SOP templatesIT

User Account Provisioning SOP Template

A ready-to-use SOP for creating new hire accounts, assigning least-privilege access and enrolling multi-factor authentication before the employee's first day.

FreeNo sign-upWord, PDF, Excel & CSV
Ilia PirozhenkoReviewed by Ilia Pirozhenko, Founder, Perfect WikiUpdated September 15, 202613 steps4 roles4 min read
Standard operating procedureSOP-IT-001 ยท Rev 1.0
Owner
IT Service Delivery Manager
Effective date
September 15, 2026
Review cycle
Every 12 months

1.Purpose

To make sure every new hire receives working accounts and only the access their role requires, granted with manager approval and secured with multi-factor authentication before day one.

2.Scope

Applies to creating new employee identities, mailboxes, group memberships and application access requested through HR onboarding. Password resets and periodic access reviews for existing employees are covered by separate SOPs.

Definitions

Onboarding ticket
The ticket raised in the ticketing system to request a new hire's accounts and access.
Identity provider (IdP)
The system of record for user identities, used for single sign-on and account creation.
Least privilege
Granting only the access a role needs to do its job, and no more.
Role-based access profile
A predefined set of application and group access mapped to a job role or department.

3.Responsibilities

Service Desk Analyst
Validates onboarding requests, delivers credentials, and confirms the new hire can log in.
System Administrator
Creates identities, provisions accounts and application access, and configures MFA.
Hiring Manager
Approves the access profile and scope requested for the new hire.
HR Coordinator
Submits the onboarding request with role, department and start date.

RACI matrix

ActivityService Desk AnalystSystem AdministratorHiring ManagerHR Coordinator
Submit the onboarding requestI-CR/A
Approve the requested access scopeI-R/AC
Create identity and provision accountsCR/AI-
Verify least-privilege access is appliedR/ARI-
Deliver credentials and confirm loginR/ACII

R = Responsible, A = Accountable, C = Consulted, I = Informed

4.Materials and PPE

Materials, tools and systems

  • โ†’Onboarding ticket in the ticketing system
  • โ†’Identity provider admin console
  • โ†’Role-based access profile template
  • โ†’MFA enrollment tool
  • โ†’Access register or asset management system
  • โ†’Secure credential delivery channel

5.Procedure

  1. 5.1

    Receive the onboarding request

    HR Coordinator

    The HR Coordinator submits the onboarding ticket with the new hire's name, start date, job title, department and manager. The ticket must reach the service desk at least two business days before the start date.

  2. 5.2

    Verify request and approval are complete

    Service Desk Analyst

    The Service Desk Analyst checks that the manager's approval of the requested access scope is attached to the ticket before doing any work.

    Checkpoint: The account is never created until manager approval is attached to the ticket, regardless of the start date.

  3. 5.3

    Select the role-based access profile

    System Administrator

    The System Administrator matches the new hire's job title and department to the standard role-based access profile, which lists the exact groups and applications to grant.

  4. 5.4

    Create the identity

    System Administrator

    The System Administrator creates the account in the identity provider with a unique username and a temporary password that must be changed at first login.

  5. 5.5

    Provision mailbox and calendar

    System Administrator

    The System Administrator provisions the new hire's mailbox, calendar and shared distribution list memberships defined in the access profile.

  6. 5.6

    Assign security groups

    System Administrator

    The System Administrator adds the account to the security groups and distribution lists listed in the access profile for the new hire's role.

  7. 5.7

    Provision application access

    System Administrator

    The System Administrator grants access to the ticketing system, file shares and business applications named in the access profile, and nothing beyond that list.

    Checkpoint: The granted access matches the role-based access profile exactly, with no extra applications or admin rights added.

  8. 5.8

    Configure MFA enrollment

    System Administrator

    The System Administrator sends the new hire an MFA enrollment link tied to the temporary password and confirms enrollment is required before the account can sign in to company applications.

    Warning: Never share an MFA enrollment link or code over an unverified channel; confirm the recipient's identity first.

