Frontrow Technology

Free tool · 5 minutes · Microsoft 365 identity lifecycle

JOINER, MOVER, LEAVER —
PROCESS AUDIT.

Every business has a starter process and a leaver process. Almost none of them survive contact with a resignation on a Friday afternoon. Score how access is granted, changed and removed across the full Microsoft 365 identity lifecycle in five minutes — including the mover stage most audits never look at.

20 questions · 5 domains

Joiner, Mover, Leaver Process Audit

Score how your organisation handles the full Microsoft 365 identity lifecycle — from the day someone starts, through every role change, to the day they leave. Pick the option closest to how it actually works today, not how the policy document says it should work.

Domain 1

Joiner: account creation and access

How new-starter accounts are created, whether access is granted by group membership or file by file, and whether MFA is registered before first use.

  • How are new-starter accounts created in Microsoft 365?

    Source: Microsoft Entra ID Governance guidance on Lifecycle Workflows.

  • When a new starter needs access to files, mailboxes, and applications, how is that access granted?

    Source: Microsoft Entra ID guidance on role-based access via group membership.

  • Is a new starter fully provisioned — mailbox, licence, applications — and ready to work on their first day?

    Source: General practice — new-starter onboarding lead-time benchmarks in Australian managed IT. See also: Microsoft 365 new starter setup: the ordered checklist.

  • How is multi-factor authentication registration handled for new starters?

    Source: Microsoft Entra ID Conditional Access guidance on MFA registration enforcement.

Domain 2

Mover: role change and access accumulation

What happens to access when someone changes role internally — and whether their previous access is ever formally removed rather than simply added to.

  • When someone changes role or department internally, is there a defined process to update their Microsoft 365 access?

    Source: Microsoft Entra ID Governance guidance on entitlement management.

  • When someone moves roles, is their previous role's access ever formally removed?

    Source: Microsoft Entra ID guidance on least-privilege access and group membership hygiene.

  • Have you ever reviewed how much access your longest-serving staff have accumulated across multiple role changes?

    Source: Microsoft Entra ID Governance guidance on access reviews for privilege creep.

  • Do you run periodic access reviews across the organisation, not just at the point of a role change?

    Source: Microsoft Entra ID Governance access reviews guidance.

Domain 3

Leaver: identity and sign-in

Speed of sign-in blocking, whether active sessions and tokens are revoked, and whether MFA methods, devices, and hybrid on-premises accounts are all shut down together.

  • How quickly is a departing employee's sign-in blocked once IT is notified?

    Source: Microsoft Entra ID guidance on blocking user sign-in.

  • When an account's sign-in is blocked, are active sessions and refresh tokens also revoked?

    Source: Microsoft Entra ID guidance on revoking user access, including session and token invalidation.

  • Are MFA methods and registered devices removed or reset for departed employees?

    Source: Microsoft Entra ID guidance on managing authentication methods.

  • For hybrid Active Directory environments, how synchronised is on-premises account disablement with the cloud block?

    Source: Microsoft Entra Connect hybrid identity guidance on synchronised account disablement.

Domain 4

Leaver: data and devices

What happens to the mailbox, OneDrive content, personal devices carrying company data, and company-owned hardware when someone leaves.

  • What happens to a departed employee's mailbox?

    Source: Microsoft Learn guidance on converting a user mailbox to a shared mailbox.

  • What happens to a departed employee's OneDrive content?

    Source: Microsoft Learn guidance on OneDrive retention and data access for departed users.

  • Is company data removed from personal devices, such as BYOD phones and laptops, when someone leaves?

    Source: Microsoft Intune guidance on app protection policies and selective wipe.

  • What happens to company-owned devices, such as laptops and phones, when someone leaves?

    Source: General practice — Australian managed IT asset lifecycle management.

Domain 5

Process and evidence

Whether IT is told before someone leaves, whether a documented runbook exists, whether licences are reclaimed, and whether any of it can be proven after the fact.

  • Is IT told about a departure before or on the person's last day, rather than finding out after?

    Source: General practice — offboarding notification lead-time benchmarks. See also: Microsoft 365 offboarding: the day-one checklist.

  • Is there a documented, repeatable offboarding runbook that anyone in IT can follow?

    Source: General practice — IT operations runbook standards.

  • When someone leaves, is their Microsoft 365 licence reclaimed promptly?

    Source: Microsoft 365 admin centre guidance on licence assignment.

  • If asked, could you produce evidence of exactly what access was granted, changed, and removed for a specific individual over their employment?

    Source: Microsoft Entra ID guidance on audit logs and sign-in log retention.

This is an indicative self-assessment. It is not a substitute for a tenant-level identity governance review. For verified results Frontrow Technology offers an in-tenant joiner, mover, leaver audit.

What the audit covers

Five domains. One identity lifecycle.

Domain 1

Joiner: account creation and access

The joiner stage sets the pattern for everything that follows. Access granted individually, file by file, has to be found and unpicked individually when it needs to be removed. Access granted through a role-based security group disappears the moment the group membership does. Get this stage wrong and every later stage inherits the mess.

