Co-Managed to Managed IT Transition: When to Make the Shift

A co-managed to managed IT transition makes sense once your internal IT person no longer does work that only they can do. At that point, moving to fully managed IT services usually costs less and removes a single point of failure. This guide covers the salary crossover, 6 signs the time has come, and a 90-day handover plan that protects you when your admin walks out the door.

Shift from co-managed to fully managed IT when your internal IT person leaves, when their week has shrunk to routing tickets, or when their loaded salary costs more than the price gap between the two contracts. Then run a documented handover of accounts, vendors and knowledge before their last day, not after it.

Nobody plans this move on a quiet Tuesday. It usually starts with a resignation letter. Sometimes a retirement. Occasionally it starts in a budget review, when someone finally adds the IT salary to the co-managed invoice and stares at the total for a while. Ouch.

That last one deserves more attention than it gets.

Co-managed IT is built on a split. Your internal person owns some things, the provider owns the rest, and a responsibility matrix says who does what. It’s a good model. We sell it, and co-managed IT support is the right answer for plenty of companies with a capable internal team. But a split only makes sense while both halves are doing real work, and a co-managed to managed IT transition is what happens when one half quietly stops pulling its weight or simply walks out the door with every password in their head.

So how do you tell? And what do you do next?

What does a co-managed to managed IT transition actually mean?

A co-managed to managed IT transition is the move from a shared model, where your employees and a provider split IT duties, to a fully managed model, where the provider owns day-to-day support, security, monitoring and planning under one contract. Your company keeps the decision rights. The provider takes the operational work and the accountability.

It’s a scope change. Not a vendor change. If you like your current partner, you usually keep them. Most owners do. The contract gets rewritten, the responsibility matrix collapses into one column, and the provider inherits whatever your internal person was carrying.

That inheritance is where things break.

Changing providers at the same time is a separate project with its own risks, and our guide to switching MSPs without downtime covers the parallel-run side of it. This piece stays on the model change. Still weighing the two models from scratch? Read the co-managed vs fully managed comparison first. Everything below assumes you already run co-managed and want to know when to stop.

When does fully managed IT cost less than co-managed?

At Uprite’s published starting rates, fully managed IT costs $38 more per user each month than co-managed. It costs less overall whenever your internal IT salary, fully loaded, is larger than that monthly gap multiplied by your headcount and by 12.

Here’s the arithmetic. Our published plans start at $100 per user per month for the Co-Managed IT Partnership and $138 for Fully Managed IT. The gap is $38 a month, or $456 a year, per user. Co-managed also carries the salary of the person you employ. Fully managed doesn’t. That’s the whole trick.

So is that salary bigger than $456 times your user count?

Start with the wage. The Bureau of Labor Statistics puts the median annual wage for network and computer systems administrators at $99,130 as of May 2025. Wages aren’t the whole cost. Not even close. In the June 2026 Employer Costs for Employee Compensation release, private employers paid $46.89 an hour in total compensation against $32.82 in wages and salaries, which works out to a load factor of about 1.43 once benefits, payroll taxes and insurance ride along with every paycheck. Apply that to the median admin and you get roughly $141,756 a year.

Divide by $456. You get 311 users.

Below that headcount, a company paying a median systems administrator plus a co-managed fee spends more than it would on fully managed IT at our starting rates, even before you count recruiting fees, turnover or the weeks of coverage you lose every time that person takes a vacation. Above it, the salary is spread thin enough that co-managed wins on price alone. Simple enough.

Internal role you employNational median wage, May 2025Loaded at 1.43Fully managed costs less below
Computer user support specialist$61,860$88,460194 users
Computer network support specialist$76,220$108,995239 users
Network and computer systems administrator$99,130$141,756311 users

The two support roles come from the BLS profile of computer support specialists. Your quote won’t match our starting rates exactly, and it shouldn’t be expected to, so run your own version. Divide the loaded salary by 12, then divide again by the monthly per-user gap in your quotes. That’s your crossover headcount. If you want to know what sits inside a co-managed rate before you compare, our breakdown of co-managed IT cost per user splits the platform, labor and strategy lines.

Want a worked example? Picture a 60-person company with one median-paid admin. Co-managed runs $72,000 a year in fees plus $141,756 in salary and load, or $213,756. Fully managed runs $99,360. That’s a gap of $114,396 a year. Every year. And that’s before anyone argues about coverage.

A business owner reviewing IT cost documents with a colleague at a conference table with a calculator and coffee

Now the honest part.

That math assumes your admin does work a provider would do anyway. If they run your ERP, keep the plant floor network alive or know every quirk of a line-of-business app nobody else understands, the salary isn’t overhead at all, and cutting it to save the per-user difference would be a false economy. It’s the price of knowledge no per-user fee replaces. Treat it that way. The crossover tells you where to look. It doesn’t make the call for you.

What are the signs it’s time to shift?

Six signals point toward fully managed IT. Your IT person is leaving, their role has shrunk to routing tickets, the responsibility matrix has orphaned tasks, security needs have outgrown one generalist, the salary math favors switching, or leadership wants one accountable owner.

