We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. IT support
  2. Switching IT provider
How to switch IT provider

Changing providers costs less administrative pain than another year with one who has stopped caring.

Companies tolerate a failing provider roughly a year longer than they should, for two reasons: the move feels dangerous, and the incumbent is sitting on every password. In reality a well-run change is two to four weeks of administration. A defined checklist, a period where both providers run side by side so nothing ever goes dark, and a credentials handover you are entitled to regardless of whether the outgoing provider feels like helping. What follows is the whole playbook, from recognizing the moment through to what the first ninety days should look like.

Talk to us about switchingSee the safe transition path
Engineer managing a structured IT provider handover for a US business
  • 2-4 weeksTypical switch duration
  • 0Downtime in a parallel-run switch
  • 14 daysBoth providers active
  • FreePre-switch environment audit
The credentials-and-access checklist

Nine things that have to come back to you before or during any move.

This list is the heart of every transition. Every item on it belongs to your company rather than to the provider, no matter who originally set it up. Work through it with the incoming provider before you serve notice, so you know exactly what sits where and what will need recovering.

Microsoft 365 or Google Workspace Global Admin

This is the master key to your mail, your files, and every identity you own. You need at least one global administrator account in your own name, protected by multi-factor, before cutover happens. Where the tenant currently sits inside the provider partner account, transferring ownership is a documented Microsoft process rather than a favor they can decline.

Domain registrar and DNS control

Whoever controls the domain decides where your email is delivered, and no setting inside your tenant overrides that. Confirm the registrar account is in your company name. If it turns out to be registered to the provider, start the transfer immediately, because it takes days and it is the item left too late more often than any other.

Firewall, router, and switch admin passwords

Every network device in your building carries an administrative credential. Collect each one, or accept that it gets factory reset and rebuilt during handover. A provider who cannot find the firewall password is telling you, without meaning to, that the device was never documented in the first place.

Backup console access and a proven restore

Establish where the backups physically sit, who holds the encryption keys, and whose name the subscription is in. Then have the incoming provider actually restore something before the old service is switched off. A backup nobody can restore during a handover was never a backup at all.

Software licenses and subscriptions in your name

Microsoft licensing, endpoint security seats, line-of-business software, certificates. Providers routinely buy all of it through their own reseller accounts. On exit each license either transfers into your tenant, moves to the incoming provider relationship, or has to be bought again. Work out which of those three applies to every item before you serve notice, not after.

Documentation: network, assets, configurations

The network diagram, the addressing plan, the server and endpoint inventory, wireless keys, how the VPN is configured, and the change history. Contractually all of that is normally yours already. Where it simply does not exist, the incoming provider builds it during the walkthrough, and you end up with documentation you can actually read for the first time.

ISP, telecom, and SaaS account ownership

Your carrier account numbers and authorized contacts, hardware warranty registrations, and every third-party subscription the provider currently administers on your behalf. Each of those needs your name added now and the outgoing provider contact removed once cutover is done.

Monitoring agents and remote-access tools

The outgoing provider has remote control software installed on every machine you own. A clean handover removes their agents, deploys the replacement, and confirms in writing that the old remote access is revoked. Skip that step and a former vendor keeps a working door into your endpoints indefinitely.

Mailbox and service-account passwords

Service accounts, shared mailboxes of the info and billing variety, and whatever password vault the provider has been maintaining. All of it rotates at cutover, so the old access stops working on a specific known date, cleanly, and without anybody having to accuse anybody of anything.

What a safe transition looks like

Four principles that make the whole thing boring, which is exactly the goal.

Run properly, this is one checklist executed twice: once on paper, then once for real.

Parallel-run, never a hard cutover

The incoming provider stands up monitoring and a help desk alongside the outgoing one for a fortnight. Both run at once and nothing ever goes dark. Cutover then happens at an agreed quiet window, once the new monitoring has proved it works. At no point is there a moment where nobody is watching.

Checklist-driven, with named owners and dates

Every credential, license, device, and document goes into a written plan with a name against it, a date, and a definition of what finished looks like. Handovers fail in the ambiguity, and a proper checklist removes the ambiguity entirely.

