Skip to content

Resource

Employee IT onboarding and offboarding checklist

Two processes that most businesses run informally until something goes wrong. Onboarding done badly creates permission sprawl that takes years to unwind. Offboarding done badly leaves working credentials in the hands of people who no longer work for you.

Both directions, in order

The offboarding column is the one that matters most and the one most often improvised.

Onboarding and offboarding steps in order
StageOnboarding
IdentityDisable immediately, do not delete yetCreate from a role template, never by copying a person
AccessRevoke application and third party accessGrant only what the role requires
DeviceCollect, wipe, record returnEnrol in management, encrypt, install standard software
EmailConvert to shared or forward, per policyConfigure, add to relevant groups
Multi factorRemove registered methodsEnrol before first sign in
DataTransfer ownership of files and shared itemsExplain where files belong
RecordUpdate the register and diarise final deletionAdd to the asset and access register

Why copying permissions causes problems

Creating an account by duplicating an existing employee is fast and it is the root of most access sprawl.

  • The copied account inherits everything that person accumulated over years, including access they should not still have
  • Nobody can later explain why a given person has a given permission
  • Access reviews become impossible because there is no defensible baseline
  • Compliance frameworks expecting least privilege will record it as a finding
  • The problem compounds, because the next copy inherits the last one's excess

The account that outlives the employee

The most common finding in an access review is a set of active accounts belonging to people who left, sometimes years earlier.

Each one is a working credential into company systems, held by someone with no current relationship to the business, usually with an unchanged password and frequently without multi factor authentication.

The fix is procedural rather than technical. Offboarding runs on the last day as a defined step rather than when somebody remembers, a quarterly access review catches anything missed, and single sign on means disabling one identity removes access everywhere rather than relying on a list.

Common questions

Answered before you ask.

Should we delete a leaver's account immediately?

Disable immediately, delete later. Immediate deletion can destroy data you still need, break shared items they owned, and remove audit history you may want if a dispute arises. Standard practice is to disable on the last day, transfer ownership of files and shared content, then delete after an agreed retention period.

What about their email?

Convert it to a shared mailbox or apply forwarding for a defined period so customers and colleagues are not lost, then close it. On most platforms a shared mailbox does not consume a licence, which makes it both the tidier and the cheaper option compared with leaving the account active.

How do we handle someone leaving on bad terms?

Coordinate the timing so access is revoked as the conversation happens rather than after it, and include remote access, third party services and any shared credentials they knew. This is one of the strongest practical arguments for a password manager and single sign on, since shared passwords they memorised cannot be revoked by disabling an account.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment