Resource
Employee IT onboarding and offboarding checklist
Two processes that most businesses run informally until something goes wrong. Onboarding done badly creates permission sprawl that takes years to unwind. Offboarding done badly leaves working credentials in the hands of people who no longer work for you.
Both directions, in order
The offboarding column is the one that matters most and the one most often improvised.
| Stage | Onboarding |
|---|---|
| IdentityDisable immediately, do not delete yet | Create from a role template, never by copying a person |
| AccessRevoke application and third party access | Grant only what the role requires |
| DeviceCollect, wipe, record return | Enrol in management, encrypt, install standard software |
| EmailConvert to shared or forward, per policy | Configure, add to relevant groups |
| Multi factorRemove registered methods | Enrol before first sign in |
| DataTransfer ownership of files and shared items | Explain where files belong |
| RecordUpdate the register and diarise final deletion | Add to the asset and access register |
Why copying permissions causes problems
Creating an account by duplicating an existing employee is fast and it is the root of most access sprawl.
- The copied account inherits everything that person accumulated over years, including access they should not still have
- Nobody can later explain why a given person has a given permission
- Access reviews become impossible because there is no defensible baseline
- Compliance frameworks expecting least privilege will record it as a finding
- The problem compounds, because the next copy inherits the last one's excess
The account that outlives the employee
The most common finding in an access review is a set of active accounts belonging to people who left, sometimes years earlier.
Each one is a working credential into company systems, held by someone with no current relationship to the business, usually with an unchanged password and frequently without multi factor authentication.
The fix is procedural rather than technical. Offboarding runs on the last day as a defined step rather than when somebody remembers, a quarterly access review catches anything missed, and single sign on means disabling one identity removes access everywhere rather than relying on a list.
Common questions
Answered before you ask.
Should we delete a leaver's account immediately?
Disable immediately, delete later. Immediate deletion can destroy data you still need, break shared items they owned, and remove audit history you may want if a dispute arises. Standard practice is to disable on the last day, transfer ownership of files and shared content, then delete after an agreed retention period.
What about their email?
Convert it to a shared mailbox or apply forwarding for a defined period so customers and colleagues are not lost, then close it. On most platforms a shared mailbox does not consume a licence, which makes it both the tidier and the cheaper option compared with leaving the account active.
How do we handle someone leaving on bad terms?
Coordinate the timing so access is revoked as the conversation happens rather than after it, and include remote access, third party services and any shared credentials they knew. This is one of the strongest practical arguments for a password manager and single sign on, since shared passwords they memorised cannot be revoked by disabling an account.
Related
Read next.
IT support and help desk
Tiered support with published response targets, remote and onsite.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Microsoft Copilot and AI adoption security
The permissions review to do before deploying it.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Accounting and CPA firms
FTC Safeguards, WISP, tax season uptime
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.