Every hire, role change, and departure changes who can access business systems. A repeatable checklist makes onboarding faster and offboarding complete, so access matches each person's current role.
Key takeaways
What to know before you act
- Onboarding and offboarding are identity-security processes as much as HR processes.
- Role-based templates make access consistent and easier to remove later.
- Offboarding should happen on the last day—or immediately for involuntary departures.
Why it matters
What business leaders should understand
Accounts left active after an employee leaves are a common security gap, and slow onboarding wastes the first days of a new hire's time. Both problems are solved by process rather than tools.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with managed it services and it consulting and vcio.
Related reading: IT documentation: what every business should have and SharePoint vs. OneDrive vs. Teams.
Onboarding checklist
Good onboarding gives a new employee what they need on day one—and nothing more. Ask HR or the hiring manager for the start date, role, and location at least a few days in advance.
- Create the account from a role template with the correct groups and licenses.
- Enroll MFA and the password manager during the first session.
- Prepare and enroll a managed, encrypted device.
- Grant application and shared-folder access based on the role.
- Provide security awareness training and the acceptable-use policy.
- Explain how to request IT help and report suspicious messages.
Offboarding checklist
Complete offboarding protects business data and accounts. Coordinate timing with HR, especially for involuntary departures where access should be removed before or during the notification meeting.
- Disable the account and revoke active sessions and MFA methods.
- Remove access to SaaS applications, VPN, and shared accounts; change shared passwords.
- Convert or delegate the mailbox and transfer file ownership before deletion.
- Recover laptops, phones, keys, and badges; wipe or reassign devices.
- Remove the user from distribution lists, phone systems, and building access.
- Document completion and keep records according to the retention policy.
Role changes
Internal transfers are easy to overlook. When someone changes roles, add new access and remove the access they no longer need, so permissions do not accumulate over years.
Practical action plan
Steps your business can take
Create role-based access templates for common positions.
Have HR notify IT before start dates and on or before last days.
Disable accounts, revoke sessions, and recover devices on the final day.
Transfer mailbox and file ownership before deleting accounts.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
IT documentation: what every business should have
Keep role templates and procedures current.
Explore nextRelated guide
SharePoint vs. OneDrive vs. Teams
Move shared files out of personal storage before offboarding.
Explore nextRelated guide
The hidden dangers of security shortcuts
Avoid shared accounts and lingering access.
Explore nextService
Microsoft 365 management & security
Automate account creation, licensing, and removal.
Explore nextWarning signs
Do not ignore these indicators
- Former employees' accounts are still active
- New hires wait days for email or application access
- Shared passwords are not changed after someone leaves
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
National Institute of Standards and Technology
The NIST Cybersecurity Framework (CSF) 2.0
A flexible framework for governing, identifying, protecting, detecting, responding to, and recovering from cybersecurity risk.
Cybersecurity and Infrastructure Security Agency
Zero Trust Maturity Model
A roadmap for maturing identity, device, network, application, and data protections over time.
Federal Trade Commission
Protecting Personal Information: A Guide for Business
Five principles for taking stock of, reducing, locking down, disposing of, and planning around personal information.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
