A secure checklist for staff joining and leaving

People joining and leaving are normal business events, but access is often handled through hurried messages and memory. This guide gives small businesses a practical checklist for both. It covers what to prepare for a joiner and, just as importantly, how to close access properly when someone leaves so business information does not remain available to the wrong person.
Make one person own the process
HR or a manager should notify the person responsible for IT as soon as a start date, role change or leaving date is known. Use one checklist that records who requested access, who approved it, what was issued and when it was completed. Do not let a line manager email "please set them up like Jane" and treat that as the access plan.
Prepare the account and licence for a joiner
Step 1: create only the accounts they need
Create the employee's named account using your chosen naming convention. Assign the correct Microsoft 365 licence, email address, groups and shared mailboxes for the role. Do not share an old employee account or reuse their password. If an account needs access to a business application, create a named user there too so actions can be traced to the person who performed them.
Ask the manager to approve the access list before it is granted. A sales person may need CRM and a sales mailbox; they do not automatically need finance folders, server administration or the payroll system. This is least privilege: give enough access to do the job, and no more. It reduces mistakes as well as the damage from a compromised account.
Step 2: set up security before day one
Require a strong, unique password and MFA when the account is created. Do not send a permanent password over ordinary email. Arrange a first sign-in process where the employee sets their own password and registers an authenticator app, or better still a passkey. Day one is the easiest moment to get this right, because there is no old habit to undo. Make sure their laptop has current updates, disk encryption where available, endpoint protection and a standard user account for everyday use.
For Microsoft 365, use the controls in our Microsoft 365 security checklist as the baseline. If someone genuinely needs administrator rights, use a separate protected account and record the reason. Ordinary work should never need a Global Administrator account. Confirm that recovery phone numbers and secondary sign-in methods belong to the business process, not an unrecorded personal arrangement.
Issue equipment with a clear record
Prepare the laptop, charger, dock, monitor, phone, headset and access fob before the start date. Record serial numbers, condition, accessories and recipient. Configure WiFi, printing and required applications in advance. Give a short setup session on day one.
Give a short security induction
Explain how to report a suspicious email, lost device, unexpected MFA prompt or possible mistake. Show the person where approved passwords, policies and IT support contacts are kept. Cover phishing, password managers, locking screens, safe file sharing and supplier impersonation. The aim is quick, normal reporting.
Treat a leaver as an access deadline
An ex-employee with live access is a real risk, even when everybody parts on good terms. Their mailbox may receive customer information, their cloud storage may still contain files and their saved browser sessions may still work. In a difficult departure, access can be misused deliberately; in an ordinary departure, it can be forgotten and later exposed through a lost or reused device.
Disable, revoke and preserve what is needed
Step 1: stop live access
Disable the user account rather than deleting it straight away. Revoking sign-in sessions and MFA tokens prevents existing browser sessions or registered methods being used after the account is blocked. Remove the person from security groups, shared mailboxes, distribution lists, Teams, SharePoint sites, VPN access, remote management tools and any administrator role. Check that automatic mailbox forwarding has not been set.
Step 2: handle email and files properly
Agree what happens to the mailbox. You may need a manager to review it for a limited period, an automatic reply that directs senders to a new contact, or a shared mailbox for continuity. Tell customers the correct route without pretending the former employee is still there. Preserve records in line with your retention needs and remove personal material sensitively.
Transfer ownership of business files, calendars, contacts and shared documents before removing the licence or deleting data. Check shared folders and cloud applications where the leaver may have been the only owner. Do not make a rushed deletion that loses a project handover. A tested business data backup arrangement provides another layer of protection, but it does not replace orderly ownership transfer.
Recover equipment and change shared secrets
Collect laptops, phones, badges, keys, tokens, chargers, paper records and any backup media. Compare everything with the asset record and arrange remote lock or wipe for a device that is not returned. Inspect returned equipment before issuing it to someone else. Remove company data from personal devices where your policy and management controls allow.
Change any shared password, PIN, WiFi key, alarm code, safe code or supplier login the person knew. This is easy to miss because shared credentials are often not on the normal user account list. Better still, replace shared passwords over time with named accounts and a password manager. The same principle applies to guest WiFi and physical access; see our access control guidance when reviewing fobs and entry permissions.
Review access after the change
Ask the manager a week later whether the team can still reach the files, mailbox and systems needed for work. Review licence counts, administrator roles and group memberships. Look for external guests or service accounts that were added as a shortcut during the handover. Update the asset register and record any missing device or unfinished action.
What to do next
Turn this guide into a checklist with named owners, then test it with the next planned joiner or leaver. Begin with timely notification, least-privilege access and a firm process for disabling sessions when employment ends. TSS can offer a free, no-obligation chat to help businesses in Bury, Greater Manchester and Lancashire put a workable process in place.
Need a safer staff access process?
Book a free, no-obligation chat and we will help you turn these checks into a workable routine.