Skip to main content
Cost & Provider Decisions8 min read

How to Switch Managed IT Providers Without Losing Data or Sleep

"A practical, week-by-week migration plan for small businesses leaving an underperforming IT provider - including the credentials you must demand and the legal protections that work in your favour."

Author

Lior Refael

Published

Apr 23, 2026

Back to Articles

Why this is the most stressful IT decision SMBs make

Switching managed IT providers is genuinely scary because the outgoing provider holds the keys to everything: your domain, your email, your backups, your cloud accounts. Stories of providers refusing handover, holding data hostage, or "accidentally" wiping configurations are common - and they keep small businesses stuck with bad providers far longer than they should be.

The good news: the law (in the EU, Israel, and most jurisdictions) is on your side, and a clean handover is entirely doable in 4-6 weeks if you plan it properly. This article walks through that plan.

What you actually own (and what you don't)

The first question to settle is whether your Microsoft 365 tenant is yours. It should be: a provider normally holds delegated administrative access to your tenant, which can be granted and revoked[1], and you should be able to see and control the Global Administrator accounts yourself[2]. If instead your licences sit inside the provider's own tenant, your data lives somewhere you do not control and moving it is a tenant-to-tenant migration rather than a handover[3].

Before you start a switch, get clear on ownership. In most setups for a small business, you own:

  • Your domain name (registered in your business's name)
  • Your Microsoft 365 or Google Workspace tenant (paid for in your business's name)
  • Your data inside those tenants (email, files, calendars)
  • Any business accounts paid by your business (Acronis, 1Password, etc.)

Your provider should be administering these - not owning them. If your domain is registered in their company name, or your M365 tenant is on their billing, that is a structural problem you need to fix immediately, regardless of whether you switch.

This is a service transition, and there is a standard for it

Changing provider is not an IT chore; it is a service transition, and the ITIL 4 framework has a defined practice for exactly this - service transition covers moving a service between providers or environments with continuity of knowledge, assets and support[4]. Two of its principles are worth borrowing even if you never read the rest:

  • Knowledge transfer is a deliverable, not a courtesy. Documentation, credentials, network diagrams, vendor contacts and the list of known quirks are artefacts your outgoing provider owes you. Put them in the plan with dates.
  • Run a period of overlap. ITIL calls it early life support. In practice: the new provider is live and the old contract has not been terminated, for two to four weeks, so anything undiscovered surfaces while someone who knows the history is still reachable.

The four-week plan below is that practice, sized for a business of 10 to 50 people.

The 4-week switch plan

Week 1: Audit and document

Before notifying your current provider, document everything you can on your own:

  • Every business account and where the credentials live
  • Every domain you own and where it's registered
  • Every device that's managed (laptops, phones, servers)
  • Every backup that's running and where backups are stored
  • Every recurring invoice you pay for IT-related services

Your new provider will work from this list.

Week 2: Notify and request handover

Notify your current provider in writing. Reference your contract's termination clause (most managed IT contracts require 30-60 days notice; if yours doesn't say, 30 days is the legal default in most EU jurisdictions). In the same notice, formally request:

  • All admin credentials for every system they manage
  • All API keys, certificates, and recovery codes
  • All documentation and runbooks
  • Confirmation of where backups are stored and how to access them
  • A list of any third-party services they manage on your behalf

Under GDPR (and Israeli privacy law equivalents), you have a legal right to your data. A provider refusing to hand it over isn't being awkward. It's breaking the law.

Week 3: Parallel run

This is the safest pattern: have both providers active for one week. Your new provider takes over administration of email, devices, and backups. Your old provider remains active in case anything was missed. Don't skip this week.

Week 4: Cutover and decommission

Once the new provider has confirmed everything is migrated and tested, formally decommission the old provider:

  • Remove their admin access from every system
  • Rotate any shared credentials
  • Confirm in writing that they no longer hold any of your data
  • Final invoice and contract closure

The handover checklist: what to demand, and what it costs you to skip

Domain registrar access

What good looks like
Registered in your business name, with 2FA you control
Risk if you skip it
Your provider can move or lose the domain your mail depends on

Global Administrator accounts

What good looks like
You hold them; the provider holds delegated access
Risk if you skip it
You cannot revoke anyone or prove who has access

Credential inventory in writing

What good looks like
Every account, exported to your password manager
Risk if you skip it
Systems surface months later with nobody able to sign in

Backup configuration and a test restore

What good looks like
A restore proven before cutover, not described
Risk if you skip it
You discover the backup was never running when you need it

Written documentation and vendor contacts

What good looks like
Diagrams, quirks, licence and support contracts
Risk if you skip it
Every future change starts with reverse engineering

Confirmation that access is removed

What good looks like
In writing, after credentials are rotated
Risk if you skip it
A former provider keeps standing access to your tenant

The handover bar we hold outgoing providers to. Ask for all six in the notification letter, with dates.

Red flags during a switch

Some behaviour from an outgoing provider goes past frustrating. Treat it as a warning:

  • Refusing to provide credentials in writing ("we'll just transfer them when needed")
  • Charging an "exit fee" that wasn't in your contract
  • Claiming they own your domain or M365 tenant
  • Disabling services or "accidentally" deleting accounts during handover
  • Slow-walking responses past your notice period

If any of these happen, document everything in writing and escalate. In the EU, your data protection authority will take complaints seriously when a provider obstructs lawful data access. Your incoming provider should also know how to handle these - that's part of why you hire them.

What a good handover looks like

A clean switch ends with:

  • You hold every admin credential, in your password manager, in your name
  • You have written documentation of how everything works
  • Your new provider has tested every critical system (email send/receive, backup restore, login from a new device)
  • The old provider has confirmed in writing they no longer have access
  • You haven't lost a single email, file, or working hour

That's the bar. It's achievable. Don't accept less.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. Granular delegated admin privileges (GDAP) for Microsoft partnersMicrosoft Learn · 2026How partner administrative access to your tenant is granted, scoped and revoked. (opens in a new tab)
  2. Assign admin roles in the Microsoft 365 admin centerMicrosoft Learn · 2026Taking and verifying ownership of Global Administrator access during a handover. (opens in a new tab)
  3. Microsoft 365 tenant-to-tenant migrationMicrosoft Learn · 2026What is involved if your data sits in a provider-owned tenant and has to move. (opens in a new tab)
  4. ITIL 4 service transition and change enablement practicesAXELOS / PeopleCert · 2025 · reporting on primary dataRecognised framework treating provider change as a managed service transition with knowledge transfer and early life support. (opens in a new tab)
  5. Regulation (EU) 2016/679 (GDPR), Article 20 - Right to data portabilityEUR-Lex, Publications Office of the EU · 2016The right to receive personal data in a structured, commonly used, machine-readable format. (opens in a new tab)
  6. Buy or transfer a domain in Microsoft 365Microsoft Learn · 2026Establishing who controls the domain, and moving it if the outgoing provider registered it. (opens in a new tab)

Figures last checked 28 July 2026

Stuck with a provider that's holding you back?

Book a free 30-minute call. We'll walk you through what a clean switch would look like for your specific setup - including what to demand from your current provider.