Changing IT Support Provider: What Should Happen During the Handover

A practical IT handover checklist for Dubai offices switching providers: ownership, records, a short overlap and revoking old access.

Part of our guide to IT Support Dubai.

Two people reviewing and signing documents at a desk during a handover
Quick answer

When changing IT support provider, check your contract's notice and exit terms first, then confirm your company controls the domain, Microsoft 365 tenant, firewall and every admin credential. Collect documentation, a password vault export, licence, warranty and vendor records, hold a handover meeting, overlap the two providers briefly, then revoke all of the old provider's access and have the new provider audit everything.

Key takeaways

  • Read the notice period, renewal and exit terms in your current contract before you tell the old provider you are leaving.
  • The domain, Microsoft 365 tenant, firewall and all admin credentials should be registered to and controlled by your company, not the provider.
  • Collect documentation, a password vault export, licence records, vendor contacts and warranty records before the cutover date.
  • Run both providers together for a short, agreed period with a clear date when responsibility moves.
  • Remove every old admin account, remote access tool, VPN account and partner relationship once the new provider has control.
  • Expect the new provider to audit accounts, backups, security and documentation in the first 30 days.

When is it time to change IT support provider?

It is time to switch when problems keep coming back, response is slow or unclear, and you cannot see what your provider actually does. One bad week is not a reason to move; a pattern is.

Many Dubai offices outgrow a provider that suited them at ten staff but struggles at forty, or find that the person who knew their setup has left. Moving is easier and safer when it is planned rather than done in the middle of a dispute.

  • The same faults return because root causes are never fixed.
  • Nobody can show you a network diagram, asset register or list of admin accounts.
  • The provider holds passwords that your own management cannot access.
  • Security basics such as MFA, patching and tested backups are missing or unreported.
  • On-site visits are hard to get when something physical fails.
  • Every change becomes an extra charge, so nothing is maintained proactively.

What should you check in your contract before switching?

Check the notice period, renewal date and exit terms before you announce anything. These decide your timeline and what the old provider must hand back.

Look for automatic renewal, how notice must be given (often in writing to a named address), any transition or exit assistance the provider agreed to give, and whether equipment was sold, leased or supplied as part of a bundle. Check whether Microsoft 365 licences, firewall subscriptions or backup services are billed through the provider, because those need a planned move so users are not left without service. Settle outstanding invoices you agree with, since disputes over money slow handovers down. This is a practical checklist, not legal advice; if the terms are unclear or contested, ask your legal adviser to read them.

Who should own the domain, Microsoft 365 tenant and firewall?

Your company should own all of them, with the provider given named access to manage them. If a provider registered your domain in its own account or holds the only admin login, fix that first.

Ownership means the accounts are in the company's name, linked to an email address the company controls, and the company can sign in without asking anyone. Providers should work through their own named accounts that you can remove. The table shows what to check.

IT handover checklist: ownership and verification
ItemWho should own itHow to verify
Domain name registrationThe company, with a company-controlled contact emailSign in to the registrar account yourself and check the registrant details
DNS hostingThe company, in its own accountConfirm where DNS records are hosted and that you can sign in there
Microsoft 365 tenantThe company, with at least one company-held Global Administrator accountSign in to the admin centre and review admin roles and partner relationships
Firewall, switches and Wi-Fi controllerThe company holds the admin credentials; providers use named accountsSign in and review the list of admin users on each device or cloud console
Vendor portal registrations and support contractsThe companyCheck which account each device, subscription and warranty is registered to
Password vaultThe company, with provider access to shared vaults onlyConfirm company owners can open every vault and remove provider users
Backups and backup dataThe companySign in to the backup console and restore a test file
Internet line accounts with du or e&The company as account holderCheck the account name on the ISP portal or latest bill

What should you collect from the old IT provider?

Collect everything the new provider needs to run your IT without guessing. Ask for it in writing, as a specific list, with a date.

  • Documentation: network diagram, port map, asset register, account list and any configuration notes. Our office network documentation guide explains what each should contain.
  • Password vault export: every admin, service and vendor portal credential, transferred through a secure method and never by plain email.
  • Licence records: Microsoft 365, firewall security subscriptions, endpoint protection, backup software and renewal dates.
  • Vendor contacts: ISP account references, telephone system supplier, printer lease company, line-of-business software support.
  • Warranty records: serial numbers, warranty end dates and any support contracts for servers, NAS units, firewalls and laptops.
  • Configuration backups for the firewall, switches and Wi-Fi controller.
  • Open tickets and known issues, including anything postponed or awaiting parts.

What should happen during an IT handover meeting?

A handover meeting walks through the environment with both providers and your own decision-maker present. It turns a pile of files into shared understanding and exposes gaps early.

Keep it to one focused session with written notes and actions, and follow up any unanswered item by email the same day.

