IT Operations · Production Runbook

The Production IT Operations Runbook: Employee Onboarding & 30-Day Security Audit

Standard Operating Procedures (SOP) for Sysadmins, IT Engineers, and Managed Service Providers.

Version 1.2Joiner · Audit · LeaverInteractive checklist + PDF

Why a repeatable onboarding runbook matters

Ad-hoc onboarding turns a straightforward people change into a chain of undocumented exceptions. A missed approval can leave a new hire with excessive access; a rushed laptop handover can expose an unencrypted endpoint; and an account created outside the normal request path can be invisible to access reviews. These gaps create avoidable compliance findings and make it difficult to prove who approved access, when a device was secured, or whether a license was reclaimed.

Inconsistent provisioning also wastes money. Teams buy duplicate subscriptions, assign premium seats without role justification, and forget to reclaim licenses after a departure. Meanwhile, credentials shared in chat or reused from a temporary password can linger long after the first login. This SOP ties each action to an owner, a verification step, and durable evidence so the process is secure, auditable, and practical for both internal IT teams and MSP service desks.

Use the first three phases for every joiner, adapting named platforms to your environment. Phase 4 is the linked emergency leaver procedure: execute it when employment ends or access must be revoked immediately. Record exceptions in the service ticket, name an approver, and set an expiry before any exception is granted.

1 Before the start date

Phase 1: Pre-Day 1 Hardware & Identity Provisioning

Start from an approved HR or manager request containing the employee’s legal name, start date, manager, department, location, role, and approved access profile. Use that request as the source of truth; do not infer elevated access from a job title. Assign the endpoint and identity work to named owners early enough to resolve stock, licensing, or approval issues before the employee arrives.

Prepare a known-good, attributable endpoint

  • Asset tagging in the CMDB: Assign a unique asset identifier and record serial number, make/model, assigned user, purchase/warranty details, location, and lifecycle status. Apply the physical tag and reconcile the device record against the actual hardware before release.
  • Clean OS deployment: Provision from the organization’s approved, supported image or zero-touch enrollment profile. Apply the current security baseline, remove stale local accounts and unapproved software, confirm time synchronization, and record the build or enrollment result.
  • BitLocker/FileVault key escrow: Enable full-disk encryption before user data is placed on the device. Verify the recovery key has escrowed to the approved Entra ID, AD, or MDM repository and that authorized recovery staff can retrieve it; never place recovery secrets in the asset notes or ticket.
  • EDR/RMM agent verification: Confirm the endpoint appears in the correct tenant, reports healthy and current, and is assigned the intended policy. A locally installed agent is not proof of protection: check in-console heartbeat, device identity, and alert status.

Provision least-privilege identity and services

  • AD/IdP account creation: Create the account from the approved identity request with a unique sign-in name, correct directory attributes, manager, organizational unit, and lifecycle status. Use a controlled provisioning workflow where available and document the immutable user identifier in the ticket.
  • RBAC security group assignment: Apply only role-approved baseline groups and application entitlements. Check inherited access, nested group membership, privileged roles, and conflicting duties. Record who approved each non-standard group and its review date.
  • SaaS license provisioning: Allocate only the licenses needed for the employee’s approved duties. Confirm seat availability and application access, record the SKU/assignment in the identity ticket, and set a review trigger for temporary or premium licenses.
Release gate: Do not hand over an endpoint until encryption recovery is escrowed and the management/security agents report healthy. Escalate any exception to the security or IT owner and document the risk acceptance and expiry.
2 First working day

Phase 2: Day-1 Access & Handover

Verify the recipient’s identity using the organization’s established in-person or remote verification process before disclosing access details or transferring equipment. The manager or sponsor should confirm the role and requested access. Provide concise instructions, then ask the employee to complete the sign-in and recovery steps themselves rather than observing or recording their secrets.

