Employee IT Onboarding Checklist for Dubai Businesses

A new employee’s first working day should not begin with several hours spent waiting for a laptop, email account or access to essential files.

Employee IT onboarding and offboarding checklist for a Dubai business

Similarly, an employee’s final day should not end while their cloud applications, remote access and company data remain available indefinitely.

Employee onboarding and offboarding are sometimes treated as administrative tasks handled mainly by HR. However, almost every employee now receives access to technology that affects the wider business:

  • Email and calendars
  • Laptops and mobile devices
  • Shared files
  • Cloud applications
  • Customer records
  • Finance or HR platforms
  • Social-media accounts
  • Remote-access systems
  • Office Wi-Fi
  • Business communication tools

Managing this access requires coordination between HR, the employee’s manager and whoever is responsible for IT.

A documented process helps the employee become productive without granting unnecessary access. It also gives the business a reliable method for removing access, recovering equipment and transferring important information when someone changes roles or leaves.

Manage Joiners, Movers and Leavers Together

Employee access should be managed as one continuous lifecycle.

Joiner

A new employee receives the accounts, equipment and permissions required for their role.

Mover

An existing employee changes department, location, responsibilities or seniority. Their existing access must be reviewed rather than simply adding more permissions.

Leaver

An employee, contractor or temporary worker leaves the organisation. Access must be withdrawn and company property recovered.

This joiner–mover–leaver model prevents access from accumulating without review.

An employee who moves from accounts to sales may no longer need finance-system access. A temporary project worker may retain an active account long after the project ends. Someone promoted to management may receive new permissions without outdated access being removed.

The UK National Cyber Security Centre recommends including joiners, movers and leavers in account-management processes so permissions can be changed or revoked when they are no longer required. Its guidance also recommends removing temporary accounts when their purpose ends. Review the NCSC identity and access-management guidance.

Assign Clear Responsibility

The process should define who approves, creates, verifies and closes employee access.

HR should confirm:

  • Employee’s full name
  • Job title
  • Department
  • Manager
  • Joining date
  • Employment status
  • Expected final day
  • Whether the departure is planned or urgent

The employee’s manager should approve:

  • Required applications
  • Shared folders
  • Customer or project access
  • Department groups
  • Device requirements
  • Administrative privileges
  • Access duration for temporary workers

The IT administrator should handle:

  • Device preparation
  • Account creation
  • Security settings
  • Access assignment
  • Technical testing
  • Equipment records
  • Session termination
  • Account suspension
  • Device recovery

No account should be created solely from an informal chat message. A consistent request and approval record reduces misunderstandings later.

Create a Pre-Onboarding Request

The manager should submit the employee’s technology requirements before the joining date.

Record:

  • Employee name and role
  • Start date
  • Work location
  • Manager
  • Laptop or desktop requirement
  • Mobile-device requirement
  • Email address
  • Applications needed
  • File and folder access
  • Department distribution lists
  • Remote-access requirement
  • Special hardware or accessibility requirements
  • Person approving the access

Avoid copying every permission from another employee without reviewing it.

Two people with similar job titles may handle different customers, systems or confidential information. Use an existing employee’s access as a reference, not as automatic approval.

Businesses expecting regular hiring should include devices and software licences in their IT budget planning for employee growth.

Prepare and Record the Employee’s Device

A laptop should be prepared before it reaches the employee.

The preparation checklist can include:

  • Record manufacturer, model and serial number
  • Assign an internal asset number
  • Record the employee receiving the device
  • Install operating-system updates
  • Enable device encryption where supported
  • Install approved business software
  • Configure security protection
  • Remove unnecessary applications
  • Test the camera, microphone and charging equipment
  • Confirm Wi-Fi and remote-access connectivity
  • Apply automatic screen locking
  • Create a standard user account
  • Limit administrator access
  • Record warranty information
  • Include the charger and approved accessories

The business should retain an equipment handover record showing the device’s condition and the items supplied.

