By Maurice Coles on Monday, 03 August 2026
Category: Insights

What Happens During the First 30 Days With a New IT Support Provider?

Good onboarding establishes control before routine support takes over.

During the first 30 days with a new IT support provider, the priority should be control rather than immediate transformation. A well-managed onboarding normally covers discovery, secure access, documentation, monitoring, user communication, risk triage and an agreed improvement plan.

The exact timetable depends on business size and complexity. A simple cloud-based office may move faster; multiple sites, legacy servers or missing credentials may require a longer transition.

Days 1–5: Confirm scope, people and access

The incoming provider should confirm what is included, who can approve changes and how incidents will be escalated. Employees also need a clear service-desk contact and a date from which the new arrangements apply.

Initial access should cover systems such as Microsoft 365, domains, firewalls, servers, backups and security platforms. Credentials must be transferred securely, tested and limited to what the provider needs.

The provider should not rush to replace tools before understanding the environment. Early changes can remove useful evidence or create disruption.

Days 6–10: Discover and document the environment

Technical discovery builds a dependable record of:

Any gap should be recorded, assigned an owner and prioritised. Missing documentation is common; leaving it unresolved is the real problem.

Days 11–20: Deploy support tools and test critical controls

The provider can now configure the agreed service-desk, monitoring and management tools. This may involve installing agents, setting alerts, establishing maintenance policies and confirming how users request help.

Critical controls should be verified rather than assumed. That includes checking backup coverage, testing an agreed recovery sample, reviewing privileged access and confirming that former suppliers no longer retain unnecessary access.

Businesses that need stronger resilience can review HTL's backup and disaster recovery services.

A practical first-month sequence for taking control of business IT.
Period Primary focus Expected output
Days 1–5 Scope and secure access Contacts, responsibilities and verified credentials
Days 6–10 Technical discovery Asset, supplier and system documentation
Days 11–20 Tooling and control checks Monitoring, service desk and prioritised risks
Days 21–30 Stabilisation and planning Baseline report and agreed improvement plan

Days 21–30: Stabilise and agree priorities

By the end of the first month, routine support should be operating and urgent risks should have clear actions. The provider should present a baseline showing the environment it found, what has been resolved, what remains exposed and which improvements are recommended.

That review should separate urgent remediation from longer-term projects. It should also confirm reporting, service levels, meeting frequency and how performance will be measured.

What should you have after 30 days?

A successful onboarding should leave the business with:

The NCSC advises organisations to understand the privileged access an MSP may hold and the security responsibilities of both parties. Its guidance on using MSPs to administer cloud services is a useful reference.

Planning a controlled onboarding?

HTL provides managed IT services and outsourced IT support for London businesses. Arrange a free IT review to discuss the current environment before changing providers.

Related Posts