A spreadsheet of passwords, half of them wrong
The client has given notice to their old IT provider, who is being polite but not quick. The handover arrives as a spreadsheet: firewall admin, a couple of server passwords, the Microsoft 365 global admin account, the Wi-Fi key. Some work. The firewall password has been changed since. The spreadsheet does not mention the domain registrar, the backup portal, the line-of-business vendor's support login, the phone system or the alarm company's remote access.
Your engineer tries to log in to each thing as they come across it. Each failure turns into an email to the client, who forwards it to the old provider, who replies days later. Meanwhile, the old provider still has global admin access to the tenant.
Why takeover access is always incomplete
Nobody holds a full list of the services a small business depends on. The old provider documents what they manage, not what the business uses. The client does not know what an admin login is for half their systems.
- Admin accounts are named after people who left years ago.
- Some services are in the old provider's own partner accounts, not the client's.
- Recovery emails and phone numbers point to the old provider or a former employee.
- Multi-factor authentication is tied to a phone you do not have.
- Nobody checks which old accounts should be removed after the handover.
The risk in a messy takeover
| Access gap | Risk to you and the client |
|---|---|
| Old provider keeps admin access | Changes you did not make, and unclear responsibility |
| Registrar held by a former director | Domain or email at risk if it lapses |
| Admin MFA on an unknown phone | Locked out when you need to act |
| Vendor logins missing | Support cases cannot be raised |
| Credentials kept in the handover spreadsheet | Passwords sitting in email attachments |
What access you take and remove is agreed with the client and within your contract. The tracker makes sure nothing is forgotten.
The takeover tracker we build
- A service checklist built from your standard list (tenant, registrar, DNS, firewall, Wi-Fi, backup, antivirus, phone system, printers, line-of-business vendors) plus whatever discovery finds.
- For each service: who controls it now, the admin account, MFA method, recovery contacts and status (requested, received, verified, rotated, old access removed).
- Verification steps recorded as they are done, with the engineer's name and date, so 'received' does not mean 'assumed to work'.
- Credentials moved into your password vault on receipt, never stored in the tracker itself.
- Automatic chasers to the client contact, and to the outgoing provider if the client agrees, listing only the outstanding items.
- A final report for the client showing every service, who now holds admin access, and which old accounts were removed.
A takeover with nothing left dangling
The engineer starts the tracker on the day notice is given. Discovery adds services the handover missed. Each day's chaser lists the remaining items. As access arrives, it is tested, moved into your vault, and the old admin accounts are disabled once you and the client agree. The old provider's partner relationship on the tenant is noted for removal.
At the end, the client receives a clear list of what you now hold and what has been removed. The next time someone asks who has access to the firewall, the answer is on record.
The same tracker works in reverse. If the client ever moves on, you have the complete list of services, admin accounts and recovery contacts ready to hand over, which is the kind of exit you would want from the provider before you. A tidy takeover record also helps if a cyber insurer or auditor later asks the client who held privileged access and when it changed.
Checklist: takeover risk at your MSP
- Handover information arrives as a spreadsheet or email thread.
- You find services needing admin access weeks after go-live.
- Old provider accounts stay active longer than they should.
- MFA for admin accounts is tied to devices you do not hold.
- There is no final record of access transferred and removed.