Skip to content

Ops Log tag

#Offboarding

Reviewed Ops Log notes tagged Offboarding, written by Michal Jatczak with source links, test context and operational checks.

8 reviewed notes

Operator RunbookSecurity & Infrastructure

The Google Workspace scope for reading a leaver's app grants is not read-only

Listing a Google Workspace user's third-party app tokens needs admin.directory.user.security, the same scope that deletes them, and Google lists no read-only variant. Microsoft Graph lists the equivalent grants with Directory.Read.All. Treat the Google credential as a revocation key.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

A daily offboarding check can prove closure only as a bound

A leaver check that runs once a day can report closure only as a bound between two runs. A Graph 429, including one inside a batch that returns 200, and a membership read that returns nulls can each make a degraded run look clean, so an absence counts only from a run that read cleanly.

By Michal Jatczak
Change NoteModern Workspace

Auto-renew off without an explicit cancel bills as an Extended Service Term

In the Microsoft CSP program, setting an EST-eligible subscription to auto-renew false with no explicit cancel instruction converts it to a paid Extended Service Term that renews monthly. The API confirms the cancelled state first and a background job reverses it, so the read-back has to happen the next day.

By Michal Jatczak
Operator RunbookModern Workspace

A Purview hold does not stop an unpaid OneDrive being deleted at day 365

Since 1 July 2026 an unlicensed OneDrive that is neither relicensed nor covered by unlicensed-account billing is subject to deletion after 365 cumulative unpaid days, whatever Purview retention or hold sits on it, and it drops out of eDiscovery at day 275. This note gives the read-only check.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

The offboarding runbook and the MTTFAR clock

Offboarding is a race against the access a leaver still holds. This is the order of operations I run and the mean-time-to-full-access-revocation targets I hold each departure to, from a standard leaver to a hostile termination.

By Michal Jatczak
Decision MemoSecurity & Infrastructure

The offboarding evidence pack, control by control

An auditor does not ask whether an offboarding SOP exists. They ask for the artifact that proves each control ran. Here are the twelve controls I build the evidence pack around and the proof each one needs.

By Michal Jatczak
Operator RunbookSecurity & Infrastructure

Mailbox forwarding rules survive the leaver: the offboarding check most runbooks skip

An enabled inbox forwarding or redirect rule keeps sending a departed employee mail long after the account is disabled. Here is how to find every one from Microsoft Graph and shut it before it becomes an exfiltration path.

By Michal Jatczak
Lab NoteSecurity & Infrastructure

What a Microsoft 365 offboarding scan finds after the account is disabled

Disabling an Entra account is the start of offboarding, not the end. Here are the eight access residues a read-only Microsoft Graph scan reads back, and why each one matters to an auditor.

By Michal Jatczak

Adjacent tags

Ops Log briefing

Evidence you can inspect.

Michal's field notes on Microsoft 365, Azure and AI operations for regulated European teams.

  • Primary-source analysis
  • Tenant checks and tested configuration paths
  • Named author, test context, and visible limits

We send a confirmation link first. No briefing is scheduled before you confirm.