Managed IT services onboarding is the only part of a support contract that happens exactly once, and it is the part that decides everything after it. Thirty days in, either your new provider knows your estate better than you do, or they are still guessing — and every ticket, every patch and every restore for the next three years runs on whatever they wrote down in month one.

This guide sets out what managed IT services onboarding should actually deliver, day by day. Every deadline below is read off a source published and checked on 21 August 2026: Microsoft’s Partner Center documentation for granular delegated admin privileges, Microsoft’s subscription lifecycle and Entra ID deletion windows, the IASME and NCSC Cyber Essentials v3.3 “Danzell” question set that applies from 26 April 2026, NCSC guidance on choosing a managed service provider, and ICO guidance on processor contracts under the UK GDPR.

Where a figure had to be modelled rather than read off a page, it is labelled modelled and the working is shown. The worked example throughout is a 60-user UK professional services firm across three sites, paying £55 per user per month — £3,300 a month, £39,600 a year. If you are still choosing a supplier, our guide to switching IT support providers without business disruption covers the exit side, and our earlier IT provider onboarding checklist covers what to demand in plainer terms. What we deliver sits on our managed IT services page.

What Managed IT Services Onboarding Actually Has to Achieve

managed it services onboarding checklist first 30 days b planner block four slots solid

Buying managed IT services is a transaction. Onboarding is a transfer of knowledge, control and risk, and it is the only one of the three that has a deadline attached. Treat it as a project with exit criteria rather than a settling-in period and the whole thing changes shape.

Three transfers, not one

Managed IT services onboarding moves three separate things. Control moves when administrative rights land in the new provider’s hands. Continuity moves when monitoring, patching and backup start running under their platform. Knowledge moves when what your estate looks like stops living in one departing engineer’s head and starts living in a document.

Why month one is the only leverage you get

You will never have more attention from a supplier than in the first thirty days. The account is new, the transition team is assigned, and nobody wants an early failure on the record. Managed IT services onboarding done in that window costs the provider planned hours. The same work done in month seven costs them unplanned hours, which is why it usually does not happen.

The test that separates a good month from a busy one

A busy month produces activity: agents installed, tickets closed, a friendly review call. A good managed IT services onboarding produces evidence: a device count you can reconcile, a restore you watched succeed, a list of privileged accounts with dates against them. Ask for the second and the first tends to follow.

The Four Clocks That Govern Managed IT Services Onboarding

managed it services onboarding checklist first 30 days c magnifier round rim straight handle

Most onboarding plans are written around people’s availability. A managed IT transition is really governed by four clocks that run whether or not anyone is watching them, and each has a published number attached. Any managed IT services onboarding plan that ignores them is being written on optimism.

The delegated access clock

Microsoft’s granular delegated admin privileges are deliberately time-bound. A GDAP relationship request expires after 90 days if the customer takes no action, the maximum duration of any relationship is two years, and auto-extend adds six months at a time. Nothing about partner access to your tenant is permanent, by design.

The licence clock

If a subscription lapses during the changeover, Microsoft’s published lifecycle gives you Expired for 30 days with users still working, then Disabled for 90 days with admin access to data only, then deletion. That is a 120-day total window, and confirming it early in managed IT services onboarding is the difference between an awkward week and a lost tenant.

The identity clock

A deleted user account in Microsoft Entra ID stays in a suspended, restorable state for 30 days and is then permanently deleted, with no recovery by you or by Microsoft Support. A leaver processed in week one of managed IT services onboarding therefore has a hard expiry date on their mailbox and files.

The patching clock

Under the Cyber Essentials v3.3 question set, failing to install high-risk or critical updates within 14 days of release is an automatic fail. A thirty-day onboarding contains two complete 14-day windows, so a provider who has not established patching by day 14 has already missed one of them.

