A new teacher starts Monday. At 8:05 a.m. someone realizes she has no email address, so she borrows the front desk login "just for today." By Friday that borrowed login is how she checks the parent app, and nobody remembers to undo it. This is how small businesses end up with shared passwords, accounts nobody can trace, and a staff member who somehow still has access to payroll two jobs later. None of it comes from carelessness — it comes from doing the setup on the same morning the person walks in.
Good IT onboarding is not complicated. It is a short, boring list, done a few days early, the same way every time. Here is the version we use with childcare centers and small businesses across Southern California — and it takes about twenty minutes once it is a routine.
Day one is a security decision, not a paperwork task
Whatever access a person gets in their first week tends to be the access they keep for their whole time with you. Nobody goes back later and trims it. So the choices you make in a rushed twenty minutes on a Monday morning quietly set the blast radius of every future mistake — the phishing email that gets clicked, the laptop left in a car, the departure that ends badly.
That is why onboarding and offboarding are really the same project viewed from opposite ends. If you have read our employee IT offboarding checklist, you already know the punchline: you can only switch off access you knew existed. Onboarding is where that record gets created.
Two or three days before they arrive
Everything below should be finished and tested before the new hire's first morning. Not because it is urgent, but because doing it early is what gives you room to fix whatever does not work the first time.
- Create a named account on your business platform. Microsoft 365 or Google Workspace, on the company tenant — never a personal Gmail or Outlook address, and never a recycled account from the person who had the job before.
- Assign the license the role actually needs. A classroom teacher and a bookkeeper rarely need the same plan. Paying for the wrong tier by default is one of the quiet costs of ad-hoc onboarding.
- Add them to role-based groups, not to individual files. Permissions attached to a "Teachers" or "Front Desk" group are easy to audit and easy to revoke. Permissions granted file by file are invisible forever.
- Set up the app accounts they will need. Parent communication app, scheduling, payroll, point of sale, phone system. Write each one down as you create it — that list becomes the offboarding list later.
- Prepare the device. Updates installed, disk encryption on, antivirus running, and the laptop or tablet enrolled in management so it can be locked or wiped remotely. Our guide to device management for small business covers what enrollment involves if you have not done it before.
- Record the hardware against their name. Serial number, what it is, who has it. A tool like SenAsset.app keeps that register inside Microsoft Teams, which beats the spreadsheet that gets updated twice and then abandoned.
- Write the temporary password somewhere safe — a password manager entry, not a sticky note on the monitor — and set it to require a change at first sign-in.
The first 45 minutes
Block out a real slot on day one. Not squeezed between drop-off and lunch — an actual sit-down, with the person, at their device.
- Sign in and set their own password. Long passphrase, not a variation of the center's name.
- Turn on multi-factor authentication, together, before anything else. CISA puts it plainly: "Users who enable MFA are significantly less likely to get hacked." Doing it during onboarding takes three minutes; chasing someone to do it six weeks later takes six emails. You can read CISA's guidance on multi-factor authentication directly.
- Get them into the password manager and show them how to save a login. If the team does not have one, this is the moment it becomes obvious you need it.
- Walk through where things live. Which folder holds what, what they are allowed to open, what they are not, and where nothing sensitive should ever be saved — like a personal cloud drive or a desktop folder that nothing backs up.
- Sign the policies while you have their attention. Acceptable use, device policy, and — in a childcare setting — the photo and cell phone rules. Our staff cell phone and photo policy guide has language you can adapt.
- Say the phishing sentence out loud. "In your first month, someone will email you pretending to be me, asking you to buy gift cards or change a payment. It will look real. Call me instead." New employees are targeted precisely because they are eager and do not yet know what normal looks like.
- Tell them who to call when something breaks, and make sure that answer is a person or a number, not a shrug.
Week one, then day thirty
In the first week, get them through your security awareness basics — short, practical, and repeated, which is what makes it stick. Our security awareness training guide covers what a small team realistically needs.
