Blog

IT Onboarding Checklists for MSP Hires and Client Staff

Written by Nia Rabanes | Oct 5, 2026, 8:03:46 PM

An IT onboarding checklist can mean two different jobs for an MSP: train a new employee on your own team, or set up accounts, devices and access for a new employee at a client. Use the right checklist below. The first ends with a manager judging observed work; the second ends with a client's authorized owner confirming access and exceptions.

Choose the Right Checklist

  • New MSP employee: give a teammate the tools, training, practice and supervision to work your desk.
  • New client employee: fulfill an authorized request for identity, device and application access under that client's policy.

The complete checklists are on this page. Each MSP and client sets its own access and security policy, so adapt the tasks before using them. A printable PDF of both checklists is at the end of this post.

Before You Start: Name the Owner and Evidence

For an MSP hire, the service manager owns the training path and a supervisor decides when observed work is ready. For a client hire, an authorized client requester approves the role and access; the MSP technician acts within that approval. Record a ticket, assignment or document link that proves each step was done, plus any exception and who accepted it. Do not put passwords or sensitive personal data in this checklist.

Access should match the role rather than a convenient default. Microsoft's least-privilege guidance describes granting only the access needed for a job. CISA's MFA guidance explains why the authentication method matters. Follow the client's actual policy and approved stack; these links do not give the MSP permission to make changes without authorization.

Checklist 1: Onboard a New MSP Employee

Use this checklist for your own employee, such as a new help desk technician. Record a proof link in the system your MSP uses. A completed course prepares the hire for observed work; it does not replace a supervisor's sign-off.

Each task names its owner and the proof to keep. Record a real link or an approved exception, not a guess. An Empath tag names the training part Empath can handle; your team still reviews work, signs off and checks tickets.

  1. Before day one: confirm role, supervisor, start date and who can approve access

    Owner: Service manager · Proof: Approved hiring handoff

  2. Approve identity, PSA, documentation, RMM and support-channel access by role

    Owner: Service manager · Proof: Access request or exception

  3. Assign a mentor for supervised ticket work

    Owner: Service manager · Proof: Mentor and handoff note

  4. Day one: verify sign-in and show where to ask for help

    Owner: Mentor · Proof: Sign-in and channel check

  5. Show ticket notes, time logging and the escalation route

    Owner: Mentor · Proof: Observed walk-through

  6. Assign Introduction to Tickets and Triage and the local escalation SOP

    Owner: Training owner · Proof: Path assignment

    Empath Learn: assign and track the course and SOP lesson

  7. First week: review a ticket handled under supervision

    Owner: Mentor · Proof: Observed ticket and feedback

  8. Assign Ticket Escalations 101 and the MSP's time-tracking lesson

    Owner: Training owner · Proof: Course assignments

    Empath Learn: assign and track the lessons

  9. Practice a customer update and record supervisor feedback

    Owner: Supervisor · Proof: Coaching note

  10. First month: review assigned work, training progress and gaps

    Owner: Service manager · Proof: Progress and review note

    Empath Learn: training progress report

  11. Add role-appropriate Microsoft Learn material or a lab where useful

    Owner: Training owner · Proof: Assignment and practice record

    Empath Learn: Microsoft Learn content and labs, assigned and tracked

  12. Sign off on observed work, or name the next supervised step

    Owner: Supervisor · Proof: Decision and owner

First 90 Days: Role and Career Growth

  1. Agree a 30-60-90 plan: what the hire owns at 30, 60 and 90 days

    Owner: Supervisor

  2. Name the next step on their ladder (Tier 1 to Tier 2, dispatch, a specialty) and the skills it takes

    Owner: Service manager

  3. Pick one certification goal (for example CompTIA A+ or a Microsoft role exam) with a target date; assign its prep path

    Owner: Training owner

    Empath Learn: certification prep path

  4. Practice in a hands-on lab before touching a client system

    Owner: Training owner

    Empath Learn: hands-on labs

  5. Rehearse a hard customer call with an AI roleplay

    Owner: Mentor

    Empath Learn: AI roleplays

  6. 90-day review: what is done, the next skill, the next course path

    Owner: Service manager

    Empath Learn: progress report and next course path

These are checkpoints, not a promise that a technician is ready after a fixed number of days. Keep the mentor's judgment and the manager's assignment record separate. A difficult client escalation can reveal a gap that a completed lesson alone cannot show.

Checklist 2: Onboard a New Employee at an MSP Client

This is a service request for the client, not staff training for your MSP. Start with an authorized requester and the client's policy. Use only the applications, licensing and device process that client approved. A role or access question is an exception to resolve, not permission to guess.

A tech often teaches the new user by hand, on a call or at the desk. The same how-to questions can come back as tickets. Empath Grow is a separately priced LMS for client staff; it does not provision accounts or devices. Pair its security basics with the MSP's phishing tool. Empath runs no phishing simulations.

