Back to Blog
    How to Create a New Employee IT Setup Checklist

    How to Create a New Employee IT Setup Checklist

    business it
    employee onboarding
    it checklist
    cybersecurity
    managed it
    Author: Fix My PC Store Editorial TeamPublished: 8/3/2026Last Updated: 8/12/2026

    A solid new employee IT setup checklist prevents Day One login failures, missing permissions, and security gaps. Use this practical process to coordinate HR, managers, and IT, prepare equipment, control access, document decisions, and give every new hire a dependable start.

    A new employee should arrive to working equipment, the right access, and clear instructions. That sounds basic. It is also where many small businesses lose hours on first-day password resets, missing licenses, and last-minute “who has the admin login?” conversations.

    The fix is a repeatable checklist with an owner, deadlines, and a clean handoff. Build it once, review it quarterly, and use it for every employee, contractor, and role change.

    What you need

    Before writing the checklist, gather the information and authority needed to make it usable. A checklist cannot compensate for unclear ownership or a manager who tells IT about a new hire the afternoon before they start.

    You need:

    1. One request owner. Usually HR, an office manager, or the hiring manager submits the onboarding request. IT should not have to infer job requirements from an employee’s title.
    2. A lead-time rule. Set a reasonable minimum notice period for new hires. More notice is needed for a laptop order, specialized software, mobile device enrollment, or a remote employee shipment.
    3. A standard request form. Include the employee’s legal and preferred name, start date, manager, department, job title, work location, employment type, device needs, and required systems.
    4. An approved software and access catalog. List standard tools by department and identify who can approve exceptions. This prevents a new employee from receiving a random collection of applications that no one supports.
    5. An asset register. Track company laptops, desktops, monitors, phones, docks, chargers, serial numbers, assigned user, purchase date, warranty information, and return status.
    6. An identity platform and access policy. Decide where accounts are created, how passwords and multifactor authentication are handled, and which applications use single sign-on where available.
    7. A named IT owner or provider. Internal IT or a managed provider needs authority to provision accounts, configure equipment, and deny unsafe requests. For ongoing help with documentation and onboarding workflows, managed IT support is usually more practical than rebuilding the process every time someone joins.

    The basic principle is simple: HR confirms the person, the manager confirms the role, and IT provisions only the access required for that role. Nobody should be improvising on payroll day.

    1. Define the onboarding trigger and timeline

    Start the checklist before the employee’s first day. The trigger should be a completed hiring notice, not a casual mention in a hallway or a half-finished email.

    Create a simple timeline with accountability:

    1. At offer acceptance: HR opens the onboarding request and confirms the anticipated start date, manager, location, and employee type.
    2. Before the start date: The manager selects the role profile, applications, shared folders, distribution groups, and equipment requirements.
    3. Several business days before start: IT creates accounts, prepares the device, applies updates, installs approved software, and verifies access.
    4. One business day before start: IT checks that the device is charged, labeled, and ready. The manager receives confirmation, along with any setup steps the employee must complete.
    5. On the first day: The employee receives equipment, completes MFA enrollment, signs the acceptable-use and equipment acknowledgment, and gets basic support instructions.
    6. During the first week: IT or the manager confirms that critical systems work and removes anything provisioned by mistake.

    Use a ticket, shared onboarding board, or HR workflow to track each task. Email alone is a poor system of record. It produces several versions of the truth, usually at the exact moment someone needs the correct one.

    Include an escalation rule. If a required item is incomplete by the target date, the request owner and manager should know early enough to correct it. Silence is not a status update.

    2. Create role-based access profiles

    Do not build access one application at a time for every new employee. Instead, create role-based profiles for common positions, such as front desk, sales, accounting, field technician, manager, and remote contractor.

    Each profile should define:

    1. Core identity access. Email, calendar, chat, password reset options, MFA, and single sign-on.
    2. Department applications. Accounting software, CRM, scheduling tools, document management, phone system, or industry-specific systems.
    3. Shared resources. Team mailboxes, shared drives, SharePoint sites, printers, distribution lists, and internal knowledge bases.
    4. Data permissions. Read, edit, approve, export, and administrator rights. These are different privileges and should not be bundled by default.
    5. Hardware standard. Laptop or desktop, monitor count, docking station, headset, webcam, mobile phone, and any accessibility equipment.
    6. Training requirements. Security awareness, acceptable use, phishing reporting, handling customer data, and the approved support process.