ClockThe published numberWhat happens when it runs out
GDAP relationship requestExpires after 90 daysRequest dies; a new one must be raised and approved
GDAP relationship durationMaximum two yearsPartner access ends; subscriptions are unaffected
GDAP auto-extendAdds six monthsNot available on Global Administrator relationships
Relationship name reuse365 days after terminationThe same name cannot be recreated before then
Subscription Expired state30 daysUsers keep working; reactivation still possible
Subscription Disabled state90 daysAdmins only; then data is deleted
Deleted Entra ID user30 days restorablePermanent deletion, unrecoverable by anyone
Critical security update14 days from releaseAutomatic Cyber Essentials failure

Before Day One: What Managed IT Services Onboarding Needs in Writing

managed it services onboarding checklist first 30 days d fence five pickets two rails

The managed IT relationship starts before the first engineer logs in. Four documents decide whether managed IT services onboarding starts productively or is spent chasing signatures, and all four are cheap to produce while everyone is still enthusiastic.

The signed order and the service schedule

Agree what is in scope by device count, user count and site, not by adjective. “Unlimited support” is a pricing model, not a scope. The schedule should name the hours of cover, the response targets, and the categories of work that fall outside the fee.

The data processing agreement

Your provider will process personal data on your behalf, so UK GDPR requires a written contract. ICO guidance sets out what must be in it: documented instructions, confidentiality, security measures, terms binding any sub-processor, help with data subject requests, assistance with breach notification and impact assessments, submission to audits, and deletion or return of all personal data at the end of the contract.

The named contacts on both sides

One named service delivery lead at the provider, one named business owner at your end, and one named technical contact each. Managed IT services onboarding fails more often through ambiguity about who decides than through anything technical.

The credential handover pack

Every administrative credential, licence portal login, registrar account, and line-of-business vendor contact, in one encrypted store, with an owner against each. This is the artefact the outgoing supplier is least motivated to produce, so ask for it while the previous contract still has time to run.

Days 1 to 2: Kick-Off, Escalation and the First Real Ticket

managed it services onboarding checklist first 30 days e scoreboard panel three blank windows

The kick-off is not a sales call and should not feel like one. It is where the managed IT services onboarding plan gets dates against it and where the escalation path is agreed while everyone is calm rather than during an outage.

What the kick-off must produce

A dated plan with named owners, an agreed change freeze window, the support routes your staff should use from day one, and the date of the day-30 review. Anything discussed but not written into that plan will not survive contact with week two.

The escalation path, agreed in advance

Three levels, with names and out-of-hours routes: the service desk, the service delivery lead, and a director. Agree what constitutes a major incident in your business, not in the provider’s template. For a firm that bills by the hour, a document management system outage is a major incident even if no server is down.

Why the first ticket matters more than it looks

The first genuine ticket in a managed IT services onboarding is a live test of routing, ownership and communication. Watch how it is acknowledged, who owns it, and whether the update arrives before you chase. That single ticket tells you more about the next three years than the whole proposal did.

Communicating the change to your staff

Send one short message before day one: what is changing, what is not, how to log a ticket from today, and who to ask if something looks wrong. Most early managed IT services onboarding friction is people using the old route out of habit and concluding the new provider is slow.

Days 1 to 7: Discovery and the Gap Between Declared and Discovered

managed it services onboarding checklist first 30 days f cog wheel eight square teeth

Discovery is the workstream that pays for the whole of managed IT services onboarding, and the one most likely to be quietly truncated. A representative sample is not discovery. Every device, every identity, every application that touches company data is discovery.

What full discovery covers

Endpoints and servers, network hardware and firmware versions, every Microsoft 365 identity including shared and service accounts, every SaaS application holding company data, every line-of-business system and its support entitlement, and every backup job with its current retention.

The gap you should expect to find

The declared estate is almost never the real one. In the worked 60-user firm, the declared list ran to 60 endpoints, 4 servers, 2 network devices, 18 SaaS applications and 5 privileged accounts. Discovery found 78 endpoints, 6 servers, 3 network devices, 31 SaaS applications and 11 privileged accounts.

Discovery gap: how much more was found than declared (modelled 60-user firm)
Endpoints — 60 declared, 78 found +30.00%
Servers — 4 declared, 6 found +50.00%
Network devices — 2 declared, 3 found +50.00%
SaaS applications — 18 declared, 31 found +72.22%
Privileged accounts — 5 declared, 11 found +120.00%

Why the privileged account gap is the dangerous one

An extra 18 laptops is a budget conversation. Six privileged accounts nobody declared is a security finding, and it is the single most common discovery outcome in a managed IT services onboarding. Old admin accounts from previous suppliers, break-glass accounts with no owner, and service accounts with passwords that never expire all surface in the same week.

