top of page
Search

New Hire to Last Day: The IT Checklist Every Business Should Have


Onboarding and offboarding an employee involves more than assigning a desk and sending a welcome email. From the moment someone joins your organization, they may receive access to company email, business applications, shared files, sensitive data, and physical devices.


When onboarding is rushed, employees begin without the tools they need or with more access than their role requires. When offboarding is incomplete, former employees may retain access to company systems, devices go unreturned, and important business information becomes difficult to recover.


A clear employee IT lifecycle process prevents both problems.

The Reality: Employee Changes Create Technology Risk


Many businesses manage onboarding and offboarding through informal emails, verbal requests, or last-minute messages to IT. This often leads to:

  • Accounts created after the employee starts

  • Incorrect or excessive permissions

  • Missing software licenses

  • Unmanaged personal devices

  • Shared passwords and undocumented access

  • Former employee accounts remaining active

  • Lost email, files, or customer information

  • Devices that are never returned or properly erased


These are not merely administrative inconveniences. They create security gaps, productivity delays, unnecessary expenses, and business continuity risks.


A standardized process ensures Human Resources, management, and IT know exactly what must happen when an employee joins, changes roles, or leaves.


Before the First Day: Prepare the Technology

Effective onboarding begins before the employee arrives. IT should receive a formal request containing everything needed to configure the employee correctly: full name, job title and department, manager, start date, work location, employment type, required equipment and applications, access requirements, phone needs, remote-work status, and any special security or compliance requirements.



Providing this early gives IT time to prepare the account, equipment, and permissions before day one.


Account and Identity Setup

Every employee should receive an individual, company-managed identity. Onboarding should include:

  • Creating the primary user account and company email address

  • Adding the employee to the correct security and distribution groups

  • Configuring multifactor authentication

  • Establishing password and account-recovery requirements

  • Granting access to approved business applications

  • Confirming access to shared mailboxes, calendars, and collaboration platforms

  • Documenting account ownership and licensing


Employees should never share usernames or passwords. Individual accounts create accountability, improve auditing, and allow access to be removed without disrupting others.


Give Employees the Access They Need Not Everything Available

Access should follow the principle of least privilege: users receive only what their responsibilities require. Accounting staff may need financial systems; sales staff may need the CRM; managers may need departmental reports; IT admins may require separate privileged accounts; temporary staff may need time-limited access.

Role-based access makes onboarding consistent and prevents employees from inheriting permissions simply because a coworker has them.


Device Preparation

Company devices should be configured before they are issued:

  • Record the device in the asset inventory

  • Apply operating system and security updates

  • Install endpoint protection and monitoring tools

  • Enable disk encryption and screen-lock requirements

  • Install approved applications

  • Remove unnecessary local administrator access

  • Confirm backup and cloud-sync settings

  • Record the serial number and assigned employee

  • Test connectivity, email, printing, and remote access


The employee should acknowledge receipt and understand acceptable-use requirements.


Software and Application Access

Modern employees use more applications than leadership often realizes — Microsoft 365 or Google Workspace, CRM, accounting and payroll, project management, file sharing, password managers, remote access tools, and industry-specific platforms.


Every application should have a documented owner, business purpose, license assignment, and access level. Without centralized tracking, organizations pay for unused licenses or overlook accounts during offboarding.


Security Orientation for New Employees

Technology onboarding is more than issuing credentials. Employees should understand how to identify and report suspicious emails, why MFA is required, how data should be stored and shared, which applications are approved, how to request support, and how to report a lost or stolen device. These expectations should be set on day one and reinforced through ongoing security awareness training.


Confirm That Onboarding Is Complete

A completed onboarding ticket should verify — not just assume — that the employee can sign in, MFA is active, email works, required applications are available, permissions are correct, the device is functioning, security tools are reporting, and the manager has confirmed the access level. This final validation prevents small setup problems from becoming days of lost productivity.


Employee Transfers and Role Changes

One of the most common access-control problems occurs when permissions are continually added but never removed. An employee who has held several roles may accumulate access to systems no longer relevant to their current position.


