Best Practices - When someone leaves your organization - What do you do?

%3CLINGO-SUB%20id%3D%22lingo-sub-142619%22%20slang%3D%22en-US%22%3EBest%20Practices%20-%20When%20someone%20leaves%20your%20organization%20-%20What%20do%20you%20do%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-142619%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20all%20-%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EJust%20looking%20to%20get%20some%20insight%20from%20some%20others%20on%20how%20you%26nbsp%3B%20handle%20this%20situation%20--We%20are%20running%20with%20all%20of%20our%20mailboxes%20in%20the%20cloud%20-%20in%20hybrid%20mode%20-%20with%20ADFS%26nbsp%3B%20and%20AADConnect.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWhen%20someone%20leaves%20your%20organization%20-%20what%20do%20you%20do%3F%26nbsp%3B%20Assume%20that%20someone%20needs%20access%20to%20this%20users%20email%20historically%2C%20that%20same%20person%20needs%20access%20to%20any%20new%20mail%20that%20comes%20in%20for%20that%20person%20for%20a%20period%20of%20time%20while%20the%20transition%20occurs.%26nbsp%3B%20Also%20-%20for%20security%2C%20the%20user%20that%20left%20needs%20to%20be%20revoked%20access%20to%20prevent%20any%20access%20to%20email%20post%20employment.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20seems%20to%20be%20a%20chain%20of%20events%20that%20should%20%2F%20could%20occur%20-%20user%20account%20gets%20disabled%2C%20either%20the%20mailbox%20gets%20delegated%20to%20the%20person%20that%20needs%20access.%26nbsp%3B%20At%20some%20point%2C%20all%20of%20the%20valuable%20information%20from%20the%20mailbox%20should%20be%20moved%20somewhere%20else%20and%20the%20mailbox%20be%20deleted%3F%26nbsp%3B%20Possibly%20an%20alias%20is%20created%20for%20the%20person%20that%20needs%20access%3F%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHow%20do%20you%20handle%20this%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%3C%2FP%3E%0A%3CP%3ESteve%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-142619%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-142648%22%20slang%3D%22en-US%22%3ERe%3A%20Best%20Practices%20-%20When%20someone%20leaves%20your%20organization%20-%20What%20do%20you%20do%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-142648%22%20slang%3D%22en-US%22%3E%3CP%3EHere%20is%20the%20official%20recommended%20sequence%20of%20events%20as%20they%20stand%20for%20managing%20former%20employees%26nbsp%3B%20-%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FRemove-a-former-employee-from-Office-365-44d96212-4d90-4027-9aa9-a95eddb367d1%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3ERemove%20a%20former%20employee%20from%20Office%20365%3C%2FA%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-142639%22%20slang%3D%22en-US%22%3ERe%3A%20Best%20Practices%20-%20When%20someone%20leaves%20your%20organization%20-%20What%20do%20you%20do%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-142639%22%20slang%3D%22en-US%22%3E%3CP%3EBelow%20is%20a%20good%20blog%20post%20(it's%20old%20but%20it%20still%20applies%20most%20part)%3C%2FP%3E%0A%3CP%3EOffice%20365%20%E2%80%93%20How%20to%20Handle%20Departed%20Users%20(Part%201%20of%202)%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.perficient.com%2Fmicrosoft%2F2015%2F04%2Foffice-365-how-to-handle-departed-users-part-1-of-2%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.perficient.com%2Fmicrosoft%2F2015%2F04%2Foffice-365-how-to-handle-departed-users-part-1-of-2%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20it%20helps%3C%2FP%3E%0A%3CP%3ERavs%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-142631%22%20slang%3D%22en-US%22%3ERe%3A%20Best%20Practices%20-%20When%20someone%20leaves%20your%20organization%20-%20What%20do%20you%20do%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-142631%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20located%20entirely%20in%20the%20US.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-142628%22%20slang%3D%22en-US%22%3ERe%3A%20Best%20Practices%20-%20When%20someone%20leaves%20your%20organization%20-%20What%20do%20you%20do%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-142628%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAll%20depends%20on%20where%20in%20the%20world%20you%20are%20located.%20Within%20the%20EU%20or%20E%C3%98S%20area%2C%20where%20the%20GDPR%20regulation%20starts%20on%2025th%20of%20may%202018%20-%20you%20will%20have%20to%20delete%20the%20mailbox%20as%20this%20is%20considered%20personal%20data.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20do%20already%20enforce%20this%20policy.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBR%3C%2FP%3E%0A%3CP%3ELeif%20Kruse%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hey all - 

 

Just looking to get some insight from some others on how you  handle this situation --We are running with all of our mailboxes in the cloud - in hybrid mode - with ADFS  and AADConnect.

 

When someone leaves your organization - what do you do?  Assume that someone needs access to this users email historically, that same person needs access to any new mail that comes in for that person for a period of time while the transition occurs.  Also - for security, the user that left needs to be revoked access to prevent any access to email post employment.

 

There seems to be a chain of events that should / could occur - user account gets disabled, either the mailbox gets delegated to the person that needs access.  At some point, all of the valuable information from the mailbox should be moved somewhere else and the mailbox be deleted?  Possibly an alias is created for the person that needs access?  

 

How do you handle this?

 

Thanks

Steve

 

4 Replies
Highlighted

Hi

 

All depends on where in the world you are located. Within the EU or EØS area, where the GDPR regulation starts on 25th of may 2018 - you will have to delete the mailbox as this is considered personal data.

 

We do already enforce this policy.

 

BR

Leif Kruse

Highlighted

We are located entirely in the US.  

Highlighted

Below is a good blog post (it's old but it still applies most part)

Office 365 – How to Handle Departed Users (Part 1 of 2)

https://blogs.perficient.com/microsoft/2015/04/office-365-how-to-handle-departed-users-part-1-of-2/

 

Hope it helps

Ravs

 

Highlighted

Here is the official recommended sequence of events as they stand for managing former employees  - Remove a former employee from Office 365.