Day of IT Onboarding Checklist
Day-of Onboarding Checklist
Client: ____________________ Date: ____________ Start Time: ____________
On-Site Tech: ____________________ Remote Tech: ____________________
Phase 1 — Arrival & Quick Network Audit (0:00 – 0:30)
✓ | Role | Task |
☐ | On-Site | Check in with client POC — introduce yourself, set 2–4 hr expectations |
☐ | On-Site | Walk through office — count all workstations, servers, and network devices |
☐ | On-Site | Identify current router/firewall (make & model) — reference Network Assessment |
☐ | On-Site | Locate all network switches and patch panel locations |
☐ | On-Site | Log any obvious issues (damaged cables, devices off, no network) — DO NOT FIX |
Phase 2 — NinjaRMM Agent Deployment (0:30 – 1:30)
✓ | Role | Task |
☐ | Remote | Create client org in NinjaRMM and pull agent installer URL |
☐ | On-Site | Run installer on each workstation (manual or GPO/script if domain accessible) |
☐ | Remote | Confirm each device checks in to NinjaRMM in real time |
☐ | On-Site | Power on any accessible workstations that are off — install Ninja on them |
☐ | Both | Log inaccessible/missing devices on punch list — do not hold up onboarding |
☐ | Remote | Confirm 100% of accessible devices enrolled and reporting before proceeding |
Phase 3 — Security Stack Deployment (1:30 – 2:00)
✓ | Role | Task |
☐ | Remote | Push DTC security stack bundle via NinjaRMM to all enrolled endpoints |
☐ | Remote | Monitor deployment status — confirm each device completes install |
☐ | Remote | Log any deployment failures on punch list — do not hold up onboarding |
☐ | On-Site | Continue UDM Pro setup during this phase (see Phase 4) |
Phase 4 — Unifi UDM Pro Firewall Setup (1:30 – 2:30)
✓ | Role | Task |
☐ | On-Site | Physically install UDM Pro in network rack or appropriate location |
☐ | On-Site | Connect WAN port to ISP modem/ONT |
☐ | On-Site | Connect LAN/switch ports to existing network infrastructure |
☐ | On-Site | Configure WAN settings (DHCP or static IP per ISP requirements) |
☐ | On-Site | Set LAN subnet and DHCP scope per DTC network standards |
☐ | On-Site | Enable IDS/IPS — standard DTC policy |
☐ | On-Site | Apply VLANs if required (guest Wi-Fi, VoIP, etc.) per pre-onboarding notes |
☐ | On-Site | Confirm internet is live from multiple workstations |
☐ | Remote | Verify devices continue to report in NinjaRMM after network change |
Phase 5 — Verification, Punch List & Sign-Off (2:30 – 3:00)
✓ | Role | Task |
☐ | Remote | Confirm all NinjaRMM agents reporting with policies applied |
☐ | Remote | Confirm security stack active on all enrolled devices |
☐ | On-Site | Confirm internet working from client workstations post-UDM cutover |
☐ | On-Site | Walk through completion criteria (Section 6 of SOP) with client POC |
☐ | On-Site | Collect punch list from staff — ask about devices, printers, software issues |
☐ | On-Site | Provide client POC with DTC support contact information |
☐ | On-Site | Add punch list notes to onboarding ticket for PM |
☐ | Remote | Create support ticket from punch list for post-onboarding follow-up |
☐ | Both | Document all work in HALO |
☐ | Both | Notify Account Manager (AM) that onboarding is complete |
⚠ Key Reminders
· DO NOT troubleshoot anything found during walkthrough — log it and keep moving.
· DO NOT let scope creep blow the 2–4 hour window. Punch list everything outside the 3 deliverables.
· If approaching 4 hours, notify PM immediately of delays and issues.
· Out of scope: printers, dental/practice software, domain joins, email/M365, VoIP, legacy issues.
On-Site Tech Signature: ________________________ Date/Time: ____________
Remote Tech Confirmation: ________________________ Date/Time: ____________