What data must an IT Onboarding Form in SharePoint capture so that tasks, permissions, and proofs are automatically generated without HR, IT, and the business team needing to coordinate manually? An IT onboarding process rarely fails due to a lack of willingness, but rather due to a lack of data flow. When HR enters master data into one system and IT only learns of it days later, delays occur in account creation, device assignment, and access provisioning.
An SharePoint Onboarding Form combined with Power Automate solves this problem by automatically generating tasks for all involved teams, triggering notifications, and storing proofs from a single data entry. This guide describes how this setup is implemented technically in a clean manner.
Which form should capture which master data
The onboarding form is the starting point of the entire process. All subsequent steps depend on the quality of the data captured within it. A form with too many mandatory fields will be filled out incorrectly. A form with too few fields forces IT to ask follow-up questions.
Master data the form should capture
Field Name: First Name
Type: Text
Why Necessary: For account creation, welcome messages, and name spellings
Field Name: Last Name
Type: Text
Why Necessary: For account creation and email addressing
Field Name: Start Date
Type: Date
Why Necessary: For time-based provisioning and device pre-assignment
Field Name: Department
Type: Selection
Why Necessary: Determines group membership, licenses, and storage structure
Field Name: Location
Type: Selection
Why Necessary: Relevant for device procurement, VPN, and local printers
Field Name: Role / Job Title
Type: Selection or Text
Why Necessary: For license selection and access groups
Field Name: Supervisor
Type: Person column
Why necessary: For approval workflows and reporting line
Field name: Direct contact (Buddy)
Type: Person column
Why necessary: Optional, for social onboarding process
Field name: Device type
Type: Choice
Why necessary: Laptop, Desktop, Tablet – for device procurement
Field name: Mobile Device
Type: Choice
Why necessary: Yes/No, for MDM enrollment
Field name: Required software
Type: Multiple choice
Why necessary: Standard list of approved applications
Field name: Special access requirements
Type: Multi-line text
Why necessary: Business team-specific requirements not covered by standard
Field name: Data privacy training required
Type: Yes/No
Why necessary: For task generation
Field name: IT security training required
Type: Yes/No
Why necessary: For task generation
What does not belong in the form
The form should not include technical fields such as username, email address, or group membership. These values are automatically derived from master data and set by the flow, not by the HR personnel filling out the form. Free-text fields for special requests should be kept to a minimum because they are difficult to process automatically.
Implementing the form in SharePoint
The form can be implemented at various levels:
- Microsoft Lists: A simple list form with a customized view. Cost-effective, no development effort required, but offers limited flexibility in user experience.
- Power Apps Form: A customized canvas app with SharePoint as the data source. Provides more design freedom, conditional required fields, and support for multi-step forms.
- Microsoft Forms + Power Automate: A form in Microsoft Forms with data transfer via flow to SharePoint. Easy to use, but does not natively support person columns.
For IT onboarding that requires person columns, multiple selections, and conditional required fields, a Power Apps form is the most robust choice.
Building the task list, responsibilities, and status model
Upon receipt of the form, Power Automate automatically generates tasks for all involved teams. The tasks are stored in a SharePoint task list for onboarding. The basic trigger and status patterns for this are described in Connecting SharePoint Tasks with Power Automate.
Structure of the onboarding task list
Column Name: Title
Type: Text
Purpose: Specific task description
Column Name: Category
Type: Choice
Purpose: IT, HR, Business Team, Facility
Column Name: Assigned To
Type: Person Column
Purpose: Responsible person or group
Column Name: Due Date
Type: Date
Purpose: When the task must be completed
Column Name: Status
Type: Choice
Purpose: Pending, In Progress, Completed, Blocked
Column Name: Priority
Type: Choice
Purpose: High, Normal, Low
Column Name: Evidence URL
Type: Hyperlink
Purpose: Link to the uploaded document or evidence
Column Name: Evidence Date
Type: Date
Purpose: When the evidence was provided
Column Name: Onboarding Reference
Type: Lookup Column
Purpose: Reference to the master data entry in the form
Column Name: Comment
Type: Multi-line Text
Purpose: Note or inquiry
Automatically generated tasks
Once the form is received, the flow creates a task for each involved unit. A typical task list looks like this:
IT Tasks (Category: IT)
- Create account in Entra ID
- Set up email address
- Initiate device procurement
- Set up and deliver device
- Configure VPN access
- Install software (as specified in the form input)
- Perform MDM enrollment (if Mobile Device = Yes)
- Set up special access (if special requirements apply)
HR Tasks (Category: HR)
- Send welcome package
- Schedule data protection training (if required)
- Schedule IT security training (if required)
- Request certificates and documents
Business Unit Tasks (Category: Business Unit)
- Plan onboarding
- Confirm Buddy assignment
- Define and approve domain-specific access
Facility Tasks (Category: Facility)
- Set up workstation
- Create access badge
Due date logic
For a smooth deployment, some tasks must be completed before the start date. The flow calculates due dates relative to the start date:
- Device procurement: Start date minus 10 business days
- Account setup: Start date minus 3 business days
- Welcome package: Start date minus 1 business day
- Training: Start date plus 5 business days
Calculating business days (excluding weekends and holidays) requires custom logic in Power Automate because no built-in function exists for this. A holiday helper list or an Azure function can handle the calculation.
