Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays [email protected]

Dallas business IT

Hiring your first employees: the IT onboarding checklist

Your first hire arrives Monday and nobody has thought about the laptop, the email address or who has the password. Here is the repeatable day-one process I set up for Dallas businesses, and the offboarding half that protects you later.

Written and reviewed by Anthony Omini, Cross River Tech·10 min read·Published

What IT do I need when I hire my first employee?

When you hire your first employee in Dallas, they need four things on day one: their own named account on Microsoft 365 or Google Workspace, a license, a company-owned computer with multi-factor authentication turned on, and membership in the right access groups and shared drives. Add a phone extension and a one-page written welcome sheet, and the first morning stops being a scramble.

Answered by Anthony Omini, Cross River Tech, Dallas

Open laptop and chair at a ready wooden desk

Key takeaways

  • A first hire needs a named account, a license, a company-owned computer, multi-factor authentication, the right access groups and shared drives, a phone extension and a written welcome sheet.
  • Shared logins feel efficient on day one and cost you badly later: you cannot tell who did what, you cannot cut off a departing employee's access, and you cannot answer a client security questionnaire honestly.
  • Build the process once as a written checklist, not from memory, so the fifth hire takes the same short amount of work as the first.
  • Offboarding is the same list run backwards on the same day the person leaves, and it is the half most Dallas small businesses skip.
  • Onboarding is included in a managed IT plan; if you are not on one, it is straightforward hourly work at published break/fix rates.

What IT do I need when I hire my first employee?

You need seven things, and they are the same seven every time. Once you have hired your first person in Dallas, you are no longer a founder improvising on a personal Gmail account and a laptop you bought at a big-box store. You are a company with staff, and the day-one setup you build now is the one you will repeat for every hire after.

  • A named account. One Microsoft 365 or Google Workspace user in the company domain, in the person's own name, never a shared mailbox that two people sign into.
  • A license. The subscription that gives that account email, calendar, file storage and the desktop applications the role actually needs.
  • A company-owned computer. Set up, updated, encrypted and signed in before the person touches it.
  • Multi-factor authentication. A prompt or code on the employee's phone, enrolled during setup rather than left as a task the new hire will never get around to.
  • Access groups and shared drives. Membership decided by the role, so the person sees what they need and nothing else.
  • A phone extension. A number or softphone that reaches them, and a place in the call flow if you have one.
  • A written welcome sheet. One page that tells them their sign-in, where files live, how to reach IT and what the rules are.

That list takes a couple of hours the first time and much less after that, because the pattern is already built. I run it as part of managed IT for businesses across Dallas, and I run it as a one-off job for people who just need this one thing done properly.

What has to be ready before their first morning?

Everything. A new hire who spends their first morning waiting on an email address remembers that morning for a long time, and so does the manager who has to keep apologising. The work happens the week before, not on the day, and it starts with information only you have.

Here is what I need from you before I can build the account, and it fits in a short message:

  1. The person's full name and the email address format you want to keep using across the company.
  2. Their role and start date.
  3. Who in the business does the closest job to theirs, so I can copy that person's access rather than guess at it.
  4. Whether they need a laptop or a desktop, and whether they will work in the office, from home, or both.
  5. Whether they need a phone extension, a direct number or nothing at all.
  6. Any application beyond email and files that the role needs a login for.

Point three does most of the work. "Give her the same access as Marcus in accounts" is a far better instruction than a list of folders, because it uses knowledge you already have and it makes the access decision belong to the business rather than to IT. The rest is mechanical. If the computer needs ordering, that is the item with a real lead time, so tell me about a hire as soon as the offer is accepted rather than the week they start.

How do I set up a new employee's computer and email?

In the order below. The sequence matters, because each step depends on the one before it, and doing them out of order is how you end up with a laptop signed in to the wrong account.

  1. Create the account first. A user in your Microsoft 365 or Google Workspace tenant with the person's real name, the standard address format, and a temporary password that must be changed at first sign-in.
  2. Assign the license. Pick the subscription that matches the role. Not everyone needs the most expensive plan, and a front-desk person and a designer rarely need the same one.
  3. Turn on multi-factor authentication before the account is used. Enroll it during setup with the employee's phone in the room, or with a temporary method you can hand over on day one.
  4. Add the person to groups. Distribution lists, security groups, shared mailboxes as members rather than as a shared password, and the teams or shared drives their role needs.
  5. Prepare the computer. Windows updates applied, drive encryption on, endpoint protection installed, the remote management agent installed, browser and applications installed, printers mapped, and the company account signed in.
  6. Set the files up properly. Cloud storage synced so the desktop and documents folders back up automatically, and shortcuts to the shared drives the person will actually open.
  7. Add the phone. Extension created, softphone installed on the computer and the mobile if that is how you work, and the person added to the ring group that answers the main line.
  8. Write it down. The welcome sheet, and one line in the shared record of who has what.

The computer part is worth doing on business-class hardware rather than whatever is on sale. I work with Dell and Lenovo, and the reasoning is in buying and supporting Dell and Lenovo business computers. A machine that is easy to manage and still supportable in three years costs less than the cheap one you replace twice.

Why do shared logins cost you later?

Because every problem a shared login creates arrives months after the convenience wore off. It is the single most common thing I have to unpick at a growing Dallas business, and it always started as a sensible-sounding shortcut: one info@ mailbox everybody opens, one QuickBooks user, one password for the point-of-sale, one admin account with a password on a sticky note.

What a shared login costs youWhat a named account gives you instead
Nobody can tell who sent, deleted or changed somethingA clear record tied to a real person
Removing one employee means changing the password for everyoneDisable one account, everyone else keeps working
Multi-factor authentication is impractical, so it never gets turned onMFA works normally, on each person's own phone
The password spreads by text message and never gets rotatedNothing to spread
Client and cyber-insurance questionnaires get answered dishonestly or not at allHonest answers to the access questions everyone now asks
Files and mail belonging to a departed employee are tangled with everyone else'sOne mailbox and one file set to hand over cleanly

There is one honest exception. A genuinely shared address such as info@ or billing@ should exist, but as a shared mailbox that named users are given permission to open, not as a separate password anybody types. That way the mailbox is shared and the accountability is not. Converting existing shared logins to that model is a short project and one of the best security improvements a small business can make, which is why it also appears on the short list in cybersecurity basics for a Dallas small business.

What should the written welcome sheet say?

One page, handed over on the first morning, written for someone who has never seen your systems. It saves you the same six questions from every hire and it gives the person something to look at before they feel comfortable asking. Keep it plain and keep it short.

  • Sign-in. Their email address, how to change the temporary password, and what multi-factor authentication will ask them for.
  • Where files live. The shared drive or team site names, what belongs in each, and the rule that work does not live on the desktop.
  • Email etiquette that is really security. Nobody will ever ask them for a password by email, payment or bank-detail changes are confirmed by phone, and forwarding company mail to a personal address is not allowed.
  • Phone. Their extension, how to transfer a call, how voicemail reaches them.
  • Printing and Wi-Fi. Which printer, which network, and the guest network that visitors use instead.
  • How to get help. The direct number and email for IT, what counts as urgent, and the reassurance that reporting a mistake early is welcome and never punished.
  • What is company property. The computer, the accounts and the data, and what happens to them if the person leaves.

That last point about reporting mistakes matters more than it looks. The employee who clicks something they should not have and tells you within the hour costs you almost nothing. The one who hides it for three days can cost you a great deal. Writing "tell me straight away, you will not be in trouble" on a welcome sheet is a cheap and genuinely effective security control.

How do access groups and shared drives keep this simple?

By making access a property of the role rather than a set of one-off decisions. If you hand out permissions folder by folder for each new person, you will have an unmaintainable mess by your fifth hire and no way to answer the question "who can see the payroll folder?" Groups fix that.

The structure I set up for a small Dallas office usually looks like this:

  • A group per function. Sales, Operations, Finance, Management. A person joins the groups their role needs.
  • Permissions attached to the group, never to the person. The Finance shared drive is open to the Finance group. Nobody is added individually.
  • An "everyone" area on purpose. Templates, policies, the price list, the things that genuinely should be open, so people are not asking for access all day.
  • A locked area for the things that should be locked. Payroll, personnel files, banking. Usually two or three people.
  • Guest and contractor access that expires. Time-limited, reviewed, and removed when the project ends.

Onboarding then becomes one line of instruction: add this person to Sales and Everyone. Offboarding becomes one action. A yearly review becomes a readable list rather than an archaeology project. If your files are still on an old server or scattered across personal drives, moving them into a proper shared structure is the piece to do before the hiring starts, and I cover the account side of it under Microsoft 365 and Google Workspace support.

How does offboarding mirror onboarding?

