The New-Employee IT Onboarding Checklist
Everything a new starter needs to be productive on day one — accounts, devices, access and security — set up properly instead of scrambled together at the last minute.
New-employee IT onboarding is simply everything that needs to be set up so a new starter can sit down and get to work — their accounts, their laptop, the systems they need access to, and the security around all of it. Done well, it’s invisible: the new person logs in on their first morning and everything is there. Done badly, they spend day one watching someone reset passwords and hunt for a spare charger.
This guide is a practical checklist you can adapt. It’s ordered roughly the way the day should flow, and it works whether you’re hiring your fifth person or your fiftieth.
What good onboarding actually includes
1. Accounts and identity
Start with who they are on your systems. That means an email account and a login on your main platform — for most businesses that’s Microsoft 365 or Google Workspace. Get the display name, the email address format and the job title right the first time, because these flow through to signatures, directories and dozens of other places.
Set them up in your groups from the start — the sales team group, the whole-company distribution list, whatever applies to their role. Group-based access is far easier to manage than granting things one by one, and it means the next person in the same role can be set up in minutes.
2. Access to the right systems — and nothing more
List the specific tools the role needs: shared drives and folders, the CRM, the accounting or booking software, any line-of-business app. Grant access based on the job, not on “give them what the last person had.” Over-granting is how businesses quietly accumulate security risk.
This is also the moment to enable multi-factor authentication and get it registered on their phone before they need it. Setting it up on day one is painless. Retrofitting it across a whole team later is a project.
3. The device
Whether it’s a company laptop or a desktop, it should arrive built, not blank. That means the operating system updated, the standard apps installed, disk encryption switched on, and the machine enrolled in whatever management you use so it can be kept patched and secure from the start. If you issue phones, the same thinking applies.
A properly prepared device is the single biggest difference between a smooth first day and a frustrating one. If you’d rather not build machines yourself, this is exactly the kind of thing business device support covers — the laptop turns up ready to go.
4. Communication and the small stuff
Add them to your calendars, chat and video tools. Set up their email signature to the company standard. Connect them to the office Wi-Fi and any printers they’ll use. Point them at where shared documents live. None of this is complicated, but forgetting it is what generates a trickle of “how do I…” questions all week.
5. Security and the ground rules
Give the new starter a short, plain briefing on how your business handles security: how to spot a suspicious email, why they should never reuse passwords, where to save work so it’s backed up, and who to tell if something looks wrong. You don’t need a lecture — a five-minute conversation on day one sets the tone far better than a policy document nobody reads.
Who needs a proper checklist, and when
Any business that hires more than occasionally benefits from a written onboarding checklist. If setup lives in one person’s memory, it falls apart the moment that person is away — and it’s never consistent, so one new starter gets multi-factor authentication and the next one doesn’t.
It matters most in regulated or client-sensitive settings. A law firm, an accountancy practice or a dental surgery has real obligations around who can see what, so getting access right on day one isn’t just tidy — it’s part of staying compliant. But even a ten-person office feels the difference between a new joiner who’s productive by lunchtime and one who’s still locked out at 4pm.
The best time to build your checklist is before your next hire, not during it. Write down what a standard new starter needs, keep a version for each common role, and treat it as a living document — every time you add a new tool, add it to the list.
A quick word on offboarding, too: the same list works in reverse. When someone leaves, you want a reliable way to revoke access, recover the device and secure their accounts. A business that onboards well usually offboards well, because both run off the same clear record of who has access to what.
Getting it right without the scramble
Most onboarding problems aren’t hard to solve — they’re just left too late. A short lead time, a shared checklist and a device that arrives ready to use will handle the vast majority of first-day friction.
If you’d rather hand the whole thing over, that’s a normal part of managed IT support: you tell us a new person is starting, their role and their date, and we handle the accounts, the access, the device and the security so they’re ready to work on their first morning. If you’d like help turning your onboarding into a repeatable, boring, reliable process, get in touch and we’ll set it up with you.
Frequently asked questions
How far in advance should IT onboarding start?
Aim to have everything requested at least a week before the start date, and fully built two or three days ahead. Hardware can take time to arrive, and licences occasionally need ordering, so a last-minute request almost always means the new person waits around on their first morning. A short lead time turns a stressful scramble into a quiet, boring, well-run day — which is exactly what you want.
Who should own the onboarding checklist — HR or IT?
Both, working from the same list. HR knows the start date, the role and the reporting line; IT knows what accounts, access and hardware that role needs. The handover point is a simple form or ticket HR raises the moment an offer is accepted. If the list lives only in one person's head, it breaks the first time that person is on holiday.
What should happen to a new starter's access if they change roles later?
The same discipline that got access right on day one should review it whenever the role changes. People tend to accumulate permissions as they move around, and old access rarely gets removed unless someone checks. A light review at each role change keeps access matched to the job and closes quiet security gaps.
Want a hand with any of this?
Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.
