Employee Onboarding IT Checklist: Day-One Setup Guide
August 7, 2026 · Elecrics Team
Why day-one IT setup matters more than you think
A new hire's first day sets the tone. When their laptop is ready, their email works, and they can log into the tools they need, they feel welcome and get productive fast. When they spend the morning waiting on a password reset or borrowing a coworker's login, you've lost momentum—and quietly created a security risk.
For a 5–50 person business without dedicated IT staff, onboarding often falls to the office manager or owner. The good news: with a repeatable checklist, you can get it right every time without being a tech expert.
Here's a practical, plain-English guide you can copy and use.
Before the start date: prepare in advance
The biggest mistake is starting setup the morning someone walks in. Order and configure everything a few days early.
Order or assign a device
- Decide whether the new hire gets a new device or a cleaned-up existing one. Never hand over a former employee's laptop without fully wiping it first.
- If ordering new, allow shipping time—popular business laptops can take a week or more.
- Physically label the device (an asset tag or simple sticker with an ID number) so you can track who has what.
Gather the essentials
Make a short list of exactly what this role needs. A bookkeeper needs different access than a warehouse lead. Ask the hiring manager:
- What software and files will they use daily?
- Do they need a phone extension or a company cell?
- Will they work in the office, remotely, or both?
Accounts: create identities the secure way
An "account" is a login that identifies the employee to your systems. The cleanest approach is to create one central account that connects to everything, rather than a dozen separate logins scattered across apps.
The core account checklist
- Create a company email account using your business domain (name@yourcompany.com), not a personal Gmail.
- Turn on multi-factor authentication (MFA) from the start. MFA means logging in requires a password plus a second step, like a code from a phone app. It's the single most effective way to stop account break-ins.
- Set a strong, unique starting password and require the employee to change it at first login.
- Use naming standards so accounts are consistent (for example, firstname.lastname). This makes cleanup easier later.
Use groups, not one-off permissions
Instead of granting access app by app, assign the person to a role-based group—for example, "Sales" or "Accounting." Everyone in that group gets the same standard access automatically. This saves time and prevents someone from accidentally getting the keys to systems they shouldn't touch.
This is exactly the kind of structure a managed IT provider sets up once so every future hire is a few clicks instead of a scavenger hunt.
Devices: set up laptops and phones properly
Handing someone a laptop straight out of the box is asking for trouble. A business device needs a few protections in place first.
Device setup checklist
- Install security software (antivirus/endpoint protection) that your business manages centrally.
- Enable disk encryption (BitLocker on Windows, FileVault on Mac). Encryption scrambles the data so a lost or stolen laptop can't be read by a stranger.
- Turn on automatic updates for the operating system and key apps.
- Set up automatic backup for any files stored on the device.
- Enroll the device in management so you can push updates and, if needed, remotely wipe it if it's lost. This is especially important for South Shore businesses with staff commuting through Boston or working from home.
- Install the standard software set: email, browser, video calls, and role-specific tools.
- Configure the printer connection if they'll print in the office.
Don't forget mobile
If the employee will read work email on a personal phone, require a screen lock and, ideally, enroll the phone in basic mobile management. That way if they leave or lose the phone, you can remove company data without touching their personal photos.
Access: give the right keys—and only those
The guiding principle here is least privilege: give each person the minimum access they need to do their job, nothing more. Over-granting access is how a single compromised account turns into a company-wide problem.
Access checklist
- Add the employee to the correct shared drives and folders for their role.
- Grant access to specific apps (accounting, CRM, scheduling, etc.) through their central account where possible.
- Set up their email signature and any shared mailboxes or distribution lists (like sales@ or info@).
- Add them to relevant communication channels (Teams, Slack, group chats).
- Provide a password manager account so they store logins securely instead of on a sticky note.
- Document what you granted. You'll need this list on their last day.
Avoid the admin trap
Most employees should not have administrator rights on their own computer. Admin rights let someone install any software—including, accidentally, malware. Keep admin access to the few people who genuinely need it.
Day one: the human side
Technology setup isn't finished until the person can actually use it. Build 30 minutes into their first day for a quick orientation:
- Walk them through logging in and setting up MFA.
- Show them where files live and how to save work so it's backed up.
- Explain your basic security rules: don't reuse passwords, be suspicious of unexpected email links, and report anything odd.
- Tell them who to contact when something breaks—and how.
A five-minute security conversation on day one prevents a lot of trouble down the road.
A note on offboarding
Good onboarding makes offboarding easy. Because you documented every account, group, and device you assigned, you can shut off access quickly when someone leaves. Disable the account the same day, collect the device, and reclaim software licenses so you're not paying for empty seats.
Your reusable day-one checklist
- [ ] Device ordered/wiped, labeled, and configured
- [ ] Security software, encryption, and backups enabled
- [ ] Device enrolled in management
- [ ] Company email created with MFA turned on
- [ ] Assigned to correct role-based access group
- [ ] Shared drives, apps, and channels granted
- [ ] Password manager set up
- [ ] Admin rights limited appropriately
- [ ] Access list documented for future offboarding
- [ ] Day-one orientation and security walkthrough completed
When it's worth getting help
If onboarding eats a full day of your office manager's time, or you're not confident everything's locked down, this is one of the most valuable things to standardize. A managed IT provider builds these steps into a repeatable process so each new hire takes minutes, not hours—and nothing important gets skipped.
If you'd like a second set of eyes on how your business handles new-hire setup, Elecrics offers a free 20-minute IT Fit Call. We work with small and mid-sized businesses across Braintree, Quincy, Weymouth, and the greater South Shore. You can book one at https://elecrics.com/book—no pressure, just practical answers.