// LEAVER ACCOUNT RECOVERY

An employee left and you don’t know their computer password

An employee has left, their computer’s locked, and the password walked out of the door with them. Here’s what you can actually recover — the login, the mailbox and the files — when the data is genuinely at risk, and how a proper offboarding is done so it never bites you twice. Rated 4.9 on Google.

  • ● No fix, no fee
  • ● 4.9-star rated
  • ● Remote-first, UK-wide

/01 — THE SHORT ANSWER

Can you get back into a leaver’s locked computer?

Whether you can get back in comes down almost entirely to what type of account the employee used. A local Windows account can usually be reset in seconds from a second administrator account on the same PC; a work or Microsoft 365 account is reset centrally by whoever runs your business’s 365 sign-ins — not on the machine itself. In most cases where the business set the computers up properly, you don’t need the leaver’s cooperation at all.

The part that catches firms out is encryption. If the drive is protected with BitLocker and nobody has the recovery key or a working login, the data can be genuinely unreachable — resetting the password won’t help, and wiping the machine loses everything on it. So before anyone starts guessing passwords or factory-resetting, work out which of these you’re in:

  • Local account, a second admin exists — straightforward reset, every file intact.
  • Microsoft 365 / work account — your admin resets it centrally and the PC follows next time it’s online.
  • No admin access and the drive is encrypted — stop, and find the BitLocker recovery key before doing anything drastic.

We deal with this most weeks for Dorset businesses. Call us on 01202 775566 before you reset anything you can’t undo.

// NEED THIS FIXED RIGHT NOW?

Skip the DIY — call 01202 775566 and we can be looking at your screen within minutes. You watch everything we do, and most problems on this page are fixed in one short remote session. (Mon–Fri, 9am–5pm.)

Start SOS Remote Support Call 01202 775566

/02 — KNOW YOUR ACCOUNT TYPE

Local account, Microsoft account or Microsoft 365?

Windows sign-ins come in three flavours, and telling them apart decides everything that follows.

  • A local account shows only a username on the sign-in screen — no email. If any other account on that PC has administrator rights, that account can reset the leaver’s password from Control Panel > User Accounts, the Computer Management console, or an elevated prompt using the net user command. The leaver’s files stay exactly where they are.
  • A personal Microsoft account shows a masked email (for example, name@outlook.com). These are reset online from any phone or PC at the Microsoft account website, so you don’t even need the locked machine — but you do need the recovery email or phone on that account, which a leaver often still controls.
  • A work or Microsoft 365 account (Microsoft Entra ID, once called Azure AD) also looks like an email, but the password lives in your business’s 365 tenant, not on the PC. Whoever holds your Global Admin login resets it centrally, and the computer accepts the new password the next time it connects.

That last case is the good news for most small firms: if staff computers run through Microsoft 365, you almost never need the ex-employee’s help. If you can’t reach the admin side either, our guide on being locked out of your Microsoft 365 admin account covers your options.

/03 — THE BITLOCKER CATCH

When the data is genuinely at risk

Before you factory-reset or wipe a leaver’s PC, check whether the drive is encrypted — because this is where business data gets lost for good. Many modern Windows 11 machines switch BitLocker on automatically, often without anyone realising.

Here’s the hard truth: resetting the password does not bypass BitLocker. If Windows shows a blue screen asking for a 48-digit recovery key on start-up, you must supply that key. Without it — and without a working login — the encrypted data cannot be decrypted by us, by Microsoft, or by any recovery tool. Re-installing Windows to reclaim the machine wipes everything on the drive.

The recovery key is usually stored in one of a few places: the leaver’s personal Microsoft account, your Microsoft 365 / Entra admin area (under Devices) for company-managed machines, printed on paper, saved to a USB stick, or held in your on-premise directory. Track that down first.

If the data matters and the key has left with the employee, don’t keep guessing at the login — talk to us, or read our honest take on what data recovery can and can’t do so you know where you stand before spending money.

/04 — THE FULL OFFBOARDING

Don’t stop at the password — the leaver checklist

Getting into the PC is only half the job. A proper leaver process protects the business’s email, files and shared logins. Here’s the checklist we work through:

  • Block the sign-in and reset the 365 password so the leaver can’t reach email or files while you sort everything out.
  • Keep the mailbox. In Microsoft 365 you can convert the leaver’s mailbox to a shared mailbox — all their email and calendar stays, colleagues can open it, and once it’s under 50 GB you can remove the paid licence and reuse it. Or set up email forwarding so nothing sent to them is missed.
  • Rescue their files from OneDrive and any Teams or SharePoint areas before the account is touched.
  • Wipe and block their mobile so company mail is removed from a phone you don’t control.
  • Rotate every shared password the leaver knew — the Wi-Fi, the banking, the website, any shared logins. This is the step most businesses forget.
  • Tighten folder access so the next person only sees what they should.

Don’t delete the account too soon — a shared mailbox or forwarding rule needs it to stay in place as an anchor. Our fuller guides on what to do when an employee leaves and restricting staff access to shared folders walk through the rest.

/05 — THE HONEST RULE

One plain line about whose machine it is

Let’s be straight about this, because it matters. A business owns its equipment and its accounts, so it’s entitled to get back into them — but we only work on machines the business genuinely owns.

In practice that means we’ll happily reset a company PC or a company Microsoft 365 account for the person who runs the business or its IT. What we won’t do is help anyone break into a device or account they don’t own or aren’t authorised for — a personal laptop the employee bought themselves, or a previous employer’s system. If the awkward case is a company laptop the leaver has kept, that’s a conversation to have with them, not a lock for us to pick.

