Offboarding in PowerShell: the checklist I run when someone leaves

Someone hands in their notice and IT gets one chance to get the offboarding right. Miss a step and you're explaining to security why a terminated employee's account still resolved Kerberos tickets three weeks later.

Here's the checklist I run, with the PowerShell for every step that can be automated — and an honest note about the steps that shouldn't be.

1. Disable the account (not delete)

Disable-ADAccount -Identity $user

Deleting breaks audit history and exchange artifacts you still need. Disable, and let your 30-day cleanup process delete later.

2. Kill the password now

Disabling stops interactive logon, but you also want the credential itself dead:

Set-ADUser -Identity $user -Replace @{ pwdLastSet = '0' }

pwdLastSet = 0 marks the password as needing a change at next logon — which effectively means the old password is done. Services still running as that user will fail loudly instead of silently continuing.

3. Terminate active sessions

Leaving a disconnected RDP session alive means a profile hive stays locked and scheduled tasks may keep running:

Get-Process -ComputerName $env:COMPUTERNAME |
    Where-Object { $_.UserName -like "*\$($user.SamAccountName)" } |
    Stop-Process -Force

Do this after disabling the account, and do it on every box your jump-host inventory knows about — not just the one you remember.

4. Archive the home directory before anyone empties it

$dest = "E:\offboarding\$($user.SamAccountName)-$(Get-Date -Format yyyyMMdd)"
& robocopy.exe $user.HomeDirectory $dest /E /R:1 /W:1 /NP

robocopy exit codes 0–7 are success — check for >= 8 before you let anything claim the copy worked. Archive first, remove access second. The order matters exactly once, and it matters a lot.

5. Write the audit trail while you do it

Every action above appends one row:

Timestamp | Ticket | Operator | User | LastLogon | Actions | HomeBackup

When security asks "when exactly did we cut off jsmith?", the answer should be a Select-String, not archaeology across four consoles.

6. The parts that must stay manual (on purpose)

Mailbox delegation and forwarding, distribution-group membership, VPN certificates, SaaS SSO apps, badge access — these live in systems with different owners and different blast radii. My script deliberately prints them as a to-do list instead of silently automating them:

Manual follow-ups: mailboxes/distribution groups, VPN, SaaS SSO, badge - not automatable here.

Automating revocation in a system you can't verify is how you get a "why did the CEO lose email" ticket.

The script

Steps 1–5 are one command with -WhatIf support and ConfirmImpact = High (you get prompted before anything changes):

.\user-offboarding.ps1 -SamAccountName jsmith -Ticket INC-1042 -HomeDirBackup E:\offboarding
  • Just the offboarding script: $2 — OpsKit Offboard
  • All ten admin scripts (cleanup, backups, watchdog, certs, alerts, inventory, share/password audits, patch report, offboarding): $7 — OpsKit

Both are instant download with a 30-day refund. (Disclosure: those are my products — the snippets above work standalone if you'd rather assemble it yourself.)

What's step 7 on your offboarding checklist? Mine's usually "find out which service account was using their laptop."

Story originally reported by Dev.to. View at Dev.to →
← Back to all news