Local Tech Fix (626) 655-0020
All articles

An Employee Left and Their Email Left With Them: What to Do, in the Right Order

August 24, 2026

It usually surfaces weeks later: somebody left, somebody tidied up the account to stop paying for it, and now a customer says they emailed and nobody ever answered. There is a clock running, and it is shorter than most people assume.

a close up of a cell phone screen with different app icons
Photo by Ed Hardie on Unsplash

Somebody leaves a four-person company. There is no IT department, so the owner does the sensible-looking thing: opens the billing page, sees a licence still being charged for a person who no longer works there, and cancels it. Or goes one step further and deletes the account outright, because why keep it.

Three weeks later a customer calls and says they sent the quote request twice and never heard back. It went to the address of the person who left. Nobody has read that mailbox since the day they walked out, and the six years of correspondence in it — the supplier threads, the warranty claims, the one email with the account number for the merchant services provider — is now somewhere between "still there" and "permanently gone", depending on which button got pressed and how long ago.

This is one of the most common calls we get from small businesses, and it is almost always fixable if you move quickly and almost never fixable if you wait. The reason it goes wrong is not carelessness. It is that the mailbox and the files behave completely differently, the action that feels like the safe money-saving one is the action that starts the countdown, and nothing in the billing screen warns you about any of it.

Here is the order we would work through it. Microsoft 365 first, because that is what most small businesses here are on; Google Workspace further down, because the numbers are different and the difference matters.

Start here: has the account been deleted, or is it just sitting there?

Everything else follows from this one question, so answer it before you touch anything.

Sign in to the Microsoft 365 admin center and look at Users. If the person is still listed under Active users — even blocked, even with no licence — you have not lost anything and you have time. Skip ahead two sections.

If they are not in Active users, look at Deleted users. If they are there, the account is soft-deleted and you are on a clock, but you are still in the good case. Read the next section now, today, before you finish reading the rest of this.

If they are in neither list, the deletion has already run its course. Do not spend the afternoon on it yourself — that is the one scenario in this article that has to go to Microsoft, and the sooner the better.

If the account is already deleted, you are on a 30-day clock — and restoring is the fix

Microsoft is unusually plain about this one. Their documentation states that when you restore a user account within 30 days of deleting it, the account and all associated data are restored, the person can sign in with the same work account, and the mailbox is fully restored. After the account is deleted, the mailbox and OneDrive content are retained for 30 days and then permanently deleted.

Note the shape of the fix, because people reach for the wrong tool here. You do not go hunting for a recovery utility or a data-recovery service. You go to Users, then Deleted users, select the person, and choose Restore user. It is a two-minute job. You will be asked to set a password, and you will need a licence available to assign afterwards if you want the account usable — so if you cancelled the subscription seat to save money, you may need to add one back temporarily.

Then, having got everything back, do the rest of this article properly instead of deleting it again.

Two things that can go wrong on the way, both of which have documented fixes: a user name conflict, where somebody has since created a new account using the same address, and a proxy address conflict, where the departed person's address was added as an alias to somebody else's account in the meantime. Both are resolvable in the restore dialog — you either rename the conflicting live account first, or give the restored account a different primary address.

If the 30 days have elapsed, standard recovery is over. The one exception worth asking about: if the mailbox was under a retention policy, a litigation hold or an eDiscovery hold before it was deleted, it may have become an inactive mailbox rather than being destroyed, in which case the contents can still be searched and exported through Microsoft Purview. Most four-person businesses have never configured any of that, so treat it as a long shot rather than a plan.

And if your accounts are synchronised from an on-premises Active Directory server — uncommon at this size, but it happens with older businesses that still have a server in the closet — deletion and restoration have to be done in Active Directory, not in Microsoft 365. Doing it in the wrong place is why some restores silently fail.

If the account is still there: reset the password first. Do not start with "block sign-in"

Every offboarding checklist on the internet says to block sign-in first. Microsoft's own page says something more useful and slightly alarming: blocking an account can take up to 24 hours to take effect, and to immediately prevent a user's sign-in access you should reset their password.

So the correct first move on a departure that is at all unfriendly is: reset the password, then use Sign out of all sessions on the Account tab, then block sign-in as the belt-and-braces step. Not the other way round.

Even sign-out is not instant, and it is worth knowing why so you are not surprised. An access token is good for an hour, so the person is prompted to sign in again within the hour, or sooner if they leave the page they are on. If they are sitting in Outlook on the web, they may not be kicked out immediately — the service signs them out when they click a different tile or refresh the browser. Which is a long way of saying: on a genuinely bad departure, the phone in their pocket may still be showing company mail for the rest of the afternoon. If that matters, the Exchange admin center lets you turn off the individual protocols for that mailbox — Outlook desktop, Exchange web services, mobile, IMAP, POP3 and Outlook on the web — and that bites straight away.

