For any Microsoft 365 administrator, user onboarding is one of the most recurring and critical tasks. A smooth onboarding process ensures that new employees are productive from day one, while a clunky, error-prone process can lead to frustration, security risks, and a significant drain on IT resources.
This guide walks through each technical onboarding step, and highlights best practices that reduce errors, rework, and support tickets. Whether you’re onboarding one user or dozens, following this checklist will help you create a consistent, secure, and efficient process using Microsoft 365’s standard tools.
Step 1: Access the Microsoft 365 Admin Center
The Microsoft 365 admin center is the central hub for managing your M365 tenant. To begin, you’ll need to log in with an account that has the appropriate administrative privileges (such as a Global Administrator or User Administrator).
- Navigate to https://admin.microsoft.com.
- Log in with your administrator credentials.
- From the left-hand navigation menu, go to Users > Active users.
Step 2: Create a New User
This is where you’ll create the user’s account and define their basic identity in your organization.
- Click on Add a user.
- Fill in the user’s First name, Last name, and Display name.
- Create a Username that follows your organization’s naming convention (e.g., firstname.lastname).
- Choose the appropriate domain for the user’s account.
- Configure the Password settings. It’s best practice to automatically create a password and require the user to change their password upon their first sign-in.
Best Practice: Username and Naming Conventions
Establish and enforce a consistent naming convention for usernames across your organization. Common approaches include firstname.lastname (john.smith@company.com), firstletter.lastname (j.smith@company.com), or firstletterlastname (jsmith@company.com). Document this standard and ensure all administrators follow it.
Consistency makes it easier for users to remember colleagues’ email addresses and reduces confusion. Whatever convention you choose, apply it consistently and review it periodically to ensure it still meets your organizational and compliance requirements.
Step 3: Assign Licenses and Set Usage Location
A license determines which Microsoft 365 services the user can access. This is a critical step that has both productivity and cost implications. Additionally, the usage location is required for proper license assignment and compliance.
- In the Assign product licenses section, select the appropriate license for the user based on their role (e.g., Microsoft 365 E3, E5, or Business Premium).
- Set the Usage location for the user. This is a required field that determines which services and features are available in their region. For example, if the user is based in the United States, select “United States.” This setting is important for compliance and service availability.
- If you need more granular control, you can expand the Apps section to enable or disable specific applications within the license. For example, a user might not need access to Yammer or Sway, and disabling these apps can reduce clutter and potential security surface
Best Practice: Use Group-Based Licensing
For organizations with more than a few users, implement group-based licensing instead of assigning licenses individually. Group-based licensing allows you to assign licenses to Entra ID security groups, and all members of that group automatically receive the assigned licenses. This approach is more scalable, reduces manual work, and ensures consistency. For example, create groups like Sales-E3-Users or Engineering-E5-Users and assign licenses to these groups. When you add a new user to the appropriate group, they automatically receive the correct license.
Step 4: Configure User Roles and Profile Information
This step involves both administrative role assignment and configuring important profile information that will be visible throughout your organization.
Configure Administrative Roles (Optional)
If the new user requires administrative privileges, you can assign them a role. It’s a security best practice to follow the principle of least privilege, meaning you should only assign the permissions necessary for the user to perform their job.
- Expand the Roles section.
- Select the appropriate admin role from the list. For most users, no admin role is necessary.
Configure Profile Information
Profile information is critical for organizational visibility and collaboration. This information appears in the Global Address List (GAL), organizational charts, and team directories, making it essential for helping colleagues find and connect with the new user.
- Department: Enter the user’s department (e.g., “Sales,” “Engineering,” “Marketing”). This helps with organizational structure and can be used for filtering and reporting.
- Job title: Enter the user’s job title (e.g., “Senior Sales Representative,” “Software Engineer”). This provides context about the user’s role within the organization.
- Office: Specify the physical office location where the user is based (e.g., “New York,” “San Francisco,” “London”). This is particularly important for organizations with multiple office locations.
- Office phone and Fax number: Add the user’s office phone and fax number if applicable.
- Mobile phone: Add the user’s mobile phone number if applicable.
- Street address: Enter the office street address if your organization maintains this information.
- City, State/Province, and Zip or Postal code: Complete the address information for the user’s office location.
