Use a phase-based checklist (pre-boarding, day one, first week, then 30, 60 and 90 days) and enforce MFA, SSO and device enrolment before the new starter's first login. Build in least-privilege access from the start, assign a named owner to every task across IT, HR and the hiring manager, and keep a reusable template so each new hire follows the same reliable path.
TL;DR:
- Fully automate account creation, device imaging, and MFA enforcement before day one to prevent delays and security gaps during onboarding.
- Conduct scheduled follow-ups at 30, 60, and 90 days to review permissions, license use, and onboarding processes for continuous improvement.
- Maintain an accurate inventory of accounts and assets, validate activity regularly, and disable or de-provision dormant accounts within 45 days of inactivity.
- Assign clear ownership for each onboarding step, with deadlines aligning device setup five days before start, accounts three days prior, and license confirmation on day one.
- Leverage managed IT support services to handle procurement, imaging, and ongoing device and account management, reducing manual workload and errors.
Table of Contents
- Pre-boarding checklist: what to finish before day one
- First day checklist: what IT needs to verify and deliver
- First week and 30 to 90-day checkpoints
- Security and compliance checklist for new starters
- Tooling and automation that reduce onboarding workload
- Who owns each onboarding task, and by when
- Building a reusable onboarding checklist template
- What actually moves the needle in onboarding
- How CTA Systems can take onboarding off your plate
- FAQ
- Sources
Pre-boarding checklist: what to finish before day one
Think of pre-boarding like preparing soil before you plant anything: skip this stage and nothing that follows grows properly. The work happens two to four weeks before the start date, and it's almost entirely IT's responsibility, with HR feeding in the details that make it possible.
- Confirm the new hire's role, department and start date with HR, then order and image the device with the correct build for that role.
- Record the device's asset tag, serial number and assigned user in your asset register before it leaves the storeroom.
- Create the account in your identity provider (IdP) and assign it to the correct security and distribution groups based on role.
- Provision software licences and configure single sign-on (SSO) so the account can reach every approved application from day one.
- Enrol the device into your mobile device management (MDM) and endpoint detection and response (EDR) platforms, apply your baseline hardening policy, and schedule its first patch cycle.
- Prepare VPN or zero-trust network access (ZTNA) credentials, following NCSC guidance on ZTNA, which recommends having an authoritative IdP, consistent SSO and device posture checks in place before granting network access.
A few things tend to get missed at this stage, so it's worth building them into your checklist explicitly:
- Temporary access should expire automatically rather than relying on someone remembering to remove it.
- Shared drive and mailbox permissions need setting up against the role, not copied wholesale from a colleague.
- HR should confirm the legal start date in writing before any account goes live, since early activation creates an audit gap.
Assign a clear owner and deadline to every row: IT handles procurement and configuration, HR supplies the role and date, and the hiring manager signs off on access scope. When that handoff is explicit, nothing falls through the gap between departments.
First day checklist: what IT needs to verify and deliver
Day one is where all that preparation either pays off or falls apart in front of the new starter. The goal is simple: they should be working within the hour, not waiting on IT.
- Hand over the device and run a final check that imaging, asset tagging and network connectivity are all correct.
- Confirm SSO logs them into core applications first time, and reset credentials on the spot if anything doesn't match.
- Walk them through MFA or passkey setup and verify it actually works before they're left alone with the device.
- Introduce the password manager and explain how secrets and shared credentials are handled, since this is the habit that prevents sticky notes on monitors later.
- Run a short security briefing covering phishing awareness, acceptable use and who to contact if something looks wrong, and get a signed or digital acknowledgement on file.
- Ask the hiring manager to confirm that role-specific tools (CRM, finance software, design tools) are visible and usable, not just that the laptop switches on.
None of this needs to be elaborate. A fifteen-minute checklist walkthrough, done consistently, prevents the slow trickle of "I can't access X" tickets that otherwise arrive throughout the first week.
First week and 30 to 90-day checkpoints

The first week is about smoothing out the practical gaps that pre-boarding couldn't fully predict: printing, VoIP extensions, shared drive access and the small tools a team uses day to day that never made it onto the original build sheet. These checks catch the friction that slows a new starter down without anyone noticing.
From there, the 30, 60 and 90-day milestones give you a structure to tighten access and confirm nothing was left over-permissioned:
- At 30 days, confirm role-based training is complete and reconcile software licences against what's actually in use, since this is often the first point where unused seats become visible.
- At 60 days, review and refine access permissions, removing any temporary or broad grants that were issued to get the person working quickly in week one.
- At 90 days, run a formal access review alongside a short retrospective on the onboarding process itself, asking what slowed the person down and fixing it before the next hire arrives.
Where you can, tie these checkpoints to automated reminders in your ticketing or HR system rather than relying on memory. A calendar trigger at day 30 that opens a licence reconciliation ticket costs nothing to set up and quietly prevents the subscription creep that eats into IT budgets over a year.
Security and compliance checklist for new starters
Onboarding is also where most identity and access risk gets introduced, so it deserves the same rigour as any other security control, not an afterthought bolted onto HR paperwork.
- Maintain an authoritative inventory of every account, human, administrator and service, and validate it on a recurring schedule, which CIS Control 5 sets at a minimum of quarterly.
- Enforce SSO and favour phishing-resistant MFA methods such as FIDO2 passkeys over SMS codes wherever your applications support it.
- Apply a secure baseline configuration to every corporate device, with automated patching and EDR running before the device reaches the new starter's desk.
- Use MDM to check device posture continuously, and apply the same enforcement to BYOD devices as you do to company-owned hardware.
