top of page
CETech 20 year logo.png
CETech 20 year logo.png

When the Seasonal Help Leaves: The Offboarding Checklist Most Businesses Skip

4 hours ago
6 min read

Fall is the quietest turnover season of the year around here, and also one of the busiest. The summer help finished up in August. The college interns went back to campus. A few people used the end of summer as their natural moment to give notice. And in about five weeks, holiday and year-end hiring starts for the retail, food service, and logistics side of Western New York, which means a wave of short-term accounts is about to be created.


Every one of those transitions leaves something behind. Not a badge or a parking pass, those come back. What stays is access. A mailbox that still receives. A VPN profile that still connects. A shared password in a spreadsheet that four people still use, one of whom does not work there anymore. We write a lot about phishing and ransomware because that is where the headlines are, but a meaningful share of the incidents we are called into start with an account that should have been closed and was not.


We have written before about the risk in onboarding a new employee. Offboarding is the other half of that story, and it gets far less attention because nobody is excited about it. Nobody schedules a kickoff meeting for a departure. It happens on somebody's last afternoon, usually while their manager is also covering their work, and it gets done from memory.




Why the leftover account is such a good target



An abandoned account is attractive for a simple reason: nobody is watching it. If an attacker gets into your accounting manager's live account, there is a decent chance somebody notices the strange login prompt or the sent mail they do not remember sending. If an attacker gets into the account of somebody who left in July, nothing looks wrong to anyone. There is no user to be suspicious. The mailbox keeps receiving internal announcements, invoices, and vendor threads, and it can sit there quietly for months feeding a very well-informed impersonation attempt.


That is the part business owners tend to underrate. The value of a dormant account is not always the data inside it. It is the credibility of the address. An email that comes from inside your own domain, referencing a real project, with the right signature block, will get a wire instruction changed faster than any spoofed outside address ever will.




What usually gets missed



When we audit a client's user list for the first time, the disabled-but-not-really accounts follow a pattern. The obvious things are handled. The email password got changed, the computer came back to the office. It is the second and third layer that hangs around.



  • Personal devices still enrolled in email, including the phone they answered work messages on

  • Authenticator apps and MFA tokens still registered to their phone, which can be used to approve access

  • Shared or service account passwords they knew, which do not change when their own password does

  • Line-of-business software logins managed by a vendor rather than by your IT system

  • Remote access, VPN, and remote desktop profiles that live outside your main directory

  • Cloud file shares with links they created that are still set to anyone-with-the-link

  • Social media, review platform, and marketing tool logins, often tied to their personal email

  • Building and camera systems with their own separate user list nobody thinks of as IT

  • Forwarding rules they set up on their own mailbox before leaving



That last one deserves a note. A mail forwarding rule is one of the quietest ways data walks out of a business, and it survives a password change. If you only do one thing after reading this, check for forwarding rules on the mailboxes of everyone who left in the last year.




Disable, do not delete



There is a real temptation to clean up by deleting the account outright. Resist it for a while. Deleting a mailbox can destroy records you may need, break shared calendars and distribution lists, and orphan files the person owned in cloud storage. It can also complicate a legal or insurance matter later, and if something turns up six months from now, the logs and contents of that account are your evidence.


The better sequence is to disable sign-in immediately, revoke active sessions and tokens so existing logged-in devices are kicked out, reassign ownership of files and shared resources to a manager, convert the mailbox to a shared mailbox or set a forward to a supervisor so customer emails do not vanish into nothing, and only then, after a defined retention period, remove it. Pick the retention period on purpose and write it down. Thirty days, ninety days, a year for management roles. The number matters less than having one.


Revoking sessions is the step that gets skipped most often. Changing a password does not always log out a device that is already signed in. If you do not explicitly kill the session, a phone in somebody's pocket can keep pulling mail for days.




Seasonal and temporary staff need an expiration date



Here is where the fall calendar works in your favor. You know in advance that holiday help is temporary. So build the end into the beginning. When the account is created, set it to expire on a date. Most modern directory systems support account expiration natively, and it turns offboarding from a task somebody has to remember into something that happens whether anybody remembers or not.


The same logic applies to contractors, seasonal drivers, and the vendor technician who needed access for a one-week project in October. Give the access, scope it to what the work actually requires, and put an end date on it the day you turn it on. It is far easier to extend access that is about to expire than to discover access that never did.








Decide who owns the handoff



Most offboarding failures are not technical. They are handoff failures. HR knows somebody left. The manager knows what systems they touched. IT can close accounts but only if somebody tells them a departure happened. When those three do not connect, accounts stay open, and everyone involved assumed the other two had it.


The fix is boring and it works: one written checklist, one named owner, and one trigger. The trigger is notification of the departure. The owner is a specific person, not a department. The checklist is the same every time, so the Friday afternoon rush cannot shorten it. For the businesses we manage, that trigger comes to us as a ticket, we run the technical steps, and we send back written confirmation of what was disabled and when. The confirmation matters as much as the work. If your cyber liability carrier or a compliance auditor ever asks how you handle terminations, a documented answer is the answer they want.




A quick audit you can run this month



You do not need a project to get value here. Pull a list of every user account in your email and directory system and read it out loud with your managers in a room. People recognize names faster than they recognize spreadsheets. Flag anyone who no longer works there, anyone nobody can identify, and any account that is not a person, and find out what each service account is actually for and who owns it.


Then check three things on the accounts of everyone who left in the past year: sign-in is blocked, no mail forwarding rules exist, and no devices are still enrolled. Look at the last sign-in date on every account, because an account that should be dormant and shows recent activity is the single clearest warning sign you will get.


If that list is longer than you expected, you are in normal company. Turnover is constant, the steps live in several different systems, and none of it is anybody's actual job description. That is exactly the gap a managed IT partner is supposed to close.




Let us take the checklist off your plate



CETech has been handling user onboarding and offboarding for Rochester and Buffalo businesses for over twenty years, across manufacturing, construction, engineering, healthcare, trucking, and property management. If you would like us to audit your current user list, or build an offboarding process you do not have to remember, reach out. Call 585-441-0055, email [email protected], or use the contact form at cetechno.com and we will start with the list.


Comments


bottom of page