## TL;DR
Linux laptop provisioning is enrollment plus identity plus access: get the machine into your MDM or management tool, join identity, install the standard toolset, and verify before handoff. A checklist keeps every laptop identical and auditable.

## The query
```text
new hire laptop provisioning checklist: linux
```

## Use this when
- onboarding a new hire onto a Linux laptop
- standardizing a Linux fleet build
- auditing what is installed on Linux endpoints

## Not for
- Linux servers (different hardening baseline)
- personal devices (use BYOD guidance instead)
- one-off developer snowflakes (still enroll them first)

## Steps
1. Confirm the hardware receipt, record the serial and asset tag, and assign the device to the user in the asset system. Expected output: the device is tracked to the user
2. Install or verify the standard image, then enroll the machine in your device management tool. Expected output: the device shows as managed and compliant
3. Join identity: configure SSO login and enroll the user in MFA. Expected output: the user can sign in with corporate credentials
4. Install the standard toolset: VPN client, EDR agent, and required certificates. Expected output: all agents report healthy
5. Apply disk encryption and verify it is on. Expected output: encryption confirmed active
6. Have the user sign in and verify email, VPN, and core apps before closing the ticket. Expected output: the user confirms everything works

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_uG61HuvFWELfBcjKR4fSpw