The reconciliation that closes discovery

Discovery is not finished when the scan completes. It is finished when the count in the new provider’s platform matches the count you can verify, line by line, and every difference has a written explanation. Insist on that reconciliation as a deliverable with a date, or discovery will drift into month two.

Delegated Access: Least Privilege and the 90-Day Request

Delegated access is the part of managed IT services onboarding most likely to be left half-finished, because nothing visibly breaks when it is wrong. That is exactly what makes it a governance problem rather than a technical one.

How GDAP should be set up

During managed IT services onboarding, roles are assigned to security groups, not to individuals, and the relationship carries only the roles the provider actually needs. All roles inside one relationship share the same expiry date, so a single over-privileged role drags the whole relationship’s risk profile up with it.

The 90-day request window

A GDAP relationship request sits in Approval Pending until the customer acts, and expires after 90 days. During that time the partner cannot terminate it. If your approver is on leave in week one of managed IT services onboarding, that clock is running quietly in the background.

Auto-extend, and where it stops

Auto-extend renews a relationship by six months at a time until it is disabled — so a relationship created for 365 days with auto-extend enabled moves its end date to day 545 on the 365th day. It is not available for a relationship carrying the Global Administrator role, which is a useful nudge away from requesting that role at all.

Revoking the outgoing provider

The old provider’s delegated access, RMM agents, EDR tenant and administrative accounts all need explicit removal with dates recorded. NCSC guidance on choosing a provider is direct about applying least privilege to supplier access and about knowing whether security logs are kept, how long for, and whether you can get at them.

Days 8 to 14: Agents, Monitoring and the Patch Baseline

By the end of week two of managed IT services onboarding the estate should be visible in one place. Partial coverage is worse than none, because a dashboard showing green for 71 of 78 machines reads as healthy at a glance.

Agents everywhere, not mostly everywhere

Management and security agents belong on every endpoint and server found in discovery, including the ones nobody declared. Ask for the deployment report as a number against the reconciled asset count, not as a screenshot of a dashboard.

The first honest health check

The initial patch report is the most useful document produced in the whole month, because it is the only one taken before anybody has had a chance to tidy up. Keep it. It is your baseline, and at the day-30 review it is the evidence that something changed.

Remediating the backlog

Expect a genuine backlog — machines two or three cumulative updates behind, firmware last touched years ago, and at least one server nobody wanted to reboot. Agreeing a reboot window in week two is what stops that backlog rolling into month three.

Alerting that a human actually reads

Monitoring only counts if alerts route to a queue with an owner and a response target. Ask which alerts page someone out of hours, which wait for the morning, and what the provider does when the same alert fires for the fifth night running.

Days 8 to 14: Backup, and the Restore Test That Proves It

Backup configuration is easy. Backup verification is the thing that gets skipped, and the gap between the two is where most managed IT services onboarding failures eventually surface.

Configuration is not verification

A completed backup job proves data was written. Only a restore proves data can be read, and managed IT services onboarding should not end without one. Insist that week two ends with at least one file-level restore and one full-item restore performed in front of you, with the elapsed time recorded.

What to restore first

Restore something that matters: a document from the busiest shared library, a mailbox item from a partner’s account, and a whole virtual machine to an isolated network. If a restore of a live-looking item is refused, ask exactly which conditions it would be allowed under.

Retention that matches your obligations

Microsoft’s own retention behaviour is not a backup policy. Items in the recoverable items folder are permanently deleted within 14 days of a retention period ending by default, configurable to 30. Your retention requirement comes from your regulator, your insurer and your contracts, and it needs stating in writing.

The recovery numbers nobody writes down

Agree a recovery time objective and a recovery point objective per system, not per business. The document management system and the print server do not deserve the same numbers, and a managed IT services onboarding that produces one blanket figure has not really asked the question.

Days 15 to 21: Identity, Access and the Security Baseline

Week three of managed IT services onboarding is where the estate stops being merely visible and starts being defensible. It is also the week where the Cyber Essentials rules do the most work for you, because they turn opinions into pass or fail questions.

Multi-factor authentication, everywhere it exists

Under the Danzell question set published in February 2026, multi-factor authentication is mandatory for all cloud services where it is available, and failing to enable it on an in-scope cloud service is an automatic fail. That reframes the conversation: it is no longer a judgement call about user friction.

