Guides & Checklists
The first 30 days with a new IT provider: what onboarding should look like, week by week
What happens in the first 30 days with a new IT provider: discovery, credentials, audit, monitoring, security fixes, backup test, helpdesk briefing and report.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
In the first 30 days a new IT provider should gather admin credentials and documentation, audit every device, the network, Microsoft 365, security controls and backups, install monitoring, fix urgent security gaps such as missing MFA, test a backup restore, brief staff on the helpdesk, document the environment and present a prioritised findings report. Major changes wait until after that.
The worry about changing IT provider is almost always about the changeover, not the new provider. What happens on day one? Will anything break? Who do staff call? This guide sets out what a well-run first month looks like, week by week, so you can judge whether the onboarding you are offered is thorough, and so you know what to expect. The short answer: a lot of looking, some quick security fixes, and no big changes until you have seen the findings.
Before day one
A good provider does not wait for the contract start date to begin.
- Kick-off conversation. How the business works, which applications matter, who the key people are, what the previous provider did well and badly, what has been tolerated for too long. A law firm and a plant hire depot have different priorities, and the provider needs to know yours.
- Credentials request. A formal list to the outgoing provider: global admin for Microsoft 365, domain registrar and DNS, firewall, switches, Wi-Fi controller, servers, backup systems, remote-access tools. What to ask for is set out in how to switch IT support provider.
- Existing documentation. Whatever exists, however patchy.
- Staff communication drafted. A short note for your team: who the new provider is, the new number and portal, and that nothing else changes for them.
Week one: access and discovery
The first week is about seeing everything.
Gaining access. The provider creates its own named administrator accounts rather than using shared ones, and confirms it can reach every system it will be responsible for. Anything the outgoing provider has not handed over is recovered through the vendor.
Discovery. Network scanning finds every device, including the ones nobody remembered: the old NAS in the cupboard, the CCTV recorder on the main network, the printer with a public web interface. Microsoft 365 reporting lists every account, licence and mailbox. Hands-on inspection of the comms cabinet and any servers records what is physically there.
Hardware review. Age, warranty status and condition of every computer, server, switch, access point and firewall. The output is a list of what is out of support and what will need replacing in the next year.
Software and licences. Operating system versions, applications, Microsoft 365 licence assignment against headcount. It is common to find licences still assigned to leavers, and occasionally to find the business under-licensed.
Backup check. Whether backups exist, what they cover, where they go, and whether anyone has ever restored from them.
Week two: monitoring, security and the urgent fixes
With a picture of the environment, the provider installs its tools and closes the gaps that cannot wait.
Monitoring. RMM agents on every computer and server, reporting health, updates and backup status centrally. From this point the provider sees problems as they develop. The outgoing provider's agents and remote-access tools are removed.
Endpoint security. Antivirus reviewed and, where it is not a managed EDR platform, replaced. Managed centrally from now on.
Security assessment. Measured against the five controls in the NCSC's Cyber Essentials scheme: firewalls, secure configuration, security update management, user access control and malware protection. The findings that most often need immediate action are:
- MFA not enforced on Microsoft 365.
- Leavers with live accounts.
- Everyday user accounts with administrator rights.
- Patching months behind.
- Shared passwords and no password manager.
- Firewall on old firmware with remote management open to the internet.
Each of these is fixed in week two with your agreement, because each is a route to a breach and each is quick to close.
Backup restore test. A file and, where practical, a system restored from backup, timed and recorded. If the backup does not restore, this is the week you find out, rather than the day you need it.
Week three: helpdesk, priorities and documentation
Helpdesk briefing. Staff are told how to log tickets, what the priority levels mean, and what to expect. A one-page guide is usually enough. The internal contact learns how escalation works and how to declare an urgent issue.
Priority definitions. What counts as a P1 (everyone down), P2 (a team or key system), P3 (one person, with a workaround) and P4 (a request), and the response commitments for each under the SLA. See what an IT support SLA is.
Documentation. The provider writes up what it found: network diagram, device inventory with warranty dates, server and firewall configurations, Microsoft 365 structure, licence records, backup arrangements and a recovery procedure. This is shared with you, because it is yours. Businesses that have operated for years without documentation often find this the most useful output of the month.
Asset register. Devices, software, licences, warranties and subscriptions, in one place, for budgeting and for the next audit.
Week four: findings and plan
The month ends with a report and a conversation.
The findings report covers what is in good order, what is at risk, what was fixed during onboarding, what needs doing next and roughly what it will cost. Typical items: two laptops out of warranty, a server due for retirement into Microsoft 365, guest Wi-Fi sharing a network with the servers, no Microsoft 365 backup, awareness training never run.
Prioritisation. Not everything needs doing at once. The provider ranks recommendations by risk and cost so you can decide what to do this quarter and what to plan for next year. Security and backup usually come first.
The roadmap. A simple plan for the next twelve months: refresh cycle, licence review, security improvements, any projects such as a cloud move or an office relocation. Reviews are scheduled, typically quarterly, so the plan is revisited rather than filed.
What good onboarding does not do
It does not make large changes in the first month. Migrating email, replacing the network or retiring a server are projects, scheduled after the findings have been discussed and agreed. A provider that arrives and starts rebuilding things in week one is either fixing an emergency or not listening.
It does not disappear after the report. The point of the first month is to set up the routine that follows: alerts reviewed daily, patches applied weekly, backups tested monthly, reviews quarterly. What that routine looks like is described in what does an IT support company do?.
Common complications
- Missing credentials. Recovered through Microsoft, the registrar and hardware vendors. Slower, not fatal.
- No documentation. Rebuilt through discovery. Adds a week.
- Unsupported software. An application on a version the vendor no longer supports, running on a server that cannot be patched. Isolated in the short term, planned out in the roadmap.
- Multiple sites. Each needs its own discovery and visit. Onboarding a multi-depot business such as Mr Plant Hire is a longer exercise, with site-to-site connectivity and per-site Wi-Fi to review.
- Surprises. The undocumented server under a desk. The domain registered in a former employee's personal account. The backup that has been failing silently since spring. Better found in week one than in a crisis.
What to do next
If you are considering a change and want to know how this process would run for your business, our switching IT provider page describes the overlap period, what we ask the outgoing provider for, and what you receive at the end of the first month.