  • Confirm the cutover date and who is responsible for incidents before and after it.
  • Walk through the network diagram, internet lines, firewall and Wi-Fi.
  • Review the account list and confirm which admin accounts belong to the old provider.
  • Go through backups: what is backed up, where, how often, and the last successful restore test.
  • List recurring tasks the old provider performs, such as updates, renewals and new-starter setup.
  • Agree how licences and subscriptions billed through the old provider will move.
  • Record open issues, risks and anything that is undocumented.

Should the old and new providers overlap?

Yes, briefly. A short overlap lets the new provider install monitoring, confirm access and document the setup while the old provider is still available to answer questions.

Agree one clear cutover date. Before it, the old provider handles incidents and the new provider observes and prepares; after it, the new provider is responsible. Keep the overlap short, because two parties with admin rights and no clear owner is a risk in itself. If the cutover involves changing network equipment, schedule it for a quieter period, such as a weekend, so office staff are not affected.

How do you revoke the old provider's access?

Remove every route in once the new provider has confirmed control, working from the account list rather than memory. Change shared passwords the old provider knew, even if its named accounts are deleted.

  • Admin accounts: delete or disable provider accounts in Microsoft 365, the firewall, switches, Wi-Fi controller, NAS and backup console.
  • Microsoft 365 partner access: remove the old provider's partner relationship and delegated admin access in the admin centre.
  • Remote tools: uninstall remote access and monitoring agents from every laptop, desktop and server.
  • VPN: remove provider VPN accounts and any certificates or keys issued to them.
  • Passwords: rotate shared admin, Wi-Fi management, service account and vendor portal passwords.
  • Email rules and forwarding: check for mailbox access or forwarding set up for the provider.
  • MFA: remove the provider's phones or authenticator registrations from company accounts. Our guide to MFA for small businesses covers setting it up properly.

What should the new provider audit in the first 30 days?

The new provider should verify what it inherited rather than trust the handover pack. Expect a written summary of findings with priorities.

A useful first-30-days audit checks admin roles and unknown accounts, MFA coverage for every user, patch and firmware status, firewall rules and remote access, endpoint protection on every device, licences against actual users, warranty dates, and backups with a real restore test, as described in our guide to backups that actually restore. The provider should also correct or create the documentation and list urgent gaps separately from longer-term improvements.

What if the old provider will not cooperate?

Stay calm, factual and persistent. Send a written, itemised request with a reasonable deadline, keep copies, and escalate to the provider's management. Meanwhile, secure what you already control: sign in to anything you can and add a company-held admin account. For the domain, contact the registrar with your trade licence and proof of ownership. For Microsoft 365, Microsoft support can advise on regaining admin access; be ready to prove your organisation's identity and control of the domain. A firewall or controller with unknown credentials may need a planned factory reset and rebuild, done out of hours. If it becomes a contractual dispute, take advice from your legal adviser.

How Listonics helps with changing IT support provider

Listonics takes over setups installed and supported by others for Dubai offices of roughly 5 to 200 staff. We start with a free office IT assessment, then audit and document first, fix urgent gaps, and move you onto managed IT support at a fixed monthly fee per user or per device, replacing equipment only where genuinely needed. We help recover admin access, bring the domain, tenant and firewall under your company's control and remove old access. You receive a network diagram, asset register, account list and port map, so your IT does not depend on one person's memory. To plan a handover, book a free IT assessment.

Frequently asked questions

It depends mostly on your notice period and how organised the current setup is. A well-documented office can hand over quickly once notice is served, while an undocumented one needs time to recover access and records. Plan a short overlap and one clear cutover date rather than an open-ended transition.

No. You can speak to new providers and get an assessment before giving notice, which helps you set a realistic cutover date. Check your contract's notice terms first, then give notice in the way the contract requires once the new arrangement is agreed.

It should not keep working access. Ask for a secure export of all credentials, then remove the provider's accounts and change every shared password it knew. Admin credentials belong to your company and should be stored in a company-owned password manager with access you control.

Ask the provider in writing to transfer it into your company's own registrar account. If it refuses or does not respond, contact the registrar directly with your trade licence and evidence that the domain is used by your business. Do this early, because email and your website depend on the domain.

It should not if the handover is planned. Most of the work is access, documentation and monitoring, which happens in the background. Any change to network equipment or a firewall rebuild should be scheduled out of hours, with the old configuration backed up so it can be restored if needed.

Not automatically. A new provider should audit what you have and replace equipment only when it is failing, out of support or unsuitable for your needs. Ask for recommendations in writing with the reason for each, and expect urgent security gaps to be separated from longer-term upgrades.

Published Sep 14, 2026 · Last reviewed September 13, 2026 · 1,823 words

Talk to an engineer about managed it services & amc for your office.

contact us
Chat on WhatsApp