A new hire starts Monday. HR has the contract, the manager has a welcome lunch planned, and someone in IT gets a Slack message at 4:45 on Friday saying, “Can you set up a laptop for Curtis?” That’s the onboarding process most companies undergo. Then eight months later, someone leaves on bad terms, and no one thinks to turn off their access.
A proper IT onboarding checklist fixes both problems. It gives every new person the right access on day one and makes sure that access disappears the day they leave.
At 𝗭𝗜𝗔 𝗡𝗲𝘁𝘄𝗼𝗿𝗸𝘀, we see the same gaps again and again in small and mid-sized businesses. Nobody is careless. The process just lives in someone’s head instead of on paper. This guide walks through the full checklist, from the first day to the last, and shows how it helps prevent insider threats along the way.
What Is an IT Onboarding Checklist?
A technical onboarding checklist is a written list of all activities needed to safely onboard a new staff member within your organization. The opposite of an onboarding checklist is an offboarding checklist, which deals with how access is removed upon termination of employment.
It is part of a lifecycle. Access is provided, then adjusted over time and eventually revoked. If one step is not done well, there is risk involved.
Why do most businesses skip the IT onboarding checklist?
Asking any business owner if they care about security would get an affirmative answer. Asking if they have a written IT onboarding process for all their new hires and employees who left the business will give a bit of a different response. This doesn’t come from negligence, but rather from the way teams usually operate. Here is why.
1. Faster = Better
While the new hire needs to work by Monday, IT wants to open a lot of access to ensure it happens without issues. Then, it’s supposed to clean it up later. This doesn’t happen, and a year later that person will have access to folders and tools that are completely unnecessary for their job.
What helps: Creating access templates for each role will make sure that speed and safety won’t be opposing forces anymore. Pre-approved access templates will be much faster and more restrictive.
2. No one controls it
HR thinks IT does it, while IT thinks that HR would mention resignations. Managers don’t even think about it. That’s why laptop requests are made on Friday afternoon, while resignation emails are never forwarded to the IT department.
Before Day One: The IT Onboarding Process for New Employees
An effective onboarding process starts even before the employee joins. Once the employee is officially hired by HR, IT needs to act fast.
1. Start with a Role-Based Access Template
Don’t copy the access of the last person who held the job. They probably collected permissions over the years that the new hire doesn’t need.
Instead, build access templates for each role. A sales rep gets the CRM, the shared sales drive, and email. They don’t get payroll folders or the finance system. This is the principle of least privilege, and it’s the most useful habit for preventing insider threats.
2. Create Accounts the Right Way:
Create the email account, single sign-on solution, and other applications that your department uses. Try to use your identity platform as much as possible to have all these solutions consolidated into one application. The fewer accounts to remember, the better.
3. Prepare the device
Before you hand it over, check whether it is a laptop, phone, or both:
- Operating system fully updated.
- Disk encryption turned on.
- Endpoint protection and device management installed.
- Local admin rights removed for the user.
- Screen lock and automatic updates enforced.
4. Set up multi-factor authentication
Do this on day one, not “when we get around to it.” Every account that supports MFA should have it enabled before the employee logs in for the first time.
Day One to Week One: The IT Checklist for New Hires
This is where the human side matters. The best technical setup fails if people don’t understand why the rules exist.
Hand over credentials securely
Never use emails to transfer passwords in plain text format. Use a password manager or a one-time link to make an immediate password change for the employee.
Teach them to use a password manager
Give people the right tool, and they’ll stop using the same password for both work and personal stuff.
Run a short security briefing
This will take about fifteen to twenty minutes. Talk about phishing, reporting anything suspicious, and the proper use of your company’s equipment. Don’t give a lecture; use examples like an invoice email or one saying “The CEO needs gift cards.”
Get policies signed
A signed agreement is necessary for the acceptable use policy, remote work policy, and data-handling policy. This helps both parties.
Record everything
Log what was issued, what access was granted, and who approved it. This record is gold during an audit or an investigation.
Here is the short version you can paste into your own process:
- Role-based access approved by the manager
- Accounts and MFA created
- Device encrypted, patched, and enrolled
- Credentials delivered securely
- Security training completed
- Policies acknowledged
- Everything documented
That list is the core IT checklist for new hires. Keep it simple enough that people actually follow it.
How Do You Prevent Insider Threats While Employees Are Still Here?
Many companies stop thinking about security the moment onboarding ends. That is a mistake, because most access problems build up slowly.
The insider threat is one where a person with legitimate access to your systems poses the danger. This may be malevolent, like a worker stealing data before switching jobs. This threat may also be unintentional, where an employee sends a spreadsheet to the wrong person.
Here are ways you can protect yourself from these threats without creating a Big Brother atmosphere at the office.
Review access every quarter
Ask managers to confirm who still needs what. People change roles, projects end, and permissions stay behind. A quarterly review takes an hour and clears out surprising amounts of clutter.
Adjust access on every role change
The move to a new position is a form of both onboarding and offboarding in relation to the previous position.
Watch for unusual behavior
Large downloads at midnight, logins from unexpected locations, or sudden access to files outside someone’s normal work are all worth a look. Basic logging and alerting will catch most of these.
Limit who can export data
Not everyone needs the ability to copy client records to a USB drive or personal cloud storage. Restrict it by role.
Separate duties for sensitive tasks.
It is a mistake for an individual responsible for creating a vendor payment to be the same individual who approves it.
Create a culture that encourages speaking up.
A great many of what can be called insider occurrences are already seen by other employees way before they are detected by IT.

Offboarding: The Account Deprovisioning Checklist
And now comes the piece that most companies get wrong. Deprovisioning involves denying access to all systems, devices, and services once someone has left. The objective is clear. By their last day, they should not have any way in.
This is important when timing is considered. In case of a resignation, ensure that you plan the cut-off to happen on their last day. In case of a termination, ensure that the IT department can carry out this action prior to or during the discussion.
Use this sequence:
- Disable the primary account first. Block sign-in on your identity platform. This usually cuts off email, SSO apps, and VPN in one move.
- Revoke active sessions and tokens. The disabling of a password does not necessarily terminate all existing sessions on a mobile device or browser.
- Remove MFA devices. Clear any registered authenticator apps or hardware keys.
- Recover company devices. Collect laptops, phones, badges, and keys. Log serial numbers.
- Wipe or lock mobile access. If they used a personal phone to access work email, remove the work profile or selectively wipe the phone.
- Change shared credentials. Any password the person knew, such as a shared admin login or social media account, must be rotated. This one is missed constantly.
- Review other applications. Marketing tools, project management tools, and vendor websites are usually separate from your core authentication application. Review your applications.
- Assign new owners for their mailboxes and files. Redirect emails to the manager, migrate the files, and transfer the calendar so that work proceeds.
- Preserve data where required. Make sure you back up their mailbox and files before you delete anything.
- Reclaim licenses. You are paying for software seats nobody uses. This part pays for itself.
- Confirm and document. Have a second person verify the checklist is complete and sign it off.
Expiry dates should be set when creating accounts for contractors and temporary workers. This helps to prevent accidental misuse of accounts due to forgetting.
Common Mistakes We See
Truth has no single source
If HR, IT, and management all have their own separate directory systems, one thing is sure: discrepancies will always exist. Integrate your HR directory into your identity management system such that changes prompt action.
Forgotten service accounts
Service accounts created for past integration efforts may now have owners long gone and forgotten what they support.
Taking departures too lightly
Even amicable departures pose risks. Users take away contacts, documents, and passwords with them without ill intentions.
Doing it from memory
The checklist only works if it is written down and used every time, including for the CEO’s cousin who joins on a Tuesday.
Making the Checklist Stick
A checklist nobody uses is just a document. A few small moves help it become a habit:
- Assign one named owner, usually IT or operations.
- Trigger it automatically from HR events.
- Keep it to one page per stage.
- Audit a few completed examples every quarter.
- Update it whenever you add a new tool.
If you don’t have the in-house time, this is exactly the kind of work a managed IT partner can take over. ZIA Networks builds and runs onboarding and offboarding workflows for growing businesses, so access is granted fast, reviewed regularly, and removed cleanly.
FAQs
What should be on an IT onboarding checklist?
IT onboarding should consist of access role permission approval, setting up accounts and MFA, encryption of devices, credential delivery in a secure way, security awareness training, policy signing, and logging of all issued items.
What is account deprovisioning?
The definition of deprovisioning an account means taking away an employee’s access rights to resources, either after the person has left the company or after a change in his/her position.
How soon should you remove access after an employee leaves?
Immediately. For planned departures, access should end at the close of their last working hour. For terminations, it should be cut at or before the moment the employee is told.
How do you prevent insider threats in a small business?
One should start with such basics as least privilege access, quarterly access reviews, multi-factor authentication, simple logging of activities, and a good offboarding policy. It would be beneficial to add security awareness and policy creation in order to reduce the risk of errors and misuse.
Who is responsible for onboarding and offboarding security?
The technical aspect belongs to IT; however, HR and management should initiate those actions. The best approach is when all three work under one policy.
Conclusion
What is important for security? It is not about using complex techniques; rather, it is about having a consistently applied approach. An effective checklist in relation to onboarding of IT will guarantee that new employees can easily enter, whereas an appropriate offboarding procedure will put a stop to former employees. Additionally, conducting access reviews will help avoid potential incidents.
If your current approach looks like “IT will work it out,” then now is a great opportunity to put everything on paper. If you need assistance in that regard, then our experts at ZIA Networks would be glad to examine your system.