Home»Google Workspace Security»How to Securely Plan a Google Workspace Employee Leaving

How to Securely Plan a Google Workspace Employee Leaving

Let’s talk about the risks of an employee exit from corporate Google Workspace. 89% of former employees still had access to important company apps, such as Google Workspace, even after leaving the company. What is even more disturbing, 49% of them admitted to logging into a corporate account after their employment contract ended.

The consequences of such data security violations can be (and usually are) disastrous: data leaks, breaches, and deletions. Sometimes, companies don’t realize this for a long time. This can lead to losing money or even facing lawsuits and a damaged reputation.

As a Google Workspace admin, you need to be aware of employee leave threats to prevent them. You are responsible for transferring the data of a departing employee. This is to ensure that the new worker has the necessary information. It will help them start working efficiently and without wasting company time.

This article will guide you step-by-step to secure employee exit and provide you with some prompts on this way!

Google Workspace Backup and User Security Solution

Learn More

Step 1. Disable access to Google Workspace user account

If an employee leaves abruptly, the first thing to do is to disable their access to their Google Workspace account. Users then are prevented from sharing files or sending emails from a company Google Workspace (G Suite) domain. However, the data is retained for archiving purposes or can be transferred to another account at a later time.

To suspend a user in Google apps, use the Google Workspace admin secure workspace login. However, it’s best to log in as the user themselves to have complete access to their data in all Apps. It is particularly important if the employee has access to company apps. These could be Google Analytics, Adwords, or social media accounts such as Facebook and Twitter.

When you are logged in, here are the steps you should take:

  • Log in as admin or use employee’s credentials.
  • Change the password and reset cookies to ensure they can no longer access the account. And don’t forget to reset login cookies so the logged-in user can’t enter the account automatically. For that, go to the Security section, and press Reset sign-in cookies.

Employee Exit with Google Workspace

  • Remove all passwords for specific applications and block access to the user’s Google Account for authorized services (if provided).

Go to the settings, scroll down, press Show More and go to the Security section. Here you can do all of that, so just go in order. First, press Turn off 2-step verification.

Then come down to Applications specific passwords, where you’ll see the list of applications you can reset passwords for. Just press Reset near each one of them. Just below, you’ll see Authorized access. Press Revoke.

  • Delete access to the account and company applications from all connected devices including mobile phones. To do this, scroll to the bottom of the page and find the Mobile management section. There, you’ll see all the devices linked to this account. Click Wipe this device or Wipe this account.
  • Remove any recovery phone or email addresses associated with the account. Choose your personal information on the home screen, then delete any personal email addresses and phone numbers linked to the account.

Step 2. Backup employee’s data

There are two ways to backup important company’s data:

Your company data can’t be secure if you just save them occasionally. To keep your files safe, you should regularly and automatically back up all company data on reliable cloud storage. Moreover, you need to take care of this data to be easily restorable and protected from cybercriminals.

Spinbackup doesn’t only backup your critical Google Workspace (G Suite) data. It also protects your account from data leaks.

  • Manually with Google Takeout

Manual backup is not the best choice for companies because of a quite large amount of data to deal with. But in case you need to make just a one-time copy of your Google account data, use Google Takeout.

Related Link: How to Back up Google Drive: A Step-by-Step Guide

  1. Log in to the former employee’s Google account and click on Download your data. There you will see all apps that contain your data. All options are selected by default. To choose specific files, deselect all and then tick the desired field.

  1. To download some parts of your data just leave all the data selected and uncheck the box near the files you don’t want to save. Then press Next step.
  2. Customize your archive by choosing the delivery method, type of export, type, and size of the file.

It can take some time, depending on the number of files.

Step 3. Transfer Google Workspace Data to Another Account

There are two ways to transfer data between Google Workspace accounts:

  1. Simple, if you are using Spinbackup.

First, it’s easier because you don’t need to save data additionally before or after you transfer them – they are automatically backed up. Second, it just takes fewer steps.

By default, only the route Google Workspace (G Suite) administrator can migrate data between accounts. However, you can nominate an additional administrator and give him/her permission to migrate data. You can revoke this permission in the future if needed.

2.Tricky, if you are using Google Workspace (G Suite) migration service.

To move all data with Google Workspace, follow these steps for migrating Google Workspace data to another Google account.

After you successfully backed up and transferred all the important data, you can delete the original user account without fear of losing vital information.

Step 4. Forward Emails

When an employee departs, it is crucial to configure Google Workspace (G Suite) to forward their emails. This ensures that any significant unfinished messages can be addressed promptly.

Most likely, the leaving employee had some important unfinished correspondences, or their email is the only way for some customers/companies to reach your company. In this case, you may need to forward suspended emails. All you have to do is:

  • Create the same email address (if you have already terminated an employee’s Gmail) and put someone responsible to go through it.
  • Set an auto-responder to inform the sender that the employee is no longer working at the company and offer a new point of contact.

P.S.: if you need to configure Google Workspace (G Suite) for email archiving, you may use Google Vault or back up your Gmail with Spinbackup.


Step 5. Collect Company Devices and Wipe Clean

Of course, before leaving the employee must return any laptops or mobile devices that they used for work. In most cases, these devices are recycled for new employees. To prevent inadvertently giving a new employee access to sensitive information, don’t forget to back up, transfer, and wipe clean all data on the devices.

Step 6. Add an account as an alias

If the former employee used their email as a login to some sites or services you may need in the future, this is the right move to make.

To add their email as a nickname, you need to:

  • Log in to your Google Workspace admin panel.
  • Press Users and choose a user.
  • Press Accounts, and then press Add a nickname under Alias.
  • Insert the email of the former employee.

Step 7. Review Risky Third-Party Apps Installed by the User

Another important measure to take is to control risky third-party apps that the employee has granted access to from their corporate Google account. Why? Because these apps could have been used to copy company files and may retain access to corporate data.

There is currently no easy way to monitor third-party apps in Google Workspace. But Spinbackup Cybersecurity suite allows you, the administrator, to see all apps installed by the users, all the permissions that have been granted, and the risk rate of these apps.

Revoke access of risky apps to your Google Workspace

Start now!

From the Spinbackup admin console, you can easily block risky apps as a security measure after the employee leaves the company. Also, you can flag and block activity such as unauthorized downloading of files. This feature can provide enhanced surveillance of user actions if an employee has given the notice to leave but still has to work at the company.

Step 8. Conduct an Exit Interview

Conducting an exit interview is a common part of HR procedure when an employee leaves a company, but data security is not always included in this conversation.

A thorough exit interview should include questioning the employee on their data practices while they were at work, such as if they downloaded corporate files to personal cloud storage. The previously mentioned survey found that 68% of ex-employees had downloaded work files to their personal cloud storage.

It’s also essential to remind the ex-employee that company information is confidential and should not be shared with anyone outside the organization.

The exit interview is also the last chance to ask the user for their login credentials for cloud apps. This is necessary to gain access to data stored within the apps – even a Google Workspace super admin does not have full access to all data and apps within another user account.

Finally, it’s important to ensure that employee contact information is up to date. This ensures that he or she can be contacted in the event that access is needed to any forgotten corporate accounts in the future.

Your next steps as an administrator after reading this article:

1. If you don’t have a rule that HR notifies you every time an employee is about to leave, set up this rule. From now on, when someone is about to leave their job, you should be notified immediately. No one should underestimate this moment since all company data security depends on it.

2. Ask your HR or responsible manager about how much time the employee needs to finish the tasks that require access to their Google Workspace account. Before you cut access to Google Workspace for the employee, you better use Spinbackup tools to track all data movements within the company to prevent any leaks of sensitive or important company data.

3. If an exit interview is still not mandatory in your company, you should speak with your Human Resources Department about setting up this rule.