Skip to main content
Dig IT Solutions logo

Guides & Checklists

IT onboarding checklist for new starters (what to have ready before day one)

An IT onboarding checklist for UK small businesses: information to collect, accounts and licences, device build, security, phones and access, with a timeline.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

A new starter should arrive to a configured laptop, a Microsoft 365 account with MFA enrolled, the right group memberships, a phone extension, access to the systems their role needs and a short security briefing. That takes a written request at least five working days before the start date, a standard device build, spare stock and a checklist someone owns.

A new starter's first day sets a tone. Arriving to a working laptop, a signed-in email account, the right shared folders and a phone that rings says the business is organised. Arriving to a borrowed machine, a login that does not work and a week of "I'll get IT to sort that" says the opposite, and it costs the business a week of productivity from someone it is paying. This checklist sets out what to have ready, who provides what and when, for businesses of up to 250 people. It reflects the process Dig IT runs through the new-starter and leaver forms in its client portal.

The principle: request early, build standard

Onboarding goes wrong for two reasons. The request reaches IT too late, or every starter is set up from scratch. Both are fixed by process: a written request submitted the day the offer is accepted, a standard device build and a standard access profile per role. With those in place, provisioning a new person is a routine task rather than a project. The IT onboarding and offboarding service exists to make it exactly that.

Timeline

WhenWhoWhat
Offer acceptedManager or HRSubmit the new-starter request with all the details below
2 to 3 weeks outITOrder device if none in stock, confirm licence availability, flag any specialist software
5 working days outITCreate account, assign licences and groups, build device, set up phone extension
1 to 2 days outIT and managerConfirm everything is ready, place device and peripherals at the desk or ship to home
Day oneManager, ITFirst sign-in, MFA enrolment, security briefing, check access to every system
End of week oneManagerConfirm nothing is missing, log any gaps as tickets

The information to collect

The request should capture everything in one go:

  • full name, preferred name and how it should appear in email
  • job title, department and manager
  • start date and working pattern
  • location: which office, hybrid or fully remote
  • an existing colleague whose access should be mirrored, if the role is similar
  • shared mailboxes, distribution lists, Teams and SharePoint sites required
  • line-of-business systems required, with the role or permission level in each
  • phone: desk extension, mobile, call queue membership
  • device: laptop or desktop, monitors, dock, headset, any accessibility needs
  • whether they need a company mobile or will use their own for MFA
  • anything unusual: specialist software, a second language keyboard, a printer at home

Accounts and licences

  • Microsoft 365 account created with the standard naming convention and the correct licence for the role (Business Premium is the sensible default because it includes Intune and Defender).
  • Groups and roles assigned from the profile for that job, not individually. Role-based groups mean a new accounts assistant gets exactly what the last one had.
  • Shared mailboxes and distribution lists added.
  • Teams and SharePoint membership set, with the starter placed in the right channels.
  • Line-of-business systems provisioned: accounts package, practice or job management, CRM, industry portals. Each with the minimum permission for the role.
  • Email signature set centrally (Dig IT uses Exclaimer) so it is right from the first message.
  • Password manager account created, if the business runs one, with the relevant shared vaults.
  • No admin rights on the device or in Microsoft 365. Admin access, where truly needed, is a separate account.

The device

  • A standard build applied from an image or through Intune autopilot: Windows 11 (the estate should have no Windows 10 left, given end of support), BitLocker enabled with keys escrowed, EDR installed, RMM agent enrolled, Microsoft 365 apps, browser, VPN client if needed, printer queues and any role-specific software.
  • Asset register updated with the device serial, user and date.
  • Peripherals at the desk: monitors, dock, keyboard, mouse, headset for Teams and VoIP.
  • Remote starters receive the device by tracked courier with a setup sheet, and a scheduled call with the helpdesk on day one.
  • Spare stock. Keep at least one spare of the standard laptop so a late hire or a failure does not stall the process.

Security on day one

  • Temporary password given in person or by the helpdesk on the phone, never emailed to a personal address, and changed at first sign-in.
  • MFA enrolled immediately using the Microsoft Authenticator app with number matching. The NCSC's guidance on multi-factor authentication explains why this is non-negotiable.
  • Windows Hello set up so day-to-day sign-in is by PIN or biometric.
  • Security briefing of ten to fifteen minutes: phishing and how to report it, never approving an unexpected MFA prompt, where company data lives and that personal cloud storage is not allowed, what to do if the device is lost. Then enrolment in the regular security awareness training.
  • Acceptable-use policy signed and filed with HR.