  9. 5.9

    Notify the hiring manager and HR

    Service Desk Analyst

    The Service Desk Analyst notifies the hiring manager and HR Coordinator that the accounts are ready and shares the credential delivery plan.

  10. 5.10

    Deliver credentials securely

    Service Desk Analyst

    The Service Desk Analyst sends the username and the temporary password through two separate channels, such as a portal message and a phone call, never in the same email.

    Warning: Sending a username and temporary password together in one message defeats the purpose of separate verification.

  11. 5.11

    Confirm first login and MFA

    Service Desk Analyst

    On day one, the Service Desk Analyst confirms with the new hire that they logged in, changed the temporary password and completed MFA enrollment.

    Checkpoint: The new hire has signed in, changed the password and enrolled MFA before being marked ready to work.

  12. 5.12

    Log the account in the access register

    Service Desk Analyst

    The Service Desk Analyst records the account details, access profile and creation date in the access register or asset management system.

  13. 5.13

    Close the onboarding ticket

    Service Desk Analyst

    The Service Desk Analyst closes the ticket once the account, access and MFA enrollment are all confirmed working, and archives the approval documentation.

6.Quality checks

  • โ†’New hires have working login, email and required application access before the start of their first day.
  • โ†’Access granted matches the role-based access profile exactly, with no extra permissions added.
  • โ†’MFA is enrolled before the account is used to access any company application.
  • โ†’Every onboarding ticket includes documented manager approval before account creation.

7.Records

  • โ†’Approved onboarding request ticket
  • โ†’Access register entry for the new account
  • โ†’MFA enrollment confirmation
  • โ†’Credential delivery confirmation

8.KPIs

  • โ†’Percentage of accounts ready before the new hire's start date
  • โ†’Average time from approval to completed provisioning
  • โ†’Number of access exceptions found during later access reviews

9.Common mistakes

  • โ†’Creating the account before manager approval is attached to the ticket.
  • โ†’Copying an existing employee's access instead of using the role-based access profile.
  • โ†’Sending the username and temporary password in the same message.
  • โ†’Forgetting to require MFA enrollment before the account can sign in.
  • โ†’Leaving the ticket open after the account and access are confirmed working.

10.Revision history

RevisionDateDescriptionReviewed by
1.0September 15, 2026Initial releaseIlia Pirozhenko

This is a template. Adapt it to your organization, equipment and local regulations before use.

Ask this SOP

Nobody opens a PDF in the middle of a task. They ask.

Add this SOP to Perfect Wiki and your team gets answers in the chat app they already use, with a link to the exact step. Ask from ChatGPT, Claude or Copilot too.

Perfect Wiki AIExample answer

The new hire's manager hasn't approved access yet but they start tomorrow, what do I do?

Do not create the account until the approval is attached to the ticket, even if the start date is tomorrow. Follow up with the hiring manager directly and let HR know the account will be ready as soon as approval is recorded.Source: step 5.2 ยท Verify request and approval are complete
Ask your own question about this SOPโ€ฆSign up to keep asking
Word file vs Perfect Wiki

A downloaded SOP starts going out of date the day you save it.

Screen recorders like Scribe and Tango capture clicks. Perfect Wiki holds the whole procedure, including your recorded guides, and answers questions about it.

Word or PDFPerfect Wiki
Finding itDig through folders and email threadsAsk in Teams, Slack, kChat or Mattermost
Keeping it currentEmail a new version and hopeEdit once with AI, everyone sees the update
Everything in one placeText and imagesEmbed Scribe and Tango guides, SharePoint files and videos
Who can change itAnyone with the fileEditors you choose, everyone else reads
Common questions

Frequently asked questions

Didn't find what you're looking for? Contact our support โ†’

Your SOP library

Keep every SOP where your team can ask it.

Perfect Wiki is the knowledge base for Microsoft Teams, Slack, kChat and Mattermost. Store your SOPs, embed your Scribe and Tango guides, and let AI answer questions with a link to the right step.

No credit cardSetup in under 10 minutesCancel anytime