Here's a scenario that plays out more often than anyone admits. A business wraps up with a contractor in March. Their Microsoft 365 guest account is removed. Someone checks it off. Done.
Six months later, that contractor's VPN credentials still work. They're still on a shared project folder. The API key they created to connect your CRM to another tool is still active.
No one looked, because the offboarding was "handled."
The problem isn't that anyone was careless. It's that contractor offboarding has a different scope than employee offboarding — and most checklists treat them as the same thing.
A meaningful share of breaches involve insiders — including former employees and contractors. Most aren't malicious. They simply still had access nobody knew to revoke.
Why Contractors Are Different
When a W-2 employee leaves, there's an HR record, a termination date, a defined role, and usually a manager who knew it was coming. Items still get missed — but at least you know who left and roughly what they had.
Contractors are messier in every dimension:
- Clear end date through HR
- Company-managed M365 / Google account
- Company laptop returned
- Role-based permissions
- One identity in your directory
- Payroll stops on a known date
- End date often unclear (project-based)
- May use personal email or their own tenant
- Works on their own equipment
- Often given elevated access for the project
- Multiple identities — email, API, VPN
- Invoicing stops, access doesn't
That last point does the real damage. When a contractor's final invoice is paid, nothing in most small business environments ties their access to the contract ending.
The Baseline: Employee Offboarding Checklist
Start with what a complete offboarding looks like for an employee. Most companies hit 60–70% of this list at best.
Disable the primary account the same day
Block sign-in on the departure date. Disable first, delete later — after 30+ days so data can be recovered if needed.
Revoke active sessions and tokens
Disabling an account doesn't end existing sessions on phones and browsers. Revoke sessions in Microsoft 365 or your identity provider.
Remove from groups, shared mailboxes, and distribution lists
So access doesn't quietly return if the account is ever re-enabled by mistake.
Recover and wipe company devices
If a device isn't returned and it's enrolled in device management, wipe it remotely anyway.
Remove VPN access
VPN credentials and certificates are often separate from the directory account and need their own step.
Rotate shared credentials
Any shared password they knew — admin logins, vendor portals, Wi-Fi — gets changed.
Transfer data and set up forwarding
Reassign files to their manager, forward email for 30–90 days, and archive the mailbox before deletion.
Remove them from every SaaS app
CRM, project management, billing, HR, Slack. Single sign-on helps, but it doesn't catch everything — keep an app inventory.
The Additional Contractor Checklist
Everything above applies to contractors too. Plus these items, which most businesses miss entirely:
Audit and revoke API keys and service tokens
Contractors often create their own API keys to connect your systems. Search each platform for keys tied to them and revoke all of them — including ones that look inactive.
Remove app authorizations they granted
If they connected a third-party tool to your Microsoft 365 or Google Workspace, that authorization can outlive their account. Review connected apps.
Remove firewall and network exceptions
IP addresses allowed in for the project tend to stay allowed for months. Record them when they're granted so they're easy to remove.
Confirm data return or deletion — in writing
Contractors often keep copies of project files on their own machines. Your agreement should require written confirmation of deletion at project close.
Remove the whole firm's access, not just your contact
If you engaged an agency, people on their side may have come and gone. Remove every account associated with the firm.
Pull elevated access the moment the work ends
Admin rights granted for a specific project should come off when that work is done — not whenever the contract formally ends.
Which Access Gets Missed Most
From access reviews across small business environments, here's what typically gets cleaned up — and what lingers:
| Access type | Employees | Contractors |
|---|---|---|
| Primary email / M365 account | Usually revoked | Sometimes |
| Active sessions | Often missed | Rarely checked |
| VPN access | Often missed | Often missed |
| API keys & tokens | Often missed | Rarely revoked |
| SaaS apps | Often missed | Often missed |
| Shared passwords | Rarely rotated | Rarely rotated |
| Firewall / IP exceptions | N/A | Rarely removed |
Contractor access lingers because nobody recorded what was granted on day one. Keep a simple access log for every contractor — accounts created, permissions granted, keys issued. Offboarding becomes a checklist instead of an investigation.
Give Contractor Offboarding a Trigger
Employee offboarding starts with an HR event. Contractor offboarding needs its own trigger:
- Contract end date: review active contracts against active accounts every quarter, and flag anyone without a current agreement
- Final invoice: when the last invoice is approved and there's no new engagement, treat it as an offboarding event — not just an accounts payable task
- Project close: make "project complete" automatically open an IT offboarding ticket
- Inactivity review: any account unused for 30+ days gets reviewed, either automatically through your identity provider or in a quarterly sweep
Free Access & Offboarding Audit
We'll surface every employee, contractor, and third-party connection that still has access to your systems — and build a process so the next departure doesn't leave a door open.
DM us "OFFBOARD" on LinkedIn or schedule a free consultation · (646) 791-2137