Phones and communication

  • Desk extension or softphone created on the cloud phone system (8x8 for most Dig IT clients), added to the right call queues and ring groups, with voicemail to email configured.
  • Mobile provisioned if required, enrolled in mobile device management if it will hold company email.
  • Teams calling or meeting settings confirmed if the role is client-facing.
  • Internal directory and website or email signature updated.

Access to the building and systems

  • Door entry fob or code issued, and recorded against the person.
  • Printer and scan-to-email working from their account.
  • Wi-Fi: the device joins the staff network automatically through certificate or managed configuration, not a shared password.
  • Any client or supplier portals that require a named user requested in advance, since these often take days.

First week

The manager checks on day one that every system on the request works, and again at the end of the week. Anything missing goes in as a helpdesk ticket rather than a corridor conversation, so the gap is fixed in the profile for the next person as well as for this one. An unusually long list of gaps means the role's access profile needs updating.

The checklist

For copying into your own process:

Before day one

  • New-starter request submitted with all details
  • Device in stock or ordered
  • Microsoft 365 account created, licence assigned
  • Role-based groups, shared mailboxes, Teams and SharePoint set
  • Line-of-business systems provisioned
  • Device built to standard, encrypted, EDR and RMM enrolled
  • Asset register updated
  • Phone extension and queues configured
  • Email signature set
  • Door entry issued
  • Desk equipment in place or device shipped

Day one

  • Temporary password handed over, changed at sign-in
  • MFA and Windows Hello enrolled
  • Security briefing delivered, acceptable-use policy signed
  • Every system on the request tested
  • Printer and Wi-Fi confirmed

Week one

  • Manager check for gaps
  • Gaps logged as tickets and the role profile updated
  • Enrolled in security awareness training

Offboarding is the same list in reverse

The day someone leaves, their account is disabled, active sessions and MFA methods revoked, the mailbox converted to shared or forwarded to the manager, OneDrive ownership transferred, the device recovered and wiped, the licence reclaimed, phone extension reassigned, door fob cancelled and every line-of-business and third-party system access removed. A leaver form triggers the whole sequence. Leavers with live access are among the most common findings in IT audits, and the fix is simply to treat offboarding with the same discipline as onboarding.

What to do next

If new starters in your business regularly spend their first days waiting for access, the process rather than the people is the problem. Dig IT's IT onboarding and offboarding service gives clients across Hertfordshire, west Essex and London a request form, a standard build and a same-week turnaround. Talk to an engineer about setting it up.

Frequently asked questions

How much notice does IT need for a new starter?
Five working days is a realistic minimum if a laptop is in stock and the role has a standard access profile. Allow two to three weeks if a device needs ordering, the role needs a new licence type, or specialist software must be installed and tested. The single most useful habit is submitting the request the day the offer is accepted, not the week before the start date.
What information does IT need to set up a new starter?
Full name and preferred name, job title and department, start date, manager, office or home location, the person whose access they should mirror (if any), which shared mailboxes, Teams and SharePoint sites they need, which line-of-business systems, whether they need a phone extension and mobile, and whether they will work remotely. A form that captures all of this, such as the new-starter form in Dig IT's client portal, avoids the back-and-forth.
Should new starters have admin rights on their laptop?
No. Standard users cannot install software or disable security tools, which blocks most malware from doing damage and is a requirement of Cyber Essentials. Software installs go through the helpdesk or a self-service portal. The few people who genuinely need admin rights get a separate admin account used only for that purpose.
How should a new starter get their first password?
Never by email to a personal address in plain text. The usual approach is a temporary password given by the manager or helpdesk on day one, changed at first sign-in, with MFA enrolled at the same time using the Microsoft Authenticator app. Where Windows Hello for Business or passwordless sign-in is available, enrol it during setup so the password is rarely needed afterwards.
What security briefing should a new starter receive?
Ten to fifteen minutes on day one covering: MFA and never approving a prompt they did not trigger, how to spot and report phishing, where company files live and that personal cloud storage is not permitted, what to do if a device is lost, and the acceptable-use policy they will sign. Follow with the same security awareness training everyone else receives.
Why does offboarding matter as much as onboarding?
Because a leaver who keeps access is one of the most common findings in IT audits and one of the easiest routes into a business. The offboarding checklist disables the account, revokes sessions and MFA, forwards or converts the mailbox, recovers the device and licences, and removes access to every third-party system, on the day they leave. It is the onboarding list in reverse and deserves the same discipline.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us