Account provisioning
Microsoft 365, email, groups, and shared resources set up from a role template.
IT Onboarding and Offboarding in Omaha
ECS runs IT onboarding and offboarding for Omaha businesses as a documented process, so new hires start with working accounts and departures do not leave access behind.
Spend Time on What Matters.
Best of B2B (IT Services), from B2B Omaha Magazine, and Best of Omaha (Computer Repair), from Omaha Magazine, are community-voted awards won 5 consecutive years, 2022–2026. See our awards and story
Why It Matters
A new hire sitting at a desk without a laptop, a mailbox, or access to the system they were hired to use is an expensive first impression, and it happens because IT found out on the morning of the start date.
Offboarding is the riskier half. Accounts that outlive employment are among the most common audit findings and a favourite route back in. The usual cause is simple: no list of what the person had access to, so revocation covers the obvious systems and misses the rest.
What Is Covered
Microsoft 365, email, groups, and shared resources set up from a role template.
Hardware ordered, enrolled, encrypted, and configured before the start date.
Vault access granted for the systems the role needs, without emailing passwords.
Accounts disabled, sessions and tokens revoked, MFA methods removed, on the agreed day.
Mailbox and files preserved or transferred to a manager, rather than deleted in haste.
A record of what was granted and what was removed, which is what auditors ask for.
What Runs It
Microsoft Entra ID
Provisioning, group membership, session revocation, and MFA method removal.
Microsoft Intune
Devices configured for a new hire, and retired or wiped on departure.
Keeper
Shared credentials granted and revoked centrally rather than person to person.
ECS service desk
Each onboarding and offboarding runs as a tracked request with a documented checklist.
If that takes more than a minute, it is worth fixing before the next departure.
Start the ConversationHow It Works
Agree what each role needs once, so provisioning stops being improvised per person.
You submit a start or departure with the date. Lead time is what makes day one work.
Accounts, devices, and credentials handled against the checklist for that role.
You get written confirmation of what was granted or revoked, which is the part auditors want.
What You Get
People start working instead of waiting on access.
The most common audit finding stops being a finding.
A record per person, rather than a search through memory and email.
A week is comfortable when hardware is needed, since devices have to be ordered, enrolled, and configured. Accounts alone can be done much faster. Tell us as early as you can and we will tell you what is achievable.
It is preserved rather than deleted. Typical handling is to convert the mailbox to a shared one or delegate it to a manager so client correspondence is not lost, while sign-in is blocked immediately.
Yes. For urgent departures the sequence is access first: disable sign-in, revoke active sessions and tokens, remove MFA methods, then deal with data and devices. Tell us the moment the decision is made.
Yes. ECS is an authorized reseller for Dell and Lenovo, so procurement, configuration, and enrolment are one process rather than you buying a laptop and sending it to us.
Because it was granted through the same process. That is the real argument for role templates and a credential vault: revocation is only as complete as your record of what was granted.
Get Started
We will build role templates with you, then run onboarding and offboarding against them.
Spend Time on What Matters.