Changing providers costs less administrative pain than another year with one who has stopped caring.
Companies tolerate a failing provider roughly a year longer than they should, for two reasons: the move feels dangerous, and the incumbent is sitting on every password. In reality a well-run change is two to four weeks of administration. A defined checklist, a period where both providers run side by side so nothing ever goes dark, and a credentials handover you are entitled to regardless of whether the outgoing provider feels like helping. What follows is the whole playbook, from recognizing the moment through to what the first ninety days should look like.

- 2-4 weeksTypical switch duration
- 0Downtime in a parallel-run switch
- 14 daysBoth providers active
- FreePre-switch environment audit
Nine things that have to come back to you before or during any move.
Microsoft 365 or Google Workspace Global Admin
This is the master key to your mail, your files, and every identity you own. You need at least one global administrator account in your own name, protected by multi-factor, before cutover happens. Where the tenant currently sits inside the provider partner account, transferring ownership is a documented Microsoft process rather than a favor they can decline.
Domain registrar and DNS control
Whoever controls the domain decides where your email is delivered, and no setting inside your tenant overrides that. Confirm the registrar account is in your company name. If it turns out to be registered to the provider, start the transfer immediately, because it takes days and it is the item left too late more often than any other.
Firewall, router, and switch admin passwords
Every network device in your building carries an administrative credential. Collect each one, or accept that it gets factory reset and rebuilt during handover. A provider who cannot find the firewall password is telling you, without meaning to, that the device was never documented in the first place.
Backup console access and a proven restore
Establish where the backups physically sit, who holds the encryption keys, and whose name the subscription is in. Then have the incoming provider actually restore something before the old service is switched off. A backup nobody can restore during a handover was never a backup at all.
Software licenses and subscriptions in your name
Microsoft licensing, endpoint security seats, line-of-business software, certificates. Providers routinely buy all of it through their own reseller accounts. On exit each license either transfers into your tenant, moves to the incoming provider relationship, or has to be bought again. Work out which of those three applies to every item before you serve notice, not after.
Documentation: network, assets, configurations
The network diagram, the addressing plan, the server and endpoint inventory, wireless keys, how the VPN is configured, and the change history. Contractually all of that is normally yours already. Where it simply does not exist, the incoming provider builds it during the walkthrough, and you end up with documentation you can actually read for the first time.
ISP, telecom, and SaaS account ownership
Your carrier account numbers and authorized contacts, hardware warranty registrations, and every third-party subscription the provider currently administers on your behalf. Each of those needs your name added now and the outgoing provider contact removed once cutover is done.
Monitoring agents and remote-access tools
The outgoing provider has remote control software installed on every machine you own. A clean handover removes their agents, deploys the replacement, and confirms in writing that the old remote access is revoked. Skip that step and a former vendor keeps a working door into your endpoints indefinitely.
Mailbox and service-account passwords
Service accounts, shared mailboxes of the info and billing variety, and whatever password vault the provider has been maintaining. All of it rotates at cutover, so the old access stops working on a specific known date, cleanly, and without anybody having to accuse anybody of anything.
Four principles that make the whole thing boring, which is exactly the goal.
Parallel-run, never a hard cutover
The incoming provider stands up monitoring and a help desk alongside the outgoing one for a fortnight. Both run at once and nothing ever goes dark. Cutover then happens at an agreed quiet window, once the new monitoring has proved it works. At no point is there a moment where nobody is watching.
Checklist-driven, with named owners and dates
Every credential, license, device, and document goes into a written plan with a name against it, a date, and a definition of what finished looks like. Handovers fail in the ambiguity, and a proper checklist removes the ambiguity entirely.
Designed to work without the old provider
The plan assumes from the start that the outgoing provider may be slow, unhelpful, or entirely silent, and routes around all three. Tenant ownership recovers through Microsoft directly. Domains transfer at the registrar. Firewalls get reset and rebuilt. Cooperation makes everything faster and is never a precondition for anything.
Knowledge captured, not assumed
While both providers are running, the incoming team walks your environment with your own people: what is fragile, what nobody ever wrote down, which recurring annoyance everyone has quietly learned to work around. Nearly all of what the outgoing provider knows can be reconstructed inside thirty days, and the walkthrough captures it deliberately rather than during an outage at two in the morning.
What to check in your current contract first.
Term and notice
- Notice period and how notice must be servedMost American managed services agreements require somewhere between thirty and ninety days written notice. Check whether email satisfies that, and put the deadline in a calendar today.
