Skip to content

Joiner, mover, and leaver deserve their own lane, not a bullet inside Microsoft 365.

The service catalog already mentions "joiner/mover/leaver tasks where approved" in passing. That is honest, but it treats three different risk profiles as one bullet point. This page gives new-hire setup, role changes, and departures their own written request family — with a safe-stop built specifically for the moment someone leaves.

What enters the joiner, mover, leaver lane.

Useful when new-hire setup, role changes, and departures are currently absorbed into general Microsoft 365 administration instead of following their own written procedure. The delivery-model walkthrough already follows one joiner request end to end.

Common request families

Joiner provisioning — account creation, group and license assignment, and device or access handoff against an approved role profile — mover requests adjusting group membership, license tier, and access when someone changes role, team, or location, and leaver processing: access suspension or removal, license reclamation, and a data-retention handoff on an agreed timeline.

Illustrative outcome

A joiner request completes with the account, license, and access matching the approved profile before the person's start date; a leaver request completes with access removed on schedule, the account or its data handled per instruction, and a closure record naming what was done and when.

Inputs needed

An approved profile per role, or a defined process for requesting one, the authorized-requester list for each event type — usually HR or a manager, never the departing employee — and a written data-retention instruction for a leaver's mailbox and files.

The leaver safe-stop, defined precisely.

A vague offboarding step is how access quietly outlives the person it belonged to. A precise one is how the lane can actually be trusted with it.

Suspension versus removal
Suspension disables sign-in immediately and reversibly; removal deletes or reassigns the account and is not the default first step.
Timing
When access is cut relative to the client's notice — immediately for an involuntary departure, or on an agreed date for a planned one.
Data-retention handoff
Where the mailbox and files go — a manager, a hold, or deletion — decided by the client's instruction, not delivery's default.
Confirmation record
A closure note naming what was suspended, removed, or handed off, and when, so the request has a real end point.

Who decides in the joiner, mover, leaver lane.

Joiner profile approvalSelling practice or client approves the role profile; delivery provisions against it.
Mover access affecting privileged or admin rightsNamed owner approves, per the escalation matrix — not treated as a routine mover request.
Leaver access-removal timingClient's authorized requester sets it; delivery executes on schedule, not early or late.
Data-retention instructionClient decides; delivery follows the written instruction and records that it did.

Ask these before assuming lifecycle requests are covered.

  1. Is the departing employee ever the one requesting their own offboarding?It should never be — confirm the authorized-requester list names someone else.
  2. What happens on a same-day, for-cause termination?That needs a faster path than the standard leaver timeline, agreed in advance.
  3. Does a mover request ever touch admin or privileged access?That should escalate like any other privileged-access change, not ride through as routine.
  4. Is there a default for a leaver with no data-retention instruction on file?Silence should not become deletion, or retention, by accident.

See where this connects to identity and the wider request flow.

A leaver's access removal is identity work as much as it is a lifecycle event.