Device Onboarding Offboarding Checklist | IT Guide

Device Onboarding and Offboarding Checklist for Small IT Teams
An offboarding checklist (and its twin, IT onboarding) is how a small IT team gets a new hire productive on day one and removes every account, device, and token when someone leaves — without relying on memory. This device onboarding and offboarding checklist is for IT managers at roughly 20–100 person companies: what to provision, what to revoke, who owns each step, and a light joiners–movers–leavers process you can run in under an hour.
What is a device onboarding and offboarding checklist?
A device onboarding checklist is the short list of identity, hardware, and access steps that get a new starter onto company systems on day one. An offboarding checklist is the matching list that runs the day someone leaves: disable identity, recover the laptop and phone, revoke tokens, and reassign data. Together they are the IT half of a joiner mover leaver process — not an HR handbook.
At this size you do not need an IAM suite to make it work. You need a written IT onboarding checklist, a same-day IT offboarding checklist, one asset tracker (a sheet is fine), and named owners. The new hire IT checklist covers email / SSO, MFA, the approved app list, disk encryption, MDM enrolment, and a recorded asset tag. The employee offboarding checklist covers the reverse: SSO first, then MFA devices, API keys, hardware, seats, groups, and calling access.
The point is repeatability. If the only record of a leaver is a Slack message to “turn them off,” you will miss a token, a shared admin password, or an extension. If the only record of a joiner is “order a laptop,” they will sit idle while MFA, files, and a work number get sorted ad hoc.
When do you need a joiner–mover–leaver process (not just a new-laptop ticket)?
A new-laptop ticket is a hardware request. A joiner mover leaver process is the whole path: who they are, what they can reach, which device they hold, and what happens when the role or the person changes.
Run the full process — not just a procurement ticket — when any of these are true:
- You hire more than a couple of people a quarter, or people leave without a clean hand-back.
- Staff work remote or hybrid, so devices leave the building and remote-work rules sit next to identity. Keep this aligned with your IT manager remote work checklist.
- People change team or role (movers) and keep old access “just in case.”
- You already have SSO or are rolling out MFA — joiners and leavers are how those controls stay honest. Pair enrolment with your MFA rollout for small business.
- You have more than a handful of SaaS seats and no one is sure who owns them after a departure. That is the same hygiene as SaaS vendor evaluation and shadow IT: named tools, named owners, no leftover accounts.
A ticket that only says “MacBook for start date” will not create the identity, will not enrol MFA, will not assign the approved stack, and will not tell you who recovers the kit six months later. Write the process once; reuse it every joiner, mover, and leaver.
What should day-one device onboarding cover?
Day one is verification, not shopping. The laptop should already be imaged or shipped. Identity and MFA should already exist. The new hire IT checklist on the morning they start is: can they sign in, is the device enrolled, can they reach email, chat, and files, and is the work calling app company-managed rather than a personal WhatsApp default.
Do the heavy lift before day one. Confirm start date, manager, and role, and whether they need a laptop, a phone, or both. Create the identity (email / SSO) and send MFA enrolment steps — not a vague “set up 2FA later.” Assign baseline apps from the approved list, not whatever the last team sideloaded. Image or ship the device with disk encryption, MDM enrolment, and a named owner ticket. Prep a one-screen welcome: how to sign in, who to ping, and where the remote-work rules live.
Before day one (joiner)
- Confirm start date, manager, role, and whether they need a laptop, phone, or both.
- Create the identity (email / SSO) and add MFA enrollment steps — see the MFA rollout for small business.
- Assign baseline apps from the approved list — not whatever the team already sideloaded (tie this to shadow IT and SaaS vendor evaluation).
- Image or ship the device with disk encryption, MDM/enrolment, and a named owner ticket.
- Prep a day-one welcome note: how to sign in, who to ping, and where the remote-work rules live (your remote work checklist).
Day one (joiner)
- Verify SSO login + MFA works before handing over other tools.
- Confirm laptop/phone enrolment and that the user can reach email, chat, and files.
- Walk through the approved softphone / calling app if they take customer or internal calls — company-managed on sessiontalk.io, not a personal WhatsApp default.
- Record asset tag, serial, and assignee in one tracker (a sheet is fine under ~100 people).
- Schedule a 7-day check: access gaps, unused seats, shadow tools already appearing.
That is the whole IT onboarding checklist for device onboarding. If step 6 fails, stop and fix identity before you dump them into ten more apps.

