Skip to content

New employee IT onboarding checklist

Short answer. Work backwards from the first morning. The account and licence come first, because everything else depends on them. Then group-based access, then the device, then multi-factor enrolment on day one while the person is in front of you. That order avoids the rework that turns an hour of setup into a day.

Two to three days before they start

  1. 1Create the user account and assign a licence. Nothing else can happen until this exists.
  2. 2Decide the email address format now and keep it consistent. Changing it later breaks calendar invites and mailing lists.
  3. 3Add them to the groups their role needs, not to individual folders. Group-based access is the single decision that makes offboarding quick later.
  4. 4Order or prepare the device, and install your standard software before it reaches them.
  5. 5Write down what you granted. That list is what you reverse on their last day.

The day before

  1. 1Sign in to the account yourself once to clear any first-run prompts.
  2. 2Confirm email sends and receives, rather than assuming it does.
  3. 3Check the shared drives they need actually open from that device.
  4. 4Set a temporary password that must be changed at first sign-in.

First morning, with the person present

Multi-factor enrolment belongs here, not earlier. Doing it while they are in front of you takes two minutes. Doing it remotely three weeks later, when they are travelling, takes a support call.

  1. 1They set their own password. Nobody else should know it.
  2. 2Enrol multi-factor authentication, and register a backup method at the same time.
  3. 3Sign in on their phone if they will use work email there.
  4. 4Show them how to reach IT support, so their first problem does not become a week of quiet struggling.

The offboarding half, which is the part that gets skipped

Onboarding gets attention because someone is waiting. Offboarding gets skipped because nobody is. That is exactly why old accounts stay live for months. The order matters here more than anywhere: access stops first, data is preserved second.

  1. 1Disable the sign-in immediately. Not delete — disable, which stops access without destroying anything.
  2. 2Revoke active sessions, otherwise a signed-in phone keeps working after the password changes.
  3. 3Convert the mailbox to shared, or forward it to whoever is covering.
  4. 4Transfer their files to the new owner before touching the licence.
  5. 5Remove the licence once the data is moved, so you stop paying for it.
  6. 6Wipe or reassign the device.
Run through your own list once a quarter and check every account against current staff. Finding one live account for someone who left last year is common, and it is exactly the kind of gap that gets exploited.

When to stop and call someone

  • You are hiring regularly and onboarding is eating someone’s week
  • You are not certain every past employee’s access is actually closed
  • Access was granted folder by folder and nobody knows who can see what
  • Somebody left on bad terms and access needs closing today
  • Nobody currently has working administrator access to do any of this

Want this handled for you?

A technician can look at it directly. First session is $49, up to 45 minutes, and we confirm the scope and price before any work starts.