1. Confirm business and technical contacts
Identify the executive sponsor, day-to-day contact, billing contact and people authorized to approve access or significant changes. Document escalation contacts for urgent incidents and after-hours decisions.
2. Inventory users, devices and locations
Create a current inventory of employees, workstations, laptops, servers, mobile devices, printers, network equipment and office locations. Match devices to users where possible and identify equipment that is unsupported, unknown or no longer required.
3. Establish administrative access
Validate access to Microsoft 365 or Google Workspace, domain registrar, DNS, cloud subscriptions, firewalls, wireless systems, backup platforms, line-of-business applications and other critical services. Use named administrative accounts and MFA where supported instead of relying on undocumented shared credentials.
4. Review Microsoft 365 and identity
Review administrator roles, MFA, Conditional Access or security defaults, shared mailboxes, distribution groups, licensing, external forwarding, legacy authentication and important third-party integrations. Identity configuration affects many other security and support workflows.
5. Document the network
Record internet providers, public IP information, firewall configuration, switches, wireless networks, VLANs, VPNs and important internal services. The MSP should know how users and systems connect before troubleshooting or changing the environment.
6. Verify backups and recovery
Document what is backed up, where copies are stored, retention periods, ownership of backup accounts and recent restore-test results. A successful backup job is not the same as verified recovery. Identify gaps before removing an existing backup system.
7. Establish the cybersecurity baseline
Review endpoint protection, EDR, email security, MFA, patching, privileged access, vulnerability exposure and security monitoring. Record existing controls before replacing tools so the transition does not create a temporary protection gap.
8. Map critical applications and vendors
List accounting, CRM, practice-management, industry-specific and other important applications. Record vendor contacts, support agreements, renewal information and dependencies. The MSP should know which problems require coordination with a third party.
9. Deploy management and support tools
Install the agreed monitoring, remote management, endpoint security and support agents. Confirm device reporting and policy application before considering deployment complete. Remove obsolete provider tools only after replacement coverage is verified.
10. Define help desk and escalation procedures
Tell employees how to request support, what information to provide and how urgent incidents are handled. Define who can approve purchases, account changes and access requests. Clear support procedures reduce confusion during the first weeks of service.
11. Build and validate documentation
- User and device inventory
- Network and infrastructure overview
- Cloud and Microsoft 365 administration
- Backup and recovery configuration
- Security stack and monitoring responsibilities
- Critical vendors and applications
- Escalation contacts and approval rules
- Known technical risks and remediation priorities
12. Complete a post-onboarding review
After discovery and deployment, review findings with the business. Separate urgent risks from longer-term improvements, agree on priorities and document any systems outside the managed scope. Onboarding should finish with a shared understanding of the environment, not simply a collection of installed agents.
Switching from another provider?
If onboarding is part of an MSP change, use this checklist together with our switching managed IT providers checklist. You can also compare co-managed and fully outsourced IT.
Planning managed IT onboarding?
Outsource IT Canada can review your environment, identify transition dependencies and build a practical onboarding plan.