How Should an Insurance Agency Onboard and Offboard Employees Securely?
An insurance agency should use a documented IT checklist that begins at least 3–5 business days before a new employee starts and disables a departing employee’s access at or before the employee’s final working time.
For an agency with 25–50 employees, the checklist should coordinate human resources, management, IT, payroll, and application vendors. It should cover the employee’s computer, Microsoft 365 account, multi-factor authentication, agency-management system, carrier portals, shared files, phone service, security training, and company data.
A strong process should accomplish three measurable goals:
- The new employee can perform essential work on the first day.
- The employee receives only the access required for the role.
- A departing employee can no longer access agency systems, data, or devices.
Onboarding and offboarding are not routine administrative tasks. They are important cybersecurity, productivity, client-service, and compliance controls.
The 7-Part Employee Lifecycle Framework
- Submit a complete employee change request.
- Define access according to the employee’s role.
- Prepare accounts, equipment, and security controls.
- Complete first-day setup and training.
- Review access during employment.
- Disable and preserve access during offboarding.
- Verify completion and update documentation.
Using one repeatable framework reduces forgotten accounts, rushed equipment setup, excessive permissions, licensing waste, and unauthorized access after an employee leaves.
1. Submit a Complete Employee Change Request
The onboarding or offboarding process should begin with one approved request containing all information the IT provider needs.
Information Required for a New Employee
- Employee’s legal and preferred name
- Job title
- Department
- Manager
- Start date and expected start time
- Office or remote-work location
- Employment type
- Required email address
- Required applications
- Required shared folders and mailboxes
- Required telephone extension
- Whether a computer, monitor, or mobile device is needed
- Whether the employee is replacing another person
- Any unusual access requirements
Information Required for a Departing Employee
- Employee name
- Job title and department
- Manager
- Final working date and exact access-removal time
- Whether the departure is voluntary or involuntary
- Whether immediate access removal is required
- Who should receive the employee’s email and files
- Whether an automatic email response is needed
- Who will take ownership of client records and work in progress
- Which equipment must be returned
- Whether the employee worked remotely
- Any known security or legal concerns
Sensitive employment details should be shared only with authorized people. The IT team generally needs timing and technical instructions, not confidential explanations about the departure.
Use One Authorized Request Process
Employee changes should come from approved managers or human-resources personnel. An employee should not be able to request privileged access, a new administrator account, or access to another department without authorization.
The request process may use:
- A secured service portal form
- An approved human-resources workflow
- A standardized ticket template
- A documented management approval process
2. Define Access According to the Employee’s Role
Access should be based on job responsibilities rather than copied automatically from another employee.
A useful role-based access model may define standard requirements for:
- Producers
- Account managers
- Claims support personnel
- Accounting employees
- Human-resources employees
- Agency leadership
- Reception and administrative personnel
- Temporary staff
- IT administrators
Apply the Principle of Least Privilege
Least privilege means giving employees only the access needed to perform their assigned work.
For example:
- A producer may need access to client records and carrier portals but not payroll data.
- An accounting employee may need payment systems but not unrestricted access to every department’s files.
- A receptionist may need a shared calendar and phone console but not administrative access to Microsoft 365.
- A manager may need access to a former employee’s mailbox without receiving the employee’s password.
Create a Role-Based Access Matrix
| Role | Common Access Requirements | Access Usually Restricted |
|---|---|---|
| Producer | Agency-management system, carrier portals, email, Teams, client documents | Payroll, global administration, unrelated department records |
| Account manager | Client records, shared mailboxes, policy documents, carrier systems | Financial administration and privileged IT access |
| Accounting | Accounting software, payment systems, approved financial folders | Unrelated client or HR records |
| Human resources | Employee records, onboarding systems, payroll coordination | Unrelated client and accounting data |
| Executive | Leadership files, reporting systems, approved financial access | Technical administration unless specifically required |
| IT administrator | Separate privileged account for authorized administration | Routine email and web use through the privileged account |
The matrix should be reviewed whenever the agency adds a new application, restructures a department, or changes responsibilities.
