Technology Resources Post-Retirement
| Type: | Procedure |
| Last Updated: | January 27, 2026 |
| Sponsor: | Steve Sandberg, Steve Hafen, Larry Howell, and Brian Radford |
| Owner: | Scott Hunt, Assistant Vice President, OIT |
| Custodian: | Mary Stevens, IT Governance, OIT |
| Version: | 1.0 |
PURPOSE
These procedures establish the steps to be taken when a faculty or staff member retires to ensure a secure, compliant, and orderly transition of university technology resources. The procedures protect institutional data, uphold record retention requirements, and clarify post-retirement access to hardware, software, and services.
SCOPE
This document applies to all university employees who retire, including faculty members who receive continued access to email or continue university-sponsored research after retirement.
POLICY BASIS
These procedures implement the Appropriate Use of Information Technology Resources Policy which states that “the university retains absolute ownership rights of IT Resources.” All technology assets, accounts, and data remain the property of the university and must be handled according to university policy and applicable law.
Retiring employees remain bound by all confidentiality and compliance obligations and institutional data retention requirements.
GENERAL PROCEDURES
- Begin Preparation for Technology Transition Early
- Some technology resources may require some planning and time to decommission.
- Retiring personnel should schedule time with their CSR no later than 30 days before the last day of work so that they can ask questions and be fully prepared to separate from university accounts and systems such as:
- Box drives with shared documents—These can be particularly complex for faculty members sharing research with faculty at other universities. Time should be taken to plan well before the last day of employment.
- OneDrive folders, backups in a variety of formats—These may take some time to copy, and retiring personnel may need to purchase storage equipment to manage the files.
- Password managers—Loss of access to these types of services may have significant impact on a retiree if these items are not addressed before the last day of work. Employees will want to ensure they have access to passwords for personal accounts, subscription links, and other items that have been stored on university systems before they lose access.
- Elevated access privileges and delegated Exchange privileges should be revoked and, in some cases, CSRs should arrange for transfer of ownership or permissions to another active employee before the last day of work. (typically includes shared email boxes, access to service accounts, etc.) Most employees will not have elevated or delegated rights; CSRs can provide guidance.
- Delegated access rights to the retiree account should be revoked prior to retirement.
- Device Return & Data Backup
- All university-owned devices (computers, tablets, mobile phones, peripherals) must be returned to the CSR or Office of Information Technology (OIT) before or on the final day of employment.
- Employees should meet with the CSR prior to retirement to:
- Backup or remove personal information stored on university devices or accounts.
- Identify and transfer any institutional data, such as departmental files, to shared storage (e.g., departmental SharePoint site or shared drive).
- Account Deactivation and Retention
- University accounts (M365, LMS, VPN, etc.) are deactivated following retirement unless otherwise authorized.
- Deactivation typically occurs within 1 day of the official retirement date, unless an approved extension exists (e.g., retiring faculty continuing research status).
- Email forwarding or archiving must be configured before deactivation. (Full-time faculty members may keep a BYU email address post-retirement. Other retiring employees must complete the archiving and forwarding activities).
- Data Retention and Legal Holds
- Records subject to institutional retention schedules or legal hold must not be deleted or removed.
- CSRs will coordinate with Records Management and IT Security before removing or wiping any system associated with a legal or compliance hold.
- Security Requirements for Continued Access
- Retirees retaining access must comply with university security controls and standards, including multifactor authentication (MFA), encryption standards, and annual security awareness training.
PROCEDURES BY USE CASE
Use Case 1 – Standard retirement (no continued access)
Description: Employee retires and will not retain any hardware, software, or services. (Most common)
Procedure:
- Meet with the CSR before the final day of employment.
- Backup or remove personal data from:
- University email
- Box or OneDrive
- Local device drives or Teams folders
- Transfer any departmental or shared data to appropriate locations.
- Return all university-owned devices to the CSR.
- The CSR securely wipes devices and confirms removal of all university-licensed software.
Use Case 2 – Retiree purchasing a university device (rare) This requires vice president’s approval. See: https://finserve.byu.edu/accounting/sale-of-equipment-to-current-and-retiringemployees.
Procedure:
- Complete all steps from Use Case 1.
- The CSR wipes all institutional data and software (including M365, Exchange, and licensed applications).
- Surplus finalizes sale to the retiring employee.
Use Case 3 – Retiring faculty continuing research
Procedure:
- Before retirement, the dean notifies HR Benefits of the faculty member’s intent to continue university-sponsored research.
- The dean submits the Continued Access for Retired Faculty Engaged in Research form.
- HR receives approval from the appropriate vice president to allow continued access.
- HR adds the faculty member to the appropriate group for Retirees Conducting Research, granting access to research-appropriate tools and limited licensing.
- Deans receive an annual notification of retiree access and are required to approve continued access each year.
- Vice presidents receive an annual report indicating which former employees continue to have access to elevated systems and university-owned computer devices.
