The IT Onboarding Checklist for New Employees at a Remote-First Company
A remote-first onboarding that runs from a checklist gets a new hire from signed offer to productive work without anyone standing at a desk: the account exists before the laptop ships, the laptop arrives already enrolled, and day one is spent meeting the team instead of requesting access. This checklist covers the eight items we run for distributed hires, in the order that keeps each one from blocking the next. It reads the same for a 5-person startup onboarding its first remote hire and a 120-person company tightening a process that grew up ad hoc: configure the checklist for scale from day one, and if your onboarding started as improvisation, the same eight items are the cleanup.
Cross-referenced against Google Workspace, Slack, 1Password, Kandji, Microsoft Intune, and Jira Service Management documentation on 2026-08-25.
1. Create the Identity Before Anything Else
Every other account keys off the identity provider, so the Google Workspace or Microsoft 365 account comes first, created as soon as the start date is set. Naming convention, group memberships, and the multi-factor enrollment policy all apply at creation, which means every app added later inherits them. Create the account several business days before the start date so licenses, mail routing, and group syncs have time to settle.
2. Ship the Laptop Enrolled, Not Blank
Remote hires cannot walk over to IT, so the laptop has to arrive configured: enrolled in device management through Apple Business Manager or Windows Autopilot, disk encryption on, security baseline applied. The hire opens the lid, signs in with the company identity, and the device finishes setting itself up. Order through a reseller connected to your enrollment program so devices ship straight to the hire without a stop at anyone's kitchen table.
3. Provision Apps Through Groups, Not One-Off Invites
Individual app invites are the slowest part of any onboarding, and they are also how access drifts out of sync with roles. Map each role to a group in the identity provider and let membership carry the grants: engineering gets GitHub and Jira, sales gets the CRM, everyone gets Slack and the knowledge base. A hire added to the right groups before day one signs in to a full toolset without a single manual invite.
4. Put Credentials in a Password Manager From the Start
Whatever lives outside single sign-on, shared vendor logins, API keys, the odd legacy account, belongs in a managed vault the hire joins during the first week. 1Password or an equivalent gives those credentials per-group access instead of a pinned message in a channel. Grant vault access by group so the credentials that come with the role are already waiting when the hire first opens the app.
5. Send a Pre-Start Welcome Note With the Plan
A remote hire cannot absorb the first day by watching an office, so a short note before the start date does that work: when the laptop arrives, what to sign into first, and who to message when something does not behave. Include the first-day schedule so the hire logs in knowing exactly what happens first. This one message removes most of the day-one support requests before they exist.
6. Book the Day-One IT Check-In
Put a 30-minute video call with whoever runs IT on the hire's calendar for the first morning. The agenda is verification: sign-in works, multi-factor prompts appear, the vault opens, the right Slack channels are joined, and the device shows as compliant in device management. For a distributed team this call replaces the walk to the IT desk, and it ends onboarding with a person rather than a form.
7. Route Everything After Day One Through the Help Desk
Onboarding questions keep surfacing for weeks, and they need a destination that is not a direct message to whoever set up the laptop. A help desk intake in Jira Service Management or an equivalent, reachable from Slack, turns each question into a ticket with an owner and a searchable answer. The habit formed in week one, ask the help desk rather than a person, is the one that scales.
8. Close the Loop With a Sign-Off and an Offboarding Mirror
The checklist ends with a verification pass: the hire confirms access to every tool the role needs, and IT records the device serial and the accounts issued. That record is the offboarding checklist in reverse, which is the point. Keep the completed checklist with the asset record so a future departure is a single identity suspension plus a device return label, not an investigation.
What Did Not Make the List
Badge access, desk assignments, and printer setup have no remote-first equivalent, and their absence is part of why a distributed checklist stays short. Role-specific training also stays off this list because it belongs to the hiring manager, not to IT. Keep the IT checklist small enough that it runs identically for every hire, because a checklist with exceptions stops being a checklist.
Would you like every new hire to start this smoothly without running the checklist yourself? We can help. Book a free call and we will run onboarding and offboarding as part of your managed IT.
Cross-referenced against Google Workspace, Slack, 1Password, Kandji, Microsoft Intune, and Jira Service Management documentation on 2026-08-25.