Former employee Microsoft 365 accounts are one of the most common gaps we find when we review IT in a professional services firm, and one of the easiest to close. This accountancy practice had 17 of them still live, the oldest belonging to someone who left in 2021. Here is what we found, what it put at risk, and what we did about it.
The client
Client: a UK accountancy practice, around 30 staff across two offices
Sector: accountancy and tax
Service: infrastructure review, Microsoft 365 remediation, ongoing managed IT
An independent accountancy practice doing payroll and tax work for owner-managed businesses. Busy, well run, and growing steadily.
Like most practices of that size, they had no internal IT person. IT was handled by whoever was nearest and most willing, in this case a partner who was good with computers, and a break-fix provider they called when something stopped working.
They also had regular staff turnover. That is normal in accountancy. Trainees qualify and move on, seasonal help comes in around the busy periods, and people change firms. Over the two years before they called us, roughly a third of the team had changed.
Why they called us
Nothing had gone wrong. That is worth saying, because it is usually the case.
They approached us because their professional indemnity renewal asked more questions about cyber security than it had the year before, and one of their larger clients had started asking about their data handling. The partners wanted to know where they actually stood before answering.
So we started with an infrastructure review rather than a sales pitch.
What we found
We looked at the whole estate: the server, the network, backups, Microsoft 365, the practice management software, and how staff accounts were set up and taken away.
Most of it was in reasonable shape. Backups were running. The machines were patched, if a little behind.
The problem was leavers.
When someone left the practice, the routine was to change the password on their email and leave the account in place, so that the partner covering their clients could still get at the mailbox. Nobody had ever formally closed an account. When we listed the active users in Microsoft 365, 17 of them belonged to people who no longer worked there. The oldest had left in 2021.
Two of those accounts had no multi-factor authentication on them. Several still had access to the shared client folders in SharePoint. A handful were still named in Teams channels where live client work was being discussed. And because the accounts were still licensed, the practice was paying for every one of them.
Email was the part they could see. Once we traced what each of those accounts had been used to sign into, we also found:
- Logins to the HMRC agent services account, still tied to former staff email addresses
- Xero and Sage practice logins that had never been removed
- Companies House filing access under a leaver’s credentials
- Password manager and portal accounts that had gone with the person
The risks that come with an open leaver account
I want to be careful about how I put this, because the partners’ first reaction was to worry about their former colleagues, and that is almost never the issue. Most people who leave a firm have no interest in the accounts they left behind.
The risk sits with the account rather than the person who used to use it. An account that still exists is something an attacker can use, whatever the intentions of the person whose name is on it.
It is an unmonitored door. An account nobody logs into is an account nobody notices being logged into. A live mailbox belonging to someone who left in 2021 can be accessed for months without a single person in the practice realising.
It is the easiest account to break into. Old accounts tend to have old passwords, often reused elsewhere and often sitting in a breach dump. Two of these had no MFA at all, which means a password on its own was enough.
It carries live client data. These are accountancy mailboxes. They contain tax references, National Insurance numbers, payroll files, bank details, signed engagement letters. Under UK GDPR Article 32 the practice is required to have appropriate security around that data, and “we changed the password” is not a control anyone would recognise as appropriate.
It is a trusted sender. An attacker in a former employee’s mailbox can email that person’s old clients from a genuine firm address, in an existing thread, and ask for a change of bank details. That is how invoice fraud usually works, and it works because the address is real.
It undermines the audit trail. If a filing is made or a document is changed under a leaver’s login, the practice cannot say who did it. For a regulated firm that is a problem in itself.
It costs money. 17 unused Microsoft 365 licences are a bill the practice was paying every month for the privilege of carrying the risk.
What we did
We worked through it in a fortnight, without interrupting client work.
We converted every leaver’s mailbox to a shared mailbox. That keeps the mail history accessible to the partner who needs it, keeps it searchable, and keeps it inside the practice, but the account itself can no longer be signed into. That single change closed the door while keeping everything the partners were worried about losing.
We then disabled the underlying accounts in Entra ID, revoked their active sessions, and removed the licences. We reclaimed 17 licences, which paid for a meaningful part of the remediation.
We audited the third-party systems and moved the HMRC agent services, Xero, Sage and Companies House access onto current staff with named individual logins. Anything shared went into a password manager the practice controls, rather than living in people’s heads and inboxes.
Then we turned MFA on across every remaining account, and set conditional access rules so that sign-ins from outside the UK are blocked by default.
Future proofing
Cleaning up once is only worth doing if it stays clean, and a practice with regular turnover will be back where it started within a year if nothing changes.
So the leaver process is now written down and owned:
- A joiner/leaver checklist the practice manager works through, covering Microsoft 365, the practice software, HMRC, Companies House, the password manager, and any client portals. IT is a line on the HR process, not a separate thing someone remembers.
- Same-day account closure, triggered by the leave date rather than by someone raising a ticket. Mailbox converts to shared, licence is reclaimed, sessions revoked.
- A quarterly account review we run for them, comparing the live account list against the current staff list. Anything that does not match gets queried. It takes us under an hour and it catches the things a checklist misses.
- Device return and wipe for laptops and phones, managed through Intune, so a device that leaves the building stops holding practice data.
- Cyber Essentials certification, which the practice achieved a few months later and now uses in its PI renewal and its answers to client due diligence questions, the thing that prompted the call in the first place.
Common questions about former employees’ Microsoft 365 accounts
Can we not just change the password and leave the account open?
No. Changing the password leaves the account live and signed-in sessions intact.
A password change does not sign anyone out. Existing tokens on phones and laptops can keep working, and the account still exists as a target. Converting the mailbox to a shared mailbox gives you the same access to the mail without leaving an account anyone can log into.
Will we lose the leaver’s emails if we close the account?
No. A shared mailbox keeps the full mail history at no licence cost.
This is the worry that stops most firms acting, and it is easily solved. Microsoft 365 lets you convert a user mailbox to a shared mailbox, which keeps everything in place, keeps it searchable, and lets you give named colleagues access to it. You do not need to pay for a licence to keep it.
How quickly should an account be closed when someone leaves?
On their last working day, as part of the leave process.
Not the following week, and not when someone gets round to it. If there is a notice period and a risk of an acrimonious exit, it may need to be sooner. The point is that it has a trigger and an owner, rather than depending on someone remembering.
Is an old email account really a data protection issue?
Yes. UK GDPR Article 32 requires appropriate security for personal data, and an unmonitored live account is not that.
If a leaver’s mailbox is breached and it contains client tax records or payroll data, that is a personal data breach the practice has to assess and, in most cases of this kind, report to the ICO within 72 hours. The ICO’s interest will be in whether reasonable measures were in place. An account belonging to someone who left years ago is difficult to defend.
What about everything that is not email?
Email is usually the smallest part of the problem.
In an accountancy practice, the more significant access tends to sit in HMRC agent services, the practice management and bookkeeping software, Companies House filing credentials and client portals. Those are rarely on anyone’s offboarding list because they were never on an onboarding list either. It is worth writing down every system a new joiner is given access to. That list becomes your leaver list.
Want us to look at your own account list?
If you would like us to check which former employee Microsoft 365 accounts are still live in your own tenant, you are welcome to book a meeting with me or connect with me on LinkedIn.
You may also want to read our case study on closing the third-party security gap for a regulated business.

