Erkenntnisse in Maßnahmen umsetzen: Bitwarden Access Intelligence jetzt verfügbar Mehr erfahren >

Bitwarden-Ressourcen

IT offboarding checklist for secure credential and access removal

This IT offboarding checklist shows what IT, HR, and security must cover to deprovision credentials, SaaS accounts, SSO, MFA, and devices.

An IT offboarding checklist is a documented sequence of steps that removes a departing employee's access to every system, credential, and device connected to their role, with a named owner and deadline for each task.

Every departure leaves a trail of accounts, tokens, and shared logins that stay active until someone closes them. A role-based checklist makes closure predictable across credentials, software-as-a-service (SaaS) access, single sign-on (SSO), multifactor authentication (MFA), and devices.

What is an IT offboarding checklist?

The checklist gives IT, HR, and security a shared record of what needs to happen, in what order, and by when. Its scope ranges from account closure to asset reclamation and business continuity.

An employee offboarding checklist covers the full transition, from payroll to knowledge transfer. The IT portion narrows to one question: which accounts, credentials, and systems did this person hold, and how are each closed or reassigned? Directory accounts, application logins, shared vault entries, application programming interface (API) keys, certificates, and active browser sessions all fall inside that scope. The rigor applied when granting access belongs at the point of removal, which is why many teams document access deprovisioning and account creation in a single onboarding and succession planning guide.

Why an IT offboarding checklist reduces security risk

Access that outlives the role it was granted is one of the most tractable security problems an IT team owns, and offboarding credentials on schedule directly closes it. The IBM Cost of a Data Breach Report 2025 puts the global average breach cost at $4.44 million, with malicious insider activity as the costliest initial vector at $4.92 million, because trusted access looks like normal behavior right up until it isn't. The same report puts the average time for breach identification and containment at 241 days, a window during which access left open after a departure continues to generate activity attributed to a name no longer on the payroll. Closing it on schedule is one of the higher-leverage controls available.

The CISA Insider Threat Mitigation Guide recommends a program spanning security, HR, and legal for insider risk, including former employees. A role-based checklist puts that split into practice on every exit.

Where account disablement leaves gaps

Disabling one user record closes one path. Several others survive the directory change:

  • Shared credentials. A vendor portal login that circulates across a team stays valid until the password rotates.

  • Active sessions and tokens. Refresh tokens and long-lived sessions persist until someone revokes them.

  • Local and cached access. Credentials cached in browsers or on personal devices remain readable.

  • Direct application accounts. A tool bought on a team credit card sits outside the central directory, and it becomes an orphaned account the moment its creator leaves.

Mapping those gaps to specific systems is what makes a checklist auditable rather than a matter of memory. Building an application inventory into the checklist keeps these tools visible, and IT user management and access controls keep that record current between departures.

Which systems should the checklist cover?

Coverage determines whether the rest of the process holds. The table below maps the categories worth confirming on every departure.

Three of these categories carry most of the risk, and each calls for a different technique to close.

Start with SSO deprovisioning and MFA revocation

The identity provider is the fastest lever available. Removing SSO assignments closes all connected applications at once, and MFA revocation occurs in the same pass, so a recovery flow cannot restore access later. It is good practice to configure the session timeout duration between SSO reauthentication ahead of time.

Shared password rotation matters most for logins that keep working regardless of whose account is disabled. SaaS offboarding requires the same tool-by-tool treatment for orphaned accounts; the rotation itself is the step that turns a closed account into a closed access account.

Devices, sessions, and data handoff belong in the same window, before the account closes: collect hardware, revoke certificates, terminate active sessions, and transfer file ownership. Ownership transfer is the step most often deferred, turning a routine departure into a data recovery project.

IT offboarding checklist template

Knowing which systems to cover answers half the question. The other half is who acts on each one, which makes the checklist role-based as much as task-based. HR triggers the process and owns the dates, IT executes every revocation and reassignment, and security validates the result and retains the record. High-risk departures, such as a systems administrator's, warrant coordinating to the hour instead of the day.

Before departure

Automation pays off most in this phase, synchronizing the account inventory before anyone opens the list.

  • HR: Confirm the separation date and effective time.

  • IT: Inventory every account, shared credential, and application the person holds.

  • IT: Identify shared logins the person can view and schedule their rotation.

  • IT: Assign a recipient for each file and application the person owns.

  • Security: Flag privileged access, including cloud console roles and production systems.

  • IT: Confirm the device return method.

Day of departure

These steps run in sequence on the separation date, permanently removing access rather than just disabling it.

  • IT: Disable the directory account and revoke SSO assignments.

  • IT: Terminate active sessions and revoke refresh tokens.

  • IT: Remove MFA registrations, backup codes, and hardware keys.

  • IT: Rotate every shared password the person had access to.

  • IT: Revoke API keys, personal access tokens, deploy keys, and certificates.

  • IT: Remove the person from shared vault collections and groups.

  • IT: Transfer ownership of files and any service accounts they controlled.

  • IT: Collect devices and revoke VPN and device certificates.

  • HR: Suspend the mailbox per the retention policy.

Post-departure validation

Validation is what turns a completed checklist into evidence, and it belongs in the week after the departure, not the same afternoon.

  • Security: Review audit logs for authentication attempts on the closed accounts.

  • Security: Confirm the directory reports no active sessions for the user.

  • Security: Verify that shared credential rotation has been completed across every collection.

  • IT: Reconcile the application inventory against remaining licenses.

  • Security: File the completed checklist with the separation record.

  • IT: Schedule a 30-day review to catch anything the first pass missed.

When employee offboarding software improves the process

A manual template holds up for a handful of departures per quarter, but strains when a single HR event has to traverse dozens of connected systems. Directory synchronization solves that by automatically propagating status changes to every connected application, and audit logs turn validation into a query rather than a screenshot exercise. Identity governance closes the remaining gap, extending the offboarding workflow to shared credentials that an automated inventory does not reach, and the IT due diligence and security checklist covers how to keep that inventory current.

How Bitwarden supports cleaner access removal

Identity providers govern accounts, but they do not hold the shared passwords, keys, and secrets alongside those accounts. Bitwarden Password Manager stores those credentials with end-to-end encryption, and collection-based sharing answers the ownership question directly, showing exactly who could see each login, with audit logs that turn post-departure validation into a review rather than a reconstruction.

The Centralize organization ownership policy reinforces this by preventing members from storing items in a private individual vault in the first place: items are saved to an organization-owned My Items location instead, so departing employees never accumulate credentials that only they can see. After a member is removed, the data in that member's My Items stays with the organization, closing off the scenario where offboarding leaves shared logins stranded in a personal vault no one else can reach.

System for Cross-domain Identity Management (SCIM) provisioning and SSO compatibility connect the platform to existing identity infrastructure, so a directory status change propagates without a second manual step. Bitwarden Directory Connector keeps that synchronization running as part of employee lifecycle management. Bitwarden is a zero-knowledge encryption solution, and the business identity and access management strategy covers how these capabilities fit into a broader access strategy.

Build a repeatable access removal process with Bitwarden

Credential visibility and repeatable deprovisioning make employee transitions predictable. An access removal checklist that names owners, rotates shared credentials, and validates its own results holds up on every departure, independent of institutional memory. The next departure is already on someone's calendar; see how Bitwarden Password Manager powers identity and access management, and put the process in place before that date arrives.

Sorgen Sie jetzt für leistungsstarke, vertrauenswürdige Passwortsicherheit und wählen Sie Ihr Abo.