← All resources
ArticleIT planning

New employee IT checklist for small businesses in Burnaby and Vancouver

What to set up before someone starts, what to do with them on day one, and what to shut off the day they leave.

Jake, Umbrella IT·August 19, 2026·5 min read

A new bookkeeper starts Monday at your Burnaby office, and on Friday afternoon nobody has made her email account yet. Or someone left three weeks ago and their login still works, because nobody was sure whose job it was to turn it off. A short new employee IT checklist fixes both problems. This one is written for offices of 5 to 25 people in Vancouver and across the Lower Mainland, and it covers the week before someone starts, their first day, and the day they leave.

New employee IT checklist: before day one

Most of the work belongs in the week before the person arrives. If it waits until their first morning, shortcuts get taken, like handing over a shared password “for now.”

  • Create their Microsoft 365 or Google Workspace account and assign a licence. Check that you have a spare licence a few days ahead so you aren’t buying one at 8:45 a.m.
  • Add them to groups based on their role. A new front desk person joins the front desk group and gets the shared drives and mailboxes that come with it. Don’t copy another employee’s access, because that person has probably picked up years of extra permissions nobody remembers granting.
  • Get the laptop ready with updates installed, disk encryption on (BitLocker on Windows, FileVault on a Mac), antivirus running, and the apps for their job. Enrol it in your device management so you can lock or wipe it later if you need to.
  • Set up their phone extension or softphone app, record a voicemail greeting, and add their name to the dial-by-name directory.
  • Add them to your password manager with only the shared vaults their role needs.
  • Book 20 to 30 minutes in their first week for phishing training.

Building access by role also helps with privacy law. BC’s Personal Information Protection Act (PIPA) requires businesses to make reasonable security arrangements to protect the personal information they hold, and that includes information about your own staff. The privacy commissioner’s guide to PIPA lists role-based access, so employees only reach the personal information they need for their duties, and encrypting personal information on laptops as examples of safeguards. A tidy new hire setup covers part of that for you.

Day one: set up MFA in person

Sit with the new person while they turn on multi-factor authentication (MFA), the code or app prompt that appears after the password. Doing it together means the MFA ends up on their own phone and you can watch it work before you leave. If you email instructions instead, it’s easy for that step to slide for weeks, and an account protected by a password alone is much easier to take over.

Then walk them through where files live, how to open the shared mailbox, and how to ask for IT help. Keep the phishing training in the first week while habits are still forming, and leave them with one rule. If an email asks for a password, a code, or a change to payment details, they call the sender at a number they already have before doing anything. Umbrella runs short sessions like this through our technology training service.

Offboarding the same day someone leaves

Offboarding should happen the day the person finishes, ideally within the hour they walk out. For a planned departure, put it in the calendar for their last afternoon. For a termination, do it while the meeting is happening.

In Microsoft 365, blocking sign-in can take up to 24 hours to take effect, so Microsoft’s own steps start with resetting the password and then using “Sign out of all sessions.” Even then, someone who is already signed in can keep working for up to an hour, until their access token runs out.

  • Reset the password, sign them out of all sessions, and block sign-in.
  • Clear their MFA methods so an old phone can’t approve a sign-in.
  • Convert their mailbox to a shared mailbox or forward their email to whoever takes over their clients, and give that person access to their OneDrive files.
  • Remove them from the password manager, then change the shared passwords they knew, starting with ones that don’t sit behind your own sign-in, such as the office Wi-Fi and the alarm code.
  • Collect the laptop, phone, keys and door fob, and wipe or reissue the devices.
  • Take them off vendor portals, online banking, payroll, and any software with its own separate login.

When you convert a Microsoft 365 mailbox to a shared mailbox, the account needs a licence at the moment you convert it, and you shouldn’t delete the old user account afterward because the shared mailbox depends on it. Microsoft also notes that if you don’t reset the password, the old username and password keep working on the shared mailbox. Once it’s converted and under 50 GB, you can remove the licence and stop paying for it.

The logins outside Microsoft 365 are the ones people forget, because each one keeps its own list of users. If the person was set up as a representative on your CRA business account, remove them in My Business Account. The CRA says a representative’s access stays in place until it’s cancelled or reaches an expiry date, and removing it online takes effect right away.

Keep one list for everyone

The simplest fix is a written list that lives in one place and gets used every time. A six-person accounting office in Richmond and a 20-person trades company in Coquitlam need about the same steps, with different apps on the list. If you’re also changing offices, our office move IT checklist covers the equipment side.

At Umbrella, we write our procedures down, so the steps are the same whoever on our Burnaby team picks up the ticket. That’s part of our managed IT support, and the account work sits inside our Microsoft 365 service.

Common questions

How long does it take to set up IT for a new employee?

With a checklist and a spare licence ready, the account, groups and laptop usually take an hour or two a few days before the start date. MFA setup and a walkthrough on day one take about 30 minutes.

Should I delete a former employee’s Microsoft 365 account right away?

Usually not. Reset the password and block sign-in first, then convert or forward the mailbox and move their files. Microsoft keeps a deleted account’s email and OneDrive for 30 days and then removes them, so move what you need before you delete.

Can we give a new hire the same access as the person they replaced?

It’s safer to give access by role. The person leaving has often collected permissions over the years that the new person doesn’t need.

If you’d like someone to look over how your accounts, devices and shared passwords are set up today, you can book a free IT assessment.

Want this checked against your own setup?

Book a free IT assessment and a senior tech will review where your business stands, with no obligation.