You’ve chosen a new IT provider. The contract is signed. The start date is agreed, and everyone is ready to move on with IT provider offboarding.
Then someone from your new provider asks “Can you send us your IT documentation?”
And then, “Who controls your domains? Where are your SSL certificates? Do you have the administrator passwords? Can we see the recent support history? Who manages your Microsoft 365 licences?”
Suddenly, changing IT providers feels rather more complicated than it did when you made the decision.
The technology itself might not have changed. But the knowledge and access needed to manage it may have been sitting with one company for years.
Changing IT providers can also feel like ending a relationship, particularly if you’ve worked with the same provider for a long time. But businesses grow, requirements change and sometimes a provider that was once the right fit is no longer the right fit for where your business is heading. Moving to a new provider is a legitimate business decision, and the process shouldn’t be made unnecessarily difficult because of it.
A good IT provider should make that transition as straightforward as possible.
In this article, we’ll look at what a good IT provider offboarding process should cover, including documentation, administrator access, domains and SSL certificates, licences and subscriptions, support history, backups, third-party suppliers and ongoing projects.
Unfortunately, that isn’t always what businesses experience.
So, if you’re thinking about changing IT providers, what should you actually expect to receive from your old one during offboarding?
Your IT Provider Shouldn’t Be The Only One Who Knows How Your IT Works
One of the biggest problems with a poor handover during IT provider offboarding isn’t necessarily missing passwords. It’s missing knowledge.
An IT provider may have spent years learning how your systems fit together: which server does what, where your backups go, which suppliers you use, which problems have happened before and which projects are already planned.
If none of that information makes its way across, your new provider is effectively starting from the beginning.
Not only is that frustrating for everyone, but it can also create unnecessary risk.
After all, it’s something with a few legalities behind it. The Information Commissioner’s Office (ICO) recommends organisations maintain appropriate access controls, keep records of privileged accounts and have processes for removing access when people or third parties no longer need it. The National Cyber Security Centre (NCSC) similarly recommends having clear joiner, mover and leaver processes and ensuring third-party access can be revoked when it’s no longer required.
So a change of IT provider is, in effect, a very large version of that same principle.
You need to know who has access, what they have access to and how that access will change when responsibility moves elsewhere.
So, What Should Actually Be Handed Over?
There’s no universal handover pack that looks exactly the same for every business. A five-person company with Microsoft 365 and a cloud-based phone system will have very different requirements from a 200-user organisation with servers, multiple sites and specialist applications.
But there are some areas that should always be considered.
IT documentation
Your new provider needs enough information to understand the environment they are taking over. That might include:
- Network diagrams
- Server and device information
- User and administrator accounts
- Microsoft 365 or other cloud environment details
- Firewall and networking information
- Backup configuration
- Important applications and integrations
- Supplier details
- Existing IT policies and procedures
- Technical notes about unusual or business-critical systems
Some providers use platforms such as IT Glue to store this information. But the particular software doesn’t matter nearly as much as the principle.
The information your new provider needs to support your business should not disappear simply because you have changed suppliers.
It’s also worth remembering that documentation isn’t just useful when it comes to IT provider offboarding. It becomes particularly valuable when something goes wrong, a key member of staff leaves or you need to make a major change to your infrastructure.
Passwords and administrator access
This is one of the areas where a handover needs to be handled carefully. Your new provider may need access to things such as:
- Microsoft 365
- Network equipment
- Firewalls
- Servers
- Backup systems
- Domain registrars
- Website hosting
- Security platforms
- Cloud services
- Other third-party applications
But that doesn’t mean your old provider should simply email a spreadsheet containing every password they have.
In fact, that’s exactly the sort of approach good security practices are designed to avoid.
The NCSC recommends using secure password-management approaches and protecting privileged accounts because administrator credentials can provide extensive access across an organisation.
This means that a better handover might involve creating accounts for your new provider, transferring ownership of relevant services and securely sharing credentials where necessary. And once the transition is complete, the outgoing provider’s access should be removed.
