What to do when your IT person quits: the first week is about access, not repairs

Your IT person just left. The instinct is to start interviewing. The real emergency is that one person may still be the only route into your domain name, your Microsoft 365 tenant, your firewall and your backups, and none of it is written down anywhere you can find.

About this piece

  • Article
  • Managed IT
  • Written by Nicholas Backwell · Founder, Redsilicon
  • Updated 2026-08-24

Hiring can wait a week. Access cannot.

The short version

  • Your domain name is the single point of failure. Whoever holds the registrar login holds your email and your website.
  • Do not delete the departing person’s account. Block sign-in, reset the password, revoke active sessions and remove their registered second-step methods.
  • Make sure two people who work for you hold global administrator in Microsoft 365, and one of them is an owner.
  • Change every shared password that person knew, but find your service accounts first so you do not break a running backup job.
  • Ask for a real restore of a real file before you believe any backup report.

Access is the emergency, not the helpdesk queue

When someone leaves, nothing breaks on day one. Mail keeps flowing, printers keep printing, cameras keep recording. That is the trap. Everything works right up until the day something has to change, and then you find the domain renewal notice goes to a Gmail address nobody can open, or the sign-in prompt for the administrator account rings a personal phone that left the building.

Assume good faith. Most departures are ordinary. The problem is that one person’s memory was the documentation, and memory does not transfer.

Six things to get control of, in order

1. The domain name and the DNS records under it

Your domain (the yourcompany.ca part of your email address) sits with a registrar. Under it is DNS, the records that tell the rest of the internet where your mail and your website live. If mail is the thing that breaks, an MX record is what broke.

A public WHOIS lookup will name the registrar holding your domain and roughly when it expires. Getting the login is the harder part.

Fix four things once you are in:

  • Move the registrant and administrative contact to a company email address more than one person can open.
  • Put the renewal on a company credit card and turn on auto-renew.
  • Turn on registrar lock, so the domain cannot be transferred away without a deliberate release step.
  • Turn on two-step sign-in for the registrar account itself.

You can do all of this alone. If you cannot get in, the registrar has a recovery process that asks for proof you are the business. Start it today, because it takes days.

2. Microsoft 365 global administrator

Global administrator is the account that can do anything in your tenant, including reading any mailbox and removing other administrators. If the only global admin was the person who left, you have a problem with a clock on it.

Sign in to the Microsoft 365 admin centre and list your administrators. Look for accounts you do not recognise, and for admin rights still held by former staff or outside vendors.

Then give a second person global administrator, ideally an owner. Create a break-glass account as well: a separate admin login tied to no individual, with a long password stored offline in a safe, used by nobody day to day.

If no administrator login works at all, Microsoft has a domain takeover process that proves you own the business by asking you to add a DNS record. That is why the domain comes first.

3. The departing person’s account and their MFA methods

Do not delete the account. Deleting can orphan files, strand licences and break automated jobs that were signing in as that user. Deletion is a month-four decision.

Do this instead:

  • Block sign-in and reset the password.
  • Revoke active sessions, which kicks out any device still holding a valid token.
  • Remove their registered second-step methods. Multi-factor authentication (MFA) is the code or app prompt after the password, and if it is still registered to a personal phone, that phone is still a way in.
  • Convert the mailbox to a shared mailbox so mail keeps arriving without paying for a licence.
  • Reassign ownership of their OneDrive and any files only they could see.

Then hunt for their personal phone number or personal email sitting as the recovery method on other company accounts. The registrar, the bank portal, the alarm account and the ISP portal are the usual four.

4. Shared passwords and service accounts

Every business has a pile of logins nobody owns: info@, accounts@, the Wi-Fi password, the alarm panel code, the accounting software admin, the camera recorder, the ISP portal.

Anything the departing person knew should change. That is hygiene, not suspicion.

Before you rotate anything, spend an hour finding your service accounts. A service account is a login a piece of software uses rather than a person: the account a backup job signs in with, the account the scanner uses to email PDFs, the account connecting your field software to accounting. Change one of those blind and something stops working on a Saturday. Write them down first, rotate second.

While you are here, buy a password manager with a shared company vault. The vault belongs to the business, not to whoever administers it.

5. The firewall and the ISP account

The firewall is the box between your network and the internet, and it is usually the least documented device in the building. Find it, note the model, find out who can log in.

Four things worth knowing:

  • Whether it has an active security subscription and when that expires. When the subscription lapses, filtering quietly stops while the box keeps forwarding traffic.
  • Whether there are remote access or VPN accounts, and whose. Remove the departing person’s.
  • Whether any port is forwarded from the internet to something inside, and what.
  • Your ISP account number and who is an authorised contact. Carriers will not discuss the account with someone who is not on it, and adding yourself is a phone call best made now rather than during an outage.

Finding the box and fixing the ISP contact list is a you job. Changing firewall rules is not, unless you already know what the rules do.

6. Backups, proven by an actual restore

A backup nobody has ever restored from is not a backup. It is a scheduled job that reports success.

Find out four things: what is backed up, where the copies live, how far back you can go, and when someone last restored something on purpose.

Two blind spots come up almost every time. Microsoft 365 is usually not in the backup, because people assume Microsoft handles it. And the backup destination is often an account only the departed person could reach.

Ask for a restore of one real file today. Not a report. A file.

The vendor list and the documentation that should exist

Nobody hands you a vendor list, so build one. Pull twelve months of bank and credit card statements and highlight every recurring technology charge. That finds the subscriptions nobody remembers and the monitoring contract that renews next month. For each vendor, capture the account number, the main contact, who is authorised to request changes, and the renewal date.

When people say a business has no IT documentation, this is the list they mean:

  • A simple network diagram: what connects to what, and where the equipment lives.
  • A list of every device with a fixed address, and what it does.
  • An account register: every system, who has admin on it, where the credential is stored.
  • Labelled patch panels and wall plates that match a port list.
  • A licence and renewal calendar.
  • A written restore procedure, including how to get back in if the main admin account is unavailable.

If you have none of it, that is normal, and producing it is the first thing an incoming IT consulting engagement should do before anyone touches configuration.

What you can do alone, and what needs somebody

TaskDo it yourselfBring somebody in
Registrar contact email, lock, auto-renew, two-stepYesOnly if you cannot prove ownership
Second global admin and a break-glass accountYesOnly if no admin login works
Block account, revoke sessions, strip MFA methodsYesNo
Inventory shared logins, buy a password vaultYesNo
Rotate service account passwordsCarefulYes, if you cannot identify what uses them
Audit firewall rules, VPN accounts, port forwardsNoYes
Verify backups with a live restoreAsk for itYes, run it with you watching

What this means for your building

Picture a thirty person contractor in Bowmanville. The IT person was the senior estimator who was good with computers, and over eight years he became the only one who knew the Wi-Fi password for the yard, the login for the camera recorder in the shop, and the account the field software used to push job data into accounting.

He retires. Nothing breaks for five weeks. Then the domain renewal fails because it was billed to his personal card, mail stops for a day and a half, and the recorder in the loading bay turns out to have stopped writing to disk in March. None of that was a technical failure. All of it was preventable in the week after he handed in his notice.

What to do about it, day by day

  1. Day one. Block the departing account, reset the password, revoke sessions, remove their MFA methods. Run a WHOIS lookup and find out which registrar holds your domain.
  2. Day two. Get into the registrar. Change the contact email, enable lock and auto-renew, turn on two-step sign-in.
  3. Day three. List your Microsoft 365 administrators. Add a second global admin, create the break-glass account, check executive mailboxes for forwarding rules.
  4. Day four. Inventory shared logins and service accounts on paper. Buy a shared vault. Rotate human passwords now, service accounts once you know what uses them.
  5. Day five. Find the firewall, remove the departing person’s VPN access, get added as an authorised contact on the ISP account.
  6. Day six. Sit with whoever manages backups and watch a file get restored.
  7. Week two. Build the vendor list from your statements, then start interviewing. You will interview far better now, because you know what you actually have.

Steps one through five are owner and office manager work with no technician required. The restore test and the firewall audit are where an outside pair of hands earns the money, and so is the decision about whether to hire internally again or move to managed IT support so the knowledge lives in a system instead of a person.

Want this scoped for your site?

Tell us the building and what you’re trying to achieve. We’ll tell you what it takes, and whether you actually need it.

Before you call

Can I just delete their account and be done with it?

No. Deleting removes the mailbox, can orphan files, and can silently break jobs signing in as that account. Block, reset, revoke, convert to a shared mailbox. Decide about deletion in a few months.

They left on good terms. Do I really have to change everything?

Change the passwords, yes. It has nothing to do with trust. If something goes wrong in six months, you do not want an explanation that starts with someone who has not worked here since spring.

Do I need to hire anyone at all?

Possibly not. A ten person office on Microsoft 365 with a decent firewall and cloud accounting may only need a few hours of help a month, and an hourly arrangement or a small helpdesk plan is honest and enough. Businesses with a server, a warehouse network, or cameras and access control on site usually need something ongoing, because those break at inconvenient times.

\n
\n \n