Designed to work without the old provider

The plan assumes from the start that the outgoing provider may be slow, unhelpful, or entirely silent, and routes around all three. Tenant ownership recovers through Microsoft directly. Domains transfer at the registrar. Firewalls get reset and rebuilt. Cooperation makes everything faster and is never a precondition for anything.

Knowledge captured, not assumed

While both providers are running, the incoming team walks your environment with your own people: what is fragile, what nobody ever wrote down, which recurring annoyance everyone has quietly learned to work around. Nearly all of what the outgoing provider knows can be reconstructed inside thirty days, and the walkthrough captures it deliberately rather than during an outage at two in the morning.

Before you give notice

What to check in your current contract first.

Read the agreement before you say a word to anyone. Ten minutes with the contract settles your timing, your leverage, and whether this costs you anything beyond effort. Being unable to find the contract is itself useful information, because an unsigned or lapsed agreement usually means you are on rolling terms with a short notice period.

Term and notice

  • Notice period and how notice must be served
    Most American managed services agreements require somewhere between thirty and ninety days written notice. Check whether email satisfies that, and put the deadline in a calendar today.
  • Auto-renewal date
    Plenty of agreements roll into another full year if notice misses a specific date. Where that date is close, serve protective notice now and make the actual decision at your own pace.
  • Early-termination clause
    Find out what leaving early actually costs, and whether sustained service failure gives you grounds to leave without paying it.

Data, access, and exit obligations

  • Exit-assistance clause
    The better agreements require the outgoing provider to hand over credentials, documentation, and data inside a defined window. If yours contains one, quote the clause directly in your notice letter.
  • Data return and deletion
    Establish exactly what they hold, how it comes back, and when their own copies get destroyed. Where you carry HIPAA obligations or answer to a state privacy statute, their copies sit inside your compliance scope as much as yours do.
  • Who owns the documentation
    Documentation produced under a contract you paid for is normally yours. Read the intellectual property clause before assuming it.

Licenses, hardware, and money

  • Licenses bought through the provider
    List every subscription currently billed through the provider and establish whether each one lapses the day you leave. This is precisely where an unmanaged move quietly switches your email off.
  • Provider-owned equipment on your site
    Any firewall, access point, or backup appliance they loaned you goes back when you leave. Know which devices belong to them in advance, so removal is scheduled rather than discovered on the day.
  • Outstanding invoices and disputes
    Pay whatever is not in dispute and document the disputed items separately in writing. An unpaid invoice is by far the most common pretext for withholding a handover.
The signs it is time to switch

Six signs the provider has stopped earning what you pay them.

Any one of these on its own is not a reason to move. Two or more, running for months, means staying has quietly become riskier than leaving.

Tickets sit for days, escalations go nowhere

You raise a ticket, chase it twice, and eventually somebody resolves it without ever explaining what went wrong. What that usually means is your account is no longer staffed the way it was when you signed, and response quality almost never recovers on its own.

Surprise invoices for things you thought were covered

Things that were covered last year now arrive with a line item attached. Routine maintenance turns up as a project charge. Scope creeping in the invoicing direction usually means somebody has worked out you are unlikely to reread the agreement.

No documentation you can actually see

Ask for three things: the network diagram, the asset register, and a list of administrative accounts. If what comes back is silence, a PDF from 2022, or an assurance that it is all held in their system, then the knowledge of how your company runs lives inside a vendor you are already unhappy with. That is a dependency wearing the costume of a service.

They hold your credentials and you hold nothing

The global administrator account, the registrar login, the firewall password, the backup console. Every one of them with the provider and none of them with you. Held credentials are the single biggest reason companies stay too long, and also the most fixable. That access belongs to you by right, and recovering it is routine work.

Security appears in their brochure and nowhere in your environment

No enforced multi-factor, no evidence anything is being patched, no backup anyone has ever test-restored, and not one word about any of it until your carrier or a customer questionnaire forced the question. A provider who has not raised security with you in twelve months is exposing you quietly and getting paid for it.

