New Employee Laptop Setup: A Day-One IT Onboarding Checklist for Offices

How to give every new starter a secure, standard laptop and working accounts on day one, and recover it cleanly when they leave.

Overhead view of a new employee working on a business laptop at a white desk with a desk phone, tablet and coffee
Quick answer

A good new employee laptop setup uses a standard business-class laptop, enrolled in Microsoft Intune so policies and apps arrive automatically, with encryption, endpoint protection and updates switched on. Accounts, licences, group access and MFA are prepared before day one, and the same checklist runs in reverse when someone leaves, so nothing is forgotten either way.

Key takeaways

  • Pick one or two standard laptop models from Dell, HP or Lenovo business lines, with on-site or next-business-day warranty.
  • Windows Autopilot with Intune lets a sealed laptop configure itself when the user signs in, instead of hand-imaging each machine.
  • Every device gets BitLocker, endpoint protection, automatic updates, a screen lock and standard user rights rather than local admin.
  • The manager should request the setup at least a few working days before the start date, with role, apps and access listed.
  • On the last day, disable the account the same day, keep the mailbox, recover the laptop and wipe it before reissuing.

Why does every new employee laptop need a standard build?

A standard build means every laptop in the office runs the same approved configuration, so support is faster, security is consistent and a broken machine can be replaced in hours rather than days.

Without a standard, each laptop becomes its own project. One person has local admin rights, another skipped updates for months, a third was set up with a personal Microsoft account. When something breaks, the engineer first has to work out what is on the machine.

A defined build removes that guesswork. Security settings apply the same way to everyone, and if a laptop is lost in a taxi or dies the week before a VAT deadline, a spare can be brought to the same state quickly because the build is documented rather than living in someone's memory.

Which laptops should an office buy for new starters?

Buy business-class laptops from the business ranges of Dell, HP or Lenovo, and standardise on one or two models rather than whatever is on offer that week.

Business lines such as Dell Latitude, HP EliteBook or ProBook and Lenovo ThinkPad are built for longer life cycles, come with Windows Pro editions that support BitLocker and Intune management, and keep the same model available long enough to hold spares and matching docks. Consumer laptops often ship with Windows Home, extra bundled software and short model runs, which makes them harder to manage and replace like for like.

Warranty matters more than the spec sheet

Choose a warranty with on-site or next-business-day service for the life you expect to keep the laptop. A carry-in warranty that sends the machine away for repair leaves a staff member without a computer. Check that the warranty is valid in the UAE, particularly for devices bought abroad.

Describe the specification by role, not by the cheapest option

Most office staff need a current business processor, enough memory to run Outlook, Teams, a browser and a few spreadsheets at once without slowing down, and solid-state storage. Finance users with large workbooks, designers and anyone running heavier line-of-business software need a higher tier. Two or three role-based profiles are usually enough, and they keep purchasing simple.

Zero-touch or manual imaging: how should the laptop be set up?

For offices on Microsoft 365, zero-touch deployment with Windows Autopilot and Microsoft Intune is usually the better choice, because the laptop configures itself when the new starter signs in with their work account.

With Autopilot, the device's hardware identity is registered to your organisation, often by the supplier at the point of purchase. When the laptop is switched on and connected to the internet, Windows recognises it as a company device, asks the user to sign in, joins it to Microsoft Entra ID and enrols it in Intune. Intune then applies the security policies and installs the assigned apps, so the laptop can go straight from the box to the employee.

Manual imaging means an engineer builds each machine by hand or copies a saved image onto it. It still works for very small offices, but it is slow, depends on the image being kept current and drifts over time. Intune is included in some Microsoft 365 business plans, so check yours first; our Microsoft 365 and cloud service covers the Intune and Autopilot setup.

What security baseline should every laptop have?

Every laptop should leave IT encrypted, protected, updating itself and locked down so the user cannot switch those protections off. These settings are best enforced by policy rather than applied by hand.

  • Device encryption with BitLocker, with recovery keys stored against the device in Entra ID, so a lost laptop does not mean lost data.
  • Endpoint protection, such as Microsoft Defender, turned on, reporting centrally and not removable by the user.
  • Automatic Windows and Microsoft 365 app updates on a managed schedule, plus driver and firmware updates from the manufacturer.
  • Standard user rights instead of local administrator, so malware and unapproved software cannot install freely. Approved apps are pushed through Intune instead.
  • A screen lock after a short period of inactivity, with sign-in by PIN, password or Windows Hello.
  • Firewall on, and files saved to OneDrive or SharePoint rather than only the local drive.

What belongs on an IT onboarding checklist for accounts and access?

The accounts side of an IT onboarding checklist covers the Microsoft 365 licence, mailbox, groups, shared mailboxes, Teams, file access by role, line-of-business apps and MFA, all prepared before the person arrives.