One more thing to do on the way past, while you still have the mailbox open as a normal user mailbox: read their inbox rules. A rule quietly forwarding a copy of everything to a personal Gmail account is a real thing that happens, and it survives everything you are about to do next.

The part that catches everyone: the mail and the files are on two different clocks

This is the single most valuable thing in this article, so it gets its own section.

Cancelling the licence feels like the cautious move. It stops the bill, it does not delete anything, the account is still sitting right there. It reads as reversible. It is not, for the mail.

Microsoft's own wording: when you remove or delete a licence, the former employee's email, contacts and calendar are retained for 30 days, and are then deleted permanently. The account can still be sitting in Active users, untouched, looking perfectly healthy — and the mailbox behind it is on a fuse.

The files behave in the opposite way. If you remove or delete a licence but do not delete the account, the content in the user's OneDrive remains accessible to you even after 30 days. And the retention clock for cleaning up a OneDrive only begins when the user account is deleted from Microsoft Entra ID — Microsoft says no other action causes the cleanup process to occur, including blocking the user from signing in or removing the user's licence.

Read those two paragraphs together and you get the trap in one sentence: cancelling the licence to save money quietly destroys the email in 30 days while leaving the documents alone, so the business gets a false all-clear from the half of it that survived.

Which is why the order below matters. Deal with the mailbox before you cancel anything.

The move most small businesses have never heard of: convert it to a shared mailbox

If there is one thing to take away, it is this. You can convert a departed employee's mailbox into a shared mailbox. All of the existing email and calendar information is retained; it is simply now a mailbox that several people can open instead of one. The address stays alive, so the customer who emails sales@ or the old rep's address six months from now still reaches a human. Inbox rules are preserved. You can convert it back to an ordinary user mailbox later if the role gets refilled.

And the money part: a shared mailbox can store up to 50 GB of data without a licence assigned to it. So the seat you were paying for genuinely does go away — Microsoft 365 Business Basic is $7.00 per user per month on an annual subscription as of August 2026, and Business Standard is several times that — while the mail itself stays readable by whoever takes over the work.

There is one piece of sequencing that trips people up, and it is the reason this article keeps saying "in the right order". The mailbox needs a licence assigned to it at the moment you convert it — otherwise the Convert to shared mailbox option does not appear at all. If you have already stripped the licence, put it back, convert, and then remove it. People who cancel first spend an afternoon wondering why the button they read about does not exist.

The steps, once you know that: admin center, Users, Active users, select the person, Mail tab, Convert to shared mailbox, Convert. Then, if the mailbox is under 50 GB, remove the licence and stop paying for it. If it is over 50 GB you will need to clear out some large messages and attachments to get under the line, or assign an Exchange Online Plan 2 licence to raise the limit to 100 GB — worth pricing against just deleting some 2019 attachments.

Then the rule that undoes all of it if you get it wrong: do not delete the user account. The account is required to anchor the shared mailbox. It sits there unlicensed, costing nothing, holding the mailbox in place. Delete it in a later tidy-up and you are back at the start of this article.

Two caveats worth knowing. A shared mailbox only works inside your organisation — you cannot give someone with an outside Gmail address access to it. And if the mailbox has been made inactive for compliance reasons, converting it to a shared mailbox does not work at all.

The trap inside that move: converting does not lock the former employee out

This one is buried in Microsoft's documentation and it deserves to be in bold on the first page. Converting a user mailbox to a shared mailbox does not require you to reset the password — and, in their words, if you do not reset the password, the original username and password will continue to work on the shared mailbox after the conversion is finished.

So a business owner who does the clever, thrifty, correct thing — converts the mailbox, cancels the licence, saves the money — and who never reset the password can leave a former employee holding working credentials to the mailbox. Microsoft's guidance on shared mailboxes is explicit that a shared mailbox is not intended for direct sign-in with its associated account, and that sign-in should be blocked.

Do both. Reset the password and block sign-in on that account, and then convert. It costs thirty seconds and it is the difference between a tidy handover and an ex-employee reading your quotes.

Forwarding is not the same thing, and it is not a substitute

The other option Microsoft offers is forwarding: everything sent to the departed person's address gets delivered to whoever is picking up the work. It is one checkbox on the Mail tab, and you can choose whether to keep a copy in the original mailbox.