No reporting, no reviews, no roadmap

You cannot recall the last written report, or the last meeting where they arrived with an idea rather than an invoice. Support with no periodic review is pay-per-incident wearing a contract: a retainer for something that only exists on the days it fails.

Your three real options

Switching, staying, or running the transition yourself.

Credentials recovered into your name
Structured switch
Stay and hopeStill held by provider
DIY transitionIf you know the list
Coverage during the transition
Structured switch14-day parallel run
Stay and hopeN/A
DIY transitionGap between providers
Backup proven by a test restore
Structured switch
Stay and hopeUnknown
DIY transitionIf you remember
Old provider access cleanly revoked
Structured switch
Stay and hopeN/A
DIY transitionOften missed
Handles an uncooperative incumbent
Structured switchPlanned for
Stay and hopeN/A
DIY transitionStressful, unfamiliar
Your time consumed
Structured switchA few hours of decisions
Stay and hopeNone now, more later
DIY transitionDays of coordination
Feature
Structured switch
Stay and hope
DIY transition
Credentials recovered into your name
Still held by providerIf you know the list
Coverage during the transition
14-day parallel runN/AGap between providers
Backup proven by a test restore
UnknownIf you remember
Old provider access cleanly revoked
N/AOften missed
Handles an uncooperative incumbent
Planned forN/AStressful, unfamiliar
Your time consumed
A few hours of decisionsNone now, more laterDays of coordination
After the switch

The first ninety days, and what good actually looks like.

The move itself takes two to four weeks. The proof turns up across the quarter after it. Hold whoever you appoint to this shape, and that very much includes us.
  1. 01
    Days 1-14

    Stabilize and secure

    The parallel period closes, the incoming provider becomes primary, and every credential on the handover checklist is rotated and vaulted. Monitoring is live on every endpoint, the old remote access is confirmed revoked in writing, and somebody has actually restored a backup rather than assuming one exists.

    • All passwords rotated and vaulted
    • Access revocation confirmed in writing
    • Test restore evidenced
  2. 02
    Days 15-30

    Document and baseline

    The walkthrough finishes and produces a network diagram, an asset register, a license inventory, and a security baseline review covering multi-factor, patching, and mail authentication. Everything the previous provider never bothered writing down now exists in a form you can open and read.

    • Documentation pack: network, assets, licenses
    • Security baseline review with findings
    • First monthly service report
  3. 03
    Days 31-60

    Fix the inherited backlog

    Every move uncovers deferred maintenance somebody has been avoiding: servers well behind on patches, accounts belonging to people who left in 2023, warranties that expired without anyone noticing, and a backup job that has been failing silently for months. All of it goes onto an agreed priority list, and the recurring problems get root-cause fixes rather than the same workaround applied for the fifteenth time.

    • Inherited-issues backlog worked to an agreed priority list
    • Dormant accounts removed, patching brought current
  4. 04
    Days 61-90

    Review and plan forward

    The first quarterly review covers what the transition found, what has been fixed since, what the numbers actually say, and a twelve-month plan covering renewals, replacements, and improvements. This is precisely the meeting your previous provider quietly stopped holding.

    • First quarterly review held
    • 12-month IT plan delivered in writing
The safe path

How a provider switch actually runs, in four phases.

The same structure applies whether you are leaving a national MSP, a local shop, or a one-person arrangement. Only the depth of each phase changes.
  1. 1

    Audit and transition plan

    Week 1

    The incoming provider works the credentials and access checklist against your actual environment: what exists, who currently holds it, and what is missing entirely. Meanwhile you read your contract for the notice terms. What comes out is a written transition plan with names and dates on it, produced before a word of notice is served.

  2. 2

    Serve notice and recover access

    Weeks 1-2

    Notice goes to the outgoing provider in whatever form the contract demands, quoting the exit assistance clause. Credential recovery starts the same day: tenant ownership, the domain transfer, mapping the licensing, and a formal documentation request. Providers who cooperate hand things over. Providers who do not get routed around.

