When an IT provider relationship ends, the technical work of leaving is really an inventory problem: getting back everything that is yours, and removing everything that is theirs. Miss an item in the first category and you will be locked out of something at the worst possible moment. Miss an item in the second and a former vendor keeps a door into your business indefinitely.
This is the checklist we work through on every switch we run. Use it as your written request list when you give notice (see how to fire your MSP professionally for the conversation itself), and again as your verification list before you consider the offboarding done.
Part 1: Credentials to recover
Work through these by category, and for each one confirm two things: that you have a working login, and that the account is registered to an email address your company controls, not the provider's.
- Domain registrar. The account where your domain name lives (GoDaddy, Namecheap, Network Solutions, and similar). Confirm your company is the registrant and the account email is yours. A domain registered under a provider's account is the single hardest thing to get back later.
- DNS hosting. Often separate from the registrar (Cloudflare, your web host, or the registrar itself). Whoever controls DNS controls where your email and website actually go.
- Email and productivity admin. Global administrator access to Microsoft 365 or Google Workspace, plus any admin accounts the provider created for themselves inside your tenant.
- Firewall, switches, and Wi-Fi. Local admin logins for the hardware, and any cloud management portals (Meraki, UniFi, FortiCloud, and similar) where the devices may be claimed under the provider's organization.
- Servers and workstations. Domain administrator or local admin credentials, plus any hypervisor logins (VMware, Hyper-V) if you run virtual machines.
- Backup platform. The account, the storage location, and critically the encryption keys or passphrases. A backup you cannot decrypt is not a backup.
- Line-of-business applications. Admin access to your accounting system, industry-specific software, CRM, and anything with a vendor support PIN the provider set up.
- Phone system. The VoIP admin portal and the account with the underlying carrier, including the authority to port your numbers.
- Websites and certificates. Web hosting, content management logins, and where your SSL certificates are issued and renewed.
Part 2: Documentation and records
- Network documentation: diagrams, IP addressing, VLANs, and how the pieces connect.
- An asset list: every device the provider managed, with age, warranty status, and which machines belong to you versus them.
- Software license records: what is licensed, in whose name, and through which reseller.
- Vendor account list: every third party the provider dealt with on your behalf (internet carrier, printer company, software vendors) and who the named contact is.
- Configuration exports for the firewall and network gear, so settings can be rebuilt if hardware fails.
- Ticket history, if the provider will export it. It is the institutional memory of every fix and quirk in your environment.
If the provider says some of this documentation is proprietary, that can be a genuine gray area; documentation about your environment and documentation of their internal methods are different things. Check your contract's language on deliverables and data return, and read who owns your IT documentation and passwords for how these disputes usually resolve.
Part 3: Things billed through the provider
Many MSPs resell licenses and services, which means some of what you use every day is technically their account. Each of these needs to be transferred to your name or your new provider before the end date:
- Microsoft 365 or Google Workspace licenses purchased through the provider's reseller relationship.
- Antivirus, email filtering, and security tools licensed under their umbrella.
- Backup storage and cloud infrastructure on their master account.
- Domain names, SSL certificates, or web hosting they registered and rebill.
- Hardware they own and rent to you, such as firewalls or access points, which they may collect or offer to sell you.
Part 4: Access to remove
The mirror image of recovery, and just as important. On the agreed end date, verify all of it is actually gone:
- Uninstall their remote monitoring and management agents and remote-control tools from every server and workstation.
- Disable or delete every admin account they used, in your email tenant, on your domain, on your firewall, and inside applications.
- Remove their multi-factor devices and recovery addresses from any account that stays.
- Shut off email forwarding rules, shared mailboxes, and calendar delegations pointing at their staff.
- Remove their VPN accounts and any site-to-site tunnels into their office.
- Rotate every password they ever held, even for accounts they should no longer be able to reach. Assume old credentials are written down somewhere.
Part 5: The final verifications
- Run a test restore from your backups under your own credentials.
- Send and receive email externally after any DNS or tenant changes.
- Confirm the final invoice matches the contract, and get written confirmation that your data on their systems has been returned or destroyed per your agreement.
- Store everything recovered in a password manager your company owns, with at least two trusted people holding access.
The realistic caveat
On paper this is an afternoon of requests. In practice it is weeks of follow-ups, because an outgoing provider has little incentive to hurry and every incentive to let your emails age. The sequencing matters too: recover before you remove, overlap before you cut over, which is the heart of switching IT providers without downtime. This chase is a standard part of every switch we run, and honestly, requests land differently coming from another engineering team than from a frustrated owner.
We run this checklist for you
Every item above, requested, chased, verified, and handed back to you, while your team keeps working. Get a free written switch plan in 48 hours.
Start the Switch