A departed employee’s OneDrive can contain the only working copy of a proposal, spreadsheet, project folder, or client handover. It can also contain personal material, confidential communications, privileged documents, and files the requester has no legitimate reason to see.
Administrator capability does not settle that conflict.
The right objective is not “log in as the former user.” It is:
Preserve and transfer the minimum authorised business data to a durable owner, while keeping the requester, administrator, actions, retention state, and final access accountable.
This guide assumes the organisation has a legitimate continuity need and an authorised process. It does not determine whether access is lawful in your jurisdiction or justified in a particular employment, dispute, investigation, or privacy context. When the purpose is contested, investigative, or likely to involve personal or privileged material, pause ordinary IT handover and obtain the required HR, legal, privacy, or records-management direction.
The short controlled path
For an ordinary business-continuity case:
- open a case with a named requester, approver, purpose, scope, deadline, and data destination;
- confirm the person’s account, OneDrive URL, deletion and licence state, configured retention, holds, and available audit window;
- preserve the current state before deletion, permanent deletion, licence removal, or broad file movement starts a clock or destroys context;
- use a supported administrator or delegated-access path—do not reset the person’s password and sign in as them;
- give one accountable custodian time-bounded access to the minimum necessary material;
- inventory and review what is being transferred, including versions, permissions, links, external sharing, and exceptions;
- move accepted business records to a team-owned SharePoint library or another approved durable repository;
- have the business owner verify the handover;
- remove temporary site-administrator and delegated access; and
- record the final retention, source-disposition, audit, and ownership decisions.
The process is incomplete if the files moved but nobody can say who approved the access, what was reviewed, where the records now live, or whether temporary privilege was removed.
Confirm authority before touching the data
The case record should answer:
- Who is requesting access, and in what business role?
- Who is authorised to approve it?
- What exact business outcome is required?
- Which projects, clients, dates, folders, or document types are in scope?
- What is explicitly out of scope?
- Is the request routine continuity, regulatory retention, litigation, fraud investigation, disciplinary action, or incident response?
- Could the OneDrive include personal, union, health, legal, whistleblowing, security, or third-party-confidential material?
- Who will review and receive the files?
- Where will the durable business copy live?
- How long may temporary access remain?
- What evidence must be retained, by whom, and until when?
“Manager asked” may be sufficient under an approved routine offboarding policy, or it may be wholly inadequate for a sensitive investigation. The administrator should not make that governance decision alone.
Use a narrower method when the purpose is narrow. If the business needs one named proposal, do not grant unrestricted browsing for convenience without documenting why a scoped search or records process cannot meet the need.
Understand the four different states
Before acting, separate these concepts:
The user account
The Microsoft Entra identity may be active, disabled, soft-deleted, restored, or permanently deleted. Microsoft’s current deleted-user guidance states that a recently deleted user can normally be restored during the recovery window, while permanent deletion cannot be undone by Microsoft support.
Restoring an identity is not the same as authorising interactive sign-in. If restoration is technically required to recover a linked service, keep the account blocked from normal use, document the reason, and follow the tenant’s identity and licence controls.
The licence
A licence can be present or removed while the identity still exists. Licence removal affects service availability and can interact with unlicensed-account policies, but it does not by itself answer whether the files are retained, discoverable, backed up, or lawfully accessible.
Do not remove a licence solely because “the files are in the cloud” and assume there is no time consequence. Read the current tenant state and Microsoft guidance first.
The OneDrive site
OneDrive for work is built on SharePoint. The site can exist while the user is active, remain during the configured deleted-user retention period, enter a deleted state, or be restored by an authorised SharePoint administrator during an available recovery window.
Microsoft’s current deleted-OneDrive restoration guidance explains that account deletion and OneDrive deletion have separate stages. Do not turn the default timing described in documentation into a promise for a specific tenant.
Retention, holds, recycle bins, and backup
These are not interchangeable:
- the deleted-user OneDrive retention setting controls the ordinary site lifecycle after account deletion;
- recycle bins provide time-limited recovery for deleted items or sites;
- Microsoft Purview retention policies, retention labels, and eDiscovery holds can preserve or dispose of content under different rules;
- version history may preserve earlier versions of files that remain in place;
- Microsoft 365 Backup, if purchased and configured, is a separate recovery service; and
- an organisation’s independent backup or export is another control entirely.
Microsoft’s current SharePoint and OneDrive retention guidance explains how retention policies can preserve copies and how recycle-bin timing interacts with disposal. Verify which policies and licences actually apply to this user and site. A default value in an article is not evidence of the tenant’s configuration.
