Who Still Has Access to Your Business?

Harrison
09.01.26 02:22 PM Comment(s)

The Employee Left. Their Access Didn’t.

Disabling an email account is not the same thing as offboarding an employee.

In February 2025, two IT employees at a government contractor were fired during a remote meeting. According to federal court records, about five minutes after the termination, one of the employees attempted to reconnect to the company’s network. He couldn’t. His VPN connection had been deactivated and his Windows account had been disabled.

His brother, however, was still connected. About a minute later, he began deleting databases. Over the next hour, approximately 96 databases containing U.S. government information were deleted. In May 2026, a federal jury convicted one of the brothers on charges related to the incident.

It’s an extreme example, but it highlights a problem businesses of every size need to think about: when an employee leaves your company, are you certain they can no longer get in?

You Can't Remove Access You Don't Know Exists

This is often the biggest problem. Imagine an employee who has worked at your company for five years. During that time, they’ve been given access to Microsoft 365, QuickBooks, a CRM, your website, a vendor portal, social media accounts, a security camera system, and several industry-specific applications.

Does anyone have a complete list?

If your answer is “probably,” that’s a problem.

Businesses accumulate technology over time. Someone signs up for a service to solve a problem. A manager shares a password. An employee creates an account with their company email. Five years later, nobody remembers who has access to what. Then the employee leaves, their Microsoft account gets disabled, everyone checks the “offboarding” box, and several other doors may remain wide open.

You can’t revoke access you don’t know exists.

This is one reason we strongly recommend businesses use a company-managed password manager. Instead of passwords being saved in browsers, spreadsheets, sticky notes, or an employee’s personal password manager, company credentials can be centrally managed. That gives the business much better visibility into which credentials an employee has been granted access to.

When an employee’s role changes, their access can change with them. When they leave, they can be removed from shared vaults, and sensitive credentials can be rotated when necessary. Even better, businesses should avoid shared accounts whenever a service allows it. Giving each employee their own login creates accountability and makes it much easier to remove one person’s access without disrupting everyone else.


Offboarding Actually Starts During Onboarding

The best time to figure out how you’re going to remove someone’s access isn’t the day you fire them. It’s the day you give them access.

Every new application, account, permission, and credential should be managed with the assumption that someday that employee will change roles or leave the company. Ideally, onboarding should create a clear record of what each employee has access to. If they’re given access to another application six months later, that should be documented too.

When this is done well, offboarding becomes the reverse of onboarding. You know which accounts need to be disabled, which applications need to be removed, which shared credentials the employee had access to, and which company files need to be transferred.

Without that visibility, offboarding becomes a scavenger hunt, and the things you don’t find are often the things that create the most risk.

A Good Lockout Process Matters

Once you know what an employee has access to, you need a consistent process for removing that access.

Most businesses know they should disable an employee’s email account when that employee leaves. That’s important, but it’s only one part of a proper lockout. An employee may still have an active session on a laptop, phone, VPN connection, browser, or cloud application. They may still have access to shared accounts, company files, administrative systems, or third-party services that aren’t directly connected to their primary company account.

A good lockout process should disable the employee’s primary account, revoke active sign-in sessions and authentication tokens, remove VPN and remote-access permissions, remove access to company applications and shared mailboxes, and eliminate unnecessary group memberships or administrative privileges. Company email and files should be transferred where appropriate, company devices should be recovered, access to shared credentials should be removed, and sensitive passwords should be rotated when necessary.

Timing matters too. For an involuntary termination, IT access shouldn’t be removed several hours later, or whenever someone remembers to send IT an email. Access should be terminated at the time the employee is notified, and in some cases immediately before.

You don’t need to be a company hosting databases for the federal government for this to matter. Your email, customer records, accounting systems, files, and passwords are valuable too.

When an employee leaves, don’t just ask, “Did we disable their email?”

Ask the more important question:
“Are we certain they can no longer access the business?”