Avoid Copying Excessive Access
Copying another employee’s permissions can reproduce years of unnecessary access. Use a standard role profile, then add approved exceptions individually.
3. Prepare Accounts, Equipment, and Security Controls
The IT provider should receive enough notice to prepare the employee’s environment before the start date. A standard onboarding request should ideally arrive at least 3–5 business days in advance. Specialized hardware or unusual software may require more time.
Prepare the Employee’s Computer
The computer should be:
- Business-grade and supported
- Assigned to the employee in the device inventory
- Updated with current operating-system and application patches
- Protected by full-disk encryption
- Configured with endpoint security
- Enrolled in remote monitoring and management
- Configured with approved applications
- Restricted so the employee does not have unnecessary local administrator rights
- Tested before delivery
Prepare Microsoft 365
Microsoft 365 setup may include:
- Creating the employee account
- Assigning the appropriate license
- Creating the email address
- Adding approved aliases
- Adding the employee to distribution lists
- Assigning shared mailbox access
- Adding approved Teams and SharePoint access
- Applying security and retention policies
- Configuring multi-factor authentication
- Applying conditional-access requirements
Passwords should be delivered through an approved secure method rather than ordinary email or an unprotected document.
Prepare Insurance Applications
Depending on the role, the employee may need access to:
- Applied Epic
- AMS360
- HawkSoft
- EZLynx
- Vertafore applications
- Carrier portals
- Comparative-rating tools
- Document-management platforms
- Electronic signature services
- Claims platforms
- Accounting applications
The agency should verify whether each application is managed by the MSP, an internal administrator, or a separate vendor.
Prepare Telephone and Communication Services
Setup may include:
- Telephone extension
- Voicemail
- Call queues
- Auto-attendant options
- Microsoft Teams calling
- Mobile application access
- Company directory listing
- Emergency calling location
Prepare Remote Employees
Remote employees may also require:
- Secure equipment shipping
- Delivery confirmation
- Remote setup appointment
- Home internet requirements
- Approved headset and monitors
- Secure access to cloud applications
- Remote support instructions
- Guidance for protecting confidential information at home
4. Complete First-Day Setup and Security Training
The employee’s first day should include both technical setup and clear expectations for using agency systems securely.
First-Day Technical Checklist
- Confirm the employee can sign in to the computer.
- Register approved multi-factor authentication methods.
- Verify Outlook and email access.
- Verify Microsoft Teams access.
- Test the agency-management system.
- Test required carrier portals.
- Confirm shared mailbox and folder permissions.
- Test the employee’s telephone and voicemail.
- Confirm printing and scanning where required.
- Explain how to contact the help desk.
Complete Security Awareness Training
New employees should complete security training during their first 5–10 business days, with critical security instructions provided before unrestricted access whenever practical.
Training should cover:
- Phishing and impersonation
- Unexpected multi-factor authentication prompts
- Password and password-manager requirements
- Client-data handling
- Approved file-sharing methods
- Payment and banking verification
- Remote-work security
- Lost or stolen device reporting
- Suspicious email reporting
- Incident escalation
Provide Help Desk Instructions
The employee should know:
- How to submit a routine request
- How to report an urgent outage
- How to report a suspected security incident
- Which support channels are approved
- What information to include in a ticket
- That passwords and authentication codes should never be included
911 IT’s managed IT services can provide a standardized help desk, device setup, Microsoft 365 administration, and employee support process.
5. Review Access During Employment
Onboarding is not the last time an employee’s access should be reviewed. Roles change, employees transfer departments, temporary projects end, and permissions accumulate.
Review Access After Role Changes
When an employee is promoted or transferred:
- Identify the new access required.
- Remove access that is no longer necessary.