Capture the current state before changing it
Create a non-secret case snapshot:
- user display name, sign-in name, immutable identifier where appropriate, manager, and employment status;
- account active, blocked, deleted, or restored state and relevant timestamps;
- licence and service-plan state;
- OneDrive URL and whether the site currently opens for an authorised administrator;
- configured deleted-user retention and any known deletion date;
- applicable retention policy, label, hold, backup, or legal instruction;
- site size, item count, last activity, sharing and ownership indicators available to the administrator;
- current site administrators and automatic access delegates;
- available audit subscription, search permission, and searchable date range; and
- every action already taken in the offboarding process.
Do not include file contents, credentials, or unnecessary personal data in a general support ticket. Store sensitive evidence in the approved case or records system and give the ticket a reference.
Microsoft’s current OneDrive retention-setting guidance describes a configurable deleted-user retention period and when its countdown begins. Read the actual tenant setting; do not change a tenant-wide retention value merely to solve one case without records, privacy, storage, and cost approval.
Do not take over the person’s identity
Resetting the former user’s password and signing in interactively is a poor default because it:
- makes activity look like the departed user rather than the administrator or custodian;
- can trigger or bypass identity, MFA, Conditional Access, and device controls unpredictably;
- exposes mail, Teams, applications, and other data outside the authorised OneDrive purpose;
- can alter last-sign-in, sync, sharing, or application state; and
- weakens the audit story when the case is challenged later.
Use Microsoft 365 and SharePoint’s supported administrator or delegation paths. Microsoft’s current former-user data guidance describes granting access to another user and revoking it after use. Its current user-profile administration guidance documents adding and removing administrators for a user’s OneDrive.
Portal names and available options can vary by tenant and Microsoft update. Record the exact method and interface used in the case rather than treating this article as a permanent click map.
Choose the access model that fits the purpose
Automatic manager or secondary-owner access
Some tenants configure automatic delegation when a user is deleted. That can support routine handover, but only if the directory manager is correct, the recipient is authorised, the retention window is known, and the access is later reviewed.
Automatic does not mean risk-free. A stale manager field can send access to the wrong person. A manager may also be involved in a dispute or lack authority for some records.
Temporary named custodian access
For most continuity cases, grant one named person access for a defined period and purpose. This might be the manager, project owner, records custodian, or an administrator acting under instruction.
Record:
- access recipient;
- permission or site-administrator role granted;
- approver and purpose;
- start and expiry time;
- folders or records expected;
- allowed actions—view, classify, copy, transfer, or preserve;
- prohibited actions; and
- revocation owner.
Avoid giving several people full access “just in case.” Use the smallest group that can complete the handover and preserve separation between technical administration and business content review where practical.
Formal investigation or eDiscovery
When the purpose is legal, regulatory, disciplinary, fraud-related, or evidentiary, ordinary browsing and copying may be the wrong workflow. Use the organisation’s approved Microsoft Purview eDiscovery, records, investigation, or legal-hold process with the right custodians, permissions, preservation, review, and export controls.
Do not tell a manager to search the OneDrive casually when chain of custody, privilege, confidentiality, or legal hold matters.
Make an inventory before transferring files
The custodian should identify:
- business-owned folders and documents;
- project or client owner;
- destination library and owner;
- last modified date and relevant version history;
- file sharing and permissions;
- links embedded in email, Teams, SharePoint, workflows, or documents;
- external guests or anonymous links;
- sensitivity, retention label, record status, or hold;
- files that appear personal, privileged, unrelated, duplicated, obsolete, or unsafe; and
- exceptions requiring another decision.
Do not open every file to decide what exists. Use names, metadata, approved search, known project structure, and the business owner to narrow the review. Escalate clearly personal or sensitive material rather than copying it into the handover set.
Transfer to durable business ownership
Another employee’s OneDrive is usually a poor final destination for shared business records. It simply repeats the same ownership problem at the next departure.
Prefer an approved team-owned SharePoint library or other durable repository with:
- a named business owner and backup owner;
- group-based access where appropriate;
- agreed retention and classification;
- controlled external sharing;
- a documented folder or information architecture; and
- normal backup, audit, support, and review coverage.
Choose copy, move, migration, or records export based on what must be preserved. Microsoft’s former-user guidance warns that ordinary move or copy operations can preserve only the latest file version. If version history, metadata, sharing relationships, labels, or evidence matter, test the chosen transfer method with representative files before using it broadly.
For every transferred set, record:
- source path or stable item identifiers where available;
- destination path;
- item and size counts;
- transfer method and actor;
- start and completion time;
- skipped, failed, renamed, duplicate, or transformed items;
- version and metadata outcome;
- permission and sharing outcome; and
- business-owner acceptance.
A screenshot of a green progress bar is not reconciliation.
Review sharing and downstream copies
OneDrive access is not limited to the browser. Check, within the approved scope:
- direct permissions;
- organisation-wide, specific-person, guest, and anonymous links;
- external users and guests;
- Teams chats or emails containing sharing links;
- synced Windows or macOS devices;
- mobile offline files;
- applications with delegated access;
- Power Automate or other workflows;
- shortcuts and linked files; and
- copies already downloaded or exported.
Revoking a cloud account does not erase files already synchronised to a personal or unmanaged device. Microsoft’s current user-deletion guidance explicitly warns that local synced copies can remain. Device, information-protection, contractual, and HR controls must handle that separate risk.
Do not break every historical sharing link automatically. Some are legitimate business dependencies. Decide whether each important link should be recreated at the durable destination, redirected through communication, or retired.
Use audit evidence honestly
Microsoft Purview Audit can record SharePoint and OneDrive activities, including the actor, time, operation, item, and other details. Microsoft’s current audit-search guidance explains search criteria and results, while its audit-retention guidance shows that searchable retention depends on licensing, user state, policy, workload, and event date.
Before promising an audit trail, verify:
- auditing is available and producing events in this tenant;
- the investigator has the correct least-privileged audit role;
- the relevant time range is still retained;
- the expected OneDrive and SharePoint operations are audited;
- timestamps and time zone are interpreted correctly;
- search filters identify the site, actor, and activity accurately; and
- exported evidence is stored and protected appropriately.
An empty search does not prove that no access occurred. It can also mean the event has not arrived, the filter is wrong, the operation is not logged as expected, the record expired, or the tenant lacks the required configuration.
Keep the access grant, transfer record, audit search, and access removal in the same case timeline.
Validate the handback
The business owner—not only the administrator—should confirm:
- required projects and records are present at the approved destination;
- representative files open and contain the expected content;
- versions, metadata, labels, and permissions meet the accepted requirement;
- authorised team members can work;
- unauthorised and former external access is absent;
- important sharing links and workflows have an explicit outcome;
- failed and excluded items have owners and decisions; and
- the durable repository has normal ownership, support, retention, and backup.
Do not make “all files copied” the acceptance test when the real requirement is “the team can continue the client project with its approved records and permissions.”
Remove temporary access
After acceptance:
- remove the temporary OneDrive site administrator or delegated custodian;
- remove investigation or migration roles and application access no longer required;
- expire temporary sharing links and local working copies according to policy;
- verify that removal took effect;
- capture the available audit evidence;
- record remaining source access and the person responsible for it; and
- set the final review or source-disposition date.
Microsoft’s former-user guidance includes a specific revocation path because access that was justified for transfer is not automatically justified forever.
If a business owner needs continuing access to a few source-only items, document the exception, limit it, and set an expiry. Do not leave full site-administrator access as an invisible convenience.
Handle common failure states
| Situation | Controlled response | Avoid |
|---|---|---|
| User still exists and OneDrive opens | Block sign-in as required, record state, authorise temporary admin or custodian access | Resetting the user’s password and signing in as them |
| User was recently deleted | Check the recoverable identity and OneDrive states, retention, holds, and approved restoration path | Permanent deletion to “start clean” |
| OneDrive is in deleted state | Use the current supported SharePoint administrator restoration process if still recoverable and authorised | Assuming a default recovery window without checking dates and policy |
| Manager is wrong or absent | Assign an authorised named custodian under the case | Sending access to the directory’s stale manager automatically |
| Files include personal or privileged material | Stop that subset and obtain privacy, HR, legal, or records direction | Copying everything into a manager’s folder |
| Ordinary copy loses versions or metadata | Test a method that preserves the required record properties, or document accepted loss | Calling latest-version copy a full preservation |
| Audit search is empty | Check ingestion delay, filter, operation, permissions, licensing, and retention | Claiming no access occurred |
| Retention deadline is close | Escalate the decision immediately and preserve through an approved mechanism | Quietly changing a tenant-wide retention policy for one case |
| Source is gone beyond supported recovery | Check approved backups, exports, legal holds, downstream copies, and Microsoft support eligibility | Promising recovery or using untrusted “recovery” tools |
Close the case with a reproducible record
The final record should state:
- requester, approver, administrator, custodian, and business owner;
- purpose, scope, exclusions, and authority reference;
- source user, site, account, licence, retention, hold, and backup state;
- access method, permissions, start, expiry, and removal evidence;
- inventory and transfer reconciliation;
- destination, owner, access model, retention, and backup;
- sharing-link and external-access decisions;
- audit searches and evidence retained;
- sensitive exceptions and who resolved them;
- source OneDrive disposition and date; and
- business acceptance.
Future administrators should be able to explain what happened without reopening the departed person’s whole OneDrive.
Preserve continuity without erasing accountability
The safest departed-user process does not pretend that access is harmless because an administrator can grant it. It defines why the business needs the data, limits who can see it, preserves the retention decision, records the transfer, moves durable records to durable ownership, and removes extraordinary access when the job is done.
That protects the business from lost work. It also protects the departed person, the administrator, and the organisation from an access process nobody can later justify.
