Disabling an account in the directory (Entra ID / Active Directory) blocks the sign-in, but not necessarily the delegations, forwarding rules, OAuth applications, or Teams channel memberships that employee had accumulated. Offboarding Express precisely verifies what remains active, beyond the directory.
A disabled account is not the same thing as an employee who is fully disconnected from your systems
Blocking the sign-in in the directory stops direct access, but the delegations it held on shared mailboxes, or the forwarding rules it had configured, can remain active independently of the account.
An employee may have authorized third-party applications (calendar, CRM, browser extensions) that retain access to company data independently of their user account.
Membership in teams, channels and their associated shared files often persists long after the last working day, with no alert flagging it.
Without a systematic check at each departure, these residual access rights pile up over the years and become forgotten entry points, invisible from the directory.
A multi-rail verification engine, the same one used for the SYAGA M365 audit, applied to an employee's departure
Name of the departed (or departing) employee and the planned access cut-off date. No installation required on your side.
Our engine queries the Microsoft Graph, Exchange Online, Teams and Purview rails to find delegations on shared mailboxes, automatic forwarding rules, OAuth consents and Teams channel memberships.
Sensitive identifiers are pseudonymized before any analysis. No raw data is copied or kept on our servers: only the measurement is transmitted.
You receive a report listing each checked area with its status (closed / active / to verify), along with recommendations to permanently close what remains open.
A concrete report on the actual access status of an account, beyond the status shown in the directory
Detailed status (closed / active / to verify) for each of the areas checked on the account concerned.
Technical trace of the verification performed, useful for an internal control or an incident involving a former account.
Prioritized list of actions to carry out on your side to permanently close the access rights identified as active.
Managing access rights when an employee leaves is part of common security frameworks
Appropriate technical and organizational measures to ensure the security of personal data. The effective revocation of a departed employee's access rights directly contributes to this security obligation.
The French cybersecurity agency ANSSI's IT hygiene guides recommend rigorous management of accounts and access rights, including their complete removal when employees leave.
Managing access rights throughout an employee's lifecycle, including their removal at the end of the contract, is part of the organizational controls covered by the standard.
A systematic review of residual access when an employee leaves is part of a general cyber risk management approach, without by itself constituting a specific regulatory obligation.
A personalized quote in all cases - no price shown here is fixed in advance
A single departure, on request
Frequent departures, integrated into your HR/IT process
Multi-tenant, subsidiaries, large volumes
Contact us to receive a personalized quote.
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu