A new hire shows up Monday morning. The laptop is still in the box, the email account doesn’t exist yet, and a coworker shares their own login “just for today.” By Friday, nobody remembers to change it. That is what happens when new hire IT setup is left to the first morning.
A repeatable process prevents that week. New staff, seasonal help and temps start on day one with the right device, the right access and the right training, and nothing more than they need. For our clients, setting up a new person’s accounts is routine work, and the earlier the request comes in, the more is ready on the first morning.
Key takeaways
- IT onboarding starts the day an offer is accepted.
- Give every new hire their own account, protected by multifactor sign-in (MFA) from day one. Never use a shared login as a shortcut.
- Grant access by role, and add more only when there is a reason.
- Seasonal and temporary staff need the same basics plus a planned end date.
Why new hire IT setup matters
12%
of employees strongly agreed that their organization did a great job onboarding new employees, in a Gallup survey published in 2018
Waiting days for a working login is a big part of why onboarding feels that way. The security side matters as much. The first week is when people get handed shared passwords, broad access “to be safe,” or permission to use a personal laptop until theirs arrives, and those shortcuts tend to stick.
If you keep client, patient or financial records, onboarding is also a compliance step. The HIPAA Security Rule expects procedures for authorizing and supervising workforce access to patient data and a security training program for the whole workforce. The FTC Safeguards Rule, which covers many accounting and tax firms, requires security awareness training for staff.
Before day one
Once an offer is accepted, HR or the manager sends IT a short request with the person’s name, title, manager, start date and role. From there, IT can prepare almost everything in advance.

- Create the account in Microsoft 365 and any line-of-business systems from a role template, so access is consistent.
- Assign licenses for email, Teams and the apps the role needs.
- Prepare the device. With Windows Autopilot, a new Windows PC can ship straight to the employee and set itself up on first sign-in, joining the organization, enrolling in device management and installing the required apps and settings.
- Plan a secure first sign-in. A Microsoft Entra Temporary Access Pass is a time-limited code that lets a new user sign in once and register MFA or a passkey, so no permanent password has to be emailed or written down.
- Add the person to the right shared mailboxes, Teams channels and file locations.
- Set up their phone extension and printing.
Day one
The goal for the first morning is simple: the employee signs in to their own device with their own account, protected by MFA, and can reach what they need.
- Register MFA together, so it is done right. Our post on passkeys explains the strongest option.
- Set up the business password manager. For our clients, that is the managed one we provide.
- Confirm email, files, Teams and the main business applications all work.
- Walk through where files go, how to report a suspicious email, who to call for help, and your acceptable use and AI policies.
- Have the employee sign your security and acceptable use policies, and keep the record.
Grant access by role, not by copying a coworker
Copying another employee’s access is the fastest way to onboard someone, and it is how a receptionist ends up with access to payroll. Build simple role templates instead, such as front desk, billing, associate and manager, each listing exactly which groups, apps and folders the role needs.
- Everyday users get no admin rights on their computers.
- Extra access requires a request from the manager, and the request is recorded.
- The data owner approves access to patient records, client financials or case files.
- Access is reviewed after 90 days and whenever someone changes roles.
This is the least-privilege idea behind Zero Trust, and our post on access management explains why it matters. It is part of a sound cybersecurity program.
Seasonal, temporary and remote hires
Tax season, year-end rushes and grant-funded projects bring in short-term help. Temporary staff often get less training and broader access than permanent staff because there is no time, which is backwards. Give them named accounts so every action traces to a person, record an end date for their access when the account is created, limit them to the systems the work requires, and provide managed devices or approved remote access instead of unmanaged personal laptops.
When the season ends, follow your offboarding checklist the same day. For our clients, access is disabled the same day the client requests it. Our post on why employee departures are a security blind spot covers that side.
Training in the first week
Security training belongs in the first week, before habits form, and it should be the same for temps as for permanent staff. Our clients’ new hires join the same continuous phishing simulations as everyone else, and a click brings a short lesson on the spot. Our guide to employee cybersecurity training covers what a good program includes.
After each new hire, ask what went wrong and fix the checklist. Onboarding that depends on someone remembering every step will eventually miss one. Book an intro call and we’ll talk about turning it into a process through our managed IT services, with a recorded trail for every hire, which businesses with compliance requirements need.
FAQ
Frequently asked questions
How far ahead should IT know about a new hire?
As early as possible, ideally when the offer is accepted. Lead time lets IT order or prepare a device and set up accounts properly instead of rushing.
Can a new hire use a coworker’s login until their account is ready?
No. Shared logins remove accountability and often skip MFA. If an account can’t be ready in time, delay system access rather than share credentials.
Sources: Gallup, Why the Onboarding Experience Is Key for Retention, 2018; Microsoft Learn, Windows Autopilot user-driven mode; Microsoft Learn, Configure Temporary Access Pass; HIPAA Security Rule administrative safeguards, 45 CFR 164.308; FTC Safeguards Rule, 16 CFR 314.4.




