Before the start date
- Confirmed name and sign-in identity
- Manager, role, and start time
- Required licence and Microsoft 365 services
- Approved mailboxes, Teams, sites, and groups
- Device owner and readiness
“Someone starts Monday—what do we send?”
A desk can support routine Microsoft 365 setup and approved access changes. The business still decides who should have access, who owns work, and when account actions take effect.
Responsibility map
A checklist organizes the request. It does not authorize access, decide retention, or prove that a sensitive change is appropriate.
| Decision or task | Business owner | Support desk | Separate specialist |
|---|---|---|---|
| Approve access | Names the role, resource owner, and duration. | Applies an approved routine change. | Reviews complex or privileged design. |
| Set up user services | Confirms date, role, device, and needs. | Supports account, licence, mail, Teams, and files. | Handles migration or custom automation. |
| Protect departing work | Decides ownership and retention need. | Supports approved access and handoff steps. | Advises on legal, compliance, or investigation needs. |
| Recover equipment | Owns the physical process. | Clarifies Microsoft 365 sign-out and access. | Handles device fleet or hardware logistics if scoped. |
Important boundary
Role changes should name intended resources and owners. The desk should not infer sensitive access from a title or reuse another person’s permissions without review.