New starter setup in Microsoft 365 is the sequence run before an employee's first day: create the account, assign the licence, register multifactor authentication (MFA), add the person to the right groups so access is inherited rather than granted one file at a time, sort out the device, configure the mailbox and Teams, and hand it all over on morning one. Get the order wrong and you either lock the person out on day one or, more quietly, hand them access that nobody can cleanly take back later.
Most businesses do this in whatever order the requests arrive: an account created the afternoon before start, access to shared drives granted ad hoc as the new starter asks for things in their first week. It works, in the sense that the person eventually gets what they need. It also means nobody can say with confidence what they have access to, which is the exact problem that makes offboarding hard later.
Why does the order matter?
Each step in this checklist depends on the one before it. The account has to exist before a licence can be assigned to it. The licence has to be assigned early enough for Microsoft 365 to provision the mailbox, OneDrive and Teams behind it, which is not instant. Authentication should be registered before the account is used for anything real, not worked out under pressure on the first morning. Group membership should be sorted before any file or site access is granted directly, because access granted through a group can be removed by removing the person from the group — access granted one link at a time has to be found and removed individually, and it usually isn't. The device and mailbox come last, because by the time they arrive everything underneath should already be correct.
Step 1: create the account ahead of the start date
The account should exist in Microsoft Entra ID (the identity platform behind Microsoft 365, formerly Azure Active Directory) a few working days before the person starts, not on the morning itself. That gives licence assignment, group membership and provisioning time to settle before anyone relies on them. Use a consistent naming convention, record the correct manager and department so dynamic groups pick the account up correctly, and set a temporary password that changes at first sign-in.
Step 2: assign the licence early enough to provision
Assigning a Microsoft 365 licence is what switches on the mailbox, OneDrive storage and Teams presence behind the account, and that provisioning is not instant. A licence assigned the same morning the person starts can mean a mailbox that is not fully ready when they try to send their first email. Assigning it the day before removes that risk entirely and costs nothing, since most subscription terms bill from the point of assignment or the start of the term rather than the hour of first use.
Step 3: register authentication before the account does anything real
MFA registration — enrolling the Microsoft Authenticator app, a phone number or another approved method against the account — should happen before the new starter relies on the account for real work, ideally during a short IT onboarding call rather than left for them to work out alone. An account with a password but no registered MFA method is either blocked from signing in under a conditional access policy, or a soft spot in the tenant if MFA isn't enforced consistently. Registering early also means the person isn't fumbling through an unfamiliar prompt on their first morning while everyone is waiting.
Step 4: add to groups, not individual files
This is the step that determines whether the whole setup can be unwound cleanly later. Access to shared drives, SharePoint sites, distribution lists and internal applications should come from adding the new starter to the security groups or Microsoft 365 groups that represent their role or department — not from sharing a specific folder, mailbox or file directly with their individual account. A group-based model means one place, the person's group memberships in Microsoft Entra ID, shows everything they can reach. Access granted directly, one link at a time, doesn't show up there.
Step 5: enrol or hand over the device
A company-owned laptop should be enrolled in Intune (Microsoft's device management platform) and, where the fleet supports it, pre-provisioned through Windows Autopilot so it is genuinely ready to use out of the box. A personal device the person will use for email or Teams — most often a phone — needs an app protection policy applied, so company data inside Outlook and Teams is managed and can be wiped later without the business touching anything else on the device. Either way, this happens after groups are sorted, so the device picks up access that already exists rather than triggering it.
Step 6: mailbox and Teams setup
With the account, licence, authentication, groups and device in place, mailbox and Teams configuration is largely a formality: the mailbox is ready, distribution list and shared mailbox membership follow from the groups already assigned, and the person appears in the right Teams and channels without anyone adding them by hand. This is also the point to set an email signature template and confirm the person shows up correctly in the directory and org chart.
What should be ready on their first morning?
By the time the new starter sits down, the technical setup should be invisible to them. What they should actually receive is a short, human handover:
- A working device, signed in, with MFA already registered so there is no setup friction in front of them.
- Their username and a way to complete the first sign-in without a phone call to IT.
- A one-page quick reference: how to reset a password, how to reach the help desk, and who to ask about access they don't yet have.
- Calendar invites already sitting in their mailbox for any onboarding meetings, rather than being sent to them cold.
- Confirmation of which Teams and channels they're in, so their first login isn't spent hunting for the right places.
The complete new starter checklist
- 1Confirm the start date, manager and department with HR, and create the account in Microsoft Entra ID a few working days ahead of it.
- 2Assign the Microsoft 365 licence early enough for the mailbox, OneDrive and Teams presence to fully provision before day one.
- 3Register MFA on the account during a short setup call, before the person is relying on it for real sign-ins.
- 4Add the account to the security and Microsoft 365 groups that represent their role and department — not direct file or folder shares.
- 5Enrol a company device in Intune, or apply an app protection policy to a personal device that will handle company email and Teams.
- 6Confirm mailbox provisioning, Teams and channel membership, shared calendars and distribution lists are all inherited correctly from the groups assigned.
- 7Prepare the device, sign-in details and a one-page reference guide ready to hand over on the first morning.
- 8Record what was done and when, so there is a clear log of exactly what access this person was given from day one.
This checklist is the mirror image of the leaver process. Offboarding works quickly and completely when access was granted through groups in the first place — that's the whole reason the ordering here insists on it. A business that runs a tidy joiner process and a sloppy leaver process, or the other way around, still ends up with an access list nobody trusts.