  • Enforced MFA authenticator app setup: Require registration of the approved authenticator or phishing-resistant factor, enforce MFA through the identity provider’s policy, and verify a fresh sign-in challenge. Provide a secure recovery method consistent with policy; do not treat SMS as equivalent where stronger factors are required.
  • One-time secret credential handover: Deliver the initial sign-in secret through an approved, access-controlled channel separate from the account identifier where possible. Require a change at first sign-in, prohibit reuse, and never put passwords, recovery codes, or private keys in tickets, email, or chat transcripts.
  • 802.1X/VPN certificate setup: Enroll the managed device for certificate-based network access using the approved device identity and profile. Test 802.1X and remote VPN access from the expected network path; verify certificate validity, renewal behavior, and revocation ownership.
  • Ticketing portal onboarding: Confirm the employee can access the service portal, find support instructions, and submit a test or real request. Explain severity routing, support hours, and how to report a lost device or suspected compromise.
  • Digital asset acknowledgment: Obtain the organization’s electronic acknowledgment for the specific issued equipment and accessories. Record asset IDs, condition, handover timestamp, policy version, and the employee’s acknowledgment in the approved asset or HR system.
Handover evidence: Record completion timestamps and system evidence, not authenticator seeds, passwords, recovery codes, or private certificate material. Any credential reset or MFA bypass must be temporary, approved, and independently reviewed.
3 By day 30

Phase 3: 30-Day Post-Onboarding Security Audit

Schedule the review when access is requested so it is not forgotten after the immediate start-date work. Compare effective access with the employee’s actual duties and manager approval. The review should be performed by someone with authority to remove access and, where practicable, not solely by the person who provisioned it.

  • Audit temporary privilege escalations: Review PIM/PAM activation history, local administrator membership, emergency elevation grants, and temporary group changes. Confirm each elevation had a business justification, approver, bounded duration, and completed removal; investigate any standing privilege that was meant to expire.
  • MDM/WSUS patch health check: Confirm the device remains enrolled and compliant, has checked in recently, and has installed required OS and application security updates within policy. Investigate failed or deferred updates, stale WSUS/MDM status, disabled controls, and unsupported software; document remediation and due date.
  • Shadow IT inspection: Review endpoint software inventory, browser extensions, unsanctioned cloud storage, OAuth grants, and relevant proxy/CASB or SaaS discovery alerts. Validate business need with the manager; remove prohibited applications or move approved use into sanctioned, managed services.
  • Cloud backup sync verification: Verify protected folders and approved cloud backup clients are active, current, and associated with the correct employee identity. Check recent successful sync/backup status and restore capability without exposing personal data; resolve quota, policy, or authentication errors.
Close the audit: Record reviewer, evidence sources, findings, remediation owner, target dates, and the manager’s access attestation. Leave unresolved findings open with a risk owner; do not mark the review complete merely because a ticket was created.
4 Emergency / leaver workflow

Phase 4: Emergency Offboarding Protocol

Offboarding is a coordinated identity, endpoint, data-retention, and asset process. Follow legal hold, privacy, labor, and incident-response requirements for the jurisdiction and case. For an involuntary or security-sensitive departure, coordinate timing with HR and the incident commander; avoid notifying the departing user before access controls are ready.

  • T-0 account revocation & session kill: At the authorized effective time, disable the primary identity and linked accounts, revoke refresh tokens and active sessions, invalidate application sessions where supported, remove privileged access, and block remote access. Preserve audit logs and evidence before routine cleanup. Verify revocation in the identity provider and critical connected services; prioritize this step for emergency containment.
  • T+24h mailbox/drive reassignment: After the documented approval and retention/legal-hold check, delegate or transfer business records to the manager or designated custodian. Apply mailbox auto-reply or forwarding only where policy and law permit. Keep access time-bound, log the recipient and scope, and verify shared files remain owned by the organization rather than an individual account.
  • T+7d hardware sanitize & license reclamation: Recover all issued devices and accessories, update custody in the CMDB, then sanitize or securely erase storage using the approved media procedure before redeployment or disposal. Reclaim SaaS and platform licenses only after retention and transfer needs are met; record the sanitization certificate, asset disposition, and reclaimed seat.
Emergency control: If the device is lost, stolen, or potentially compromised, do not wait for the normal T+24h/T+7d milestones. Initiate incident response, remote lock or wipe when authorized, revoke device certificates, and preserve relevant logs.

