New Employee IT Security Checklist for Day One

The New Employee IT Security Checklist: What Should Happen on Day One (and What Usually Doesn’t)

A new hire's first login is a security event as much as a setup task. Before day one they need scoped accounts, a managed device and multi-factor authentication (MFA); on day one they need a short, real security orientation; and you need a record of everything they were given so it can all be removed when they leave.

Most businesses think of IT onboarding as a laptop and an email address. Those matter, but they are the easy part. The access decisions, device controls and habits set in the first week are where many security incidents, compliance gaps and access-control problems begin. Here is what a complete IT security onboarding looks like, and what tends to go wrong when steps get skipped.

Before day one: setup that shouldn't be rushed

Account creation and access scoping

Accounts for Microsoft 365, line-of-business applications, cloud platforms and remote access should be created before the person arrives, with access limited to what their role needs. "Give them everything and we'll trim it later" tends to stay that way for years. Single sign-on (SSO) makes this easier to manage: one identity, one place to grant access and one place to remove it.

Device preparation

Whether the device is company-issued or personal under a BYOD policy, it should be enrolled in mobile device management (MDM) before it touches company data. That means encryption on, screen lock required, remote wipe available, and endpoint detection and response (EDR) installed and reporting. A company-owned laptop that was never enrolled is, for security purposes, an unmanaged device.

MFA enrollment

MFA should be set up before the account goes live, not as an afterthought. An account without MFA is exposed from the moment it exists. We enroll an authenticator app, confirm it works, and turn off text-message codes as a fallback where possible, because SMS codes are a weaker second factor.

Day one: the conversations that change behavior

Security awareness orientation

Skip the 45-minute video people click through while answering email. Have a real conversation about the threats they're likely to see in their role: phishing patterns, how wire or payment changes get verified, how to report something suspicious and what to do if they think they clicked something they shouldn't have. The "if in doubt, call IT" habit matters most, and day one is when it gets set. Formal security awareness training then builds on it.

Passwords and password managers

Explain the password requirements, why they exist and how to use the company password manager. The goal is an employee who understands why reusing passwords causes problems (see credential stuffing and password spraying) and knows what to do instead.

Clean desk and screen lock habits

In offices where sensitive information sits on screens and desks, such as medical practices, financial firms and law offices, physical habits matter as much as digital ones. HIPAA includes physical safeguards, and the FTC Safeguards Rule under GLBA expects access to customer information to be controlled. Locking the workstation before walking away is a habit worth starting on day one.

Acceptable use policy acknowledgment

The written policy covers what company devices and systems may be used for, how data should be handled and what is prohibited. A signed acknowledgment also serves as compliance evidence: HIPAA, the FTC Safeguards Rule and PCI DSS all expect documented security policies and workforce training, and the acknowledgment shows the policy was communicated.

What usually gets skipped, and what it costs

MFA enrollment. The most common gap. "We'll set that up next week" slides into months. Then a phished or reused password leads to an account takeover that MFA would very likely have stopped.

Over-provisioned access. Giving a new hire administrator rights, every shared drive and full permissions in every application because it's quicker than working out what they need is one of the most common access problems we see. If that account is later compromised, or the person leaves on bad terms, the damage can spread much further than it should.

Unenrolled devices. A personal phone or laptop that reaches company email, cloud storage or remote access without MDM is invisible to your security tools. There is no encryption check, no remote wipe and no EDR. If the device is lost, or the employee leaves, you have no technical control over the company data on it.

No record for offboarding. The best time to document what access someone has is when they start, not on their last afternoon. Log every account, application and shared resource at onboarding so offboarding can be done completely. Former employees with active accounts are a significant and entirely preventable risk.

The offboarding mirror

Every onboarding step has an offboarding counterpart. Accounts created must be disabled. Device enrollment means remote wipe is available. Precisely scoped access makes access removal precise. Same-day offboarding only works if onboarding created the records to make it possible. Our employee offboarding checklist covers the other half of the cycle step by step.

For managed IT clients, our IT help desk handles the full onboarding and offboarding cycle: accounts and devices prepared before the first day, and access removed on the schedule you set once you let us know someone is leaving. The sooner we hear about a departure, the cleaner the cutover. Account setup and licensing run through our Microsoft 365 support.

For more on the controls behind this, see our articles on remote work security and Zero Trust. For what happens when your business first becomes a client, see our managed IT onboarding process.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT help desk for onboarding and offboarding