Frontrow Technology
← All insights & guides
Guide

Managed Services

Microsoft 365 new starter setup: the ordered checklist

The ordered Microsoft 365 checklist for a new starter: account, licence, MFA, group-based access, device handover, mailbox and Teams before day one.

Simon Aspinall · 19 August 2026 · 11 min read

New starter setup in Microsoft 365 is the sequence run before an employee's first day: create the account, assign the licence, register multifactor authentication (MFA), add the person to the right groups so access is inherited rather than granted one file at a time, sort out the device, configure the mailbox and Teams, and hand it all over on morning one. Get the order wrong and you either lock the person out on day one or, more quietly, hand them access that nobody can cleanly take back later.

Most businesses do this in whatever order the requests arrive: an account created the afternoon before start, access to shared drives granted ad hoc as the new starter asks for things in their first week. It works, in the sense that the person eventually gets what they need. It also means nobody can say with confidence what they have access to, which is the exact problem that makes offboarding hard later.

Why does the order matter?

Each step in this checklist depends on the one before it. The account has to exist before a licence can be assigned to it. The licence has to be assigned early enough for Microsoft 365 to provision the mailbox, OneDrive and Teams behind it, which is not instant. Authentication should be registered before the account is used for anything real, not worked out under pressure on the first morning. Group membership should be sorted before any file or site access is granted directly, because access granted through a group can be removed by removing the person from the group — access granted one link at a time has to be found and removed individually, and it usually isn't. The device and mailbox come last, because by the time they arrive everything underneath should already be correct.

Step 1: create the account ahead of the start date

The account should exist in Microsoft Entra ID (the identity platform behind Microsoft 365, formerly Azure Active Directory) a few working days before the person starts, not on the morning itself. That gives licence assignment, group membership and provisioning time to settle before anyone relies on them. Use a consistent naming convention, record the correct manager and department so dynamic groups pick the account up correctly, and set a temporary password that changes at first sign-in.

Step 2: assign the licence early enough to provision

Assigning a Microsoft 365 licence is what switches on the mailbox, OneDrive storage and Teams presence behind the account, and that provisioning is not instant. A licence assigned the same morning the person starts can mean a mailbox that is not fully ready when they try to send their first email. Assigning it the day before removes that risk entirely and costs nothing, since most subscription terms bill from the point of assignment or the start of the term rather than the hour of first use.

Step 3: register authentication before the account does anything real

MFA registration — enrolling the Microsoft Authenticator app, a phone number or another approved method against the account — should happen before the new starter relies on the account for real work, ideally during a short IT onboarding call rather than left for them to work out alone. An account with a password but no registered MFA method is either blocked from signing in under a conditional access policy, or a soft spot in the tenant if MFA isn't enforced consistently. Registering early also means the person isn't fumbling through an unfamiliar prompt on their first morning while everyone is waiting.

Step 4: add to groups, not individual files

This is the step that determines whether the whole setup can be unwound cleanly later. Access to shared drives, SharePoint sites, distribution lists and internal applications should come from adding the new starter to the security groups or Microsoft 365 groups that represent their role or department — not from sharing a specific folder, mailbox or file directly with their individual account. A group-based model means one place, the person's group memberships in Microsoft Entra ID, shows everything they can reach. Access granted directly, one link at a time, doesn't show up there.

Step 5: enrol or hand over the device

A company-owned laptop should be enrolled in Intune (Microsoft's device management platform) and, where the fleet supports it, pre-provisioned through Windows Autopilot so it is genuinely ready to use out of the box. A personal device the person will use for email or Teams — most often a phone — needs an app protection policy applied, so company data inside Outlook and Teams is managed and can be wiped later without the business touching anything else on the device. Either way, this happens after groups are sorted, so the device picks up access that already exists rather than triggering it.

Step 6: mailbox and Teams setup

With the account, licence, authentication, groups and device in place, mailbox and Teams configuration is largely a formality: the mailbox is ready, distribution list and shared mailbox membership follow from the groups already assigned, and the person appears in the right Teams and channels without anyone adding them by hand. This is also the point to set an email signature template and confirm the person shows up correctly in the directory and org chart.

What should be ready on their first morning?

By the time the new starter sits down, the technical setup should be invisible to them. What they should actually receive is a short, human handover:

  • A working device, signed in, with MFA already registered so there is no setup friction in front of them.
  • Their username and a way to complete the first sign-in without a phone call to IT.
  • A one-page quick reference: how to reset a password, how to reach the help desk, and who to ask about access they don't yet have.
  • Calendar invites already sitting in their mailbox for any onboarding meetings, rather than being sent to them cold.
  • Confirmation of which Teams and channels they're in, so their first login isn't spent hunting for the right places.

The complete new starter checklist

  1. 1Confirm the start date, manager and department with HR, and create the account in Microsoft Entra ID a few working days ahead of it.
  2. 2Assign the Microsoft 365 licence early enough for the mailbox, OneDrive and Teams presence to fully provision before day one.
  3. 3Register MFA on the account during a short setup call, before the person is relying on it for real sign-ins.
  4. 4Add the account to the security and Microsoft 365 groups that represent their role and department — not direct file or folder shares.
  5. 5Enrol a company device in Intune, or apply an app protection policy to a personal device that will handle company email and Teams.
  6. 6Confirm mailbox provisioning, Teams and channel membership, shared calendars and distribution lists are all inherited correctly from the groups assigned.
  7. 7Prepare the device, sign-in details and a one-page reference guide ready to hand over on the first morning.
  8. 8Record what was done and when, so there is a clear log of exactly what access this person was given from day one.

This checklist is the mirror image of the leaver process. Offboarding works quickly and completely when access was granted through groups in the first place — that's the whole reason the ordering here insists on it. A business that runs a tidy joiner process and a sloppy leaver process, or the other way around, still ends up with an access list nobody trusts.

Common questions

Frequently asked

What is the right order to set up a new starter in Microsoft 365?
Create the account first, assign the licence early enough for it to provision, register MFA before the account is relied on for real work, add the person to the groups that represent their role, then enrol the device and finish mailbox and Teams configuration. Each step depends on the one before it, and access should be granted through groups rather than shared directly with the individual, because that is what makes offboarding possible later.
Why use groups instead of sharing files directly with a new starter?
Access granted through a security group or Microsoft 365 group can be removed in one step, by removing the person from the group. Access granted directly to an individual account, through a one-off sharing link or a folder shared with their personal login, has to be found and removed one item at a time — and it usually isn't found, because nobody kept a record of it. Group-based access is what lets a leaver's access be closed off completely and quickly.
How early should a Microsoft 365 licence be assigned before someone starts?
At least a day ahead of the start date, where possible. Assigning a licence provisions the mailbox, OneDrive and Teams presence behind it, and that provisioning takes some time. Assigning the licence the same morning the person starts risks a mailbox or Teams account that isn't fully ready when they first try to use it.
Should MFA be set up before or after a new starter's first day?
Before. Registering multifactor authentication during a short IT onboarding call, ahead of the start date or first thing on the morning itself, means the account is properly secured before it is used for real work, and the new starter isn't left working out an unfamiliar prompt while colleagues are waiting on them.
What device setup does a new starter need before day one?
A company-owned device should be enrolled in Intune and ideally pre-provisioned through Windows Autopilot so it is ready without a full manual build. A personal device that will be used for company email or Teams needs an app protection policy applied, which manages the company data inside those apps without the business having control over the rest of the device.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.