- Country or region: Ensure the country or region is set correctly, as this may affect service availability and compliance settings.
This profile information is not just for administrative purposes. It’s used by the Global Address List, which employees use to find colleagues, and it can be displayed in organizational charts and team directories. Accurate and complete profile information improves the user experience and facilitates better collaboration across your organization.
Best Practice: Standardize Profile Information and Department Naming
Create and document standards for how profile information should be entered. For department and office location fields, use consistent naming across all users. For example, if you have a sales team in New York and another in Los Angeles, use “Sales – New York” and “Sales – Los Angeles” rather than mixing formats like “NY Sales” or “Sales LA”. This consistency makes it easier to create reports, filter users, and manage group memberships based on department or locations.
Step 5: Configure User Roles and Profile Information (Continued in Entra ID)
While some profile information can be set in the Microsoft 365 admin center, you may also want to configure additional details in the Entra ID admin center for more comprehensive profile management. This step is crucial for maintaining accurate employee records and enabling advanced features like access reviews and organizational governance.
- Navigate to the Entra ID portal at https://entra.microsoft.com/
- In the left-hand navigation menu, select Entra ID -> Users.
- Find the newly created user and edit properties.
- Review and update the following additional profile fields:
Employment Information:
- Employee ID: Enter the user’s unique employee identifier from your HR system. This is essential for linking the M365 account to your HR records and enables better tracking and reporting.
- Employee Type: Specify whether the user is a “Member” (full-time employee), “Contractor,” “Vendor,” “Guest,” or another employment classification. This is critical for security policies, access reviews, and compliance purposes. In Entra ID, this is often managed through user properties and can be used to apply conditional access policies.
- Employee Hire Date: Record the date the employee was hired. This information is useful for onboarding workflows, access reviews, and organizational reporting.
Organizational Relationships:
- Manager: Assign the user’s direct manager. This is important for organizational structure, approval workflows, and reporting hierarchies.
- Direct Reports: If applicable, link any direct reports to this user.
- Sponsors: Identify the user’s sponsor or sponsors (typically a manager or senior leader responsible for the user’s access and performance). Sponsors are important for access reviews and governance processes, as they may be required to approve or certify the user’s access rights periodically.
Custom Attributes:
If your organization uses custom attributes or extensions in Entra ID, configure any relevant custom fields specific to your organization’s needs. These might include cost center, business unit, or other organizational identifiers.
Best Practice: Link Employee Records to HR Systems
Use the Employee ID field to create a link between the M365 account and your HR system. This enables better tracking, reporting, and automation. If your organization uses HR integration tools or identity governance solutions, accurate Employee ID data is essential for syncing employee information and managing lifecycle events (onboarding, transfers, offboarding). Additionally, always assign a manager to each user and set the appropriate Employee Type. This information is critical for access reviews, approval workflows, and compliance reporting. Ensure that manager relationships are kept up-to-date as organizational changes occur.
Step 6: Set up Mailbox and Email
Once the user is created and a license is assigned, their Exchange Online mailbox will be provisioned. You’ll want to ensure their email settings are configured correctly. This step involves configuring email addresses, aliases, and important mailbox features.
- Navigate to the Exchange admin center at https://admin.exchange.microsoft.com.
- Find the new user’s mailbox by searching for the user in the Recipients -> Mailboxes section.
- In the General tab verify that their primary email address is correct. This should follow your organization’s naming convention (e.g., firstname.lastname@company.com ).
- Add any necessary email aliases that follow your organization’s naming convention. Email aliases should be consistent with your existing naming standards to maintain clarity and professionalism.
- In the Delegation tab configure mailbox delegation settings if the user’s manager or an executive assistant needs access to their mailbox. This allows designated individuals to send emails on behalf of the user or manage their mailbox.
- Navigating to the Mailbox tab you may set up email forwarding if the user’s emails need to be forwarded to another mailbox or external address.
- Moving on to the Others tab you can configure auto-reply settings if needed. This is particularly useful for users who will be out of the office or during onboarding periods.
- Enable mailbox archive if your organization uses archiving for compliance or storage management. This allows older emails to be automatically moved to an archive mailbox.
- Configure litigation hold if required by your organization’s compliance or legal requirements. Litigation hold preserves all mailbox content for legal discovery purposes.
