A practical IT checklist for creating, changing, and removing employee access across devices, Microsoft 365, applications, and business data.
The business, not the IT provider, should identify the authorized requester and decide what access each role requires. IT should implement and document those approved decisions consistently.
Before a new employee starts
- Confirm legal name, preferred display name, role, manager, start date, location, and approved requester.
- Identify required Microsoft 365 license, email address, groups, shared mailboxes, Teams, SharePoint sites, and business applications.
- Assign an appropriate computer, accessories, security settings, and delivery or setup plan.
- Create access according to role rather than copying another employee without review.
- Define what must be ready before the first day and what requires manager-led training.
On the first day
- Verify identity before issuing credentials or changing authentication methods.
- Enroll multifactor authentication through the approved process.
- Confirm the user can access required email, files, applications, printing, and communication tools.
- Explain the support channel, urgent-issue path, password expectations, and how suspicious messages should be reported.
- Record exceptions instead of silently granting broader access to make setup faster.
When an employee changes roles
Role changes deserve the same discipline as new hires. Add approved access for the new responsibilities, then review whether access from the previous role is still required. Otherwise permissions tend to accumulate over time.
Changes to administrative roles, finance systems, customer records, sensitive files, or shared credentials should receive explicit approval and a documented completion record.
When an employee leaves
- Confirm the effective time, departure type, authorized requester, and any special handling before making changes.
- Block or disable access according to the approved timing across Microsoft 365, business applications, remote access, and other covered systems.
- Revoke active sessions, review authentication methods, and address shared or known credentials where applicable.
- Recover business devices, keys, badges, tokens, and other company property through the responsible internal owner.
- Decide how email, files, OneDrive data, shared ownership, licenses, and customer communications should be retained or reassigned.
- Document completed actions, exceptions, inaccessible systems, and follow-up responsibilities.
Review the process, not only the ticket
Periodically compare active employees, accounts, licenses, devices, groups, and administrator roles. This can reveal departures that were never reported, duplicate licenses, dormant access, and role changes that left unnecessary permissions behind.
A repeatable checklist does not remove the need for judgment. It makes sure the right business decisions are requested, approved, implemented, and recorded each time.
