EMPLOYEE DEPARTURE

The account is disabled.
Are its access rights really gone?

Disabling an account in the directory (Entra ID / Active Directory) blocks the sign-in, but not necessarily the delegations, forwarding rules, OAuth applications, or Teams channel memberships that employee had accumulated. Offboarding Express precisely verifies what remains active, beyond the directory.

5
Areas checked beyond the directory
4
Technical rails queried
0
Raw data copied (zero-knowledge)
1
Proof report per departure

The problem

A disabled account is not the same thing as an employee who is fully disconnected from your systems

Disabling the account is not enough

Blocking the sign-in in the directory stops direct access, but the delegations it held on shared mailboxes, or the forwarding rules it had configured, can remain active independently of the account.

🔐

OAuth applications keep running

An employee may have authorized third-party applications (calendar, CRM, browser extensions) that retain access to company data independently of their user account.

💬

Teams channels do not clean themselves up

Membership in teams, channels and their associated shared files often persists long after the last working day, with no alert flagging it.

The risk accumulates with every departure

Without a systematic check at each departure, these residual access rights pile up over the years and become forgotten entry points, invisible from the directory.

The solution: Offboarding Express

A multi-rail verification engine, the same one used for the SYAGA M365 audit, applied to an employee's departure

1
Step 1 - Report the departure

You tell us which account is concerned

Name of the departed (or departing) employee and the planned access cut-off date. No installation required on your side.

2
Step 2 - Multi-rail query

Searching for any residual trace tied to the account

Our engine queries the Microsoft Graph, Exchange Online, Teams and Purview rails to find delegations on shared mailboxes, automatic forwarding rules, OAuth consents and Teams channel memberships.

3
Step 3 - Local pseudonymization

Zero-knowledge principle, as with the M365 audit

Sensitive identifiers are pseudonymized before any analysis. No raw data is copied or kept on our servers: only the measurement is transmitted.

4
Step 4 - Proof report

What was checked, what was found

You receive a report listing each checked area with its status (closed / active / to verify), along with recommendations to permanently close what remains open.

What you receive

A concrete report on the actual access status of an account, beyond the status shown in the directory

📋

Departure control report

Detailed status (closed / active / to verify) for each of the areas checked on the account concerned.

  • Delegations on shared mailboxes
  • Automatic forwarding rules
  • OAuth consents / third-party applications
  • Teams channel memberships
  • Residual rights beyond the directory
🔒

Timestamped audit proof

Technical trace of the verification performed, useful for an internal control or an incident involving a former account.

  • Timestamp of the verification
  • Rails queried and results obtained
  • Zero raw data retained (ZK)
  • Format usable for your internal file

Closure recommendations

Prioritized list of actions to carry out on your side to permanently close the access rights identified as active.

  • Actions prioritized by criticality
  • Precise reference to the object to close
  • HTML + PDF formats
  • Reusable for the next departure

A check aligned with recognized good practice

Managing access rights when an employee leaves is part of common security frameworks

GD

GDPR (Art. 32)

Appropriate technical and organizational measures to ensure the security of personal data. The effective revocation of a departed employee's access rights directly contributes to this security obligation.

AN

ANSSI guide - IT hygiene

The French cybersecurity agency ANSSI's IT hygiene guides recommend rigorous management of accounts and access rights, including their complete removal when employees leave.

ISO

ISO 27001 - Access management

Managing access rights throughout an employee's lifecycle, including their removal at the end of the contract, is part of the organizational controls covered by the standard.

GP

Good cyber governance practice

A systematic review of residual access when an employee leaves is part of a general cyber risk management approach, without by itself constituting a specific regulatory obligation.

Plans adapted to your departure volume

A personalized quote in all cases - no price shown here is fixed in advance

One-off

A single departure, on request

Quote
single verification
  • Verification of the 5 checked areas
  • Timestamped proof report
  • Closure recommendations
  • HTML + PDF formats
Request a quote

Custom

Multi-tenant, subsidiaries, large volumes

Quote
based on scope
  • Everything in Recurring +
  • Multi-tenant / multi-subsidiary
  • Integration study with your HR tool
  • Support for closure on your side
Request a quote

Frequently asked questions

The account is already disabled in the directory, why check anything else?
Disabling an account in Entra ID or Active Directory blocks the sign-in, but not necessarily the delegations it held on shared mailboxes, the forwarding rules it had configured, the OAuth consents it granted to third-party applications, or its membership in Teams channels. These elements often remain active independently of the account's status.
How does the technical verification work?
Our engine reuses the same multi-rail architecture as the SYAGA M365 audit: querying Microsoft Graph, Exchange Online, Teams and Purview to find any trace tied to the account concerned. No manual intervention on your tenant, no installation.
Is my data sent to SYAGA?
No. As with the M365 audit, the principle applied is zero-knowledge: sensitive identifiers are pseudonymized locally before any analysis, and no raw data is copied or kept on our servers.
What should I do once I receive the report?
The report precisely lists the residual access rights identified and the associated closure recommendations. Actually cutting off access (revoking delegations, removing OAuth consents, removing Teams channel memberships) remains carried out by your teams, or by SYAGA on additional request.
Does this replace a full security policy or a complete security audit?
No. Offboarding Express is a targeted check on a specific event: an employee's departure. For a complete security policy, see PSSI Express. For a comprehensive and ongoing M365 audit, see the SYAGA Audit.
Can this be integrated into our existing HR process?
Yes. In the Recurring or Custom plan, the verification can be triggered on each departure notice sent by your HR or IT teams, with no additional manual intervention on your part.

A departure underway or upcoming?

Contact us to receive a personalized quote.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu
Offboarding Express is a technical support tool and does not constitute legal advice. The compliance of your departure procedures with GDPR or your sector-specific obligations must be confirmed by legal counsel.