MSP Technician Onboarding Checklist Template

A new technician can reach every client you manage. Their first ninety days should earn that access one step at a time, not hand it all over on day one.

Hiring a technician at an MSP is not like hiring at most businesses. On day one the new starter can be given access to the PSA, the RMM, the documentation platform, the password vault and the remote access tools, and between them those reach every client you look after. Give all of it at once and you have widened your attack surface before they have closed a ticket. Hold it all back and they spend a fortnight unable to help. This free MSP technician onboarding checklist gives service managers and service-desk leads a repeatable way to bring each new technician up to speed. It covers least-privilege accounts before day one, orientation on your clients, services and SLAs, security and confidentiality, tools training and shadowing, a ticket ladder that grants elevated access only with a service manager’s approval, and the 30, 60 and 90-day reviews. A conditional phase adds onsite readiness for field technicians.

Use This Template Free See Live Example
No Credit Card Required

HR Onboards the Employee. The Service Desk Onboards the Technician.

A general onboarding process still applies to a new technician. The contract, right-to-work checks, payroll, the welcome and the probation reviews are the same as for anyone else, and the Employee Onboarding Checklist covers them well. What it can’t cover is the part specific to an MSP: access to other organisations’ systems, and the judgement to use it safely.

That part belongs to the service manager. It decides which clients the technician can see, which roles they hold in the RMM and in client tenants, when they are trusted to run scripts or reset an administrator’s MFA, and how the service desk’s rules on tickets and time entries are learned before they become habits. Run the two checklists side by side: HR owns one, the service manager owns the other, and neither assumes the other has handled the access.

Employee onboarding

Owned by HR and the line manager

Covers: contract, payroll, policies, welcome, probation.

Done when: the new hire is settled, paid and has passed probation.

Risk if missed: a poor start and an early leaver.

Technician onboarding

Owned by the service manager

Covers: client access, tools, security, service rules, the ticket ladder.

Done when: the technician works independently with exactly the access their role needs.

Risk if missed: an over-privileged account that reaches every client.

What the MSP Technician Onboarding Checklist Covers

Seven phases take a new technician from accounts before day one to the 90-day review. Phase 6 appears only for field or onsite technicians.

Phase 1

Phase 1: Before Day One: Accounts & Access

Grant the first rung of the ladder only. Everything else is approved later, in Phase 5.

  • Create the named identity — a personal account in your own tenant with MFA enforced, using a phishing-resistant method where you can
  • Provision the PSA — a technician role with the right ticket queues and time entry, and no access to billing or agreements
  • Provision the RMM — a tier-one role scoped to the clients they will support, with remote sessions logged
  • Grant documentation and vault access — only the clients and folders their tier needs, never the whole vault
  • Add them to your first-tier delegated admin groups — the Microsoft partner security groups for their tier, not a standing global admin role
  • Prepare the laptop — enrolled in management, protected by EDR and carrying only your approved remote access tools
Phase 2

Phase 2: Orientation: Clients, Services & Rules

  • Walk through the service catalogue — what each agreement covers, what is billable and what needs a quote
  • Introduce the client base — the largest clients, their key contacts, VIP users and the quirks every technician should know
  • Explain SLAs and priorities — the priority matrix, response and resolution targets, and how the clock is paused
  • Set the ticket and time-entry rules — note standards, time entered the same day and what a closing note must say
  • Explain escalation — who to escalate to, when, and how on-call works out of hours
Phase 3

Phase 3: Security & Confidentiality

  • Sign the confidentiality and acceptable use policies — covering client data, credentials and personal devices
  • Complete security awareness training — phishing, vishing and your incident reporting route
  • Train on caller verification — confirm a caller’s identity through a known channel before any password reset or MFA change
  • Review credential handling — credentials live in the vault, never in tickets, chat or email
  • Confirm the approved remote access tools — use only the tools you have approved, and report any other tool found on a client device
Phase 4

Phase 4: Tools Training & Shadowing

  • Train on the PSA — ticket workflow, time entry, statuses and the views the service desk uses
  • Train on the RMM — alerts, device views and patch status, with scripting held back until a later rung
  • Train on the documentation platform — find a client’s procedure, contacts and network details quickly
  • Shadow the service desk — listen to calls and watch triage, then reverse-shadow with a mentor watching
  • Review the first ten tickets — the mentor checks notes, time entries and closing notes and gives feedback
Phase 5

Phase 5: The Ticket Ladder

Each rung adds access. The service manager approves every step up, and the approval is recorded.

  • Rung 1: simple requests — password resets with caller verification, new-user requests and how-to questions
  • Rung 2: first-line incidents — incidents for the clients they are assigned to, with escalation when they are stuck
  • Approve elevated access — the service manager reviews ticket quality and approves the next permission set; not approved holds the technician on their current rung
  • Grant the approved access — add the technician to the higher-tier groups and record what was granted and when
Phase 6 — Field Technician

Phase 6: Onsite Readiness

Shown only for technicians who visit client sites. Conditional logic removes it for desk-based roles.