Access should follow the role, not the person who asked. Build security groups for each department so that adding someone to Finance gives them the right SharePoint sites, shared mailboxes and Teams channels in one step. Enrol MFA on day one, ideally with the Microsoft Authenticator app, while IT is on hand to help. Our guide to MFA for small businesses explains the options, and if your tenant is still half on an old email host, sort that out first with a Microsoft 365 migration plan.

Line-of-business apps such as accounting or CRM software often need separate vendor accounts, which can take longer than the laptop. Add peripherals too: a dock that matches the laptop model, monitors, headset and printer access.

Day-one IT onboarding checklist
ItemWhoDone before day one
New starter request with role, start date, apps and accessLine manager or HRYes
Microsoft 365 account, licence and mailboxITYes
Security groups, shared mailboxes, Teams and SharePoint accessIT, approved by managerYes
Laptop registered, enrolled and tested with the standard buildITYes
Line-of-business app accounts and licencesIT with the app vendorYes
Dock, monitors, headset and printer accessIT or office managerYes
Asset register entry and asset tagITYes
First sign-in, password change and MFA enrolmentNew starter with ITNo, on day one
Day-one pack walkthrough and short security briefingIT or managerNo, on day one

What should a new starter receive on day one?

Give each new starter a short day-one pack that explains how to sign in, where files live and how to get help, so their first morning is spent working rather than hunting for passwords.

Keep it to one or two pages: first sign-in and MFA steps, which SharePoint sites and Teams channels they have, how to print, how to join the office Wi-Fi and how to raise a support request. Add a line on what not to do, such as forwarding company email to a personal account.

Behind the scenes, record the laptop in the asset register with its serial number, model, warranty end date, assigned user and asset tag, so you always know what equipment each person holds.

How far ahead should the manager request setup?

Ask managers to submit the request at least a few working days before the start date, and earlier if new hardware must be ordered or a vendor has to create app accounts. Remember that the Saturday to Sunday weekend and public holidays eat into that time.

How should IT offboarding work when an employee leaves?

Offboarding should disable access the same day the person leaves, preserve their mailbox and files, recover every device and wipe laptops before they are reissued.

Block sign-in and reset the password at the agreed time, revoke active sessions and remove MFA methods. Rather than deleting the mailbox, convert it to a shared mailbox or delegate access to the manager so client emails are not lost, then reclaim the licence once data is safe. Move OneDrive files that matter to the team's SharePoint site. Collect the laptop, charger, dock and any phone, update the asset register, then run an Intune wipe or reset so the next person receives a clean standard build.

What about bring-your-own-device?

If staff use personal phones or laptops for work, protect company data rather than the whole device. Intune app protection policies can keep Outlook and Teams data inside managed apps and remove only that data when someone leaves. Agree a written BYOD policy first, and consider data protection obligations such as the UAE PDPL or DIFC Data Protection Law where they apply.

How Listonics helps with new employee laptop setup

Listonics sets up and supports workplace IT for Dubai offices of roughly 5 to 200 staff. Through our workplace IT setup service we help you choose standard Dell, HP or Lenovo business models, configure Autopilot and Intune, apply the security baseline and create accounts, groups and MFA for each new starter. We keep the asset register and account list up to date and hand them over as documentation.

Under managed IT support, new starter and leaver requests are handled as routine changes, with engineers on site across Dubai when hardware needs delivering or collecting. If you would like a standard build and onboarding process for your office, contact our team for a free office IT assessment and a fixed-scope proposal.

Frequently asked questions

With Autopilot and Intune in place, the hands-on part is short: the user signs in and policies and apps install over the internet, which depends on connection speed and the number of apps. The longer part is usually preparing accounts, licences and app access, which is why requests should arrive at least a few working days early.

Usually not. Standard user rights stop malware and unapproved software from installing and keep the build consistent. Approved apps can be published through Intune so staff install them without admin rights. Where a role genuinely needs admin rights, grant them in a controlled way to that person only, and review the decision periodically.

Often yes. Existing laptops running a supported business edition of Windows can have their hardware identity collected and uploaded to Intune, then be reset so they go through Autopilot. It suits a planned refresh or a reissue after someone leaves. Very old or consumer models may not be worth the effort.

Do not delete it straight away. Converting the mailbox to a shared mailbox, or giving the manager access, keeps client correspondence available and lets you reclaim the licence once the data is safe. Set an automatic reply if appropriate, and agree how long the mailbox will be kept with management before removing it.

It can work, but it adds friction. Consumer models often ship with Windows Home, which lacks full BitLocker and the management features business editions offer, and they change model quickly, so spares and docks rarely match. Business-class laptops with on-site or next-business-day warranty are easier to secure, support and replace.

They are the same list in opposite directions. Onboarding creates the account, licence, group memberships, device assignment and asset record. Offboarding disables sign-in, preserves the mailbox and files, removes group access, recovers the devices, wipes them and updates the asset register. Keeping both in one document makes it much harder to miss a step.

Published Sep 13, 2026 · Last reviewed September 13, 2026 · 1,848 words

Talk to an engineer about workplace it setup for your office.

contact us
Chat on WhatsApp