    Use groups rather than assigning individual permissions wherever possible. If a salesperson needs access to the sales folder, add them to the sales group. Do not grant them direct access to a dozen folders because it was quicker at the time. Quick is often just deferred cleanup.

    Keep elevated access rare. Employees who need administrator rights should have a documented business reason, approval, and a separate administrative account where appropriate. The U.S. Cybersecurity and Infrastructure Security Agency provides practical guidance on securing accounts with MFA, which is a sensible baseline for business systems.

    If your business uses Microsoft tools, define the exact license, mailbox setup, Teams or SharePoint access, and device enrollment requirements in the role profile. A properly managed Microsoft 365 environment can make onboarding much more consistent, but only when its groups, licenses, and policies are kept organized.

    3. Prepare and secure the employee device

    A new device should be configured before it reaches the employee. Avoid handing over a sealed laptop with instructions to “set it up and call if anything goes wrong.” Something will go wrong, usually while the employee is trying to join their first meeting.

    Your device preparation checklist should include:

    1. Record the asset. Capture make, model, serial number, asset tag, assigned user, issue date, charger type, and included accessories.
    2. Install current operating system updates. Verify the device restarts successfully after updates. Do not assume an update completed because a progress bar once appeared.
    3. Enroll the device in management. Apply security settings, encryption, endpoint protection, screen-lock requirements, approved software, and remote support tools through your management system.
    4. Create a standard user account. The everyday account should not have local administrator privileges unless the role truly requires it.
    5. Enable full-disk encryption. Store recovery information securely and limit access to authorized IT personnel.
    6. Install approved applications. Include office productivity tools, browser, PDF tools, communication platforms, line-of-business software, password manager if used, and remote access software only when approved.
    7. Configure backups and synchronization. Confirm that work files are stored in an approved cloud location or backup-protected system, not only on the device. Review business backup and disaster recovery options so a lost laptop does not become a lost workweek.
    8. Test the basics. Sign in as the new user, connect to Wi-Fi, test email, calendar, printer access if relevant, video camera, audio, VPN or remote access, and critical applications.
    9. Prepare the physical kit. Include power adapter, dock, monitors, cables, headset, case, and written return instructions for remote staff.

    For South Florida businesses, physical planning matters too. If equipment will travel between West Palm Beach, job sites, and vehicles, choose protective cases and establish a rule that devices are not left in hot cars or unsecured locations. Heat, theft, and spilled coffee have no respect for your onboarding calendar.

    4. Provision accounts, licenses, and communications

    Account creation is more than creating an email address. It is the foundation for ownership, auditing, password recovery, and access removal later.

    Use a consistent account naming convention. Document how you handle duplicate names, legal name changes, contractors, shared accounts, and temporary workers. Individual accounts should be tied to an individual person. Shared credentials make accountability disappear quickly.

    Provision these items in order:

    1. Primary identity account. Create the account in the central identity provider and assign the correct role groups.
    2. License assignment. Assign only the licenses the employee needs. Track exceptions and unused licenses for periodic review.
    3. Email and communication tools. Create mailbox access, email aliases where approved, calendar permissions, chat groups, phone extension or softphone account, and relevant distribution lists.
    4. Business applications. Assign role-based access, verify the manager has approved it, and avoid using a departing employee’s account as a template without review.
    5. Password and MFA setup. Send initial credentials through a safe process. Require password creation and MFA enrollment at first sign-in. Do not email a password and MFA recovery codes in the same message.
    6. Recovery contacts. Configure approved recovery methods. A personal email address or phone number may be appropriate depending on company policy, but it should be handled intentionally and documented.

    For systems holding sensitive data, confirm the account is protected by MFA and that logging is enabled where the platform supports it. If your organization handles financial records, client data, health information, or regulated information, involve the appropriate compliance owner before granting access. Business cybersecurity support can help turn these rules into practical controls rather than a binder everyone ignores.

