Key takeaways

  • Access should be based on the position and role, rather than copied from the previous employee's account.
  • Onboarding covers equipment, accounts, licences, MFA and instructions for the user.
  • Offboarding should trigger account blocking on the same day.
  • Every process should record an owner and completion date.

Effective onboarding

Before the first day, establish the role, applications and access to folders, email, VPN and devices. Prepare the computer, encryption, updates, MFA and brief instructions for reporting problems. Assign permissions through groups that correspond to the role.

Secure offboarding

Once the employee's departure has been confirmed, block the account, revoke sessions and tokens, retrieve equipment, remove licences and transfer data according to the company's arrangements. Also check email forwarding, VPN access, shared passwords and service accounts.

Do not delete data without a plan

First establish the owner of the documents and their retention period; only then should data be archived or deleted.

Common mistakes

  • Copying all permissions from the previous employee.
  • No deadline for disabling the account.
  • No equipment and licence register.
  • Overlooking accounts in external applications.
  • No confirmation that steps have been completed.

Process checklist

  1. Gather HR details. Position, line manager and start or end date.
  2. Prepare access. Accounts, groups, licences, equipment and MFA.
  3. Provide instructions. Password, support request and secure working policies.
  4. Confirm receipt and return. Equipment, keys, tokens and documents.
  5. Close access. Accounts, sessions, VPN, email and external services.
  6. Archive the documentation. Retain an audit trail of completed activities.

Frequently asked questions

When should a departing employee's account be disabled?

At the agreed end of employment, without leaving active access 'just in case'.

Can onboarding be automated?

Yes. Groups, licences and device configurations can be assigned partly on the basis of a role.

Who should approve access?

The process owner or line manager should approve it, while IT should implement and document the change.

Related service

Do you need to organise accounts, equipment and documentation?

View managed IT services

Would you like a repeatable access process?

We can prepare checklists and organise roles, accounts and devices.

Let's talk about your IT