A new employee's first day is one of the most common sources of credential security failures. In the rush to get someone productive quickly, it is tempting to share a general password, let them reuse their previous company's credentials, or defer security setup to "later in the week." This checklist structures the process to prevent those shortcuts from creating lasting vulnerabilities.
Day-One Security Checklist
- โ Create company email account with generated password (not the employee's name or a default)
- โ Enable MFA on company email โ walk the new employee through setup on day one
- โ Invite to company password manager โ provide vault and shared collections appropriate to their role
- โ Create individual credentials for each system they need โ generated by the manager, not shared verbally
- โ Enrol on any SSO (Single Sign-On) system โ test that logins work before end of day
- โ Provision laptop or device with disk encryption enabled and confirmed
- โ Brief on the password policy โ 15 minutes, not a document to read later
- โ Confirm emergency contact for account recovery in case of device loss
What Not to Do
- Do not email a password โ even temporarily. Use the password manager's secure sharing
- Do not create an account using a generic name like "[email protected]" โ accounts must be individual
- Do not skip MFA setup because it "takes too long" โ the cost of a compromised account far exceeds 15 minutes
- Do not give access to sensitive collections (finance, admin) until role requires it and probation is complete
HR onboarding new employee access control password setup security checklist
For informational purposes only. Consult a qualified IT security professional for advice specific to your organisation.