Why SharePoint Shows a Former Employee Deleted Files & How to Fix
Question details
The user needs to understand and investigate why SharePoint logs indicate that a departed employee is responsible for recently deleted files.

- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Reviewing document library history or compliance logs to determine how files were deleted after an employee left the company.
- Observed behavior
- SharePoint version history or audit logs display a former employee's name as the user who deleted files, even though they should no longer have access.
Ensure you have Microsoft 365 Global Administrator or Compliance Administrator privileges to search the unified audit logs.
Review SharePoint Audit Logs and Account Lock Times
Compare the exact timestamp of the file deletion with the moment the former employee's account was disabled to rule out delayed sync or active sessions.
In many cases, an employee might delete files right before their departure, or a delay in Microsoft 365 account synchronization might leave their session active longer than expected.
Log in to the Microsoft Purview compliance portal using your admin credentials and navigate to the Audit section.
Set the date range around the time the files disappeared, select 'Deleted file or folder' as the activity, and filter by the former employee's username.
Note the exact time of the deletion event and cross-reference it with the account deactivation logs in Microsoft Entra ID (Azure AD).
If the account was recently disabled, go to the Microsoft 365 Admin Center, select the user, and click 'Revoke sessions' to ensure all access tokens are invalidated immediately.

Check for Automated Processes and Workflows
Identify if a Power Automate flow, scheduled script, or integrated application is performing deletions using the former employee's credentials.
Manage Your Documents Securely with WPS Office
If managing complex SharePoint permissions and automated workflows feels overwhelming, consider WPS Office for a lightweight and highly compatible document editing experience. It provides excellent local and cloud file management without the heavy administrative overhead.
- 1. Download the Installer: Visit the official WPS Office website to download the free version for your operating system.
- 2. Install WPS Office: Run the setup file and follow the quick on-screen instructions to install the suite.
- 3. Open Your Documents: Launch WPS Office and open your existing Microsoft Office files directly to start editing.

Frequently Asked Questions
Can an automated script delete files in SharePoint under a disabled account's name?
Yes. If an automated script, third-party app, or Power Automate flow was authenticated using the former employee's credentials, it may continue executing tasks and logging actions under their name until the authentication token fully expires or the password is changed.
How do I prevent workflows from using a departing employee's account?
Best practice dictates transferring ownership of all critical Power Automate flows, Power Apps, and API connections to a dedicated service account before disabling the employee's personal account.
What should I do if the SharePoint audit log does not provide enough evidence?
If internal investigations do not explain how or why the file was deleted under the former employee's name, you should open a support ticket with Microsoft 365 Support to request an extended backend investigation.




