Why this is the most stressful IT decision SMBs make
Switching managed IT providers is genuinely scary because the outgoing provider holds the keys to everything: your domain, your email, your backups, your cloud accounts. Stories of providers refusing handover, holding data hostage, or "accidentally" wiping configurations are common - and they keep small businesses stuck with bad providers far longer than they should be.
The good news: the law (in the EU, Israel, and most jurisdictions) is on your side, and a clean handover is entirely doable in 4-6 weeks if you plan it properly. This article walks through that plan.
What you actually own (and what you don't)
The first question to settle is whether your Microsoft 365 tenant is yours. It should be: a provider normally holds delegated administrative access to your tenant, which can be granted and revoked[1], and you should be able to see and control the Global Administrator accounts yourself[2]. If instead your licences sit inside the provider's own tenant, your data lives somewhere you do not control and moving it is a tenant-to-tenant migration rather than a handover[3].
Before you start a switch, get clear on ownership. In most setups for a small business, you own:
- Your domain name (registered in your business's name)
- Your Microsoft 365 or Google Workspace tenant (paid for in your business's name)
- Your data inside those tenants (email, files, calendars)
- Any business accounts paid by your business (Acronis, 1Password, etc.)
Your provider should be administering these - not owning them. If your domain is registered in their company name, or your M365 tenant is on their billing, that is a structural problem you need to fix immediately, regardless of whether you switch.
This is a service transition, and there is a standard for it
Changing provider is not an IT chore; it is a service transition, and the ITIL 4 framework has a defined practice for exactly this - service transition covers moving a service between providers or environments with continuity of knowledge, assets and support[4]. Two of its principles are worth borrowing even if you never read the rest:
- Knowledge transfer is a deliverable, not a courtesy. Documentation, credentials, network diagrams, vendor contacts and the list of known quirks are artefacts your outgoing provider owes you. Put them in the plan with dates.
- Run a period of overlap. ITIL calls it early life support. In practice: the new provider is live and the old contract has not been terminated, for two to four weeks, so anything undiscovered surfaces while someone who knows the history is still reachable.
The four-week plan below is that practice, sized for a business of 10 to 50 people.
The 4-week switch plan
Week 1: Audit and document
Before notifying your current provider, document everything you can on your own:
- Every business account and where the credentials live
- Every domain you own and where it's registered
- Every device that's managed (laptops, phones, servers)
- Every backup that's running and where backups are stored
- Every recurring invoice you pay for IT-related services
Your new provider will work from this list.
Week 2: Notify and request handover
Notify your current provider in writing. Reference your contract's termination clause (most managed IT contracts require 30-60 days notice; if yours doesn't say, 30 days is the legal default in most EU jurisdictions). In the same notice, formally request:
- All admin credentials for every system they manage
- All API keys, certificates, and recovery codes
- All documentation and runbooks
- Confirmation of where backups are stored and how to access them
- A list of any third-party services they manage on your behalf
Under GDPR (and Israeli privacy law equivalents), you have a legal right to your data. A provider refusing to hand it over isn't being awkward. It's breaking the law.
Week 3: Parallel run
This is the safest pattern: have both providers active for one week. Your new provider takes over administration of email, devices, and backups. Your old provider remains active in case anything was missed. Don't skip this week.
Week 4: Cutover and decommission
Once the new provider has confirmed everything is migrated and tested, formally decommission the old provider:
- Remove their admin access from every system
- Rotate any shared credentials
- Confirm in writing that they no longer hold any of your data
- Final invoice and contract closure
Red flags during a switch
Some behaviour from an outgoing provider goes past frustrating. Treat it as a warning:
- Refusing to provide credentials in writing ("we'll just transfer them when needed")
- Charging an "exit fee" that wasn't in your contract
- Claiming they own your domain or M365 tenant
- Disabling services or "accidentally" deleting accounts during handover
- Slow-walking responses past your notice period
If any of these happen, document everything in writing and escalate. In the EU, your data protection authority will take complaints seriously when a provider obstructs lawful data access. Your incoming provider should also know how to handle these - that's part of why you hire them.
What a good handover looks like
A clean switch ends with:
- You hold every admin credential, in your password manager, in your name
- You have written documentation of how everything works
- Your new provider has tested every critical system (email send/receive, backup restore, login from a new device)
- The old provider has confirmed in writing they no longer have access
- You haven't lost a single email, file, or working hour
That's the bar. It's achievable. Don't accept less.