Onboarding is a sequence, not a favour: create the account, assign a licence via group, enforce MFA (Multi-Factor Authentication) enrolment, add to the right security groups, configure and enrol the device, install applications, grant file and application access, hand over with a short orientation, and record the device and accounts in the asset register.
Movers are the forgotten case. Someone changes role, gains new access and keeps the old. Over three years this is how a receptionist ends up with finance permissions. Quarterly access reviews — literally reading the group memberships with a manager — fix it cheaply.
Offboarding must be provable: disable the account (do not delete it immediately), revoke all sessions and refresh tokens, reset the password, remove MFA methods, convert the mailbox to shared or delegate access to the manager, reclaim licences after the retention window, remove application access, retrieve and wipe devices, transfer OneDrive content, and document the date and who authorised it.
Both processes deserve a checklist with a timestamp per step. When an owner asks 'are we sure the person who left in March cannot get to our files?', a completed checklist is the difference between confidence and a guess.