Switching IT providers? The MSP handover checklist.
Steps verified against the official documentation below · last checked 2026-07-18
Your IT provider is the one vendor that legitimately holds admin on everything: the Microsoft 365 or Google Workspace tenant, the domain and DNS, the firewall, the endpoints, the backups. That's the arrangement working as intended — right up until you switch providers, and discover that 'they manage it' has quietly become 'they own it.'
A clean MSP transition is mostly a controlled transfer of privileges. Here's the checklist, whether the split is friendly or fraught.
Before you give notice: establish your own root
- 1Get tenant admin in the business's handsAt least one Global Administrator (M365) or super admin (Workspace) on an account your business controls — not the MSP's engineer accounts. Verify you can actually sign in. This single step converts every later dispute from a hostage situation into an inconvenience.
- 2Confirm domain and DNS controlRegistrar account holder, DNS host, nameservers — run the lookup and know where each lives. MSPs frequently hold these 'for convenience.'
- 3Inventory what they manageTenants, licences, firewall/network gear and their admin logins, endpoint agents (RMM), backup systems and their storage, password vault, phone system, warranties. Ask for their asset list too — good MSPs maintain one.
The handover items
- 1Licences and subscriptionsIf Microsoft/Google licences were bought through the MSP (a CSP/reseller arrangement), they don't automatically follow you — the new provider or the business takes over billing for the tenant. Sequence this so nothing lapses mid-switch.
- 2Admin credential transferEvery system on the inventory gets a documented admin handover: tenant roles, firewall admin, switch/AP controllers, backup consoles. New provider verifies each before the old one's access ends.
- 3Backups — before anything else changesConfirm where backups live, that the business (or incoming provider) can reach them, and that a test restore works. Never cut over on faith in backups you've never restored.
- 4Remove their agents and access lastRMM/monitoring agents, remote-access tools, their engineers' accounts in your tenant, VPN accounts, conditional-access exceptions. This happens after the new provider is fully stood up — a gap in coverage is worse than an overlap.
- 5Rotate what was sharedAnything from the MSP's password vault that was ever shared outside it — local admin passwords, Wi-Fi, service accounts — gets rotated at cutover.
Run a Stedra scan and register review as part of the transition — it surfaces the tenant, DNS, and tool relationships the outgoing provider set up that nobody wrote down, while they're still contractually obliged to answer questions.
The contract and conduct notes
- Check the exit clauses before giving notice: data return, handover cooperation, and any offboarding fees. Time your notice so the overlap window is covered.
- Keep it professional and pay the final invoices — withheld payment is the top cause of handover friction, and MSPs talk to each other.
- A provider that resists giving the business its own admin account is answering your due-diligence question for you — that applies to the incoming one too.
- Going forward: the business always holds its own root (tenant admin, registrar, DNS), and every provider — however trusted — works from delegated access you can revoke.
SOURCES & OFFICIAL DOCUMENTATION
This is one asset. How many others does your business not control?
The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.
Check my businessKEEP READING