What must an employee offboarding checklist revoke the same day?
An employee offboarding checklist is a same-day job. The last working hour is the deadline, not “sometime this week.” Disable the primary identity first — that kills most SaaS access in one step — then chase anything that identity does not cover: MFA devices, API tokens, personal access keys, shared admin passwords, hardware, seats, groups, and calling.
Order matters. If you recover the laptop first and leave SSO live, a phone in their pocket can still reach email and files. If you disable SSO but leave a personal access token or a shared mailbox password, you have only half-offboarded them.
Same-day leaver (offboarding checklist)
- Disable SSO / primary identity first (kills most SaaS access in one step).
- Revoke MFA devices, API tokens, personal access keys, and shared admin passwords.
- Recover laptop, phone, badges, and tokens; wipe or re-image before reissue.
- Transfer mailbox / files ownership; cancel or reassign SaaS seats (tie leftovers to your vendor evaluation list).
- Remove from groups, distribution lists, on-call, and any out-of-hours rota.
- Confirm softphone / SIP / calling access is gone the same day — no orphaned extensions.
- Close with a one-line log: who left, what was recovered, who owns residual data, review date.
That is the IT offboarding checklist. Do not skip the log. The next person who asks “did we get the laptop back?” should find the answer in one line, not in three Slack threads.
How do movers (role or team changes) differ from joiners and leavers?
Movers are not “a bit of both.” A joiner needs everything added. A leaver needs everything removed. A mover needs the new role’s access, and only then a timed removal of what the old role no longer needs. If you strip old access first, they cannot do the job. If you never strip it, they collect privileges for years.
Time-box overlap. Forty-eight hours is a reasonable default when handover is real; “until we remember” is not. Re-check device policy (BYOD vs company laptop) and calling needs for the new role — a mover into customer support may need a company-managed softphone they did not have in finance.
Movers (role or team change)
- Add new access before removing old only when overlap is required; time-box the overlap (e.g. 48 hours).
- Re-check device policy (BYOD vs company) and calling needs for the new role.
- Update the asset + seat tracker the same day as the change.

How do phones and softphones fit the same checklist?
Phones are devices and calling apps are SaaS. Treat them as both. On join, decide laptop, phone, or both; enrol the handset or the softphone under the company identity; record the asset or seat. On leave, recover the handset, wipe it, and kill the softphone / SIP login the same day so you do not leave an orphaned extension on a personal mobile.
Personal consumer apps are the usual hole. A new hire who “just uses WhatsApp for work calls” is shadow IT with a phone number attached — unknown offboarding, no MFA on the work identity, and a number that leaves with them. Prefer company-managed softphones so access follows employment. Where calling is in scope, review options on sessiontalk.io — desktop softphone, iOS & Android softphone, and softphone pricing — then run the same joiner and leaver steps: identity, MFA, seat, and a same-day revoke.
If the leaver sat on an after-hours rota, remove them from that path the same day or the next overnight queue will still ring a dead account. Document that step next to your out-of-hours call handling process so offboarding does not silently break cover.
FAQ
What is an IT offboarding checklist?
A same-day list of identity, device, SaaS, and recovery steps so a leaver cannot keep access after their last working hour.
How is device onboarding different from HR onboarding?
HR covers contracts and culture. Device / IT onboarding covers identity, hardware, MFA, approved apps, and how the person reaches work systems on day one.
What should always happen the day someone leaves?
Disable SSO first, revoke tokens and MFA, recover devices, reassign data and seats, and remove calling access — then log it.
Do we need a full IAM suite?
Not under ~100 people. A written checklist, SSO, MFA, and one asset tracker beats an unused enterprise tool.
Where do softphones fit?
Same joiner/leaver steps as any other work app. Prefer company-managed softphones on sessiontalk.io so access follows employment, not a personal phone number.


