How to Switch MSPs Without Downtime

You switch MSPs without downtime by taking control of your own admin credentials before you give notice, then moving one system at a time during a 30-day overlap where both providers still hold access. Sequence protects you, not the size of the new provider.

Changing MSPs is a sequencing problem, not a technical one. Confirm you hold your own Microsoft 365 global admin, domain registrar, and backup accounts before anyone gives notice. Read the contract for the auto-renewal window. Run both providers in parallel for roughly 30 days, then cut over one system at a time with a tested rollback on each. In that order, most Texas businesses change providers without losing a working hour.

What does switching MSPs without downtime actually mean?

A zero-downtime MSP switch is a staged handover. Your outgoing and incoming providers both hold defined responsibilities for a fixed overlap window, and every system moves on its own scheduled cutover with a tested rollback behind it. Nothing goes dark because nothing moves all at once.

That is the whole idea, and it is very different from how most switches get sold. The pitch you usually hear is that the new provider will “handle everything” over a weekend. Sometimes that works. When it does not, you find out on a Monday, with 40 people unable to reach email. A well-run managed IT services transition spreads the risk across weeks instead of concentrating it in 48 hours.

The stakes are worth naming. In the 2025 Calyptix and ITIC SMB downtime survey of 715 organizations, businesses with 20 to 100 employees reported hourly downtime costs of roughly $8,000 to $25,000, and 8% put the figure above $25,000. A transition that loses you half a day is not a minor inconvenience. It is a five-figure event.

Why most MSP switches lose hours

Downtime during a provider change almost never comes from the technology. It comes from the order things happen in. Nearly every mid-transition emergency call we take traces back to 1 of these 4 patterns.

  • Notice went out before ownership got checked. The minute your current provider knows you are leaving, their help becomes voluntary. If they hold the only global administrator account on your Microsoft 365 tenant, you are negotiating from behind.
  • Everything moved on one weekend. Big-bang cutovers stack email, endpoints, backups, and firewall changes into 48 hours with no rollback point. One wrong DNS record and Monday becomes a queue of tickets nobody can answer.
  • Nobody read the agreement. Auto-renewal is the most common trap in managed services contracts, and many require written notice 60 to 90 days ahead of the renewal date. Miss the window and you are paying two providers at once.
  • The backups were never restored, only monitored. A green dashboard is not proof. Plenty of businesses learn their real retention policy the hard way, right after the old provider’s tooling stops protecting them.

Here is an honest note that cuts against our own interest. Not every bad experience justifies a switch. If your complaint is one slow ticket or one engineer you did not click with, changing providers costs more in disruption than fixing the relationship. Look for a pattern instead. Our guide to the warning signs you should switch your IT provider is a better first read than a termination letter.

What you have to control before you give notice

A business owner signing in to a cloud administration console to verify who holds global administrator access before giving notice to an MSP

Before you tell anyone you are leaving, you need to be able to sign in to your own environment without asking permission. That single step removes almost every point of pressure an uncooperative incumbent has over you. Work through this quietly, over 1 or 2 weeks, using accounts you already have.

  1. Sign in to the Microsoft 365 admin center and confirm a named account your company controls holds the Global Administrator role.
  2. Open the Partner relationships page and review which partners hold delegated access to your tenant, following Microsoft’s guide to reviewing partner admin privileges.
  3. Log in to your domain registrar directly, not through a link your provider sent you, and confirm the registrant is your business.
  4. Confirm you can edit a DNS record yourself, then lower your MX and A record TTL values to 300 seconds at least 2 weeks before any planned cutover.
  5. Log in to your backup console, check the retention setting, and run a real file-level restore test.
  6. Verify the local administrator password on your firewall and core switches works without a provider VPN.
  7. List every line-of-business application and confirm which person at your company the vendor treats as the account owner.
  8. Check whether your Microsoft and security licenses sit on your own tenant or inside the provider’s CSP agreement.

Delegated access deserves a closer look than most owners give it. Microsoft moved partners off the old blanket model to Granular Delegated Admin Privileges, which grants specific roles for a limited, customer-approved period. As Microsoft’s delegated administration primer lays out, that access is yours to review. You can also remove it yourself from the Partner relationships page in a few clicks, a process Microsoft documents in its customer-led removal guide. Do not do that until your new provider is ready, but know that the switch is under your control and not your provider’s.

AssetWho should hold itHow to verify it today
Microsoft 365 global adminA named account your company ownsSign in to the admin center and check the role assignment yourself
Delegated partner accessVisible to you and revocable by youReview the Partner relationships page in the Microsoft 365 admin center
Domain registrarYour business, in your business nameLog in to the registrar directly and check the registrant contact
DNS hostingYour businessEdit a low-risk record yourself and confirm the change publishes
Backup consoleYour business or a shared owner accountSign in, read the retention policy, and run a restore test
Firewall and switch adminYour businessConfirm the local admin credential works without a provider tunnel
Line-of-business appsA named owner at your company per appAsk each vendor who they have on file as account owner
Licenses and subscriptionsPurchased under your own tenant where possibleCheck whether billing sits with you or inside a provider CSP agreement

If you cannot tick most of those boxes, you are not ready to give notice yet. You are ready to start fixing your ownership position, which is worth doing whether you switch or stay.