- Auto-renewal datePlenty of agreements roll into another full year if notice misses a specific date. Where that date is close, serve protective notice now and make the actual decision at your own pace.
- Early-termination clauseFind out what leaving early actually costs, and whether sustained service failure gives you grounds to leave without paying it.
Data, access, and exit obligations
- Exit-assistance clauseThe better agreements require the outgoing provider to hand over credentials, documentation, and data inside a defined window. If yours contains one, quote the clause directly in your notice letter.
- Data return and deletionEstablish exactly what they hold, how it comes back, and when their own copies get destroyed. Where you carry HIPAA obligations or answer to a state privacy statute, their copies sit inside your compliance scope as much as yours do.
- Who owns the documentationDocumentation produced under a contract you paid for is normally yours. Read the intellectual property clause before assuming it.
Licenses, hardware, and money
- Licenses bought through the providerList every subscription currently billed through the provider and establish whether each one lapses the day you leave. This is precisely where an unmanaged move quietly switches your email off.
- Provider-owned equipment on your siteAny firewall, access point, or backup appliance they loaned you goes back when you leave. Know which devices belong to them in advance, so removal is scheduled rather than discovered on the day.
- Outstanding invoices and disputesPay whatever is not in dispute and document the disputed items separately in writing. An unpaid invoice is by far the most common pretext for withholding a handover.
Six signs the provider has stopped earning what you pay them.
Tickets sit for days, escalations go nowhere
You raise a ticket, chase it twice, and eventually somebody resolves it without ever explaining what went wrong. What that usually means is your account is no longer staffed the way it was when you signed, and response quality almost never recovers on its own.
Surprise invoices for things you thought were covered
Things that were covered last year now arrive with a line item attached. Routine maintenance turns up as a project charge. Scope creeping in the invoicing direction usually means somebody has worked out you are unlikely to reread the agreement.
No documentation you can actually see
Ask for three things: the network diagram, the asset register, and a list of administrative accounts. If what comes back is silence, a PDF from 2022, or an assurance that it is all held in their system, then the knowledge of how your company runs lives inside a vendor you are already unhappy with. That is a dependency wearing the costume of a service.
They hold your credentials and you hold nothing
The global administrator account, the registrar login, the firewall password, the backup console. Every one of them with the provider and none of them with you. Held credentials are the single biggest reason companies stay too long, and also the most fixable. That access belongs to you by right, and recovering it is routine work.
Security appears in their brochure and nowhere in your environment
No enforced multi-factor, no evidence anything is being patched, no backup anyone has ever test-restored, and not one word about any of it until your carrier or a customer questionnaire forced the question. A provider who has not raised security with you in twelve months is exposing you quietly and getting paid for it.
No reporting, no reviews, no roadmap
You cannot recall the last written report, or the last meeting where they arrived with an idea rather than an invoice. Support with no periodic review is pay-per-incident wearing a contract: a retainer for something that only exists on the days it fails.
Switching, staying, or running the transition yourself.
| Feature | Structured switch | Stay and hope | DIY transition |
|---|---|---|---|
Credentials recovered into your name | Still held by provider | If you know the list | |
Coverage during the transition | 14-day parallel run | N/A | Gap between providers |
Backup proven by a test restore | Unknown | If you remember | |
Old provider access cleanly revoked | N/A | Often missed | |
Handles an uncooperative incumbent | Planned for | N/A | Stressful, unfamiliar |
Your time consumed | A few hours of decisions | None now, more later | Days of coordination |
The first ninety days, and what good actually looks like.
- 01Days 1-14
Stabilize and secure
The parallel period closes, the incoming provider becomes primary, and every credential on the handover checklist is rotated and vaulted. Monitoring is live on every endpoint, the old remote access is confirmed revoked in writing, and somebody has actually restored a backup rather than assuming one exists.
- All passwords rotated and vaulted
- Access revocation confirmed in writing
- Test restore evidenced
- 02Days 15-30
Document and baseline
The walkthrough finishes and produces a network diagram, an asset register, a license inventory, and a security baseline review covering multi-factor, patching, and mail authentication. Everything the previous provider never bothered writing down now exists in a form you can open and read.