Trigger automatic tasks, notifications, and access grants
Flow architecture for the onboarding process
The main flow is triggered by creating a new form entry. It includes the following main sections:
- Read and validate master data: Check required fields and prepare Entra ID user search.
- Create tasks: Create entries in the task list for each task category.
- Send notifications: Inform involved teams via email or Teams message.
- Create user in Entra ID (optional): If the IT department wants to delegate account creation, this step can be initiated via the Azure AD Connector or the Microsoft Graph API. In most tenants, this step is handled manually or via a separate ITSM system for security reasons.
- Assign groups and licenses: If department-based groups and license assignments are to be automated, the flow can read the appropriate groups from a configuration list and trigger the assignment via the Azure AD Connector.
Map rights assignment in a structured way
Rights assignment is the most security-critical part of the onboarding process. Overly broad rights often do not arise from malicious intent, but because the least-privilege principle is not applied consistently under time pressure.
A sensible model:
- Base groups are automatically assigned when accounts are created (e.g., "All Employees").
- Department groups are derived from the department column in the form and automatically assigned.
- Special access from the free-text field "Special Access Requirements" is transferred into a separate task that requires manual review by IT and the business team.
No flow should automatically assign administrator rights, full access to file repositories, or access to confidential projects without prior manual approval.
Design notifications
Good onboarding notifications contain clear information without information overload. For IT, a structured message with the new employee's name, start date, department, and a link to the task list is sufficient. For the business team, a welcome email with the buddy's name and the preliminary onboarding plan is more appropriate.
Teams Adaptive Cards offer a compact, easy-to-read display for both scenarios with direct action buttons, such as "Open Tasks" or "Confirm".
Document evidence, comments, and inquiries
What constitutes evidence
In IT onboarding, evidence is any form of documentation that a task has been completed properly. Typical evidence includes:
- Screenshot or PDF of successful account creation,
- Signature on a data protection or IT security briefing,
- Confirmation of device handover,
- Completed and signed setup log.
Store evidence in SharePoint
Proofs should not circulate as email attachments but be stored in a structured way in SharePoint. A document library named "Onboarding Proofs" with a folder for each new employee is a simple, maintainable model. In the task list, the "Proof URL" field points to the respective document.
The flow can automatically store the proof URL in the task after a document is uploaded, if the library has a column default value or an automatic path mapping. Power Automate can also actively respond to the upload and mark the associated task as "Completed" when a proof document with a specific name pattern is uploaded.
Log questions in the comments field
If a task cannot be completed because information is missing or a decision is pending, the person working on the task should document the reason in the task's comments field and set the status to "Blocked." A flow responds to this status change and notifies the superior person or the onboarding coordination team.
Typical errors due to missing fields, unclear roles, and parallelism
Mandatory fields are missing from the form
If the form does not define fields such as department or start date as mandatory, these are often left blank. All follow-up logic based on these fields then fails. Fields required for task generation or due date calculation must be marked as mandatory in the form.
Role ambiguities in task assignment
If tasks are assigned to a group instead of a specific person, notifications are often ineffective. An email to a group address is frequently ignored because no one feels explicitly responsible. Better: Assign tasks to a defined role with a primary contact person, which is read from a configuration list in the flow.
Parallelism during simultaneous onboardings
If multiple new employees start on the same day and all fill out the onboarding form simultaneously, parallel flow instances are created. This is fundamentally not a problem as long as each flow works only with its own list entries. Conflicts arise only if multiple flows write to the same shared resource, for example, a central counter list for device serial numbers.
Missing audit trail for permission grants
For compliance and internal audit, it is important that all permission grants are logged with timestamps, the executing person, and the justification. If permission grants happen automatically, the flow should write an entry in a log list that contains at least: user account, assigned group, timestamp, and triggering flow run.
How to keep the onboarding process manageable even with role changes
An IT onboarding in SharePoint and Power Automate is robust when the configuration (task catalog, role matrix, due date rules) is stored in lists and not hard-coded in the flow. If tasks or responsibilities change, only the configuration list needs to be adjusted, not the flow itself.
The distinction between automated steps and manual decisions must be clear and documented. Automation is not a substitute for control but a means to make control more structured and traceable. Steps requiring approval, security-relevant access, and exceptions still require human decisions. Automation ensures these decisions reach the right person at the right time and that the result is reliably implemented afterward.
For a more comprehensive view of the onboarding process beyond technical IT setup, the article Digital Employee Onboarding with Power Platform & SharePoint describes the HR and business team process that precedes this IT setup. For the automatic assignment of Entra ID access and synchronization with offboarding processes, the article Automate Onboarding & Offboarding: SharePoint, Entra ID & Power Automate provides further technical details.
If onboarding is meant to be technically clean, not just organizational
Then it is worth looking at form logic, permissions, task lists, and audit trail. Check onboarding setup technically