← All articles
Managed IT6 min read

New Employee IT Setup: A Checklist That Gets Followed

Most small businesses onboard from memory. Someone remembers most of what a new hire needs, sets it up the day before they start, and catches the rest during their first week as they hit walls.

It works, roughly. The costs are hidden: a new person spends their first days unable to do the job, someone senior loses hours to setup, and access gets granted ad hoc in ways nobody is tracking. That last one is the part that matters later.

Before their first day

  • Hardware ordered, arrived, and actually turned on and updated — not still shrink-wrapped
  • Company account created, with a password they're required to change at first sign-in
  • Multi-factor authentication enrolled, or enforced so they must enrol on first login
  • Email set up, plus any shared mailboxes or distribution lists they belong to
  • Group membership assigned by role — the group grants the access, not a person clicking checkboxes
  • Files and shared drives mapped, with permissions that match the role
  • Software installed and licensed, including anything the role specifically needs
  • Endpoint protection installed and confirmed reporting in
  • Device enrolled in whatever management you use, so it isn't invisible

The single change with the biggest payoff is assigning access by role rather than individually. "Give them what Sarah has" quietly propagates whatever Sarah accumulated over four years, including everything she shouldn't still have.

On their first day

  • Walk them through signing in and confirm MFA works on their actual phone
  • Show them how to get IT help, so it doesn't default to whoever sits nearest
  • Point them at where files live and what the naming conventions are
  • Cover the security basics in five minutes — phishing, password manager, what to do if something looks wrong
  • Tell them explicitly what they're allowed to install, and what AI tools are and aren't approved

The half that usually doesn't exist: offboarding

Onboarding gets attention because someone is waiting. Offboarding has no one waiting, so it drifts — and it's the higher-risk half.

  • Disable the account rather than deleting it — deleting can take shared files and history with it
  • Revoke active sessions and tokens explicitly; disabling an account doesn't always end a session already signed in
  • Reset or rotate any shared credentials they knew, which is the step that's almost always skipped
  • Remove them from third-party services — the ones bought on a card and never inventoried
  • Forward or delegate their mailbox, and set an autoreply that routes people somewhere useful
  • Collect hardware, and wipe it before it's reissued
  • Transfer ownership of files and any automation or scheduled jobs in their name
  • Remove building access, VPN access, and anything on their personal phone

The item that bites hardest is the shared credential. If a departing person knew the Wi-Fi password, the shared admin login, or the account everyone uses for a vendor portal, disabling their user account changes nothing about their access. Those need rotating, which is also the argument for having very few of them.

Make it a document, not a memory

The checklist doesn't need to be sophisticated. A shared document that gets copied per person, with boxes ticked and a date, is enough. The point is that it's the same every time and someone can see what was done.

It also answers a question you'll eventually be asked — by an auditor, an insurer, or a client — which is simply: how do you know that person's access was removed?

The short version

Write the list down, grant access by role, and give offboarding the same attention as onboarding. New hires get productive faster, and you stop accumulating accounts belonging to people who left.

If onboarding has become improvised as you've grown, this is a good thing to hand off. We help New Jersey businesses set this up so it runs the same way every time.

Need a hand?

We handle this for New Jersey businesses and homes

Whether it's a one-off problem or ongoing support, we're happy to take a look — and to tell you honestly if you don't need us.

Keep reading