Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does an MSP Get Every Admin Account and Password When Taking Over From the Previous Provider?
Problems We Solve

How Does an MSP Get Every Admin Account and Password When Taking Over From the Previous Provider?

When an MSP takes over a client, admin access is spread across the old IT firm, staff and vendors. We build a takeover tracker that closes every access gap.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Taking over from an outgoing IT provider depends on receiving admin access to dozens of services, and the handover usually arrives as a partial spreadsheet of passwords. We build a takeover tracker listing every service that needs admin access, who controls it now, what has been received and verified, and what has been rotated into your own vault, with chasers for the rest.

A spreadsheet of passwords, half of them wrong

The client has given notice to their old IT provider, who is being polite but not quick. The handover arrives as a spreadsheet: firewall admin, a couple of server passwords, the Microsoft 365 global admin account, the Wi-Fi key. Some work. The firewall password has been changed since. The spreadsheet does not mention the domain registrar, the backup portal, the line-of-business vendor's support login, the phone system or the alarm company's remote access.

Your engineer tries to log in to each thing as they come across it. Each failure turns into an email to the client, who forwards it to the old provider, who replies days later. Meanwhile, the old provider still has global admin access to the tenant.

Why takeover access is always incomplete

Nobody holds a full list of the services a small business depends on. The old provider documents what they manage, not what the business uses. The client does not know what an admin login is for half their systems.

  • Admin accounts are named after people who left years ago.
  • Some services are in the old provider's own partner accounts, not the client's.
  • Recovery emails and phone numbers point to the old provider or a former employee.
  • Multi-factor authentication is tied to a phone you do not have.
  • Nobody checks which old accounts should be removed after the handover.

The risk in a messy takeover

Access gapRisk to you and the client
Old provider keeps admin accessChanges you did not make, and unclear responsibility
Registrar held by a former directorDomain or email at risk if it lapses
Admin MFA on an unknown phoneLocked out when you need to act
Vendor logins missingSupport cases cannot be raised
Credentials kept in the handover spreadsheetPasswords sitting in email attachments

What access you take and remove is agreed with the client and within your contract. The tracker makes sure nothing is forgotten.

The takeover tracker we build

  1. A service checklist built from your standard list (tenant, registrar, DNS, firewall, Wi-Fi, backup, antivirus, phone system, printers, line-of-business vendors) plus whatever discovery finds.
  2. For each service: who controls it now, the admin account, MFA method, recovery contacts and status (requested, received, verified, rotated, old access removed).
  3. Verification steps recorded as they are done, with the engineer's name and date, so 'received' does not mean 'assumed to work'.
  4. Credentials moved into your password vault on receipt, never stored in the tracker itself.
  5. Automatic chasers to the client contact, and to the outgoing provider if the client agrees, listing only the outstanding items.
  6. A final report for the client showing every service, who now holds admin access, and which old accounts were removed.

A takeover with nothing left dangling

The engineer starts the tracker on the day notice is given. Discovery adds services the handover missed. Each day's chaser lists the remaining items. As access arrives, it is tested, moved into your vault, and the old admin accounts are disabled once you and the client agree. The old provider's partner relationship on the tenant is noted for removal.

At the end, the client receives a clear list of what you now hold and what has been removed. The next time someone asks who has access to the firewall, the answer is on record.

The same tracker works in reverse. If the client ever moves on, you have the complete list of services, admin accounts and recovery contacts ready to hand over, which is the kind of exit you would want from the provider before you. A tidy takeover record also helps if a cyber insurer or auditor later asks the client who held privileged access and when it changed.

Checklist: takeover risk at your MSP

  • Handover information arrives as a spreadsheet or email thread.
  • You find services needing admin access weeks after go-live.
  • Old provider accounts stay active longer than they should.
  • MFA for admin accounts is tied to devices you do not hold.
  • There is no final record of access transferred and removed.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Does the tracker store passwords?

No. Credentials go into your password vault. The tracker records status and who holds access, not secrets.

Can it contact the outgoing provider directly?

Only if the client agrees. Many MSPs prefer chasers to go via the client.

Which vault tools does it work with?

Common vaults with APIs, such as the ones built into IT Glue and Hudu, or standalone password managers. We check yours.

What affects the cost?

Mainly how far it ties into your documentation tool and PSA, and how much of the discovery step you want automated.

What if the outgoing provider will not cooperate?

The tracker shows exactly what is outstanding and what has been asked for, with dates. That gives the client a clear list to take up with the provider under their existing contract, which is their conversation to have.

Keep reading

More on Problems We Solve

Start here

Tell us where your MSP loses time between the PSA and the invoice

Describe the tools you run (PSA, RMM, documentation, distributor portals) and the step that is still done by hand. We will tell you what we would build on top of them, and if a setting or integration you already pay for would do the job, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →