What should an IT onboarding and offboarding checklist include?
An IT onboarding checklist should cover account creation, multifactor authentication, role-based access, a configured and managed device, and security training. An offboarding checklist should block sign-in and revoke sessions promptly, recover or wipe devices, preserve and hand over email and files, remove licenses and third-party access, and document each step. Both should be triggered by HR, not by memory.
Why this matters more than it looks
Onboarding and offboarding are where access control is won or lost. New hires given broad access on day one keep it for years. Departing employees whose accounts linger keep a path to your data.
Microsoft's shared responsibility guidance notes that, whatever the cloud service, you remain responsible for managing user accounts, including creating, managing and removing access. That responsibility cannot be handed to Microsoft.
Onboarding checklist
- HR ticket with start date, role, manager and location, submitted in advance
- Account created with a role-based group set, not copied from another user
- MFA registration completed on day one
- Managed, encrypted laptop enrolled in device management and patched
- Access to business applications approved by the data owner
- Security awareness training and acceptable-use and AI policies acknowledged
- Licenses assigned and recorded
Offboarding checklist
Microsoft's guidance for removing a former employee follows a clear sequence, which is a good backbone for your checklist:
- Block sign-in and revoke active sessions so the person cannot access Microsoft 365
- Preserve mailbox contents if someone is taking over the work or there is a legal need
- Wipe and block mobile devices that hold company data
- Forward email or convert the mailbox to a shared mailbox
- Give a manager access to OneDrive and Outlook data before deletion
- Remove licenses, then delete the account
- Remove access to non-Microsoft systems: ERP, CRM, lab systems, VPN, shared passwords and vendor portals
- Recover laptops and other equipment
Watch the retention clock
Microsoft notes that after you delete an employee's account, the content in their OneDrive and Outlook is retained for 30 days, during which you can restore the account. After that, plan for the data to be gone unless retention policies or backups preserve it. Give the manager access and hand over files before you delete.
For departures involving sensitive data or disputes, consider a legal hold through Microsoft Purview eDiscovery before any deletion.
Make it repeatable
Turn both checklists into standard ticket templates triggered by HR, with each step assigned and recorded. Review a sample of completed tickets periodically and run a regular access review to catch accounts, licenses and shared credentials that were missed.
Remember systems outside Microsoft 365. Departing employees often retain access to SaaS tools, vendor portals and shared passwords that never appear in your directory, which is why an up-to-date application inventory belongs alongside the checklist.
Common follow-up questions
How quickly should access be removed when someone leaves?
As close to the time of departure as possible, and immediately for involuntary terminations. Coordinate HR and IT so sign-in is blocked and sessions revoked at the moment of notice. Delays are a common route for data loss and unauthorized access.
Should we delete a departed employee's account right away?
Usually not. Block sign-in first, then preserve and hand over data, convert or forward the mailbox and remove licenses. Delete the account only once the data is safely transferred, because deleted accounts are recoverable for a limited period only.
Who should own the onboarding and offboarding process?
HR should own the trigger and timing; IT should own execution; data owners should approve access. Use a standard ticket template so every step is recorded, and review it periodically to catch accounts and access that were missed.
LAN Service Group runs employee onboarding and offboarding for small and mid-size businesses as part of its managed IT services, including Microsoft 365 account, device and access management.
Talk to LAN Service Group (888) 281-7243