People Ops Buyer.

IT offboarding / US buying guide

7 offboarding tools for a Microsoft-based employer

People Ops Buyer research desk · US · 500-employee Microsoft estate · Updated

For a 500-person US employer using Microsoft Entra, test Entra ID Governance before buying another offboarding tool.

Compare Torii when leavers retain accounts outside single sign-on. Add Josys when the same IT team also manages remote laptops. Verify access in each application; a completed workflow alone does not prove removal.

Compare seven access-offboarding options

Editorial order for a 500-person US Microsoft estate; these products do different jobs
Order and routeChoose it forImportant limitation
1Microsoft Entra ID GovernanceRun leaver actions from the Microsoft directory you already use.Scheduled workflows default to every three hours. The application’s own session may need separate revocation.
2Torii IdentityFind SaaS accounts outside single sign-on and assign a removal method to each.Done can mean a ticket was opened or an app was ignored. Check that the app account actually lost access.
3Josys governance platformManage SaaS access and remote laptops through the same IT team.Pricing is custom. Confirm the included app actions, device connectors and offline-device procedure.
4BetterCloud User AutomationHandle Google Workspace administration and SaaS file handover.Quote User Automation and any required file-governance or data-loss-prevention add-ons separately.
5Zluri IGACombine access reviews with repeatable offboarding playbooks.An inactive badge can follow a completed playbook. Verify accounts, licences and transferred files separately.
6Okta Lifecycle ManagementRemove app access and group membership in an existing Okta environment.Remove push-group membership in the documented order; some integrations still need manual deprovisioning.
7Rippling ITBring HR-triggered app removal and device management into a planned Rippling consolidation.Quote the base platform, IT and device components. This is broader than repairing one leaver workflow.

Use the top three as trials for this case. An existing Okta, Rippling or Google-heavy environment can change the order. We have not run a live account in any of these products.

Run the five-exit acceptance test · Scope the complete quote

For a Microsoft-based employer keeping its HRIS

This shortlist is for a US employer with 500 employees, an existing HRIS, Microsoft 365/Entra as the directory, some Google Workspace accounts, Slack Business+ and remote laptops.

HR owns the termination record; IT owns identity and devices. It is an IT access decision, not a substitute for an HR exit file, payroll, benefits or locally reviewed retention policy.

First draw a line from HRIS effective time to Entra, then to each app and device. Mark which transitions are automatic, delegated or outside the tool.

If the directory and all material apps already pass the five cases below, buy nothing new. If the gap is a single Slack connector, buying a second platform is premature. If dozens of non-SSO accounts and device returns repeatedly fall outside the directory, evaluate the next layer.

The order reflects this employer’s existing Microsoft directory and the documented limits of access removal. Check whether the leaver can still sign in to each app after the workflow finishes.

1. Entra: test Microsoft’s leaver workflows first

Microsoft’s Lifecycle Workflows deployment guide documents leaver tasks including account disablement, group and Teams removal and later licence removal.

Scheduled workflows default to every three hours, configurable from one to 24 hours. That is not a promise of immediate revocation at the exact HRIS minute. Microsoft supports on-demand runs, but the emergency owner and trigger must be designed.

Microsoft’s emergency-access guide says Entra cannot directly revoke a session token issued by an application. Blocking Entra sign-in and revoking Microsoft refresh tokens are distinct actions from ending an app’s own session.

If the critical app has a direct login or long-lived cookie, check whether the account is disabled and whether an existing session still works. Do not call SSO disablement complete offboarding.

Lifecycle Workflows require Entra ID Governance or Entra Suite; P1 and P2 alone do not include that workflow line in Microsoft’s current feature table. Ask IT which licences already exist, which identities must be licensed, and the incremental quote.

Compare Torii or Josys if your team cannot remove non-SSO access or manage device returns through its current Microsoft setup.

2. Torii: accounts outside single sign-on

Torii’s own offboarding help describes how IT sets up account removal. IT defines the system that supplies employee status and a method for each app, including separate methods for integrated and unmanaged accounts. Integrated apps can receive automatic actions; others may create tasks.

Torii can mark an app offboarded when its configured action succeeds, even if that action does not end access.