Then put one recurring item on the calendar: a thirty-day access check. Open their account, look at what they can actually reach, and remove anything they have not needed. It takes five minutes and it is the only reliable defense against permission creep — the slow accumulation of access that turns an ordinary staff account into a master key. This is also the natural moment to switch off any temporary access granted during training.
If this whole sequence sounds like something that should just happen without anyone remembering it, that is exactly what EDCON's managed IT services handle for childcare centers and small businesses in Los Angeles, Oxnard, Ventura, and Azusa — accounts created, devices prepped, access reviewed, and the record kept current, so onboarding is a calendar invite rather than a scramble. Teams already living in Microsoft Teams can run the whole flow from the Employee Lifecycle Hub.
What childcare centers should add
Licensed programs carry a second layer that has nothing to do with laptops but everything to do with being ready for a visit. California's Title 22 personnel requirements cover items such as minimum age, criminal background clearance, health screening, and CPR and first aid certification — and those records need to be current and easy to produce. You can review the regulations on the California Department of Social Services website.
Practically, that means your onboarding checklist should also capture: the clearance and training documents filed in the staff record with their expiration dates noted, parent app access set to the right level (a floater does not need every classroom), and the new staff member added to your emergency contact tree and group messaging before their first solo shift, not after.
Five shortcuts that cost more than they save
- Sharing one login. If three people use the same account, you can never answer "who did this?" — and you cannot cut off one person without locking out the others.
- Copying an existing employee's permissions. It is the fastest way to set up an account and the fastest way to give a brand-new hire eight years of accumulated access. Start from a role template instead.
- Making everyone an administrator. Admin rights should belong to one or two people. Everyone else can have a normal account and a way to ask.
- Letting work live in personal accounts. A personal phone, a personal Gmail, a personal Dropbox — all of it walks out the door with the person, and none of it is yours to retrieve.
- Postponing MFA "until they settle in." The unprotected window is exactly when a new employee is most likely to be targeted. Turn it on at sign-in, or consider going further with passkeys.
Make it boring and repeatable
Write the checklist down once — a single page listing every account, device, and group a role needs — and name one person who owns running it. Keep a short record for each hire showing what was created and when. That record does three things: it makes the next onboarding faster, it makes offboarding accurate, and it gives you an honest answer if anyone ever asks who had access to what.
A new hire's first day should feel like someone was expecting them. A working login and a device that is already theirs says that better than a welcome banner does.
Common questions about IT onboarding
What should be set up before a new employee's first day?
Their work account on your business email platform, the right license, group memberships that match the role, the app accounts they will use, and a device that is updated, encrypted, and enrolled in management. Doing this two or three days early leaves time to fix what does not work — and means their first hour is training rather than waiting on a password reset.
Should a new employee get their own login, or can staff share one?
Every employee needs their own named account. Shared logins make it impossible to tell who opened a record or sent a message, and they cannot be switched off when one person leaves. If a shared classroom tablet or front-desk computer is genuinely necessary, give each person their own sign-in on that device rather than one account everybody uses.
How much access should a new hire get on day one?
Only what the role needs. The common shortcut — copying a long-tenured employee's permissions — hands a brand-new person years of accumulated access to payroll, records, and admin settings. Start from a role template, add extras by request, and review what they actually have after the first month.
Do childcare centers need anything extra in IT onboarding?
Yes. Alongside the technology setup, Title 22's personnel requirements cover items such as minimum age, criminal background clearance, health screening, and CPR and first aid certification, and those records need to be current and easy to produce for licensing. New staff also need parent app access at the right permission level and a signed photo and cell phone policy before they are in a classroom. General guidance only — confirm specifics with your licensing analyst.
Want onboarding to run itself?
EDCON sets up role-based accounts, managed devices, MFA, and a written onboarding routine for childcare centers and small businesses across Southern California — so every new hire starts with exactly the access they need and nothing they don't. Book a free 30-minute consultation and we'll map your current setup, no pressure.
Book a Free Consultation