Employee Onboarding and Offboarding IT Checklist for Small Business

September 26, 2026

A practical checklist for securing access when staff join — and closing it completely when they leave.

Access Security · Braintree, MA

Employee Onboarding and Offboarding IT Checklist for Small Business

📍 Serving Massachusetts, within 50 miles of Braintree ⏱ 7 min read 🗓 Published September 2026

The short answer: New hires should get only the access their role actually needs, set up the same way every time. Departing employees should have every account, device, and credential cut off the same day employment ends — not whenever someone on the team gets to it. A short written checklist for both moments closes the gap that attackers most often find first: an account nobody remembered to turn off.

That's not a hypothetical risk. In one case documented by the Cybersecurity and Infrastructure Security Agency (CISA), a threat actor accessed a state government organization's network simply by signing in with a former employee's VPN credentials — an account the organization had never disabled. The fix isn't complicated technology; it's a consistent process applied every time someone joins or leaves.

7 Steps for Onboarding and Offboarding Staff IT Access

1. Give new hires only the access their role needs

The National Institute of Standards and Technology ( NIST) calls this "least privilege" — restricting each person's access to the minimum needed to do their job. The Federal Trade Commission ( FTC) puts it more plainly for small businesses: "restrict sensitive information access to only those who need it to do their jobs." A new front-desk hire and a new office manager shouldn't get identical access by default just because it's easier to copy the last person's setup.

2. Build a standard access template for each role

Decide in advance what a "standard" front-desk, clinical, accounting, or admin account looks like — which systems, which folders, which software licenses. Working from a template makes onboarding faster and, just as important, makes offboarding complete: you know exactly what to remove because you know exactly what was granted. Revisit the templates whenever you add or drop a piece of software, so the list stays accurate instead of becoming a guess a year later.

3. Require unique logins — never shared accounts

A shared login for a shared mailbox or accounting tool feels convenient until someone leaves and you have to decide whether to change a password everyone else also depends on. Individual logins mean one person's departure never forces a scramble to reset access for the whole team.

4. Revoke access the same day employment ends

CISA's advisory on the former-employee VPN incident recommends that organizations "continuously remove and disable accounts and groups from the enterprise that are no longer needed, especially privileged accounts," and specifically ensure "accounts of offboarded employees are removed and can no longer access the network." Same-day matters — a departing employee's account is most likely to be misused, whether by the person themselves or by an attacker who obtains the credentials later, in the days immediately after it stops being watched.

5. Follow a complete offboarding sequence, not just a password reset

Disabling sign-in is the first step, not the whole job. For a Microsoft 365 environment, Microsoft's own offboarding guidance lays out a full sequence: block the former employee from signing in, secure and reassign their mailbox and OneDrive content, wipe company data from their mobile device, forward or convert their email, then remove the license and finally delete the account. Microsoft also notes that after a license is removed, mailbox and OneDrive content are retained for 30 days before permanent deletion — a useful window if something is needed after someone has already left.

6. Retrieve devices and company property

Laptops, phones, key fobs, badges, and any hardware security keys should be on a short list tied to each employee, so nothing is forgotten in the last conversation. If a device can't be physically retrieved right away, it should still be remotely locked or wiped the same day, not left active "until we get it back." Don't forget accounts that live outside your main systems, too — a company card saved in a cloud app, a personal phone number registered for two-factor codes, or a vendor portal login set up before your standard template existed.

7. Review who still has access on a regular schedule

Even a good process misses something occasionally — a shared app that IT didn't know about, a vendor portal, an old file-share invite. CISA's guidance frames this as a continuous practice, not a one-time cleanup: periodically reviewing administrator and standard accounts to confirm each one is still needed keeps small gaps from becoming the way someone gets back in.

⚠️ A real incident, not a hypothetical: In CISA advisory AA24-046A, an attacker used a former employee's still-active, privileged VPN account — obtained through a separate data breach — to get into a state government network and begin reconnaissance. The account had simply never been disabled after the employee left.

Quick Self-Check: Where Does Your Business Stand?