- Review shared mailboxes and folders.
- Update application roles.
- Review privileged access.
- Update the equipment inventory.
- Document manager approval.
Do not simply add the new department’s permissions while leaving every previous permission in place.
Conduct Periodic Access Reviews
Agencies should review important access at least annually. More frequent review may be appropriate for privileged, financial, or sensitive systems.
An access review may cover:
- Active Microsoft 365 accounts
- Administrator roles
- Shared mailbox access
- SharePoint and Teams membership
- Agency-management application accounts
- Carrier portals
- Accounting systems
- Remote-access tools
- Third-party applications
- Guest and contractor accounts
Identify Inactive Accounts
Inactive accounts may belong to:
- Former employees
- Temporary workers
- Vendors
- Employees on extended leave
- Duplicate accounts
- Old administrator accounts
Inactive accounts should be investigated and disabled when they are no longer required.
6. Disable and Preserve Access During Offboarding
The exact timing of access removal should be approved by management or human resources.
For a routine departure, access should generally be disabled at the employee’s final working time. For an involuntary or high-risk departure, access may need to be disabled immediately before or during the termination meeting.
Immediate Account Actions
The offboarding process may include:
- Block Microsoft 365 sign-in.
- Revoke active sessions.
- Reset the account password.
- Review and remove MFA methods.
- Disable agency-management system access.
- Disable carrier portal access.
- Disable remote-access services.
- Disable telephone and mobile applications.
- Remove privileged administrative access.
- Disable access to third-party cloud applications.
Why Revoking Sessions Matters
Changing a password may not immediately terminate every active cloud session. The IT provider should revoke sessions and review connected applications when appropriate.
Review Mailbox Rules and Forwarding
Before transferring mailbox access, review:
- Automatic forwarding
- Inbox rules
- Delegated access
- Mobile-device connections
- Connected applications
- Suspicious sign-in activity
Unauthorized forwarding can continue exposing agency email even after the employee leaves.
Preserve Business Email Appropriately
Agency leadership should decide:
- Who needs access to the mailbox
- How long email should be retained
- Whether the address should remain active temporarily
- Whether an automatic response should be configured
- Whether incoming messages should be redirected
- When the license may be removed
Do not give a manager the former employee’s password. Use approved mailbox delegation or conversion procedures.
Transfer Files and Work in Progress
Transfer ownership of:
- OneDrive files
- SharePoint documents
- Microsoft Teams content
- Local computer files
- Client documents
- Open service requests
- Project documentation
- Shared spreadsheets
- Vendor records
The manager should identify which information is required for ongoing operations and which records must be retained under agency policies.
Recover Agency Equipment
Collect:
- Laptop or desktop computer
- Mobile phone
- Tablet
- Monitors
- Docking station
- Headset
- Security keys
- Building badges
- Office keys
- External drives
- Printed records
Remote employees should receive return instructions, shipping materials, tracking, and a deadline.
Do Not Wipe Devices Too Quickly
Before resetting or reassigning a device, confirm whether the agency, legal counsel, cyber insurer, or management requires preservation of:
- Local files
- Email records
- Browser history
- Application data
- Security logs
- Evidence related to an incident or dispute
After preservation requirements are satisfied, the device should be securely erased, updated, tested, and reassigned according to the agency’s process.
7. Verify Completion and Update Documentation
Offboarding should end with verification, not an assumption that every task was completed.
Final Offboarding Review
Confirm that:
- Microsoft 365 sign-in is blocked.
- Active sessions have been revoked.
- MFA methods have been removed or reviewed.
- Insurance applications are disabled.
- Carrier portal access is removed.
- Remote-access accounts are disabled.
- Administrative privileges are removed.
- Mailbox access has been reassigned appropriately.
- Files have been transferred.
- Equipment has been recovered.
- Licenses have been reassigned or removed.
- The employee has been removed from groups and directories.
- Technical documentation has been updated.
