Changing IT providers should not interrupt email, files or Microsoft 365. Problems usually begin when a service is cancelled before the new provider has confirmed access, backups and billing.
Treat the change as a planned handover. Confirm control first. Remove the old provider only after the new provider has tested the setup.
Before you give notice
Check the agreement for notice periods, cancellation dates and any terms covering licences, backups or documentation. Set a handover date in writing and name the people authorised to approve changes.
Do not cancel email, domain, backup or security services simply because you have chosen a new provider.
Confirm the four essentials
Your incoming provider should verify these items before the handover starts:
- Microsoft 365 access. Confirm that appropriate administrator accounts and recovery methods are under business control. The incoming provider should test access before the outgoing provider's account changes.
- Domain control. Confirm who holds the domain registration, where its internet settings are managed and which business-controlled contact can recover the account.
- Backups. Confirm what is protected, how long copies are kept and whether backup access ends with the old agreement. Put replacement protection in place before cancelling the old service.
- Licences and billing. Record each licence, its user, renewal date and billing provider. Changing the provider relationship must not remove a licence that someone still needs.
Keep more than one recovery path for important accounts. A single locked account should not stop the handover.
Test the services staff rely on
Website forms, scanners, accounting software and booking tools may send email through Microsoft 365. Shared mailboxes and automated tasks may also depend on an old account or password.
Test these services before and after the move. Check that staff can use email, shared files and the applications needed for a normal working day.
Remove old access last
Once the incoming provider has confirmed administration, domain control, backups, licensing and connected services, change credentials and remove access the outgoing provider no longer needs.
Record what was removed. Do not leave unused administrator accounts behind as a fallback.
If the provider is unresponsive, keep requests in writing and gather contracts, invoices and domain records. Avoid random account or domain changes. Ask the incoming provider to use the formal recovery process for each service, and obtain legal advice if access or ownership is disputed.
Take the checklist into the handover
Download the JCPIT IT Provider Handover Checklist for the full list of accounts, due dates, services and tests to record. It is designed to be completed by the business, outgoing provider and incoming provider together. For printing, download the complete two-page ink-light copy.
If you want the critical access checked before giving notice, contact JCPIT for a provider handover review. We will confirm what is under your control and what needs to be secured first.