This is not only for resolving disputes. It helps the organisation locate equipment, schedule replacements and identify devices that still contain company information.

Create Individual Accounts

Every employee should normally receive an individual account.

Avoid shared accounts such as:

  • sales@company
  • admin
  • officeuser
  • marketingteam

A shared address may be useful for receiving messages, but each person should access it through their own identity wherever the platform allows.

Individual accounts provide better visibility into:

  • Who accessed a system
  • Who changed a file
  • Which person approved an action
  • When access was used
  • Which account must be disabled when someone leaves

Administrative accounts should not be used for normal email, browsing or daily document work.

Apply Role-Based Access

Employees should receive the access needed for their responsibilities without automatically receiving access to everything.

For each system, ask:

  1. Does the employee genuinely require access?
  2. Should the access be view-only or allow editing?
  3. Does the employee need the complete system or one section?
  4. Is the information confidential?
  5. Who approved the permission?
  6. Should the access expire automatically?
  7. Does the employee need administrative control?

Start with the minimum practical access and add permissions through approval when required.

This approach is especially important for finance, payroll, customer records, website administration, advertising accounts and cloud infrastructure.

Protect Important Accounts With MFA

Enable multi-factor authentication for supported business applications, especially:

  • Email
  • Cloud storage
  • Remote access
  • Finance systems
  • Website administration
  • Social-media accounts
  • Advertising platforms
  • Administrator accounts

CISA recommends enabling MFA across systems such as email, file storage and remote access, beginning with administrators and employees who handle sensitive data. It also recommends phishing-resistant methods when supported. Read CISA’s official MFA guidance for businesses.

Recovery methods must belong to the business or remain manageable by it. Avoid depending only on an employee’s personal phone number or personal email address for recovering an important company account.

Record which department controls recovery and what should happen if the employee loses their authentication device.

Configure Email and Communication Access

Before the first day, confirm:

  • Email address works
  • Display name is correct
  • Calendar is available
  • Relevant distribution lists are assigned
  • Shared mailbox access is approved
  • Business signature follows the company format
  • Meeting and chat applications work
  • Spam reporting is available
  • External forwarding is restricted if required

Do not automatically forward a former employee’s complete mailbox to another person without management approval and a defined period.

Email may contain confidential conversations and personal information. Access and retention should follow the organisation’s policies and applicable requirements.

Provide Access to Files and Applications

Create a list of the applications connected to each role.

Possible categories include:

  • Productivity software
  • Cloud storage
  • CRM
  • Accounting
  • HR and payroll
  • Project management
  • Customer support
  • Marketing platforms
  • Website management
  • POS or inventory
  • Industry-specific applications

For shared files, use company-managed folders rather than storing important documents only inside an employee’s personal workspace.

Confirm whether the employee can:

  • View files
  • Edit files
  • Delete information
  • Share externally
  • Download to personal devices
  • Change folder permissions

Access should reflect the sensitivity of the information and the employee’s responsibilities.

Include a Short Security Orientation

The employee should understand the company’s basic technology rules.

Cover:

  • How to create and manage secure credentials
  • Why accounts must not be shared
  • How MFA works
  • How to identify suspicious messages
  • How to report a lost device
  • Whether personal software may be installed
  • Rules for external file sharing
  • Approved cloud-storage locations
  • Remote-working requirements
  • How to report a technical or security incident
  • Who to contact for support

The session does not need to overwhelm the employee with technical terminology. It should explain what they are expected to do when something looks wrong.

Test Access Before the Employee Starts

Use a simple first-day test:

  • Sign in to the device
  • Open email and calendar
  • Join a test meeting
  • Access approved shared folders
  • Open required applications
  • Test printing where necessary
  • Confirm office Wi-Fi access
  • Test VPN or remote access
  • Verify MFA
  • Confirm the support contact

Do not send the employee their password through the same email account the password protects. Use an approved secure handover method and require a password change where appropriate.

