When somebody leaves
Offboarding a person in one step: sign-ins ended, their mail kept for somebody, new mail answered and forwarded, and an undo for thirty days.
Removing a person well means ending their sign-ins, keeping their mail for somebody, answering and forwarding what still arrives, and eventually freeing their address, without losing anything on the way. Offboarding does all of it as one change that is reviewed first, recorded in the audit log, and can be undone for thirty days.
The examples use the vsx shell function from the Quick start.
Offboarding somebody
On the console, open the person from People and choose Leaving the organisation…. A checklist opens with each step set to a sensible default and a sentence on what it does. Review… shows exactly what will change, as the server would do it, and Offboard does it.
From the command line:
vsx admin people offboard ada@example.com --delegate bob@example.com --forward bob@example.com --reply 'Ada has left. For anything urgent, write to bob@example.com.' --remove-after 90d --dry-run
vsx admin people offboard ada@example.com --delegate bob@example.com --forward bob@example.com --reply 'Ada has left. For anything urgent, write to bob@example.com.' --remove-after 90d
--dry-run prints the review and changes nothing.
Several people at once
On People, tick everybody who is leaving and choose Offboard…: one checklist applies to them all, the review names who would leave and anyone who can’t, and why, and the button says how many. From the command line, name several addresses:
vsx admin people offboard ada@example.com carl@example.com --delegate bob@example.com --remove-after 90d
Up to 100 people go in one request. Each is offboarded as one person is, with their own record and audit line; somebody who can’t be, such as a shared mailbox, is listed with why and the rest go ahead. Where the organisation asks for approval to remove accounts, the whole list is one request to approve.
From your identity provider or directory
When SCIM deactivates or deletes somebody, or a directory sync finds they have gone, the person is offboarded with the organisation’s default choices, so their mail is kept and handed on rather than stranded. An organisation that wants the old behaviour, where the account is only disabled, sets offboarding.on_deprovision to disable; offboard is the default.
The steps
| Step | Default | What it does |
|---|---|---|
| Signing in | Always | Nobody can sign in as the person any more, by any means, while their mail keeps arriving. |
| Sessions | Ended | Every place they are signed in is signed out. --keep-sessions leaves them. |
| App passwords | Revoked | --keep-app-passwords leaves them. |
| Second steps and passkeys | Removed | --keep-second-steps leaves them. |
| Their mail | Kept as it is | Give it to a manager as a delegate (--delegate, reading and organising it by default, --access to choose), or turn it into a shared mailbox the team works in (--shared --member …). |
| Their calendars and contacts | Handed over with the mail | Whoever is given the mail is given the person’s calendars and address books too, to read and change; --keep-calendars-and-contacts leaves them as they are. Undoing the offboarding takes them back. |
| Copies of their calendars and contacts | None | --copy-calendars-to <address> (in the console, Copy their calendars and address books to) copies each calendar and address book into that person’s own account, named after the leaver, where it stays after the account is removed. A private event is copied as busy time only. Undoing the offboarding removes a copy nobody has changed since. |
| New mail | Delivered as usual | Forward it (--forward, keeping a copy unless --no-copy), and send an automatic reply from today (--reply, until --reply-until). |
| Legal hold | None | Put the mailbox on legal hold (--hold 'the matter'), if a matter needs it. |
| Removal | In 90 days | The account is removed on that day and its address freed (--remove-after 90d, a date, or never). |
A mailbox turned into a shared mailbox is never removed by a date: the team keeps working in it. A mailbox on legal hold is removed only once the hold is lifted.
Once an account is removed, its mail is deleted after offboarding.keep_removed_days days, 30 unless the organisation says otherwise (0 to 3650). For an account an earlier version of the server removed, the days count from the first time the upgraded server runs. Mail that a retention policy, a legal hold or a discovery case keeps is kept as long as they keep it. The audit log says how many messages were deleted and how many were kept, never which.
Afterwards
The person’s page says when they left, lists every step taken, and offers Undo… for the next thirty days. Undo puts back each step as it was before, unless somebody has changed it since, in which case it is left alone and the undo says so.
vsx admin people undo-offboarding ada@example.com --dry-run
vsx admin people undo-offboarding ada@example.com
What undo does not bring back:
- Sign-in credentials. Revoked app passwords, removed second steps and passkeys, and ended sessions stay gone; the person adds them again. Their password works again after an undo, unless their mailbox was turned into a shared mailbox, which clears it.
- A removed account. Once the removal day has passed, the offboarding can no longer be undone.
The review and the undo’s confirmation both say this before anything is done.
Who can do what
Organisation administrators offboard anybody. A domain administrator offboards people in their own domains, and can name delegates and members only there. Nobody can offboard themselves. Where the organisation requires approval for removing people, an offboarding waits for a second administrator; its review does not. Somebody who holds an administrative role can be offboarded, or have their offboarding undone, only by somebody who could grant that role.
Every offboarding is one line in the audit log, with each step’s before and after. A legal hold it sets has a line of its own.
Over the API
| Route | What it does |
|---|---|
POST /api/v1/tenants/{tenant}/accounts/{id}/offboard | Every step chosen, in one change. With dryRun, the review of the same change, and nothing done. |
POST /api/v1/tenants/{tenant}/offboard | Several people at once: accounts (1 to 100 ids or addresses) and the same choices. Answers who was offboarded and who was refused, with why. Takes dryRun. |
POST /api/v1/tenants/{tenant}/accounts/{id}/offboard/undo | Puts each step back, within thirty days. Takes dryRun too. |
GET /api/v1/tenants/{tenant}/accounts/{id} | Says whether the person has left, and their offboarding: each step taken and the removal day. |
Something unclear or out of date on this page? Tell us.