What to Do With a Mailbox When an Employee Leaves

The short answer
When an employee leaves, block their sign-in first, then place a litigation hold if records need preserving, delegate or convert the mailbox to shared so colleagues retain access, set an auto-reply and forwarding rule for incoming mail, and only then remove the licence. Removing the licence before placing a hold starts the deletion clock.
Block sign-in, place a hold, convert to shared, set forwarding, then remove the licence when an employee leaves Microsoft 365 or Google Workspace.
On this page
When an employee leaves, the mailbox question arrives fast and usually goes wrong in the same two ways. Someone deletes the account too quickly and triggers the deletion clock before a hold is in place. Or someone holds the account, never removes the licence, and pays for an unused mailbox for months. The right sequence threads between these two failure modes.
Block the sign-in first so the departing employee cannot access mail after their last day. Place a hold if records may be needed later — this step must happen before the licence is removed. Delegate or convert the mailbox so colleagues can still access it. Set a forwarding rule or auto-reply so incoming mail reaches the right person. Only then remove the licence. In Microsoft 365, a shared mailbox under 50 GB requires no licence at all, so the ongoing cost goes to zero without sacrificing access to the history.
The short answer#
Here is the five-step sequence for what to do with a mailbox when an employee leaves, in the order that keeps records intact and stops the unnecessary licence spend:
- Block sign-in immediately in Microsoft Entra ID or Google Admin — the employee loses authentication; the mailbox stays live and accessible to admins.
- Place a litigation hold or set a retention policy before removing the licence — this preserves the mailbox as an inactive mailbox in Microsoft 365, which survives indefinitely even without a licence.
- Convert to a shared mailbox or add delegate access so colleagues can read and respond from the address without a dedicated licence.
- Set an auto-reply informing senders the employee has left, and configure forwarding to the manager or a shared team inbox so nothing is missed.
- Remove the licence only after the hold is confirmed and the mailbox is converted or delegated — in Microsoft 365, a shared mailbox under 50 GB stays active at no additional cost.
Before you start#
Before you touch the account, collect four things: the employee's confirmed last day, the names of colleagues who need access to the mailbox after departure, whether there is an active legal hold or HR investigation requiring records to be preserved, and whether any shared mailboxes, distribution groups, or calendar delegates already reference the account.
Check whether the employee is the sole owner of any shared mailboxes or the only member of distribution groups. An ownerless shared mailbox cannot be managed through the normal admin paths, and a distribution group that loses its only member silently stops routing mail. Fixing these edge cases before disabling the account takes minutes; fixing them after takes significantly longer.
The distinction between blocking sign-in and deleting an account is the most important thing to understand before you start. Blocking sign-in disables authentication; the account and its mailbox stay intact, accessible to admins and delegates. Deleting the account is the point of no return. In Microsoft 365, deletion starts a 30-day soft-delete window before the mailbox is gone permanently. Everything in this guide happens between block-sign-in and account-deletion — plan that interval deliberately.
Licence removal and account deletion are not the same event
Steps: offboarding a Microsoft 365 mailbox#
These steps follow the order that protects records at every stage. Each step can be reversed except account deletion — once you delete the account and the soft-delete window closes, the mailbox is gone.
- 1
Block sign-in in Microsoft Entra ID
Go to the Microsoft Entra admin centre, navigate to Users, open the departing user, and toggle Block sign in to Yes. The employee's existing sessions are terminated within minutes. The mailbox remains active and fully accessible to admins — nothing is deleted.
- 2
Reset the password and revoke active sessions
Reset the password immediately after blocking sign-in so any session that had not yet expired cannot be used to reconnect. In the Entra admin centre, select the user and choose Reset password, then Revoke sign-in sessions. This closes any OAuth refresh tokens that were issued before the block.
- 3
Place a litigation hold or assign a retention policy
In the Microsoft Purview compliance portal, go to eDiscovery, create a hold, and add the departing user's mailbox. Alternatively, assign a retention policy through the Microsoft Purview Data lifecycle management section. Either method converts the mailbox to an inactive mailbox the moment the licence is removed, preserving it indefinitely. Confirm the hold is active before proceeding.
- 4
Convert to a shared mailbox or add delegate permissions
In the Exchange admin centre, go to Recipients, open the user mailbox, and choose Convert to shared mailbox. Conversion takes a few minutes and is irreversible without recreating the user account. If you need colleagues to send as the address or view it in Outlook, also add Full Access and Send As permissions under Mailbox delegation. A shared mailbox under 50 GB requires no Microsoft 365 licence.
