When a collision-center employee leaves, email is usually the first account everyone remembers. It is visible, important, and easy to name. The trouble is that email may be only one doorway into a much larger working environment.

An estimator, parts employee, manager, or technician may also have Windows access, a saved browser session, a VPN, remote-control software, a collision-management login, an insurer portal, a parts account, a shared mailbox, a phone, and business files. Closing one account can make the task look finished while the other access paths remain unresolved.

A complete collision-center offboarding process disables the main identity, revokes active sessions, removes access from every system the employee used, addresses company devices, and preserves or transfers business data before any permanent deletion decision.

Why Is Disabling Email Not Enough?

Email access and organizational access are related, but they are not the same thing. A Microsoft 365 account may connect to email, OneDrive, Teams, browser sessions, and other cloud resources. Separate applications may use their own usernames, passwords, or vendor-managed roles. A Windows workstation may still have a local profile or an authenticated session. A remote-support tool or VPN may have its own permission list.

Microsoft's current former-employee guidance treats blocking sign-in, preserving email and files, forwarding or converting a mailbox, removing licenses, and deleting the account as separate steps. Microsoft also notes that blocking sign-in can take time, which is why password and session actions may be part of an immediate response. That same separation is useful beyond Microsoft 365.

Which Accounts Are Easy to Miss in a Collision Center?

The accounts most often missed are the ones owned by separate vendors, shared by a department, saved in a browser, or used only for a specialized workflow. Start with what the employee actually did rather than a generic software list.

  • Cloud identity and email, including Microsoft 365 or Google Workspace, multi-factor methods, recovery information, aliases, forwarding, and delegated mailbox access.
  • Windows or local computer access, including domain accounts, local accounts, cached profiles, shared workstations, and administrator rights.
  • VPNs, remote desktops, remote-support tools, and site-to-site resources the employee could reach.
  • Estimating, shop-management, repair-workflow, parts, rental, insurer, OEM, calibration, scanning, payment, accounting, and customer-communication applications.
  • Shared mailboxes, distribution groups, cloud folders, shared drives, saved browser profiles, password managers, and team credentials.
  • Company laptops, phones, tablets, removable storage, keys, access cards, and any device enrolled in management or security services.

The list will be different for a painter, estimator, general manager, and multi-location administrator. The manager who knows the employee's job should help identify the systems; IT should confirm the technical access and record each item as complete, not applicable, transferred, retained, or pending vendor action.

Do Password Changes End Every Existing Session?

Not always. A password change prevents many future sign-ins, but an existing authenticated session may have a token, cookie, or device state that needs separate revocation or verification. Microsoft Entra provides a revoke-sessions action for this reason, and Microsoft documents that some applications can retain access until their tokens expire or the application checks again.

We handled a private collision-center access concern where the practical lesson was simple: changing a credential and confirming that every existing session has ended are not necessarily the same event. We verified the situation and made sure the remaining access was closed. The account, device, location, and response details stay private.

What Should Happen First?

The first phase should stop access quickly and predictably without destroying business information. The authorized manager should provide the employee, effective time, locations, role, known devices, and any special instructions. IT can then act against the main identity and the highest-risk remote paths while the broader checklist is completed.

  1. Confirm authorization and timing. A named business leader decides when access should end and whether any systems must remain available for a controlled transition.
  2. Disable the primary cloud or directory identity, reset credentials when appropriate, and revoke active sessions or tokens supported by the platform.
  3. Remove VPN, remote desktop, remote-support, privileged, and administrator access. These paths deserve early attention because they can reach more than one system.
  4. Remove the employee from collision, parts, insurer, payment, accounting, phone, messaging, and other vendor systems based on the role inventory.
  5. Secure company devices and physical access items. Record whether each device was returned, remotely restricted, reassigned, wiped, or still outstanding.
  6. Transfer ownership of business email, files, calendars, contacts, documents, and application records before deleting the underlying account.
  7. Verify and document the result. Note what was completed, what was not applicable, what awaits a vendor, and who owns each remaining item.

Why Revocation Retention Transfer and Deletion Must Stay Separate

Revoking access answers who can sign in now; retention answers what the business must keep; transfer answers who needs the work product; deletion answers when the account and data should be removed. Combining those decisions creates avoidable mistakes.

An account can be blocked immediately while its mailbox and files are preserved for an approved period. A manager can receive access to necessary business records without receiving the former employee's password. A license may be removed only after mailbox or file plans are settled. The correct sequence depends on the platform, the company's policy, contractual requirements, and advice from qualified HR or legal professionals when needed.

A Real Collision Center Offboarding Example

One documented termination request required a cross-system checklist rather than a single account change. Tech Marvel reviewed which systems applied, disabled cloud access, addressed separate collision and workflow applications, checked devices and sessions, and treated non-applicable systems as explicit checklist results.

There was no documented misuse. The value of the example is operational: the shop could see that offboarding had been completed across the employee's real work environment instead of assuming that an email change covered everything.

What Should Collision Center Leadership Ask For?

Ask for a repeatable checklist, an owner for every step, and evidence of completion. The process should identify how quickly requests must reach IT, which vendors require separate action, how sessions and devices are handled, how business data is transferred, and when retained accounts are reviewed for final disposition.

For managed IT services for collision centers, Tech Marvel can coordinate the IT-access portion of onboarding and offboarding across covered accounts, devices, sessions, applications, and vendors. The exact scope depends on the agreement and the systems the client identifies.

If you want to review where former-employee access could be missed in your shop, schedule a Free 20 Minute Automotive IT Risk Review. If you are not ready to schedule, take the account categories above to the person who handles departures and mark who owns each one.

Frequently Asked Questions

Should we delete the employee's Microsoft 365 account immediately?

Usually the immediate security action is to block access and revoke sessions. Deletion should follow the company's approved retention, mailbox, OneDrive, ownership-transfer, and legal-record decisions. Microsoft treats these as separate administrative steps.


Who should tell IT that an employee is leaving?

A named authorized manager or HR contact should provide the effective time and role information. Tech Marvel can execute covered IT steps, but the client controls the employment decision, timing, and retention instructions.


Can Tech Marvel remove every vendor account?

Tech Marvel can remove or coordinate access within the agreed scope. Some proprietary platforms require the client's application administrator or the vendor to act. The checklist should make those handoffs visible rather than assuming they happened.