The Golden Onboarding Process for Remote BYOD Employees
It’s Friday afternoon. You’ve just hired someone great. They start Monday. They’re working remotely. They’re using their own laptop.
What happens next is either a smooth, secure onboarding, or a week of back-and-forth emails, shared passwords, and “can you just use your personal Gmail for now?”
Most firms fall into the second category. And every shortcut taken during onboarding creates a security gap that persists for the entire time that employee is with you.
Why onboarding is a security event
A new employee needs access to your systems. Every account created, every permission granted, and every device connected is a decision about who can touch your data. Get it right and you’ve got a productive, secure team member from day one. Get it wrong and you’ve got an unmanaged device with cached client data, no encryption, and credentials stored in a browser that syncs to a personal Google account.
The OAIC’s breach statistics are clear: 37% of reported data breaches in the first half of 2025 were caused by human error. Misconfigurations, accidental sharing, sending data to the wrong person. The kind of mistakes that happen when onboarding is rushed and ad hoc.
The FIIG Securities case put a number on it: inadequate resource management cost them $2.5 million in Federal Court penalties. One of the findings? No mandatory cyber security training for staff. Onboarding is where training starts, or doesn’t.
What goes wrong
The “just get them working” approach:
- IT creates an email account and sends the password in plain text via SMS
- The new starter logs in on their personal laptop with no encryption, no management
- Someone shares a OneDrive folder with “anyone with the link”
- The new starter downloads client files to their local desktop “just to review”
- They install Dropbox because “that’s what I used at my last firm”
- Three months later, nobody remembers what access they were given or why
Every step in that sequence is a breach vector. And it happens in professional services firms every week across SE Queensland.
The “no process” approach:
Even worse, some firms have no onboarding process at all. The new starter asks their manager for access. The manager asks whoever seems to know the systems. Permissions get granted based on “give them the same access as Sarah.” Nobody checks what Sarah actually has access to.
The golden onboarding process
Here’s what a secure, frictionless BYOD onboarding looks like, from offer acceptance to productive employee in one business day.
Before day one (HR + IT coordination)
Trigger: Signed employment contract received
- Create the identity. Microsoft 365 account provisioned with the correct licence (Business Premium for full security controls). Assigned to the right security groups based on role, not copied from another user.
- Prepare the device policy. Intune enrolment invitation ready to send. BYOD devices get a separate enrolment profile that manages the work partition without touching personal data.
- Stage the applications. Define which apps will be pushed to the device on enrolment: Outlook, Teams, OneDrive, any line-of-business applications. These deploy automatically, no manual installation required.
- Prepare access. SharePoint site permissions, Teams channel membership, shared mailbox access, all pre-configured based on role. Not “give them everything and we’ll tidy up later.”
- Queue the welcome. Automated welcome email scheduled for 8am Monday with clear instructions: enrol your device, set up your identity, complete security training.
Day one (the first two hours)
Step 1: Device enrolment (15 minutes)
The new starter receives an email with a Company Portal link. They install it on their personal device, sign in with their new credentials, and Intune does the rest:
- Enforces disk encryption (BitLocker on Windows, FileVault on Mac)
- Deploys a work profile that separates business data from personal data
- Pushes required applications
- Applies security baselines (password complexity, lock screen timeout, firewall)
- Blocks USB mass storage access to work data (not the whole device, just the work partition)
The employee keeps full control of their personal apps, photos, and data. Your firm gets a managed work environment on their device. Neither side compromises.
Step 2: Identity setup (10 minutes)
- MFA registration with Microsoft Authenticator (number matching enabled)
- Windows Hello or biometric setup for passwordless daily access
- Conditional Access verifies the device is compliant before granting access to any data
From this point forward, the user authenticates once each morning and works without interruption.
Step 3: Orientation and training (60 minutes)
- Security awareness training. Not a 45-minute video nobody watches. A focused, scenario-based module covering: phishing recognition, data handling expectations, incident reporting (who to call, what to do), acceptable use of personal devices for work
- Systems walkthrough. Where documents live (SharePoint, not local desktop). How to share files (links, not attachments). How to request access (help desk, not asking a colleague)
Step 4: Verify and confirm (15 minutes)
IT runs a compliance check:
- Device shows as compliant in Intune
- MFA is registered and working
- Conditional Access policies are applying correctly
- The user can access what they need, and nothing they shouldn’t
- A test email confirms mail flow, signatures, and encryption
Total elapsed time: under two hours. The new starter is working productively by morning tea.
Week one (settling in)
- Help desk checks in on day 3 and day 5: “anything not working?”
- Manager confirms the user has the right access for their role
- IT reviews sign-in logs for any anomalies (unusual locations, failed attempts, legacy auth attempts)
When they leave
This is the part most firms forget. Offboarding is onboarding in reverse, and it needs to be just as structured:
- Account disabled within the hour of departure (not “when IT gets around to it”)
- Device wiped: the work partition only. Personal data stays untouched. Intune selective wipe removes all corporate apps, data, and email from the device without factory-resetting their phone or laptop
- Shared access revoked. Removed from all Teams, SharePoint sites, and shared mailboxes
- Mailbox converted to shared mailbox for handover, then archived
- Sign-in logs reviewed for the final 30 days. Any unusual activity before departure?
What this protects you from
Data leakage on personal devices. Intune’s work profile means corporate data is encrypted and containerised. If the device is lost or stolen, you wipe the work partition remotely. Client data doesn’t end up on an unencrypted laptop in a café.
Shadow IT. When apps are deployed automatically and file sharing works properly, nobody needs to install Dropbox or use personal Google Drive. They have the tools. They just need them from day one.
Compliance gaps. Your cyber insurance proposal asks about device management, access controls, and offboarding procedures. Your professional obligations require safeguarding client data on every device that touches it. A documented onboarding process is evidence you take both seriously.
The “forgotten account” problem. Every firm has former employees whose accounts are still active months after they left. Automated offboarding triggers close that gap.
The cost of getting it wrong
An unmanaged personal device accessing your Microsoft 365 tenant is a breach waiting to happen. No encryption means a stolen laptop exposes client files. No conditional access means a compromised password gives an attacker the same access your employee had. No offboarding means a disgruntled former staff member still has their credentials.
The OAIC reports that 18% of reported breaches involve malicious insiders, departing employees who take data with them. Proper onboarding and offboarding processes are your defence.
How to start
If your firm currently onboards new starters with “ask Sarah to show you around the systems,” you need a process. It doesn’t have to be complicated. It just needs to be consistent.
Every Novaguard managed IT plan includes structured onboarding and offboarding as standard: provisioning, device enrolment, training, and deprovisioning. Because the most dangerous moment in your firm’s security isn’t a cyber attack. It’s a new starter on day one with no guidance and a personal laptop full of good intentions.
If you want to see what a proper onboarding process looks like for your specific setup, get in touch. We’ll walk you through it.
Not sure if your IT is actually working?
A Technology Business Review is an independent look at your current setup, no provider switch required. You get the findings either way.
More on this: Managed IT articles · Managed IT Services