Employee offboarding should close every door—not just Microsoft.

A secure employee exit covers identity, SaaS accounts, active browser sessions, shared credentials, and managed devices. Locke Armory helps IT and MSPs close the browser-session gap while the rest of deprovisioning catches up.

The identity is only one layer of access.

Disabling an Entra ID or Google Workspace account is essential. It may not immediately end sessions inside independent SaaS applications, personal browser profiles, or tools that were never connected to your tenant. Understanding how SAML and SCIM handle offboarding differently helps MSPs design a complete exit process.

badge

Identity

Directory and SSO access

apps

SaaS

Managed and shadow apps

language

Browser

Cookies and site storage

key

Credentials

Shared secrets and keys

devices

Devices

Laptops, phones, and tokens

Match the response to the exit.

The same inventory applies every time. The timing, evidence handling, and containment urgency should reflect the risk.

Planned departure

Coordinate the cutoff, transfer business records, remove group and application access, recover devices, rotate shared credentials, and confirm ownership of automations or vendor accounts.

Goal: a complete, documented handoff with no orphaned access.

Urgent or hostile departure

Coordinate a simultaneous cutoff, preserve required evidence, clear connected browser sessions, revoke provider-side sessions, disable identities, rotate exposed credentials, and recover or isolate managed devices.

Goal: contain access quickly without losing the audit trail.

A practical secure-offboarding sequence

  1. 1

    Coordinate the cutoff

    Confirm timing, authority, legal or HR requirements, business-owner handoffs, and whether evidence must be preserved.

  2. 2

    Contain active access

    Disable the identity, revoke provider sessions, and clear local session material from connected Locke browser profiles with Nuke Sessions.

  3. 3

    Remove application access

    Work through managed applications and shadow SaaS, including tools outside your tenant or without automated provisioning.

  4. 4

    Rotate shared credentials

    Change shared passwords, API keys, recovery methods, Wi-Fi credentials, and vendor logins the employee could access.

  5. 5

    Recover devices and verify

    Recover or isolate equipment, confirm critical removals, document exceptions, and retain the record of who completed each action.

delete_sweep

Close the browser-session gap

Strong Single Logout clears cookies and site storage from connected Locke browser profiles, reloads open web tabs, and revokes Locke sessions. It is designed for incident containment and urgent offboarding.

See how Nuke Sessions works arrow_forward
groups

Give MSPs a client-ready workflow

Authorized partner admins can manage client organizations and run browser-session containment from the same Armory employee profile used for client access management.

Explore Locke for MSPs arrow_forward

Employee offboarding questions

Does disabling Microsoft sign an employee out of every website?
No. Third-party applications control their own sessions and deprovisioning. Your process should also cover provider-side revocation, local browser sessions, credentials, and devices.
What should happen first in an urgent offboarding?
Follow your approved HR, legal, and security process. Coordinate timing, preserve required evidence, contain active access, disable identities, revoke application sessions, rotate credentials, and recover or isolate devices.
Does browser-session clearing replace deprovisioning?
No. It clears local browser session material from connected profiles. Continue account removal, provider-side revocation, device response, and credential rotation.

Make offboarding a repeatable security control.

Start with the printable checklist, then see how Locke Armory helps contain active browser sessions.