Overview
This article provides a low-risk, evidence-driven troubleshooting path for new employee cannot access the files or apps they need. Work from identity and service checks toward more disruptive actions, and stop before a change could cause data loss, broaden access, weaken security, or interrupt other users.
Why this happens
New-employee access failures commonly result from incomplete account setup, missing licenses, group membership, permissions, application assignment, MFA registration, or propagation delay.
Before You Begin
- Confirm the new employee's exact account and assigned role.
- Record which files, apps, or MFA step is failing.
- Compare expected access with the approved onboarding request.
- Do not share another employee's credentials or overassign access.
Navigation reference: Microsoft 365 admin center > Users > Active users.
Click-by-Click Troubleshooting
Step 1: Confirm the onboarding request
Action: Review the approved new-employee request and list the exact files, apps, groups, and mailboxes the employee should receive.
Why this matters: Access cannot be troubleshot without a defined expected state.
What to look for: Compare requested role access with what the employee says is missing.
Expected result: The expected access set should be documented.
Step 2: Verify the account and license
Action: Open Microsoft 365 admin center > Users > Active users or the relevant platform admin console and verify the user's active account and license.
Why this matters: A disabled or unlicensed account can cause many downstream access failures.
What to look for: Look for missing licenses, disabled sign-in, or wrong account.
Expected result: The base identity should be healthy.
Step 3: Test one service in the browser
Action: Have the employee sign in to one affected service through the official web portal.
Why this matters: Browser testing separates account/permission problems from local app configuration.
What to look for: Look for Access denied, license, or wrong-account messages.
Expected result: The failing layer should become clearer.
Step 4: Verify group or resource membership
Action: Check the approved Microsoft 365 group, SharePoint group, shared mailbox delegation, application role, or Google group that grants the expected access.
Why this matters: Business access should normally follow approved roles/groups rather than ad hoc credential sharing.
What to look for: Confirm the employee is in the expected access group.
Expected result: Required group-based access should match the onboarding request.
Step 5: Allow propagation and retest
Action: After an approved access assignment, wait the platform's normal propagation period, sign out/in, and retest the same resource.
Why this matters: Cloud access changes may not appear instantly.
What to look for: Confirm the same error either clears or remains reproducible.
Expected result: The resource should become accessible after the authorized change propagates.
Step 6: Escalate mismatched or privileged access
Action: Contact IT when the requested access requires elevated privileges, the resource owner is unclear, or assigned access still fails.
Why this matters: Over-permissioning a new employee creates unnecessary security risk.
What to look for: Provide the onboarding request, resource, and current membership.
Expected result: IT should be able to resolve the exact missing entitlement.
What to Look For
- Whether the issue affects one user/device or multiple users.
- Whether a clean browser or alternate approved client changes the result.
- Whether the error points to identity, permission, licensing, service, device, or network state.
- Whether the same controlled test succeeds after the targeted correction.
When to Stop
When to Contact IT
Contact J3 Systems Group if the issue remains unresolved, affects multiple users, requires administrator-level changes, involves security or data-loss risk, or the next step would be disruptive. Include article code KB-06.002, the affected account/device/resource, exact error, time observed, and the results of the controlled tests above.
Need help with this issue?
J3 Systems Group supports small businesses and nonprofits with Microsoft 365, Google Workspace, cybersecurity, devices, documentation, and day-to-day IT operations.
Contact J3 Systems GroupAuthoritative references
Vendor interfaces, licensing, and security guidance can change. Verify current platform behavior against the primary documentation below before making high-impact production changes.