A delegated Jira task is watched for completion, while some other ticket integrations are marked offboarded when the ticket opens. An Ignore method performs no action and removes the account from Torii’s current list. Check that the employee’s account is disabled in the application itself.

For this buyer, map every high-risk app to the exact connector action or a task requiring someone to confirm access was removed. If most removals still need manual tasks, compare that workload with your current process. Assign someone to update the removal method whenever the company adds an app. For deeper product due diligence, read our Torii Identity buying assessment.

3. Josys: app access and remote devices in one purchase

Josys’s June 2026 workflow instructions offer on-demand or user-status triggers and distinct actions: app-account deletion, Jira tickets, manual owner tasks, email and HTTP requests. An optional access-review step can sit between trigger and action. Consider it if the same IT team manages SaaS accounts and remote devices.

Test an urgent departure so account removal does not wait for a routine review.

Its device page describes a ledger fed by tools such as Intune and Jamf, remote lock/wipe controls, action history and device assignments.

A listed wipe control does not prove it reaches a powered-off laptop. Nor does discovering an app establish that its connector can delete an account. Test connector capabilities and offline-device exceptions, and keep a human owner for physical recovery.

The current pricing page leads with custom pricing by the number of identities governed. It does not publish a usable 500-person offboarding-and-device quote. Ask which app actions, device controls and owner workflows the written proposal includes. If you already have working device management, compare the added cost with SaaS-only options.

4–7. Other options for access and device management

4 · BetterCloud User Automation.

Its product documentation separates User Automation, Spend Optimization and Workspace Management for Google, with file governance and DLP described as additional scope.

Compare BetterCloud when Google administration and file handover are the main work. Quote the exact product, apps and add-ons. If you only need Entra leaver actions, test Microsoft’s workflow first.

5 · Zluri IGA.

Its playbook instructions list Remove User, Revoke License, forwarding and data-transfer actions. The same instructions say an inactive status in Zluri can follow the configured playbook run.

Compare Zluri when you also need access reviews; check whether your existing governance platform already covers them. Verify the resulting account, licence and file owner separately.

6 · Okta Lifecycle Management.

Keep it near the top if Okta is already the IdP. Okta’s Group Push guide explicitly warns that removing app assignment before the separate push-group membership can leave a downstream group member behind. Its provisioning guide also distinguishes deactivation from deletion and says some app integrations require manual deprovisioning.

Do not migrate a working Entra directory just to fix one leaver workflow.

7 · Rippling IT.

Its IT product page describes HR-triggered app suspension, Google file/Calendar handover, device lock or wipe and device retrieval. Compare Rippling if you already plan to bring HR and IT onto it.

For an Entra-centred buyer keeping its HRIS, quote every required platform, IT and device component. An entire platform replacement is a poor first answer to a missing connector.

Five fictional exits that make completion measurable

Use only test identities and invented content in a vendor trial. Give every finalist the same five records, the same HRIS/IdP/app/device map and the exact proposed edition. Record the trigger timestamp, workflow action, receiving-system state, session result and exception owner. A failed step may be resolved manually, but it cannot be scored as automatic.

Five offboarding tests; use fictional identities and content only
RecordTest steps and expected resultDo not mark complete if…
L01 · immediate departureHR changes the effective end from Friday to now. Block directory sign-in through the agreed emergency route, check the issued app session and verify the SaaS account itself.The process waits for the next scheduled run, or a workflow badge is the only evidence.
L02 · planned Friday exitThe HRIS end time, Entra leave attribute, timezone and workflow run time agree. A named owner checks Slack at the agreed cutoff.A calendar date is treated as proof of an exact-hour cutoff.
L03 · unmanaged SaaS accountThe app discovered through a browser or expense signal has a named revocation method: connector action or accountable task with receiving-app evidence.An Ignore setting or an opened ticket is reported as access removed.
L04 · remote laptopThe device has an owner and serial. Record whether the lock or wipe is queued, accepted or confirmed complete on the device; track physical return separately.Shipment of a return box is mistaken for a device lock, or device status is unverified.
L05 · preserve business recordsAccess ends, while a designated owner can retrieve required work records under the buyer’s retention policy. Test archive, transfer and license state separately.Records are deleted without the record owner’s approval, or a retained account still permits sign-in.

