1. Confirm ownership of your technology accounts
Your business should know who controls the registrar and DNS, Microsoft 365 or Google Workspace tenant, cloud subscriptions, backup platforms, firewall administration, line-of-business applications and other critical services. A provider may administer these systems, but the transition should preserve business ownership and continuity.
2. Build an access and documentation inventory
The incoming MSP needs enough information to assume responsibility safely. Inventory administrative accounts, network equipment, servers, endpoints, vendors, licenses, backup jobs, security tools, ISP information and key application dependencies. Do not rely on one undocumented password handoff.
3. Plan Microsoft 365 and identity carefully
Confirm global administrator access, MFA methods, security defaults or Conditional Access, DNS records, shared mailboxes, distribution groups, applications and third-party integrations. Identity is central to the transition because many other services depend on it.
4. Protect backup continuity
Verify what is backed up, where copies are stored, who owns the backup account, retention settings and whether recent restore tests exist. Do not remove an old backup platform until the replacement is configured and recovery has been validated.
5. Coordinate security-tool replacement
Endpoint agents, email security, monitoring and other controls should be transitioned in a defined sequence. Removing the outgoing provider's tooling too early can create a coverage gap; leaving overlapping agents indefinitely can create conflicts. The two sides should agree on timing.
6. Define the cutover date and escalation path
Employees need to know when the new help desk becomes responsible and how to request support. Critical vendors and business owners should know who to contact during the transition if an issue affects access, email, connectivity or a key application.
7. Complete the offboarding checklist
- Receive current network and system documentation.
- Transfer or validate administrative credentials.
- Confirm domains, DNS and cloud accounts remain under company control.
- Export relevant configuration and asset information.
- Transition endpoint, monitoring and security agents.
- Confirm backups and recovery ownership.
- Remove former-provider access after the transition is verified.
- Document any unresolved vendor or licensing issues.
8. Change privileged credentials after handoff
Once the new provider has verified access and operations are stable, rotate shared and privileged credentials where appropriate, review administrative roles and remove accounts that are no longer required. This closes the transition cleanly.
What should you ask the new MSP?
Ask who manages the transition, what information they need, how they handle missing documentation, how they avoid security gaps, what support users receive during cutover and how they verify that backups, monitoring and identity controls are operating after onboarding.
Related: Co-managed vs fully outsourced IT and managed IT vs in-house IT.
Planning an MSP change?
Outsource IT Canada can review your current environment and help map the responsibilities, access and transition steps before a provider change.