How to Submit User Onboarding and Offboarding Requests in Atomus

Last updated: October 8, 2026

Atomus supports the full user lifecycle — from onboarding new employees to offboarding departing ones. This article explains how to submit these requests, what information is required, and what to expect during each process.

Submitting an Offboarding Request

You can either remove users yourself through the Atomus portal or have Atomus support handle the offboarding process on your behalf. When Atomus support manages the offboarding, you must first approve a Change Management item in the Atomus portal before the process begins.

To initiate an offboarding request, contact Atomus support and provide the following information:

  • Employee name and email address

  • Deadline date (and time, if applicable) for offboarding

  • Whether the user's devices need to be offboarded or locked, and the device OS

  • Whether the Company Admin has physical possession of the user's device

  • Who should receive the departing user's data

  • Whether the departing user's mailbox should be converted to a shared mailbox or transferred intact to a new owner

  • Whether the user's OneDrive should be handed over, and if so, to whom

  • Whether the device is being reused internally or retired

Offboarding can be scheduled for a specific date and time. If you need a departing user's access to remain active beyond their planned departure date, notify Atomus support in advance.

What Atomus Does During Offboarding

When Atomus handles the offboarding, the following steps are performed:

  1. Reset the user's multifactor authentication method

  2. Revoke all Microsoft sessions

  3. Reset the user's password

  4. Disable the user's Microsoft account

  5. Remove the user's Duo enrollment

  6. Set up organizational data transfer via OneDrive and/or shared mailbox (if requested) and designate access to the specified user

  7. Assign the specified user access to the departing user's SharePoint data

  8. Deactivate the user's Aegis user account

  9. Unassign the user's Microsoft license

  10. Disable any Aegis devices assigned to the user

  11. Remove the user from Apple Business Manager (if applicable)

Data Transfer Options

Mailbox

Atomus can handle the departing user's mailbox in one of two ways:

  • Convert to a shared mailbox with delegated access granted to a nominated person. Once the license is released, there is no ongoing license cost.

  • Transfer the account intact to a new owner. This keeps a Microsoft license assigned to the account.

OneDrive

Atomus adds a nominated person as an administrator on the departing user's OneDrive. Note that this grants access to the entire OneDrive — partial or folder-level handover is not possible. Because access is all-or-nothing, the recommended approach is to review the OneDrive contents before granting access to the new person. You can either:

  • Have Atomus grant you access first so you can review the contents yourself before deciding who to add, or

  • Hold the handover entirely until you have reviewed the contents.

Third-Party App Permissions

If the departing user ever approved third-party app access against your Microsoft account, those permissions are not automatically removed when the user account is disabled. These must be checked and removed separately. Atomus can assist with reviewing and removing third-party app permissions upon request.

Important: The "Deactivate" Button in the Atomus Dashboard

Warning: The Deactivate option in the Atomus Security Dashboard only removes the user from the Atomus enclave group and database. It does not deactivate the user in Microsoft systems. Microsoft offboarding steps must be completed separately before clicking the Deactivate button in the Atomus portal.

Performing the Microsoft Offboarding Steps Yourself

If you prefer to handle the Microsoft side of offboarding independently, follow these steps in Microsoft Entra ID:

  1. Navigate to Users and click into the user to be offboarded.

  2. Open Authentication methods.

  3. Click Revoke sessions.

  4. Click Require re-register multifactor authentication.

  5. Click Reset password.

  6. Disable the user's account through the Overview page so that "Account status" shows "Disabled".

After completing these steps, notify Atomus support to complete the Atomus-side deactivation. You may also optionally convert the account to a shared mailbox, remove licenses, and update the display name to indicate the account is disabled (e.g., Jane Smith (Disabled)).

Device Handling During Offboarding

If the departing user is not retaining possession of their Windows CUI laptop or BYOD phone, no actions are required on either device prior to their departure. Atomus can take all necessary offboarding actions after receiving the Change Management confirmation and required details.

When offboarding a user with a managed device, verify that the device has been factory reset before completing the offboarding process. Atomus monitoring can confirm whether a device is still checking in to their systems.

For devices being reused after offboarding:

  • Re-assigning to another Aegis (CUI) user: A full wipe is not required — a normal Windows reset is sufficient. The device can then be re-enabled and re-assigned. If needed, the Company Admin can re-enable the device in Microsoft Intune by navigating to the device properties page.

  • Transferring from CUI to non-CUI use: The device must undergo complete disk erasure using a sanitization tool such as BitRaser.

Accessing a Departing User's Windows Device

If you need to access a departing user's Windows device (for example, to retrieve resources that were not fully backed up), there are two options:

  1. Reset the user's Microsoft password using an admin account and log in as them. If Duo is configured, you will also need to reset the Duo phone number so that authentication requests are directed to you rather than the departing user.

  2. Log in to the device using a Global Admin account.

Transferring a License to a Replacement Employee

If you are simultaneously offboarding a departing user and onboarding a replacement employee, Atomus can transfer the departing user's license and account to the new employee. The workflow is:

  1. Submit the offboarding Change Management request for the departing user and approve it in the Atomus portal.

  2. Once offboarding is complete, Atomus will transfer the license to the new user.

  3. Atomus will send onboarding emails with credentials to the new user to set up their device.

Offboarding Options for Users Who May Return

For users who may return in the future (such as interns or temporary employees), there are two approaches:

  • Option 1 – Full offboarding: Disable users, disable devices, transfer data to an authorized party, and remove licenses. Users can be re-onboarded later if needed. Note that while users will not be deleted, they will lose data 30 days after their licenses are unassigned. This option is recommended if you want to free up licenses and are prepared to manage data retention proactively.

  • Option 2 – Temporary disable: Disable users and devices in Microsoft while keeping Microsoft licenses assigned. This preserves the user's data and makes re-enablement straightforward. Notify Atomus when you are ready to either re-enable the users or proceed with complete offboarding. This option is recommended if data retention is a high priority and you do not need to free up licenses immediately.

Handling Users Who Were Never Formally Offboarded

If you have former employees who were never formally offboarded, you can review the list of Atomus users in the Dashboard, identify accounts that should be disabled or deactivated, and notify Atomus support. Atomus will then submit a Change Management request to offboard those users.

Cancelled Onboardings (User Never Accessed Company Systems)

For cancelled onboardings where the user never accessed the company environment or any company systems, the process differs from a standard offboarding:

  • Your IT team handles the Microsoft account cleanup: disabling the account, revoking all sessions, unassigning licenses, and removing the user from Intune.

  • Atomus removes the user from the Dashboard and creates a Change Management request for tracking purposes. Once approved, Atomus deactivates the user on their end.

If the user did access company resources before their onboarding was cancelled, treat the cleanup as a standard offboarding rather than a cancelled onboarding.

Offboarding Non-Aegis Users

For employees who are not Aegis users, the offboarding process is managed entirely by your organization — Atomus does not handle it. In this case, Atomus recommends disabling the user's account and optionally converting it to a shared mailbox if your team still needs access to the departing user's data.