What to check in your contract before you send the letter

A small business owner and an advisor reading a managed services agreement with the termination and auto-renewal clause highlighted

The termination clause decides how expensive your exit gets, and almost nobody reads it until they need it. Pull the signed agreement, not the proposal, and find these 5 things before you write anything.

  • The notice period. Most managed services agreements require 30, 60, or 90 days of written notice. Note the exact method the contract demands, because certified mail and a named signatory are common requirements.
  • The auto-renewal date. Many agreements roll into another full 12-month term unless you give notice well before the anniversary. Put that date on a calendar today.
  • Data and credential return obligations. Good contracts specify what gets handed back and how fast. Attorneys at Scott and Scott LLP note that termination clauses should cover transfer of responsibilities, data, and assets to the company or its new provider.
  • Early termination fees and unamortized hardware. Some providers finance equipment inside the monthly rate. Find out what balance rides on the gear before you plan a date.
  • Whatever is missing. A contract with no offboarding language at all is not a green light. It means the terms get negotiated when tempers are already up, so send a written request naming the specific artifacts you expect back.

One thing worth knowing if the conversation turns tense. Your provider does not get to hold your credentials hostage over a billing dispute, and a CSP partner cannot block you from holding Global Administrator on your own Microsoft tenant. They can decline extra offboarding help you are not entitled to. That is a very different thing from locking you out.

What a 30-day parallel run looks like

Two IT support teams working in the same network operations room during an MSP overlap period, one monitoring dashboards and one documenting systems on a whiteboard timeline

The overlap is the part that buys you a clean switch, and it is the part businesses try hardest to shorten because they resent paying twice. Industry practice runs anywhere from 1 week to 6 weeks. For most small and midsize Texas environments, 30 days is the sweet spot. It gives the incoming team a full monthly cycle of patching, backups, and month-end workload before they own the outcome.

During the overlap, responsibility should never be shared vaguely. Each side owns something specific, and you should be able to name who is on the hook for an outage on any given day.

WindowOutgoing provider ownsIncoming provider ownsWhat you should receive
Days 1 to 10All support and incident responseDiscovery, documentation, agent deploymentA written asset and application inventory
Days 11 to 20Support, plus answering handover questionsShadowing the ticket queue, restore testingA completed restore test, not a green dashboard
Days 21 to 30Escalation only, on standbyPrimary support and staged cutoversOne system moved per scheduled window
Days 31 to 45Nothing, access revoked and confirmedEverythingWritten confirmation that old access is closed

Notice what is not in that table. There is no single day where everything changes hands. If your prospective provider proposes a hard cutover date with no overlap, ask them what the rollback plan is for each system. A confident answer sounds like a sequence. A vague one sounds like optimism.

How each system moves without breaking

A network engineer at a dual-monitor workstation running a staged systems cutover, checking a network topology map against a migration step checklist

Sequence matters inside the cutover too. Move the systems with the cleanest rollback first, and save anything that touches identity or DNS for a window when your team is not depending on it.

Microsoft 365 and delegated admin

Your new provider requests a GDAP relationship and you approve it from your own tenant. Both partners can hold granular roles at the same time, which is exactly what you want during the overlap. Only after the incoming team has confirmed working access do you remove the old relationship. Microsoft’s GDAP documentation covers what each role grants, and it is worth skimming so you approve the smallest set that gets the job done.

Email and DNS

This is where real downtime hides. Lower your TTL values to 300 seconds at least 2 weeks before any record change, so a mistake propagates back in minutes instead of a day. If mail flow itself is moving, run split delivery rather than a single hard MX swap. And schedule DNS work for a Tuesday evening, not a Friday, so somebody senior is available on Wednesday if anything looks off.

Endpoints, monitoring, and security agents

Two remote monitoring agents can coexist on a workstation for a short window. Two endpoint protection products usually cannot. Plan for the incoming provider to deploy monitoring early and hold the security agent swap until the day the old tooling is removed, machine by machine. Expect a few laptops that never check in, and budget time to chase them. Remote and hybrid staff are almost always the stragglers.

Backups and retention

Start the new backup chain before you cancel the old one, and keep a paid export or an extended retention window on the outgoing platform for at least 30 days past cutover. Some backup vendors destroy client data shortly after a subscription ends. Confirm in writing what happens to your historical restore points on the day service stops, then verify a restore from the new system before you rely on it.

Firewall, network, and documentation

Firewall and switch credentials should change hands before the final week, not during it. Ask the incoming provider for a written network diagram, a credential inventory in a password manager you own, and a documented escalation path with real names and phone numbers. If your new provider cannot produce documentation by day 20, that is a preview of what support will feel like in month 6.

