What should the first 90 days with a new MSP look like?

Short answer

The first 90 days with a new managed IT provider should run in three phases: secure handover of admin access and documentation in the first month, urgent security fixes such as MFA, backups and patching in the second, and stabilization with a documented environment and IT roadmap in the third. You should see measurable progress and written deliverables at each checkpoint, not just tickets closed.

Days 1 to 30: take control safely

The first job is to get access right without breaking anything or leaving the old provider's doors open.

  • Inventory users, devices, licenses, domains, cloud services and vendor contracts.
  • Confirm you, the customer, own the Microsoft 365 tenant, domain registrar and key vendor accounts.
  • Create two cloud-only emergency access accounts protected by passkeys or certificate-based authentication, as Microsoft recommends, and store their credentials safely.
  • Grant the MSP least-privilege, time-bound access, for example through Microsoft's granular delegated admin privileges (GDAP), rather than shared Global Admin passwords.
  • Remove or disable the previous provider's accounts, tools and remote-access agents.
  • Deploy monitoring and endpoint protection, and start the help desk.

Days 31 to 60: close the urgent gaps

  • Enforce MFA for every user and every technician account that touches your environment, starting with admins.
  • Verify backups by restoring real data, including Microsoft 365 mailboxes and files.
  • Bring operating systems, firmware and key applications up to a supported, patched state.
  • Turn on logging and alerting, and agree how long logs are kept. CISA and its partners recommend MSP customers retain key logs for at least six months.
  • Report the risks found so far, ranked, with what is fixed and what needs a decision.

Days 61 to 90: stabilize and plan

  • Deliver written documentation: network diagram, asset list, admin-account list, backup scope and recovery steps.
  • Agree the incident response plan, including who calls whom and how the MSP notifies you.
  • Review ticket trends to find recurring problems worth fixing at the root.
  • Present a 12-month roadmap and budget covering hardware refresh, licensing, security and projects.
  • Hold a 90-day review against the contract's service levels.

If you are moving to co-managed IT

When internal IT staff remain, onboarding also means drawing the line between teams. Write a responsibility matrix covering help desk tiers, patching, security alerts, user changes and projects, and agree how tickets move between you. CISA's joint advisory on MSP risk emphasizes that contracts should state who owns hardening, detection and incident response, which applies just as much when two teams share the work.

Warning signs

Be concerned if, after 90 days, you still do not have documentation, the MSP uses shared admin credentials, MFA is not enforced on technician accounts, backups have not been restored once, or you cannot see the ticket history. These are basics, and a provider that has not delivered them in a quarter is unlikely to deliver them later.

Onboarding is a two-way job. Name one internal owner who can approve access changes and make decisions, share contracts and vendor contacts early, and tell the provider about upcoming moves, hires and projects. Waiting on customer-side decisions or credentials is a common source of delay, so set a weekly check-in for the first quarter.

Common follow-up questions

How long should MSP onboarding take?

Initial transition work such as access, monitoring and help desk often starts within weeks, but full onboarding with fixes, documentation and a roadmap typically takes about a quarter. Larger or more complex environments take longer. Agree the milestones in the contract so you can measure progress.

What should we get from the old IT provider?

Admin credentials or a handover of every account, domain and registrar access, license records, network and firewall configurations, backup locations and keys, vendor contacts and any documentation. Then make sure their access is removed. CISA notes MSP accounts are easily overlooked when contracts end.

Should the MSP have Global Administrator access?

Only as much as the work requires. Microsoft's GDAP model lets partners hold granular, time-bound roles that customers approve, rather than standing Global Administrator rights. Keep your own emergency access accounts so you never depend on the provider to get into your tenant.

Need help with this?

LAN Service Group onboards small and mid-size businesses as their full outsourced IT department or as a co-managed partner, starting with secure access handover, security fixes, documentation and a written IT roadmap.

Talk to LAN Service Group (888) 281-7243

Sources