Guides & Checklists
IT onboarding checklist for new starters (what to have ready before day one)
An IT onboarding checklist for UK small businesses: information to collect, accounts and licences, device build, security, phones and access, with a timeline.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
A new starter should arrive to a configured laptop, a Microsoft 365 account with MFA enrolled, the right group memberships, a phone extension, access to the systems their role needs and a short security briefing. That takes a written request at least five working days before the start date, a standard device build, spare stock and a checklist someone owns.
A new starter's first day sets a tone. Arriving to a working laptop, a signed-in email account, the right shared folders and a phone that rings says the business is organised. Arriving to a borrowed machine, a login that does not work and a week of "I'll get IT to sort that" says the opposite, and it costs the business a week of productivity from someone it is paying. This checklist sets out what to have ready, who provides what and when, for businesses of up to 250 people. It reflects the process Dig IT runs through the new-starter and leaver forms in its client portal.
The principle: request early, build standard
Onboarding goes wrong for two reasons. The request reaches IT too late, or every starter is set up from scratch. Both are fixed by process: a written request submitted the day the offer is accepted, a standard device build and a standard access profile per role. With those in place, provisioning a new person is a routine task rather than a project. The IT onboarding and offboarding service exists to make it exactly that.
Timeline
| When | Who | What |
|---|---|---|
| Offer accepted | Manager or HR | Submit the new-starter request with all the details below |
| 2 to 3 weeks out | IT | Order device if none in stock, confirm licence availability, flag any specialist software |
| 5 working days out | IT | Create account, assign licences and groups, build device, set up phone extension |
| 1 to 2 days out | IT and manager | Confirm everything is ready, place device and peripherals at the desk or ship to home |
| Day one | Manager, IT | First sign-in, MFA enrolment, security briefing, check access to every system |
| End of week one | Manager | Confirm nothing is missing, log any gaps as tickets |
The information to collect
The request should capture everything in one go:
- full name, preferred name and how it should appear in email
- job title, department and manager
- start date and working pattern
- location: which office, hybrid or fully remote
- an existing colleague whose access should be mirrored, if the role is similar
- shared mailboxes, distribution lists, Teams and SharePoint sites required
- line-of-business systems required, with the role or permission level in each
- phone: desk extension, mobile, call queue membership
- device: laptop or desktop, monitors, dock, headset, any accessibility needs
- whether they need a company mobile or will use their own for MFA
- anything unusual: specialist software, a second language keyboard, a printer at home
Accounts and licences
- Microsoft 365 account created with the standard naming convention and the correct licence for the role (Business Premium is the sensible default because it includes Intune and Defender).
- Groups and roles assigned from the profile for that job, not individually. Role-based groups mean a new accounts assistant gets exactly what the last one had.
- Shared mailboxes and distribution lists added.
- Teams and SharePoint membership set, with the starter placed in the right channels.
- Line-of-business systems provisioned: accounts package, practice or job management, CRM, industry portals. Each with the minimum permission for the role.
- Email signature set centrally (Dig IT uses Exclaimer) so it is right from the first message.
- Password manager account created, if the business runs one, with the relevant shared vaults.
- No admin rights on the device or in Microsoft 365. Admin access, where truly needed, is a separate account.
The device
- A standard build applied from an image or through Intune autopilot: Windows 11 (the estate should have no Windows 10 left, given end of support), BitLocker enabled with keys escrowed, EDR installed, RMM agent enrolled, Microsoft 365 apps, browser, VPN client if needed, printer queues and any role-specific software.
- Asset register updated with the device serial, user and date.
- Peripherals at the desk: monitors, dock, keyboard, mouse, headset for Teams and VoIP.
- Remote starters receive the device by tracked courier with a setup sheet, and a scheduled call with the helpdesk on day one.
- Spare stock. Keep at least one spare of the standard laptop so a late hire or a failure does not stall the process.
Security on day one
- Temporary password given in person or by the helpdesk on the phone, never emailed to a personal address, and changed at first sign-in.
- MFA enrolled immediately using the Microsoft Authenticator app with number matching. The NCSC's guidance on multi-factor authentication explains why this is non-negotiable.
- Windows Hello set up so day-to-day sign-in is by PIN or biometric.
- Security briefing of ten to fifteen minutes: phishing and how to report it, never approving an unexpected MFA prompt, where company data lives and that personal cloud storage is not allowed, what to do if the device is lost. Then enrolment in the regular security awareness training.
- Acceptable-use policy signed and filed with HR.
Phones and communication
- Desk extension or softphone created on the cloud phone system (8x8 for most Dig IT clients), added to the right call queues and ring groups, with voicemail to email configured.
- Mobile provisioned if required, enrolled in mobile device management if it will hold company email.
- Teams calling or meeting settings confirmed if the role is client-facing.
- Internal directory and website or email signature updated.
Access to the building and systems
- Door entry fob or code issued, and recorded against the person.
- Printer and scan-to-email working from their account.
- Wi-Fi: the device joins the staff network automatically through certificate or managed configuration, not a shared password.
- Any client or supplier portals that require a named user requested in advance, since these often take days.
First week
The manager checks on day one that every system on the request works, and again at the end of the week. Anything missing goes in as a helpdesk ticket rather than a corridor conversation, so the gap is fixed in the profile for the next person as well as for this one. An unusually long list of gaps means the role's access profile needs updating.
The checklist
For copying into your own process:
Before day one
- New-starter request submitted with all details
- Device in stock or ordered
- Microsoft 365 account created, licence assigned
- Role-based groups, shared mailboxes, Teams and SharePoint set
- Line-of-business systems provisioned
- Device built to standard, encrypted, EDR and RMM enrolled
- Asset register updated
- Phone extension and queues configured
- Email signature set
- Door entry issued
- Desk equipment in place or device shipped
Day one
- Temporary password handed over, changed at sign-in
- MFA and Windows Hello enrolled
- Security briefing delivered, acceptable-use policy signed
- Every system on the request tested
- Printer and Wi-Fi confirmed
Week one
- Manager check for gaps
- Gaps logged as tickets and the role profile updated
- Enrolled in security awareness training
Offboarding is the same list in reverse
The day someone leaves, their account is disabled, active sessions and MFA methods revoked, the mailbox converted to shared or forwarded to the manager, OneDrive ownership transferred, the device recovered and wiped, the licence reclaimed, phone extension reassigned, door fob cancelled and every line-of-business and third-party system access removed. A leaver form triggers the whole sequence. Leavers with live access are among the most common findings in IT audits, and the fix is simply to treat offboarding with the same discipline as onboarding.
What to do next
If new starters in your business regularly spend their first days waiting for access, the process rather than the people is the problem. Dig IT's IT onboarding and offboarding service gives clients across Hertfordshire, west Essex and London a request form, a standard build and a same-week turnaround. Talk to an engineer about setting it up.

