Starting a new employee without having their account, laptop, permissions, and security ready causes frustration, delays, and unnecessary security risks. This article explains which IT matters should ideally be arranged before the first working day.
The first working day of a new employee should not start with:
- "My laptop hasn’t arrived yet."
- "I can’t log in."
- "I don’t have access to Teams."
- "My mailbox doesn’t exist yet."
- "Which programmes do I actually need?"
- "Can someone make me an administrator for a moment?"
IT must be given enough time to properly prepare identity, device, permissions, and security.
Why is arranging things in advance so important?
IT onboarding is not just about ordering a laptop.
A new employee gains access to company information, communication, applications, and sometimes sensitive data.
Therefore, several matters must be correctly coordinated:
- identity;
- Microsoft 365;
- device management;
- security;
- access rights;
- SaaS applications;
- Teams and SharePoint;
- shared mailboxes;
- telephony;
- any specific company applications.
And temporary workarounds tend to become permanent.
1. Provide IT with the correct information in time
For good onboarding, IT needs at least correct basic information.
Think of:
- full name;
- start date;
- position;
- department;
- manager;
- workplace or branch;
- required hardware;
- which applications are needed;
- which Teams, SharePoint sites, and groups are needed;
- which shared mailboxes are needed;
- any special permissions.
2. Create the Microsoft 365 account beforehand
The user account usually forms the basis of the digital identity.
Linked to this are, among others:
- email address;
- Microsoft 365 licence;
- Teams;
- SharePoint;
- OneDrive;
- security groups;
- other cloud applications.
The account is best prepared before the first working day, but access does not necessarily have to be active before the employee actually starts.
IT can configure an identity without the employee having access to company data prior to their official start.
3. Choose the right Microsoft 365 licence
Not every employee needs the same licence.
An administrative employee, a warehouse worker, and an IT administrator may use a completely different combination of services.
Therefore, consider:
- email needs;
- desktop Office apps;
- Teams;
- Intune;
- security functionality;
- any additional Microsoft services;
- other SaaS applications.
4. Ensure the laptop is ready
A company laptop should be more than just a new computer out of the box.
Ideally, before the first working day, the device should:
- be registered in the management environment;
- have the correct security settings;
- use disk encryption;
- have endpoint protection;
- contain the necessary applications;
- receive updates;
- be ready to be used by the correct user.
Especially not when old profiles, files, or accounts from a previous user are still present.
5. Secure the device from first use
Security should not be activated weeks later.
A modern company device should be properly secured from the first login.
Think of, among others:
- BitLocker or other disk encryption;
- Windows Hello;
- MFA;
- endpoint security;
- automatic updates;
- device compliance;
- Conditional Access;
- central management.
6. Arrange MFA before the employee really starts working
The first login is a logical moment to correctly set up strong authentication.
Depending on the environment, this can be done via, for example:
- Microsoft Authenticator;
- passkeys;
- Windows Hello for Business;
- other approved authentication methods.
An account created today but only secured properly next week creates an unnecessary risk.
7. Grant only the permissions that are necessary
A common onboarding mistake is copying permissions from an existing employee.
For example:
That seems quick, but over the years Jan may have acquired many additional permissions that do not belong to the new role.
grant only the access necessary for the role.
8. Arrange Teams and SharePoint consciously
Not every new employee should automatically get access to all Teams and SharePoint sites of their department.
Check:
- which Teams are needed;
- which SharePoint sites are needed;
- which groups belong to these;
- whether read-only or also editing access is needed;
- whether sensitive information is present.
9. Don’t forget shared mailboxes and distribution lists
An employee may need access to:
- sales@;
- info@;
- support@;
- billing@;
- other shared mailboxes;
- distribution lists;
- Microsoft 365 groups.
Again, only when functionally necessary.
10. Also arrange other SaaS applications
Microsoft 365 is rarely the only application someone uses.
Consider, for example:
- CRM;
- ERP;
- accounting;
- HR platform;
- ticketing;
- telephony;
- password manager;
- project management;
- customer and supplier portals.
11. Use personal accounts
Where possible, every employee gets their own account.
Avoid arrangements such as:
with one shared password for five employees.
Personal accounts provide:
- clear accountability;
- better logging;
- personal MFA;
- simpler onboarding;
- much safer offboarding.
12. Use a password manager
Does the employee need access to shared company credentials?
Do not share these via:
- email;
- Teams;
- WhatsApp;
- Excel;
- a note next to the screen.
Use a professional password manager where access can be centrally granted and later revoked.
13. Don’t forget security awareness
A new employee should not only know how Teams works.
