Changing IT providers is not an ordinary supplier switch. Email, domains, firewalls, backups and telephony have to keep running while responsibilities and administrative access change hands. If access is missing or nobody can say who owns an account, the handover can quickly turn into an outage.
The first objective is therefore not to disable every old account as early as possible. You need to establish which systems are in scope, who controls them and whether the new provider can actually work with them. This checklist is intended for managing directors and internal IT owners preparing that transition.
Establish the real scope before giving notice
Start with the contracts and records you already have. Which sites, legal entities and services are covered by the current provider? Which licences, circuits or subscriptions are held in its name? Notice periods and contractual handover duties depend on the actual agreements and require their own review; this article is not legal advice.
Then consider operations. Record which systems are essential to production, sales, communications or accounting. Include planned office moves, renewals and major technical changes. Combining a provider change with a site migration or server replacement creates dependencies that can usually be avoided.
The IT handover checklist
- Administrative identities: Identify personal administrator accounts, roles, multifactor methods and emergency access. The business needs to know who may access critical systems. A shared everyday account is not a sound substitute for individually assigned access.
- Domains, DNS and certificates: Confirm the registrar account holder, who can change DNS records and who receives renewal or security notices. A company domain should not depend on a former provider keeping a personal account active.
- Microsoft 365 and Entra ID: Include the tenant, verified domains, administrative roles, licences, billing and emergency access. Microsoft documents separate, securely stored emergency accounts for exceptional situations; the implementation still has to fit the organisation.
- Firewall, VPN, switching and Wi-Fi: Record devices, controllers, management addresses, configuration backups, site links and network separation. An inventory alone does not explain how the environment works as a system.
- Servers, virtualisation and storage: Capture hosts, virtual machines, roles, dependencies, maintenance state and configuration backups. Also establish which services must return first after a restart or outage.
- Backup and recovery: Clarify what is backed up, how long copies are retained and who monitors failed jobs. A green dashboard is not enough; there must be a workable recovery path. Germany's BSI also treats configuration data from routers, switches and other IT components as information that may need protection.
- Endpoints and management: Device inventory, MDM or RMM, endpoint protection, local administrator rights and recovery keys must be under company control. Check whether devices have to leave an old management platform before joining the new one.
- Telephony and numbers: Treat providers, contract holders, number ranges, porting data, the phone system, routing and fallback destinations as a separate handover area. Credentials without an understanding of the current call flow are rarely sufficient.
- Vendor and supplier accounts: Support portals, warranties, licences, rental or leasing agreements and purchasing accounts must not remain tied to a former provider's personal address.
- Documentation and open work: Network diagrams, inventory, responsibilities, incidents, projects, renewals and known gaps need a current status. Each open item should have an impact, an owner and a next date.
This is not a checklist to sign off without evidence. Every item needs an owner and a state that can be verified. A PDF containing account names is of little value if the login is blocked or the second factor is still registered to somebody else's device.
Change access in a controlled order
Begin with a read-only inventory. Confirm company ownership, new personal administrator accounts and the intended emergency paths. Test the new access in practice before taking configuration backups and reviewing dependencies.
Old accounts can then be disabled or stripped of privileges according to the handover plan. The timing matters: disabling access too early can affect operations, while leaving it active too long creates unnecessary exposure. Record a responsible person and a specific date for each change.
Passwords, recovery codes and private keys do not belong in unprotected emails or general handover folders. The record should say who controls an account and where the approved transfer path is; the secret itself stays in a system designed to protect it.
What a complete handover looks like
A handover is not complete just because files have been sent. It is complete when the company controls its critical accounts, the new provider can genuinely administer the systems and the important operating paths have been checked.
That normally includes working administrative access, usable configuration and data backups, clear ownership of network and telephony systems, and a list of outstanding work. Access held by the former provider is then removed where it is no longer required. Any temporary exception should be explicit as well.
When access or documentation is missing
Missing records do not automatically mean that everything must be rebuilt at once. Start by identifying the installed systems and their dependencies: which services work, which accounts are available and where is there an immediate operational risk? Critical gaps come before cosmetic documentation issues.
Avoid forcing high-risk changes into the middle of the transition. It may be safer to keep a stable service running, create a new administrative path and retire the old structure afterwards. A responsible takeover states these limits instead of promising an instant, disruption-free switch.
Take over IT operations with control
A good provider change does not end with a ZIP archive of PDFs. It ends with company control of its accounts, a new technical provider who can work, and clearly assigned outstanding items.
JITIS helps businesses in Regensburg and Eastern Bavaria assess the existing environment and arrange the transition into manageable steps. The starting point is our IT support for SMEs. You can also read about Microsoft cloud services, IT and network infrastructure, business telephony and network monitoring and documentation.


