New laptop at the office: what to set up before you start using it?
A brand-new laptop straight out of the box feels great — but switching it on and logging in right away isn't always the smartest move. Here are the steps you should take first.
There's something satisfying about unboxing a new laptop. Peel off the plastic, lift the lid, plug it in. But that's exactly the moment where many offices cut corners that cause headaches later: an account that belongs to no one, no disk encryption, no backup configured, and three years down the line nobody can remember which Microsoft account it's tied to.
Below is a practical checklist. Nothing overly technical — just what you work through on a quiet morning before the laptop lands on someone's desk.
1. First, decide: who does this device belong to?
It sounds obvious, but this is step one. A laptop should belong to the company, not to whoever happens to be using it. That means:
- The laptop is on the company invoice (keep it — you'll need it for warranty claims and depreciation).
- No personal Microsoft or Apple ID is set up as the primary account. Only a business account.
- You record the serial number and the assigned user in a simple list. A spreadsheet works fine.
Why does this matter? If someone leaves, you can't properly reclaim the laptop otherwise. And if it gets stolen, you need to know what was on it.
2. Skip the "use your personal account" screens
Both Windows and macOS will helpfully nudge you towards a personal account during setup. On Windows 11 that screen is called "add your Microsoft account"; on macOS it's your Apple ID.
For an office laptop, what you actually want is:
- Windows: choose "set up for work or school" and sign in with the employee's Microsoft 365 account.
- Mac: create a local administrator account in the company's name, then add a user account for the employee afterwards.
That way the laptop is tied to the business, not to a personal email address you can no longer reach later.
3. Enable disk encryption (this is the most important one)
If there's one thing you absolutely must do, it's this. Without disk encryption, anyone who gets hold of the laptop can pull out the hard drive and read everything on it — your client database, your quotes, your email archive.
- Windows Pro: enable BitLocker. Store the recovery key somewhere safe — not on the laptop itself.
- Mac: enable FileVault via System Settings → Privacy & Security.
It takes five minutes and one restart. After that, a stolen laptop is "just" a lost device — not a data breach.
4. Sort out the two essential basics: updates and backup
Before letting anyone use the laptop:
- Run all updates. Yes, including BIOS/firmware updates if the manufacturer offers them. A brand-new laptop out of the box is often months behind.
- Enable OneDrive or iCloud Drive for the documents folder, so work isn't stored locally only.
- Check that 2FA is enabled on the Microsoft 365 or Google account. Without 2FA, signing in on a new laptop is just "enter your password" — and that's all someone else needs too.
Not sure whether your access management is up to scratch? Our access check walks through who actually has access to what — in about an hour. No nasty surprises later.
5. Clean up before you hand it over
Manufacturers love pre-loading new laptops with trial software: McAfee trial subscriptions, various "helper" tools, and sometimes browser extensions you never asked for. Remove all of that before the laptop goes to the employee. It saves pop-ups later and reduces your attack surface.
While you're at it, check the browser extensions. Chrome and Edge come empty by default — keep them that way. Only install what's genuinely needed for work.
6. Write two things down
Before you hand over the laptop, note down:
- The serial number (on the underside of the device or retrievable via Settings).
- The BitLocker or FileVault recovery key, stored somewhere other than on the laptop itself. A password manager works well; a locked drawer does too.
These two things are invaluable when something goes wrong — a crash, a theft, an employee who accidentally locks themselves out. Without the recovery key, you can't open the drive, even as the owner.
7. Think ahead about "what happens when it comes back"
A laptop typically lives in a business for three to five years. At some point it will leave — traded in, passed on, or disposed of. If you record which account it's linked to now, that future moment is simply a matter of signing out, wiping, and restarting. Skip that step today and it becomes a puzzle later.
In short
A new laptop isn't a consumer gadget you just "switch on". It's a tool that will have access to your clients, your email and your administration for years to come. Twenty minutes at the start saves hours at the back end.
Want to make sure your existing laptops and accounts are in order too? Take a look at our access check or use our IP lookup to see which locations your email is being accessed from. It often produces the first "hang on, that doesn't look right" moment.
Volledige gids: Security for SMBs without an IT department: what should you do this quarter?
Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.
Lees de pillar →