- The completion record has been retained.
Update Inventories and License Records
Update:
- Employee directory
- Device inventory
- Microsoft 365 licenses
- Software subscriptions
- Telephone extensions
- Application ownership
- Vendor contacts
- Emergency contact lists
- Shared mailbox permissions
Prompt license cleanup can reduce unnecessary monthly costs.
New Employee IT Onboarding Checklist
Before the Start Date
- Receive an approved onboarding request.
- Confirm the employee’s start date and location.
- Identify required hardware.
- Assign a supported computer.
- Install updates and approved software.
- Enable device encryption.
- Install endpoint security and management tools.
- Create the Microsoft 365 account.
- Assign the correct license.
- Configure email and aliases.
- Add approved groups and shared mailboxes.
- Create insurance application accounts.
- Request carrier portal access.
- Configure phone and voicemail.
- Prepare remote-work equipment.
- Schedule first-day IT setup.
On the First Day
- Verify employee identity.
- Provide initial sign-in instructions securely.
- Register multi-factor authentication.
- Test computer access.
- Test email and Microsoft Teams.
- Test the agency-management platform.
- Test shared files and mailboxes.
- Test telephone and voicemail.
- Review help desk procedures.
- Review urgent security reporting.
During the First 10 Business Days
- Complete security awareness training.
- Confirm all required application access.
- Remove access that was assigned accidentally.
- Verify backup or file-storage configuration.
- Confirm device inventory information.
- Resolve first-week support issues.
- Obtain manager confirmation that setup is complete.
Departing Employee IT Offboarding Checklist
Before the Final Working Time
- Receive an approved offboarding request.
- Confirm the exact access-removal time.
- Identify high-risk or immediate termination requirements.
- Identify the mailbox recipient or delegate.
- Identify file and client-record ownership.
- List equipment to recover.
- Coordinate with application administrators.
- Prepare remote-device return procedures.
- Identify any preservation or legal-hold requirements.
At the Approved Access-Removal Time
- Block Microsoft 365 sign-in.
- Revoke active sessions.
- Reset credentials.
- Review MFA registrations.
- Disable insurance applications.
- Disable carrier portals.
- Disable VPN and remote access.
- Disable telephone applications.
- Remove administrator privileges.
- Disable third-party cloud accounts.
After Access Is Disabled
- Review forwarding and mailbox rules.
- Delegate or convert the mailbox appropriately.
- Transfer files and application ownership.
- Configure an approved automatic response.
- Recover and inventory equipment.
- Preserve required records.
- Wipe and prepare returned devices.
- Remove unused licenses.
- Update documentation.
- Obtain final completion approval.
How Should an Agency Handle an Immediate Termination?
An immediate termination requires close coordination because access must be removed without warning the employee prematurely.
A practical sequence may include:
- Human resources or leadership submits a confidential request.
- The exact termination meeting time is confirmed.
- IT prepares the required account actions without disabling access early.
- At the approved time, IT blocks sign-in and revokes sessions.
- Agency personnel recover devices, keys, and badges.
- IT reviews account activity and forwarding.
- Files, email, and records are preserved.
- Managers confirm reassignment of active work.
- The completion checklist is documented.
When a cybersecurity, fraud, or legal concern exists, the agency may also need guidance from legal counsel, its cyber insurance carrier, or an incident-response specialist.
How Should an Agency Offboard a Remote Employee?
Remote offboarding requires additional planning because the employee may possess agency equipment and information outside the office.
The process should address:
- Exact access-removal timing
- Remote session revocation
- Mobile-device and application access
- Equipment shipping
- Package tracking
- Return deadlines
- Company files stored locally
- Printed client information
- Home-office equipment
- Confirmation of return
A managed device may support remote lock or wipe capabilities. Those features should be tested and used according to agency policy and legal guidance.
How Should Shared Passwords Be Handled?
Shared passwords should be minimized. Each employee should use an individual account whenever the application supports one.
