Few events expose a firm's IT discipline as clearly as someone joining or leaving. A new associate who spends three days without email costs the firm money and sends a poor signal. A departed paralegal whose accounts remain active for months is a security gap and, in some cases, a confidentiality problem.
A written checklist, owned by someone specific, turns both events into routine work. Here is a version you can adapt.
Onboarding checklist
Before the first day
- Collect the request. HR or the administrator submits a standard form with name, role, start date, supervising attorney, office location and the systems the person needs.
- Create accounts. Set up the Microsoft 365 account, practice management user, document management access, phone extension and any research subscriptions based on a role template.
- Apply security defaults. Enroll in MFA, assign the standard security group, and enable mailbox and device policies.
- Prepare the device. Image and encrypt the laptop, install standard software and endpoint protection, and confirm it receives updates. Label it and record the serial number in the asset inventory.
- Assign permissions by role. Avoid copying another user's access wholesale, since it carries legacy exceptions. Grant access to matter workspaces as needed.
- Prepare welcome materials. A one-page guide covering how to get help, how to report a suspicious email, and where to find policies.
On the first day
- Hand over the device and walk the new person through sign-in and MFA enrollment.
- Set up the password manager and explain its use.
- Confirm email, calendar, phone, printing, remote access and practice management all work.
- Have them read and acknowledge the acceptable use, confidentiality and AI use policies.
- Schedule a short security awareness session within the first week.
In the first month
- Check in to ask what is not working.
- Verify the person has no unnecessary access and is not missing necessary access.
- Confirm training is complete and recorded.
Offboarding checklist
Before the last day
- Get advance notice where possible. The administrator informs IT of the departure date and whether it is voluntary. Involuntary departures may require access to be removed at a specific time.
- Plan matter transitions. Identify the matters, deadlines and client contacts to reassign. Confirm who will handle the departing attorney's mail and calendar.
- Handle client notice and file transfers. Departing attorney issues, such as client choice and file transfers, are ethics matters for the attorneys and the state bar rules. IT's role is to execute the technical side under partner direction.
On the last day
- Disable sign-in and revoke sessions. Block the account, sign out all devices and reset the password.
- Remove MFA methods and tokens. Prevent re-enrollment from a personal phone.
- Retrieve devices. Collect laptops, phones, security keys, badges and any storage devices. Record what was returned.
- Remove or wipe firm data on personal devices. If your policy allows mobile access on personal devices, use managed controls to remove firm data selectively.
- Disconnect third-party access. Remove the user from practice management, document management, research tools, e-signature, banking portals, and any shared mailbox or distribution list.
- Revoke app authorizations. Cancel any API tokens or connected apps created by the user.
After the last day
- Preserve data under policy. Retain the mailbox and files according to retention rules and any legal hold. Decide whether to convert the mailbox to a shared mailbox, set up forwarding with an auto-reply, and for how long.
- Delete or archive licenses. Reclaim paid licenses promptly to avoid unnecessary cost.
- Review logs. Check for unusual downloads or forwarding in the weeks before departure, especially after resignations.
- Update documentation. Remove the person from phone trees, website listings, and signature blocks.
Common pitfalls
- Accounts shared by a team, which cannot be cleanly disabled.
- Personal cloud storage or email used for firm work.
- Forgotten accounts at vendors that were set up by the departing person.
- Passwords known only to the departing employee.
- No inventory of which systems a person could reach.
Who owns the checklist
Name an owner for each step, typically HR or the administrator for requests and IT for execution. Add a sign-off at the end of each process, recorded in your ticketing system. Review the checklist twice a year and compare your user list to your staff roster as a cross-check.
Getting help
Counsel Cyber provides onboarding and offboarding as part of our managed IT for law firms, including role templates and audit checks of lingering accounts. If you would like to test your own process, we can compare your active accounts with your current roster and report anything that looks out of place.