Said It Here

How to catch all account dependencies during user offboarding

Standard offboarding catches email and licenses, but misses hidden dependencies like Power Apps, custom flows, and SharePoint ownership tied to the departing account. This leaves administrators manually digging through every admin center to prevent broken workflows and orphaned assets.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Manually checking every separate admin center
  2. 2
    Disabling the account immediately and dealing with broken dependencies only when someone complains
  3. 3
    Relying on department managers to figure out what needs to be reassigned
  4. 4
    Deleting the user and restoring the account later if issues arise
  5. 5
    Exporting only the required site or data and deleting the rest of the unauthorized information
  6. 6
    Using local controllers or dedicated hardware per client instead of multi-tenant cloud controllers

In their words

Unedited, most upvoted first, each linked to the thread it came from.

When someone leaves, the obvious checks are email, OneDrive, groups and licences. But what about Power Apps, flows, connections, SharePoint ownership and other dependencies tied to that account?source ↗

Has anyone found a reliable offboarding process that catches everything without checking every admin centre manually?source ↗

Emergency_Recipe522 · r/sysadmin · 101 upvotes

I had access to every mailbox in the org. Checked the account and they'd given me, it was a full global admin account for their entire tenant.source ↗

CptUnderpants- · r/msp · 1 upvotes

We’ve received full backups from a competitor every time we acquire a client from them.source ↗

mtn970 · r/msp · 1 upvotes

Where this came up

People with this problem also raised