Fast answer
Do not give notice until you hold Microsoft 365 Global Admin, DNS, firewall, backup, and ISP portal access in accounts your company owns. Then run a 30-day overlap: the outgoing provider keeps monitoring while the incoming team documents, restore-tests backups, and shadows tickets. Cut over admin, alerting, and after-hours contacts in one weekend window. Email, files, and line-of-business apps stay in your tenant the entire time.
When a switch is justified - and when it is not
This guide is not about choosing your first IT company. If you are still comparing quotes, start with the Coquitlam hiring questions and the Vancouver budget guide. A switch is a different job: you already have a provider, and the risk is losing access during the exit.
Switch when two or more of these are true for 90 days:
- Critical tickets sit without a named owner, or after-hours calls roll to voicemail.
- Nobody at your company can log into Microsoft 365 as Global Admin, the firewall, or the backup console.
- Backups report “success” but nobody has restored a file or a mailbox in the last 12 months. Read why backups fail when needed before you assume the copies are usable.
- Every change requires the same one technician, and documentation does not exist outside that person’s laptop.
- Security work is sold as a constant extra, or MFA and offboarding are still optional.
Do not switch in the middle of an active ransomware incident, a same-week office move, or a Microsoft 365 tenant migration. Stabilize first with on-demand engineers, then plan the handover.
Collect the handover pack before you give notice
The outgoing provider’s leverage is access, not skill. Once your company owns the accounts, the rest is scheduling. Build this pack in a shared folder your leadership can open without the current IT company:
- Identity: Microsoft 365 or Google Workspace tenant name, Global Admin in a company mailbox (not a vendor domain), MFA methods, Conditional Access, and who pays the Microsoft invoice.
- DNS and email: registrar login, nameservers, SPF/DKIM/DMARC, and the mail filtering vendor. If outbound mail is already failing, fix deliverability as a separate track.
- Network: firewall model and serial, admin URL, VPN users, switch locations, and WiFi controller. For dense towers, see how we handle Vancouver office networks.
- Backup: product name, retention, immutability, last restore test date, and whether copies are reachable by the same admin who manages the servers. Pair this with tested backup and recovery.
- Vendors: ISP account numbers (Shaw/Rogers, TELUS, Beanfield, or building riser), phone system, copier, alarm, and any line-of-business host. Cloud workloads belong under cloud and hosting services, not a mystery login.
- People: staff list with licences, shared mailboxes, contractors, and a current offboarding example.
If the current provider will not share credentials, start with what you already own: domain registrar, Microsoft 365, and ISP portals. Reset those. Then recover firewall and backup access through the vendor. Withholding company credentials is a reason to accelerate the exit.
Run a 30-day overlap, not a Friday surprise
A zero-downtime switch is an overlap, not a swap. Keep the outgoing contract live through one billing cycle while the incoming team does discovery. That is how managed IT takeovers should work:
- Week 1: read-only discovery. Network diagram, licence true-up, backup restore of one mailbox and one shared folder, and a written gap list.
- Week 2: monitoring installed in parallel. Alerts go to the incoming team; the outgoing team still owns after-hours until the cutover date.
- Week 3: shadow tickets. Incoming engineers resolve a sample of real requests with the outgoing team still on the contract.
- Week 4: cutover window booked. Admin ownership, DNS, backup jobs, RMM, and after-hours numbers change in one verified block.
Clinics and professional firms should add a PIPA-aware access review during week 1. Healthcare context lives on our healthcare IT page; legal and accounting teams should use the matching industry guides.
Cut over on a planned window, then run 14 days of hypercare
Pick a Friday evening or Saturday morning. Staff should not notice anything except a new ticket email address on Monday.
- Confirm Global Admin, DNS, and backup consoles before touching monitoring.
- Move RMM, antivirus, and firewall alerting to the incoming team. Leave the old agent in place until Monday’s health check passes.
- Update after-hours contacts, ISP escalation, and Microsoft partner of record.
- Send staff a one-page “who to call” note. Keep emergency IT as a backup path if an unrelated outage hits during the window.
- Hypercare: 14 days of faster response, a daily backup check, and a written punch-list. Then the new SLA starts.
If production lines or warehouses cannot pause, treat the cutover like after-hours production support: named owner, rollback, and a morning handover to the day team.
Lock-in traps we see on Lower Mainland takeovers
These are the delays that turn a two-week handover into two months:
- Vendor-owned Microsoft tenant. If the tenant sits under the provider’s partner centre and billing, transfer partner of record before notice day.
- Backup product licensed to the provider. Export or re-licence before the old contract ends, then restore-test. Do not wait for a disaster to learn the copies were never yours. Use the ransomware recovery playbook as the restore standard.
- Firewall still on the provider’s support contract. Serial numbers and Fortinet/Cisco support must move with the hardware.
- Building riser and ISP accounts in a technician’s name. Common in older Vancouver and Burnaby towers. Change the account owner with the carrier while the outgoing provider is still answering email.
- Notice periods that block overlap. If the contract forbids a parallel provider, pay the overlap month. It is cheaper than a Monday without email.
How the same handover looks in each city
The identity and backup work is the same everywhere. The on-site piece is not:
- Vancouver and downtown towers: landlord access windows, shared telecom rooms, and dense WiFi. Book the riser visit before the weekend cutover.
- Coquitlam headquarters-area offices: fastest for same-day hardware swaps from our Lincoln Avenue office. Pair the handover with the local cost guide if the old quote was never scoped.
- Surrey multi-site firms: inventory each location. City Centre, Guildford, Newton, and South Surrey often have different ISPs and different on-site contacts.
- Burnaby and Richmond warehouses: scanner WiFi and shipping stations need a coverage check during overlap, not after the old provider is gone.
- Langley, Delta, and the North Shore: longer on-site lead times. Do discovery remotely, then book one combined visit per site.
Full coverage is listed on service areas.
Handover scorecard for Greater Vancouver businesses
| Item | Ready to switch | Not ready |
|---|---|---|
| Microsoft 365 admin | Global Admin in a company mailbox, MFA on that account. | Only the vendor can approve changes or reset MFA. |
| DNS and registrar | Company-owned registrar login, documented nameservers. | Domain sits under a technician’s personal account. |
| Backups | Restore tested in the last 90 days; licence transferable. | Job emails say success; no restore evidence. |
| Network | Firewall admin, diagrams, and ISP account numbers on file. | Nobody knows the firewall password or circuit ID. |
| Overlap | Outgoing contract still active through cutover plus 14 days. | Notice already given; no parallel coverage. |
| Staff communication | New ticket path and after-hours number published before Monday. | Users still email the old technician personally. |
Common mistakes that cause downtime during a switch
- Giving notice before you hold Global Admin and DNS.
- Letting the outgoing provider uninstall monitoring on Friday with no replacement.
- Assuming backups are yours because they ran on your servers.
- Changing firewalls, WiFi, and the help desk on the same night.
- Skipping a restore test because “the dashboard is green.”
- Leaving after-hours calls on the old number for a month.