Before you order anything
Get the start date, shipping location, manager, role, and any accessibility or equipment requirements. Have the manager approve an application and access list. Avoid copying another employee’s permissions wholesale; they may have exceptions that the new hire does not need.
- Confirm the delivery address through an approved channel.
- Agree on the device specification and purchasing owner.
- List essential applications and the owner who approves each one.
- Confirm whether the person is an employee or contractor and whether access has an end date.
Prepare and record the laptop
Use your standard setup rather than improvising on arrival day. Record the asset assignment and check that the device can be recovered or reassigned through your company process. Decide how the employee will receive sign-in instructions without exposing credentials in a general chat channel.
- Record the device serial number and assigned employee.
- Apply the supported operating-system updates.
- Verify disk encryption, screen lock, and device-management enrollment where used.
- Install approved applications and test camera, microphone, and required accessories.
Create accounts with the right permissions
Create a work identity and assign the required licenses. Add the person to approved groups and role-specific applications. Give access to the actual work they need without automatically granting administration rights. Set up multifactor authentication using the platform’s supported process; confirm there is an approved recovery route if a factor is lost.
- Prepare email, calendar, chat, and shared files.
- Assign the manager-approved permissions for each application.
- Check that production, finance, and customer-data access have explicit approval.
- Remove temporary setup privileges when preparation is complete.
Make day one a verification, not an installation session
Have the employee sign in and open each critical tool. A created account is not the same as a working account: a missing group membership or license can still block a task. Give the employee the support channel and explain how to report a lost device or suspicious sign-in prompt.
- Confirm the employee can sign in with their own credentials.
- Test one real workflow, such as joining a meeting or opening a shared project.
- Record unresolved items and who owns the follow-up.
- Ask the manager to confirm the setup supports the employee’s actual work.
Close the loop after the first week
Review missing tools and remove access granted only for setup. Update the role template based on what was needed, without turning every one-off request into a default. Keep the equipment and application record useful for the eventual offboarding handoff. If repeated delays come from unclear approvals, fix the request process before buying another onboarding tool.
Your working checklist
Use this as a starting point. Assign an owner and a due date to each item. Checkmarks stay on this device only; don’t enter employee information here.
0 of 16 completed
Common questions
Who owns IT onboarding: HR or IT?
People Ops or the hiring manager supplies the start date and role requirements. An IT owner prepares the device and accounts, while application owners approve sensitive access. One coordinator should track the complete handoff.
How early should we start IT onboarding?
Start once the hire and start date are confirmed. Work backward from device availability, shipping, license procurement, and setup time. Confirm your actual lead times instead of promising a fixed number of days.
Platform references
For product-specific actions, check the current instructions for your edition and account type.