Your IT Guy Just Left: How to Take Over and Hand Over Company IT Without Downtime

The short answer: When the person who ran your company IT leaves, you need to take over — and above all verify — the following during their notice period: administrator accounts and passwords, access to the domain, DNS and email, licences and contracts held in their name, network documentation, and working backups including encryption keys, tested with a trial restore. Try every single credential by actually logging in while you still have someone to ask; a spreadsheet full of passwords is not a handover. And if there is no internal replacement, it is safer to put operations in the hands of an outsourced IT provider than to let the company coast on momentum.

The tricky part about an IT admin leaving is that nothing happens. The server keeps running, email keeps arriving, printers keep printing. IT does not collapse the moment the admin walks out — it degrades gradually. The first problem shows up weeks or months later: an expired certificate, a full disk, a failed backup. Only then does it become clear what was written down and what lived only in the head of someone who no longer works there.

This is a practical guide for company directors and office managers: what to ask for, how to organise the handover, what to do when it is already too late, and when it makes sense to hand IT management to an external provider.

What happens when IT lives in one person’s head

Typical scenarios companies run into — all of which a proper handover can catch:

  • The domain is registered to their personal email address. The renewal notice lands in a mailbox nobody reads any more. The domain expires, and with it the website and the entire company email in one go. Recovery through the registrar then happens under time pressure and requires proving ownership.
  • Nobody knows the firewall or router password. The device ran untouched for years. At the first internet outage, a factory reset is the only option — and with it go the VPN, the rules, the address reservations and the network segmentation. The configuration has to be rebuilt from scratch, from memory.
  • Backups „were running", but nobody ever tried a restore. Only after a server failure does it emerge that the job had been failing for months, that the target disk is full, or that the backup is encrypted with a key that walked out with the admin.
  • Licences and services are registered to their account. Microsoft 365, antivirus or hosting was paid on their card and expensed. Once they leave, the payment fails and the service is switched off — often with no warning reaching the company at all.
  • Automation runs on their computer. The nightly export to the accounting system, order transfers from the e-shop, monitoring scripts. Once their account is disabled, everything quietly stops and nobody knows what has stopped working.

The common thread: none of these problems is visible on the day of departure. That is why an IT handover is first and foremost a stocktake — and why it cannot be squeezed into one last afternoon.

IT handover checklist: what to ask for

Work through the items group by group. The same rule applies to every one of them: you are not taking over a list, you are taking over working access — verified by logging in with the departing admin present.

1. Administrator accounts and passwords

  • local administrator passwords for computers and servers;
  • domain administrator (Active Directory), plus Microsoft 365 Global Administrator or Google Workspace super admin where applicable;
  • router, firewall, switches, Wi-Fi (both the controller and individual access points);
  • NAS and servers including out-of-band management (iLO, iDRAC) and the hypervisor (Proxmox, VMware, Hyper-V);
  • VPN — the server configuration plus an overview of who has access from outside;
  • CCTV, attendance system, phone system, print server;
  • databases, application and service accounts, API keys used in scripts;
  • BIOS/UEFI passwords and BitLocker recovery keys for company laptops — where these are stored is explained in the article on BitLocker and the recovery key.

Take passwords into a company password manager that more than one person can access. A spreadsheet on a shared drive is a security problem, not a solution.

2. Domain, DNS and email

This is where the most expensive outages originate, so be especially thorough:

  • the domain registrar account — whose name and email address it is held under, where the renewal invoices go;
  • who manages the DNS records (registrar, hosting provider, Cloudflare) and how to access them;
  • web hosting and the website itself — CMS administration, FTP/SSH;
  • email administration: the Microsoft 365 / Google Workspace admin console, or the hosted mail server;
  • SPF, DKIM and DMARC records — who set them up and where;
  • SSL certificates: where they are renewed, whether renewal is automatic, and when they expire.

The goal is not merely to know the passwords, but to transfer ownership to the company: the registrar, the hosting and the administrator accounts must all be tied to a company email address and company billing details, not to a former employee’s personal address.

3. Backups — and testing them

  • exactly what is backed up (servers, databases, shared drives, email, network device configurations), where to and how often;
  • access to the backup software and to the backup storage;
  • backup encryption passwords and keys — without them a backup is worthless;
  • where failure notifications are sent — if they go to their address, redirect them;
  • whether a copy exists off-site and out of reach of ransomware — the principle is covered in our article on the 3-2-1 rule and backing up to an external drive.

Above all: run a trial restore while they are still there. One file, one database, ideally one complete system. A backup nobody has ever restored is just an assumption.

4. Licences, contracts and service relationships

  • the contract with your internet provider and a direct contact for their support;
  • licences: Microsoft 365 / Google Workspace, antivirus or EDR, accounting and industry-specific software, CAD, backup software;
  • cloud services: virtual servers, storage, e-commerce platform;
  • service contracts and warranties for servers, NAS and network hardware;
  • for each item: whose name it is registered in, how it is paid for and when it expires.

Make a point of having everything paid on their card or from their accounts shown to you — those are the quiet outages of the future.

5. Network and systems documentation

  • the network plan: address ranges, VLANs, wiring diagram, a list of devices and their locations;
  • exported firewall and switch configurations (and where they are stored);
  • an overview of „what runs where": physical servers, virtual machines, services and their dependencies;
  • known issues and temporary workarounds — every network has some, and it is better to know about them.

If documentation never existed, there is no point demanding it in the final week. The realistic path is to have the current state mapped out — we have covered what a computer network and cabling audit involves separately.

How to organise the handover while the admin is still there

Start in the first week of the notice period, not the last. Taking stock of credentials always takes longer than expected, and by the end the departing person’s mind is usually elsewhere.

A proven approach:

  1. A handover record. A list of every item from the checklist above, each with a status: handed over / verified / missing. Signed by both parties at the end. This is not harassment — it also protects the person leaving, who cannot be blamed six months later for „a password they never handed over".
  2. Verification by logging in. Try every credential while they are present. This is exactly where you find the accounts whose passwords stopped working long ago.
  3. A walk-through of routine operations. Have them explain what they do daily and what they do once a month: checking backups, applying updates, swapping tapes or disks, renewing certificates. That becomes the operational calendar for their successor.
  4. Procedures for recurring tasks. Creating and removing a user, restoring a file from backup, replacing a disk in the NAS, what to do during an internet outage. Brief notes are enough — a screen recording works just as well.
  5. Change the passwords afterwards. Every administrator account they had access to gets a new password and multi-factor authentication tied to company contacts. Disable their accounts on their last day — but do not delete them until you have transferred the mailbox, the files and any scheduled tasks.

When they have already gone and there was no handover

This happens more often than it should — the arrangement ended quickly, or badly. The systems usually keep running, but unsupervised. Work in order of potential damage, not by what is most visible:

  1. Domain and email. Check whose name the domain is registered in and when it expires; do the same for certificates. These are the outages that stop the whole company at once.
  2. Backups. Find out whether they are running at all and whether anything can be restored from them. Until you know, treat the company as if no backup existed — no experiments on the server.
  3. Credentials. Obtain whatever is missing through legitimate channels: password resets via the registrar, the hosting provider or the manufacturer, with proof of ownership (contract, invoices, company registration number). For network hardware with no known password, expect a factory reset and a fresh configuration.
  4. The former admin’s remote access. VPN accounts, TeamViewer/AnyDesk, their administrator accounts in the cloud. Disable them — not out of ill will, but on principle: nobody who does not work at the company should have access to its network.

If there is nobody in the company who can work through all of this, that is precisely the situation for handing IT over to an external managed service provider — the first step is always mapping the current state and securing credentials and backups, and only then dealing with the rest. It is also worth calling the former admin and arranging a paid consultation to finish the handover: most people do not leave intending to cause harm, and an agreement will get you further than recriminations.

When outsourcing IT management makes sense

After your only IT person leaves, the question is not just „who replaces them„, but „do we want to run the same risk again?". Replace one person with another single person and you will be in the same position a year from now — with holidays, sick leave and weekends in between, when nobody is watching IT at all.

Outsourcing makes sense when:

  • the company does not have a full year’s worth of work for an IT specialist and the role was really „part-time IT alongside another job" anyway;
  • you need cover — with a managed service provider, the know-how does not walk out with one person;
  • you want documentation and monitoring as a standard part of the service, rather than depending on an employee’s goodwill.

What to watch for in the contract, so that today’s situation does not simply repeat in a different guise: documentation and credentials are company property and are available to you on an ongoing basis, not only when the relationship ends; administrator accounts are registered to the company; and the contract sets out how any future handover will work. A combination also works well — outsourced management plus an internal „informed user" who can handle first aid on site.

An IT admin leaving does not have to be a crisis. With a checklist, a signed record and verified backups, it is a managed change. It only turns into a crisis when the handover is put off until later.

FAQ

The admin left on bad terms and refuses to hand over the passwords. What now?

Access can usually be recovered without them: domain registrars, hosting providers and hardware manufacturers all have procedures for a company to prove ownership (contracts, invoices, company register extract). For network hardware, a factory reset and fresh configuration is the fallback. Document the whole process and disable the former admin’s access to company systems as soon as possible.

Is a spreadsheet of passwords enough?

No. Some of the passwords will be out of date, some accounts will be tied to their personal email address, and a spreadsheet tells you nothing about what is missing. A handover means verification: log in to every item, transfer accounts to company contacts, enable multi-factor authentication and store the passwords in a shared company password manager.

Should we delete their accounts on their last day?

Disable them, yes; delete them, no. An account may still hold licences, shared documents, scheduled tasks or a mailbox that important email keeps arriving in. Transfer everything to their successor first, and only then remove the account.

How long does taking over IT take?

It depends on the size of the network and the state of the documentation. Handing over credentials is a matter of days; verifying backups with a trial restore, transferring accounts at registrars and providers, and writing up operating procedures spread over weeks. That is why it matters to start at the beginning of the notice period, not at the end.

Can we survive a period without an admin until we find a replacement?

Short term, yes — provided you have verified backups, domain and certificate expiry dates under control, and working administrator access. Over the longer term the hidden risk grows: nobody is checking backups, updates or security alerts. The longer the stopgap lasts, the more expensive the first incident tends to be.