ADMIN WORKFLOW / FREEFREE WORKFLOW

User Offboarding

Guide a controlled single-user offboarding process with discovery, handover checks and explicit change steps.

Read + manual change steps9 guided stepsActive Directory · Microsoft Entra · Exchange Online · Microsoft Teams · OneDrive
WHEN TO USE IT

Use this workflow when the job is clear and bounded.

This guide is designed for a single administrative task rather than a broad tenant-wide assessment. It keeps discovery, preparation, any manual change and final verification separate so you can review each step before moving on.

Block or disable sign-in with explicit confirmationRevoke active sessionsReview and change license assignmentMailbox handover or conversion guidanceOneDrive ownership/handover guidanceGroup membership review and removal plan
RUNBOOK

The workflow, in order.

Opselith does not execute these steps against your environment. Script steps open a reviewed Opselith template; change steps remain explicit so nothing is hidden behind a browser action.

  1. 01 · PREPARE

    Confirm scope, timing and handover owner

    Confirm the approved offboarding time, data owner and retention or legal requirements before touching the account.

  2. 02 · SCRIPT

    Review Teams memberships

    Export the Teams the user belongs to so ownership or membership dependencies are visible before access is removed.

    Open Export Teams for a user →
  3. 03 · SCRIPT

    Review mailbox forwarding

    Check existing forwarding before deciding on mailbox handover, conversion or new forwarding.

    Open Export mailbox forwarding →
  4. 04 · SCRIPT

    Review current license assignment

    Capture the current licensed-user state before licenses are removed or changed.

    Open Export licensed Entra users →
  5. 05 · SCRIPT

    Review OneDrive ownership and site state

    Use the OneDrive inventory to confirm the personal site and ownership context before handover decisions.

    Open Export OneDrive site inventory →
  6. 06 · ACTION

    Block sign-in and revoke active access

    Use your approved Entra or identity administration process to block access and revoke sessions at the agreed time. Opselith does not execute this change.

  7. 07 · ACTION

    Complete mailbox, OneDrive, group and license handover

    Apply the approved handover, membership and licensing changes in the authoritative administration tools.

  8. 08 · SCRIPT

    Verify disabled Entra users

    Use the Free disabled-user report as one verification signal after the access change.

    Open Export disabled Entra users →
  9. 09 · VERIFY

    Verify and close the offboarding

    Confirm access is blocked, handover is complete and the ticket records every retained or intentionally deferred item.

PRIVACY & CONTROL

Your tenant stays outside Opselith.

No tenant connection

The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.

Local progress only

Completed workflow step IDs can be stored in your browser. Identity values, tickets, usernames, domains and generated output are not part of that progress record.

Manual changes stay manual

Where no suitable reviewed script exists, the guide labels the action as a manual change rather than pretending the website performed it.

TRUST / EVIDENCE

Recorded trust facts, not a certification.

Opselith separates metadata review, static QA, analyzer evidence and runtime evidence. A missing runtime result or a Pending analyzer state is shown as-is rather than converted into a pass claim.

Static QAPassed

Workflow catalog, ordered runbook, local-progress and manual-change boundary QA.

PSScriptAnalyzerNot applicable

A guided workflow is not itself a PowerShell artifact.

Runtime evidenceNot yet recorded

No accepted runtime result is recorded for this workflow yet.

Execution boundaryRead + explicit manual change steps

browser-guided-runbook · no website tenant connection · tenant output stays outside Opselith.

Last reviewed28 Aug 2026

Trust metadata reviewed for the current 3.0 development contract.

Referenced scripts5

5 referenced scripts · 5 analyzer Passed · 0 Pending

Pending and Not yet recorded are evidence states, not failures. Review the generated script or runbook and validate it in your own environment before production use.

RELATED POWERSHELL

Scripts used by this workflow.

BEFORE YOU CLOSE THE JOB

Verify in the authoritative admin tools.

Use the final verification step to confirm the resulting account, membership, licensing or service state in the relevant Microsoft administration portal or Active Directory tooling. Opselith is a runbook and script-generation layer, not the system of record.