IT Operations

Employee Onboarding and Offboarding IT Checklist

MSP Worx · 4 min read · Updated Oct 10, 2026

Onboarding gets attention because it is visible — a new hire without a working laptop is an obvious failure. Offboarding gets far less, because nothing appears to go wrong when it is done badly.

That asymmetry is the problem. Incomplete offboarding is one of the most common findings in security audits and one of the most exploitable gaps in a small business, and it produces no symptom until it does.

Onboarding — before the first day

Everything below should be finished before the person arrives. A new hire spending their first morning waiting for an account is an avoidable and memorable start.

  • Device provisioned, encrypted, patched, and enrolled in device management
  • Account created with a role-appropriate permission set, not a copy of an existing user's access
  • MFA registered, or a defined process for first-login enrolment
  • Email, calendar and file access configured
  • Licences assigned and recorded against the person
  • Line-of-business application accounts created
  • Group and distribution list membership set
  • Phone or extension configured if required
  • Physical access — badge, keys, alarm code — arranged with whoever owns it

The permission point deserves emphasis. Copying an existing user's access is fast and it propagates whatever excess that person accumulated. Over a few years this is how everyone ends up with access to everything, which is precisely what an attacker exploits after a single compromise.

Onboarding — the first week

  • Security awareness training delivered and recorded, before broad access if practical
  • Acceptable use and data handling policies acknowledged in writing
  • Password manager provisioned, if you use one, which you should
  • Backup and file storage explained — where work belongs, so it is protected
  • Support process explained: how to raise a ticket, what counts as urgent
  • Documented confirmation that everything above is complete

That last item is what turns a process into evidence. Under HIPAA and the FTC Safeguards Rule, training should be documented, not merely delivered — and an auditor will ask for records rather than assurances.

Offboarding — the same day

Access removal should be simultaneous with the person's departure, and for involuntary departures it should be immediate — ideally during the conversation.

  • Disable rather than delete the primary account. Deleting immediately can destroy data you still need and break shared resources. Disable, then remove after a defined retention period.
  • Terminate all active sessions. Disabling an account does not always end sessions already authenticated — this is the step most commonly missed, and it can leave someone with working access for hours or days.
  • Revoke MFA registrations and any app passwords.
  • Remove from all groups and distribution lists.
  • Redirect or delegate email, and set expectations with whoever inherits it.
  • Transfer file ownership, particularly anything in personal cloud storage.
  • Reclaim and reassign licences.
  • Revoke access to every line-of-business application, including anything managed outside IT.
  • Wipe or reclaim devices, including any personal device holding company data.
  • Revoke VPN and remote access certificates.
  • Remove physical access.
Offboarding stepWhy it matters
Disable, don't delete, the accountKeeps data and shared resources intact
Terminate active sessionsDisabling alone may leave existing sessions working
Revoke MFA and app passwordsRemoves secondary sign-in routes
Transfer files and redirect emailKeeps work accessible to the business
Reclaim licences and devicesStops cost and removes cached data
Revoke VPN, app and physical accessCovers access outside the main directory

The offboarding steps almost everyone misses

  1. Shared and service accounts. If the departing person knew a shared administrative password, that password must change. This is the single most-skipped step.
  2. External and vendor accounts. Software portals, domain registrars, cloud consoles, payment platforms, social media, the phone system administration panel. These sit outside the main directory and are rarely on anyone's checklist.
  3. Accounts registered in their name. Services signed up for with their work email, where the account itself belongs to them rather than the business. Discovering this after departure is painful.
  4. API keys and tokens they generated. These survive account disabling and are invisible unless specifically audited.
  5. Personal devices with cached company data — phones with mail profiles, home machines with synced files.
  6. Documentation only they held. Not a security step, but the point at which institutional knowledge leaves, and worth capturing during a notice period rather than after.
Often missedAction
Shared and service account passwordsChange any password the person knew
External and vendor accountsRemove from registrars, portals, consoles, social media
Accounts registered in their nameTransfer ownership to the business
API keys and tokensAudit and revoke; they survive account disabling
Personal devices with company dataRemove mail profiles and synced files
Knowledge only they heldCapture during the notice period

Why this is a compliance matter

Terminated employees retaining access is a common finding in HIPAA compliance reviews, and access management is an explicit requirement under the FTC Safeguards Rule.

Cyber insurance applications also ask about offboarding process, and a dormant account belonging to a former employee is a favoured route for attackers precisely because nobody is monitoring it for unusual behaviour.

Two practices make this durable: run a quarterly access review comparing active accounts against your current staff list, and keep a documented record of each offboarding. Both are straightforward, and both are what turns a good intention into something you can evidence.

Sources

  1. Legal Information Institute, Cornell Law School (text of the federal regulation) — 16 CFR 314.4 – Elements (FTC Safeguards Rule)
  2. Federal Trade Commission — FTC Safeguards Rule: What Your Business Needs to Know
  3. Legal Information Institute, Cornell Law School (text of the federal regulation) — 45 CFR 164.308 – Administrative safeguards (HIPAA Security Rule)
  4. Microsoft Learn — Revoke user access in an emergency in Microsoft Entra ID

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.