Guide · Active Directory & Entra ID

Your only IT person quit. What to lock down in the first 48 hours

The domain admin password, the firewall login, the registrar, the backup console, the copier portal: all of it in one head, and that head has given notice. The systems will keep running; they do not know anyone left. What has to happen quickly is narrower than it feels. This is the order we work in when a company calls us on that Friday.

Published 8 September 2026 · From the enterprise IT practice in Houston, Texas. Business hours, US Central; an engineer replies within one business day.

First, the calm part

Two things need doing in the first two days, in this order: make sure the doors cannot close on you, then close them on anyone who should no longer hold a key. Everything else, including deciding what to do about IT in general, can wait until the following week, and deciding it in a panic is how companies sign three-year contracts they regret.

If the departure is friendly, the leaver is your best source for the next 48 hours, and a short paid handover with a written list beats anything below. If it is not friendly, do the steps below first and ask questions afterwards.

Hour one: the accounts that own everything

Find out who holds each of these today, get a second person into it, change the secret, and store it in a password manager the company owns. Most of them will turn out to be in the leaver's personal password manager, browser, or head:

  • The domain admin account in Active Directory, and the Global Administrator role in Microsoft 365 or Google Workspace
  • The firewall, the switches, and the Wi-Fi controller
  • The domain registrar and the DNS host, which decide whether the website and the mail keep working, and which are often registered under a personal email address
  • The backup product's console, and the account that can delete backups from it
  • The hypervisor host, and the out-of-band management on the physical servers
  • The line-of-business application's administrator account, the accounting system, and the payroll portal
  • The ISP, the phone system, the copier fleet's portal, the security cameras, and the door controller
  • The cloud consoles: Azure, AWS, whatever hosts the website, and the email-security service in front of the mail

Add a break-glass administrator to each system you can, with the credentials sealed and stored where two people can reach them. That account is what turns the next departure from an emergency into a Tuesday.

Hour two: the leaver's own access

  1. Disable the account rather than delete it; a deleted account takes its mailbox, its files, and the answer to 'what did this run' with it
  2. Revoke every active session and reset their multi-factor registration, so a signed-in phone stops working too
  3. Take them out of every admin group, in the directory and in each cloud console, and check for a second account with a similar name
  4. Convert the mailbox to a shared one and give it to whoever inherits the vendors, so renewal notices keep arriving
  5. Collect or remotely wipe the laptop and the phone; revoke VPN certificates and any SSH or API keys issued in their name
  6. Look for things running as their account before you change its password: scheduled tasks, backup jobs, the scanner saving into a share, a service on the application server. Those are the ones that break at 2am on the first night, and the fix is a service account, not a longer delay

Day one: what would break if the lights flickered

Now the questions about what nobody has been watching. Are the backups running, where is the off-site copy, and can anyone other than the leaver restore a file from it? When did anyone last try? Which certificates and domain names renew in the next ninety days, and whose inbox do the reminders go to? Which licences are on a card in the leaver's name?

Write the answers down as you get them, however rough. This is the start of the inventory, and it is the document the next provider or hire will otherwise spend their first month reconstructing.

Day two: decide the interim, not the future

By the second day the risk is contained, and the question becomes who watches the estate next month. The honest options are a co-managed provider next to whoever is left inside, a scoped project to document everything and then decide, or a hire, which takes months and lands a person on the same undocumented estate. Whichever you pick, do not sign anything long on day two, and make the first deliverable of whoever comes next a written map of what you have.

That is what we do first, and it is the shape of the Active Directory and identity work and the help desk and lifecycle work on our Enterprise IT services page: an inventory, then a short runbook for the handful of things that break most often, then a retainer if it is wanted.

What not to do

  • Do not delete the account, the mailbox, or the OneDrive
  • Do not change the domain admin password before you know which services use it
  • Do not power-cycle the server 'to be safe'; a server that has run for four years may not come back, and you do not yet know what is on it
  • Do not let the leaver keep helping from a personal laptop with the old credentials; pay for a handover on a company device or do without
  • Do not accept 'it's all in the ticket system' as documentation until someone has opened the ticket system

Sources, so you can check the summary against the original: Manage emergency access accounts in Microsoft Entra ID (Microsoft Learn).

Where this sits on the IT page

One row of our Enterprise IT services page does this work: Active Directory & Entra ID. The page covers the eight layers together, on-site across Greater Houston and remote across Texas, and starts every engagement with an inventory of what you have.

More guides

Other tickets this page gets

Active Directory & Entra ID

Hybrid Active Directory or Entra ID only: the inventory that decides it

The decision is not a preference. It is a list of what authenticates where, and the list usually says hybrid for now and cloud-only for the next fleet.

Read the guide →
Active Directory & Entra ID

The only domain controller died. What still works, what doesn't, and the order to bring it back

Cached sign-ins keep working for a while; DNS stops at once. What runs, what stops, restore or rebuild, and the order to bring it back, then the second one so it never repeats.

Read the guide →
Printers, Scanners & Peripherals

Why a network printer keeps going offline in the office, and the four settings that fix it

Usually addressing, not hardware: a reserved address, a standard TCP/IP port, one driver from one place, and power settings that leave the network interface awake.

Read the guide →
Get in touch

Tell us what day it is.

Whether the notice was this morning or last month, describe what the person looked after and what you already have access to. You get back the next five things to do, in order, and whether any of it needs someone on-site.

Prefer to talk?

Call 832-598-8234 or email msco@stoneagesoftware.com. Houston, Texas — serving Houston, The Woodlands, Conroe, Sugar Land, Katy, Pearland, and the Greater Houston metro.

What happens next

We read your message, an engineer replies with questions or a straight answer, and if it's worth a call we book one. No drip campaign, no handoff to sales.

No obligation — we reply within one business day. This form sends your details to Stone Age Software LLC so we can respond to you. See our privacy policy for how we handle them. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.