Information a new IT provider should request during onboarding

A new IT provider should ask for enough information to understand your people, technology, suppliers, security risks and business priorities before taking responsibility for support. The request should cover users, devices, Microsoft 365, networks, servers, applications, backups, contracts and current issues, with credentials transferred through a secure process.

The short answer

Your new provider should build a verified record of who uses the technology, what the business depends on, how systems are configured, where data is protected and who owns each supplier relationship. Good onboarding turns scattered knowledge into a usable support baseline and identifies missing documentation, unsupported systems, urgent security gaps and decisions that require business approval.

In this guide

AREA 1

Start With the Business Context and People

Technology only makes sense in the context of the organisation it supports. The provider should identify the main contacts, locations, working hours, departments and approval routes. It should know who can authorise purchases, access changes, security actions and work that may interrupt a service.

01

Contacts and responsibilities

Named decision makers, finance and procurement contacts, department leads, emergency contacts and the people authorised to approve sensitive requests.

02

Sites and working patterns

Office, home, field and multi-site arrangements, opening hours, critical periods, site access requirements and teams working outside normal hours.

03

Critical services

The systems the organisation cannot operate without, the effect of downtime and the order in which services should be restored after disruption.

Business impact sets priority. This context helps the provider distinguish a minor technical fault from an incident that threatens payroll, customer service, production or a contractual deadline.

AREA 2

Build an Accurate Picture of Users and Access

The provider should request a current user list and compare it with the accounts that exist across Microsoft 365, business applications, devices and remote-access services. The review should identify employees, contractors, shared accounts, privileged administrators, dormant users and service accounts.

Area Information to establish Why it matters
User lifecycle Joiner, mover and leaver process, approvals and ownership. Reduces delayed access and accounts remaining active after someone leaves.
Microsoft 365 Tenant ownership, licences, domains, email, Teams, SharePoint and OneDrive. Shows how communication, collaboration and information are administered.
Identity security Multi-factor authentication, Conditional Access and sign-in policies. Helps expose weak or inconsistent access controls.
Privileged access Administrator roles, emergency accounts and approval routes. Supports secure administration and recovery.

If Microsoft 365 is central to the organisation, the provider should document both the technical configuration and who is responsible for governance. Stratiis can support this through its Microsoft 365 Services.

AREA 3

Map Devices, Infrastructure and Applications

A useful inventory is more than a count of laptops. It should show ownership, model, age, warranty, operating system, encryption, management status and the user or location associated with each device. Servers, virtual machines, mobile devices, printers and specialist equipment should also be recorded where they fall within the support scope.

01

Endpoints

Laptops, desktops, tablets and phones, including operating systems, security status, warranty, assigned users and management state.

02

Core systems

Physical and virtual servers, cloud workloads, storage, directories, databases, hosting arrangements and technical dependencies.

03

Connectivity

Internet circuits, public IP addresses, firewalls, switches, wireless networks, VPNs, DNS, domains and diagrams.

04

Business applications

Critical software, licences, hosting, integrations, support contacts, renewal dates, data locations and specialist access.

05

Communications

Phone platforms, number ranges, call routing, mobile services and the suppliers responsible for support.

06

Physical access

Server rooms, network cabinets, keyholders, alarm procedures, access cards and site operating hours.

The provider should verify what it can discover automatically and investigate discrepancies. An unknown server, unmanaged device or expired domain registration may represent a larger risk than its place on an inventory suggests.

AREA 4

Verify Security, Backup and Recovery

Security information should cover the controls that are active, the systems they protect and the person or supplier responsible for responding to alerts. This commonly includes endpoint protection, email security, firewalls, device management, monitoring, patching, vulnerability management and awareness training.

Control What the provider should confirm Expected evidence
Endpoint and email protection Products, coverage, policies, alert destinations and response ownership. Supported users and devices are visible and monitored.
Identity security MFA, Conditional Access, administrator roles, inactive accounts and risky access. Important access gaps and exceptions are recorded.
Backup scope Microsoft 365 data, servers, applications, files, schedules and retention. Coverage matches business requirements rather than assumptions.
Recovery readiness Restore tests, recovery order, recovery objectives and responsible contacts. Recent evidence shows that protected data can be recovered.

The provider should ask about previous incidents, cyber insurance conditions, regulatory requirements and known exceptions. Stratiis can review this through its Cybersecurity Services and Backup and Disaster Recovery services.

Onboarding is a verification exercise. A supplied spreadsheet is useful evidence, but the provider should confirm that accounts, devices, backups and security controls match the live environment.

AREA 5

Record Suppliers, Licences and Contracts

Many business systems sit outside an MSP's direct control. The new provider should know which suppliers provide internet, telephony, line-of-business software, websites, domains, printing, security, cloud hosting and other specialist services.

Account ownership
Customer name, portal ownership and authorised contacts.
Support route
Telephone, email, portal, service references and escalation.
Commercial detail
Licences, renewal dates, contract owner and important exclusions.
Technical dependency
Systems, integrations, data and infrastructure that rely on the supplier.