  3. 3

    Parallel run and cutover

    2 weeks

    New monitoring and a new help desk go live beside the existing service. Once that is stable, cutover happens at a quiet window: the support contact changes, credentials rotate, the old remote access agents come off every machine, and the revocation is confirmed in writing. Zero downtime is how it is designed, not something anybody is hoping for.

  4. 4

    Stabilize, document, review

    Days 15-90

    Documentation rebuilt, a backup genuinely restored as a test, the inherited backlog worked through, the first monthly report at day thirty and the first quarterly review by day ninety with a twelve-month plan attached. The move is finished when things are measurably better, not on the date the old contract expired.

If your provider is not responding

What to do when the outgoing provider goes quiet or simply refuses.

A minority of providers take notice badly. Calls stop being returned, handover requests go unanswered, or access is held back until an invoice dispute resolves their way. It is alarming to be on the receiving end and it is almost always survivable, because very little of what they hold cannot be recovered another way.

  • Put every request in writing with a deadline attached, citing the exit or data return clause in your agreement. A dated paper trail changes behavior all by itself, before anybody involves a lawyer.
  • Take tenant control back through Microsoft directly. Where a global administrator account already exists in your name, use it to remove theirs. Where none does, Microsoft has a documented ownership process built for exactly this situation, and it takes days rather than months.
  • Transfer the domain at the registrar level using your business formation documents to prove ownership. Registrars deal with unresponsive third parties routinely.
  • Where recovering something takes longer than rebuilding it, rebuild it. A firewall whose password nobody will surrender gets factory reset and reconfigured in a single evening.
  • Rotate every password as each service comes back and keep a log of when. The objective is a clean, dated end to the old access, not an argument that runs for six months.
Get help with a difficult handover
Switching IT provider FAQ

The questions every business asks before moving.

Not when it runs as a parallel transition, which is the only way we do them. Our monitoring and help desk go live beside your current arrangement for a fortnight, so no moment exists where nobody is covering you. Cutover is then a scheduled change at a quiet window: the support contact changes and the credentials rotate. Your email, your files, and your applications do not move anywhere at all. Only the people looking after them change.

The active work runs two to four weeks: a week of audit and planning, then a fortnight of parallel running that finishes at cutover. What actually sets the calendar is your notice period rather than any technical constraint, since most American managed services agreements demand between thirty and ninety days. Run the audit and the preparation during that notice period so cutover lands neatly on the day the old contract ends.

The move completes regardless, and simply knowing that is half your leverage. Tenant ownership recovers through Microsoft directly. Domains transfer at the registrar using your incorporation documents as proof of who you are. Devices whose passwords nobody will surrender get factory reset and rebuilt. Alongside all of that, every request goes to them in writing with a deadline and a citation of the exit clause. In practice most providers start cooperating the moment they realize the process is documented and will finish without them.

Briefly, and on purpose. The fortnight of parallel running means you are paying two providers for two weeks, which is the price of a move with no downtime in it and is well worth paying. Past that, no. The transition is planned so the new service begins exactly as the old contract ends, and transition work is not billed separately. The overlap genuinely worth avoiding is the accidental one, caused by missing an automatic renewal date, which is precisely why checking your notice deadline is step one.

They divide into three groups. Anything already sitting in your own tenant simply carries on and nothing changes at all. Anything bought through the outgoing provider reseller relationship moves across to the incoming one, which is a standard Microsoft process that interrupts nothing when it is sequenced properly. Third-party subscriptions held in the provider name get re-registered to yours. Map every single subscription before notice goes out, because the way an unmanaged move fails is a license lapsing quietly five weeks later and taking your email with it.

Yes, and you should, whether that is with us or with somebody else entirely. An audit before you commit tells you what you actually own, who holds every credential, what condition the backups are genuinely in, and what the outgoing provider has quietly left undone. It turns the whole thing from a leap of faith into a checklist, and it works equally well as leverage if you decide to stay and renegotiate instead. We run it as a free scoping exercise and the written findings are yours regardless of what you do next.

That is the normal starting position rather than an obstacle. Most companies who move have no asset list, no network diagram, and no clear idea which licenses they are paying for, because the outgoing provider never shared any of it. The first week is precisely that discovery work: the walkthrough builds an inventory from the live environment, and by cutover you hold documentation you have never had in your possession before. Not knowing what you own is an argument for moving, not an argument for staying.

