Employee Termination Playbook
Offboarding Request submitted through Freshservice
Active Directory
- Freshservice disables user
- Freshservice removes memberships to O365 Deployment
- Freshservice removes Office, Department, Company, sets disable date in Description, sets End of date
- Manual tasks:
- Set attribute for msExchHideFromAddressLists to TRUE
- Remove Manager
- Reassign direct reports (if needed)
Microsoft 365/Azure Active Directory
- Freshservice blocks user from accessing M365
- Freshservice changes password
- Freshservice converts mailbox from User to Shared
- Freshservice sets Out of Office message to indicate they're no longer with CS
- Freshservice removes M365 licenses
- Manual tasks:
- Copy group membership in AAD to Excel
- Store with Employee OneDrive data
- Remove user from M365 groups and security groups (e.g., Tango SSO)
- Transfer OneDrive data to SharePoint
- Delete OneDrive data after it's been moved
Mimecast
- Manual tasks:
- Grant manager access to employee's account (delegate mailbox)
- Remove/transfer other softwares as appropriate:
- GitHub
- RoboForm
- Asana
- Adobe
- ESRI
- SurveyMonkey
- Mural
- Mentimeter
- Slack
- Tango
- Other
Hardware
- Retrieve hardware from user
- Check C:/local drive for data
- Wipe drive
- Delete object from AD
- CS mobile - return to CS and reset to Factory Settings
Brivo/WinPak
- Revoke user
Other
- Communicate data location and Mimecast access to manager
- Decomm and retire the object in Freshservice
Termination Request received through T&C
Begin at start of T&C meeting with employee
Microsoft 365/Azure Active Directory
- Convert mailbox from User to Shared
- Set Out of Office message to indicate they're no longer with CS
Begin at conclusion of T&C meeting with employee
Active Directory
- Disable user
- Remove memberships to O365 Deployment
- Remove Office, Department, Company, set End of date, set disable date in Description
- Manual tasks:
- Set attribute for msExchHideFromAddressLists to TRUE
- Remove Manager
- Reassign direct reports (if needed)
Microsoft 365/Azure Active Directory
- Block user from accessing M365
- Change password
- Convert mailbox from User to Shared
- Set Out of Office message to indicate they're no longer with CS
- Remove M365 licenses
- Manual tasks:
- Copy group membership in AAD to Excel
- Store with Employee OneDrive data
- Remove user from M365 groups and security groups (e.g., Tango SSO)
- Transfer OneDrive data to SharePoint
- Delete OneDrive data after it's been moved
Mimecast
- Manual tasks:
- Grant manager access to employee's account (delegate mailbox)
- Remove/transfer other softwares as appropriate:
- GitHub
- RoboForm
- Asana
- Adobe
- ESRI
- SurveyMonkey
- Mural
- Mentimeter
- Slack
- Tango
- Other
Hardware
- Retrieve hardware from user
- Check C:/local drive for data
- Wipe drive
- Delete object from AD
- CS mobile - return to CS and reset to Factory Settings
Brivo/WinPak
- Revoke user
Other
- Communicate data location and Mimecast access to manager
- Decomm and retire the object in Freshservice