- Documentation pack: network, assets, licenses
- Security baseline review with findings
- First monthly service report
- 03Days 31-60
Fix the inherited backlog
Every move uncovers deferred maintenance somebody has been avoiding: servers well behind on patches, accounts belonging to people who left in 2023, warranties that expired without anyone noticing, and a backup job that has been failing silently for months. All of it goes onto an agreed priority list, and the recurring problems get root-cause fixes rather than the same workaround applied for the fifteenth time.
- Inherited-issues backlog worked to an agreed priority list
- Dormant accounts removed, patching brought current
- 04Days 61-90
Review and plan forward
The first quarterly review covers what the transition found, what has been fixed since, what the numbers actually say, and a twelve-month plan covering renewals, replacements, and improvements. This is precisely the meeting your previous provider quietly stopped holding.
- First quarterly review held
- 12-month IT plan delivered in writing
How a provider switch actually runs, in four phases.
- 1
Audit and transition plan
Week 1
The incoming provider works the credentials and access checklist against your actual environment: what exists, who currently holds it, and what is missing entirely. Meanwhile you read your contract for the notice terms. What comes out is a written transition plan with names and dates on it, produced before a word of notice is served.
- 2
Serve notice and recover access
Weeks 1-2
Notice goes to the outgoing provider in whatever form the contract demands, quoting the exit assistance clause. Credential recovery starts the same day: tenant ownership, the domain transfer, mapping the licensing, and a formal documentation request. Providers who cooperate hand things over. Providers who do not get routed around.
- 3
Parallel run and cutover
2 weeks
New monitoring and a new help desk go live beside the existing service. Once that is stable, cutover happens at a quiet window: the support contact changes, credentials rotate, the old remote access agents come off every machine, and the revocation is confirmed in writing. Zero downtime is how it is designed, not something anybody is hoping for.
- 4
Stabilize, document, review
Days 15-90
Documentation rebuilt, a backup genuinely restored as a test, the inherited backlog worked through, the first monthly report at day thirty and the first quarterly review by day ninety with a twelve-month plan attached. The move is finished when things are measurably better, not on the date the old contract expired.
What to do when the outgoing provider goes quiet or simply refuses.
A minority of providers take notice badly. Calls stop being returned, handover requests go unanswered, or access is held back until an invoice dispute resolves their way. It is alarming to be on the receiving end and it is almost always survivable, because very little of what they hold cannot be recovered another way.
- Put every request in writing with a deadline attached, citing the exit or data return clause in your agreement. A dated paper trail changes behavior all by itself, before anybody involves a lawyer.
- Take tenant control back through Microsoft directly. Where a global administrator account already exists in your name, use it to remove theirs. Where none does, Microsoft has a documented ownership process built for exactly this situation, and it takes days rather than months.
- Transfer the domain at the registrar level using your business formation documents to prove ownership. Registrars deal with unresponsive third parties routinely.
- Where recovering something takes longer than rebuilding it, rebuild it. A firewall whose password nobody will surrender gets factory reset and reconfigured in a single evening.
- Rotate every password as each service comes back and keep a log of when. The objective is a clean, dated end to the old access, not an argument that runs for six months.
The questions every business asks before moving.
The switching and evaluation library.
Recovering the Microsoft tenant
For most US businesses the Microsoft 365 tenant is the crown jewels of the handover. These pages cover taking it back and running it properly afterward.
- Tenant takeover from a previous partnerRecovering Global Admin, CSP billing, and delegated access from an old provider, cooperatively or not.
- Microsoft 365 tenant managementWhat good ongoing tenant operations look like once the takeover is complete.
- Tenant security baselineThe hardening pass every inherited tenant needs, because the last provider rarely did it.
Audit what you are inheriting
This is the natural moment to establish what the last provider left behind. These turn a general unease into a written list of findings.
Where you might land next
The contract shapes switchers typically move into, depending on how much of IT you want off your desk.
What the new arrangement could look like.
Take the free audit first and decide once you can see the findings.
Tell us what is actually frustrating you about the current arrangement. We will run the credentials checklist against your environment and put the findings in writing. Where the right answer turns out to be staying and renegotiating, you will hear that. Where it is moving, you will be holding the plan before you serve notice.
Related Services
Explore more solutions that work great with this service
Tenant Takeover
Take control back from a previous partner
Learn moreM365 Tenant Management
Your tenant run properly, end to end
Learn moreTenant Security Baseline
Documented controls mapped to CIS
Learn moreManaged IT Services
Complete outsourced IT department
Learn moreIT AMC USA
Annual maintenance contracts for IT infrastructure
Learn more