Password sharing for remote employee onboarding
When a new employee walks into a physical office on their first day, IT can hand them a printout, walk them to their desk, or log in alongside them. Remote onboarding removes this option. The credentials needed to start work have to travel from IT to the new employee via digital channels — and how they travel matters.
For organizations with remote or hybrid teams, credential delivery during onboarding is one of the highest-risk credential-sharing moments. It typically involves multiple credentials (email, VPN, internal tools, project management software, communication platforms) delivered to someone whose digital hygiene is unknown and whose devices have not yet been brought into the organization's security perimeter.
Why remote onboarding creates credential risk
Multiple credentials, single delivery event: Onboarding typically involves 5-15 credential sets. If they are all delivered in a single email, that email becomes an extremely high-value target.
Unknown device security: The new employee may be accessing their onboarding information from a personal device before their work device is configured. Personal devices are outside the organization's security controls.
New employee unfamiliarity: New employees are the most likely to make mistakes — clicking phishing links, using weak personal passwords for work accounts, or saving credentials insecurely because they do not yet know the organization's practices.
Permanent email archives: Onboarding emails are rarely deleted. A welcome email with credentials sent in 2019 may still exist in both the employee's and the IT team's email archives — even if those credentials have been rotated multiple times since.
What a secure remote onboarding credential workflow looks like
Before day one
-
Prepare accounts in advance, but do not set final passwords yet. Create accounts with temporary access credentials that are only valid during the onboarding window.
-
Identify which credentials need to be delivered to the new employee directly (vs. which can be managed through SSO, where the employee sets their own password).
-
Create one-time delivery links for each credential set. Do not bundle all credentials into one link — separate them so that if one link is compromised, the others remain safe.
Day one delivery
-
Deliver each link with a short explanation. For example: "Here is your VPN login — this link works once and expires in 24 hours. After clicking it, save the credentials in your password manager immediately."
-
Set expiry times that match the onboarding timeline. If you know the employee will be setting up their device in the afternoon, a 12-hour link is appropriate. If there is uncertainty, 72 hours gives buffer without excessive risk.
-
Confirm receipt. After the employee has retrieved their credentials, they should confirm this in your communication channel. If a link expires without retrieval, send a new one — do not send the credentials in plain text.
After day one
-
Require password changes for all temporary credentials during the first session. The temporary credential delivered via one-time link should be treated as a delivery mechanism, not a permanent credential.
-
Set up the employee's password manager as part of day-one IT configuration. This ensures they have a secure place to store credentials going forward.
-
Audit access grants at 30 days. Confirm that temporary credentials have been rotated and that access permissions match the employee's actual role.
Handling onboarding for contractors and freelancers
Contractors and freelancers present the same challenges as permanent employees, with an added complication: their relationship with the organization is temporary, and their devices and security practices are entirely outside your control.
For contractors:
- Deliver credentials via one-time links with shorter expiry times (24 hours maximum)
- Grant only the minimum access required for the specific project
- Set a calendar reminder to rotate credentials when the engagement ends
- Do not include contractor credentials in permanent password manager stores — track them separately with an expected rotation date
The first-day message
A simple template for credential delivery:
"Welcome! Your access credentials are below. Each is delivered via a secure one-time link — click to retrieve. Links expire in 24 hours. After retrieving, save each in your password manager.
- Company email: [link]
- VPN: [link]
- Project management: [link]
If a link has expired before you could use it, let me know and I will send a new one."
This sets expectations, explains the mechanism, and handles the most common failure mode (link expiry) proactively. It also signals to the new employee that the organization takes credential security seriously — which is a good cultural signal on day one.