- 5
Set an auto-reply to incoming senders
Use PowerShell to configure the out-of-office message: Set-MailboxAutoReplyConfiguration -Identity <upn> -AutoReplyState Enabled -ExternalMessage '<text>' -InternalMessage '<text>'. Include the name of the person or team to contact instead. You can also set this through Outlook Web Access if the admin account has full access to the mailbox.
- 6
Configure email forwarding to the manager or team inbox
In the Microsoft 365 admin centre, go to Users, select the departing user, open the Mail tab, and choose Manage email forwarding. Forward to the manager's address or a shared team inbox. Forwarding and shared mailbox access can coexist — colleagues read the mailbox directly while new mail also arrives in the team inbox.
- 7
Remove the licence
Return to the Microsoft 365 admin centre, open the user, go to Licences and apps, and uncheck the licence. Because the hold is already active and the mailbox is shared, removing the licence does not trigger deletion — the mailbox continues as an inactive shared mailbox. Verify the licence is removed and the mailbox still appears in the Exchange admin centre before closing the ticket.
Platform differences: Microsoft 365 vs Google Workspace#
The offboarding sequence is broadly the same across platforms, but the specific tools and the licence-free options differ significantly. Google Workspace has no direct equivalent to the Microsoft 365 inactive mailbox; preserving a former employee's mail long-term requires Google Vault, which carries its own licence cost.
| Task | Microsoft 365 | Google Workspace |
|---|---|---|
| Block sign-in | Entra admin centre → Users → select user → Block sign in | Google Admin console → Users → select user → More options → Suspend user |
| Preserve records without deleting | Microsoft Purview litigation hold or retention policy — creates an inactive mailbox | Google Vault (requires Vault licence add-on) — create a matter and place a hold before deleting the account |
| Shared or delegate access | Convert to shared mailbox in EAC, then add Full Access + Send As permissions | Delegate access via Admin console → Users → select user → Add info → Delegate mailbox (sends from original address) |
| Auto-reply for departing user | Set-MailboxAutoReplyConfiguration via PowerShell, or through OWA with full access | Admin console → Apps → Google Workspace → Gmail → Users → select user → Vacation responder |
| Mail forwarding | M365 admin centre → Users → Mail tab → Manage email forwarding | Admin console → Users → select user → User info → Email forwarding |
| Keep mailbox without a licence | Shared mailbox under 50 GB requires no licence; inactive mailbox requires a hold but no user licence | No equivalent — either keep the licence, transfer data to another user, or export and delete |
| Deletion clock after account removal | 30-day soft-delete window; inactive mailbox held indefinitely if hold is active | Data deleted 20 days after user deletion by default; configurable up to 280 days with data retention settings |
The practical consequence is that a Microsoft 365 offboarding can reach a stable, cost-neutral state — shared mailbox, no licence, records preserved in Purview — while a Google Workspace equivalent either carries a Vault licence cost or accepts a shorter preservation window. Both platforms are documented in detail in their respective admin help centres; verify current limits against the live Microsoft Learn and Google Workspace Admin Help pages, as retention periods and licence thresholds can change.

What to do when it does not work#
The most common failure is a shared mailbox conversion that completes in the Exchange admin centre but the mailbox stops appearing in Outlook for delegates. This usually means the licence was removed before the conversion completed, or the auto-mapping feature is behaving unexpectedly. Wait 30 minutes for directory sync to propagate, remove and re-add the Full Access permission, and ask the delegate to restart Outlook.
If the litigation hold does not appear to be active after you applied it, check the Microsoft Purview compliance portal under Data lifecycle management and confirm the hold status shows Active rather than Pending. Hold propagation to the mailbox can take up to 60 minutes. Do not remove the licence until the hold status is confirmed active — pending is not the same as active.
Auto-reply messages set via PowerShell sometimes do not reach external senders if the external reply is configured without the -ExternalAudience flag. Use -ExternalAudience All to ensure the message goes to everyone outside the organisation, not just to known contacts. Test from an address the departing employee would not have in their contacts list.
Shared mailbox auto-mapping in Outlook
A faster way: handling the shared mailbox continuously#
The steps above solve the immediate offboarding problem. The longer-term problem is that a shared mailbox — now receiving the former employee's ongoing mail — needs someone to actually read, triage, and respond to it. Left alone, a converted mailbox accumulates unread messages until whoever inherited it treats it as a second inbox they have to manage manually.
We build AI Emaily, an AI-native email client. When you connect a shared mailbox to AI Emaily, the agent can triage incoming mail, draft replies in the voice of the team rather than the individual who left, and surface threads that need a response — without requiring the manager or successor to sit in a separate Outlook window. Approvals stay with the human; nothing sends without a click in Copilot mode. The 7-day free trial on the Pro plan (card required, $0 if cancelled before day 7) covers shared mailbox connection. Check the current pricing at aiemaily.com/pricing.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.