Usually for the better, if the transition is run properly. The handover is the natural moment to fix the gaps the questionnaire asks about: MFA enforced, old third-party access revoked, backup proven by a test restore, and monitoring actually watched. Two cautions worth knowing: if your policy or a compliance framework requires notification when a key vendor changes, put it on the transition checklist; and make sure the outgoing provider's data copies are returned or destroyed on a documented date, because their retention is inside your compliance scope. Both items are standard lines in our transition plan.

Hold every candidate, us very much included, to four commitments visible inside ninety days: documentation delivered, a restore actually tested, a monthly report arriving, and a quarterly review with a twelve-month plan attached. Anyone who delivers all four in the first quarter is structurally different from anyone who does not, and you will know which you have by day ninety rather than in year two. Read the exit terms before you sign, too. A provider confident in their own service makes leaving straightforward.

Far more common than anybody admits, and the answer is to let process carry what personality cannot. Written notice citing business requirements, handover deadlines that are actually reasonable, undisputed invoices settled promptly, and a clean credential rotation give both sides a dignified way out. An independent audit helps enormously here, because it makes the findings rather than the friendship the reason for the change.

Not much, because the transition is remote-first by design. Monitoring, helpdesk, tenant recovery, and credential rotation are location-independent, so every site moves under the same plan. Where hands-on work is genuinely needed, a firewall replacement, equipment returns to the old provider, it is scheduled per site at its own low-risk window, with field work coordinated as part of the plan. The credentials checklist runs per entity where licenses or tenants are separate, and consolidates where they are shared.
Go deeper

The switching and evaluation library.

This page is the overview. Each page below goes deeper on one part of the transition, from recovering a Microsoft 365 tenant a previous partner still controls to the audits worth running before you commit to anyone.

Recovering the Microsoft tenant

For most US businesses the Microsoft 365 tenant is the crown jewels of the handover. These pages cover taking it back and running it properly afterward.

  • Tenant takeover from a previous partnerRecovering Global Admin, CSP billing, and delegated access from an old provider, cooperatively or not.
  • Microsoft 365 tenant managementWhat good ongoing tenant operations look like once the takeover is complete.
  • Tenant security baselineThe hardening pass every inherited tenant needs, because the last provider rarely did it.

Audit what you are inheriting

This is the natural moment to establish what the last provider left behind. These turn a general unease into a written list of findings.

  • Cybersecurity audit and complianceA complete environment audit covering security posture, licensing, access control, and evidence that backups work.
  • Data backupWhether the backups the old provider billed for can actually restore, proven by a test.

Where you might land next

The contract shapes switchers typically move into, depending on how much of IT you want off your desk.

  • Managed IT servicesThe broader arrangement: day-to-day operations plus strategy, reporting, and a roadmap.
  • IT AMCContract-backed maintenance and support for a defined estate at a fixed scope.
  • IT supportResponsive help under a tiered SLA, the lighter-touch starting point.
Where you might land next

What the new arrangement could look like.

IT AMC

The contract shape many small and mid-size businesses switch into.

Learn more

Managed IT services

The broader arrangement: day-to-day operations plus strategy, reporting, and a roadmap.

Learn more

IT support

How we support US businesses day to day.

Learn more
Ready when you are

Take the free audit first and decide once you can see the findings.

Tell us what is actually frustrating you about the current arrangement. We will run the credentials checklist against your environment and put the findings in writing. Where the right answer turns out to be staying and renegotiating, you will hear that. Where it is moving, you will be holding the plan before you serve notice.

Book the free pre-switch auditSee how we compare

Related Services

Explore more solutions that work great with this service

Tenant Takeover

Take control back from a previous partner

Learn more

M365 Tenant Management

Your tenant run properly, end to end

Learn more

Tenant Security Baseline

Documented controls mapped to CIS

Learn more

Managed IT Services

Complete outsourced IT department

Learn more

IT AMC USA

Annual maintenance contracts for IT infrastructure

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA