how to deprovision a laptop on employee exit
Deprovisions a laptop when an employee leaves. Covers remote wipe vs return, data backup, and inventory updates. Use for every offboarding. Not for device repair.
TL;DR
Decide return vs remote wipe based on the situation, back up any needed data before wiping, then wipe (remote wipe via MDM or Erase All Content on return), remove the device from the user in inventory, and return it to stock. Never leave a departed user's device assigned and encrypted in the field.
The error
(Offboarding step; no error.)Steps
- Check for data retention needs: legal hold, manager requesting files. Expected: cleared or backup plan made. Wiping first and asking later destroys evidence.
- If the device will be returned: send return instructions and a shipping label; set inventory to pending-return. Expected: return initiated. If it will not be returned (or is lost), issue a remote wipe via the MDM now.
- Revoke the device's access: remove from the user in the IdP, wipe corporate data or full wipe per policy. Expected: device shows wiped/retired in MDM.
- On receipt, verify the wipe completed and inspect for damage. Expected: confirmed. Then re-provision per the reuse checklist or retire it.
- Update inventory: user unassigned, state to in-stock or retired. Expected: accurate. Close the offboarding ticket only when the device state is resolved.
When to use
- Every employee exit
- Contractor end dates
When not to use
- Device repair (different flow)
- Temporary leave (do not wipe)
Compatibility
- Jamf, Intune, or any MDM with remote wipe
Variants
Device never returned
After the return deadline, remote wipe and mark it lost in inventory; follow the lost-device process.
Involuntary termination
Remote wipe immediately; do not wait for return.
Why it happens
Laptops hold cached credentials, VPN profiles, and company data. An offboarded device left active is an ex-employee with a key to the building.
Edge cases
- Personal data on the device: follow the jurisdiction's rules before wiping.
- FileVault/BitLocker: a remote wipe is cryptographic and fast; confirm the MDM reports success.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_SoSiCKdLzBm18zmReE4Nng
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.