Can access be revoked automatically when somebody leaves?
Partly, and the boundary is worth knowing before it is discovered. Offision holds no employment status and nothing is triggered by one; the only thing that removes anybody by itself is directory synchronisation, and it acts on accounts alone — never on the access card in somebody's wallet, and never on the long-term badge a contractor holds. What stops by itself when a leaver is removed from Microsoft 365 or your directory, why blocking an account is not the same as removing it, what a deactivated person's card still does at a panel, and the three things somebody has to withdraw by hand.
Partly. Offision holds no employment status and nothing at all is triggered by one — there is no HR field, no leaving date, and no rule watching for either. The only thing that removes anybody by itself is directory synchronisation, and what it removes is an account. Everything a person was handed — their access card, a contractor’s long-term badge — outlives it and is withdrawn separately.
What the directory does by itself
Where people sync from Microsoft 365 is on, your directory decides who exists. Someone removed from it — or moved out of a synced group — is removed from Offision on the next run, with no action on anybody’s part. That is the automatic path, and it is the only one.
| The sync removes | The sync never touches |
|---|---|
| The Offision account, and with it the ability to sign in to the console or the app | The access card stored against them. The row stays, and the number stays reserved |
| Their membership of synced user groups, and the permissions those carried | A long-term visitor badge, which belongs to a visitor record rather than to a staff account |
| Their place in lists, pickers and future invitations | A door your own access-control system releases, which Offision never held in the first place |
Turning synchronisation off deletes nobody. The people already synced stay; they simply stop updating.
Blocking an account is not removing it
The distinction costs people a security review, so it is worth stating plainly: blocking sign-in in Microsoft 365 does not remove somebody from Offision. A blocked account is still in the directory, so it still arrives in the sync and stays a live Offision user. Only deleting the account in Microsoft 365 removes them here. An on-premises Active Directory connection can instead be set up to treat a disabled account as an absent one, in which case disabling is enough — which of the two you have is part of how that connection was configured.
Where there is no sync at all, removal is a person’s job either way — see Remove someone who has left.
Their card is the part that surprises people
An access card is a number that names a person at a panel, and it does not follow the account:
- Deactivating somebody does not touch it. The card still names them at every panel, desk, clock and event screen that reads one.
- Deleting them stops the number resolving to anybody, so the card goes quiet — but it does not release the number, which stays reserved across the account until it is cleared.
- Clearing the card fields on their record is the only action that actually withdraws it. See Where a card number is read.
A contractor’s badge is a separate job
A long-term badge is issued against an email address, not against a staff account, so nothing above reaches one. When an engagement ends, disable the badges — in bulk, which is how a contract that ends is usually shaped — or set a period when you issue them and let it end by itself. See Stop a long-term badge that should no longer work.

