What should be preserved before an employee account is disabled?¶
Before an employee account is disabled, preserve the records needed to understand the account, access, work activity and organisational context.
Avoid this assumption: Disabling the account is a neutral administrative step. It may terminate sessions, revoke tokens, stop synchronisation, remove delegated access and trigger automated retention or deletion.
Record the employee identifier, username, email address, role, department, manager, tenant and account status.
Preserve active sessions, linked devices, authentication methods, administrator roles, group memberships and delegated permissions.
Identify relevant email, cloud storage, messaging, audit logs, VPN records, business applications and security alerts.
Record ownership and access for shared mailboxes, folders, documents, service accounts and team resources.
Capture any organisational warning explaining what disablement will do to data, licences, retention, forwarding or recovery.
Do not disable the account before the incident, legal, HR, safeguarding and continuity consequences are understood.
Where immediate risk requires access to stop, use the least destructive effective measure and preserve the visible state first where practicable.
Record who authorised the action, when it occurred and what sessions, services or devices were affected.
Preserve provider or administrator confirmations and reference numbers.
Do not assume that the employee was the only person using the account or that disabling it prevents access through other credentials or copied data.
Preserve any out-of-office, forwarding, mailbox-delegation, device-management or licence setting that may change automatically when the account is disabled.
Operational takeaway¶
Preserve identity, permissions, sessions, shared resources, business data and audit context before disabling an employee account, and document every operational consequence.