  • Check driving and vehicle cover — a valid licence and insurance that covers business use
  • Complete site inductions — health and safety, building access and any client-specific site rules
  • Issue the field kit — tools, spares, cables and labels, with the stock recorded
  • Explain lone working — check-in times and what happens when a technician doesn’t check in
  • Set the device handling rules — how collected or replaced equipment is recorded, transported and disposed of
Phase 7

Phase 7: 30/60/90-Day Review

  • Hold the 30-day review — ticket quality, time-entry compliance, client feedback and the mentor’s view
  • Hold the 60-day review — first-contact resolution, documentation contributions and readiness for the next rung
  • Hold the 90-day review — confirm the role, the probation outcome with HR and the development plan
  • Review the technician’s access — confirm every permission matches their rung and remove anything granted temporarily

Graduated Access: What Each Rung Allows

A ticket ladder ties access to demonstrated competence. Each rung lists the work a technician takes on and the access that work needs, and the service manager approves every step up. The rungs below are a common pattern, not a standard. Adapt them to your service tiers and the tools you use, and write down the criteria for each step up so two service managers would make the same decision.

Rung Typical work Access To move up
1. RequestsPassword resets, new users, how-to questionsPSA, read-only RMM, help desk roles in client tenantsClean ticket notes and verified identity on every reset
2. First-line incidentsIncidents for assigned clients, with escalationRemote control, documentation for assigned clientsGood first-contact resolution and accurate time entries
3. Second-lineServer, network and Microsoft 365 issuesHigher admin roles for assigned clients, RMM scriptingService manager approval and a mentor’s sign-off
4. Projects and escalationsOnboarding, migrations, change workBroader client scope, change rights, policy editsService manager approval and a review of recent changes

Why access is the part that can’t wait

MSPs are attractive targets because one compromised account can reach many clients. CISA’s joint advisory on threats to MSPs asks providers to apply least privilege in their own and their customers’ environments, to require MFA on every account with access to customer environments and to disable accounts that are not in use. Microsoft requires MFA on every user account in a partner tenant, and recommends assigning partner users to delegated admin security groups rather than a standing admin agent role.

Two newer patterns make the security phase more than a formality. Attackers have posed as employees to persuade help desks to reset passwords and move MFA to a device they control, which is why caller verification is trained before a technician takes a reset ticket. And legitimate remote access software is regularly abused, which is why a new technician should know exactly which tools you use, and treat anything else on a client device as suspicious. Neither lesson sticks if it is taught once in a slide deck, so the checklist puts each one on a named task with a due date and a person who confirms it was done.

Why Onboard MSP Technicians in CheckFlow?

1

Every technician onboarded the same way

Launch the checklist for each new starter with the start date, service manager and mentor filled in. Relative due dates put the account tasks before day one and the reviews at 30, 60 and 90 days, and conditional logic adds the onsite phase only for field technicians.

2

Elevated access approved, on the record

The step up the ticket ladder is an approval. Until the service manager marks it approved, the task that grants the access stays locked, and the record shows who approved what and when. That is the kind of evidence an insurerThat record is what an insurer or a client’s auditor asks for.rsquo;s questionnaire or a clientThat record is what an insurer or a client’s auditor asks for.rsquo;s auditor is likely to ask for.

3

Nothing left between HR and the service desk

Assign tasks to the service manager, the mentor, HR and the technician, each with a due date. The my-work view shows each person what is theirs today, and the grid view shows every new starter’s progress in one place.

Technician onboarding is one of the internal processes the MSP process management guide recommends standardising early, because it shapes how every later ticket is handled. See how CheckFlow for MSPs runs it alongside client processes, and how CheckFlow’s onboarding software handles the HR side.

When a technician leaves, the access you granted rung by rung has to come off just as carefully. The IT offboarding security checklist covers removal, and the MSP Client Onboarding Checklist is a good second-rung project for a technician to shadow.

Frequently Asked Questions

How long does it take to onboard an MSP technician?

+

Most MSPs expect a new service desk technician to handle simple requests within the first two weeks and first-line incidents within a month or two, with the 90-day review confirming them in the role. Experienced hires move up the ladder faster, but they still start on the first rung, because they need to learn your clients, your tools and your rules before they are given broad access.

What access should a new MSP technician have on day one?

+

Enough to do first-rung work and no more: a named account with MFA, the PSA with a technician role, read-only or tier-one RMM access for the clients they will support, documentation and vault access for those clients, and the delegated admin groups for their tier. Global admin roles, RMM scripting and access to every client in the vault should wait for an approved step up.

What is a ticket ladder?

+

A ticket ladder is a set of rungs that match types of work to the access they need, from simple requests up to second-line and project work. A technician moves up when they have shown they can handle the current rung well, and the service manager approves each move. It ties privilege to competence and makes the reasons for each permission easy to explain later.

How should GDAP be set up for new technicians?

+

Microsoft’s guidance is to assign Microsoft Entra roles to security groups in your partner tenant and manage access by adding users to those groups. Build groups by tier, give the first-tier group the least-privileged roles for help desk work, and add a new technician to that group only. Moving up a rung then means adding them to another group, which is easy to record and to reverse.

How is this different from a general employee onboarding checklist?

+

A general employee onboarding checklist covers HR: contracts, payroll, policies, the welcome and probation. This template covers what is specific to an MSP technician: least-privilege access to client environments, your service rules, your tools, security training for help desk work and a graduated ticket ladder. Run both together. HR owns the employee checklist and the service manager owns this one.

How do we stop new service desk staff being social-engineered?

+

Train caller verification before a technician takes a single reset ticket, and make it a rule, not a judgement call. Confirm a caller’s identity through a channel you already hold on record, such as a call back to a known number, before resetting a password or changing MFA. CISA has documented attackers posing as employees to get help desks to move MFA to a device they control.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Give Every New Technician Access They Have Earned

Free trial — no credit card required.