The IT Onboarding and Offboarding Checklist Small Businesses Keep Missing
Orphaned accounts are one of the most common security gaps we find in small businesses. Here's the full identity lifecycle checklist — first day through last day and after.
Ask a small business owner who still has access to their systems and you'll usually get a confident answer. Run an actual audit and you'll usually find something else: a former employee's mailbox still licensed and receiving mail, a contractor's VPN account from a 2023 project, a shared admin login that four people know and one of them left in the spring.
None of this happens through negligence. It happens because employee onboarding and offboarding is a handoff between HR, the manager, and whoever handles IT — and handoffs are where things get dropped.
The fix is a written checklist that runs the same way every time. Here's ours.
Why Orphaned Accounts Are Worth Caring About
Four reasons, in rough order of how often they bite:
- You're paying for it. Licenses for departed staff are one of the most common line-item wastes we find. Small businesses routinely discover they're paying for 8 to 15 more seats than they have people.
- It's a live way in. An account nobody monitors, with a password nobody has rotated, that generates no alerts because nobody notices it logging in. Attackers look specifically for these.
- Data walks out. The window between "gave notice" and "last day" is when client lists, pricing sheets, and CAD files leave — usually copied to a personal cloud account, not on a thumb drive.
- It fails audits. Access reviews are table stakes for cyber insurance renewals, SOC 2, HIPAA, and increasingly for larger customers vetting their vendors.
Onboarding: Before the First Day
The goal is that a new hire sits down to a working computer, not a morning of setup. That means the work happens the week before.
Get the details from HR early: legal name, preferred name, start date, job title, manager, department, work location, and — critically — whose access should this person's access resemble? Role-based templates beat ad-hoc decisions every time.
Provision from a template:
- Create the user account in your identity provider (Microsoft Entra ID or Google Workspace) with a standard naming convention
- Assign licenses based on the role template, not the most generous option
- Add to the right security groups, which should drive file share and app access automatically
- Add to distribution lists, shared mailboxes, and team channels the role requires
- Create accounts in line-of-business apps, ideally through single sign-on
Prepare the device:
- Enroll it in MDM before it's handed over, so policy applies from first boot
- Confirm full-disk encryption is on
- Install endpoint protection and confirm it's reporting in
- Apply all pending updates before delivery, not after
- Set up standard software and printers
Prepare the accounts:
- Require MFA enrollment at first login — a passkey or authenticator app, not SMS
- Set a temporary password delivered through a channel separate from the username
- Enroll the user in the password manager and share only the vaults their role needs
Do not grant local administrator rights by default. Standard user accounts prevent a large share of routine malware from installing successfully, and the exceptions can be handled individually.
Onboarding: Day One and Week One
- Walk through MFA setup in person or on a call, and confirm they have a backup method
- Show them the password manager and how to use it for everything
- Cover the security basics that actually apply to their job: how to report a suspicious email, why nobody from IT will ever ask for their password, and the payment verification rule if they touch invoices
- Register their phone number and location for the phone system, including 911 address if they'll work remotely
- Confirm backups cover whatever they're about to start creating
- Document what was granted. This is the step that makes offboarding possible.
That last point is the whole game. Offboarding is only as good as the record of what was provisioned.
Offboarding: The Same-Day List
The critical distinction: disable, don't delete. Deleting an account destroys mail, files, and audit history you may need — sometimes urgently, sometimes for a legal matter you don't know about yet.
Run this on the last day, and for an involuntary termination, run it during the conversation, not after:
- Disable the account in the identity provider
- Revoke all active sessions and refresh tokens. A disabled account with a live session token can keep working for hours. This is a separate action from disabling, and it's the step most often missed.
- Reset the password and remove registered MFA devices
- Revoke API keys, app passwords, and OAuth grants the user issued
- Convert the mailbox to a shared mailbox or apply a hold, and forward incoming mail to the manager
- Transfer ownership of cloud files, calendars, and documents to the manager before anything is archived
- Remove from distribution lists, shared mailboxes, group chats, and on-call rotations
- Disable VPN and remote access, including any certificates issued to their devices
- Retrieve or wipe devices. For company hardware, collect it. For BYOD under MDM, use a selective wipe that removes company data and leaves personal photos alone.
- Rotate shared credentials they knew — Wi-Fi PSKs, admin passwords, the alarm code, the safe combination, service accounts
- Reassign licenses rather than leaving them attached
- Forward the phone extension and update the auto attendant and directory
Offboarding: The Accounts Outside Your Identity Provider
This is where nearly every gap lives. Anything not behind single sign-on has to be handled by hand, and nobody has a complete list — which is exactly why you build one now rather than during someone's exit.
Work through:
- Financial systems: accounting software, payroll, banking portals, expense tools, corporate cards
- Vendor and supplier portals, including anywhere they were listed as the authorized contact
- The domain registrar and DNS provider. If the person who left is the registrant contact on your domain, fix that today, not at renewal.
- Website, CMS, and hosting admin accounts
- Social media, Google Business Profile, and review platforms
- CRM, marketing platforms, and mailing list tools
- Any SaaS purchased on a departmental credit card that IT never knew about
- Physical access: keys, badges, fobs, alarm codes, and the padlock on the server rack
Also handle the paperwork side: confirm any signed confidentiality or IP agreements are on file, and if you're planning to hold anything back from a final paycheck for unreturned equipment, check with employment counsel first — Colorado has specific rules about deductions from final pay.
The 30-Day Follow-Up Nobody Does
Put a task 30 days out to verify:
- No sign-in attempts on the disabled account (if there are, you have a live incident, not a housekeeping item)
- No mail is still forwarding externally
- Licenses were actually reclaimed and the bill went down
- The device came back and was wiped and reissued
- Retention decisions were made about the mailbox and files before anything auto-deletes
Then, quarterly, run a full access review: every account in every system, matched against the current employee roster. Every business we do this for finds something. Usually several things.
Make It Boring and Automatic
Three things turn this from a good intention into a process that survives a busy quarter:
One written checklist, stored where HR and IT both see it, run identically every time.
Role templates, so provisioning is "marketing coordinator" rather than a series of individual judgment calls that drift over the years.
Single sign-on for everything possible. The fewer accounts that live outside your identity provider, the shorter your manual list gets — and disabling one account genuinely closes most doors.
For the broader security context these steps sit inside, see our complete guide to cybersecurity for small businesses.
Frequently Asked Questions
How fast does offboarding need to happen? Same day for a voluntary departure. Simultaneous with the conversation for an involuntary one — HR and IT coordinated to the minute.
Should we delete a former employee's mailbox? Not right away. Convert it to a shared mailbox or apply a retention hold. Decide on deletion after your retention period, and never during an active dispute or legal matter.
What about contractors and temporary staff? Same process, plus a hard expiration date on the account set at creation. Accounts that expire automatically don't become orphans.
We're 12 people. Is this overkill? The list is shorter at 12 people, but every item still applies — and the risk is proportionally higher, because at 12 people one departure often takes a large share of institutional access with it.
Want Someone to Own This?
Identity lifecycle is exactly the kind of work that's straightforward when someone owns it and quietly dangerous when nobody does.
netkraft builds and runs onboarding and offboarding processes for Denver-area small businesses — role templates, same-day offboarding, quarterly access reviews, and the license cleanup that usually pays for a chunk of the engagement.
Contact netkraft to review who currently has access to your systems, or read more about our managed IT support and cybersecurity services.