Skip to main content
Cost & Provider Decisions8 min read

How to Switch Managed IT Providers Without Losing Data or Sleep

"A practical, week-by-week migration plan for small businesses leaving an underperforming IT provider - including the credentials you must demand and the legal protections that work in your favour."

Author

Lior Refael

Published

Apr 23, 2026

Back to Articles

Why this is the most stressful IT decision SMBs make

Switching managed IT providers is genuinely scary because the outgoing provider holds the keys to everything: your domain, your email, your backups, your cloud accounts. Stories of providers refusing handover, holding data hostage, or "accidentally" wiping configurations are common - and they keep small businesses stuck with bad providers far longer than they should be.

The good news: the law (in the EU, Israel, and most jurisdictions) is on your side, and a clean handover is entirely doable in 4-6 weeks if you plan it properly. This article walks through that plan.

What you actually own (and what you don't)

The first question to settle is whether your Microsoft 365 tenant is yours. It should be: a provider normally holds delegated administrative access to your tenant, which can be granted and revoked[1], and you should be able to see and control the Global Administrator accounts yourself[2]. If instead your licences sit inside the provider's own tenant, your data lives somewhere you do not control and moving it is a tenant-to-tenant migration rather than a handover[3].

Before you start a switch, get clear on ownership. In most setups for a small business, you own:

  • Your domain name (registered in your business's name)
  • Your Microsoft 365 or Google Workspace tenant (paid for in your business's name)
  • Your data inside those tenants (email, files, calendars)
  • Any business accounts paid by your business (Acronis, 1Password, etc.)

Your provider should be administering these - not owning them. If your domain is registered in their company name, or your M365 tenant is on their billing, that is a structural problem you need to fix immediately, regardless of whether you switch.

This is a service transition, and there is a standard for it

Changing provider is not an IT chore; it is a service transition, and the ITIL 4 framework has a defined practice for exactly this - service transition covers moving a service between providers or environments with continuity of knowledge, assets and support[4]. Two of its principles are worth borrowing even if you never read the rest:

  • Knowledge transfer is a deliverable, not a courtesy. Documentation, credentials, network diagrams, vendor contacts and the list of known quirks are artefacts your outgoing provider owes you. Put them in the plan with dates.
  • Run a period of overlap. ITIL calls it early life support. In practice: the new provider is live and the old contract has not been terminated, for two to four weeks, so anything undiscovered surfaces while someone who knows the history is still reachable.

The four-week plan below is that practice, sized for a business of 10 to 50 people.

The 4-week switch plan

Week 1: Audit and document

Before notifying your current provider, document everything you can on your own:

  • Every business account and where the credentials live
  • Every domain you own and where it's registered
  • Every device that's managed (laptops, phones, servers)
  • Every backup that's running and where backups are stored
  • Every recurring invoice you pay for IT-related services

Your new provider will work from this list.

Week 2: Notify and request handover

Notify your current provider in writing. Reference your contract's termination clause (most managed IT contracts require 30-60 days notice; if yours doesn't say, 30 days is the legal default in most EU jurisdictions). In the same notice, formally request:

  • All admin credentials for every system they manage
  • All API keys, certificates, and recovery codes
  • All documentation and runbooks
  • Confirmation of where backups are stored and how to access them
  • A list of any third-party services they manage on your behalf

Under GDPR (and Israeli privacy law equivalents), you have a legal right to your data. A provider refusing to hand it over isn't being awkward. It's breaking the law.

Week 3: Parallel run

This is the safest pattern: have both providers active for one week. Your new provider takes over administration of email, devices, and backups. Your old provider remains active in case anything was missed. Don't skip this week.

Week 4: Cutover and decommission

Once the new provider has confirmed everything is migrated and tested, formally decommission the old provider:

  • Remove their admin access from every system
  • Rotate any shared credentials
  • Confirm in writing that they no longer hold any of your data
  • Final invoice and contract closure

The handover checklist: what to demand, and what it costs you to skip

Table of six handover deliverables to demand from an outgoing IT provider, what good looks like for each, and the risk of skipping it.
What you are asking forWhat good looks likeRisk if you skip it
Domain registrar accessRegistered in your business name, with 2FA you controlYour provider can move or lose the domain your mail depends on
Global Administrator accountsYou hold them; the provider holds delegated accessYou cannot revoke anyone or prove who has access
Credential inventory in writingEvery account, exported to your password managerSystems surface months later with nobody able to sign in
Backup configuration and a test restoreA restore proven before cutover, not describedYou discover the backup was never running when you need it
Written documentation and vendor contactsDiagrams, quirks, licence and support contractsEvery future change starts with reverse engineering
Confirmation that access is removedIn writing, after credentials are rotatedA former provider keeps standing access to your tenant

The handover bar we hold outgoing providers to. Ask for all six in the notification letter, with dates.

Red flags during a switch

Some behaviour from an outgoing provider goes past frustrating. Treat it as a warning:

  • Refusing to provide credentials in writing ("we'll just transfer them when needed")
  • Charging an "exit fee" that wasn't in your contract
  • Claiming they own your domain or M365 tenant
  • Disabling services or "accidentally" deleting accounts during handover
  • Slow-walking responses past your notice period

If any of these happen, document everything in writing and escalate. In the EU, your data protection authority will take complaints seriously when a provider obstructs lawful data access. Your incoming provider should also know how to handle these - that's part of why you hire them.

What a good handover looks like

A clean switch ends with:

  • You hold every admin credential, in your password manager, in your name
  • You have written documentation of how everything works
  • Your new provider has tested every critical system (email send/receive, backup restore, login from a new device)
  • The old provider has confirmed in writing they no longer have access
  • You haven't lost a single email, file, or working hour

That's the bar. It's achievable. Don't accept less.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. Granular delegated admin privileges (GDAP) for Microsoft partners (opens in a new tab)

    Microsoft Learn · 2026

    How partner administrative access to your tenant is granted, scoped and revoked.

  2. Assign admin roles in the Microsoft 365 admin center (opens in a new tab)

    Microsoft Learn · 2026

    Taking and verifying ownership of Global Administrator access during a handover.

  3. Microsoft 365 tenant-to-tenant migration (opens in a new tab)

    Microsoft Learn · 2026

    What is involved if your data sits in a provider-owned tenant and has to move.

  4. ITIL 4 service transition and change enablement practices (opens in a new tab)

    AXELOS / PeopleCert · 2025 · reporting on primary data

    Recognised framework treating provider change as a managed service transition with knowledge transfer and early life support.

  5. Regulation (EU) 2016/679 (GDPR), Article 20 - Right to data portability (opens in a new tab)

    EUR-Lex, Publications Office of the EU · 2016

    The right to receive personal data in a structured, commonly used, machine-readable format.

  6. Buy or transfer a domain in Microsoft 365 (opens in a new tab)

    Microsoft Learn · 2026

    Establishing who controls the domain, and moving it if the outgoing provider registered it.

Figures last checked 28 July 2026

Stuck with a provider that's holding you back?

Book a free 30-minute call. We'll walk you through what a clean switch would look like for your specific setup - including what to demand from your current provider.