Returning seasonal or rehired employees often still have an archived mailbox. Restoring access without checks can expose historical mail, wrong group memberships, or stale forwarding. This guide gives a secure reactivation workflow: verify identity and employment, review ownership, restore access carefully, and reset security controls.
Prefer restore over a new mailbox when the same person returns and the archived account still exists.
The worker returns next peak and you archived—not deleted—the mailbox after last season. Same address and history support continuity.
HR confirms it is the same individual rejoining. The archived account maps to their prior employment record—not a new hire with a similar name.
Operations or customers expect mail at the same address. Reactivation preserves the mailbox identity without re-provisioning from scratch.
For the full seasonal lifecycle—archive, seat cost, and rehire timing—see Seasonal employee email lifecycle and How to manage seasonal employee email accounts.
An archived mailbox can still carry last season’s configuration. Treat restore as a security event—not a one-click undo.
Site, shift, or role groups from the prior assignment may still include the account. The returning worker could receive mail meant for last year’s roster.
External forwards or delegate access set before archive may still be active. Mail can leave the organization without the employee logging in.
Restoring login gives access to prior threads—some may be sensitive or no longer relevant to the new role. Decide what the employee should see before unlock.
Common names, reused addresses, or manager shortcuts can link the wrong archived mailbox to a new hire. Identity verification prevents ownership mistakes.
HR or ops confirms the person and start date before IT touches the mailbox.
Match person to mailbox
Compare employee ID, legal name, and prior mailbox address. Do not restore from a manager’s memory of “the old account.”
Confirm active employment
Verify rehire or seasonal return is approved in HR systems with a current start date—not a verbal request alone.
Document approval
Record who approved reactivation and the target site or role. IT uses this ticket before changing account state.
Clean configuration before login—not after the employee discovers last season’s mail.
Confirm the SMTP address still matches policy. Remove obsolete aliases tied to old roles or sites.
Remove from prior site, shift, and admin groups. Add only groups required for the new assignment.
Clear external forwards, auto-replies, and delegate permissions from the prior employment period.
Revoke mailbox permissions others held on this account, and remove this account’s access to mailboxes it should no longer see.
Retention and legal-hold context: Employee offboarding email retention policy.
Move archived → active only after review. Vendor recovery paths differ—cite primary docs, do not assume one-click behavior.
Restore should re-enable the mailbox for the verified employee—not replay every permission from offboarding day. In Microsoft 365, recovering an inactive mailbox converts it to a new active mailbox via Exchange Online PowerShell; restoring merges contents into an existing mailbox while keeping the inactive copy. In Google Workspace, preserving former-employee data follows admin archive and transfer workflows before reassigning access.
Primary source references
If the account is still archived in your stack, follow Archive employee email without deleting data for the archive side of the lifecycle—this page covers restore only.
Treat reactivation like a new hire for authentication—never reuse prior passwords or MFA enrollment.
Issue new credentials at restore. Require change on first login. Do not reactivate with a password the employee may have shared before archive.
Clear stale MFA devices from the prior period. Enroll against current policy before the employee sends or receives operational mail.
Confirm the account sits under today’s send/receive restrictions and walled-garden rules—not last year’s exception list.
Close the loop so billing, roster, and site leads reflect the restored seat.
Confirm the mailbox is active, which groups were added, and when the employee can expect day-one operational mail.
Move the seat from archived to active in your admin console. Align HR roster and license records with the restore date.
Keep ticket notes: approver, identity checks, groups changed, and credential reset timestamp for audit.
Send a test message to a site or shift group the employee joined. Verify receipt before peak operational traffic depends on the account.
Secure employee email reactivation checklist — run in order before granting login.
Secure employee email reactivation checklist
Vendor recovery behavior: Microsoft Learn & Google Workspace docs · Verified: 2026-07-22 · HR/legal retention: link to offboarding policy, not duplicated here
| Step | Task | Owner |
|---|---|---|
| Identity | Match employee ID and legal name to archived mailbox address | HR |
| Employment | Confirm rehire or seasonal return with current start date in HR system | HR / ops |
| Ownership | Review aliases, groups, forwarding, delegates; remove stale config | IT |
| Access | Restore archived → active; add only groups required for new role or site | IT |
| Credentials | Force password reset and re-enroll MFA per current policy | IT |
| Notification | Notify manager; update roster, billing, and change ticket | IT + manager |
Reactivation is not always safer than a clean mailbox. Choose new provisioning when identity or history boundaries matter.
Mailbox was deleted
Permanent removal means restore is unavailable. Create a new account and follow retention policy for any exported history.
Different person, same role title
A new hire must not inherit another worker’s mail, groups, or address without explicit policy approval.
Policy requires clean identity
Some organizations mandate new accounts after long gaps or role changes to limit historical data exposure.
Legal or hold constraints
If retention or hold status blocks restore, follow Employee offboarding email retention policy before changing account state.
For seasonal teams deciding archive vs new each year, see Seasonal employee email lifecycle.
Reactivation decisions
Reactivate when the same person returns, the archived mailbox still exists, and you need continuity of address and history. Create a new account when the mailbox was deleted, a different person takes the role, or policy requires a clean identity boundary.
Security & access
Not safely. Vendor recovery may bring back prior configuration. Review groups, aliases, and forwarding before granting login—remove stale memberships and external forwards as part of the ownership review step.
Operations
HR or ops should confirm identity and current employment. The hiring manager or site lead should confirm role and group needs. IT executes restore, credential reset, and records the change—after both confirmations are documented.
Plan the full seasonal lifecycle
Reactivation is one step in a longer archive-and-rehire workflow. See the pillar for seat states and timing.