    Tired of IT that breaks at the worst time? Talk to our business IT team

    5. Set up network, remote work, and physical access

    The new employee checklist should cover where the person works, not just what sits on their desk.

    For office-based staff, verify:

    1. Wi-Fi access. Assign the employee to the correct secure network. Guest Wi-Fi should remain separate from business devices where possible.
    2. Wired network needs. Confirm whether their desk, dock, phone, printer, or specialized equipment requires Ethernet.
    3. Printer and scanner access. Add only the devices needed for the role and test a print or scan where practical.
    4. Physical access. Coordinate keys, badges, alarm codes, parking access, and building access with the person responsible for facilities. IT should not distribute a door code by casual text message.
    5. Conference room access. Confirm the employee knows how to use meeting-room displays, cameras, and collaboration equipment if that is part of the role.

    For remote or hybrid staff, verify:

    1. Home internet suitability. You do not need to manage the employee’s entire home network, but you should confirm the connection can support required meetings and business applications.
    2. Secure remote access. Configure approved VPN, zero-trust access, remote desktop gateway, or cloud application access. Do not expose an office PC directly to the internet because somebody wants to work from home.
    3. Support path. Provide instructions for requesting help. A tested remote support service is useful when a new employee is not within driving distance of the office.
    4. Home-office equipment. Document who provides monitors, headsets, ergonomic equipment, and replacement accessories.

    A dependable business network makes onboarding easier because permissions, device policies, and support tools behave consistently. If your office setup is pieced together from aging routers and unmanaged switches, stabilize that foundation first with business networking support.

    6. Deliver a first-day handoff and short training session

    The employee should not receive a laptop without a handoff. Even a 20-minute setup session prevents common issues and gives the person a clear way to get help.

    Cover the following:

    1. Sign-in and MFA. Have the employee sign in, change any temporary password, enroll MFA, and confirm they can complete a second sign-in.
    2. Device care. Explain charging, travel, updates, lock-screen behavior, approved storage locations, and what to do if equipment is lost or damaged.
    3. Essential applications. Confirm access to email, calendar, chat, shared documents, phone system, and role-critical applications.
    4. Security basics. Explain phishing reporting, password manager use if applicable, restrictions on personal USB drives, and why they should not approve unexpected MFA prompts.
    5. Support instructions. Give the help desk contact method, expected response process, emergency contact procedure, and remote support expectations.
    6. Acknowledgments. Collect equipment receipt, acceptable-use acknowledgment, security policy acknowledgment, and any remote-work agreement required by the business.

    Keep this practical. New employees do not need a three-hour lecture about firewall rules. They do need to know how to recognize a suspicious login prompt and where their files are supposed to live.

    7. Verify, document, and schedule follow-up

    Onboarding is not complete when the laptop leaves IT. It is complete when the employee can do their job without excessive access, missing tools, or an undocumented workaround.

    Within the first week, send the employee and manager a short verification list:

    1. Can the employee access their email, calendar, communication platform, and required applications?
    2. Can they access the correct shared resources, but not restricted data they do not need?
    3. Does the laptop, phone, headset, printer, and remote access work as expected?
    4. Has MFA been enrolled and tested?
    5. Has the asset register been updated and all acknowledgments collected?
    6. Are there any temporary permissions, trial licenses, or exceptions that need an expiration date?

    Document the final configuration in the ticket or onboarding record. Record account names, assigned groups, licenses, devices, software exceptions, approvals, and outstanding actions. Do not put passwords, recovery codes, or sensitive secrets into a general ticket note.

    Then schedule a 30-day review for roles with sensitive access, new managers, finance staff, or employees who received elevated permissions. This is a good time to remove access that sounded necessary during hiring but was never used in practice.

    Common mistakes

    1. Starting after the employee arrives. This creates rushed account setup and encourages insecure shortcuts. Use a formal trigger and lead-time rule.

    2. Giving everyone the same access. Broad access is easy to provision and hard to defend. Use role-based groups and the principle of least privilege.

