← All articles

Your new hire starts Monday. Will their computer be ready before they are?

The new hire has arrived. Their laptop is still in the box, their account does not exist, and nobody knows which access to grant. Here is how to turn that first day of waiting into a professional, productive and secure welcome.

Your new hire starts Monday. Will their computer be ready before they are?

Monday morning, 8:58. The new coordinator is at her desk, ready to start. So is her manager. The computer is still in its box.

By 9:20, someone is hunting for the monitor adapter. By 10:00, her Microsoft 365 account still does not exist. Before lunch she has received three temporary passwords by email, but no access to her team's files. The CRM needs a licence nobody budgeted for. She ends her first day watching a colleague work.

Nobody did their job badly. HR confirmed the hire, the manager prepared the training, and IT reacted as soon as they were told — Friday afternoon.

The problem is not the computer. It is the absence of a process connecting the hire, the responsibilities of the role, and the digital access.

The first day starts before the first day

Successful IT onboarding should trigger the moment a hire is confirmed, not when the person shows up at reception.

IT does not need the employee's full file. It needs specific information:

  • the display name and the desired work address;
  • the date, time and location of the start;
  • the role, the department and the manager;
  • the type of computer and the accessories required;
  • whether the work is on site, remote or hybrid;
  • the applications needed;
  • the groups, folders and teams the person must reach;
  • special needs, such as specialized software or a phone.

A standardized request avoids improvised exchanges along the lines of "give her the same access as Julie." It also provides a real date from which purchasing, licensing and configuration can be planned.

The manager remains essential at this stage. IT knows how to grant access; the manager knows why it is needed.

"The same access as Julie" is not a job description

Copying a colleague's permissions looks efficient. It is also a fast way to reproduce years of exceptions.

Julie may have changed responsibilities, received temporary access that was never removed, or accumulated permissions tied to old projects. Copying her profile hands the new person access they do not need — without anyone knowing which.

Conversely, creating a minimal account and waiting for the employee to request each access turns their first week into a stream of support tickets.

The better approach is to define profiles by role. Someone in sales gets a base set: Microsoft 365, CRM, sales folders, a distribution group and communication tools. Accounting has a different profile. Special access is added separately, with approval from the appropriate owner.

The Canadian Centre for Cyber Security recommends the principle of least privilege: a person receives the minimum functions needed to do their job. Applied properly, it does not slow the employee down. It avoids the choice between too much access on day one and not enough for three weeks.

It is also the best prevention against a problem that surfaces much later. An organization where every hire inherits the previous one's permissions eventually ends up with one person who has accumulated everything — and who becomes, without anyone deciding it, the company's single point of failure .

The computer should know the employee before they arrive

Preparing a laptop should not mean spending the night before manually clicking "Next."

A corporate device should normally arrive with:

  • updates and security settings;
  • disk encryption;
  • protection and monitoring tools;
  • approved applications;
  • Wi-Fi and remote access profiles;
  • the organization's policies;
  • registration in the asset inventory.

Windows Autopilot and Microsoft Intune make it possible to preconfigure that experience. Depending on the environment, the computer can be shipped directly to the employee. When they power it on and sign in with their work identity, the device joins the organization, applies its rules and installs the expected applications.

Careful: "Autopilot" now means two different things

Since 2024, Microsoft offers two distinct solutions, and the choice has real consequences.

Classic Windows Autopilot, often called v1, is the original solution. It covers the widest range of scenarios: hybrid join, pre-provisioning, self-deploying devices, Windows 10, reset.

Windows Autopilot device preparation, sometimes called v2, is a re-architecture. The experience is similar for administrators and users, but the underlying architecture is different. It is not a successor: the two can coexist in one organization, but any given device runs only one of them — and a classic Autopilot profile takes precedence over a device preparation policy.

The difference that matters for a smaller business: device preparation does not require collecting or uploading the device hardware hash. That is friction point number one when you buy laptops from a reseller who does not register them in your tenant. In exchange, this method supports only Microsoft Entra joined deployments, and requires Windows 11 version 24H2 or later.

Practitioner opinion remains divided here. Many recommend keeping classic Autopilot where it already works well, and configuring device preparation as a catch-all — for the cases where obtaining the hardware hash is outside your control. It is a decision to make deliberately, not a box to tick.

None of this is magically automatic: you first have to standardize device models, profiles and software. But once that foundation exists, the company stops rebuilding every workstation as a one-off project.

And if full automation is not warranted for a small team, a standard image, a checklist and a minimum lead time already deliver an enormous improvement.

Digital identity comes before applications

The employee's account is the starting point. It ties together email, Teams, files, groups, licences and, increasingly, the company's other applications.

Before arrival, you need to prepare at least:

  • the Microsoft 365 account and email address;
  • security and distribution groups;
  • the relevant Teams and SharePoint sites;
  • telephony and an extension, if applicable;
  • the appropriate licence;
  • the initial authentication method;
  • registration of a passkey.

This point just changed, and the deadline is close

Until recently, registering a new hire's phone to receive text message codes was standard practice. It is not anymore.

On September 1, 2026, users enabled for SMS or voice in Microsoft Entra are automatically enabled for passkeys and prompted to register one at an upcoming sign-in. On February 1, 2027, SMS and voice stop working entirely as authentication methods.