It solves exactly one problem — new mail reaching a human — and it does nothing about the six years of history, because forwarding only applies to new messages sent to the address. If the reason you care is "a customer emailed and nobody answered", forwarding is enough. If the reason you care is "the supplier account number is in an email from 2021", it is not, and you want the shared mailbox.

Forwarding carries the same anchor rule: do not delete the account that the forwarding is set on, or the forwarding stops. And, like the shared mailbox, it will not work on a mailbox that has been made inactive for compliance reasons.

Most of the time the honest answer is to do both — convert to a shared mailbox so the archive survives, and add the person taking over as a member so it appears in their Outlook alongside their own mail.

The files: OneDrive has its own rules and a quieter deadline

Assume the departing person kept work in their OneDrive, because they did. The proposal template, the price list, the photographs from the job in March.

While the account still exists, getting at it is straightforward: in the admin center, select the user, open the OneDrive tab, and under Get access to files choose Create link to files. That opens their file location, and you can download what you need or move and copy it into your own OneDrive or a shared library. One catch to know before you rely on it: when you move or copy documents that have version history, only the latest version comes across. If an earlier version of a spreadsheet is the thing you actually want, retrieve it before you move the file, not after.

There is a helpful default most owners do not know is switched on: when a user is deleted, the user's manager is automatically given access to their OneDrive. Useful when it works, useless when it does not — if no manager is set on the account and no secondary owner has been configured, nobody gets access and nobody gets warned that the OneDrive is going to be deleted. It is worth setting a secondary owner in the SharePoint admin center once, so that this safety net actually exists before you need it.

After deletion, the default window to get at a deleted user's OneDrive is 30 days, and if the account is not restored within that period the content is deleted. And there is a second, slower deadline that nobody expects, because it does not depend on deletion at all: OneDrive accounts without a valid OneDrive licence are automatically archived on their 93rd unlicensed day. Retention settings and holds are still honoured while an account sits in that archived state, but this is the detail that quietly punctures the comfortable idea that an unlicensed account can be left alone forever. If the files matter, move them somewhere shared. Do not leave them parked in a departed person's personal storage as a filing strategy.

The thing nobody thinks of until a room is double-booked

Cancel the meetings the departed person owned. It sounds like housekeeping and it is the item that generates the most confused phone calls a month later.

Meetings they organised stay on everyone else's calendars, recurring ones keep recurring, and — the part that actually hurts — if they had meetings that booked equipment or a room, those resources stay booked and cannot be reserved by anyone else until the meetings are cancelled. A conference room that is mysteriously unavailable every Tuesday at ten, six months after the person who booked it left, is a real support ticket and it takes ten minutes to prevent.

While you are in the calendar, that is also the moment to spot the standing appointments that were really business commitments — the quarterly review with a client, the annual inspection — and move them onto someone who still works there.

The wall: when nobody left at the company is an administrator

Everything above assumes you can sign in to the admin center. Sometimes the person who left was the person who set the whole thing up, and the admin account was theirs, and nobody else was ever given the role. This is common in small businesses and it is the version of this problem we cannot solve for you, so it is worth being straight about it.

A work or school account belongs to the organisation's tenant, not to an individual — which is the good news, because it means the business has a legitimate claim to it. But you cannot promote yourself back into control from outside, even if you can prove you own the domain in DNS. Recovering a tenant with no reachable administrator goes through Microsoft support as an identity-verified process: they will want to establish that you are who you say you are and that the business is yours, typically using billing records and official business documentation, and it is handled by a specialist team rather than the ordinary support queue.

It is not quick and it is not fun, and it is far cheaper than the alternative. Two practical notes: start it the day you discover the problem rather than after you have exhausted every idea, and have the subscription billing details, the domain registrar login and your business registration paperwork in front of you before you begin.

The prevention is one line long: a business should always have at least two people with the top admin role, and one of them should be the owner. Not because you will use it — because the day you need it, creating it is no longer possible.

If you are on Google Workspace instead, the numbers are different

Plenty of small businesses around here run on Workspace rather than Microsoft 365, and the shape of the advice is similar while the specifics are not. The differences are the kind that matter.

The restore window is 20 days, not 30. Google's documentation is blunt: you can restore a user account, including administrator accounts, up to 20 days after deleting it, and after 20 days the data is gone and you cannot restore it. Restoring can take up to 24 hours to take effect and occasionally longer, and it will fail if you no longer have a spare licence of the right edition or if the username has since been reused. If you are reading this on day 18, stop reading and go restore it.