Two documented details make L03 and L05 essential: Slack SCIM is edition-dependent and requires a connector; some member-installed integrations or bots may remain active after deactivation.

Google archives former-employee accounts to retain their data while preventing Workspace sign-in; archived storage still counts toward pooled capacity. Decide the retention and transfer policy with the record owner.

What to include in the quote

Ask for a quote covering your 500 employees and any contractor identities. Break it into:

  • Identity-governance licences and the identities they cover.
  • App connectors, permitted actions and workflow executions.
  • Device management and retained or archived accounts.
  • Implementation, support and ongoing administration.

Price recurring manual removals and escalation separately. Compare what each finalist adds to your current setup. Keep estimates of staff time separate from cash savings.

Who signs the exit as complete?

Use one completion record for HR, the directory owner, each SaaS app owner and the device owner:

  • HR: authorise the employee’s end date and time.
  • IT: record the directory action and each application’s result.
  • Manager: confirm content transfer and device handover under the agreed policy.

Each owner must confirm their account, file or device action happened before the exit is marked complete.

For urgent departures, write a separate emergency route. Microsoft’s documented access revocation steps include blocking the user, revoking refresh tokens and considering devices; the app’s own cookie can require app-side action.

For a scheduled departure, monitor the run window and exceptions. If a supplier cannot show the five records with your actual licences and integrations, keep the claim in the unresolved column.

Questions buyers ask

What is the best offboarding software for a 500-person Microsoft company?

Start with Entra ID Governance if you already use Microsoft Entra. Compare Torii for accounts outside single sign-on and Josys when your IT team also manages remote laptops. Test whether each required application actually removes access.

Does disabling an Entra account end every SaaS session?

No. Microsoft says each application controls its own session token; Entra cannot directly revoke it. Check the app account and existing session separately, and use the agreed emergency procedure for urgent exits.

Why can an offboarding workflow show Done while access remains?

A workflow may count a delegated task, an opened ticket or an ignored app as complete under its configuration. Torii documents these cases. Compare the workflow log with the downstream account and session state.

What should an offboarding software quote include?

Scope the identity product and licences, connected applications and their actual actions, device capabilities, implementation, support, retained-account treatment and manual tasks. Ask for the 500-person population and contractor identities in writing.

Sources and research scope

Primary product/help material inspected 2 October 2026; Microsoft, Torii, Josys, BetterCloud, Zluri, Okta, Rippling, Slack and Google. The 500-person estate and five identities are fictional decision inputs. Product capabilities are documented claims, not supplier accounts tested by this publication. This page covers IT access and device offboarding, not payroll, benefits or legal advice.

  1. Microsoft Lifecycle Workflows deploymentLeaver tasks, three-hour default schedule, configurable interval and on-demand limits.
  2. Microsoft governance licensingLifecycle Workflows product prerequisites; P1/P2 distinction.
  3. Microsoft emergency access revocationIndependent app-issued session cookies and directory/refresh-token/device actions.
  4. Torii offboarding helpAutomatic, delegated and Ignore methods; exact Done-state semantics.
  5. Josys automated offboarding helpStatus and on-demand triggers, review step, action choices and run history.
  6. Josys current pricingCustom governed-identity quote; no published 500-person offboarding-and-device total.
  7. Josys device managementConnector-fed device inventory, remote action status and assignment claims.
  8. BetterCloud product documentationSeparate User Automation, Spend Optimization and Google Workspace components/add-ons.
  9. Zluri offboarding playbooksConfigured action types and inactive-status behaviour.
  10. Okta Group Push orderSeparate assignment and push groups; downstream membership can remain after wrong order.
  11. Okta provisioningDeactivation is not deletion; app capability can require manual deprovisioning.
  12. Rippling IT device and identity productDeclared app, device and Google handover functions, not observed outcomes.
  13. Slack SCIM provisioningConnector and supported-plan context for deactivation.
  14. Slack deactivated-member integrationsSome bots or integrations can persist after member deactivation.
  15. Google former-user archiveArchived Workspace account blocks access while retaining data; pooled storage remains.