When a departing employee knew a shared credential, the agency should:
- Identify the shared account.
- Change the password promptly.
- Update the approved password manager.
- Review multi-factor authentication methods.
- Review recent account activity.
- Notify only authorized users of the change.
Shared credentials should not be distributed through unencrypted email, spreadsheets, or ordinary documents.
What Accounts Are Commonly Forgotten During Offboarding?
Frequently overlooked accounts include:
- Carrier portals
- Electronic signature platforms
- Social media accounts
- Website administration
- Domain registrar access
- Accounting and expense systems
- Marketing platforms
- Cloud storage services
- Password managers
- VoIP mobile applications
- Remote desktop tools
- Vendor support portals
- Security cameras and building access systems
- Third-party applications connected to Microsoft 365
Maintaining an application inventory makes these accounts easier to identify.
Common Onboarding Mistakes
| Mistake | Potential Result |
|---|---|
| Submitting the request the night before the start date | Equipment, licensing, and vendor access may not be ready. |
| Copying another employee’s permissions | The new employee may receive excessive or inappropriate access. |
| Giving the employee local administrator rights | Malware and unauthorized software may create greater risk. |
| Sending passwords through ordinary email | Initial credentials may be exposed. |
| Delaying MFA enrollment | The account may remain weakly protected. |
| Skipping security training | The employee may not recognize phishing or reporting procedures. |
| Failing to test applications before the first day | The employee may lose productive time waiting for support. |
| Not confirming manager approval | Unnecessary access may remain unnoticed. |
Common Offboarding Mistakes
| Mistake | Potential Result |
|---|---|
| Disabling email but leaving other accounts active | The former employee may retain access to agency data. |
| Changing a password without revoking sessions | Existing cloud sessions may remain active. |
| Forgetting carrier portals | The employee may continue accessing insurance systems. |
| Giving a manager the former employee’s password | Accountability and security controls are weakened. |
| Deleting the account immediately | Business email, files, and records may be lost. |
| Wiping the computer before preservation review | Required business or legal evidence may be destroyed. |
| Failing to recover remote equipment | Agency devices and data may remain outside company control. |
| Leaving licenses assigned indefinitely | The agency continues paying for unused services. |
| Using no completion checklist | Important steps may be assumed rather than verified. |
A Practical Onboarding Scenario for a 40-Person Insurance Agency
A 40-person independent insurance agency hires a new commercial-lines account manager who will work remotely three days per week.
Five business days before the start date, the manager submits an approved request identifying:
- The employee’s role and start date
- Required Microsoft 365 access
- Applied Epic access
- Three carrier portals
- Two shared mailboxes
- Commercial-lines document folders
- A laptop, dock, monitors, and headset
- A telephone extension and call queue
Before the first day, the IT provider:
- Configures and updates the laptop.
- Enables encryption and endpoint security.
- Creates the Microsoft 365 account.
- Assigns approved groups and mailboxes.
- Coordinates insurance application access.
- Ships the equipment with tracking.
- Schedules a first-day remote setup appointment.
On the first day, the employee completes MFA enrollment, tests required systems, reviews help desk procedures, and begins security training.
Because the request was complete and submitted early, the employee can perform essential work on the first day instead of waiting for equipment and permissions.
A Practical Offboarding Scenario
A producer leaves the same agency after providing two weeks’ notice. The producer has a laptop, Microsoft 365 account, agency-management access, several carrier portal accounts, a VoIP mobile application, and locally stored client documents.
The agency prepares the following plan:
- Access will be removed at 5:00 p.m. on the final day.
- The sales manager will receive delegated mailbox access.
- Client files will be transferred to an approved SharePoint location.
- Open opportunities and client tasks will be reassigned.
- The laptop will be returned using prepaid tracked shipping.
- Carrier portal administrators will disable access.
- The IT provider will revoke Microsoft 365 sessions and review forwarding.