- The CSR updates the device’s assigned location in the IT Asset Inventory to reflect the new working space.
- The CSR maintains patching and updates for university-owned devices in continued use.
- When research activities conclude, the retiree follows Use Case 1 or 2.
Use Case 4 – Retiring full-time faculty who will retain a BYU email address
Procedure:
- Follow Use Case 1 for device and data transition.
- Retiring full-time faculty are automatically added to the Retired Faculty Licensing Group, providing email access. Faculty who do not wish to retain access to email can submit a request to remove their account. Deans are notified annually, but approval is not required to maintain these accounts.
- The CSR assists with:
- Running a data lifecycle review before license downgrade (auto-archive or export relevant data).
- Applying retention policies to preserve institutional records while restricting new data intake.
- MFA is required for all accounts.
- Inactive email accounts (no login activity for 12 months) will be closed and licensing discontinued.
- Running a data lifecycle review before license downgrade (auto-archive or export relevant data).
- Applying retention policies to preserve institutional records while restricting new data intake.
Use Case 5 – Retiring staff employee requiring continued access (rare)
Procedure:
- Before retirement, the dean or managing director notifies HR Benefits of the unit’s need to have the staf member continue assisting the university in some fashion. Note: This is almost always prohibited. However, if a unit feels they have a need for this type of access, they may submit a request for HR Benefits, the administration vice president, and the OIice of General Counsel (OGC) to review. Submitting the request does not guarantee approval.
- The dean submits the Continued Access for Retired StaA Member Request for Continued Access form.
- HR and OGC review the request and determine the level of risk and required guidelines for the continuing arrangement. The VP reviews the request. If approved, HR adds the staf member to an appropriate group, based on the defined unit needs for the retired staf employee access. Currently there are three available designations which can grant limited access to retirees: Volunteer (Web-based M365 tools including email licensing), Retiree doing Research (Full M365 licensing, access to library services), or Limited Use Retiree (limited email licensing). Other employee or affiliate classifications in Workday could also be used at the discretion of HR and OGC. Note: Some licensing is not available for any retired staff member.
- Vice presidents receive an annual notification of elevated retiree access and are required to approve continued access each year for anything more than the limited licensing automatically available to retired faculty. (It is anticipated that continued post-retirement access for a staf employee will be of brief duration.)
- Staff member access to systems is noted on the OIT Risk Register and reviewed annually.
- If the retiree is retaining a university-owned device, the CSR updates the device’s assigned location in the IT Asset Inventory to reflect the new working space.
- The CSR maintains patching and updates for university-owned devices in continued use. Retirees who do not allow patching and updates risk losing access to the university network.
- When activities assisting the university conclude, the retiree follows Use Case 1 or 2, returning the device.
POST-RETIREMENT CSR SERVICES
- CSRs may provide support only for retirees authorized to use university technology resources under Use Case #3, Retiring faculty continuing research, or, very rarely, under Use Case #5 Retiring staff employee requiring continued access.
- For other retirees, CSR assistance ends at retirement except for limited transition counseling (e.g., migrating data to personal devices or cloud accounts prior to retirement).
- CSRs may not install software, provide license keys, or transfer university data or services to personal devices.
COMPUTERS AS RETIREMENT GIFTS IS NOT ALLOWED
A computer should not be purchased for a retiring employee as a retirement gift. In addition, retiring employees should not be given the workstation or laptop used during their employment without going through the surplus processes and rendering appropriate payment in accordance with surplus and financial services policies.
ROLES & RESPONSIBILITIES
Employee (Retiree):
Works with their Computer Support Representative (CSR) to ensure appropriate data backup, transfer, and return of all university-owned equipment and account access.Computer Support Representative (CSR):
Coordinates technology transitions, device collection, secure data erasure, and assists in configuring access for retirees approved to retain limited university technology privileges.
Dean or Unit Leadership:
Requests post-retirement access to technology resources beyond basic email as appropriate (e.g., research continuation) and submits required forms to Human Resources.
Vice President’s Office:
Authorizes post-retirement access to technology resources beyond basic email as requested by the dean or unit leadership.
Human Resources (HR) Benefits:
Maintains official retirement status, updates eligibility for continued access, counsels with units on allowing continued access on an exception basis, and manages appropriate retiree access group.
Office of General Counsel and Risk Management:
Evaluates, advises HR and unit personnel, and catalogs risks associated with retirees retaining technology.
COMPLIANCE & ENFORCEMENT
Failure to follow these procedures may result in loss of post-retirement access privileges and/or referral to Human Resources or IT Security for remediation. All technology use by
retirees remains subject to university policy, including Acceptable Use, Data Classification, and Records Retention standards.
RELATED RESOURCES
IT Standards are developed by subject matter experts and approved by the Information Technology Committee, which consists of the CIO, the CISO, University Vice Presidents and other senior leaders.