Conditional access and the exception list

Agree the baseline policies and, more importantly, agree the exception list. Every exception should have an owner, a business reason and a review date. An exception list that only grows is the clearest early warning sign in any managed IT services onboarding.

Privileged access and the break-glass account

Administrator accounts should be separate from daily accounts, excluded from standard sign-in paths, and documented. Two break-glass accounts, stored offline, tested once, and reviewed quarterly, is the pattern that survives audit. Good cybersecurity practice here costs nothing but discipline.

Joiners, movers and leavers

Agree the process in week three rather than discovering it during a resignation. Note the 30-day Entra ID window: a deleted account is restorable for 30 days and then gone permanently, so a leaver’s data must be preserved deliberately, not by accident.

Days 22 to 30: Documentation, Handover and the Knowledge Test

Documentation is the managed IT services onboarding deliverable that determines what happens when your favourite engineer leaves. It is also the easiest thing to fake, so test it rather than reading it.

What documentation must contain

A network diagram that matches reality, an asset register reconciled to discovery, a credential inventory with owners, runbooks for the systems that actually break, and a written escalation matrix. Ask for it in a format you can export and keep.

The handover test

Pick a system nobody on the transition team built and ask a different engineer to explain how it would be recovered, using only the documentation. If they need to phone a colleague, the documentation is a folder of screenshots and the managed IT services onboarding is not finished.

Who owns the documentation

Confirm in writing that the documentation is yours and is exportable on termination. NCSC guidance is clear that the contract should say who is responsible for tracking end-of-life dates and acting before support ends — a question that can only be answered from a real asset register.

The knowledge that never gets written down

Some knowledge is tacit: the client who always calls the office directly, the machine that must not be rebooted before payroll runs. Capture it in a short operational notes document during managed IT services onboarding, while the previous arrangement is still fresh in people’s minds.

What Managed IT Services Onboarding Costs the Provider

Managed IT services onboarding is usually presented as free. It is not free; it is amortised. Understanding the modelled effort behind it explains almost every commercial term in the contract you just signed.

The modelled effort for 60 users

The table below models the first thirty days for the worked firm. Agent deployment assumes 78 endpoints at ten minutes each, which is 780 minutes, or 13.0 hours.

WorkstreamModelled hoursShare of total
Estate discovery and reconciliation2419.51%
Documentation build2016.26%
Patch baseline and remediation1613.01%
Security baseline and EDR rollout1411.38%
Agent deployment across 78 endpoints1310.57%
Identity, MFA and access review129.76%
Backup build and first test restore108.13%
Day-30 review and reporting pack86.50%
Kick-off, governance and contacts64.88%
Total123100.00%

What that converts to in money

At a blended £85 per hour, 123 hours is £10,455. Against a fee of £3,300 a month, that is 3.1682 months of revenue consumed before the account contributes anything, or 26.40% of the £39,600 first-year fee.

Why the top five workstreams matter most

Discovery, documentation, patch remediation, the security baseline and agent deployment together account for 70.73% of the modelled effort. A provider who compresses managed IT services onboarding into a week has not found a faster method — they have dropped part of that 70.73%.

Share of the modelled 123 onboarding hours, top five workstreams
Estate discovery and reconciliation 19.51%
Documentation build 16.26%
Patch baseline and remediation 13.01%
Security baseline and EDR rollout 11.38%
Agent deployment across 78 endpoints 10.57%

Why Free Managed IT Services Onboarding Is Never Actually Free

If the modelled effort is £10,455 and the invoice says nothing, that money did not disappear. It moved somewhere else in the agreement, and knowing where tells you what to negotiate.

Where the cost is recovered

It comes back in three places: a minimum term long enough to amortise it, a per-user rate slightly above the market, or an early termination charge that recovers unrecouped transition costs. All three are reasonable. What is not reasonable is a supplier who claims none of them apply.

What “onboarding included” usually excludes

Read the exclusions carefully. Data migration, hardware replacement, licence purchases, out-of-hours work, remediation of pre-existing faults, and travel to sites are all commonly outside a bundled managed IT services onboarding, and each can be a five-figure line on its own.