And we’ll say it plainly: we’re an IT firm, not solicitors. If anything about the leaver’s contract, data or ownership is disputed, take proper legal advice — we’ll stick to the technical side and get you back into the kit that’s rightfully yours.

/06 — HOW WE FIX IT

How we sort it — and when to call us

Most of this we can do remotely, usually the same day, once we’ve confirmed the machine and accounts belong to your business. Here’s roughly how a job runs:

  • We check the account type and whether the drive is encrypted before anyone touches a reset — that one check prevents most data loss.
  • We reset or recover the login the safe way. If the PC is domain-joined or centrally managed, we do it through your directory rather than fighting local policy.
  • We run the offboarding checklist — mailbox, files, mobile, shared passwords — so nothing’s left open.
  • We hand you documented, tidy access so the next person can pick up where the leaver left off.

We’re a family-run firm in Kinson, Bournemouth, trading since 1995, and we help businesses across the UK remotely with collection or on-site visits across Bournemouth, Poole, Christchurch and Dorset. It’s no fix, no fee — if we can’t get you back in, you don’t pay for the attempt. Ongoing, our small-business IT support means a leaver is handled properly before it ever becomes a panic.

/07 — NEVER AGAIN

Stop this catching you out next time

A locked-out leaver is almost always a sign that access was never set up to survive someone walking away. A few simple habits fix that for good:

  • Run staff computers through Microsoft 365 so you, not the employee, control every sign-in and can reset it centrally in seconds.
  • Keep a separate administrator account on every PC that only the business holds — never rely on the staff member’s own login being the only admin.
  • Store BitLocker recovery keys in your 365 tenant so an encrypted drive is never a dead end.
  • Use a password manager for shared logins, so the Wi-Fi and banking passwords aren’t living only in one person’s head.
  • Write down a one-page leaver checklist and follow it every time.

We can set all of this up for you and lock down your Microsoft 365 account security at the same time. Ten minutes of setup now saves a very stressful afternoon later — give us a call on 01202 775566 and we’ll get it sorted.

FAMILY-RUN SINCE 1995 · ★ 4.9 ON GOOGLE · 200+ COMPUTERS UNDER OUR CARE · NO FIX, NO FEE · SAME-DAY REMOTE SUPPORT

// GOOD QUESTIONS

Frequently asked

How do I tell if it’s a local, Microsoft or work account?

Look at the sign-in screen. If it shows only a name with no email, it’s a local account. If it shows a masked email (like name@outlook.com), it’s a personal Microsoft account you can reset online. If it’s an email tied to your company domain, it’s a work or Microsoft 365 account reset from your 365 admin centre. Not sure? Send us a photo and we’ll tell you which it is.

Can you reset the password without losing the files?

Almost always, yes — a password reset and the data are two separate things. Resetting a local account from another admin, or a 365 account from your tenant, leaves every file untouched. The only real exception is an encrypted drive (BitLocker) where nobody has the recovery key — there, regaining the machine can mean losing the data, which is exactly why we check for encryption before we touch anything.

The screen is asking for a BitLocker recovery key — what now?

Stop and find the key before you do anything else. It’s a 48-digit number, usually stored in the leaver’s Microsoft account, your Microsoft 365 admin area, on a USB stick, on paper, or in your directory. Without it, the encrypted data cannot be recovered by anyone — not us, not Microsoft. Don’t re-install Windows hoping it clears; that wipes the drive. Call us and we’ll help you hunt the key down first.

Can you just do all of this for us?

Yes — that’s exactly what most businesses ask for. Tell us what happened and confirm the kit is the company’s, and we’ll handle the whole thing remotely where we can: the login reset, the mailbox handover, the files, the mobile and the shared-password rotation. It’s no fix, no fee, so if we can’t get you back in, you don’t pay for the attempt. Call 01202 775566.

Do we need the ex-employee’s help or permission?

Usually not, if the computer runs through Microsoft 365 or has a second admin account — you control those resets yourself. You only tend to need the leaver’s cooperation when everything hinged on a personal Microsoft account they still control, or when they hold the only BitLocker key. That’s precisely the trap we help you avoid in future by centralising access.

How do we get into their email after they’ve gone?

In Microsoft 365 you don’t need their password at all. You can convert their mailbox to a shared mailbox — all the email and calendar stays and colleagues can open it — or set up forwarding so new messages reach the right person. Keep the account in place while you do, as it anchors the shared mailbox. We can set either up in a few minutes.

We don’t know the Microsoft 365 admin login either — can you still help?

Often, yes, but it’s a bigger job. Recovering control of a tenant depends on what recovery details and verification you have. Start with our guide on being locked out of your Microsoft 365 admin account, then call us — we’ll walk through the ownership checks with you and take it from there. The sooner you act, the more options you have.

What does it cost, and what if you can’t get in?

We work on a no fix, no fee basis — if we can’t recover access, you don’t pay for the attempt. A straightforward reset is a quick, low-cost job; a full leaver offboarding or a tricky encrypted-drive case takes longer, and we’ll always tell you honestly upfront what’s realistic before you commit to anything. No surprises.

How do we stop this happening next time?

Run staff PCs through Microsoft 365 so you control every reset, keep a business-only admin account on each machine, store BitLocker keys in your tenant, and put shared logins in a password manager rather than in one person’s head. A one-page leaver checklist ties it together. We can set all of this up as part of ongoing support so the next departure is a five-minute task.

An employee’s left and nobody can get in?

Tell us the account type and we’ll tell you straight what’s recoverable — then sort the reset, the mailbox and the handover for you. Remote-first across the UK, usually same-day, and no fix, no fee.

01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM