Managed IT

Employee Onboarding and Offboarding IT Checklist

Give new hires the right access on day one and remove access completely when employees leave.

Reviewed October 10, 2026 3 minute read Reviewed by Meta IT Pro
Part of the Managed IT Learning Center

Every hire, role change, and departure changes who can access business systems. A repeatable checklist makes onboarding faster and offboarding complete, so access matches each person's current role.

Key takeaways

What to know before you act

  • Onboarding and offboarding are identity-security processes as much as HR processes.
  • Role-based templates make access consistent and easier to remove later.
  • Offboarding should happen on the last day—or immediately for involuntary departures.

Why it matters

What business leaders should understand

Accounts left active after an employee leaves are a common security gap, and slow onboarding wastes the first days of a new hire's time. Both problems are solved by process rather than tools.

The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.

Onboarding checklist

Good onboarding gives a new employee what they need on day one—and nothing more. Ask HR or the hiring manager for the start date, role, and location at least a few days in advance.

  • Create the account from a role template with the correct groups and licenses.
  • Enroll MFA and the password manager during the first session.
  • Prepare and enroll a managed, encrypted device.
  • Grant application and shared-folder access based on the role.
  • Provide security awareness training and the acceptable-use policy.
  • Explain how to request IT help and report suspicious messages.

Offboarding checklist

Complete offboarding protects business data and accounts. Coordinate timing with HR, especially for involuntary departures where access should be removed before or during the notification meeting.

  • Disable the account and revoke active sessions and MFA methods.
  • Remove access to SaaS applications, VPN, and shared accounts; change shared passwords.
  • Convert or delegate the mailbox and transfer file ownership before deletion.
  • Recover laptops, phones, keys, and badges; wipe or reassign devices.
  • Remove the user from distribution lists, phone systems, and building access.
  • Document completion and keep records according to the retention policy.

Role changes

Internal transfers are easy to overlook. When someone changes roles, add new access and remove the access they no longer need, so permissions do not accumulate over years.

Practical action plan

Steps your business can take

01

Create role-based access templates for common positions.

02

Have HR notify IT before start dates and on or before last days.

03

Disable accounts, revoke sessions, and recover devices on the final day.

04

Transfer mailbox and file ownership before deleting accounts.

Recommended next steps

Continue from this article.

These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.

Warning signs

Do not ignore these indicators

  • Former employees' accounts are still active
  • New hires wait days for email or application access
  • Shared passwords are not changed after someone leaves

How Meta IT Pro can help

Related services and practical next steps

Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.

Authoritative references

Sources and further reading

These primary sources support the guidance in this article and provide additional technical or consumer information.

Need help with your IT solution?

Get practical guidance from a local IT and cybersecurity team.

Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.