PROCEDURE WI for offboarding a kpe employee.
Phase 1: Steps 1-12
Phase 2: Steps 13-17
REQUIREMENTS
-
This process must be intiated/authorized by the kpe Client POC(s) and include the Employee Offboarding Form (reference KB00002470 [retired])
-
M365 Admin Console Access: PWS > Domain\Service Accounts > M365 Admin Account
-
SMS MFA PHASE 1 STEPS
- Open & review Employee Offboarding Form
- Log into the M365 portal
- Find the user account being terminated
- Click Reset password
- Generate random secure credentials
- Click Block Sign in
- Click Sign out of all sessions
- On the left-hand side of the page, navigate to the Azure Portal.
- From the Azure portal, go to the Users tab on the left-hand side, then search and select the terminated User.
- From the User’s page, select Authentication Methods on the left-hand side. Verify all contact information is removed and recorded in the offboarding ticket.
- Select the 3 dots at the top, then select Revoke MFA Sessions. Hit Save once complete.
- Navigate to the Groups tab on the left-hand side. Then check all groups (record them all in the ticket) and Remove Memberships. Close out of the Azure portal once complete. (All Users should be the only one that will not remove)
- Check the Off-boarding Form for the following actions:
- If Archive Users Mailbox is checked. Convert the user’s mailbox to shared mailbox
- If Forward emails is checked. Forward emails to the designated person
- If Auto-reply is checked. Please set the standard reply below:
- (Text for Auto Reply)
- PHASE 2 STEPS:
- Check the Off-boarding Form for the following actions:
- If backup of local users’ data is checked. Ensure the following folder is created (Screenshot further below for example): Sharepoint > Terminated Users > Documents > [First Last] > Local Data
- IMPORTANT: Verify if Onedrive is enabled and fully synced!
- Move all non-synced data from local computer to location provided above (eg Downloads, Pictures, C:\ and D:\)
- IMPORTANT**:** Take screenshots and post in public notes of the ticket! Recommend Treesize to show size and make sure Sharepoint shows similarly.
- If backup of one-drive data is checked. Ensure the following folder is created (Screenshot further below for example): Sharepoint > Terminated Users > Documents > [First Last] > Onedrive
- IMPORTANT: Verify if Onedrive is enabled and fully synced!
- Use move command via M365 Admin Center to location provided above for Onedrive.
- IMPORTANT: Take screenshots and post in public notes of the ticket!
- If grant access to termed employee data is checked. Grant the requested access to the end-user.
- IMPORTANT DATA SANITIZATION INFORMATION:
- If DO NOT delete local user data is checked, DO NOT delete any data off the local computer
- Otherwise, delete all local user data once data transfer steps have been confirmed complete. This allows the device to be reassigned and re-used later.
- Remove license from account
- Send ticket to procurement to remove the license from the portal.
- IMPORTANT
- Assigned ticket to vITM for removal of PII Protect account! DO NOT close the ticket.
REFERENCES
- See attached offboarding form for KPE that the client uses