There’s a particular kind of dread that comes with leaving an IT provider you no longer trust. You start to wonder what exactly they’re holding. The administrator passwords. The keys to your email. Access to the domain your whole brand runs on. And the uncomfortable question sits there: if the relationship goes badly, can they make leaving painful, or even lock you out of your own business?
It’s a fair worry, and we’ll be honest with you. A small number of providers do behave this way, holding access over clients to keep them from walking. Most don’t. But the way you protect yourself is the same either way. You start from a clear principle, you ask for the right things in writing, and you don’t wait until the relationship has already gone cold to begin.
The principle is simple. Your data is yours. Your accounts are yours. The administrative control over systems your business depends on is yours. A provider manages these things on your behalf, but ownership never transfers to them. Holding it back from you isn’t standard practice. It’s a problem.
Start before you announce you are leaving
The best time to confirm you have control of your own systems is while everyone is still on good terms. If you have already decided to switch, do this quiet inventory before you give notice. Once a provider knows they are being replaced, cooperation sometimes slows down, and you would rather discover a missing piece while goodwill still exists.
This isn’t about being sneaky. It’s about not handing anyone the ability to make your exit difficult. If your access turns out to be clean and complete, wonderful, you’ve lost nothing. If it doesn’t, you’ve just found out at the only time you can still fix it easily.
The list of what to reclaim
Work through these deliberately. Each one is a place where control can quietly sit with the provider instead of you:
- Your domain name registrar. This is the account where your web domain is registered, and it is the single most damaging thing to lose control of. Whoever holds it can affect your website and your email. Confirm you can log in to the registrar directly, not just that “it is handled.”
- Email and identity administration. Your Microsoft 365 or Google Workspace tenant should have a global administrator account that belongs to you, in your control, separate from any account tied to the provider.
- Your password vault. If your provider stored your credentials in their password management system, you need an export or a copy of everything that is yours before you part ways.
- Server and network administrator credentials. The top-level passwords for your servers, firewall, and network equipment.
- Backups and your actual data. Not just confirmation that backups exist, but a clear answer to where your data physically lives and how you get a complete copy of it.
- Licensing and accounts. Software licenses, your internet and phone accounts, and any service registered on your behalf.
If you want a structured place to track all of this so nothing slips during a tense handoff, our MSP transition and offboarding checklist lays out every category to work through.
Ask in writing, and be specific
When you do make the request, put it in writing, by email, and be precise. A vague “please send us our stuff” is easy to stall. A clear list, with a reasonable deadline, is much harder to ignore and gives you a record if things get difficult.
A simple, professional message works best. State that you are transitioning providers, thank them for the work, and request a written list of specific items: a full export of company data, all administrator credentials, confirmation of domain registrar access, and a copy of any documentation about your environment. Ask them to confirm in writing once each item is handed over. Keep the tone matter of fact. You are asking for what is already yours, not negotiating a favor.
If they stall or refuse
Most of the time this goes fine. If it doesn’t, stay calm and methodical rather than combative.
First, point to your contract. Many service agreements include language about data ownership and what happens at the end of the relationship. Re-read it, and reference it in your request.
Second, route around what you can. For things like a domain registrar or your Microsoft 365 tenant, the underlying platforms have their own account-recovery processes that can sometimes restore your control directly, without the provider’s cooperation. An incoming provider who knows these processes can often help you reclaim access even when the old one is dragging their feet.
Third, keep records of everything. Dates, requests, responses. If a provider is genuinely holding your business hostage, documentation is what protects you, and in serious cases it is the basis for involving an attorney. That is rare, but knowing the path exists takes away a lot of the fear.
You don’t have to do this alone
Reclaiming access from an uncooperative provider is one of the situations where having an experienced team on your side changes everything. We help businesses across Alaska and Hawaii take back control of their own systems as part of a clean switch, and because we’ve done it many times, we know which platform recovery paths exist and how to use them. It fits inside the larger picture of moving providers without losing data, which we cover in how to switch IT providers without downtime, and the broader decision lives in our switching and co-managed IT hub.
Where to start
If you’re worried about what your current provider is holding, the most useful first step is a short conversation to map out exactly what you control today and what you need to reclaim. We’ll help you build the list, draft the request, and have a plan ready if anyone tries to make leaving harder than it should be. Your business should never be locked inside someone else’s accounts, and getting it back is more straightforward than the worry suggests.