Switching IT provider is administratively simpler than staying with one who has stopped caring.
Most businesses put up with a failing IT provider a year longer than they should, because switching feels risky and the incumbent holds the passwords. In practice a well-run switch is a two-to-four-week administrative process: a defined checklist, a parallel run so nothing goes dark, and a credentials handover you are entitled to whether your current provider cooperates or not. This page is the complete playbook, from the signs it is time through to the first 90 days.

- 2-4 weeksTypical switch duration
- 0Downtime in a parallel-run switch
- 14 daysBoth providers active
- FreePre-switch environment audit
Nine things you must get back before or during any switch.
Microsoft 365 or Google Workspace Global Admin
The master key to your email, files, and identity. You need at least one Global Administrator account in your own name, secured with MFA, before cutover. If the tenant sits inside the provider partner account, ownership transfer is a defined Microsoft process, not a favour.
Domain registrar and DNS control
Whoever controls the domain controls where your email is delivered. Confirm the registrar account is in your company name. If the domain is registered to the provider, start the transfer early; it can take days and is the item most often left until too late.
Firewall, router, and switch admin passwords
Every network device on your premises has an admin credential. Get each one, or accept a factory reset and reconfiguration during handover. A provider who "cannot find" the firewall password is telling you the device was never documented.
Backup console access and a proven restore
Know where your backups live, who holds the encryption keys, and whether the subscription is in your name. Then have the new provider run a test restore before the old service is cancelled. A backup you cannot restore during a handover is a backup you never had.
Software licences and subscriptions in your name
Microsoft licences, antivirus seats, line-of-business software, SSL certificates. Providers often buy these through their own reseller accounts. On exit, each licence transfers to your tenant, moves to the new provider CSP relationship, or gets repurchased. Map all three before notice.
Documentation: network, assets, configurations
Network diagram, IP plan, server and endpoint inventory, Wi-Fi keys, VPN setup, change history. Contractually this is usually yours. If it does not exist, the new provider rebuilds it during the walkthrough and you finally get documentation you can see.
Vendor and ISP account ownership
Etisalat or du account numbers and authorised contacts, hardware warranty registrations, and any third-party SaaS the provider administers. Each one needs your name added and, after cutover, the old provider contact removed.
Monitoring agents and remote-access tools
The incumbent has remote-control software on every one of your machines. A clean handover removes their agents, deploys the new stack, and confirms in writing that old remote access is revoked. Skipping this leaves a former vendor with a door into your endpoints.
Mailbox and service-account passwords
Service accounts, shared mailboxes like info@ and accounts@, and any password vault the provider maintained. Everything rotates at cutover so old provider access stops working on a known date, cleanly and without accusation.
Four principles that make a switch boring, which is the goal.
Parallel-run, never a hard cutover
The new provider deploys monitoring and helpdesk alongside the incumbent for 14 days. Both are active; nothing goes dark. Cutover happens at an agreed low-risk window once the new monitoring has proven itself. There is never a moment when nobody is watching.
Checklist-driven, with named owners and dates
Every credential, licence, device, and document goes into a written transition plan: who recovers it, by when, and how completion is evidenced. Ambiguity is where handovers fail; the checklist removes it.
Designed to work without the old provider
The plan assumes the incumbent may be slow, unhelpful, or silent, and routes around it. Tenant ownership recovers through Microsoft directly, domains transfer at the registrar, firewalls reset and rebuild. Cooperation makes a switch faster; it is never a precondition.
Knowledge captured, not assumed
During the parallel period the new provider walks the environment with your team: what is fragile, what is undocumented, which recurring issue everyone has learned to live with. Most incumbent knowledge is reconstructable within 30 days; the walkthrough captures it deliberately rather than during an outage.
What to check in your current contract first.
Term and notice
- Notice period and how notice must be servedMost Dubai IT contracts require 30 to 90 days written notice. Check whether email counts, and diarise the deadline.