  • Your IT person gave notice. This is the trigger that comes with a deadline.
  • Their calendar is mostly vendor calls and ticket forwarding. If the provider already does the fixing, what’s left is a very expensive dispatcher.
  • Nobody can say who tests the backups. Or who disables accounts when someone quits.
  • A cyber insurance questionnaire, a client audit or a new framework asks for controls that one generalist can’t staff around the clock.
  • The crossover lands in favor of fully managed, and the internal role owns nothing a provider couldn’t take over.
  • Two parties point at each other after every outage. Leadership wants one contract and one owner.

The first sign deserves a closer look, because it will arrive whether you plan for it or not. Median tenure with a current employer was 3.9 years in January 2024, and just 3.5 years for private-sector workers, according to the BLS Employee Tenure survey. For a one-person IT function, plan as if the person who knows every password will move on before your next laptop refresh, and build the handover plan while they are still happy and still answering the phone. Plan for it.

An overloaded in-house IT generalist working alone at a cluttered desk late at night in a mostly empty office

Replacing them isn’t quick. SHRM’s 2026 recruiting benchmarks put the median time to fill a nonexecutive role at 39 calendar days, and that clock only starts once the posting is live, which means notice periods, interviews and onboarding can leave a company running half a co-managed model for most of a quarter. Half a model is worse than either whole one.

Security is the other pressure point. In the 2025 ISC2 Cybersecurity Workforce Study, 59% of respondents reported critical or significant skills needs, up from 44% a year earlier, and 33% said their organizations lack the budget to staff security properly. That survey covered 16,029 practitioners. Big sample. One internal generalist won’t close a gap that dedicated security teams say they can’t close either.

Orphaned tasks are the quietest sign. Nobody notices them. Then a laptop gets stolen, and it turns out the backup job for that department failed in March.

When should you stay co-managed instead?

Stay co-managed if your internal IT person owns systems a provider can’t learn quickly, if you’re well past the salary crossover, or if you plan to grow the internal team soon. In those cases the split is doing its job.

Your situationBetter fitWhy
One admin, 45 users, role is mostly password resets and vendor callsFully managedThe provider already does the work, and the salary sits far above the crossover
IT manager who runs your ERP and plant floor systemsStay co-managedThat knowledge is the asset, and the provider covers everything around it
400 users with a 3-person internal teamStay co-managedPast the crossover, with depth a provider can add to
Admin resigned, 90 users, no internal candidateFully managedA 39-day median search leaves a gap the provider can close now
Hiring an IT director within 6 monthsStay co-managed for nowConverting and converting back means 2 transitions instead of 1
Two offices, frequent on-site hardware work handled by an internal techIt dependsPrice the on-site visits under a fully managed scope before deciding

One more case worth naming. If your internal person is excellent and simply buried, the fix may be a bigger co-managed scope rather than a new model, with the provider taking the routine tickets so your person gets their week back. Worth checking. Bias disclosed, we earn more on fully managed. We’d still rather say that than sell a conversion you’ll regret in a year.

And if the real debate is whether to add a second internal hire, the numbers in co-managed IT or a second sysadmin walk through that fork.

What has to happen before your IT person’s last day?

Before an internal admin leaves, secure every admin credential, document every vendor and system they touch, create emergency access accounts no single person controls, and have the provider shadow their work while they’re still around to answer questions.

Take inventory of what they actually own

The CISA Cybersecurity Performance Goals start with a regularly updated inventory of data, hardware, software, systems, facilities and personnel. Most small companies don’t have one. Nothing formal, anyway. Theirs lives in one person’s head. Get it written down while that person is still on payroll.

  • Every admin account, service account and shared password, moved into a password vault the company owns
  • Domain registrar and DNS logins, plus certificate renewal dates (a lapsed domain takes email down with it)
  • Line-of-business vendors, their support numbers and the account IDs they’ll ask for
  • Any license or warranty that comes due in the next 12 months
  • The undocumented stuff. Scheduled tasks, the printer that only works one way, the VPN exception someone made for the owner’s home office.

Fix admin access before it turns into a lockout

Microsoft describes this exact scenario in its guidance on emergency access accounts. The person with the most recent Global Administrator access leaves, and the organization can’t recover the account. That’s a real outage. The answer is 2 or more cloud-only emergency accounts with phishing-resistant sign-in, such as FIDO2 passkeys, whose credentials are stored where several authorized people can reach them. Microsoft also says to validate those accounts at least every 90 days and whenever IT staff change, which in a co-managed shop usually means the day your internal admin walks out.

Do this before a resignation. At the latest, during notice.

Hands placing a sealed envelope of emergency admin credentials into an office safe before an IT administrator leaves

Your provider’s access needs the same attention. Microsoft partners manage customer tenants through granular delegated admin privileges, which give the partner least-privileged, time-bound access that the customer must explicitly grant. The roles you granted a co-managed partner probably don’t match what a fully managed partner needs. Review them deliberately. Don’t just widen them.