A structured IT support process can also define how onboarding problems are recorded and resolved.

Review Access When an Employee Changes Roles

Role changes are easily overlooked because the employee is not leaving the company.

When someone changes responsibilities:

  1. Record the effective date.
  2. Identify the access required for the new role.
  3. Review every existing permission.
  4. Remove access that is no longer justified.
  5. Add newly approved access.
  6. Update department and communication groups.
  7. Review administrative privileges.
  8. Confirm equipment requirements.
  9. Document completion.

Do not treat a promotion as permission to retain every previous access while adding more.

The manager responsible for the new role should approve the final access list.

Begin Offboarding With a Confirmed Instruction

The IT team needs a confirmed departure instruction containing:

  • Employee name
  • Final working date
  • Access cutoff time
  • Manager
  • Equipment assigned
  • Systems used
  • Data-transfer requirements
  • Email-handling instruction
  • Whether the departure is normal or urgent

For a planned departure, prepare the checklist before the final day.

For an urgent or sensitive departure, HR, management and IT may need to coordinate the access cutoff precisely. Avoid announcing or changing access before authorised confirmation.

Disable Access at the Correct Time

The offboarding checklist should cover more than the employee’s primary email.

Review:

  • Email and calendar
  • Cloud storage
  • VPN
  • Remote desktop
  • CRM
  • Finance and HR platforms
  • Website administration
  • Social-media access
  • Advertising accounts
  • Project-management tools
  • Support systems
  • Developer platforms
  • Password manager
  • Building and door access
  • Office Wi-Fi credentials
  • Supplier portals
  • Company mobile services
  • Third-party applications

Where supported, revoke active sessions and authentication tokens. Changing a password may not terminate every session that is already signed in.

For important cloud services, integrate account removal with the joiner–mover–leaver process. The NCSC specifically advises updating cloud access when personnel change roles and removing it when they leave. See its cloud-platform security guidance.

Preserve Business Data Before Deleting Accounts

Do not immediately delete the employee’s account.

First determine:

  • Which business files they own
  • Whether shared documents depend on their account
  • Which calendars require transfer
  • Whether customer conversations must be retained
  • Who will own ongoing projects
  • Whether automated workflows use the account
  • Whether website or form notifications go to their address
  • Whether retention requirements apply

Transfer ownership or preserve necessary data according to company policy.

Backing up company information should be part of a wider business data backup and recovery plan, not an improvised action performed only when someone leaves.

Recover and Inspect Company Equipment

Collect:

  • Laptop or desktop
  • Mobile phone
  • Charger
  • Monitor
  • Storage devices
  • Security token
  • SIM card
  • Access card
  • Keys
  • Special equipment
  • Printed confidential material

Compare returned equipment with the asset record.

Before assigning a returned device to someone else:

  • Preserve authorised business data
  • Remove the former employee’s access
  • Sign out active accounts
  • Perform an approved reset or reinstallation
  • Install updates
  • Inspect physical condition
  • Update the asset record
  • Test the device

Do not give a device directly from one employee to another while the previous user’s files and sessions remain available.

Review Shared Credentials and Integrations

Shared passwords should be avoided where individual access is available.

If the departing employee knew credentials that cannot be individually revoked, change them.

Check:

  • Shared administrator passwords
  • Router or network credentials
  • Website hosting
  • Domain management
  • API keys
  • Software licence portals
  • Social-media credentials
  • Payment or supplier portals
  • Backup administration
  • Automation accounts

Do not rotate every company password automatically. Identify which secrets the employee could access and update those through a controlled process.

Document Completion

A completed offboarding record should show:

  • Access disabled
  • Sessions revoked
  • Equipment returned
  • Data ownership transferred
  • Email handling approved
  • Shared credentials reviewed
  • Building access removed
  • Manager confirmation received
  • Person completing each action
  • Completion date and time
  • Unresolved items

This record allows management to verify that offboarding was completed rather than assuming somebody else handled it.

