Beyond Automation script pack
Stop doing offboarding by hand.
OffboardPilot automates the complete hybrid AD + M365 offboarding workflow in a single guided PowerShell script — six steps, a color-coded reconciliation report, and a full session transcript logged automatically.
The silent failure
Most offboarding scripts get the EXO groups wrong.
When you remove a user’s M365 license, Exchange Online quietly reverts their primary email address back to [email protected]. Any script that filters distribution group memberships by email address — and most do — runs after the license removal, hits the wrong address, finds nothing, and reports success.
The user is still in every cloud DL they were ever added to.
OffboardPilot captures the user’s Exchange Distinguished Name before any license changes, then uses that DN for every group query. DN is stable regardless of licensing state.
What it does
Six steps. One script. Nothing missed.
Disable AD account
Disables the on-premises Active Directory account immediately.
Block Entra ID sign-in
Sets BlockSignIn in Entra ID / Azure AD to prevent cloud authentication.
Revoke M365 sessions
Revokes all active Microsoft 365 sessions and OAuth refresh tokens.
Mailbox conversion
Converts to Shared mailbox, configures forwarding, and removes all assigned licenses.
Remove EXO groups
Removes cloud-only Exchange Online distribution group memberships using the stable DN.
Remove AD groups
Removes on-premises AD group memberships including AD-synced distribution lists.
Built for real hybrid environments
Works out of the box. No configuration required.
- ✓ No hardcoded values — drop it in any environment
- ✓ Handles users with no EXO mailbox — EXO steps skip gracefully, AD steps continue
- ✓ Mailbox size pre-check — warns before conversion if mailbox exceeds 50GB
- ✓ EXO group membership uses Distinguished Name — prevents silent misses after license removal
- ✓ AD operations use explicit admin credentials — supports least-privilege accounts
- ✓ Required modules auto-install on first run
- ✓ Full session transcript logged automatically to C:\Scripts\Logs\
Requirements
- PowerShell 5.1 (recommended) — PS7 compatible
- RSAT Active Directory module
- ExchangeOnlineManagement module
- Microsoft.Graph.Authentication module
- Domain-connected Windows workstation