  1. Intake: confirm authorized requester, hire date, role and location

    Owner: Client requester · Proof: Approved service request

  2. Confirm approved device, licenses, apps and any access exceptions

    Owner: Client requester · Proof: Role and access approval

  3. Create or assign identity under the client's policy

    Owner: MSP technician · Proof: Ticket action record

  4. Apply approved groups and least-privilege app access

    Owner: MSP technician · Proof: Access check, no secrets

  5. Arrange licenses and device enrollment or delivery

    Owner: MSP technician · Proof: License and asset handoff

  6. Arrange the client's MFA enrollment path

    Owner: MSP technician · Proof: Enrollment confirmation

  7. Day one: test sign-in, device and network or VPN where applicable

    Owner: MSP technician · Proof: Test result or exception

  8. Test email, collaboration apps and required business apps

    Owner: Client employee and MSP · Proof: User-confirmed result

  9. Explain the support route and hand off to the client's manager

    Owner: MSP technician · Proof: Handoff note

  10. After start: resolve or record open exceptions

    Owner: MSP ticket owner · Proof: Exception owner and next step

  11. Confirm the employee can work and close after owner sign-off

    Owner: Client requester · Proof: Approval in service ticket

Day One and After: Teach the New User

  1. Show Outlook basics: inbox, calendar, shared mailboxes

    Owner: Tech

    Empath Grow: Outlook courses

  2. Show Teams and where files live (OneDrive, SharePoint)

    Owner: Tech

    Empath Grow: Teams and SharePoint courses

  3. Word and Excel basics the role needs

    Owner: Client manager

    Empath Grow: Word and Excel courses

  4. Safe use of AI and Copilot: what company data may go into AI tools

    Owner: Client manager + tech

    Empath Grow: Copilot and AI courses

  5. Security basics: phishing, MFA prompts, how to report something odd

    Owner: Tech

    Empath Grow: security awareness courses

  6. Assign the role's starter courses with a due date; the client manager sees completion

    Owner: Client manager

    Empath Grow: assigns with due dates and reports completion (not Grow Lite)

  7. 30-day check: which how-to tickets did the new user open? Point repeat questions to a course

    Owner: Tech or account manager

    Empath Grow: the follow-up course

Use the client's own approval and retention rules for evidence. Record a ticket link or a status, not a password, recovery code, personal identifier or unrestricted account export. Where the client does not use VPN, an RMM agent or a particular app, mark the step not applicable under the client's process instead of creating unnecessary access.

What Belongs in a Training Path, SOP or Live Handoff?

The marked MSP hire rows belong in an Empath Learn path for your own team. Choose ticket and certification courses from the Empath course catalog, add a hands-on lab or AI roleplay, and use progress reports at the manager review. Keep the escalation SOP in your documentation or add it as a text lesson. A mentor still watches real work, and a supervisor signs off.

The client hire's access and device tasks stay in the service ticket. The marked teach-the-user rows belong in Empath Grow, a separately priced client LMS that can assign starter courses with due dates and report completion to the client manager. Grow Lite is watch-only, so use Grow for assignments. Empath's own courses are for Learn, not client staff. As of October 2026, available client catalogs include Clip Training's Microsoft 365 courses and Bigger Brains courses on Outlook, Teams and Copilot; premium catalogs are add-ons. Empath Grow does not approve access, create accounts or enroll devices.

Empath was built to make these steps easier. The training rows run as paths you assign and track, for your own team in Empath Learn and for your clients in Empath Grow.

See It in Empath

Walk through an MSP role path and a client training plan with our team.

Book a Demo

Take the Checklists With You

Both checklists as a four-page printable PDF, ready for your next hire.

Get the Checklists

Download the Printable Checklists

Get both checklists as a four-page printable PDF. Enter your work email and the download link appears right away.

The printable PDF has one section for an MSP hire and one for a client hire, each with Task, Owner, Proof/link and Done fields. Leave proof fields blank until the responsible person records a real location. Never put credentials or sensitive personal data on a printed copy.

Frequently Asked Questions

What is the 30-60-90 onboarding rule?

An employer guide to 30-60-90 plans describes goals for a new hire's first three months: agree what they should own by day 30, 60 and 90, then review the work and adjust the next goal. For an MSP technician, pair course progress with observed ticket work. The dates are checkpoints, not an automatic sign-off.

Which checklist is for a new MSP technician?

Use Checklist 1 for an employee joining your own MSP team. It covers role and tool access, mentor assignment, MSP courses, local SOPs, supervised tickets and a manager review. Checklist 2 is for a client company's employee who needs approved accounts, a device and application access. Keep the two ownership records separate.

What does an MSP need from a client before provisioning a hire?

Get an authorized request that names the hire's role, start date, location, device and required applications, plus any approved exception. Follow the client's access and security policy. If the requester cannot approve a role or a privilege, pause that item and record the decision owner. Do not infer access from another employee's account.

Is course completion enough for a new technician?

No. An assigned Empath Learn course can show that a technician completed the preparation. A supervisor must still observe how they handle a real ticket, communicate with a client and follow the escalation rule. Record that sign-off or the next supervised task. Course completion is evidence of training, not a universal readiness certificate.

How should completion and exceptions be tracked?

Use the system that owns each job. Keep MSP employee course assignments and progress in the staff training path, with observed-work sign-off from a supervisor. Keep client provisioning actions, approvals and exceptions in the service ticket or approved client record. Name the owner and next step for anything unfinished; close only after the proper handoff.