- Auto-renewal dateMany agreements renew for a full year if notice is not served by a specific date. If it is close, serve protective notice now and decide at leisure.
- Early-termination clauseCheck what exiting before the end date costs, and whether persistent service failure gives you grounds to exit without penalty.
Data, access, and exit obligations
- Exit-assistance clauseBetter contracts oblige the outgoing provider to hand over credentials, documentation, and data within a defined window. If yours has one, quote it in your notice letter.
- Data return and deletionConfirm what the provider holds, how it is returned, and when their copies are destroyed.
- Who owns the documentationDocumentation produced under a paid contract is normally yours. Check the intellectual-property clause before assuming.
Licences, hardware, and money
- Licences bought through the providerList every subscription billed via the provider and check whether it lapses on exit. This is where an unmanaged switch can silently cut your email off.
- Provider-owned equipment on your siteLoaned firewalls, access points, or backup appliances go back on exit. Know which devices are theirs so removal is planned, not discovered.
- Outstanding invoices and disputesSettle undisputed amounts and document disputed ones separately. An unpaid invoice is the most common pretext for withholding a handover.
Six signals that your current IT provider has stopped earning the contract.
Tickets sit for days, escalations go nowhere
You log an issue, chase it twice, and eventually someone fixes it without telling you what happened. The provider is not responding because your account is no longer staffed properly, and response quality rarely recovers on its own.
Surprise invoices for things you thought were covered
A visit that used to be included is now billable. A "project charge" appears for routine maintenance. Scope creep in the invoicing direction means the provider is monetising your reluctance to re-read the contract.
No documentation you can actually see
Ask for the network diagram, the asset register, and the list of admin accounts. If the answer is silence, a stale PDF, or "it is all in our system", your business knowledge lives inside a vendor you are already unhappy with. That is a dependency, not a service.
They hold your credentials and you hold nothing
The Global Admin, the domain registrar login, the firewall password, the backup console: all with the provider, none with you. Hostage credentials are the biggest reason businesses stay too long, and the most fixable one. The access is yours by right; recovering it is routine.
Security is a word in the brochure, not a practice
No MFA enforcement, no patching evidence, no tested backup restore, and nobody mentioned any of it until your bank or insurer asked. A provider who has not raised security with you in the last year is exposing you quietly.
No reporting, no reviews, no roadmap
You cannot remember the last written report or the last meeting where the provider brought an idea. Support without periodic review is break-fix wearing a contract: a retainer for a service that only exists when something breaks.
Switching, staying, or running the transition yourself.
| Feature | Structured switch | Stay and hope | DIY transition |
|---|---|---|---|
Credentials recovered into your name | Still held by provider | If you know the list | |
Coverage during the transition | 14-day parallel run | N/A | Gap between providers |
Backup proven by a test restore | Unknown | If you remember | |
Old provider access cleanly revoked | N/A | Often missed | |
Handles an uncooperative incumbent | Planned for | N/A | Stressful, unfamiliar |
Your time consumed | A few hours of decisions | None now, more later | Days of coordination |
How a provider switch actually runs, in four phases.
- 1
Audit and transition plan
Week 1
The new provider walks your environment and works through the credentials-and-access checklist: what exists, who holds it, what is missing. You review your contract for notice terms. Output: a written transition plan with named owners and dates, before any notice is served.
- 2
Serve notice and recover access
Weeks 1-2
Notice goes to the incumbent in the form the contract requires, quoting the exit-assistance clause. Credential recovery starts immediately: tenant ownership, domain transfer, licence mapping, documentation request. Cooperative incumbents hand things over; uncooperative ones get routed around.
- 3
Parallel run and cutover
2 weeks
New monitoring and helpdesk deploy alongside the old service. Once stable, cutover happens at a low-risk window: helpdesk number switches, credentials rotate, old remote-access agents come off, and revocation is confirmed in writing. Zero downtime is the design, not the aspiration.