In practice: onboarding that configures SMS as a second factor this fall is provisioning something that will die within months. Every hire done that way creates a migration to redo later.

So the destination for registration has to be a passkey, not a method of the user's choosing.

The initial password should never travel in the same email chain as the username and the rest of the welcome information. Microsoft Entra's Temporary Access Pass solves this elegantly: it lets the person complete a first sign-in and register their passkey without a permanent password ever circulating. It is the right bootstrap mechanism — provided you aim it at the right destination.

This step is worth a few minutes of guidance. Someone who understands from the start how to sign in, how to report a suspicious request and how to recover their account is less likely to work around the rules when they are in a hurry.

Microsoft 365 is only part of the list

An employee can open Outlook perfectly and still be unable to work.

You also need to think about the CRM, accounting software, payroll, project management, timesheets, a vendor portal, e-signature, the ticketing system, and industry-specific applications.

For each role, a small matrix can capture:

  • the application required;
  • the normal level of access;
  • the licence needed;
  • who approves;
  • the lead time to create it;
  • the sign-in method;
  • the service owner.

That matrix prevents an application from being discovered during training. It also makes role changes easier and prepares for the day access has to be removed. The article on the keys nobody remembers to collect when someone leaves covers the other half of the cycle: a good process has to open the right doors, then close them at the right moment.

Automate the process, not the decision

Onboarding contains plenty of predictable tasks: creating an account, assigning a licence, adding certain groups, notifying the manager and preparing a checklist. Some of it can be automated.

Microsoft Entra offers lifecycle workflows covering three moments: joining, changing roles and leaving. A scenario can trigger before the start date, prepare the identity and notify the manager.

But do the licensing arithmetic before getting excited. These workflows require a Microsoft Entra ID Governance or Microsoft Entra Suite licence. And the decisive point: the licence must be assigned to every user managed by the workflows — meaning the employees being onboarded and offboarded, not just the IT administrators. The going rate is around US$7 per user per month. Organizations already on Entra ID P1 or P2 can buy a Step-Up licence rather than the full standalone one.

For a 30-person company, automating onboarding therefore means licensing 30 people, not two administrators. That is not necessarily unreasonable — but it is not the small expense the word "automation" tends to suggest either.

For many smaller businesses, the best starting point remains a single form connected to a clear procedure. When a hire is confirmed, it can automatically:

  1. create a request for IT;
  2. send the manager the list of access to approve;
  3. reserve a licence and a device;
  4. assign tasks to the right owners;
  5. send a reminder before the start date;
  6. keep a record of what was requested and delivered.

This is exactly the kind of repetitive work discussed in the article on the thousand copy-pastes your team does every week . Automation carries information and watches deadlines. It should not decide on its own that a new employee may see the finances or every customer file.

The welcome kit that fits on one page

A new employee does not need a 40-page technical manual. They need quick answers to the first questions:

  • How do I reach IT support?
  • Where do I save company documents?
  • How do I use my passkey?
  • What do I do with a suspicious email?
  • Can I work from my personal device?
  • How do I reach the tools remotely?
  • Who approves a new application or additional access?

One clear page, matched to the actual environment, will do more good than a generic policy nobody rereads. The manager can then fold those instructions into the human welcome: introducing the team, explaining responsibilities, showing where information lives.

IT prepares the workstation. It does not replace the manager's onboarding.

The 15-minute test before arrival

The day before, someone other than the person who configured the device should verify:

  1. The computer starts and recognizes the right user.
  2. Initial sign-in and strong authentication work.
  3. Essential applications are installed and licensed.
  4. Expected groups, files and teams are reachable.
  5. Camera, headset, monitors and telephony work.
  6. The printer or remote access is available if the role requires it.
  7. Support contact information is visible.

Do not open the employee's personal session on their behalf. The test confirms that the device and the assignments are ready; the person then completes their own first sign-in securely.

The goal is simple: at 9:00, the employee can start their orientation and training — not become the day's first support ticket.

Review access after 30 days

Even an excellent role profile rests on assumptions. After a few weeks, the manager knows which tools are genuinely needed.

A short review lets you remove an unused licence, correct access that is too broad, add a forgotten resource and document a legitimate exception.

This step gained value this year. Microsoft 365 prices rose 12 to 25 percent depending on the plan as of July 1, 2026, and the increase applies at annual contract renewal. A licence assigned and never used now costs appreciably more than it did six months ago. The 30-day review is no longer only a security best practice: it is a line in your budget.

The step matters even more when someone changes departments: new rights should not simply pile on top of the old ones indefinitely.

IT onboarding is therefore not a task that closes when the laptop is handed over. It is the start of a cycle of identity, device and access management.

In closing

The first day sends a message. A ready computer, coherent access and easy-to-reach support tell the new employee: "We knew you were coming and we are ready to work with you."

A day spent waiting for passwords says the opposite — a company where information moves too late and every hire becomes an emergency.

You do not need a large IT team to do better. A clear trigger between HR, the manager and IT, role-based profiles, a checklist and a test before arrival already handle the essentials. Automation then accelerates a process that already works.

The real measure of success is not that the computer was delivered. It is that the person can do their job, productively and securely, from day one.

An IT project or a question?

MMO Techno can structure your onboarding process, standardize your devices and automate identity and access preparation — so every new employee starts with the right tools at the right time.

Talk to an MMO Techno expert .

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us