- The agency will retain the mailbox according to its policy.
The agency verifies every step before closing the offboarding request. No active account is left dependent on an assumption that another department completed the work.
Questions to Ask Your IT Provider
- How much notice do you require for a new employee?
- Do you provide a standardized onboarding form?
- Which setup tasks are included in our monthly agreement?
- Which applications require separate vendor coordination?
- How are initial credentials delivered securely?
- How is MFA configured?
- Do employees receive security training?
- How are computers encrypted and managed?
- How do you prevent unnecessary administrator rights?
- What is your immediate termination process?
- Can you revoke Microsoft 365 sessions?
- How do you review forwarding and mailbox rules?
- How are former employee files transferred?
- How are remote devices recovered?
- How are licenses reclaimed?
- Do you provide a completed checklist or report?
- How are carrier portal accounts tracked?
- How often do you review inactive accounts?
- How do you preserve data before wiping a device?
- Which onboarding or offboarding services cost extra?
Frequently Asked Questions
How much notice should IT receive before a new employee starts?
Submit a complete request at least 3–5 business days before the start date. Additional time may be required for new hardware, shipping, specialized software, or vendor-managed applications.
When should a departing employee’s access be disabled?
Access should generally be disabled at or before the employee’s approved final working time. Immediate or involuntary departures may require coordinated removal during the termination meeting.
Is changing the employee’s password enough?
No. The agency should also revoke active sessions, review MFA methods, disable other applications, remove remote access, and review mailbox forwarding and connected services.
Should the employee’s Microsoft 365 account be deleted immediately?
Usually not. The agency may need to retain email, transfer files, delegate mailbox access, or preserve records before removing the account and license.
Can a manager use the former employee’s password?
No. Use approved mailbox delegation, file transfer, or application reassignment procedures rather than sharing the former employee’s credentials.
Who should approve application access?
The employee’s manager or another designated business owner should approve access. IT should implement approved permissions but should not independently decide which sensitive business information the employee needs.
Should contractors follow the same process?
Yes. Contractors, interns, temporary workers, and vendors with access should have approved start and end dates, limited permissions, security requirements, and documented offboarding.
How often should employee access be reviewed?
Review critical access at least annually and after promotions, transfers, extended leave, department changes, or major application changes. Privileged and financial access may require more frequent review.
What happens to a former employee’s OneDrive files?
Required business files should be transferred to an approved manager or shared location before the account is deleted. The process should follow the agency’s retention requirements.
Should the MSP contact every carrier directly?
That depends on the agreement and each portal’s administrative model. The agency should document who owns carrier access and verify that every account is disabled.
How should remote equipment be returned?
Use documented shipping instructions, prepaid labels, tracking, a return deadline, and inventory confirmation. Preserve required data before wiping or reassigning the device.
Can automated onboarding replace human review?
Automation can improve consistency, but managers should still approve access and verify that the employee receives only the permissions required for the role.
Make Employee Changes Predictable and Secure
A reliable onboarding and offboarding process protects client information while helping employees become productive faster.
Use the seven-part framework:
- Submit a complete and authorized request.
- Assign access according to the employee’s role.
- Prepare equipment, accounts, and security controls.
- Complete first-day testing and training.
- Review access throughout employment.
- Disable and preserve access during offboarding.
- Verify every action and update documentation.
The agency should submit routine onboarding requests at least 3–5 business days in advance, complete new-hire security training during the first 5–10 business days, and remove departing employee access at the approved final working time.
911 IT provides managed IT services, Microsoft 365 and cloud administration, cybersecurity services, and business continuity and data protection for organizations that need standardized employee setup, secure access management, and responsive support.
Are employee onboarding and offboarding requests creating delays or leaving security gaps? Schedule a discovery call with 911 IT to review your employee lifecycle process, Microsoft 365 access, device management, application permissions, security training, and account-removal procedures.