- 4
Stabilise, document, review
Days 15-90
Documentation rebuilt, backup restore tested, inherited backlog worked through, first monthly report at day 30 and first quarterly review by day 90 with a 12-month plan. The switch is finished when the new normal is measurably better, not when the old contract ends.
What to do when the incumbent goes quiet or refuses to hand over.
A minority of providers respond badly to notice: calls stop being answered, handover requests are ignored, or access is withheld until an invoice dispute goes their way. It feels alarming and is almost always survivable, because very little of what they hold is irrecoverable.
- Put every request in writing with a deadline, referencing the exit or data-return clause in your contract. A dated paper trail changes behaviour on its own.
- Recover Microsoft 365 tenant control through Microsoft directly. If any Global Admin account is in your name, use it to remove theirs. If none is, Microsoft has an ownership process for exactly this situation; it takes days, not months.
- Transfer the domain at the registrar level using your trade licence to prove ownership. Registrars deal with unresponsive third parties routinely.
- Accept a reset where recovery is slower than rebuilding. A firewall with an unobtainable password gets factory-reset and reconfigured in an evening.
- Rotate every password as each service is recovered, and keep a log. The goal is a clean, dated end to old provider access, not a running argument.
“We knew for a year that we needed to move, but our provider had every password and we did not know what we even had. The audit gave us the full list in a week, both companies ran live at the same time, and nobody in the office noticed the cutover day. Five years with the old company and we had never seen a network diagram; now we have our own documentation.”
The first 90 days with a new provider, and what good looks like.
- 01Days 1-14
Stabilise and secure
Parallel coverage ends, the new provider becomes primary, and every credential from the handover checklist is rotated and vaulted. Monitoring is live on every endpoint, old provider remote access is confirmed revoked in writing, and a backup restore has been tested.
- All passwords rotated and vaulted
- Access revocation confirmed in writing
- Test restore evidenced
- 02Days 15-30
Document and baseline
The environment walkthrough completes: network diagram, asset register, licence inventory, and a security baseline review covering MFA, patching, and mail authentication. Everything the old provider never wrote down now exists in a form you can see.
- Documentation pack: network, assets, licences
- Security baseline review with findings
- First monthly service report
- 03Days 31-60
Fix the inherited backlog
Every switch uncovers deferred maintenance: unpatched servers, dormant accounts of departed staff, expired warranties, a UPS that has been beeping for a year. These get worked through as an agreed priority list, and recurring issues get root-cause fixes rather than repeat workarounds.
- Inherited-issues backlog worked to an agreed priority list
- Dormant accounts removed, patching brought current
- 04Days 61-90
Review and plan forward
The first quarterly review: what the transition found, what has been fixed, what the numbers show, and a 12-month plan covering renewals, replacements, and improvements. This is the meeting your old provider stopped holding.
- First quarterly review held
- 12-month IT plan delivered in writing
The questions every business asks before moving.
The complete switching and evaluation library.
Switching by contract type
The handover mechanics differ with the shape of your current contract. Pick the guide that matches what you have today.
Evaluate before you commit
Independent checks on what state your environment is really in, and how to run a fair selection for the next provider.
Audit what you are inheriting
The natural moment to find out what the last provider left behind. These audits turn suspicion into a written findings list.
What the new arrangement could look like.
Start with the free audit, decide with the findings in hand.
Tell us what is frustrating you about the current arrangement and we will walk your environment, work through the credentials checklist, and give you the findings in writing. If the right answer is to stay and renegotiate, we will say so. If it is to switch, you will have the plan before you serve notice.
Related Services
Explore more solutions that work great with this service
Switching AMC Provider
Zero-downtime transition from your incumbent AMC provider
Switching MSP Provider
Zero-downtime transition from your incumbent MSP
IT Due Diligence
What the target runs, what it costs, what integration costs
IT Procurement
Sourcing, vendor selection, TCO
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
IT Infrastructure Audit
What you run, how much is supported, what fails