimated that each employee who retained equipment took an average of $1,963 in company property.
A reliable process should cover access and assets. NIST’s personnel-termination control calls for organizations to disable system access, revoke authenticators and credentials, retrieve security-related property, and retain access to information previously controlled by the departing employee.
Remote employee offboarding is the coordinated process of removing a departing worker’s access, transferring their responsibilities and business data, recovering company-owned equipment, and completing HR and legal requirements.
The remote element changes the logistics. A laptop may be hundreds of miles from IT, the employee may be signed into multiple cloud applications, and equipment recovery may depend on packaging, shipping labels, couriers, and follow-up.
Offboarding should go beyond changing a password or disabling a directory account.
CISA documented a 2024 incident in which a threat actor used a former employee’s administrator account to access a state government environment through its VPN. The organization confirmed that the account had not been disabled immediately after the employee left. The organization later posted information accessed during the compromise on a dark-web brokerage site.
Application sessions can also outlive the initial account action. Microsoft explains that Entra access tokens last for 1 hour by default, while an application’s own session token may remain valid until the application reevaluates access or revokes the session. Microsoft therefore recommends blocking sign-in, revoking refresh tokens, disabling registered devices, and maintaining a process for applications that require manual deprovisioning.
For each departure, IT should verify five layers:
When a remote employee leaves, closing their accounts does not resolve what happens to the physical device. IT still needs to confirm whether the laptop or phone has been returned, whether it is still communicating, and what to do if the equipment remains outstanding.
HRIS and identity platforms manage employee records and access, while MDMs handle device enrollment, configuration, and applications. Senturo adds device location, status, and recovery workflows, alongside platforms such as Microsoft Intune, Jamf, Google Admin Console, and Cisco Meraki.
For remote offboarding, Senturo can help IT:
Employee privacy should remain part of the workflow. With Senturo’s Privacy-First Geotracking, organizations can keep location hidden during normal use and reveal it after a device is reported missing. They can also require approval from a second administrator before location becomes visible.
Senturo supports the device-recovery stage of offboarding once account access has been secured. IT can identify outstanding equipment, check whether a device is still communicating, and take actions such as locating, locking, messaging, or wiping it according to company policy.
Send return materials before the employee’s final day whenever possible. The instructions should identify every item, the return deadline, the approved shipping method, and the contact person if collection fails.
When equipment arrives:
This record supports asset accounting, security investigations, and any later dispute about whether the equipment was returned.
The manager should confirm that another employee can access the departing worker’s files, contacts, workflows, and recurring responsibilities before access ends.
HR should complete final compensation, benefits information, property acknowledgments, confidentiality reminders, and any jurisdiction-specific notices. NIST also includes security topics in exit interviews and the retrieval of security-related property within its personnel-termination control.
Instead of publishing arbitrary universal targets, organizations should build internal baselines and track:
These measures reveal where the process is breaking down and whether ownership, automation, or policy needs to change.
The organization should define the timing in advance. For a routine resignation, schedule access to end at the agreed end of the employee’s final working day. Sensitive or involuntary terminations may require HR and IT to coordinate access removal during the termination meeting.
Confirm the device assignment, resend return instructions, track the shipment, and escalate the case under the organization’s asset policy. When authorized, IT can use available device-management and recovery tools to locate, lock, message, or wipe the device.
Senturo supports the device-recovery portion of the process. It works alongside identity, HR, and MDM platforms by helping IT investigate outstanding devices and take recovery or security actions when equipment is not returned.