    3. Reusing accounts or shared passwords. Every person should have their own identity. Shared credentials make audits, offboarding, and incident response unnecessarily difficult.

    4. Skipping MFA until later. “Later” often means never. Make MFA enrollment part of first-day setup, not an optional follow-up.

    5. Handing out unprepared devices. A device should be patched, protected, enrolled, tested, and documented before delivery.

    6. Forgetting physical access and equipment. The employee may have a working email account but still lack a badge, charger, headset, or desk connection. The checklist must include non-IT dependencies.

    7. Failing to test role-critical applications. A basic email test is not enough for an accountant who cannot access the accounting platform or a field employee who cannot use the scheduling app.

    8. Treating onboarding and offboarding as unrelated. The data you collect when issuing accounts and equipment is what makes later removal clean. Build your checklist so it supports both.

    Bottom line

    A reliable new employee IT setup checklist is a control system, not administrative paperwork. It makes hiring smoother, reduces preventable support calls, limits unnecessary access, and leaves a record your business can use when roles change or employment ends.

    Start with a standard request form, role-based profiles, prepared devices, MFA, documented approvals, and a first-week verification step. If your West Palm Beach or South Florida business needs the workflow, device standards, and security controls put into a repeatable process, contact Fix My PC Store for practical business IT help.


    Tired of IT that breaks at the worst time?

    We run managed IT, backups, and security for South Florida businesses so you can stop thinking about it.

    Talk to our business IT team

    Frequently asked questions

    What should be included in a new employee IT setup checklist?

    Include the onboarding request details, approved role-based access, account and license setup, MFA enrollment, device preparation, asset tracking, network or remote-work access, first-day training, and a first-week verification. Also document approvals and any temporary exceptions so they can be reviewed later.

    How far in advance should IT receive a new hire request?

    Set a clear minimum lead time based on your business and equipment needs. A standard office setup may need only a few business days, while a custom device order, specialized software, or remote shipment requires more time. The important part is that HR and managers use a formal request process as soon as the hire is confirmed.

    Should every new employee have administrator rights on their computer?

    No. Everyday employee accounts should normally be standard user accounts, with elevated rights granted only when there is a documented business need. Limiting administrator access reduces the damage from malware, unsafe software installs, and accidental system changes.

    Why use role-based access instead of assigning permissions individually?

    Role-based access makes onboarding faster and more consistent because employees in comparable jobs receive the same approved access through groups. It also simplifies audits, role changes, and offboarding because permissions can be reviewed and removed in one place.

    What should happen after a new employee receives their laptop?

    IT and the manager should verify that the employee can sign in, use MFA, access essential applications, connect to needed resources, and follow the support process. Update the asset record, collect acknowledgments, and review any elevated or temporary access during the first month.

    Frequently Asked Questions

    What should be included in a new employee IT setup checklist?
    Include the onboarding request details, approved role-based access, account and license setup, MFA enrollment, device preparation, asset tracking, network or remote-work access, first-day training, and a first-week verification. Also document approvals and any temporary exceptions so they can be reviewed later.
    How far in advance should IT receive a new hire request?
    Set a clear minimum lead time based on your business and equipment needs. A standard office setup may need only a few business days, while a custom device order, specialized software, or remote shipment requires more time. The important part is that HR and managers use a formal request process as soon as the hire is confirmed.
    Should every new employee have administrator rights on their computer?
    No. Everyday employee accounts should normally be standard user accounts, with elevated rights granted only when there is a documented business need. Limiting administrator access reduces the damage from malware, unsafe software installs, and accidental system changes.
    Why use role-based access instead of assigning permissions individually?
    Role-based access makes onboarding faster and more consistent because employees in comparable jobs receive the same approved access through groups. It also simplifies audits, role changes, and offboarding because permissions can be reviewed and removed in one place.
    What should happen after a new employee receives their laptop?
    IT and the manager should verify that the employee can sign in, use MFA, access essential applications, connect to needed resources, and follow the support process. Update the asset record, collect acknowledgments, and review any elevated or temporary access during the first month.

    Share this article

    You May Also Like