The Work
When someone joins, they need an account, the right access, a configured device, and to actually understand how to use it all. I create Active Directory accounts, set up Microsoft 365 access and group memberships, assign hardware, and enroll devices in Intune. I follow the same checklist every time. No shortcuts, no skipped steps.
When someone leaves, the work reverses: I revoke access, remove them from groups, wipe and decommission their device, and update inventory. Done cleanly, nobody leaves with lingering access or orphaned equipment.
Why It Matters
A bad onboarding ruins someone’s first week and creates support friction for months. They can’t log in, they don’t have Teams access, their device isn’t set up. That’s first-impression stuff that sticks. A rushed offboarding leaves security gaps: abandoned accounts, devices that should be wiped but aren’t, license seats still assigned to people who left. Both deserve equal attention.
Good onboarding means someone can actually work on day one. Good offboarding means the organization stays secure and doesn’t waste money on licenses assigned to empty desks.
What I’ve Learned
Offboarding deserves the same patience and attention as onboarding. That’s usually where gaps show up, when someone’s leaving and pressure is on, it’s tempting to cut corners. Don’t. I’ve learned that documenting your onboarding checklist and actually following it prevents most mistakes. And I’ve learned that the best time to remove someone’s access is the same day they leave, not next week.