A practical checklist for changing managed IT providers while protecting access, ownership, documentation, support continuity, and business systems.
Keep the outgoing provider in place until the incoming provider confirms access, documentation, licensing, backup responsibilities, escalation contacts, and continued access to critical systems.
Start with ownership, not passwords
Before announcing a change, identify the legal and administrative ownership of the domain, DNS, Microsoft 365 account, cloud subscriptions, backup platforms, security tools, internet accounts, software licenses, and important vendor relationships.
A business should not discover during a transition that an outside provider is the only owner of a critical account. Resolve ownership carefully and preserve logs or records when access changes matter.
Build the transition inventory
- Employees, locations, computers, mobile devices, printers, network equipment, servers, and cloud services.
- Domains, DNS, email, Microsoft 365, line-of-business applications, websites, and phone systems.
- Administrative accounts, service accounts, emergency access, multifactor authentication methods, and recovery contacts.
- Security, monitoring, backup, remote access, documentation, ticketing, and licensing platforms.
- Open incidents, planned projects, renewals, known risks, aging equipment, and vendor escalations.
Agree on the sequence
The incoming provider should identify what must be accessible on the first day, what can be transferred later, and what cannot be verified until the outgoing provider participates. Critical access should have an owner, validation step, and fallback path.
- Confirm authorized decision-makers and a private transition communication channel.
- Inventory systems and request documentation without removing active coverage.
- Validate customer ownership and establish appropriate incoming-provider access.
- Confirm backup status, security tooling, support intake, and critical vendor contacts.
- Coordinate removal of outgoing-provider access only after replacement access is verified.
- Record unresolved risks, missing documentation, and follow-up work in writing.
Protect business continuity
Avoid unnecessary tool changes during the handoff. Replacing every agent, backup platform, security product, and administrative workflow at once can make the transition harder to observe and troubleshoot.
Where practical, separate the handoff from later improvement projects. The immediate goal is to keep critical systems available and responsibilities visible. Other changes can follow once the current setup is understood.
Close the transition with evidence
- The business controls its core accounts and recovery contacts.
- The new support path has been communicated to employees.
- Covered devices and systems appear in the new inventory.
- Backup, security, and monitoring responsibilities are assigned and their current status is known.
- Outgoing-provider access has been reviewed and removed where appropriate.
- Open issues, exceptions, and recommended fixes have a documented owner and next step.
