Joiner, mover, and leaver deserve their own lane, not a bullet inside Microsoft 365.
The service catalog already mentions "joiner/mover/leaver tasks where approved" in passing. That is honest, but it treats three different risk profiles as one bullet point. This page gives new-hire setup, role changes, and departures their own written request family — with a safe-stop built specifically for the moment someone leaves.
What enters the joiner, mover, leaver lane.
Useful when new-hire setup, role changes, and departures are currently absorbed into general Microsoft 365 administration instead of following their own written procedure. The delivery-model walkthrough already follows one joiner request end to end.
Joiner provisioning — account creation, group and license assignment, and device or access handoff against an approved role profile — mover requests adjusting group membership, license tier, and access when someone changes role, team, or location, and leaver processing: access suspension or removal, license reclamation, and a data-retention handoff on an agreed timeline.
A joiner request completes with the account, license, and access matching the approved profile before the person's start date; a leaver request completes with access removed on schedule, the account or its data handled per instruction, and a closure record naming what was done and when.
An approved profile per role, or a defined process for requesting one, the authorized-requester list for each event type — usually HR or a manager, never the departing employee — and a written data-retention instruction for a leaver's mailbox and files.
The leaver safe-stop, defined precisely.
A vague offboarding step is how access quietly outlives the person it belonged to. A precise one is how the lane can actually be trusted with it.
- Suspension versus removal
- Suspension disables sign-in immediately and reversibly; removal deletes or reassigns the account and is not the default first step.
- Timing
- When access is cut relative to the client's notice — immediately for an involuntary departure, or on an agreed date for a planned one.
- Data-retention handoff
- Where the mailbox and files go — a manager, a hold, or deletion — decided by the client's instruction, not delivery's default.
- Confirmation record
- A closure note naming what was suspended, removed, or handed off, and when, so the request has a real end point.
Who decides in the joiner, mover, leaver lane.
| Joiner profile approval | Selling practice or client approves the role profile; delivery provisions against it. |
|---|---|
| Mover access affecting privileged or admin rights | Named owner approves, per the escalation matrix — not treated as a routine mover request. |
| Leaver access-removal timing | Client's authorized requester sets it; delivery executes on schedule, not early or late. |
| Data-retention instruction | Client decides; delivery follows the written instruction and records that it did. |
Ask these before assuming lifecycle requests are covered.
- Is the departing employee ever the one requesting their own offboarding?It should never be — confirm the authorized-requester list names someone else.
- What happens on a same-day, for-cause termination?That needs a faster path than the standard leaver timeline, agreed in advance.
- Does a mover request ever touch admin or privileged access?That should escalate like any other privileged-access change, not ride through as routine.
- Is there a default for a leaver with no data-retention instruction on file?Silence should not become deletion, or retention, by accident.
See where this connects to identity and the wider request flow.
A leaver's access removal is identity work as much as it is a lifecycle event.