It is the same checklist run backwards, on the day the person leaves rather than the week after. Every item you created has a matching item to close, and the reason to write it down is that offboarding always happens at a bad moment: someone resigns, someone is let go, and nobody is thinking clearly about the softphone app on their personal mobile.

Onboarding stepMatching offboarding step
Create the named accountDisable the sign-in and revoke active sessions so open devices stop working
Assign the licenseReassign or drop the license once the mailbox is handled, so you stop paying for it
Enroll multi-factor authenticationRemove the registered phone and any app passwords
Add to groups and shared drivesRemove from all groups, and transfer owned files to a named colleague
Hand over the computerCollect it, or wipe it remotely if it does not come back
Create the phone extensionRemove the extension, redirect the number, uninstall the softphone from personal devices
Set up third-party application loginsClose each one, including the ones only that person used
Give the welcome sheetConfirm in writing what was returned and what was closed

The mailbox usually needs a short grace period: converted to a shared mailbox a manager can read, or forwarded for thirty days, so client conversations do not fall in a hole. That is a business decision, not a technical one, and it belongs on the checklist so it gets made deliberately. If a departure has already gone wrong and the laptop and accounts walked out the door, the recovery steps are in an employee left with the company laptop and accounts.

Who does this for a small business in Dallas, and what does it cost?

I do. Cross River Tech is a small, owner-led managed IT company based in Dallas, and setting up new hires is ordinary work my team and I do every month for businesses across the metroplex. You send me a short message when an offer is accepted, and the account, the license, the device, the access and the phone are ready before the start date.

  • On a managed IT plan, onboarding and offboarding are part of the monthly fee, quoted per user or per device after a short conversation, month-to-month with no lock-in. The checklist lives in a shared document you can read at any time.
  • Without a plan, it is straightforward hourly work: $100 per hour remote and $150 per hour onsite during business hours, Monday to Friday 8 AM to 5 PM Central, with a one-hour minimum. After hours and weekends are $150 remote and $225 onsite.
  • Hardware is quoted separately at what it costs, and I will tell you honestly when the machine you already have is fine for another year.

The reason to keep it with the same company, and the same point of contact, is continuity. I know which groups your Finance folder uses, which laptop model you standardized on, and what the last hire needed, so the next one takes a fraction of the effort. You never explain your setup twice. I work onsite by appointment across Dallas and the surrounding metroplex, and remotely anywhere in Texas, which covers the hire who will be working from a spare bedroom in another city.

If you have a start date on the calendar and nothing prepared, tell me the name, the role and the date and I will tell you exactly what needs ordering and when.

Questions people ask

How long before a start date should I involve IT?

As soon as the offer is accepted. Accounts, licenses and access take very little time, but a computer that has to be ordered and configured is the item with a real lead time. Two weeks is comfortable. If you have less than that, tell me anyway; a spare machine or a temporary setup usually bridges the gap so the person can work on their first morning.

Can my new employee just use their own laptop for now?

It can work briefly, with limits: a separate work account, multi-factor authentication, and company files kept in cloud storage rather than on the machine. It is not a good permanent answer. A personal computer cannot be updated, monitored, encrypted or wiped by you, and when the person leaves, your data leaves with the laptop. A company-owned machine solves all of that.

Do I really need multi-factor authentication for a two-person business?

Yes, and it matters most when you are small. Email account takeover is the most common way a small business gets hurt, and MFA stops the overwhelming majority of it. It is included in the Microsoft 365 and Google Workspace subscriptions you already pay for, it takes minutes per person to enroll, and it costs nothing extra to run.

What should I do about shared logins already in place?

Convert them one at a time, starting with email and anything touching money. A shared mailbox such as info@ becomes a mailbox that named users are given permission to open, rather than a password people type. Application logins get a user each. It is usually an afternoon of work and it is the single change that makes everything else in your security easier.

Who keeps the record of who has access to what?

You should, and I set it up so you can read it without asking me. A shared document lists each person, their groups, their devices and their application logins, updated as part of every onboarding and offboarding. If you ever move on from Cross River Tech, that document goes with you. Nothing about your accounts or access should live only inside my company.

What happens on offboarding if the employee will not return the laptop?

On a managed device, the drive is encrypted and the sign-in is disabled the same day, so the machine is hardware rather than a data breach. I issue a remote wipe that runs the next time it connects to the internet. Company files stay safe because they live in cloud storage, not only on that computer. The laptop itself becomes a matter for you and your employment adviser.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Got a start date on the calendar? Send me the name, the role and the first day. I will have the account, the computer, the access and the phone ready before they walk in.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080