Office move IT checklist for London SMEs
Office move IT checklist for London SMEs: internet lead times, surveys, cabling, network design, servers and security before and after moving.
·
4 min read
Offboarding staff from Microsoft 365 or Google Workspace is a short list of admin steps, and the order matters more than the list. Cut access first, keep the data second, and only delete the account once the mail, files and licence have somewhere to go.
In Microsoft 365, reset the password, then use Sign out of all sessions on the user's Account tab in the admin centre, then Block sign-in. Microsoft's own guidance says a block can take up to 24 hours to take effect, while the password reset works straight away, and an existing access token can stay valid for up to an hour unless you revoke sessions with PowerShell.
In Google Workspace, change the password, reset the user's sign-in cookies and remove their recovery email and phone number, so the account can't be recovered by the person who just left. Suspending the user stops sign-in but keeps the data. Plan it as a timed job, not something someone gets round to on Monday.
A new password doesn't help if an old phone still holds a working token. On Google, revoke security keys, app-specific passwords and OAuth tokens for third-party apps. On Microsoft, remove their registered sign-in methods and any legacy app passwords.
Then deal with the phone and laptop. Exchange admin centre lets you run an account-only remote wipe and block the device, and Google's Admin console can wipe the whole device or just your organisation's data.
This is the step people rush. In Microsoft 365 you have two sensible options for mail. Convert the mailbox to a shared mailbox, which Microsoft says needs no licence while it's under 50 GB, or forward new mail to a colleague. Either way, don't delete the account, because it anchors the forwarding or the shared mailbox.
OneDrive behaves differently. By default the user's manager gets access when the account is deleted, and has 30 days to take what they need unless you've changed the retention period. Microsoft also now archives unlicensed OneDrive accounts on their 93rd unlicensed day into a paid archive, so "we'll just leave it" costs money.
In Google Workspace, transfer Drive files to a new owner before or during deletion. Gmail isn't included in that transfer. You either migrate the mail to another account or redirect incoming messages, and Google says any data that isn't transferred is deleted. You can restore a deleted user for 20 days, then it's gone.
Remove the leaver from shared mailboxes and groups, look for forwarding rules they set up themselves, and cancel meetings they organised, because Microsoft notes booked rooms stay unavailable until those meetings are cancelled. Google warns that deleting a calendar owner now deletes their secondary and group calendars too, so transfer those first.
Suspended Google users are still charged at the same rate as active ones, on both the Annual and Flexible plans. In Microsoft 365, removing the licence from a user frees it for the next hire, but you keep paying for it until you reduce the licence count on the subscription.
The platform steps don't touch the passwords that live outside it: the domain registrar, the social accounts, the Wi-Fi key, the card on the cloud account. Rotate anything the leaver knew, and check the secrets sitting in your git repository if they were a developer.
On retention, don't delete by reflex. If you might need the mail for a dispute, Microsoft offers holds and inactive mailboxes on the right plans, and Google's route is archiving the user or Vault retention rather than deleting.
When offboarding staff from Microsoft 365 or Google Workspace, lock out, revoke, keep the data, transfer ownership, then reclaim the licence and delete. If you can't say today who in your business can read a leaver's mailbox, or which staff still have working accounts, that's a gap worth checking properly. Leaver access and lost devices are within the scope of an Eight Mile security audit, alongside the cloud accounts and identity behind them. If you're weighing options, here's the difference between an audit and a pen test.
If you'd like a London engineer to look at how your business handles leavers across Microsoft 365 or Google Workspace, tell us what you run and we'll scope a review.
Office move IT checklist for London SMEs: internet lead times, surveys, cabling, network design, servers and security before and after moving.
·
4 min read
Multi-site office network design for London SMEs: site-to-site links, consistent segmentation, accounts you keep.
·
3 min read
Security audit vs penetration test: when to review config first, when a buyer needs a pentest, and usual order for SaaS.
·
3 min read
Secrets in git repository history outlive a deleted file. Rotate first, then stop the next temporary commit.
·
3 min read
Website care plan vs rebuild: when maintenance is enough for a London SMB site, and when a full rebuild earns the spend.
·
3 min read
When UniFi is enough, and when you want Meraki/Cisco: cost, ownership, multi-site, and support for London offices.
·
3 min read
Separate guest Wi-Fi from office network traffic so visitors never sit one hop from finance, payments, or file shares.
·
3 min read
A backup restore test proves copies work on a clock you can live with. Untested backups are hope with a green tick.
·
3 min read
Moving off the server under the desk: stage a move to managed hosting or cloud you own — without a big-bang rewrite.
·
3 min read
Multi-tenant SaaS mistakes that show up after launch: isolation, roles, files, billing, and when to stop and fix.
·
3 min read
Office network for a growing London team: when the ISP router fails, what a proper office network includes, and why survey first.
·
3 min read
Security audit checklist before you go live: access, secrets, backups, auth, deps, alerting, and when to bring in an auditor.
·
3 min read