Skip to content

Knowledge centre

IT onboarding and offboarding checklist for UAE businesses

Every time an employee joins or leaves, your organisation's security posture either tightens or weakens. A structured IT checklist is the difference between a controlled handover and an open door.

Why IT onboarding and offboarding deserve a written process

Most UAE businesses have an HR onboarding process. Far fewer have an IT onboarding process that matches it in detail. The result is a predictable pattern: new starters spend their first days waiting for access, and departed employees leave behind accounts that stay active for weeks — sometimes months.

The stakes are not trivial. An active account belonging to a former employee is an open credential. If that individual left on poor terms, or if their password was ever reused or shared, the exposure is direct. For organisations subject to the UAE Personal Data Protection Law (PDPL), an uncontrolled departure that leaves personal data accessible to a former employee also creates a potential compliance breach.

A written IT onboarding and offboarding checklist solves both problems. It gives the IT team a repeatable process, gives HR a clear handover point, and gives leadership confidence that access is controlled.

The IT onboarding checklist

Onboarding is not just about providing a laptop. It is about giving a new employee the access they need — and only the access they need — from day one. Over-provisioning access is one of the most common IT governance failures in UAE SMEs, and it compounds with every hire.

Before the start date

  • Confirm the role, department and line manager with HR — this determines which systems the new employee should access.
  • Create the Microsoft 365 account and assign the correct licence tier. Do not assign a Copilot or enterprise licence by default — align it with the role's actual needs. (See our guide on who should get a Copilot seat.)
  • Add the account to the correct Microsoft 365 groups, Teams channels and SharePoint sites for the role — not to every group in the tenant.
  • Prepare the device: image it, apply the baseline security policy, enrol it in Microsoft Intune or your MDM platform, and verify endpoint protection is active.
  • Set a temporary password and configure a required password change on first login.
  • Confirm multi-factor authentication (MFA) will be enforced from the first login — no grace period exceptions.
  • Create accounts in any role-specific line-of-business systems (ERP, CRM, HRIS) and confirm permissions are scoped to the job function.

On the first day

  • Hand over the device with documentation: IT contact, helpdesk process and a short written summary of acceptable use.
  • Walk through MFA enrolment if the employee has not completed it during pre-boarding.
  • Confirm email, calendar, Teams and shared drives are accessible and working correctly.
  • Log the device serial number, assigned user and date in the IT asset register. This is essential for audit trails under both ISO 27001 principles and the PDPL.
  • Record the account creation date, licence assigned and access groups in your IT onboarding log.

During the probation period

  • Review whether any access granted on day one should be adjusted after the employee settles into their actual role.
  • Confirm that no shared passwords have been passed informally — this is common in small teams and undermines accountability.
  • For employees in finance, HR or leadership roles, verify that privileged access is properly scoped and audited.

If your organisation runs a structured managed IT service, your provider should own this checklist as part of the service — not leave it to an office manager or a busy IT contact to remember.

The IT offboarding checklist

Offboarding is higher risk than onboarding. When an employee joins, access gaps are inconvenient. When an employee leaves with active accounts, the exposure can be serious. The checklist below applies to all departures — voluntary resignations, redundancies and dismissals alike.

On the last working day (or at the point of departure for immediate exits)

  • Suspend the Microsoft 365 account immediately — do not delete it yet. Suspension blocks login while preserving the mailbox, OneDrive and audit logs.
  • Revoke all active Microsoft 365 sessions and refresh tokens. A suspended account still has active sessions until tokens are explicitly revoked in Entra ID (formerly Azure AD). This step is missed more often than it should be.
  • Disable or remove the employee from all line-of-business systems: ERP, CRM, HRIS, VPN, any cloud portals.
  • Revoke any admin rights or elevated permissions the employee held. Check both role assignments and group memberships — admin access is sometimes granted informally via group membership.
  • Retrieve the device, confirm it is intact and factory-reset it before reassignment. Log the device return date in the asset register.
  • Change any shared passwords the employee had access to — Wi-Fi, service accounts, server room codes. Shared credentials are a structural weakness; offboarding is a prompt to remove them.
  • Transfer Microsoft 365 mailbox ownership to the line manager or a shared mailbox. Set an auto-reply directing contacts to the appropriate successor.
  • Transfer OneDrive contents to the line manager and apply a retention hold if there is any litigation risk.

