Start with the role, not the laptop
A reliable onboarding process begins with what the person will do, where they will work and which information they should access. Copying the previous employee's permissions is quick, but it can quietly give a new starter far more access than their role requires.
- Job role and manager
- Office, remote or hybrid location
- Required Microsoft 365 groups and shared mailboxes
- Business applications, files and printers
- Any privileged or sensitive access
Create the identity securely
Create an individual account rather than sharing credentials. Apply the correct licence, groups and access policies, then make multi-factor authentication part of the first sign-in process.
- Use a named user account
- Assign only the required licences and groups
- Require multi-factor authentication
- Keep administrator access separate from everyday work
- Record who approved the access
Build the laptop for your environment
The device should be prepared against a documented company standard. That makes support easier, improves security and gives every employee a consistent experience.
- Install supported Windows updates and firmware
- Join the device to Microsoft Entra ID or the approved directory
- Enable device encryption and endpoint protection
- Configure Microsoft 365, OneDrive, SharePoint and Teams
- Install role-specific applications, VPNs and printers
- Remove unnecessary software and local administrator rights
- Record the device in the asset register
Make day one human
Good onboarding is not only technical. Give the new starter a short introduction to support, security expectations, password and MFA processes, file locations and how to report a suspicious email. A ten-minute explanation can prevent weeks of confusion.
Wrexham Tech Support can create a repeatable onboarding standard and prepare laptops around your specific environment.