Interactive onboarding & security checklist

Filter by phase, search for a control, and check off completed work on this device. Your check marks stay in this browser only and are not included in feedback submissions.

IT onboarding, 30-day security audit, and offboarding checklist
PhaseChecklist itemExecution standardEvidence to retain
Pre-Day 1 Assign a unique asset ID; reconcile tag, serial, assigned user, location, warranty, and lifecycle status with the physical device.CMDB record and asset handover ticket
Pre-Day 1 Deploy the approved supported image, apply the security baseline, remove stale accounts and unapproved software, and confirm enrollment/build status.Deployment or MDM enrollment record
Pre-Day 1 Enable full-disk encryption and verify the recovery key is escrowed in the approved directory or MDM vault and retrievable by authorized staff.Encryption compliance and escrow status (never the key itself)
Pre-Day 1 Verify device identity, healthy console heartbeat, current policy assignment, and absence of blocking alerts in the EDR/RMM consoles.Console device status and policy assignment
Pre-Day 1 Create the account from an approved request; validate unique sign-in, attributes, manager, organizational unit, and lifecycle state.Identity request, approver, and account identifier
Pre-Day 1 Assign role-approved baseline groups; check nested/inherited and privileged membership and document approval for exceptions.Group membership export and approvals
Pre-Day 1 Allocate the minimum role-required SKUs, verify seat availability and service access, and set a review for temporary or premium seats.License assignment record and role justification
Day 1 Enroll the approved factor, enforce the identity-provider policy, and verify a fresh challenge; provide a policy-compliant recovery path.MFA registration and sign-in policy status; no seeds/codes
Day 1 Use an approved controlled channel, require a first-login change, and never store passwords or recovery codes in tickets, email, or chat.Handover completion timestamp only
Day 1 Enroll the managed device profile, test wired/wireless and remote connectivity, and confirm validity, renewal, and revocation ownership.Certificate enrollment and connection test result
Day 1 Verify portal access and a test or real request; explain support hours, priority routing, and lost-device/compromise reporting.Portal account and onboarding confirmation
Day 1 Collect electronic acknowledgment for assigned equipment and accessories with asset IDs, condition, timestamp, and policy version.Signed acknowledgment in approved asset/HR system
30-Day Audit Review PIM/PAM, local admin, emergency grants, and temporary groups; verify justification, approval, expiry, removal, and remaining privilege.Activation logs, access review, and remediation record
30-Day Audit Confirm recent check-in, compliant enrollment, required OS/app patches within policy, and remediation of failed or deferred updates.MDM/WSUS compliance report and remediation ticket
30-Day Audit Review software, browser extensions, unmanaged storage, OAuth grants, and discovery alerts; validate need and remove or sanction use.Inventory/discovery findings and manager disposition
30-Day Audit Verify approved folders/client, correct identity, recent successful sync/backup, and restore capability without exposing personal data.Backup status, sync timestamp, and any remediation
Offboarding · T-0 At the authorized time, disable identity and linked accounts, revoke tokens/sessions, remove privilege, block remote access, and verify critical apps.Revocation timestamps, verification, and preserved audit logs
Offboarding · T+24h After approval and retention/legal-hold review, transfer business records to an authorized custodian; limit and log delegated access.Approval, retention decision, and time-bound access record
Offboarding · T+7d Recover and reconcile assets, securely sanitize media before reuse/disposal, then reclaim licenses after transfer and retention needs are met.Chain of custody, sanitization record, disposition, and reclaimed seat

A4 PDF · Version 1.2 · Includes all phases regardless of filters

Make the process yours, then keep it measurable

Map every step to the tools and approval paths your organization actually uses. Define a control owner and an evidence location, test the emergency offboarding path before it is urgent, and review this SOP whenever identity, device-management, or retention policy changes. The checklist is a repeatable starting point—not a substitute for your organization’s legal, privacy, security, or change-control requirements.