The cost of doing it twice

If onboarding is superficial and has to be redone in month seven, the modelled 123 hours are spent again — another £10,455 — on top of six months of fees already paid on an unestablished service, which is 6 × £3,300 = £19,800. Total exposure: £30,255, against a £39,600 annual fee.

The pacing that actually happens

By the end of week one the model has consumed 43 of 123 hours, or 34.96%. By the end of week two, 73 hours, or 59.35%. By the end of week three, 115 hours, or 93.50%. The final week is the review, the reporting pack and the loose ends.

Cumulative share of the 123 modelled hours consumed, by week
End of week 1 — 43 hours 34.96%
End of week 2 — 73 hours 59.35%
End of week 3 — 115 hours 93.50%
End of day 30 — 123 hours 100.00%

The Day-30 Managed IT Services Onboarding Scorecard

A managed IT services onboarding review without a scorecard becomes a conversation about how everyone feels it is going. Score it instead, out of 100, with the weights agreed before day one so nobody is marking their own homework retrospectively.

The weights that work

Four workstreams carry twenty points each because each one can sink the service on its own. The remaining twenty points cover how the desk behaved and whether the governance actually happened.

SectionWeightWhat full marks looks like
Access and identity20Least-privilege delegation live, MFA everywhere available, old supplier access revoked with dates
Discovery and documentation20Asset register reconciled line by line, diagram matches reality, handover test passed
Coverage and patching20Agents on 100% of reconciled assets, baseline report kept, backlog plan dated
Backup and recovery20Every system in scope, one witnessed restore, recovery objectives written per system
Desk performance10Response targets met, ownership visible, no ticket lost in the changeover
Governance and reporting10Review held on the agreed date, reporting pack delivered, actions owned and dated
Total100Pass mark 80

The rule that stops a good average hiding a bad section

Any section scoring below half its weight is a fail regardless of the total. A managed IT services onboarding that scores 84 out of 100 with 8 out of 20 on backup has not passed; it has an unverified recovery capability and a comfortable-looking number.

Metrics that actually mean something

Percentage of reconciled assets under management. Percentage patched to the current baseline. Number of successful restores witnessed. Count of privileged accounts, opened and closed. Tickets by category, so you can see what is actually consuming the service.

What to do with a score in the sixties

Do not terminate; agree a written remediation plan with dates and a re-score at day 60. A score in the sixties usually means the plan was too thin, not that the provider is incapable. A second failed score, however, is a genuine signal.

Red Flags in the First Thirty Days

Some managed IT services onboarding warning signs appear early and are easy to explain away in the goodwill of a new relationship. These four are worth taking seriously the first time you see them.

Discovery that never quite finishes

If the asset count keeps moving and nobody will sign off a reconciliation, discovery is not being finished — it is being abandoned quietly. Every downstream workstream inherits that uncertainty.

The single point of contact who never answers

One named contact is good practice until that person becomes the only route in. Ask on day two what happens when they are on leave, and confirm the answer is a team with shared visibility rather than a redirected phone.

Documentation that is a folder of screenshots

Screenshots are evidence, not documentation. If the handover test in week four cannot be passed from the written material alone, the knowledge is still in one person’s head and you are exposed to their resignation.

Silence on security findings

A discovery that surfaces eleven privileged accounts where five were declared should generate a finding, an owner and a date. Silence means either it was not looked for or it was not thought worth mentioning, and neither is acceptable in a managed IT services onboarding.

What Only You Can Supply

Some parts of managed IT services onboarding depend entirely on you, and a provider cannot compensate for their absence however good they are. Naming them at kick-off is the cheapest way to protect the timetable.

Decisions, made on time

Approval of the delegated access request, sign-off on the reboot window, agreement on the exception list. Every one of these blocks a workstream, and each has a clock attached.

Access to your own suppliers

Line-of-business vendors will often only speak to a registered contact. Introducing your new provider to those vendors in week one prevents the support-entitlement problem that otherwise surfaces during the first real outage.

Honesty about the estate

The declared estate is usually optimistic rather than dishonest. Saying so upfront — “we think there are around 60 machines but there are laptops we have lost track of” — turns a discovery gap from an awkward finding into an expected one.

An internal owner with time

Managed IT services onboarding needs perhaps two to four hours a week of a capable internal person’s attention. Without that, every decision queues behind someone whose day job is not this, and the thirty days become forty-five.

Data Protection Through the Transition

Managed IT services onboarding is the period when personal data is most exposed, because two suppliers hold access at once and neither is fully accountable yet. UK GDPR does not pause for onboarding.

Both contracts are live at the same time

During any overlap window, two processors are handling your data under two agreements. Confirm both are in force, record the overlap dates, and diarise the deletion or return obligation on the outgoing side.

Deletion or return at the end

The outgoing processor must delete or return all personal data at the end of the contract, at your choice. Ask for written confirmation of which happened and when, and hold it with your onboarding records — it is the evidence you will want if anything surfaces later.

Sub-processors, named

Your new provider almost certainly uses sub-processors: a backup platform, a monitoring platform, a service desk tool. Those must be bound by equivalent terms, and you should have the opportunity to object to changes. Ask for the list in week one, not at renewal.

Logging you can actually reach

NCSC guidance recommends confirming that security logs are kept, understanding the retention period, and checking whether your organisation can access them. Agree those three points during managed IT services onboarding, because after an incident is the worst possible time to discover the answer.

Mistakes UK Firms Keep Making in the First 30 Days

The same handful of managed IT services onboarding errors turn up repeatedly, and none of them is technical. Each is a planning decision made at the start of the month.

Starting onboarding after the old contract ends

Overlap costs a month of double fees and removes almost every risk in the transition. Running managed IT services onboarding with no overlap saves £3,300 in the worked example and gambles the entire estate against it.

Treating the review as optional

The day-30 review is where the whole month either gets signed off or gets a remediation plan. Firms that let it slip to “sometime next month” almost always find that it never happens at all and the open items become permanent.

Confusing responsiveness with progress

A provider can answer every call quickly and still be nowhere on discovery, documentation and backup verification. Speed on the desk is a service quality; the four workstreams above are the actual product of the first month.

Leaving the outgoing provider’s access in place

It is the easiest item to defer because nothing breaks. Months later it is an unowned administrative account belonging to a company you no longer pay, and it is the finding nobody wants to explain to an insurer.

How Progressive Robot Runs Managed IT Services Onboarding

We run the first thirty days as a project with named owners, dated exit criteria and a scored day-30 review, because that is the only version of managed IT services onboarding that produces evidence rather than activity.

What we commit to

Full estate discovery with a written reconciliation, least-privilege delegated access, agents on every reconciled asset, a witnessed restore before day 14, and a documentation pack you own and can export.

How we report it

One scorecard against the weights above, one baseline patch report kept from week two for comparison, and a written action list with owners and dates. If you would like the same structure applied to your own transition, our team can walk through it against your estate — the contact page is the quickest route.

Managed IT Services Onboarding: Frequently Asked Questions

How long should managed IT services onboarding take?

Thirty days is the right target for a business of 30 to 150 users on a reasonably conventional estate. Larger estates, multiple sites with their own infrastructure, or a hostile exit from the previous supplier can push it to 60 days — but the exit criteria do not change, only the dates.

Should we overlap the old and new contracts?

Almost always yes. Running managed IT services onboarding with a one-month overlap costs £3,300 and removes the two worst scenarios: an unmanageable estate and a backup gap. Treat it as insurance rather than duplicated fees.

What if the outgoing provider will not cooperate?

Fall back on the contract and on the law. The exit clause covers documentation and credentials; UK GDPR covers deletion or return of personal data regardless of how thin the commercial terms are. Plan for a rebuild of anything you cannot compel.

Is a 14-day patching promise realistic in month one?

Reaching the standard by day 14 of managed IT services onboarding is realistic; being at the standard on day 1 is not. What matters is that the baseline report exists, the backlog has a dated plan, and the 14-day rule is being met by the end of the month.

Do we need Cyber Essentials before onboarding?

No, but aligning the first thirty days to it is efficient, because the auto-fail questions in the current question set are a short, unambiguous checklist. Doing the work once during managed IT services onboarding is cheaper than doing it again before an assessment.

Who owns the documentation the provider creates?

You should, and every managed IT services onboarding pack should be exportable on termination. Get that in writing before day one; it is a routine request that costs nothing to agree at the start and is very difficult to win later.

References