Every business hires people and, eventually, people leave. The IT side of both processes is critical — and at most small businesses, it's completely ad hoc. Someone scrambles to set up a laptop the morning a new hire starts. Someone vaguely remembers to change a password a week after someone leaves. Things get missed.
This checklist gives you a documented, repeatable process for both onboarding and offboarding. Use it as-is or customize it for your business. The point is to have a process — one that anyone can follow, every time, without things falling through the cracks.
We've organized everything by timeline so you know exactly what needs to happen and when.
Part 1: Onboarding — Before Day One
This is where the work happens. If you get this right, day one is smooth. If you leave it until the morning they start, you're setting everyone up for a frustrating experience. Ideally, everything in this section should be completed at least 2-3 business days before the new hire's start date.
Accounts and Access
- Create Microsoft 365 account — set up their email address, assign the appropriate license (Business Basic, Standard, or Premium), and add them to the correct security groups
- Create accounts in line-of-business applications — whatever software your business runs (accounting, CRM, project management, industry-specific apps), get their accounts created and ready
- Set up VPN access — if they'll be working remotely or need access to on-premises resources, configure their VPN credentials
- Create network credentials — Active Directory or local account, depending on your setup
- Assign file share and SharePoint access — determine what files and folders they need access to based on their role. Don't give blanket access to everything — principle of least privilege
- Add to distribution lists and Teams channels — the all-company list, their department list, relevant Teams channels. Ask their manager which ones
- Set up email signature — if your company has a standard email signature format, configure it in advance
Equipment
- Provision laptop or desktop — image or configure with your standard build, including OS, drivers, and all required software
- Monitors, keyboard, mouse, headset — have everything ready at their desk or shipped to them if remote
- Install required software — Office apps, line-of-business applications, VPN client, antivirus, backup agent, and any other standard tools
- Configure MFA — pre-register the account for MFA so you can walk them through the phone app setup on day one
- Test everything — log in with their credentials, verify email works, verify app access, verify file share access. Don't wait for them to find the problems
Documentation
- Prepare a welcome packet — IT contact information, how to submit a help request, Wi-Fi password, basic how-tos for your key systems, and any acceptable use policies they'll need to review
Part 2: Onboarding — Day One
Day one should be about getting the new hire comfortable and productive — not troubleshooting IT problems. If you did the pre-work, this is mostly walkthrough and verification.
- Walk through equipment and login — sit with them (or screen share if remote) and walk through their laptop, login credentials, and basic navigation
- Verify all systems and apps are accessible — have them actually log into every application they'll need. Don't assume it works because it worked when you tested it
- Complete MFA setup — walk them through installing the authenticator app on their phone and registering their account
- Set up password manager — if your company uses a password manager (and it should), get them set up with their vault and show them how to use it
- Enroll in security awareness training — sign them up for your security training program. Phishing awareness, password hygiene, social engineering basics
- Review acceptable use policy — make sure they've read and acknowledged your IT acceptable use policy
- Introduce IT support contact and process — who to call, how to submit a ticket, what qualifies as urgent vs. routine
- Verify email sending and receiving — have them send a test email and reply to one. Simple, but it catches configuration issues early
- Test VPN if remote — if they're working remotely, have them connect to the VPN and verify access to internal resources
Part 3: Onboarding — First Week
The first week is about follow-up. Things always come up once someone starts actually working — access they didn't know they needed, software that's not working quite right, permissions that need adjusting.
- Follow up on any access issues — check in with the new hire (or their manager) within 2-3 days. "Is there anything you can't access that you need?"
- Verify all line-of-business apps are working — sometimes apps work in testing but break in real use. Catch it early
- Complete security awareness training — make sure they finish whatever training they were enrolled in on day one
- Set up mobile device — if they'll access company email or apps on their phone, configure it with your MDM or app protection policies
- Confirm backup is running — verify that their device is being backed up according to your backup policy
Part 4: Offboarding — Immediate (Day Of or Before)
When an employee is leaving — whether it's a resignation, a layoff, or a termination — time is critical on the IT side. The actions below should happen on their last day or, in the case of an involuntary departure, before they're notified. Speed matters here. A disgruntled employee with active access is a real risk.
- Disable the user account — disable, don't delete. You'll need the account intact for data preservation. Disabling immediately revokes their ability to log in
- Change or revoke shared passwords — any shared credentials they had access to (Wi-Fi, shared email accounts, vendor portals) need to be changed immediately
- Revoke VPN access — remove their VPN credentials or disable their VPN account
- Remove from MFA — deregister their authentication methods so they can't approve sign-in requests
- Set up email forwarding or shared mailbox — if their role requires continuity, convert their mailbox to a shared mailbox or set up forwarding to their manager. This doesn't require a license
- Disable remote access — RDP, remote desktop tools, any remote access they had
- Block mobile device access — perform a selective wipe to remove company data from their personal device, or a full wipe if it's a company device
- Collect equipment — laptop, phone, keys, access badges, monitors, peripherals. Have a checklist of what was issued to them and check everything off
Part 5: Offboarding — Within 48 Hours
Once the immediate access revocation is done, you have a short window to handle data preservation and cleanup.
- Review and export mailbox — if you need to retain email for legal, compliance, or business continuity reasons, export the mailbox to PST or place it on litigation hold
- Transfer OneDrive files to manager — M365 allows you to transfer a user's OneDrive contents to another user. Do this before deleting the account, or the files are gone
- Remove from all security groups and distribution lists — clean up their group memberships so they're not receiving email or appearing in directories
- Remove from line-of-business applications — deactivate or delete their accounts in every app they had access to. Don't forget the small ones — project management tools, chat apps, file-sharing services
- Audit for auto-forwarding rules — check whether they set up any email forwarding rules during their tenure, especially to external addresses. This is both a security check and a business continuity check
- Review recent activity logs — look at their sign-in history and file activity for anything unusual — mass downloads, large file transfers, access to sensitive data they don't normally touch. This isn't about suspecting everyone, it's about due diligence
Part 6: Offboarding — Within 30 Days
The final cleanup. At this point, you've secured everything that was urgent. Now you're tying up loose ends and reclaiming resources.
- Delete user account and reclaim M365 license — once you've preserved everything you need, delete the account and reassign the license. No point paying for a license nobody's using
- Wipe and reimage returned equipment — fully wipe the hard drive and reimage with a clean build. Don't just delete their profile and hand it to the next person
- Update documentation — update your network documentation, org charts, asset tracking, and any diagrams that reference the departed employee or their equipment
- Remove from vendor and partner portals — anywhere they had external access representing your company — vendor portals, client systems, partner dashboards — remove their accounts
- Update shared credentials — do a final review of any shared passwords or access they might have known about. When in doubt, change it