Pay for overlap

This is the step owners try to skip. Please don’t. A departing admin who spends their final 2 weeks walking the provider through the environment is worth more than any documentation template, because they can show the provider which alerts are noise and which ones mean something is actually on fire. Leaving on good terms? A short paid consulting arrangement after their last day is cheap insurance for the questions nobody thought to ask. Worth every dollar.

Close the door properly

On the last day, revoke everything. CISA goal 3.D calls for a defined, enforced process to offboard staff that removes all access to systems and facilities. That covers the shared passwords they knew, the MFA methods registered to their phone and, per Microsoft, the combination on any safe that holds emergency credentials. Awkward? A little. Necessary? Completely.

What does a 90-day handover plan look like?

A workable plan runs about 90 days. The first 30 cover discovery and access, the next 30 move ownership one system at a time, and the last 30 prove the provider can run everything without the departing admin in the room.

PhaseDaysWhat gets doneFinished when
Discover1 to 30Inventory, credential vault, emergency accounts, provider shadows the adminEvery system on the inventory has a named owner
Transfer31 to 60Provider takes over tickets, patching, backups and vendor contacts one area at a timeThe admin answers questions but no longer does the work
Prove61 to 90Full restore test, offboarding drill, first monthly review under the new scopeA restore and a user offboarding both succeed without the admin

Can it go faster? Sure. If the resignation gave you 2 weeks, squeeze the discovery phase into those 2 weeks and accept that the provider will learn a few things the hard way. That’s still far better than learning them after the admin’s mailbox is disabled. Learn it early.

Managed IT support engineers with headsets taking over help desk tickets during the handover from an internal IT team

Paperwork matters too. The contract work runs alongside all of this. Rewrite the responsibility matrix so every row has exactly one owner, confirm how much on-site support the new scope includes, and read the current agreement for notice periods. Uprite locks pricing for the first 12 months and backs agreements with a 120-day satisfaction guarantee. Whoever your provider is, ask how a scope change affects any rate lock or guarantee window before you sign.

What happens to the internal IT person?

They don’t always leave. Some move into a business systems or operations role, some stay on as the on-site liaison, and some are the reason for the transition because they already resigned.

Be honest about the middle option. An internal liaison who still does IT work is co-managed with a new job title. That can be perfectly fine, as long as you price it as what it really is. Label it correctly.

If the person is staying through the change, tell them early and give them a defined role in the handover. Surprises here go badly.

Where does Uprite fit in this decision?

Uprite Services is a managed IT and cybersecurity provider that has supported businesses since 1999, with offices in Houston, Dallas and San Antonio. We run both models covered in this guide, which is why we can say plainly when co-managed is still the better deal. Sometimes it is. Our team of 42 supports 2,227 users and 444 servers, averages a 5.06-minute response time and holds a 98.4% client satisfaction score.

When a client’s admin resigns, the plan above is the work we do. Inventory first. Then access cleanup, overlap with the departing person, and a rewritten scope under our managed IT services with one owner for every task.

Make the call with real numbers

Three things decide this. Whether your internal person owns anything irreplaceable. Where their loaded salary lands against the crossover. And whether a handover plan exists before you need it.

Run the arithmetic with your own quotes. If it points toward fully managed, start the inventory this month, not the week someone hands in a letter.

What owners ask before making the shift

Will our IT bill go up when we move to fully managed?

Your provider invoice will rise by about $38 per user per month at Uprite’s published starting rates. Total IT spend can still fall, because the internal salary line goes away. For a 60-person company with a median-paid admin, the yearly difference is roughly $114,396 in favor of fully managed.

What should a departing IT admin hand over before their last day?

Everything they know that isn’t written down. That means admin and service account passwords moved into a company vault, domain and DNS access, license and warranty renewal dates, line-of-business support contacts, and a walkthrough of anything scheduled or scripted. After the handover, revoke all of their access the same day they leave.

Can we make the switch while our IT person is still serving notice?

That’s the best window you’ll get. They can answer questions and hand over credentials in person, and once they’re gone every question becomes a guess.

Realistically, how long does the handover take?

About 90 days for a clean transition, split into discovery, transfer and proof. A forced resignation can squeeze it into 2 weeks, but expect the provider to learn a few things the hard way after the admin leaves.

Do we need a new provider, or can our co-managed partner take over?

Usually your current partner is the faster path, since it already has monitoring agents deployed, some documentation and a working relationship with your team. Test it first. Ask the partner to complete one full restore and one user offboarding without your admin’s help before you sign a fully managed scope, and walk away if either one stalls.

At what size does fully managed stop making financial sense?

Around 311 users, if you employ one systems administrator at the national median wage and pay Uprite’s starting rates. Above that, the salary spreads thin enough for co-managed to cost less. With a help desk technician instead of an administrator, the crossover drops to about 194 users.

See where your company lands

Bring your current co-managed scope and headcount. A Uprite expert will work out your crossover number and show what a fully managed scope would cover before anyone signs anything.

Speak to an IT Expert

About Author

Learn More