The business should retain ownership of its domains, cloud tenants and important service accounts wherever possible. Third-party access should have a defined purpose, scope and expiry, with legacy accounts removed.

AREA 6

Understand Support History and Planned Change

Technical discovery should be paired with a review of current experience. The provider should ask about recurring faults, unresolved tickets, unreliable systems, user complaints, previous cyber concerns and workarounds that have become normal.

What is causing friction now?

Slow support, recurring outages, unreliable Wi-Fi, ageing devices, Microsoft 365 problems, backup concerns and incomplete documentation can reveal priorities that an inventory alone will miss.

What is changing next?

Recruitment, new premises, acquisitions, contract wins, cloud migrations and system replacements can change the support requirement quickly.

If the relationship is being selected or reviewed, compare how providers discover, document and prioritise this information. See What Questions Should You Ask Before Choosing a Managed IT Provider?, How Do You Compare Managed IT Support Providers? and What Should You Check Before Renewing Your IT Support Contract?

SECURE HANDOVER

Transfer Accounts and Passwords Safely

Credentials should not be collected in ordinary email, open spreadsheets or shared documents. The new provider should explain the secure transfer method, who can access the information and when temporary credentials will be changed.

01

Establish ownership

Confirm that the business owns the tenant, domain, licences and service accounts before changing access.

02

Transfer securely

Use an approved encrypted channel or password vault with access limited to named people.

03

Verify access

Test administration and recovery routes before the outgoing provider's access is removed.

04

Rotate credentials

Change shared or inherited passwords and protect privileged accounts with strong authentication.

05

Remove old access

Disable obsolete accounts, remote tools and supplier access through a controlled process.

06

Record the result

Document new ownership, access routes, emergency accounts and remaining gaps.

A well-managed change also sets clear dates, responsibilities and escalation contacts. Read How to Switch IT Providers Without Disrupting Your Business for the wider transition process.

WHEN RECORDS ARE INCOMPLETE

Rebuild Missing Information in Priority Order

Incomplete documentation should not stop a move, but it should change the onboarding plan. The new provider can combine technical discovery with information from the organisation, cloud portals, invoices, suppliers and the outgoing provider.

01

Inspect the live environment

Use device, network, tenant and licence data to establish what exists and who is using it.

02

Close the riskiest gaps

Secure administrator access, backups, domains, critical systems and support routes first.

03

Create a controlled baseline

Document assumptions, missing evidence, decisions and owners so progress is visible.

Poor records can indicate that the current relationship no longer meets the organisation's needs. See The 7 Warning Signs Your Business Has Outgrown Its Current IT Provider.

ONBOARDING OUTCOMES

What Should the New Provider Know by the End?

By the end of onboarding, the provider should be able to explain the supported environment, the most important dependencies and the risks that need a decision. The business should receive a clear baseline rather than a silent collection of passwords.

Accurate records
Users, devices, systems, locations, suppliers and ownership are documented.
Controlled access
Administration is protected, traceable and independent of the outgoing provider.
Verified protection
Security, patching, monitoring and backup coverage have been checked.
Known priorities
Urgent risks, service improvements and future projects have owners and next steps.

The first month should turn discovery into action, reporting and an agreed improvement plan. See What Happens in the First 30 Days After Changing IT Provider?

Warning Signs of Weak Onboarding

Inherited gaps are common. The concern is a provider that fails to identify them, cannot explain what it controls or produces no structured improvement plan.

01

Control remains unclear

Important credentials, ownership, old-provider access or supported assets remain unknown.

02

Protection is assumed

Backup, MFA, endpoint security and monitoring have not been verified.

03

Users are confused

Employees do not know how to contact support or which provider owns an issue.

04

No findings are shared

Leadership receives activity updates without a clear risk and service assessment.

05

Everything changes at once

Tools and settings are replaced before dependencies and business impact are understood.

06

No next step exists

The onboarding ends without owners, priorities, review dates or an improvement plan.

Common Questions About IT Provider Onboarding

Should a new provider ask for every password?

No. It should request the access required for the agreed service, use secure transfer and storage, and replace shared or inherited credentials where practical.

Who should provide the information?

The business, outgoing provider and specialist suppliers may each hold part of the picture. A senior business contact should oversee the process.

How long should onboarding take?

It depends on the number of users, locations, systems and suppliers, plus the quality of existing records. The provider should give a timetable and progress updates.

Can support start if records are incomplete?

Yes, provided the provider understands the gaps and manages the risk. Critical access, security, backup and escalation information should be prioritised.

Should the new provider speak to the old one?

Usually yes. A controlled technical handover can resolve questions quickly, with the customer setting the authority, scope and dates.

What should the customer receive?

A current support baseline, confirmed contacts and scope, a risk summary and an agreed plan for urgent remediation and longer-term improvement.

The written scope should also be clear. Compare the onboarding plan with What Should Be Included in a Managed IT Support Agreement? and What Is Actually Included in Fully Managed IT Support?

Planning to Change IT Provider in Scotland?

Stratiis can assess the current environment, coordinate the handover and establish a secure, documented foundation for ongoing support.

Discuss Your IT Onboarding

Related Articles and Services