Prepared workplace with a laptop and an access card, overlaid by a glowing technical network that converges into a key and a laptop shape, fully AI generated and marked with the EU label
All solutions31 / IT onboarding

IT onboarding

Provision equipment and access for new employees

As soon as a new hire's role and start date are known, the required devices, software accounts and access rights are derived automatically and provisioned in time for the first day. IT only has to decide on non-standard equipment, instead of setting up every access manually.

Process architecture

From role to a fully provisioned workplace.

The process takes the personnel data of a newly hired person, derives the required standard equipment from role and department, and sets up devices, accounts and access rights in time for the start date. Deviations from the standard equipment go to IT for review; the standard case runs through without manually creating every single access.

Process diagram

  • 09Nodes
  • 09Connections
  • 03Phases
Environment

01Input

Open quotes and their context come together.

The process starts with silence rather than a message: a quote that has had no answer for days. The leading system supplies the quote, its deadline and the contact, together with the correspondence already attached to the case.

2 Steps

02Process

The right message is derived from the state of the case.

The draft comes from the quote itself, not from a template full of placeholders. The rules then check whether a follow-up is allowed at all; anything outside the agreed frame goes to a salesperson.

4 Steps

03Output

The message goes out and the case stays traceable.

The follow-up sits in the same conversation as the quote, sales sees the current state without asking, and every attempt is documented on the case.

3 Steps

Source01

Take over new personnel data

Role, department, location and start date of a newly hired person are taken from the HR system as soon as the contract is signed – via Microsoft Entra ID, Google Workspace Admin or a custom identity management system, depending on the environment.Details

Process node 01Source

Take over new personnel data

Role, department, location and start date of a newly hired person are taken from the HR system as soon as the contract is signed – via Microsoft Entra ID, Google Workspace Admin or a custom identity management system, depending on the environment.

Interfaces
  • Microsoft Graph API
  • SharePoint API
Next steps
Data02

Derive standard equipment

Role and department are matched against a stored template to derive which devices, software accounts and access rights the person needs by default.Details

Process node 02Data

Derive standard equipment

Role and department are matched against a stored template to derive which devices, software accounts and access rights the person needs by default.

Interfaces
  • Azure AI Document Intelligence
  • Mistral OCR
  • Dataverse API
Next steps
Action03

Create accounts and access

The user account, mailbox and the software accounts defined in the template are created automatically, with the matching permission groups.Details

Process node 03Action

Create accounts and access

The user account, mailbox and the software accounts defined in the template are created automatically, with the matching permission groups.

Interfaces
  • Power Automate
  • Azure Functions
  • Microsoft Graph API
Next steps
Decision04

Check for deviations

If the requested equipment deviates from the standard template, for example through an additional system or extended rights, the case counts as needing clarification.Details

Process node 04Decision

Check for deviations

If the requested equipment deviates from the standard template, for example through an additional system or extended rights, the case counts as needing clarification.

Interfaces
  • Azure OpenAI GPT
  • Anthropic Claude
  • AI Builder
Next steps
Approval05

Approve non-standard equipment

For a deviation, IT reviews the request and approves the additional equipment or declines it with a reason.Details

Process node 05Approval

Approve non-standard equipment

For a deviation, IT reviews the request and approves the additional equipment or declines it with a reason.

Interfaces
  • Teams Adaptive Cards
  • Power Apps
Next steps
System06

Trigger device provisioning

The devices intended for the new person are reserved from stock or a procurement request is triggered, in time for the start date.Details

Process node 06System

Trigger device provisioning

The devices intended for the new person are reserved from stock or a procurement request is triggered, in time for the start date.

Interfaces
  • Dynamics 365 API
  • Azure Service Bus
Next steps
Result07

Activate access

All accounts and access rights are activated automatically on the start date, not earlier and not later.Details

Process node 07Result

Activate access

All accounts and access rights are activated automatically on the start date, not earlier and not later.

Interfaces
  • Power BI API
  • Teams Webhook
Next steps
Result08

Inform the responsible people

Managers and IT receive confirmation that equipment and access are ready for the start date, along with an overview of the device handover.Details

Process node 08Result

Inform the responsible people

Managers and IT receive confirmation that equipment and access are ready for the start date, along with an overview of the device handover.

Interfaces
  • Power BI API
  • Teams Webhook
Result09

Log the equipment

Every account created, every device assigned and every approval is documented with a timestamp, as a basis for later return or adjustment.Details

Process node 09Result

Log the equipment

Every account created, every device assigned and every approval is documented with a timestamp, as a basis for later return or adjustment.

Interfaces
  • Power BI API
  • Teams Webhook
  • Standard path
  • Direct path
  • Review required
  • Return

Steps in execution order

System landscape

The same process in three environments.

  • Microsoft

    Microsoft Graph API

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    SharePoint API

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Azure AI Document Intelligence

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Mistral OCR

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Dataverse API

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Power Automate

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Azure Functions

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Azure OpenAI GPT

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Anthropic Claude

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    AI Builder

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Teams Adaptive Cards

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Power Apps

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Dynamics 365 API

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Azure Service Bus

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Power BI API

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Microsoft

    Teams Webhook

    Möglicher Baustein für die Microsoft-Systemvariante.

  • Interfaces in use

    Google Workspace Admin SDK

    Google environment: creates user accounts in the Google Workspace Admin console and assigns groups.

  • Interfaces in use

    REST API

    Individual environment: connects the custom identity management system with the HR system and device management.

  • Interfaces in use

    SCIM-Protokoll

    Creates accounts in connected business applications automatically to the same standard, independent of the chosen environment.

  • Interfaces in use

    Microsoft Intune

    Microsoft environment: configures and manages the assigned devices centrally.

  • Interfaces in use

    Google Endpoint Management

    Google environment: configures and manages the assigned devices centrally.

  • Possible apps & platforms

    Microsoft Entra ID und Microsoft Intune

    Account creation, rights management and device management in the Microsoft environment.

  • Possible apps & platforms

    Google Workspace Admin-Konsole

    Account creation and rights management in the Google environment.

  • Possible apps & platforms

    Identitätsmanagementsystem

    Leading system for accounts and rights in the individual environment.

  • Possible apps & platforms

    Gerätemanagement-Software

    Management and assignment of devices in the individual environment.

Implementation in context

What the process does and what it deliberately leaves to people.

The process creates accounts and access according to a fixed template; it does not decide on new access rights outside that template. Every deviation – an additional system, extended permissions – goes to IT for a deliberate approval.

The environment determines the tools, not the process. In a Microsoft 365 environment account creation and device management run through Microsoft Entra ID and Intune, in a Google Workspace environment through the Google Workspace Admin console, in a self-hosted environment through a custom identity management system. Which variant fits depends on where the company already runs its user management.

Access is deliberately activated only on the start date, not earlier. That way there is no window in which an account is already usable while the person has not officially joined the company yet.

Every account creation, device handout and approval is logged. That eases not just traceability but also the later return or adjustment of equipment, for example on a role change.

Starting point

Equipping new employees runs in many companies through a chain of emails to IT, facilities and the department, often triggered only a few days before the start date. If the laptop or access to an important system is missing on the first day, that costs not just time but also the new hire's first impression of the company.

Target picture

As soon as role and start date are known, accounts, access rights and devices are derived automatically from a stored template and provisioned in time. IT only deals with genuine deviations from the standard equipment, not with every single account.

Expected benefits

  • Accounts and access are ready automatically on the start date, instead of after days of email coordination.
  • IT only deals with genuine deviations from the standard equipment.
  • Access is not activated before the official start date, avoiding an unnecessary security risk.
  • Managers automatically see that equipment and access are ready for the first day.
  • Every account creation and device handout stays traceably documented, including for later return.
  • The process adapts to the existing environment instead of making an additional identity management tool a precondition.

Prerequisites to start

  • 01An HR system from which role, department and start date of a new person can be taken automatically.
  • 02A stored template defining which devices, accounts and access rights belong to the standard equipment per role or department.
  • 03An identity or user management system in which the process is allowed to create accounts.
  • 04A device stock or procurement process to which the process can hand off a reservation or order.
  • 05A decision on the environment: Microsoft 365, Google Workspace or self-hosted – and the matching access rights.

Your next step

Which process costs your team unnecessary time every day?

Give us a short outline. We will tell you honestly where automation is useful—and where it is not.

DiscoverBack to top