A role change should trigger a complete access review — not simply a request for more permissions. That means adding required access, removing what is no longer needed, updating groups and shared resources, reassigning equipment, reviewing administrative privileges, and updating documentation.


The Offboarding Process: Protecting the Business on the Last Day

Offboarding should be coordinated between management, HR, and IT, with clearly defined timing. For planned departures, IT should know the final working date and time. For involuntary separations, access may need to be disabled the moment the employee is notified.

Incomplete offboarding is a documented security risk. CISA has reported incidents involving compromised former-employee accounts and recommends ensuring departed employees can no longer access organizational systems.


Immediate Account Actions

  • Block the primary sign-in

  • Revoke active sessions and authentication tokens

  • Disable remote and VPN access

  • Remove application access and security-group membership

  • Disable privileged or administrative accounts

  • Remove access to shared password vaults

  • Revoke physical access credentials

  • Rotate shared credentials the employee may have known

  • Remove access to third-party vendor and customer portals


Blocking the account is generally preferable to immediately deleting it — the organization may still need to preserve email, files, and audit records first. Microsoft's own offboarding guidance separates immediate access blocking from mailbox, OneDrive, and eventual account-deletion steps.


Email and Data Handoff

Before removing an account, decide what happens to the employee's communications and files. Depending on the role, that may mean converting the mailbox to a shared mailbox, granting a manager authorized access, configuring a temporary auto-reply, reassigning calendar meetings, and updating distribution lists.

For files: transfer ownership of business documents, move them into approved shared locations, reassign cloud storage and customer accounts, confirm passwords are stored in the company vault, and apply any retention or legal-hold requirements. Important business information should never remain isolated in a departed employee's personal workspace.


Device and Asset Recovery

Every assigned item — laptop, phone, tablet, security key, access badge, docking station, external storage — should be returned and verified. After recovery, IT should inspect the device, preserve required data, securely erase or reimage it, and update the asset inventory. Remote employees should receive clear return and shipping instructions.


Don't Forget Third-Party and Informal Access

The main company account is only one piece. Former employees may still have access through vendor websites, social media accounts, website admin platforms, domain and hosting providers, marketing tools, banking systems, and shared passwords stored outside approved systems.


You cannot reliably remove access from systems you don't know the employee was using which is exactly why an application and access inventory is critical.


Business Impact

A structured employee IT lifecycle process helps organizations:

  • Reduce security exposure and prevent unauthorized access

  • Improve employee productivity from day one

  • Protect company and customer data

  • Recover equipment more consistently

  • Reduce unnecessary software expenses

  • Maintain accurate account and asset records

  • Support compliance and cyber insurance requirements

  • Create clear accountability between departments


Most importantly, it replaces informal, reactive decisions with a repeatable process.

From Reactive Administration to Lifecycle Management


Onboarding and offboarding should not depend on someone remembering to send IT an email. The process should be documented, assigned, tracked, and verified — HR initiates the request, the manager defines required access, IT provisions or removes it, security requirements are applied consistently, and completion is documented. This creates a reliable employee lifecycle from the first day through the last.


Final Thoughts

If your organization creates accounts after employees start, lacks a standardized access checklist, cannot quickly identify every application an employee uses, rarely reviews permissions after role changes, deletes accounts without transferring business data, or isn't sure whether former employee accounts are still active — then your process likely contains avoidable gaps.

The good news: these processes can be standardized. With clear roles, documented checklists, accurate inventories, and coordinated communication, businesses can improve productivity while reducing security and operational risk.


Next Step

True Source 365 helps small and midsize businesses build practical, repeatable IT processes for onboarding, access management, device deployment, security, and offboarding.


If you're unsure whether former employees still have access — or whether new hires are getting the right technology and permissions — we can help you evaluate your current process and create a clearer path forward.


👉 Schedule a discovery call with True Source 365 to review your employee IT lifecycle and identify what to address first.

 
 
 

Comments


bottom of page