What to do if your current provider stalls

Most offboardings are professional. A minority are not, and the failure mode is usually delay rather than outright refusal. Requests go unanswered, documentation arrives incomplete, and the clock runs while you wait.

  • Put every request in writing, dated, with a named list of artifacts. Verbal asks disappear. A written request naming specific credentials, exports, and documents creates the record you need if this ever escalates.
  • Escalate to the owner, not the account manager. Most MSPs are small businesses that care about their reputation in a market as tight as Houston or Dallas. A calm note to leadership moves faster than another ticket.
  • Rebuild rather than wait, where rebuilding is cheaper. A missing firewall password costs a scheduled factory reset and 2 hours. Waiting 3 weeks for it costs more.
  • Keep your own access current the whole time. If you hold global admin, DNS, and your backups, a slow incumbent can inconvenience you. They cannot hold you hostage.

The businesses that get stuck are almost always the ones that gave notice first and checked ownership second. If you have already sent the letter and you are reading this now, start with the Microsoft 365 admin center and the domain registrar today. Everything else is recoverable.

What switching actually costs

Budget for 3 things. There is the overlap, where you pay both providers for part of a month. There is onboarding, which some providers charge for and some absorb. And there is remediation, the work of fixing whatever the last provider left undone, which is genuinely variable and should be quoted separately rather than buried in your monthly rate.

What you should not pay for is a discovery phase that produces nothing you can keep, or an onboarding fee with no deliverable attached to it. Ask what artifact you receive for every dollar of transition cost. If the answer is a documented network diagram, a credential inventory, a tested restore, and a written 90-day plan, that is real. If the answer is vague, it is a markup. For a broader view of what ongoing managed IT should cost in this state, our Texas MSP Pricing Index tracks the actual ranges, and if you are weighing whether to hand over everything or keep some work in house, managed versus co-managed IT breaks that decision down.

How Uprite runs an MSP switch

We have been supporting Texas businesses since the year 2000, with staffed teams in Houston, San Antonio, and Dallas. That matters during a transition because somebody can be standing in your office the week the endpoints move, not routing a ticket to another time zone.

Our onboarding runs on the same sequence described above. Discovery and documentation first, restore testing before we touch anything, then staged cutovers with a rollback point on each. Our average response time is just over 5 minutes once we own support, and every engagement is backed by a 120-day satisfaction guarantee, which is our way of saying we would rather you be able to leave than feel trapped. Rates are also guaranteed not to increase during your first year.

One more thing we build into every transition, because Texas changed the rules. SB 2610 took effect on September 1, 2025, and it shields businesses with fewer than 250 employees from punitive damages in a breach lawsuit if they maintain a qualified cybersecurity program, as summarized by Spencer Fane. A provider change is the natural moment to close those gaps, so our cybersecurity team maps your controls against the standard during onboarding rather than treating it as a separate project later. The SB 2610 compliance guide walks through the tiers.

If you want the shorter version of this process written for a general provider change rather than an MSP specifically, we cover it in how to transition from one IT provider to another.

Planning a provider change this quarter?

We will walk your environment, tell you exactly what you need to control before you give notice, and give you a written week-by-week transition plan. No obligation to switch. Call (866) 570-3065 or request a consultation.

Get a transition plan

What Texas businesses ask before changing MSPs

Can my team keep working normally while we switch MSPs?

Yes, in a staged transition. Your staff should notice a new support phone number and email address, and very little else. The technical work happens in scheduled evening windows, one system at a time, with the outgoing provider still covering incidents until the new team formally takes over support.

How long does it take to switch to a new MSP?

Plan on 30 to 90 days from signing to full handover, with day-to-day support usually live in the first 2 weeks. The overlap window itself is typically 30 days. Environments with on-premises servers, multiple sites, or heavy compliance obligations sit at the longer end of that range.

What happens to my data during the transition?

Nothing moves until a restore has been tested. Your new provider should start a fresh backup chain before the old one stops, keep the outgoing platform in extended retention for at least 30 days past cutover, and prove a real file recovery from the new system before you depend on it.

What if my old provider refuses to hand over passwords?

They can slow you down, but they cannot lock you out of accounts you own. Send a dated written request naming each credential, escalate to the owner rather than the account manager, and rebuild anything cheaper to reset than to wait for. Holding credentials over a billing dispute rarely survives scrutiny.

Do I really have to pay two providers at the same time?

For part of one month, usually yes, and it is the best money in the whole project. The overlap is what lets the incoming team document your environment and test restores while somebody is still accountable for incidents. Skipping it is how a switch turns into an outage.

Should we switch during our busy season?

Almost never. Pick a window with a light month-end, no audits, and no major project deadlines, then schedule cutovers midweek so senior people are available the following morning. Retail and professional services firms in Texas often find late spring or early fall works better than either year-end or summer.

Will changing MSPs affect our cyber insurance?

It can. Most policies ask about monitoring, backup, and multi-factor authentication controls, and a gap during transition is exactly the kind of thing an insurer asks about after a claim. Tell your broker the dates in advance and keep monitoring coverage continuous across the overlap.

About Author

Learn More