People coming and going is when firms leak access. A new associate waits three days for a laptop, so someone shares a password to get them started. A paralegal departs and their email, VPN and practice-management accounts stay active for months. Neither is dramatic, but both are the kind of gaps that auditors, insurers and attackers notice.
A written checklist, owned by one person and triggered by HR, solves most of it.
Who Owns the Process
Assign a single owner, typically the firm administrator, and a backup. HR or the hiring partner should notify IT at least a week before a start date, and as early as possible before a departure. IT should confirm completion in writing.
Onboarding Checklist
Before the first day
- Request form. Name, role, start date, supervising attorney, practice group and which matters or folders they need.
- Create the account with a unique username. Never reuse another employee's account.
- Assign licenses for Microsoft 365, the practice-management system, document management and any research tools.
- Set group membership based on role, not on copying a coworker. Least privilege means giving only the access the job requires.
- Prepare the device. Image it with encryption, endpoint protection and standard software, and enroll it in management.
- Order phone and desk equipment early enough to arrive on time.
First day
- Hand over the device and walk through sign-in.
- Enroll in multi-factor authentication in person, so the process is not left to an email link.
- Set up a password manager.
- Review the acceptable use and security policies, and collect a signed acknowledgment.
- Assign security awareness training to be completed in the first week.
- Confirm access to the right matter folders and test it.
First month
- Check in about problems.
- Confirm training is finished.
- Review access again, removing anything not needed.
Offboarding Checklist
Offboarding is more urgent and more often forgotten. Plan it by the day, and for involuntary departures, coordinate timing so access is cut at the moment the conversation happens.
On the departure date
- Disable the account and revoke active sessions and tokens. Reset the password.
- Remove MFA devices and revoke app passwords.
- Disconnect from the practice-management, document-management, billing and research platforms. Many sit outside Microsoft 365 and are easy to miss.
- Collect devices: laptop, phone, badge, security keys and any removable media.
- Wipe or lock mobile devices that held firm data, including personal phones enrolled in management.
- Remove from distribution lists, shared mailboxes and Teams channels.
- Revoke remote access such as VPN, remote desktop and any shared passwords the person knew.
Within the first week
- Preserve data. Convert the mailbox to a shared mailbox or archive it according to your retention policy, and move files to a supervisor or the matter file.
- Forward mail and set an automatic reply for a defined period, with a named contact.
- Reassign ownership of files, calendar items and matters.
- Rotate shared credentials and any service passwords the person had.
- Review audit logs for unusual downloads or forwarding rules in the final weeks, especially for involuntary departures.
- Update vendor portals such as court e-filing accounts, if they were tied to the individual.
Common Mistakes
- Relying on a verbal "let IT know" with no ticket
- Forgetting accounts that sit outside the main directory
- Keeping departed users' licenses active, which wastes money and leaves doors open
- Letting departing staff keep personal devices with firm email synced
- No record that offboarding was completed
Keep Evidence
Retain each completed checklist. Insurers and clients sometimes ask how you handle access, and a record is much stronger than a promise.
Support From Counsel Cyber
Counsel Cyber builds these checklists into our onboarding and offboarding ticket workflows for managed clients, so access is granted and revoked the same way every time. If you want a template tailored to your systems, ask us.