Onboarding & offboarding · Burlington, Ontario
Employee IT Onboarding and Offboarding in Burlington
Joiner, mover and leaver processes run as standard service request models: the right access provisioned by role on day one, adjusted when people change jobs, and revoked completely on departure with evidence retained.
What this covers
- Role-based access templates
- Device ready before the start date
- Least-privilege provisioning by default
- Same-day access revocation on departure
- Documented audit trail for every change
01The risk
Leavers with live accounts are a standing exposure
Access that outlives employment is one of the most common findings in access reviews — and one of the easiest to eliminate.
Without a defined process, access accumulates. A person moves department and keeps their old permissions. A contractor finishes and their account stays enabled. A departing employee retains mailbox access, a VPN profile, and a SaaS login that HR never knew existed. ISO/IEC 27001 expects access rights to be provisioned, reviewed and removed under a defined process, and NIST CSF treats identity and access management as a core Protect function.
We build joiner, mover and leaver as request models with named approvers. Onboarding provisions from a role template so two people in the same job get the same access. Movers have old rights removed, not just new ones added. Leavers are processed against a checklist that covers every system in the asset register, including the SaaS tools that sit outside the Microsoft tenant.
02Process coverage
What each process includes
Consistent steps, executed the same way every time.
- Account creation from role template
- Microsoft 365 licence assignment
- Group, shared mailbox and file access
- Device build, enrolment and delivery
- MFA registration and secure credential handover
- Line-of-business and SaaS application accounts
- Phone, extension and Teams configuration
- Manager sign-off on elevated access
- Mover: revoke prior access, apply new role
- Leaver: disable, sign out sessions, reset credentials
- Mailbox delegation or conversion for continuity
- Device return, wipe and reissue
03Controls
How the process stays reliable
Reliability comes from templates, approvals and verification — not from remembering.
Role templates
Access is defined per role and reviewed periodically, so provisioning is a decision made once rather than improvised per hire.
Advance notice workflow
A simple request form gives the desk the lead time to have hardware, accounts and licences ready before the first day.
Least privilege
Elevated and administrative access is granted deliberately, time-bounded where possible, and recorded with the approval.
Immediate revocation
On departure, accounts are disabled, active sessions revoked and credentials reset — the sequence matters, and a simple password change is not enough.
Data continuity
Mailboxes and files are preserved, delegated or archived according to your retention position rather than deleted on the spot.
Periodic access review
Scheduled reviews confirm that live accounts still correspond to current employees and current roles.
FAQCommon questions
Questions Burlington organizations ask
How much notice do you need for a new starter?
Several business days is comfortable for standard roles, allowing hardware to be built, enrolled and delivered. Short-notice starts can be accommodated, particularly where a spare standard device is held on site.
What happens to a departing employee's email?
The mailbox is retained and can be delegated to a manager or converted to a shared mailbox so business correspondence remains accessible without keeping the user account active.
Do you cover applications outside Microsoft 365?
Yes. The leaver checklist is built from your asset register, so line-of-business systems, SaaS tools, VPN access and remote access accounts are all included.
Can offboarding happen immediately for a sensitive departure?
Yes. Urgent revocations are treated as priority requests and can be executed within the hour when coordinated with HR, including session revocation and device wipe.
NEXTRelated capabilities
Identity governance sits behind these processes
Joiner-mover-leaver is where identity and access management becomes visible day to day.
Providing Two Decades of IT Experience
Request an IT assessment for your Burlington organization
We review your current environment, security posture, cloud footprint and support model, then outline what to fix first and what it should cost.