Common Onboarding and Offboarding Mistakes

Avoid:

  • Preparing the laptop on the employee’s first morning
  • Giving every new employee the same access
  • Using shared administrator accounts
  • Sending passwords through unsecured messages
  • Depending on personal recovery email addresses
  • Ignoring contractors and temporary workers
  • Adding access after a role change without removing old permissions
  • Deleting accounts before transferring business files
  • Disabling email but forgetting other cloud applications
  • Allowing former employees to retain remote access
  • Reassigning devices without resetting them
  • Failing to collect chargers, tokens and access cards
  • Keeping temporary accounts active indefinitely
  • Completing the process without a written record

Expert Commentary: Treat Access as an Inventory

In practical website, advertising and business-technology work, I treat employee access like an asset inventory.

It should be possible to answer three questions:

  1. Who has access?
  2. Why do they have it?
  3. Who approved it?

This becomes particularly important for websites, advertising platforms and analytics accounts. Access is often granted for a temporary task but remains active because nobody records an end date.

A reliable process does not depend on one administrator remembering every application. It uses a role-based checklist, an account register and a confirmed completion record.

The objective is not to make onboarding unnecessarily restrictive. It is to give employees the access they need while keeping ownership and responsibility clear.

Employee Technology Lifecycle Checklist

Before the employee joins

  • Confirm role, manager and start date
  • Approve applications and folders
  • Prepare and record the device
  • Create individual accounts
  • Enable MFA
  • Configure email and communication tools
  • Test required access
  • Prepare the security orientation

When the employee changes roles

  • Review current access
  • Remove outdated permissions
  • Approve new permissions
  • Update groups and applications
  • Review administrator privileges
  • Document completion

When the employee leaves

  • Confirm the access cutoff time
  • Disable all relevant accounts
  • Revoke active sessions
  • Remove remote access
  • Transfer business data
  • Recover company equipment
  • Review shared credentials
  • Remove physical access
  • Preserve required records
  • Obtain manager confirmation

Final Thoughts

Employee onboarding and offboarding should not be managed as separate last-minute tasks.

They are parts of the same process: granting appropriate access, reviewing it when responsibilities change and removing it when no longer required.

Start with a clear request from HR and the employee’s manager. Prepare devices and accounts before the first day, use individual identities, enable suitable security controls and document every important permission.

When someone leaves, coordinate the cutoff time, disable all relevant systems, recover equipment and transfer business information before deleting anything.

A consistent process improves the employee experience while giving the business clearer control over its devices, accounts and data.

Frequently Asked Questions

What should be included in a new employee IT checklist?

Include device preparation, email, required applications, shared folders, MFA, remote access, communication tools, security orientation and first-day testing.

When should a new employee’s accounts be created?

Create and test them before the joining date, but activate or provide access according to the organisation’s approved start-time policy.

Should every employee receive administrator access?

No. Administrator permissions should be provided only when justified by the employee’s responsibilities. Standard accounts are more appropriate for normal daily work.

What happens to an employee’s email after they leave?

The account can initially be disabled while authorised business data and messages are handled according to company policy. Any forwarding or delegated access should be approved and time-limited.

Should an employee’s account be deleted immediately?

Usually not. First transfer required files, calendar ownership, workflow dependencies and business records. Deletion should follow the organisation’s retention process.

What is a mover process?

A mover process reviews an employee’s technology access when they change roles. Unneeded permissions are removed and newly required access is approved.

Should contractors follow the same offboarding process?

Yes. Contractors, temporary staff, interns and external partners may hold devices or system access and should have defined start and expiry dates.

How often should employee access be reviewed?

Review it when roles change and periodically for important systems. Temporary access and privileged permissions deserve particular attention.

Comments