Two of the most overlooked moments in business security happen at the very start and very end of an employee’s time with you. A sloppy onboarding leaves new hires unproductive and over-permissioned; a sloppy offboarding leaves active accounts, accessible data, and security holes behind former staff. Both are avoidable with a simple, repeatable IT checklist. Here’s what every Boston business should have in place.
Why This Matters More Than It Seems
Former employees with lingering access are a genuine breach risk, whether through carelessness, a disgruntled departure, or an attacker exploiting a forgotten account. On the other side, a chaotic onboarding wastes the expensive first week of every new hire and tempts managers into insecure shortcuts (“just share your login with them for now”). A documented process fixes both and makes audits, cyber insurance, and compliance far easier.
The IT Onboarding Checklist
Before day one
Provision the device and image it with your standard software and security tools, create accounts (email, Microsoft 365, line-of-business apps) with the correct role-based permissions, and enroll the user in MFA from the start. Prepare access to only the systems the role actually needs, no more.
Day one
Walk the new hire through secure login and the password manager, confirm MFA is working, and cover the basics of your acceptable-use and security policies. Starting people with good habits is far easier than correcting bad ones later.
First week
Enroll them in security awareness training and confirm they can reach everything they need, while verifying they can’t reach things they shouldn’t.
The Principle Behind Good Onboarding: Least Privilege
Give each person access to exactly what their job requires, nothing more. It limits the damage if an account is compromised, keeps tools like Microsoft 365 and Copilot from surfacing data people shouldn’t see, and makes offboarding cleaner. Over-permissioning “to be safe” is the opposite of safe.
The IT Offboarding Checklist
The moment of departure
Disable accounts immediately (don’t delete yet), this instantly cuts access while preserving data. Reset or revoke passwords, terminate active sessions, and remove MFA devices. Timing matters most for involuntary departures: access should be cut the moment the person is notified, not at end of day.
Securing the data and devices
Recover company laptops, phones, and any hardware, and reclaim physical access (keys, badges, alarm codes). Transfer or preserve the departed employee’s email and files, then convert their mailbox appropriately so messages aren’t lost.
Closing the loop
Remove the user from all third-party apps and services (these are the ones most often forgotten), revoke VPN and remote access, and update any shared or service accounts whose passwords the person knew. Document everything you did.
The Trap: Forgotten Third-Party Accounts
Disabling someone’s email feels like offboarding is done, but the modern business runs on dozens of separate apps, CRM, accounting, design tools, social media, file sharing. Each is a door that needs closing. This is exactly why maintaining a current inventory of accounts and access is part of well-run managed IT.
Make It Repeatable
The goal is a process that runs the same way every time, regardless of who’s handling it, so nothing slips through during a busy week or a stressful departure. Boston Networks builds and runs onboarding and offboarding workflows for clients so the right access is granted fast and revoked completely. Request a consultation and we’ll turn this checklist into a process your business can rely on.