  1. New hire access: Is there a defined, role-based list of what a new employee gets access to before their first day?
  2. Shared logins: Does anyone currently share a login for email, accounting software, or a shared drive?
  3. Same-day offboarding: If someone left today, could every one of their accounts be disabled before end of day?
  4. Devices: Is there a list of who has a company laptop, phone, or key fob, so it can be recovered on exit?
  5. Mailbox and files: Is there a plan for who takes over a departing employee's email and documents?
  6. Access review: Has anyone checked in the last 90 days for accounts that should have been removed but weren't?

Common Questions

What's the biggest offboarding mistake small businesses make?

Treating it as a single step — "turn off their email" — instead of a sequence. Sign-in, mailbox, files, mobile device, physical property, and license all need their own step, and it's easy for one of them to slip through when it's handled from memory instead of a checklist.

Do we need special software to manage onboarding and offboarding?

Not necessarily. A written role-based checklist covers most small offices. Identity management tools become more useful as the number of systems and employees grows, but the checklist habit matters more than the tool.

What happens to a departing employee's email and files?

That's a decision to make before someone leaves, not during their exit conversation. In Microsoft 365, for example, content can be forwarded, reassigned to another employee, or placed under a legal hold if there's a compliance reason to preserve it — each option is set up differently, so it helps to decide in advance which one applies.

How long should we keep a former employee's data?

That depends on your industry's recordkeeping requirements and any pending legal or compliance needs — this varies by business and isn't something a general article can answer for your organization. It's worth deciding as policy rather than case by case.

Is onboarding and offboarding IT access an HR job or an IT job?

Both. HR usually knows the start and end dates first; IT is the one who actually grants or removes access. The businesses that handle this well treat it as a shared checklist with a clear handoff point — HR notifies IT the moment a date is confirmed, not the morning someone's last day arrives.

How Bridge IT Services Helps Massachusetts Businesses

Bridge IT Services, based in Braintree, MA, supports Massachusetts businesses within about 50 miles of our office with managed IT, network, and security support, including help setting up consistent account access for new hires and closing it out completely when someone leaves. If you're not sure every departed employee's access has actually been removed, that's worth a conversation.

Not sure every former employee's access is really gone?

Book a free consultation by phone at (857) 344-0222 or in person at 400 Franklin St, Suite 203, Braintree.

Book a Free Consultation →

This article is general guidance, not a guarantee of security or compliance for any organization. Access and offboarding requirements vary by business — confirm current recommendations in CISA's, NIST's, and Microsoft's published guidance before making decisions for your organization.

Navy-and-orange cover graphic reading Outsourced IT vs. Co-Managed IT: Which Fits You?, with a shield-check icon and the Bridge IT Services wordmark.
September 23, 2026
Outsourced IT replaces day-to-day tech management; co-managed IT supports the staff you already have. See which fits. By Bridge IT in Braintree, MA.
Navy cover graphic with an orange shield and checkmark reading Microsoft 365 Security Checklist for Small Businesses, Bridge IT Services
September 20, 2026
Seven practical steps to secure Microsoft 365 for a small business, from MFA and admin accounts to legacy sign-ins and backups. By Bridge IT in Braintree, MA.
Warning signs your business was hacked — blog illustration
By site-1fJuLQ • April 22, 2026
Worried your business was hacked? Here are 10 warning signs of a cyberattack and what to do next. Bridge IT Services helps South Shore MA businesses stay secure.
Evolution of cybersecurity roles and responsibilities — blog featured image
February 23, 2023
How cybersecurity roles are changing, and the twelve security functions to consider as you build or restructure your team. From Bridge IT Services.
Infographic: 10 practical tips for keeping business data secure
By site-1fJuLQ • February 23, 2023
Ten practical ways to protect business data, from passwords and software updates to Wi-Fi security and employee training. From Bridge IT Services in Braintree, MA.
By site-1fJuLQ • February 13, 2023
What IT support is, how Level 1 and Level 2 help desk tiers work, and why small businesses need it. From Bridge IT Services in Braintree, MA.
February 9, 2023
Cloud providers secure their data centers, but your business still has security work to do. An introduction to cloud security from Bridge IT Services.