Article summary: A physical SIM card gets collected the moment an employee turns in company hardware, but an eSIM is embedded in the device and provisioned remotely, so there is nothing to physically hand back. On a personal phone enrolled in a bring-your-own-device plan, that digital cellular profile can keep working long after the employee's last day. Closing the eSIM offboarding gap means treating a cellular profile like any other account that needs a formal revocation step.
The laptop is returned. The company accounts are disabled. The badge is sitting on someone’s desk. As far as the offboarding checklist is concerned, the former employee is disconnected.
A traditional SIM gives IT something physical to account for. An eSIM does not. Its carrier profile is provisioned digitally, which makes it especially convenient for remote employees.
IT can activate cellular service without shipping a SIM card or requiring an office visit. But that convenience creates an extra offboarding step: the service must also be deliberately deactivated when the employee leaves.
The gap is easiest to miss with personal devices. If a company provisions an eSIM on an employee’s own phone, there is no hardware to collect during offboarding. IT needs to deactivate the cellular line and, where applicable, remove the managed eSIM profile separately.
Otherwise, a former employee could retain company-paid cellular service even after their other access has been shut down.
The most immediate cost of a forgotten eSIM is financial: the company keeps paying for cellular service for someone who no longer works there. Like an unused software license, it can continue generating charges until someone notices.
There can also be a security risk if the associated phone number is still used for account recovery or SMS-based authentication. NIST specifically identifies SIM changes and number porting as risks associated with SMS authentication, reinforcing why phone-based credentials should be reviewed when an employee leaves.
eSIMs do provide remote-management options. For example, Apple supports managing eSIMs through device management services, including controls over eSIM modification and removal during a remote wipe. But those tools only help if eSIM management is actually included in the offboarding process.
A forgotten company eSIM is different from SIM swapping or port-out fraud. In those attacks, a criminal impersonates a customer and convinces a carrier to transfer the victim’s service or phone number to a device or account the attacker controls.
The FCC specifically warns that SIM-swap fraud can involve both physical SIMs and eSIMs. Port-out fraud presents a related risk by transferring the victim’s number to another provider.
A reliable offboarding process treats the cellular profile as its own line item rather than burying it under “return the phone.”
1. Maintain a current inventory. Know which employees have an active eSIM profile, whether it sits on a company-owned or personal device, and which carrier account it bills to.
2. Tie eSIM deprovisioning to account access. When IT disables email, SSO, and other credentials, cellular service should be part of the same offboarding workflow rather than a separate task that can easily be missed.
3. Remove managed eSIM profiles where appropriate. Supported device-management platforms can remotely manage eSIMs on enrolled devices. Apple, for example, provides eSIM management capabilities through device management.
4. Verify that service has actually ended. A completed IT ticket does not necessarily mean the carrier line is inactive. Confirm its status through the appropriate management platform and carrier account.
5. Cancel or reassign the carrier line. Removing an eSIM profile from a device and terminating the underlying cellular service are not always the same action. Make sure unused lines are canceled or reassigned so they do not remain active and billable.
For personal devices, the cleanest fix is addressing this before offboarding ever happens. A bring-your-own-device policy should state upfront that any company-provisioned eSIM profile will be remotely removed at separation.
Offboarding is only complete when the access an employee leaves with is shut down too. An eSIM may be easy to miss because there is no card to collect, but the cellular line behind it still needs the same attention as email, SSO, and every other company-managed connection.
Vudu Consulting can help review your current offboarding process, identify overlooked access points like eSIMs and BYOD devices, and put a repeatable process in place for shutting them down when employees leave.
Get started with Vudu Consulting or email contact@vuduconsulting.com to close the gaps before a forgotten connection becomes a security or billing problem.
An eSIM is a cellular profile embedded directly in a device's hardware rather than stored on a removable card. It is activated, managed, and removed remotely through the carrier or a mobile device management platform, instead of being physically inserted or taken out.
A full device wipe on company-owned hardware removes data, but it does not always deactivate the underlying carrier line. The eSIM profile and the carrier account behind it should be confirmed as canceled or reassigned as a separate step.
Both. Company-owned phones are easier to account for because the device itself is returned, but the eSIM and associated carrier line still need attention. IT should remove or reassign the profile as appropriate and confirm that the underlying cellular service has been canceled, suspended, or reassigned so the company is not paying for an unused line.