Domain 2

Mover: role change and access accumulation

This is the domain almost nobody has thought about. A leaver process gets attention because it has a clear trigger: someone resigns. A mover has no equivalent trigger. Someone changes role, gets added to a new group, and nobody circles back to remove the old one. Three role changes later they hold the access of four different jobs, and nobody notices until an audit or a breach forces the question.

Domain 3

Leaver: identity and sign-in

Blocking sign-in is the visible half of cutting someone off. The invisible half is revoking the session and refresh tokens that let an already-open connection keep working after the block, and removing the MFA methods and devices that could be used to get back in. A hybrid environment adds a third half: the on-premises account that Entra Connect can quietly re-enable on its next sync.

Domain 4

Leaver: data and devices

Cutting off identity is only half the leaver problem. The mailbox and OneDrive still hold business records someone else needs. Personal phones and laptops may still have company mail and files on them. Company-owned devices need to be returned, wiped, and reissued. None of this happens by accident — it happens because a runbook says it has to.

Domain 5

Process and evidence

A good technical control that nobody follows consistently is worse than a documented process that's followed every time. This domain scores whether the joiner, mover, leaver lifecycle is actually a process — with a trigger, a runbook, and an audit trail — rather than something that happens when someone remembers.

Frequently asked questions

What Australian IT and HR teams ask.

What is the joiner, mover, leaver lifecycle?

It is the full arc of an employee's identity in Microsoft 365: the joiner stage when an account and its access are first created, the mover stage whenever that person changes role or department, and the leaver stage when they depart and their access needs to be cut off. Most organisations have a rough process for the joiner and leaver ends. Almost none have a process for the middle, which is exactly where access quietly accumulates for years.

Why is the mover stage the one most businesses forget?

A leaver has an obvious trigger: someone resigns, and eventually IT is told. A mover has no equivalent trigger. Someone is promoted or moves teams, gets added to their new group, and everyone assumes the old access will be tidied up later. It rarely is. Three or four role changes over several years and that person holds a stack of permissions that no single manager would ever knowingly approve if asked all at once.

Why does group-based access matter so much for offboarding?

Access granted directly to a person, file by file or mailbox by mailbox, has to be found and removed the same way: one item at a time, and only if whoever is offboarding them happens to know where to look. Access granted through a role-based security group disappears the instant that group membership is removed, in one action, with a visible record of what changed. The joiner-stage decision about how access is granted is what determines whether the leaver stage is a five-minute task or a week of guesswork.

Isn't blocking sign-in enough to secure a departed employee's account?

No. Blocking sign-in stops new authentication attempts, but a session or refresh token issued before the block can keep an existing connection working for a period afterwards unless it is separately revoked. MFA methods and registered devices can also still exist and, depending on configuration, be usable for recovery. A thorough leaver process blocks sign-in, revokes active sessions and tokens, and removes MFA methods and devices, all as part of the same action rather than as separate steps someone might skip.

What should happen to a leaver's mailbox and OneDrive content?

The mailbox should be converted to a shared mailbox, with the licence reclaimed and delegated access given to a manager for a defined handover period, then a deliberate decision made about how long to retain it. OneDrive content should have ownership of business-critical files transferred to the manager or a team site before the account is disabled, rather than left to expire on default retention settings. Both of these depend on the account still being in a known, controlled state when the transfer happens, not scrambled together after the fact.

We have a hybrid Active Directory environment. Does that change anything?

It adds a step that's easy to miss. If the on-premises Active Directory account is not disabled at the same time as the cloud account, Entra Connect can quietly re-enable sign-in on its next synchronisation cycle, undoing the cloud-side block without anyone noticing. The fix is to disable the on-premises account in the same script or workflow that blocks the cloud account, not as a separate manual task performed on a different system by a different person.

How does the article on new starter setup relate to this tool?

Microsoft 365 new starter setup: the ordered checklist walks through the practical sequence for provisioning a new employee correctly. This tool scores whether your organisation is actually following a process like that one, consistently, across joiners, movers and leavers, and tells you where the gaps sit. The article is the instruction manual; the tool is the diagnostic.

How does the offboarding article relate to this tool?

Microsoft 365 offboarding: the day-one checklist sets out the ordered steps for shutting an account down properly on someone's last day. This tool measures whether that kind of checklist exists at all in your organisation, whether it is followed every time, and whether the mover stage that precedes it has left the account in a state that makes offboarding straightforward or genuinely difficult.

What does Frontrow's managed joiner, mover, leaver runbook include?

Frontrow takes ownership of the runbook itself: a documented, tested process covering account creation, role-change access updates, and departure handling, built on group-based access and Entra ID Governance automation where the tenant supports it. That includes the notification SLA with HR, the technical steps for each stage, and an audit trail that can be produced on request. It is delivered as part of Frontrow's managed services rather than a one-off document that goes stale within a year.