Switching IT providers without losing access to your own systems

Most provider changes go fine. The ones that go badly go badly in one specific way: the business discovers, after giving notice, that it does not actually control its own systems.

About this piece

  • Guide
  • Managed IT
  • Written by Nicholas Backwell · Founder, Redsilicon
  • Updated 2026-08-24

The domain is registered in the provider’s account. The Microsoft 365 tenant was created under their partner relationship. The firewall admin password is in their password manager and nowhere else. None of this is usually malice. It is what happens when nobody ever asked.

The order of operations matters. Establish what you control before you announce anything.

The short version

  • Find out what you control before you give notice, not after.
  • Domain registration and DNS are the two things that must be yours. Everything else is recoverable.
  • Create your own administrator account in every system now, while relations are good.
  • Ask for documentation as a normal request, not as part of an exit.
  • Overlap the two providers rather than switching on a date.

Step one: find out what you actually own

Do this quietly, before any conversation about leaving. None of it is unreasonable to ask for at any time, and asking now avoids it looking like a manoeuvre.

Your domain name. Log into your registrar. If you cannot, that is finding number one. Check who the registrant is. If the registrant is your provider rather than your business, the domain is legally theirs, and that is a much bigger problem than a password. Fix it now.

DNS. Whoever controls DNS controls where your website and your email go. It should be in an account you own.

Microsoft 365 or Google Workspace. Confirm you hold at least one global administrator account, with credentials only your business has, and MFA registered to a device or method you control. Not your provider’s device.

Firewall and network equipment. Admin credentials for the firewall, switches, wireless controller and any VPN. These are frequently in a provider’s system exclusively.

Backup system. Where backups go, on whose account, and whether you can initiate a restore without the provider.

Line-of-business software. Vendor portal logins, licence keys, support contract numbers. Usually held by whoever set the system up.

Website and hosting. Registrar, host, and WordPress or CMS admin. Often three different companies and three sets of credentials.

Licences. Whose name are your Microsoft licences in? If they sit under the provider’s agreement, moving them is a process with its own timeline.

This is a similar exercise to the first week after an internal IT person leaves, and for the same reason. Access is the thing that becomes urgent.

Step two: fix the two that are not recoverable

Everything on that list can be recovered with effort, with two exceptions worth treating differently.

Domain registration. If the domain is registered to your provider rather than to you, sort it out before anything else. Transfer the registration into an account in your business’s name, with your billing details, and put the renewal on a card that will not expire. A lapsed or hostage domain takes your email and your website down together, and it is the one problem that can genuinely stop a business.

DNS control. Move DNS to an account you own, or at minimum ensure you have full access to wherever it lives. You can do this without changing any records, so nothing breaks.

Both of these are undramatic and take an afternoon. Do them now, whether or not you are switching.

Step three: ask for the documentation

Frame it as normal governance rather than as an exit, because it is. Any good provider will hand it over without comment. Reluctance is itself informative.

Ask for:

  • A current network diagram
  • An asset list: every device, its age, its warranty status, its role
  • A list of every system, what it does, and who the vendor is
  • Backup configuration: what is backed up, where to, on what schedule, retention
  • Recovery documentation: the actual steps to restore, not a statement that backups exist
  • Licence inventory and renewal dates
  • Known issues and outstanding recommendations

That last one is worth asking for explicitly. A provider will usually have a list of things they have recommended and you have not done. It is useful for you and it is fair to them.

If a provider cannot produce a network diagram and an asset list, that is worth knowing regardless of whether you leave. It is one of the clearer signs the relationship has run its course.

Step four: read the contract

Before giving notice, check three things.

Notice period. Often 30, 60 or 90 days. Some agreements auto-renew annually with a notice window, and missing the window costs you another year.

Offboarding terms. Whether handover assistance is included, chargeable, or unaddressed. Unaddressed is common and means you are relying on goodwill.

Equipment and licence ownership. Whether hardware you have been paying for monthly is yours at the end or theirs. Firewalls and switches provided as part of a service frequently belong to the provider, and you may need to buy or replace them.