They must know from the start:
- what phishing can look like;
- that unexpected MFA requests must be refused;
- how to report suspicious messages;
- how company data is shared securely;
- what the password policy is;
- what to do if a device is lost;
- who to contact if in doubt.
The basics should be part of onboarding.
14. GDPR also starts on day 1
A new user may get access to personal data of:
- customers;
- suppliers;
- colleagues;
- applicants;
- other data subjects.
From a GDPR perspective, access must also be limited to what someone needs for their role.
It also helps to limit unnecessary access to personal data.
15. Grant administrator rights only when truly necessary
Making an employee administrator "because it’s easier" is not a good starting point.
Elevated rights increase the impact of:
- human errors;
- malware;
- account misuse;
- phishing;
- a compromised device.
16. Think about future offboarding already
Good onboarding makes future offboarding predictable.
If onboarding records:
- which accounts were created;
- which licences were assigned;
- which groups someone belongs to;
- which applications are used;
- which devices are linked;
- which special permissions exist;
you will later also know what needs to be revoked again.
Who may request a new user?
Onboarding should not happen solely on the basis of an informal request.
A new user can gain access to sensitive company information, personal data, and company applications.
FLEXAMIT therefore expects requests to come from an authorised or mandated person within the organisation.
Depending on the client, this could be, for example:
- the managing director;
- HR;
- the manager;
- a designated IT responsible person;
- another formally mandated contact person.
Because FLEXAMIT should not decide which employee gets access to which client information.
The client organisation determines who needs which functional access. FLEXAMIT then ensures that this access is technically set up correctly and securely.
What does an ideal first working day look like?
The employee receives their laptop.
They log in with their own company account.
Strong authentication is correctly activated.
The laptop automatically receives the correct security settings and applications.
Teams, SharePoint, mailboxes, and company applications are available according to their role.
And the employee can start working.
What does a bad first working day look like?
09:30 — "For now, use Peter's old laptop."
10:15 — "Can someone share their password for a moment?"
11:00 — "Just give her access to everything for now."
14:00 — "Why can’t she access SharePoint?"
16:00 — "We’ll arrange MFA later."
That is not only inefficient. Several of these temporary solutions also create security and privacy risks.
Use a fixed onboarding procedure
New employees should not be set up each time via scattered emails and verbal instructions.
A good organisation works with a fixed checklist.
Example of an onboarding checklist:
- receive personal data;
- confirm start date;
- determine role and department;
- create Microsoft 365 account;
- assign correct licences;
- prepare laptop;
- apply security policy;
- prepare MFA;
- assign Teams and SharePoint;
- set up shared mailboxes;
- configure SaaS applications;
- set up password manager;
- configure telephony;
- provide security awareness;
- perform checks before the start date.
FLEXAMIT can manage the entire onboarding process
Good onboarding combines:
- Microsoft 365;
- identity & access management;
- cybersecurity;
- endpoint management;
- hardware;
- SaaS applications;
- security awareness;
- privacy and GDPR;
- business processes.
We prepare account, Microsoft 365, device, security, permissions, and other necessary IT services in a controlled manner.
We do not just provide as much access as possible but ensure the right access for the right person.
That is better for the employee, more efficient for the organisation, and safer for company data.
Our cybersecurity expertise has been recognised three years in a row by our Microsoft distributor with the Cybersecurity Partner of the Year award.
New employee coming?
Submit the onboarding request as early as possible.
Are you a FLEXAMIT client? Please provide us at least with:
- name of the new employee;
- start date;
- role and department;
- which hardware is needed;
- which Microsoft 365 and company applications are needed;
- which Teams, mailboxes, and other access are needed.
The earlier we receive this information, the better we can ensure everything is correctly ready on the first working day.
Contact us via:
support@flexamit.com
Want to structurally improve onboarding?
Does your organisation lack a fixed onboarding procedure or are new employees still set up ad hoc today?
Contact us for this:
sales@flexamit.com
In brief
- Provide IT with onboarding information before the first working day.
- Prepare account and Microsoft 365 correctly in advance.
- Choose the correct licences based on the role.
- Ensure the laptop is fully managed and secured.
- Activate strong authentication from the first login.
- Grant only the necessary access rights.
- Do not blindly copy all permissions from an existing employee.
- Also arrange Teams, SharePoint, shared mailboxes, and SaaS applications.
- Use personal accounts and a professional password manager.
- Make security awareness part of onboarding.
- Consider GDPR and limit access to personal data.
- Document what is granted so later offboarding can be done correctly.
- Good onboarding ensures someone can work on day 1 without sidelining security.
Comments
0 comments
Please sign in to leave a comment.