- Before rolling new access controls out widely, test them, since NCSC device security guidance recommends penetration testing technical controls prior to full deployment.
- Disable dormant accounts after a suitable policy-defined inactivity period and build de-provisioning into your offboarding workflow so departures don't leave stray access behind.
- Log identity and device activity consistently, so an incident investigation has something to work from rather than a gap in the record.
CIS Control 5 calls for disabling or deleting dormant accounts after 45 days of inactivity where your systems support it, a threshold worth building into your deprovisioning rules rather than leaving to manual review.
Pro Tip: Map your onboarding security controls directly against the five themes in the Cyber Essentials IT requirements: firewalls, secure configuration, patching, access control and malware protection. It turns certification from an annual scramble into something you're already doing.
Tooling and automation that reduce onboarding workload
Most onboarding delays come down to the same root cause: too many manual handoffs between systems that should already be talking to each other. Fixing that is less about buying new software and more about wiring up what you already have.
- Make your IdP and SSO platform the single source of truth for authentication and policy, rather than letting individual applications manage their own logins.
- Automate provisioning so that a new starter record in your HR system triggers account creation in your IdP automatically, removing the manual re-typing that causes most data mismatches.
- Set MDM and EDR to enrol new devices automatically and apply your baseline policy the moment a device checks in, rather than relying on someone remembering to run the enrolment manually.
- Use your remote monitoring and management (RMM) tooling alongside your asset inventory to surface unused software licences and devices that have gone quiet.
- If you're planning a move towards zero-trust network access, finish your identity and device groundwork first. NCSC's ZTNA guidance treats this prerequisite work as the foundation, not an optional extra.
Pro Tip: Start with the HR-to-IdP link before touching anything else. It's the single automation that removes the most manual effort, and it makes every later improvement easier to build on. For teams exploring broader automation options, AI-driven onboarding tools are worth a look; however, the groundwork above still has to come first.
Who owns each onboarding task, and by when
Clear ownership is what turns a checklist from a nice document into something that actually gets followed. A simple RACI-style split works well for most IT teams:
- IT owns device procurement, imaging, account creation, MDM and EDR enrolment, and technical access reviews.
- HR owns the new starter's confirmed details, start date, contract type and any role changes that affect access scope.
- The hiring manager owns confirming that role-specific applications and permissions are correct once the account is live.
A workable service level might be: devices imaged five working days before the start date, accounts created and tested three working days before, and licences confirmed by the morning of day one. Build an escalation path for anything blocked, so a missing licence becomes a ticket with an owner rather than a problem that surfaces awkwardly at 9am on someone's first day. Any temporary access granted outside the normal process should be logged and ticketed, so it's never left forgotten in a corner of the system.
Building a reusable onboarding checklist template
A template only works if it's structured consistently and easy to reuse for every role.
- Import this structure directly into your ticketing system or HR platform as a recurring workflow template rather than a static document.
- Tailor the rows for remote workers by adding shipping and remote setup verification steps in place of in-person handover.
- For contractors and privileged users, add shorter access expiry dates and an extra review checkpoint.
- Store the template under version control in your documentation system so changes are tracked and the latest version is always obvious.
What actually moves the needle in onboarding
The biggest wins come early and cheaply: getting MFA, SSO and MDM enrolment right before day one prevents more friction than almost any later process improvement. Automating the handoff from HR into your identity provider removes the largest single source of manual error, and it pays for itself quickly.
Two KPIs worth tracking from the start are time to first successful login and licence waste at the 90-day mark, since both expose problems that are otherwise invisible until they've cost real money. A client we worked with once found that fixing one broken SSO integration cut their first-day support tickets by more than half.
— Will
How CTA Systems can take onboarding off your plate
Running a full phase-based checklist well takes consistent attention, and that's exactly the kind of recurring, detail-heavy work that managed IT support is built for. CTA Systems handles procurement, imaging, identity lifecycle management and ongoing device monitoring as part of its day-to-day service, so onboarding stops depending on whoever happens to be free that week.

- Managed IT support can cover device setup, account provisioning and the technical side of every new starter.
- Remote monitoring and management services keep devices patched and healthy long after onboarding is finished.
- Microsoft 365 management services can handle licensing and SSO configuration.
- Care plans offer predictable monthly costs for ongoing support, providing financial predictability rather than unexpected bills when something goes wrong.
If you would rather hand the checklist to a team that already runs it daily, explore CTA Systems' managed IT support or compare the Care Plans to find the right level of ongoing cover.
FAQ
What are the 5 C's of effective onboarding?
Definitions vary across HR literature, but a common version covers compliance, clarification, culture, connection and checkback, essentially moving from rules and role clarity through to team integration and follow-up. For IT managers, the practical equivalent is making sure compliance and clarification happen through device and access setup before culture and connection can follow.
What is the 30-60-90 onboarding rule?
It's a staged framework for checking progress at 30, 60 and 90 days after a new starter joins, rather than treating onboarding as finished after day one. In an IT context, that typically means confirming training and licence use at 30 days, refining access permissions at 60 days, and running a formal access review at 90 days.
What should be on an IT onboarding checklist?
A solid checklist covers device procurement and imaging, account and licence provisioning, MFA and SSO enforcement, MDM and EDR enrolment, a day-one security briefing, and scheduled follow-up reviews at 30, 60 and 90 days. It should also name an owner and deadline for every task so nothing depends on memory.
What are the 5 stages of the onboarding process?
Most frameworks describe pre-boarding, orientation, training, integration and ongoing development as the five stages a new hire moves through. For IT purposes, these map closely onto pre-boarding, day one, first week, and the 30 and 60-90 day checkpoints covered earlier in this guide.