The address has the same 20-day fuse. Twenty days after an account is deleted the email address is removed from Workspace, though you can reassign it to another managed user before that window closes. There is also a quirk worth knowing if the person is taking the address with them personally: if the address is going to be used for an unmanaged personal Google account, you have to wait 30 days to avoid an account conflict.

The order of operations is stricter than Microsoft's, because Workspace expects you to move the data before the account goes. Transfer Drive files to a new owner and migrate or redirect the mail first, and only then delete. A super administrator can transfer Drive and Docs files, primary calendar data and a few other things as part of the deletion flow itself; anyone with a lesser admin role has to do the transfers beforehand or lose them.

On security, Google's own departure checklist is more aggressive than most people expect and is worth copying wholesale: change the password, remove the account's recovery methods, revoke OAuth tokens, reset sign-in cookies, and revoke any security keys or app-specific passwords that were granted access. That last one is the item people miss — an app password issued to a mail client two years ago keeps working after the main password changes, which is precisely what it was designed to do.

And the nearest equivalent to the shared-mailbox trick is not identical. Workspace offers archived user licences on Business Starter, Standard and Plus (and the Enterprise and Education tiers), which preserve the account's data for retrieval while the account cannot sign in, cannot receive new mail or calendar invitations, and no longer appears in the directory. That last part is the real difference from a Microsoft shared mailbox: an archived Workspace account is a container for the history, not a live address that keeps catching customer mail. If the goal is that nothing sent to the old address is lost, the usual answers are to reassign the address as an alias on someone else's account, or to turn it into a group, before the 20 days run out.

None of this is a backup, and it is worth saying out loud

Everything above is a grace period. Thirty days at Microsoft, 20 at Google, and one 93-day quirk in the middle. They exist to let an administrator undo a mistake, and they are not a substitute for a backup, an archive, or a records policy.

A grace period does not help with the failure modes that actually take businesses down: the departure nobody told you about until month three, the mailbox someone emptied deliberately on their way out, the ransomware event, the compliance request for correspondence from 2023. If your business genuinely needs to be able to produce old email years later — because of the industry you are in, or a contract you signed, or an insurer — then that is a retention or third-party backup conversation, and it needs to happen while everyone still works there.

The general point holds beyond email, and we have written it up separately: the cloud is a place your data lives, not a promise it will still be there.

Do these three things before the next person leaves

All of the above is the fire. Here is the fire prevention, and it is short.

First, put role addresses on shared mailboxes from day one — info@, sales@, accounts@, service@. Not on a person's mailbox with a forward, and not on a person's mailbox with an alias, because both of those quietly turn a business function into one employee's personal property. Shared mailboxes are free below 50 GB and several people can work them, which is exactly what a business address should be. The day someone leaves, the customer-facing addresses simply carry on and are not part of the emergency at all.

Second, get the business's working files out of individual OneDrive and Drive accounts and into a shared library or shared drive. Personal cloud storage is the right home for a draft; it is the wrong home for the price list. The test is simple and slightly uncomfortable: if this person did not come in tomorrow, is there a document the business needs that only they can open?

Third, have two administrators, and write down where the billing lives. The subscription, the domain registrar and the admin account are three separate logins and losing any one of them turns a twenty-minute job into a documentation exercise with a support team.

And when someone does leave, work in this order: reset the password, sign out all sessions, block sign-in, pull the files out or hand them to a named person, convert the mailbox to a shared mailbox while it still has a licence, add the people who need it as members, cancel their meetings, and only then remove the licence. Leave the account in place, unlicensed, as the anchor. Nothing on that list takes long. Doing them out of order is what costs the money.

Where we come in

We do this for small businesses across the San Gabriel Valley, Orange County, the Inland Empire and the desert — the four-to-fifteen-person companies that have Microsoft 365 or Google Workspace, do not have an IT department, and have never had a reason to look at the admin center until the week they suddenly need it.

The urgent version is the one where the account is already deleted and the clock is running, and it is worth calling the same day rather than the following week; the restore itself is quick, and its value drops to zero on a fixed date. The unhurried version is the useful one: setting up the shared mailboxes and the shared file storage before anybody leaves, adding the second administrator, and writing down where all of it lives, so the next departure is a checklist instead of a phone call.

What we will not do is pretend the wall is not a wall. If nobody at the company holds an admin role, we will tell you that it is a support case with the vendor, help you assemble the billing and business documents that process needs, and get out of the way of it. And if you want the mail kept somewhere you control rather than trusted to a 30-day grace period, that is a backup conversation and we will have it honestly, including the parts that cost money.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →