Business IT · Workforce Lifecycle

Small Business IT Onboarding and Offboarding Checklist

Give new employees the right technology on time, then remove access and transfer business ownership consistently when people change roles or leave.

Published July 22, 202610-minute readEmployee technology lifecycle
Small business manager and IT specialist preparing a laptop and secure accounts for an employee

Employee technology problems often begin before the employee’s first day. The laptop is ordered late, the wrong license is assigned, access is copied from someone with a different role, multifactor authentication is rushed, and no one confirms which files or customer systems the person should own. When someone leaves, the same lack of process can leave active accounts, unreturned devices, forgotten vendor access, and business information with no new owner.

A repeatable joiner, mover, and leaver process connects the manager, HR, operations, IT, security, facilities, and application owners. It gives the employee what is approved, records who made the decision, and produces evidence that access changed when employment or responsibilities changed.

Core workflow: authorized request, role-based access, prepared device, secure authentication, manager validation, documented changes, timely access removal, data transfer, equipment recovery, and final review.

1. Start with a complete, approved request

Collect the employee name, manager, title, department, location, start date and time, employment type, remote-work needs, required applications, shared resources, phone needs, equipment, and any special data or regulatory requirements. Identify who approves each type of access and how exceptions are recorded.

2. Build role-based access instead of copying a coworker

Define standard access packages for common roles, then approve exceptions separately. Copying another employee’s permissions can reproduce old mistakes or grant access the new person does not need. Use groups where practical so access remains understandable and can change consistently.

3. Create unique accounts and secure authentication

  • Create a named account for each person; avoid shared sign-ins.
  • Assign only the required Microsoft 365 and application licenses.
  • Require MFA and register approved authentication methods.
  • Separate privileged administrator access from ordinary work.
  • Configure password, recovery, and sign-in policies according to the environment.
  • Record who owns service, shared, and emergency accounts.

4. Prepare and record the device

Record asset tag, serial number, model, warranty, assigned user, location, operating system, and expected return. Apply approved configuration, updates, encryption, endpoint protection, screen lock, remote support, business applications, and device-management policies. Test the camera, microphone, dock, monitors, printer access, VPN, and other role-specific functions.

5. Decide where business information belongs

Show the employee where individual work, team files, customer information, templates, and records belong. Clarify approved cloud storage, external sharing, removable media, personal-device use, and data-handling rules. Assign owners for Teams, SharePoint sites, shared mailboxes, vendor portals, and important workflows.

6. Validate on the first day

Confirm identity before issuing credentials or helping with MFA. Test sign-in, email, collaboration, required applications, files, printers, phones, remote connectivity, and support channels. The manager should verify that access matches the role. Record unresolved items and owners instead of allowing informal workarounds to become permanent.

7. Treat role changes like controlled onboarding and offboarding

Promotions, transfers, leaves, contractor changes, and location moves require review. Add newly approved access, remove permissions no longer needed, update groups and licensing, reassign equipment, transfer ownership, and document the effective date. Do not let old access accumulate indefinitely.

8. Coordinate offboarding around an exact time

HR and the manager should provide the effective date and time, whether the departure is planned or urgent, who receives business information, which devices must return, and any legal or investigative hold. IT should have a verified list of cloud, local, remote-access, vendor, phone, building, and specialized application accounts.

9. Block access and revoke active sessions

Microsoft’s current guidance begins by resetting the former employee’s password, signing out active sessions, and blocking access. Timing and behavior can vary across services, devices, tokens, and connected applications, so organizations should understand their environment and not assume one button instantly reaches every system.

  • Disable or block identity and application access at the authorized time.
  • Revoke sessions, tokens, VPN access, and remote-support access.
  • Remove administrative roles, groups, shared credentials, and vendor portals.
  • Change codes or secrets the departing person knew when individual revocation is not possible.
  • Secure or wipe organizational data from managed mobile devices where appropriate.

10. Preserve and transfer business information

Determine how mailbox, OneDrive, files, application records, contacts, documentation, and workflow ownership will be retained or transferred. Convert or forward mail only with authorized business rules and a defined end date. Preserve required information before removing licenses or deleting accounts.

11. Recover equipment and close physical access

Collect laptops, desktops, phones, tablets, tokens, keys, badges, storage media, chargers, docks, and other accessories. Record condition and missing items. Remove personal information through an approved process, preserve required business data, then securely reset, reassign, store, or dispose of equipment.

12. Complete a final verification

Use a second-person or manager review to confirm access removal, data ownership, equipment status, licenses, forwarding, shared credentials, vendor access, and open tasks. Keep a completion record with approvals, timestamps, exceptions, and follow-up dates.

Minimum fields for your checklist

  • Employee, manager, department, location, status, and effective date/time.
  • Approved role and exception approvers.
  • Accounts, groups, licenses, applications, vendors, and administrative roles.
  • Device identifiers, configuration, delivery, recovery, and condition.
  • MFA, remote access, phone, shared resources, and physical access.
  • Data, mailbox, file, site, workflow, and customer ownership.
  • Completion evidence, unresolved exceptions, reviewer, and follow-up date.

Odyssey provides business IT support, Microsoft 365 administration, computer setup, remote support, device management, and onboarding/offboarding coordination for Greater Houston organizations.

Official Microsoft guidance

Exact steps depend on licensing, applications, device management, retention, legal requirements, and identity architecture. Coordinate employment actions with authorized HR and legal decision-makers.

Make every employee technology change accountable

Prepare access and devices before the first day—and close every dependency when responsibilities change.

Book Consultation