Best Practice: Email Address and Alias Standards
Establish and maintain clear naming conventions for both primary email addresses and aliases. Primary email addresses should follow the organization’s standard format (for example, firstname.lastname@company.com). Email aliases may be used to support alternate domains, subsidiaries, or short-form addresses (for example, firstname.lastname@subsidiary.com, ceo@company.com, or flastname@company.com). Aliases should be created only when there is a defined business purpose.
Step 7: Manage Group Membership
Adding users to the appropriate groups is essential for collaboration and resource access. Groups serve multiple critical functions in Microsoft 365, and this step consolidates all group management tasks in one place. You will manage Distribution Lists and mail-enabled security groups via the Exchange Admin Center, Microsoft 365 Groups via the Microsoft 365 admin center or Teams client, and Security Groups via Entra ID.
Types of Groups and Their Functions
Distribution Lists are used to send email to multiple recipients and are managed in the Exchange Admin Center.
Mail-Enabled Security Groups combine email distribution with security-based access control and are managed in the Exchange Admin Center.
Microsoft 365 Groups are the primary collaboration mechanism in Microsoft 365. When you add a user to a Microsoft 365 Group, they automatically gain access to multiple connected services, including Teams channels, SharePoint sites, shared mailboxes, Planner, and shared calendars.
Security Groups are used for access control and permissions management across your organization and are managed in Entra ID.
Adding Users to Distribution Lists and Mail-Enabled Security Groups
Both Distribution Lists and mail-enabled security groups are managed through the same interface in the Exchange Admin Center.
- In the Exchange admin center at https://admin.exchange.microsoft.com, navigate to Recipients > Groups.
- Select the relevant Distribution List or mail-enabled security group.
- Click on the Members section.
- Click Manage members.
- Click Add members and search for the new user.
- Click Add and then Save.
Adding Users to Microsoft 365 Groups
- Navigate to the Microsoft 365 admin center at https://admin.microsoft.com.
- Go to Teams & groups > Active teams & groups.
- Select the relevant Microsoft 365 Group.
- Click on the Members tab.
- Click Add members and search for the new user.
- Click Add to add the user to the group.
- Alternatively, manage Teams membership directly in the Teams client at https://teams.microsoft.com by selecting the team, clicking the team name at the top, selecting the Members tab, and clicking Add member.
Adding Users to Security Groups
- Navigate to the Azure portal at https://portal.azure.com.
- Select Microsoft Entra ID from the left-hand navigation.
- Go to Groups > All groups.
- Find the relevant security group.
- Click on the group to open its details.
- Click Members and then Add members.
- Search for and select the new user.
- Click Select to add the user to the security group.
Best Practice: Implement Group Naming Conventions
Create and enforce naming conventions for all group types. For example, use prefixes to indicate group type and purpose: “DL-” for Distribution Lists, “SG-” for Security Groups, “M365G-” for Microsoft 365 Groups. Include the department or function in the name (e.g., “SG-Sales-US” or “M365G-Engineering-Team”).
Step 8: Final Review and Credential Handover
Before completing the onboarding process, conduct a final review of all the settings you have configured. Verify that the user account is active and the username is correct, the appropriate license has been assigned, profile information is accurately populated, mailbox configuration is correct with proper email addresses and aliases, the user has been added to all necessary groups. Once you are confident that all configurations are in place, provide the user’s credentials (username and temporary password) to the employee’s manager or the HR person in charge. They will be responsible for communicating this information to the new employee and providing any additional onboarding support.
Streamline User Onboarding with EasyEntra Virtual User Templates
Following the manual checklist above works, but as you can see, it requires navigating multiple admin centers, performing dozens of steps, and is highly error-prone. For organizations onboarding multiple users regularly, this process becomes a significant drain on IT resources.
EasyEntra Virtual User Templates solve this problem by allowing you to standardize and automate the entire onboarding process. Instead of manually configuring each user, you create reusable templates that capture all the settings for a specific role or department, and then deploy new users in just 30 seconds.
What Can You Configure in Virtual User Templates?
