A new hire starts on Monday and spends two days waiting for a laptop and a login. Someone else left last month and, as far as anyone can tell, can still read their email from home. Both problems have the same root: nobody wrote down what happens when a person joins or leaves, so it happens differently every time. This IT onboarding and offboarding checklist is deliberately boring, because boring is what makes it repeatable.
Before day one
A single request, from one place
Onboarding starts with a request from the hiring manager that captures everything IT needs at once: name, start date, role, manager, location, which applications and shared folders the role requires, and what hardware is appropriate. A form or ticket template does this; a hallway conversation does not. The same request should trigger account creation, device preparation and licence assignment in one motion.
Accounts built from a role, not from a colleague
The temptation is to “make them like Sarah”, copying an existing user’s permissions. Sarah has accumulated years of access she no longer needs, and the new person now has all of it. Define access by role instead: a small number of standard profiles that say which groups, applications and folders each role gets. Access beyond the profile is requested, approved and recorded separately. This is least privilege in practice, and it is what makes offboarding clean later.
Multi-factor authentication on day one
MFA enrolment belongs in the first hour, not in a follow-up email. The person registers their authenticator and a backup method and signs in for the first time with both factors. Accounts that exist without MFA for even a few days are the ones that get compromised, because a welcome email with a temporary password is exactly what attackers hope to intercept.
Device provisioned, encrypted and enrolled
The laptop arrives with the disk encrypted, the endpoint security agent installed, the device enrolled in management so it can be locked or wiped remotely, and the standard applications present. The user should not have administrative rights on it. An asset record links the serial number to the person from the first day.
Things to decide once, so nobody has to decide them each time
Shared credentials are the awkward corner. Where a shared login is unavoidable, such as a supplier portal that only supports one user, it lives in a password manager with access granted to named people, and it is rotated when any of them leaves. Decide too who approves access outside a role profile, how contractors get accounts with expiry dates, and what day one looks like for a remote starter who never visits the office.
Offboarding: the same day, in the right order
Access removed before the goodbye
When a person’s last day is known, the offboarding ticket is raised in advance and executed at an agreed time on that day: sign-in blocked, sessions revoked, MFA methods cleared, password reset, remote access and VPN removed, and access to every cloud application ended. For an involuntary departure, that sequence happens while the conversation is taking place. Every day of delay is a day a former employee can read mail, download files or simply keep credentials that will later be reused elsewhere.
Mailbox and files handed over, not deleted
The mailbox is converted to a shared mailbox or delegated to the manager, with an automatic reply and a recorded decision about how long it stays. Files in the person’s personal cloud storage are transferred to a manager or a shared location before the account is removed. Ownership of any documents, groups or automations they controlled is reassigned. This is where a departing salesperson’s pipeline quietly disappears if nobody checks.
Device returned and wiped, and the record closed
The laptop, phone, security key and any access cards come back and are checked against the asset record. The device is wiped through management before it is reissued or retired, and the record is updated to show where it went. If a device cannot be recovered, it is remotely wiped and marked as lost.
Shared credentials rotated, licences reclaimed
Every shared credential the person could have known is rotated. Licences are removed after the mailbox and file transfer are complete, not before, so nothing is deleted by an automated retention rule.
Documentation is the checklist itself
This works in a growing company because it is written down and followed every time, and the resulting tickets are the audit trail. Periodically, someone compares the list of active accounts to the list of current staff. When they do not match, the checklist has a gap, and the gap is fixed in the checklist rather than in a panic. Many organizations hand the whole cycle to their managed IT provider because a provider runs it the same way for every starter and leaver, with the tooling to prove it.
Common questions
How quickly should access be removed when someone leaves?
On the day they leave, at an agreed time, and before they walk out for a planned departure. For an involuntary exit, access is removed while the conversation is happening. Sign-in blocked, sessions revoked, MFA cleared, VPN and cloud applications ended, in that order. Delay is the most common offboarding failure, and it leaves a former employee able to read mail and download files.
What happens to a departed employee’s email and files?
Convert the mailbox to a shared one or delegate it to the manager with an automatic reply, transfer personal cloud files to a manager or shared location, and reassign ownership of documents, groups and automations. Only then remove the licence, so nothing is deleted by an automated rule. Record how long the mailbox will be kept and who is responsible for it.
Should new employees have administrator rights on their laptop?
No. Standard user rights are enough for almost every role, and removing local administrator access is one of the most effective controls against malware and accidental damage. Applications that need elevated rights can be installed through management tools or approved on request. Administrative work should use a separate account, used only when needed.
How do we handle shared passwords when someone leaves?
Rotate every shared credential the person could have known, the same day. That is only practical if shared logins already live in a password manager with named access, which is why onboarding should put them there in the first place. Wherever possible, replace shared logins with individual accounts so there is nothing to rotate and every action is attributable to a person.
If joiners and leavers are handled differently every time in your organization, our managed IT services and multi-factor authentication pages describe how we make the process consistent, and you can contact us to have your current checklist, or the absence of one, looked at.


