OneDrive Admin Checklist: former employee OneDrive access shows access denied for project teams
🔍 WiseChecker

OneDrive Admin Checklist: former employee OneDrive access shows access denied for project teams

When a former employee leaves your organization, their OneDrive files often remain critical for ongoing project work. Project team members who previously had access to specific files or folders may now see an access denied message. This happens because the former employee’s user account is disabled or deleted, which breaks the sharing permissions that relied on that account. This checklist guides Microsoft 365 admins through recovering access to a former employee’s OneDrive content for project teams.

You need to understand how OneDrive handles sharing permissions when an account is deactivated. OneDrive does not automatically reassign file ownership or restore sharing links after the owner’s account is removed. The access denied message appears because the system no longer validates the former employee’s identity for permission checks. This article provides a complete step-by-step process to regain access, assign a new owner, and prevent data loss for project teams.

Key Takeaways: Recovering OneDrive Access for Project Teams

  • Microsoft 365 admin center > Users > Active Users: Check the former employee’s account status before attempting any recovery steps.
  • Microsoft 365 admin center > Users > Deleted Users: Restore a deleted user account for up to 30 days to regain access to their OneDrive.
  • OneDrive admin center > User > Access > Add user permissions: Grant a project team member direct access to the former employee’s OneDrive files.

ADVERTISEMENT

Why Project Teams See Access Denied After an Employee Leaves

OneDrive sharing permissions are tied to the account of the person who shared the file or folder. When that employee’s account is disabled or deleted, the sharing links that were created by that account stop working. The system treats the former employee as an unrecognized user and denies access to anyone relying on those links. This affects both direct sharing with specific people and sharing links sent to groups or external users.

The access denied message does not mean the files are lost. The files remain in the former employee’s OneDrive site, which is preserved for 30 days after account deletion by default. During this period, admins can restore the account, transfer ownership, or assign permissions directly. After 30 days, the OneDrive site and all its content are permanently deleted, making recovery impossible without a backup.

OneDrive Retention Policy After Account Deletion

Microsoft 365 retains a deleted user’s OneDrive for 30 days. During this time, admins can restore the user account and regain access to the OneDrive. After 30 days, the OneDrive is moved to a recycle bin for an additional 93 days, but admin intervention is required to restore it. If the account was disabled but not deleted, the OneDrive remains accessible to admins indefinitely, but sharing permissions are still broken for non-admin users.

Checklist: Steps to Restore Access for Project Teams

Follow these steps in order. Each step builds on the previous one. Do not skip steps unless the former employee’s account is still active but disabled.

  1. Check the former employee’s account status
    Go to the Microsoft 365 admin center at admin.microsoft.com. Select Users > Active Users. Search for the former employee’s name. If the account appears here, it is still active but may be disabled. If it does not appear, go to Users > Deleted Users. If the account is in the deleted list, you can restore it within 30 days of deletion.
  2. Restore the deleted user account if needed
    In the Microsoft 365 admin center, go to Users > Deleted Users. Select the former employee’s name and click Restore user. This reactivates the account and reconnects it to the OneDrive site. The restoration process takes a few minutes. After the account is restored, the user will appear in Active Users with a disabled state.
  3. Access the former employee’s OneDrive directly
    With the account restored or still active, go to the OneDrive admin center at admin.onedrive.com. Select User and search for the former employee’s name. Click on the user to open their OneDrive site. You will see a list of all files and folders stored in that OneDrive.
  4. Grant direct access to a project team member
    In the OneDrive admin center, while viewing the former employee’s OneDrive, click Access in the top toolbar. Click Add people and enter the email address of a project team lead or manager. Set the permission level to Can edit or Can view as needed. Click Add. This grants the team member direct access to all files in that OneDrive.
  5. Transfer file ownership to a current employee
    For a more permanent solution, transfer ownership of the former employee’s OneDrive files. In the OneDrive admin center, select the former employee’s OneDrive. Click Access and then Transfer files. Enter the email address of a current employee who will become the new owner. Click Start transfer. This moves all files to the new owner’s OneDrive and preserves sharing permissions where possible.
  6. Notify the project team about the new access method
    After granting access or transferring ownership, inform the project team that they can now access the files. If you transferred ownership, provide the new owner’s OneDrive link. If you granted direct access, team members can access the former employee’s OneDrive via a direct link you share from the admin center.

ADVERTISEMENT

If the Former Employee’s OneDrive Is Still Inaccessible

Sometimes the steps above do not resolve the issue immediately. Here are common failure patterns and their fixes.

OneDrive shows the former employee’s account as deleted and cannot be restored

If more than 30 days have passed since account deletion, the user account cannot be restored through the admin center. You can still access the OneDrive site for up to 93 additional days through the SharePoint admin center. Go to SharePoint admin center > Sites > Active sites. Search for the former employee’s OneDrive URL, which follows the pattern https://yourtenant-my.sharepoint.com/personal/username_domain_com. Open the site and add a current employee as a site collection administrator. This grants full access to the content.

Project team members still see access denied after being added

Access permissions may take up to 24 hours to propagate across Microsoft 365. If users still see access denied after 24 hours, check that the user was added correctly. In the OneDrive admin center, go to the former employee’s OneDrive and click Access. Verify that the team member’s email appears in the list. If it does, remove the user and add them again. If the issue persists, the user may need to sign out of all Microsoft 365 apps and sign back in to refresh their authentication token.

Shared links to specific files or folders still fail

Sharing links created by the former employee are permanently broken after account deletion. Even after restoring the account or transferring files, those old links will not work. You must create new sharing links from the new owner’s account or from the direct access granted to the team member. Instruct the project team to use the new links or access the files through the direct OneDrive URL you provided.

Restoring Access vs Transferring Ownership: Key Differences

Item Restoring Access Transferring Ownership
Description Grants a specific user direct access to the former employee’s OneDrive files Moves all files from the former employee’s OneDrive to a current employee’s OneDrive
Permissions retained Original sharing permissions are broken; new permissions must be set Original sharing permissions on individual files are preserved where possible
Time to complete Under 5 minutes Up to 30 minutes for large OneDrive sites
Best for Quick recovery when one team member needs immediate access Long-term ownership when multiple team members need ongoing access
Admin center used OneDrive admin center OneDrive admin center

Using the checklist in this article, you can restore access to a former employee’s OneDrive for project teams. Start by checking the account status in the Microsoft 365 admin center. If the account was deleted within 30 days, restore it. Then access the OneDrive through the OneDrive admin center and either grant direct access to a team member or transfer ownership to a current employee. For long-term management, consider setting up a retention policy for OneDrive sites in the Microsoft 365 compliance center to extend the default 30-day recovery window to 90 or 365 days.

ADVERTISEMENT