Law Firm Employee Offboarding Checklist: Access and Records
A practical law-firm offboarding checklist to remove access, preserve client records, and verify completion—with a worksheet for owners and office managers.
Blog post - By Securing Your Law Firm
An attorney leaves. Their laptop comes back, email access is blocked, and the office manager checks the departure off the list.
Then a client calls about an unanswered message. A deadline reminder was left in the former employee's calendar. Or a document portal still lets that person sign in.
Plan access removal and record handover together, then check each separately. Microsoft's former-employee guidance treats these as separate tasks. "IT handled the account" needs a more specific follow-up.
You do not need to manage the technical settings yourself. You need named owners, a cutoff time, and written confirmation.
1. Name a coordinator and set the cutoff
The office manager can coordinate the departure. The firm owner or responsible attorney should approve record-preservation decisions and who may see client information. Assign account changes to each system's administrator or IT provider.
Set the access cutoff date, time, and time zone. Coordinate it with the departure notification. Urgent or disputed departures need prompt direction from firm leadership.
2. List every system the person used
Include email, matter management, document storage, billing, client portals, remote access, and e-signature services. Check separate administrator accounts and software purchased directly by an attorney or department.
For a planned departure, ask for a handover list. Compare it with account records and have each system owner confirm their part.
Court filing accounts and outside client portals may belong to the individual. Ask the provider or client to change firm permissions or associations where appropriate; do not take over personal credentials.
Ask: "Which systems need their own removal step after we block Microsoft 365?"
3. Approve the preservation plan before deleting anything
The responsible attorney should identify active matters, deadlines, client communications, billing records, and any records subject to a preservation instruction. Name a successor and specify where each record will remain.
Block access when required, but confirm preservation before deleting accounts, removing licenses, or erasing devices.
Microsoft's inactive mailbox option can retain qualifying email after account deletion. Required licensing and preservation settings must be in place beforehand. It does not receive new email. Ask your administrator which supported option fits the firm's needs.
The firm must determine applicable retention and confidentiality requirements. Saving email alone does not preserve every matter file or Teams conversation.
4. Remove access and arrange email coverage
Ask the administrator to block sign-in and address existing sessions using Microsoft's access-removal guidance. Other applications can maintain their own signed-in sessions. Have each system owner confirm separate action and any remaining delay.
Decide who may read the old mailbox, how new client inquiries will reach the right person, and when that arrangement will be reviewed.
Converting a mailbox to a shared mailbox does not itself block the former employee. Microsoft's shared-mailbox guidance requires additional access-removal steps. Existing inbox rules remain after conversion. Review forwarding, approved readers, and licensing; keep the account that supports the shared mailbox.
A replacement employee may not need access to every confidential matter.
5. Hand over files, deadlines, and devices
Have the successor open representative approved files in OneDrive, shared folders, Teams, and the matter system. Check calendars, task lists, and deadline reminders. Review sharing links and guest permissions too; blocking one account may leave other routes to a file.
Ask the administrator to check OneDrive retention and deletion settings before account deletion or license removal. Do not assume files remain available indefinitely. Moving working files does not replace required preservation.
Collect firm laptops, phones, keys, and security devices. Record who received them and preserve required local records before reuse or erasure.
For a personal phone, confirm what the firm is authorized and equipped to remove. Selective wipe targets company data in supported managed apps; a full device wipe can remove personal data too. Check the result. A pending request is not completed removal, and account blocking does not erase downloaded copies.
6. Use an offboarding worksheet
Copy this table into the departure record. Replace roles with names and add a row for each actual system or device.
Departure details: person leaving; coordinator; cutoff date, time, and time zone; attorney approving preservation; completion reviewer.
| System or property | Owner | Completion check | Records or work to hand over |
|---|---|---|---|
| Microsoft 365 sign-in | IT administrator | Sign-in blocked; existing sessions addressed; delays recorded | Email and file preservation plan |
| Email mailbox | Email administrator | Former-user access removed; forwarding and approved readers checked | Required email and incoming client inquiries |
| OneDrive, shared folders, Teams | File-system owner | Permissions and sharing checked; successor can open approved files | Matter files and required conversations |
| Matter and document systems | Software administrator | Account disabled; sessions addressed; tasks reassigned | Documents, deadlines, notes, activity history |
| Client portals and court filing | Portal owner or outside contact | Firm access or association changes confirmed | Continuing access for authorized staff |
| Billing, e-signature, other services | Each software owner | Account and approval rights removed | Billing records, signed documents, outstanding work |
| Remote access and admin accounts | IT administrator | Access and connections ended; known shared credentials rotated | Transferred responsibilities and relevant access records |
| Devices, keys, security devices | Office manager and IT | Return documented; approved data removal confirmed | Required local files; unresolved copies or missing property |
For every row, record completion date, evidence location, reviewer, and status: Verified, Pending, or Not Applicable. Explain Not Applicable entries. Give pending items an owner and follow-up date.
Request dated confirmation or a saved change record. Keep passwords and unnecessary client details out of the worksheet.
Before closing the departure, check both outcomes: access is removed from the identified systems, and authorized staff can retrieve records and continue the work. Keep unresolved items visible.
If you find suspicious forwarding, downloads, or access, preserve available evidence and involve the firm's incident lead. The first 72-hour incident response playbook explains the broader response.
Check the process before the next departure
Use the Microsoft 365 security checklist for the broader account review. The law firm document security guide explains why permissions and copies matter beyond the office network.
If any step is unclear, or you would like help carrying it out, Contact Us. You do not need to diagnose the issue first. We can clarify what to ask your administrator, help assess what needs attention, and discuss authorized support alongside your existing IT provider.
The right next step depends on the need. A Law Firm Security Baseline assesses agreed safeguards and evidence; it does not include remediation. Email & Microsoft 365 Security can help with agreed email and account work. Other systems, device changes, and record-preservation tasks need their own review and scope.
Close the departure when you can show who removed access, who checked it, and who now owns the work.