Step five: overlap rather than switch

The clean-break switch on a fixed date is where problems concentrate. A period where both providers are engaged is worth paying for.

A sequence that works:

Weeks one to two. New provider does a discovery review. They document what exists, find what the incumbent’s documentation missed, and produce a transition plan with a list of things they intend to change and why.

Weeks three to four. New provider gets access alongside the incumbent. Monitoring and management tools deployed. Nothing changed yet.

Weeks five to six. New provider takes the helpdesk. Users start calling them. The incumbent remains reachable for the things only they know.

Weeks seven to eight. Administrative access transitions properly. Every credential the incumbent held is rotated, because a password that has been in someone else’s password manager is no longer a secret, no matter how amicably you parted.

Week nine onward. Incumbent’s access removed entirely, and verified as removed. This means checking, not being told.

That rotation and verification step is the one most often skipped, and it is not about distrust. A departing provider’s staff may have left, their tools may have logged credentials, and their own systems are outside your control. Rotate everything.

Step six: leave well

Two reasons this matters beyond politeness.

The practical one: you will need something from them in month three. A licence detail, a vendor contact, the reason something was configured a particular way. A relationship that ended reasonably gets you an answer to that email.

The other: Durham is not a big market. Word travels among providers, suppliers and other businesses. Handling a departure professionally costs nothing.

So: give proper notice in writing, pay the final invoice, do not litigate old grievances during the handover, and say thank you if any of it was good. If it genuinely went badly, a factual review is fair. A campaign is not.

The red flags that mean move faster

A few responses should change your timeline rather than your approach.

Refusing to provide documentation. There is no legitimate version of this. Your network diagram is a description of your own business.

Refusing to hand over administrative access to systems you pay for.

Claiming the domain is theirs. Deal with this immediately and get advice if they hold firm.

Demanding payment to release credentials not covered by the contract.

Suddenly discovering urgent work that requires a new commitment, right after you raise the question of leaving.

None of these are common. All of them mean you stop being gradual and start being methodical, with everything in writing.

What this means for your business

A 30-person business in Ajax leaving a provider it has used for eight years usually finds two or three surprises in the access audit. That is normal and it is why the audit comes first.

A business whose provider set up their Microsoft 365 tenant originally should expect the licence transfer to be the fiddliest part, with its own lead time.

A business in a regulated field, such as a clinic, should add its software vendors to the handover list explicitly, since those relationships are often held by the provider and the vendors have their own authorisation processes.

Anyone who cannot log into their own domain registrar right now should stop reading and go check.

What to do about it

  1. Try to log into your domain registrar today. If you cannot, that is your first task regardless of everything else.
  2. Build the access audit list and work through it quietly.
  3. Create your own global admin account in Microsoft 365 with MFA on a method you control.
  4. Ask for documentation as a normal request, before any conversation about leaving.
  5. Read your contract for notice period, offboarding terms and equipment ownership.
  6. Plan an overlap, not a switch date.
  7. Rotate every credential at the end, and verify old access is gone.

Our own takeover process starts with an environment assessment and access re-keying, in that order, because the assessment is what tells you what the re-keying has to cover. IT consulting is the same work when you want the review without changing provider.

Want this scoped for your site?

Tell us the building and what you’re trying to achieve. We’ll tell you what it takes, and whether you actually need it.

Before you call

Can we get a review without committing to switch?

Yes, and it is the sensible way round. A discovery review that tells you your current setup is fine is a good outcome, and you keep the documentation either way.

Our provider is fine, we are just curious what we would need.

Then do steps one to four and stop. Owning your domain, holding your own admin credentials, and having current documentation are worth having with a provider you intend to keep. Most businesses that do this find one thing worth fixing.

How long does a switch take?

Six to ten weeks for a smooth one, driven mostly by notice periods and licence transfers rather than technical work. Faster is possible and tends to leave loose ends.

What if we have no provider at all right now?

Then the access audit is still the first step, because whoever set things up originally may still hold credentials. That happens more often than you would expect.

\n
\n \n