ALLMSP Blog

Microsoft 365 User Lifecycle: Joiners, Movers, and Leavers

A practical Microsoft 365 joiner, mover, and leaver operating model for timely access, clean role changes, defensible offboarding, and responsible business-data custody.

Microsoft 365 joiner-mover-leaver-identity-lifecycle support for a Georgia business

The Microsoft 365 user lifecycle is a business process expressed through cloud identities. A new employee needs the right mailbox, applications, groups, Teams workspaces, SharePoint sites, device, and authentication methods at the right time. A person changing roles should gain new access and lose access that no longer fits. A departure requires swift containment without accidentally deleting records, stranding meetings, or abandoning OneDrive data. When these events are handled as unrelated tickets, both productivity and security depend on memory.

Microsoft Entra Lifecycle Workflows models joiner, mover, and leaver phases with reusable tasks and attribute-based execution conditions. That capability requires Microsoft Entra ID Governance or Microsoft Entra Suite licensing, and a newly created workflow is disabled so administrators can test it before broad use. Organizations without that entitlement can still build a disciplined lifecycle with approved forms, groups, scheduled tasks, checklists, and audit evidence. The operating design matters before the automation platform.

This guide defines handoffs among HR, managers, IT, security, records owners, and finance. It emphasizes effective dates, role-based access, license hygiene, data custody, and verification. It also separates tenant governance from day-to-day troubleshooting: the [ALLMSP Microsoft 365 category](https://www.allmsp.com/category/software-support/software-support-microsoft-365/) covers vendor administration, while [Software Support](https://www.allmsp.com/category/software-support/) offers the broader service context.

Key decisions at a glance

  • Use an authoritative HR or management signal with effective dates and named approvals; a ticket without business context is not a lifecycle control.
  • Assign routine access through role-based groups where practical, verify licensing capacity and usage location, and test the employee's real first-day workflow.
  • Treat internal moves as access redesigns that remove obsolete rights instead of only adding the new department's permissions.
  • Offboarding must coordinate sign-in blocking, session revocation, group and application access, device return, mailbox decisions, OneDrive custody, and retention requirements.
  • Automate only stable, well-understood steps and preserve human approval for exceptions, sensitive access, data disposition, and legal requirements.

Establish an Authoritative Lifecycle Signal and Access Model

Microsoft 365 support workflow: Establish an Authoritative Lifecycle Signal and Access Model
Microsoft 365 support workflow: Establish an Authoritative Lifecycle Signal and Access Model

Define which system or role is authoritative for legal name, preferred name, manager, department, location, employment type, start date, expected end date, and termination time. In a small business, that source may be an HR platform or a controlled manager form, but it must have an owner and approval chain. Normalize the data before it reaches Microsoft Entra ID because attributes drive dynamic groups, address lists, access packages, and automated workflows. Document how corrections are made without silently changing historical evidence.

Build a role-access catalog that maps job functions to Microsoft 365 groups, application access, Teams and SharePoint membership, shared mailboxes, administrative roles, devices, and license requirements. Keep baseline access separate from exceptions so a manager can recognize what is inherited and what needs explicit approval. Group-based licensing can assign and remove product licenses through membership, but administrators must verify available inventory, usage location, service-plan conflicts, and any direct assignments that would continue after group removal.

Decide which actions can be automated and which require human review. Stable tasks such as adding a standard group or disabling an account at a verified end time are candidates for automation; unusual administrator roles, sensitive sites, legal holds, and data disposition need accountable decisions. If Lifecycle Workflows is licensed, start from a suitable template, limit the first scope, run on-demand tests against nonproduction identities, and inspect workflow history before enabling schedules.

  • Name the authoritative source, data owner, approver, effective date, correction path, and evidence retained for every lifecycle event.
  • Map each business role to baseline groups, licenses, applications, devices, collaboration spaces, and prohibited combinations.
  • Separate standard entitlements from time-bounded exceptions and require a business owner for every exception.
  • Test automation against a small audience and confirm failure handling before it can change production identities.

Deliver a Joiner Experience That Proves Access, Not Just Provisioning

Microsoft 365 support workflow: Deliver a Joiner Experience That Proves Access, Not Just Provisioning
Microsoft 365 support workflow: Deliver a Joiner Experience That Proves Access, Not Just Provisioning

Begin before the start date with a validated identity record, manager approval, role selection, license availability, device requirement, and delivery location. Create the account early enough for synchronization and configuration, but control when credentials and access become usable. Assign routine services through role groups where practical, then handle exceptions as separate approvals. Avoid cloning another employee wholesale; hidden access, stale project membership, and direct license assignments are easily copied along with the intended configuration.

Coordinate device setup with identity readiness. The employee should register approved authentication methods, change any temporary credential through a protected process, enroll or validate the device where management is licensed, and complete first sign-in from the expected network. Test Outlook, Teams, OneDrive, required SharePoint sites, shared mailboxes, line-of-business applications, printers, and mobile access according to the role. The manager should confirm business access, while IT records any exception instead of declaring success after the mailbox opens.

Provide a concise orientation that explains where documents belong, how external sharing works, which collaboration workspace is authoritative, how to report a suspicious prompt, and where support begins. Record the person who delivered the device and badge, the recipient, time, asset identifiers, authentication registration outcome, and acceptance result. A reliable joiner process concludes with evidence that the employee can complete representative work without excessive privilege.

  • Verify identity attributes, manager, role, location, start date, device, license capacity, and exceptional approvals before provisioning.
  • Use groups for repeatable access and document every direct assignment that cannot yet be removed.
  • Test the employee's actual mail, meeting, file, application, device, and recovery flows on the first day.
  • Capture asset custody, authentication registration, manager acceptance, exceptions, and an owner for every unresolved item.

Treat Movers as Access Reviews With a Defined Effective Date

Microsoft 365 support workflow: Treat Movers as Access Reviews With a Defined Effective Date
Microsoft 365 support workflow: Treat Movers as Access Reviews With a Defined Effective Date

An internal transfer is not a smaller onboarding event. It can change the employee's manager, department, location, license needs, data ownership, administrative duties, segregation-of-duties constraints, and participation in confidential projects. Use the approved effective date to stage changes without granting the full old and new roles indefinitely. The former and new managers should identify access that must end, access that should continue temporarily, and responsibility for documents, shared mailboxes, teams, and approvals.

Generate a before-and-after access view that includes groups, enterprise applications, Teams and SharePoint memberships, shared mailboxes, delegated permissions, administrative roles, devices, and direct license assignments. Remove obsolete access as deliberately as new access is granted. Microsoft Entra access reviews can provide recurring review campaigns for supported group, application, guest, and role scenarios when properly licensed; otherwise, use exported membership evidence and manager attestation with the same attention to scope and completion.

Validate the new job's representative workflows and the loss of access that should end. If the employee must finish a prior project, specify the exact resource, reason, approver, expiration date, and review owner instead of preserving the entire former role. Reconcile licensing after the move because changing groups can add or remove service plans, while direct licenses may mask the intended result. Store the final access record with the effective date and approvals.

  • Require both the former and new manager to identify data, approvals, memberships, and duties that change.
  • Compare before-and-after groups, apps, collaboration spaces, delegated rights, privileged roles, devices, and licenses.
  • Give transitional access a narrow resource scope, explicit business reason, end date, and accountable approver.
  • Verify the employee's new work and confirm removal of obsolete access rather than checking additions alone.

Coordinate Leaver Containment, Data Custody, and Final Deletion

Use the authoritative departure time and risk classification to sequence offboarding. Typical actions include blocking sign-in, revoking sessions, resetting credentials where appropriate, removing privileged roles and group memberships, reviewing application access, disabling managed devices, and recovering physical assets. High-risk involuntary departures may require a confidential pre-staged plan; routine departures may allow knowledge transfer. Either way, the process needs a named coordinator and confirmation that each control completed rather than one unchecked bulk command.

Decide what happens to business mail and files before deleting the account. Microsoft documents options to convert a mailbox to shared, provide access to another person, configure forwarding for new messages, and remove the license when requirements permit. A shared mailbox normally does not require a license below 50 GB, but holds and advanced capabilities can change that conclusion. For OneDrive, set manager or secondary-owner handling, understand the configured deleted-user retention period, and account for retention policies or holds that override standard cleanup.

Deletion is the last governance step, not the first cost-saving action. Confirm mailbox disposition, meeting ownership, OneDrive custody, Teams and SharePoint ownership, records requirements, application dependencies, asset return, and finance approval before licenses or the identity disappear. Microsoft's current OneDrive lifecycle also includes behavior for unlicensed accounts, so validate the tenant's licensing and archival implications. Close the event with an evidence packet and review trends through the [Cybersecurity](https://www.allmsp.com/category/cybersecurity/) program; use [Contact ALLMSP](https://www.allmsp.com/contact-us/) when the lifecycle design needs outside help.

  • Sequence sign-in blocking, session revocation, privileged-access removal, application review, device action, and asset recovery.
  • Approve mailbox conversion or forwarding, meeting handling, OneDrive custody, site ownership, retention, and legal requirements.
  • Do not delete the account while a shared mailbox, forwarding configuration, data handoff, or application dependency still relies on it.
  • Retain timestamps, actor identity, command or workflow results, approvals, exceptions, returned assets, and closure acceptance.

Frequently Asked Questions

What are joiners, movers, and leavers in Microsoft 365?

Joiners are people entering the organization, movers are people changing roles or conditions, and leavers are people departing. Each phase changes identity attributes, groups, licenses, applications, devices, collaboration access, business-data ownership, and audit responsibilities.

Does Microsoft Entra Lifecycle Workflows require a license?

Yes. Microsoft states that Lifecycle Workflows requires Microsoft Entra ID Governance or Microsoft Entra Suite licensing for the relevant users and capabilities. Organizations without it can still operate a controlled process using groups, approved checklists, scripts, scheduled reviews, and retained evidence.

Should a new employee's access be copied from a coworker?

Usually not. Cloning can copy hidden project memberships, exceptions, privileged roles, and direct licenses that do not belong to the new employee. Start from an approved role profile, then add narrowly approved exceptions with owners and expiration dates.

How does group-based licensing help Microsoft 365 onboarding?

Membership in a configured group can assign and remove product licenses consistently. Administrators still need enough inventory, a valid usage location, compatible service plans, and checks for direct assignments that could preserve access after group removal.

What should be tested on a Microsoft 365 employee's first day?

Test authentication registration, primary sign-in, Outlook, Teams, OneDrive, required SharePoint sites, shared mailboxes, business applications, mobile or remote access, and the support path. The manager should confirm the employee can perform representative work.

Why are internal role changes a security risk?

Movers often keep old permissions while receiving new ones, creating accumulated access or segregation-of-duties conflicts. Compare the full before-and-after access state, remove obsolete rights, and give any transitional access a reason, owner, and end date.

What should happen first when an employee leaves?

Use the approved departure time and risk plan to block sign-in, revoke active sessions, remove privileged access, review applications, and secure devices. Coordinate these actions with mailbox, OneDrive, records, meeting, and ownership decisions before deletion.

Can a former employee's mailbox be converted to a shared mailbox?

Yes. Microsoft documents conversion to a shared mailbox and forwarding options. A shared mailbox below 50 GB commonly needs no license, but holds, archive, or advanced capabilities can require one; confirm the exact tenant requirements before removing the license or account.

How long is a deleted user's OneDrive retained?

Microsoft documents a 30-day default deleted-user OneDrive retention period that administrators can configure, followed by recycle-bin behavior. Retention policies, labels, or holds can override normal deletion. Check the tenant setting and legal requirements rather than relying on the default.

What evidence should close a Microsoft 365 offboarding event?

Retain the authoritative request, effective time, approvers, sign-in and session actions, groups and roles removed, application review, mailbox and OneDrive decisions, device and asset results, retention requirements, exceptions, timestamps, and final acceptance by the responsible business owner.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Related Articles