Apple Device Offboarding: A Security Checklist for Departing Employees
Onboarding gets all the attention in device management — offboarding is where the real security risk hides. Here's a practical checklist for what to do when an employee with a company Apple device leaves.
Most companies have a reasonably solid process for setting a new employee up with their Apple devices. Far fewer have an equally solid process for what happens when that employee leaves — and that gap is where a surprising amount of real security risk sits.
A departing employee's MacBook or iPhone often still has active access to email, internal tools, VPN, and cloud storage right up until someone remembers to do something about it. If that "someone remembers" step depends on a person rather than a process, it eventually gets missed.
Why Offboarding Is a Security Moment, Not Just an HR Task
Onboarding is proactive: you're building something and it's obvious when it's incomplete — the new hire can't log in, and they'll tell you. Offboarding is the opposite. Nothing visibly breaks if you forget a step. The device still works, accounts stay active, and nobody notices until something goes wrong — a former employee accessing a shared drive weeks later, or a device that was never wiped turning up second-hand with company data still on it.
That asymmetry is exactly why offboarding needs a checklist rather than institutional memory.
The Offboarding Checklist
For a company-owned Apple device, a complete offboarding process covers:
- Revoke MDM and Jamf console access — if the departing employee had any administrative access to your management tools, remove it immediately, not at the end of the process
- Remote lock the device — as soon as offboarding is confirmed, lock it before working through the rest of the list
- Reclaim VPP app licences — unenroll or reassign so paid app licences return to your pool instead of sitting unused (see our guide to VPP app deployment for how licence reclaiming works)
- Disable identity access — Managed Apple ID, email, SSO, and any connected accounts (Slack, Google Workspace, Microsoft 365) should be disabled the same day, not the same week
- Rotate shared credentials — if the device had access to any shared logins (rare, but it happens with legacy systems), rotate them
- Retrieve the physical device — for corporate-owned hardware, get it back; a wiped device with a stranger's family photos still on it isn't the same problem as an unreturned one
- Remote wipe once retrieval isn't happening soon — if the device won't be physically returned quickly (remote employee, international departure), don't wait — wipe it remotely and follow up on physical return separately
- Update your asset inventory — mark the device as unassigned or retired so it doesn't quietly disappear from your records
BYOD Adds a Layer of Complexity
If the device was personally owned under a BYOD policy, the checklist changes. You can't wipe the whole device — that would delete the employee's personal photos, messages, and accounts along with company data. This is exactly the scenario Apple's User Enrollment model was built for: it separates a "managed" partition from personal data, so offboarding removes only the company side — corporate apps, email profile, and managed data — and leaves everything personal untouched.
We go into the tradeoffs between corporate-owned and BYOD devices in more depth in our BYOD comparison guide — but if you're not sure whether a leaving employee's device supports this kind of clean separation, that's worth checking before the exit interview, not during it.
Automating Offboarding with Jamf
The most reliable version of this process doesn't rely on someone remembering to run through a checklist manually. With Jamf, offboarding can be built into a Smart Group: when a device's assigned user is flagged as inactive (synced from your HR or directory system), Jamf can automatically restrict access, trigger a remote lock, and flag the device for review — all without a manual trigger.
This doesn't remove every step — retrieving physical hardware is still a human task — but it closes the gap where offboarding depends entirely on someone remembering to act.
What Happens If You Skip This
The risk isn't hypothetical. A former employee's still-active VPN access, a departed contractor's lingering Slack login, or a "wiped" device that was actually just factory-reset by the user themselves (leaving company MDM enrollment intact, or worse, not) are all common, avoidable incidents that trace back to the same root cause: offboarding treated as optional rather than procedural.
If your offboarding process currently depends on someone remembering to do it, talk to us. We help companies build offboarding into their Jamf setup properly, so it happens the same way every time.
Need help with Apple device management?
We specialise in Jamf-based MDM for businesses across Europe and the Gulf. Get in touch for a free consultation.
