everyday mac tools

A Mac handover checklist for a new employee

· 5 min read

Most Mac handovers in small companies happen the morning someone starts, from whoever is free. It works, and the gaps show up over the following fortnight as small support requests that all trace back to the same twenty minutes.

This is the sequence that removes most of them.

Before the machine is handed over

Erase it properly if it is second-hand. Not a reset of the previous user’s account, an actual erase. Anything else leaves their files and their Apple Account attached. Erasing a Mac properly covers the order, and the previous holder must sign out of iCloud before you erase or the machine stays Activation Locked.

Update macOS to the version you standardise on. Doing it before handover saves an hour of their first day and means they start where everyone else is.

Name it to your scheme. Asset tag, or a naming convention you can look up. When they call with a problem, the first useful question is which machine. Naming a Mac covers what works.

Enrol it in management if you use it, before they set it up, so the profile is there from the start rather than being applied over a configured machine.

Record the serial number against their name, somewhere that is not the machine.

At handover

Sit with them for twenty minutes. This is the part that gets skipped and the part that pays.

Let them create their own account. Do not hand over a machine logged in as admin with a shared password. Their account, their password.

Decide administrator or standard, and tell them which. If they are standard, tell them how to request software rather than letting them discover it when blocked. Standard, admin and guest accounts covers the distinction.

Set the Apple Account expectation explicitly. Either a work account you provide, or none. Tell them not to sign in with their personal one, and say why: the machine can be recalled or wiped, and their photos and messages should not be on it. What to do on day one with a work-issued Mac covers it from their side.

Turn on FileVault and record the recovery key in whatever you use for that. A laptop without FileVault is a data breach waiting for a train.

Connect the Wi-Fi, the printer, and the shared drives. Print a test page. Printing is the single most common support call and it takes two minutes to remove.

Tell them the things that are not on the machine

Who to contact, how, and for what. With a name, not a generic address, if you are small enough.

What is backed up and what is not. If laptops are not backed up centrally, say so plainly and tell them where work is expected to live. The assumption that IT has a copy of everything is nearly universal and frequently wrong.

The software request process. Even if it is “ask me”.

What happens when they leave. Awkward on day one, and much less awkward than on the last day. The machine goes back and gets wiped; keep personal things off it.

Set up the security basics

Quick, and worth doing with them rather than for them so they know it is there.

  • FileVault on, key recorded
  • Firewall on
  • Automatic updates on
  • Find My on, if your policy allows it
  • Screen lock requiring password immediately, with a short idle delay
  • Sharing services off

For anyone travelling, add the travel setup. Setting up a Mac you will travel with covers it.

Write the checklist down

The real recommendation. Whatever your version of the above is, write it as a list and use it every time.

Handovers done from memory are inconsistent, and inconsistency is what produces the machine three years later that nobody can account for: enrolled differently, named nothing, FileVault off, still signed in to a former employee’s Apple Account.

A one-page checklist in a shared document is enough. It does not need to be a system.

When it comes back

The reverse, and it is worth having written down too.

  1. Confirm their work is in company systems, not only in their home folder.
  2. They sign out of every personal account, including the App Store.
  3. Sign out of iCloud, before erasing.
  4. Deauthorise licensed applications.
  5. Erase All Content and Settings.
  6. Record it as available in your asset list.

Step three is the one that strands machines. Unpairing everything before a Mac leaves you covers the full list.

Questions

Should we use one shared administrator account on every Mac? A local administrator account for support is reasonable, with a password managed properly. What is not reasonable is people working day to day in a shared account, because nothing is attributable.

Do we need mobile device management for a handful of Macs? Below about ten machines, a written checklist and consistency usually beats the overhead. Above that, enrolment starts paying for itself.

What if they want to use their own Mac? That is a policy question with real consequences for data and for support. Decide it deliberately rather than case by case.

Who keeps the FileVault recovery key? Whoever administers the machines, in whatever you use for secrets. Not in a spreadsheet on the same laptop.