What is the joiner, mover, leaver lifecycle?
It is the full arc of an employee's identity in Microsoft 365: the joiner stage when an account and its access are first created, the mover stage whenever that person changes role or department, and the leaver stage when they depart and their access needs to be cut off. Most organisations have a rough process for the joiner and leaver ends. Almost none have a process for the middle, which is exactly where access quietly accumulates for years.
Why is the mover stage the one most businesses forget?
A leaver has an obvious trigger: someone resigns, and eventually IT is told. A mover has no equivalent trigger. Someone is promoted or moves teams, gets added to their new group, and everyone assumes the old access will be tidied up later. It rarely is. Three or four role changes over several years and that person holds a stack of permissions that no single manager would ever knowingly approve if asked all at once.
Why does group-based access matter so much for offboarding?
Access granted directly to a person, file by file or mailbox by mailbox, has to be found and removed the same way: one item at a time, and only if whoever is offboarding them happens to know where to look. Access granted through a role-based security group disappears the instant that group membership is removed, in one action, with a visible record of what changed. The joiner-stage decision about how access is granted is what determines whether the leaver stage is a five-minute task or a week of guesswork.
Isn't blocking sign-in enough to secure a departed employee's account?
No. Blocking sign-in stops new authentication attempts, but a session or refresh token issued before the block can keep an existing connection working for a period afterwards unless it is separately revoked. MFA methods and registered devices can also still exist and, depending on configuration, be usable for recovery. A thorough leaver process blocks sign-in, revokes active sessions and tokens, and removes MFA methods and devices, all as part of the same action rather than as separate steps someone might skip.
What should happen to a leaver's mailbox and OneDrive content?
The mailbox should be converted to a shared mailbox, with the licence reclaimed and delegated access given to a manager for a defined handover period, then a deliberate decision made about how long to retain it. OneDrive content should have ownership of business-critical files transferred to the manager or a team site before the account is disabled, rather than left to expire on default retention settings. Both of these depend on the account still being in a known, controlled state when the transfer happens, not scrambled together after the fact.
We have a hybrid Active Directory environment. Does that change anything?
It adds a step that's easy to miss. If the on-premises Active Directory account is not disabled at the same time as the cloud account, Entra Connect can quietly re-enable sign-in on its next synchronisation cycle, undoing the cloud-side block without anyone noticing. The fix is to disable the on-premises account in the same script or workflow that blocks the cloud account, not as a separate manual task performed on a different system by a different person.
How does the article on new starter setup relate to this tool?
Microsoft 365 new starter setup: the ordered checklist walks through the practical sequence for provisioning a new employee correctly. This tool scores whether your organisation is actually following a process like that one, consistently, across joiners, movers and leavers, and tells you where the gaps sit. The article is the instruction manual; the tool is the diagnostic.
How does the offboarding article relate to this tool?
Microsoft 365 offboarding: the day-one checklist sets out the ordered steps for shutting an account down properly on someone's last day. This tool measures whether that kind of checklist exists at all in your organisation, whether it is followed every time, and whether the mover stage that precedes it has left the account in a state that makes offboarding straightforward or genuinely difficult.
What does Frontrow's managed joiner, mover, leaver runbook include?
Frontrow takes ownership of the runbook itself: a documented, tested process covering account creation, role-change access updates, and departure handling, built on group-based access and Entra ID Governance automation where the tenant supports it. That includes the notification SLA with HR, the technical steps for each stage, and an audit trail that can be produced on request. It is delivered as part of Frontrow's managed services rather than a one-off document that goes stale within a year.