Devices, patching, joiners and leavers

New Starter IT Setup Checklist: What Should Happen?

A checklist for setting up new joiners without copying old access, missing approvals, or losing track of issued devices.

6 min readOperations teams, office managers, founders

The short answer

A good new starter setup confirms the role, approval, device, account, MFA, groups, software, shared resources, support route, and issued-access record before the first week drifts.

The takeaways

  • Start from the role and manager approval, not from copied access.
  • Record the device, accounts, groups, licences, and software issued.
  • Use the first week to check access is sufficient but not excessive.

What should happen before day one?

  • Confirm legal name, preferred name, job title, manager, start date, and employment type.
  • Choose the role template or list the systems the manager has approved.
  • Confirm which Microsoft 365 licence, mailbox, groups, Teams, SharePoint sites, and shared mailboxes are needed.
  • Prepare the device, asset record, charger, dock, headset, security key, or other accessories.
  • Create the account and apply the correct licence or workspace access.
  • Prepare MFA setup instructions.
  • Schedule first-day remote setup support if needed.

What should the device record include?

  • Device name, serial number, assigned user, and purchase or warranty notes.
  • Operating system and update position before handover.
  • Encryption, screen lock, and endpoint protection status where applicable.
  • Installed core applications.
  • Management tooling only where it is part of the agreed service.
  • Accessories issued and return expectations.
  • Whether the device is the named user's included primary laptop or desktop.

How should account access be assigned?

  • Use named accounts

    Avoid shared user accounts. Named accounts make access review, offboarding, and audit trails easier.

  • Assign groups deliberately

    Use role-based groups where possible and avoid copying another employee's access without review.

  • Protect key accounts

    Microsoft recommends MFA for business accounts, with particular care around administrators and sensitive roles.

What should you review in the first week?

  • Ask the manager to confirm access is correct.
  • Remove any temporary setup access.
  • Check the starter knows how to request support.
  • Confirm MFA is working and recovery details are understood.
  • Confirm the device record and issued-access record are complete.
  • Note any access that should become part of the role template for next time.

Where are Kindura's remote-only limits?

Kindura can help with remote account setup, licence assignment, MFA guidance, device checks where tooling supports them, and joiner workflow records.

Buying hardware, physically imaging devices, posting equipment, desk setup, cabling, printer installation, and hands-on troubleshooting are outside the core remote service unless separately agreed.

Questions to ask any provider

Use these on any onboarding workflow - including ours. The answers should help your managers as well as IT.

  1. What information do you need before day one?
  2. How do you avoid copying another person's access without review?
  3. Which device, licence, groups, and apps will be recorded?
  4. Who handles physical device purchase, shipping, and handover?
  5. What gets checked again during the first week?

Where Kindura fits

Kindura can support the remote setup route

Kindura can help with remote account setup, licence assignment, MFA guidance, device checks where tooling supports them, and joiner records. Hardware buying, imaging, shipping, and desk setup remain outside the core remote service unless separately agreed. Whether or not that suits you, the split should be clear before a start date.