Here is a question worth answering before you ever need it: if your IT provider vanished tomorrow, could anyone at your company log into your domain registrar? Your firewall? The admin console for your email? For a surprising number of small businesses, the honest answer is no. The passwords live in the provider's system, the documentation lives in the provider's wiki, and the "ownership" of your own infrastructure is a polite fiction that holds up only as long as the relationship does.
Let's untangle what is actually yours, what is genuinely theirs, and what to do about the gray zone in between.
The short answer
Credentials to your accounts and systems belong to you. They are keys to property you own or subscribe to; the provider holds them as your agent, the way a property manager holds the keys to your building. Documentation is murkier: information about your environment (your IP scheme, your configurations, your license records) is generally treated as yours, while the provider's internal tooling, templates, and methodology are theirs. The contract you signed is what actually settles it, so check your agreement's language on deliverables, data return, and what happens at termination. When it is silent, most disputes resolve on the practical logic above, but do not take a blog's word over your attorney's on a contested exit.
What is unambiguously yours
- Your domain name. The registration should list your company as registrant, with the registrar account under an email address you control. This one matters more than any other item on the page, because whoever controls the domain controls your email and your website.
- DNS control. Wherever your DNS is hosted, you are entitled to access, because every service you use hangs off it.
- Admin access to your tenants. Microsoft 365 or Google Workspace is your subscription. A provider can and should have their own admin account in it, but your company should hold a global admin credential too.
- Hardware you paid for, and the admin passwords on it: firewall, switches, servers, access points.
- Your data, wherever it sits: mailboxes, files, application databases, and backups of all of it, including the encryption keys that make the backups usable.
- License records for software purchased on your behalf, even when the provider resells it.
What is legitimately the provider's
Fair is fair, and knowing what not to demand keeps an offboarding civil. Their remote monitoring platform, their ticketing system, their scripts and automation, their internal runbooks, and licenses they hold at the MSP level for their own toolset all stay with them. When they offboard you, they will uninstall their agents and close their accounts, and that is proper. What you want exported before that happens is the information those systems hold about you: your asset list, your configurations, your ticket history if they will provide it.
The gray zone, and how it goes wrong
Trouble almost never comes from a provider stealing anything. It comes from convenience decisions made years ago that nobody revisited. The domain got registered under the provider's own GoDaddy account in 2016 because it was faster that day. The Microsoft licenses are on the provider's reseller agreement. The firewall in your closet is actually theirs, rented back to you inside a bundled monthly fee. The backup account's recovery email is an engineer who left the provider two years ago. Each choice was harmless when made; together they mean "leaving" requires the provider's active cooperation on a dozen fronts.
This is also where a minority of providers get grabby on the way out: slow-walking credential handoffs, calling ordinary network documentation "proprietary," or conditioning the handoff on settling a disputed final invoice. You do not need to assume bad faith to plan for friction. Put every request in writing, be specific, and keep the tone even. The full request list lives in our IT provider offboarding checklist.
The audit: an hour that tells you everything
You do not need to be leaving to do this. Sit down with whoever handles your IT relationship and answer, for each category, two questions: can we log in without calling anyone, and is the account registered to an email address we control?
- Domain registrar
- DNS hosting
- Microsoft 365 or Google Workspace global admin
- Firewall and network hardware, plus their cloud portals
- Backup platform, including encryption keys
- Line-of-business applications (accounting, industry software, CRM, phones)
Score yourself honestly. Six yeses means you own your environment and a provider change is a project, not a crisis. Multiple nos means your provider effectively holds a lien on your own infrastructure, and if you are also seeing service problems, that combination is exactly the ninth sign in our list of signs you should fire your IT provider: staying because leaving feels impossible.
Taking control back, with or without a switch
If the audit turned up gaps, the fix is straightforward and reasonable to request from any provider in good standing: transfer the domain registration to a company-owned account, add a company-held global admin to your tenants, get the backup encryption keys into your own password manager with at least two trusted people holding access, and get a current copy of your documentation delivered on a schedule, not just on request. A confident provider will treat this as good hygiene. A provider who resists, deflects, or takes it personally has told you something important about why the setup looks the way it does.
And if you are heading for the exit, do the recovery quietly before you give notice, while cooperation is easy, then follow the sequencing in how to switch IT providers without downtime and the script in how to fire your MSP professionally. Recover first, announce second. It is the difference between a handoff and a negotiation.
Find out what you actually control
Our free switch plan starts with exactly this audit: what you own, what your provider holds, and the step-by-step path to getting all of it back. Written, in 48 hours.
Start the Switch