EasyEntra Virtual User Templates capture and automate all the critical settings you have learned about in this guide. Instead of manually configuring each user across multiple admin centers, a single template handles everything. Here’s what you can configure:
| Account Settings | First name, last name, and display name (automatically formatted based on your naming convention) Username (UserPrincipalName) automatically generated from template naming convention User type User profile picture Business phone number Preferred language |
| Organizational Information | Job title, department, and company Office location and address (street, city, state, postal code, country) Employee type (Member, Contractor, Vendor, etc.) Employee hire date Manager |
| Group Memberships | Entra ID groups (Microsoft 365 Groups, Security Groups, Distribution Lists, Mail-Enabled Security Groups) Active Directory groups (Security, Distribution, Domain Local, Global, Universal) Dynamic group membership based on rules |
| M365 Licenses & Applications | Microsoft 365 licenses (E3, E5, Business Premium, etc.) Individual app assignments within licenses Group-based license assignments |
| Email & Mailbox Settings | Primary email address and aliases (automatically formatted from template naming convention) Mailbox type (User, Shared, Room, or Equipment mailbox) Email forwarding and auto-reply messages Delivery restrictions Mailbox delegation (Send As, Send On Behalf, Full Access) Mailbox archive and litigation hold for compliance Calendar delegation and sharing permissions Regional settings and Outlook folder localization |
Essentially, every setting (and much more) you manually configured in the 8-step process above can be captured in a template and automatically applied to new users.
How Easy Is It to Create a Template?
Creating an EasyEntra Virtual User Template is remarkably simple:
- Right-click an existing user that matches your template requirements and select “Create Template”
- Configure a name for the template that reflects the role and/or geography (e.g., “Sales – US”, “Engineering – Europe”, “Support – APAC”)
- Review and modify the properties of the template user to ensure all settings are correct
- Click Create to save the template
That’s it. The template is now ready to use, and you can deploy new users from it in seconds.
How to Create an EasyEntra Virtual User Template
Deploy New Users in 30 Seconds
Once your templates are created, provisioning a new user is incredibly fast:
- Open EasyEntra and right click your template, select “Create User”
- Enter the user’s display name. All other settings will be automatically generated based on the selected template
- Review the user configuration, make any modifications if needed, and then click “Create”
- In approximately 30 seconds, the new user is fully provisioned with all the settings from your template
Compare this to the 30-45 minutes it takes to manually configure a user through the Microsoft 365 admin center and multiple other portals.
How to Create a User from an EasyEntra Virtual User Template
Best Practice: Create Templates for Each Role in Your Organization
To maximize the efficiency of Virtual User Templates, create a template for each distinct role or department in your organization. For example: Sales Representative – US, Sales Representative – EMEA, Software Engineer, Product Manager, Finance Analyst, HR Specialist etc.
Each template should capture the specific licenses, group memberships, mailbox settings, and profile information relevant to that role. This approach ensures consistency, reduces errors, and makes onboarding predictable and scalable.
Share Templates Across Your Admin Team
One of the most powerful features of EasyEntra Virtual User Templates is the ability to share them across your admin team. Once templates are created, all administrators in your organization can use them. This means:
- Consistency: All admins use the same standardized templates, ensuring every user is configured identically
- Reduced Training: New admins do not need extensive training on the onboarding process; they simply select the appropriate template
- Delegation: You can empower HR or department managers to provision users without requiring deep technical knowledge
- Audit Trail: All user provisioning is tracked and auditable, providing visibility into who created which users and when
Real-World Impact
Consider a mid-sized organization with 100 employees onboarding annually:
- Manual Process: 100 users x 40 minutes per user = 4,000 hours annually
- EasyEntra Templates: 100 users x 0.5 minutes per user = 50 hours annually
- Time Saved: 3,950 hours per year, equivalent to nearly 2 full-time IT staff members
Beyond time savings, using templates eliminates the most common onboarding errors: forgotten group memberships, incorrect license assignments, missing mailbox configurations, and incomplete profile information.
Get Started with EasyEntra Virtual User Templates
Ready to transform your user onboarding process? Watch the webinar on EasyEntra Virtual User Templates to see a live demonstration of how to create and use templates in your organization:
Nine-minute webinar on working with EasyEntra Virtual Templates
Try EasyEntra for free
Experience the power of EasyEntra Virtual User Templates with our 30-day free trial.
No credit card required.
Full access to all features.