Most small businesses hand a new employee a laptop, create a few accounts, and move on. The security configuration, if it happens at all, is inconsistent and depends on whoever happens to be available that day.
That approach creates quiet problems later: shared local admin rights, personal Microsoft accounts mixed with company ones, missing multi-factor authentication, unencrypted drives, and no clear record of what was installed. When the employee eventually leaves, cleaning up becomes harder than it needed to be.
A short, repeatable Day-One checklist solves most of these issues without turning onboarding into a multi-hour IT project. The version below is designed for teams without a dedicated security or IT department. It should take roughly 30 minutes once you have done it a couple of times.

Before the Laptop Is Handed Over
Do these steps yourself or with the person who manages devices:
Start with a clean device
If the laptop is new, leave it that way. If it is a reassigned machine, wipe it and reinstall the operating system. Do not carry forward the previous user’s files, accounts, or software.Create a standard local admin account (optional but useful)
Set up one local administrator account with a strong, unique password that only a small number of people know. This account is for emergency access and device management, not daily work.Prepare the company accounts the employee will need
Email, Microsoft 365 or Google Workspace, password manager, project tools, etc. Have the credentials ready so you are not creating them under time pressure while the new person is waiting.
The 30-Minute Setup Checklist
Work through these items in order with the new employee present when possible. It builds good habits from the first hour.
1. Sign in with the correct company account
Make sure the primary Windows or macOS login is the company-managed account, not a personal Microsoft or Apple ID. Personal accounts mixed into company devices create long-term access and recovery problems.
2. Enable full-disk encryption
Windows: Turn on BitLocker
Mac: Turn on FileVault
This single step protects the data if the laptop is lost or stolen. It should be non-negotiable for any device that leaves the office.
3. Install and configure the company endpoint protection
Install the antivirus or endpoint tool you have standardized on. Confirm it is updating and reporting correctly. Do not leave this for “later.”
4. Set up multi-factor authentication on key accounts
At minimum: company email, Microsoft 365 / Google Workspace admin-related accounts, password manager, and banking or financial tools if the role requires them. Use an authenticator app rather than SMS whenever possible.
5. Install a password manager and create the first vault
If the company uses a shared password manager (recommended), add the employee and have them install the browser extension and mobile app. This is the right moment to stop the habit of shared spreadsheets or browser-saved passwords.
6. Apply basic browser and system settings
Set the company homepage or start page if you use one
Disable unnecessary browser extensions
Confirm automatic updates are enabled for the operating system and browsers
Turn on the firewall if it is not already active
7. Remove local administrator rights for daily use (recommended)
The employee should work from a standard user account. Keeping daily work in a non-admin account reduces the damage if malware runs or a malicious site is visited. The separate local admin account created earlier remains available when elevation is genuinely needed.
8. Document what was done
Record the device serial number or asset tag, the primary user, the date of setup, and which major accounts were created. A simple shared spreadsheet or note is enough. This record becomes valuable at offboarding time.

What You Can Safely Skip on Day One
You do not need to configure advanced device policies, VPN profiles for every possible network, or detailed data-loss-prevention rules on the first day. Those can come later if your size and risk level require them.
The goal of Day One is to establish a clean baseline: correct accounts, encryption, endpoint protection, MFA on critical systems, and a password manager. Everything else builds on that foundation.
Why This Matters More Than It Seems
A consistent 30-minute setup prevents the most common small-business access problems before they start. It also makes offboarding dramatically easier months or years later, because you already know what accounts and protections exist on the device.
Most security gaps in small teams are not caused by sophisticated attacks. They are caused by inconsistent starting points. Fix the starting point and many later problems become smaller.
Secure enough begins on day one—with a short checklist that actually gets used.
No feedback yet — submit the first.