Within 30 days of departure

  • Reclaim and reallocate or cancel the Microsoft 365 licence. A departing employee's licence left assigned is money wasted — and often the most immediate licence saving a business can make. Our article on what managed IT services include covers licence governance as part of ongoing management.
  • Review and remove the account from any third-party service integrations: Zoom, Slack, project management tools, accounting software.
  • Delete or archive the Microsoft 365 account according to your data retention policy. Most UAE businesses keep the mailbox in a soft-deleted or litigation hold state for 90 days minimum before permanent deletion.
  • Update your IT asset register to confirm all equipment has been returned or its status documented.
  • Run a final access audit: confirm no residual group memberships, no active MFA devices registered under the old account, no forwarding rules in the mailbox.

PDPL obligations for joiners and leavers

The UAE Personal Data Protection Law creates obligations that run through both sides of the employee lifecycle. When someone joins, you are processing their personal data — and you need a documented lawful basis, a record of what you hold, and controls over who can access it.

When someone leaves, the PDPL requires that personal data is not retained longer than necessary for the purpose it was collected. If a departed employee had access to customer personal data during their role, the offboarding process should include confirming that any local copies of that data on their device or in personal folders are identified and handled correctly.

This is not bureaucracy for its own sake — it is the practical answer to "what happens to customer data when staff turn over?" An IT health check will surface whether your organisation has clear answers to that question or whether the process is informal and undocumented.

Multi-site and multi-entity considerations

For UAE businesses operating across multiple offices or legal entities — a common structure in Sharjah, Dubai, Abu Dhabi and the Northern Emirates — IT onboarding and offboarding complexity scales with the number of systems and access points. A sales manager who had access to the Dubai office SharePoint, the Sharjah ERP, a shared finance folder and a third-party logistics portal leaves behind four separate access threads, not one.

Centralised identity management through Microsoft Entra ID makes this manageable: suspending the central account cascades access removal across integrated systems. Organisations that have not centralised identity — relying instead on separate local accounts in each system — face a manual, error-prone offboarding process every time a staff member leaves.

If your business falls into the second category, addressing identity centralisation is one of the highest-return IT governance improvements available. A managed cybersecurity engagement typically includes identity review as part of the initial assessment.

Making the process repeatable

A checklist in a document is better than nothing. A checklist embedded in your IT service process — triggered automatically when HR notifies IT of a joiner or leaver — is significantly better. The goal is a process that cannot be forgotten because it runs as part of normal operations, not one that depends on someone remembering to send an email.

For organisations evaluating whether their current IT setup supports this kind of operational governance, the place to start is a structured review. Missan Global has delivered managed IT support to UAE businesses since 2004 — onboarding, offboarding and identity management are part of what a properly structured managed IT service covers. Our guide to choosing an IT partner in the UAE sets out what to look for when evaluating whether a provider can own this process for you.

Frequently asked questions

What is the biggest security risk when an employee leaves without a proper IT offboarding?

Active accounts left open after departure. A former employee — or someone who later acquires their credentials — retains access to email, cloud files, shared systems and any connected third-party services. In Microsoft 365 environments, this includes SharePoint sites, Teams channels, Power Automate flows and any apps the user authorised with their identity. Blocking the account is the first step; a structured checklist ensures nothing is missed in the hours and days that follow.

How long should a UAE business retain a departing employee's IT data before deleting it?

The UAE Labour Law and the UAE PDPL do not set a single universal retention period, but general records retention guidance points to a minimum of five years for most employment-related records. Practically, most UAE businesses retain the Microsoft 365 mailbox and OneDrive contents of departed employees for 90 days in a converted shared mailbox or litigation hold, then archive or delete according to their documented data retention policy. The key is having a written policy before you need it — not deciding case by case.

Should the IT team be told about a resignation before the employee is?

In sensitive departures — a redundancy, a disciplinary exit, or a role with elevated access to financial systems or client data — yes. IT should receive advance notice so accounts can be prepared for immediate suspension at the moment of conversation. For standard voluntary resignations with a notice period, IT onboarding and offboarding procedures typically activate on the last working day, with account suspension happening within the same business day. Document your organisation's trigger points in your HR-IT handover process so there is no ambiguity.

Is your IT onboarding and offboarding process under control?

Missan Global has supported UAE organisations with structured IT management since 2004. Start with a free IT health check — no obligation.