That last part is important.
Changing IT providers isn’t just about giving the new company access; it’s also about removing the old company’s access.
Domains and DNS
This is one of those areas you don’t think about until something stops working. Your business might have several domains, subdomains and DNS records controlling everything from your website to email and third-party services.
The outgoing provider should be able to tell you:
- Which domains you own
- Who the registrar is
- Who controls the registrar account
- Where DNS is managed
- What important DNS records are in place
- Whether there are any domain renewals approaching
For .uk domains, Nominet’s current transfer policy confirms that registrants can move between registrars and provides a formal process for doing so, including obtaining a Transfer Authorisation Code from the losing registrar.
The important point for your business is simple: Your domain should belong to your business, not become something you’re effectively locked out of because your IT provider manages it.
You should know who your registrar is and how control can be transferred.
SSL certificates
SSL certificates are another small detail that can become a very large problem. They’re responsible for helping secure connections to websites and online services. If a certificate expires or isn’t renewed correctly, you can suddenly be confronted with browser warnings or a website that doesn’t behave as expected.
Your handover should therefore identify:
- Which SSL certificates are in use
- What domains they cover
- Who issues them
- Who manages them
- When they expire
- How they are renewed
The UK Government’s guidance on domain security also recommends monitoring how SSL certificates are issued and that you pay attention to DNS records and certificate-related controls. You don’t want your new provider discovering six months into the relationship that an important certificate is still being managed through an account nobody knew existed.
Licences and subscriptions
Your IT provider may manage dozens of subscriptions without you necessarily seeing all of them. That could include:
- Microsoft 365 licences
- Antivirus and endpoint protection
- Backup software
- Security services
- Remote monitoring tools
- Cloud services
- Other specialist software
A proper handover should make clear what you’re paying for, who owns the subscription, when it renews and who currently manages it.
This is particularly important where the provider has purchased or provisioned services on your behalf.
The question isn’t simply: “What software do we have?” It’s “Who owns it, who pays for it, who has access to it and what happens to it when the provider changes?”
That distinction can save a lot of confusion during IT provider offboarding.
Your support and ticket history
Technical documentation tells your new provider what your environment looks like. Your support history tells them what it’s actually been like to run.
That’s useful information.
Perhaps a particular user’s laptop has had the same problem three times, or the office Wi-Fi has been unreliable at certain times of day. Maybe there’s an ongoing issue with a line, application or server.
Without that history, your new provider may spend time rediscovering problems you’ve already paid someone to investigate.
Where appropriate, the IT provider offboarding should therefore cover:
- Recent support tickets
- Recurring issues
- Known problems
- Outstanding requests
- Significant incidents
- Current projects
- Planned work
The objective isn’t to give your new IT company years of irrelevant ticket history, it’s to give them enough context to understand what has been happening and what still needs attention.
Backups and disaster recovery
This one deserves particular attention.
If your provider has been responsible for backups, your new provider needs to know what is being backed up, where it is stored and how it can be recovered.
That might include:
- What data is backed up
- How frequently backups run
- Where they’re stored
- How long they’re retained
- Who has access
- Whether backups are encrypted
- When they were last successfully tested
- Whether there are any known backup failures
The NCSC’s current guidance for small and medium-sized organisations makes an important point: having a backup is only part of the job. Organisations also need to know how to restore it and check that it contains the important data they expect.
That makes a provider change a useful opportunity to ask a simple question: “If we needed to restore our systems tomorrow, could our new provider actually do it?”
If the answer isn’t immediately clear, that’s something worth resolving before the IT provider offboarding is complete.
Third-party suppliers
Your IT provider probably doesn’t manage every piece of technology your business uses. They may, however, be the person who knows who does.
That could include:
- Internet providers
- Telephone providers
- Website hosting companies
- Domain registrars
- Software suppliers
- Cybersecurity providers
- Hardware suppliers
- Cloud platforms
A handover should identify these relationships where they’re relevant to the IT environment. Otherwise, your new provider may know that something isn’t working but have no idea who to contact about it.
What’s currently in progress?
There’s another piece of information that’s easily missed: what was supposed to happen next?
For example: Your business might have been planning to replace an ageing server. There might be a proposal to move to a new Microsoft 365 setup. A security improvement might have been recommended but not yet implemented. A number of laptops might be due for replacement.
None of these things necessarily appear in a list of passwords and devices. But they’re extremely useful for the new provider to know.
A good handover doesn’t just explain where you are; it gives some indication of where you were heading.
What About Information Held by the Old Provider?
This is where it’s important to distinguish between your business information and the provider’s internal information. Remember that not every document, internal note or piece of intellectual property created by an IT company automatically becomes part of a handover.
What should be transferred depends on your contract, the services provided and what information your business needs to continue operating.
Where personal data is involved, there are also data protection considerations. The ICO’s guidance says contracts with processors should address what happens to personal information at the end of the relationship, including requirements to delete or return personal information where appropriate.
So a good IT provider offboarding process isn’t simply giving the new IT company everything you’ve got. It’s a controlled process that establishes what needs to be transferred, what needs to be retained, what needs to be deleted and who should have access to what.
Good IT Offboarding Shouldn’t Feel Like a Punishment
Changing IT providers doesn’t mean the outgoing provider has done something wrong. Sometimes your business has grown and needs a different service, your requirements have changed, or the relationship just isn’t the right fit anymore.
Whatever the reason, you shouldn’t be made to feel trapped because leaving is difficult.
At Tristar, when we offboard clients, our aim is to make the transition as helpful and straightforward as possible.
That means working through the practical details, providing the information the incoming provider needs and helping avoid unnecessary disruption.
Because ultimately, the client is the one who has to live with the consequences of a poor handover.
Changing IT Providers? Use This Checklist
Before your old IT provider finishes their involvement, make sure you’ve established:
Documentation
- Do we have the information needed to understand our IT environment?
- Do we know where important documentation is stored?
- Are there network, server and infrastructure details available?
Access
- Do we know who has administrator access?
- Have the necessary accounts been transferred or created?
- Will the outgoing provider’s access be removed?
Domains and website
- Who controls our domains?
- Where is DNS managed?
- Who manages our SSL certificates?
- Are any renewals coming up?
Licensing
- What licences and subscriptions are active?
- Who owns each one?
- When do they renew?
- Are any services tied to the outgoing provider’s account?
Support
- Does the new provider have relevant ticket history?
- Are there known recurring problems?
- Are there any outstanding support issues?
Backups
- What is being backed up?
- Where are the backups?
- When were they last tested?
- Can the new provider access and restore them?
Projects
- What work is currently in progress?
- What recommendations or projects were planned?
- Are there any important upcoming deadlines?
If you can answer those questions, your new IT provider has a much better chance of taking over without spending the first few months simply trying to work out how everything fits together.
Are you changing IT providers?
Our Free Review Call, you’ll get clarity about whether Tristar Tech Solutions is the right fit for your needs.
Book your free IT Review– we’ll take it from there.
Call: 01707 378455
Email: sales@tristartechsolutions.co.uk
Frequently Asked Questions
What should my IT provider hand over when I leave? You should receive the information your new provider needs to manage your IT, including documentation, access details, domains, licences, backups and relevant support history.
Who owns my domains and licences? Your business should retain ownership of important services such as domains and business-critical licences. Your IT provider may manage them, but you should know who owns and controls them.
Should my new provider get my old support history? Where relevant, yes. Recent tickets, recurring issues, outstanding problems and ongoing projects can help your new provider understand your environment much faster.
What happens to my old provider’s access? Once the handover is complete, the outgoing provider’s unnecessary access should be removed and privileged credentials reviewed or changed where appropriate.
How do I know if my IT is properly documented? You should be able to identify your key systems, accounts, infrastructure, backups and suppliers without relying on your IT provider to explain everything from memory.