Co-Working
You can switch IT companies safely by regaining documented ownership of three critical areas: your Microsoft 365 tenant, firewall and network accounts, and administrator credentials. A structured transition protects email, internet access, member operations, and security monitoring while the incoming provider validates control before the incumbent is removed.
In This Article
- What must we regain control of before changing IT providers?
- How do we transition without interrupting email, internet, or member access?
- What if the incumbent IT company will not provide passwords or administrator access?
- How should a Norcross coworking space protect tenants during an IT change?
- What should we expect from the incoming IT provider after the handover?
- Frequently Asked Questions
What must we regain control of before changing IT providers?
Your business should own every platform that keeps it operating, even when an IT company manages it. That includes the Microsoft 365 tenant, domain registrar account, DNS records, firewall, wireless management portal, internet-service-provider portal, backup platform, endpoint security console, and password vault.
Start by identifying the legal account owner, billing contact, recovery email address, recovery phone number, and current global administrator for each system. If those details point to a former employee or the outgoing provider, the account is not yet under reliable business control.
For a coworking operator, this review should go beyond office laptops. A multi-tenant network may include separate SSIDs, VLANs, guest-network controls, access-control integrations, cameras, conference-room equipment, captive portals, printers, and connectivity in the MDF or IDF.
Microsoft 365 deserves special attention because it often holds email, SharePoint files, Teams conversations, identities, licenses, and device-management settings. The goal is not to move tenants unnecessarily; it is to verify that the business owns the tenant and can administer it independently.
Do not accept a spreadsheet of passwords as proof of control. Confirm that authorized business leaders have working administrator access, recovery methods are current, and access is protected by multifactor authentication.
Takeaway: If your company cannot independently recover an account, it does not fully control that account.
How do we transition without interrupting email, internet, or member access?
A reliable changeover uses parallel preparation rather than a single cutover day. The incoming IT provider should first document the environment, establish authorized access, verify backups, identify dependencies, and create a transition checklist with named owners and dates.
Do not disable the incumbent’s access until the new team has tested its own. The new provider should verify administrator access to Microsoft 365, the firewall, wireless systems, endpoint tools, backups, domain and DNS records, and any cloud services that support daily work.
- Inventory every account, device-management platform, circuit, license, and critical vendor relationship.
- Confirm business ownership and update recovery contacts, billing contacts, and authorized administrators.
- Create new named administrator accounts for approved internal leaders and the incoming provider.
- Test access, alerts, backups, and documented recovery procedures before changing support responsibility.
- Schedule credential rotation and removal of outgoing access after successful validation.
- Monitor the environment closely through the first business cycle after transition.
For coworking spaces in Norcross and along the I-85 business corridor, timing matters. A transition should avoid peak member activity, major move-ins, after-hours events, or tenant buildout milestones that depend on connectivity, badge access, and conference-room availability.
Internet access can be especially sensitive when the outgoing provider controls a firewall or ISP portal. The incoming team should export and document the current configuration, WAN details, VLANs, DHCP scopes, VPN settings, port-forwarding rules, content filtering, and failover design before any firewall changes are made.
A switch lifecycle plan is part of business continuity, not simply equipment maintenance. GDS discusses this broader operational risk in its guide to managing switch lifecycles without downtime, including the impact that network outages can have on building and tenant operations.
Takeaway: The safest transition is one where the new provider proves access and continuity before the old provider loses access.
What if the incumbent IT company will not provide passwords or administrator access?
Stay professional, document every request, and avoid turning off services impulsively. Ask for a written transition package that lists accounts, administrators, licenses, network diagrams, firewall configuration backups, vendor contacts, support contracts, and all credentials held on the business’s behalf.
At the same time, use ownership evidence to recover accounts directly from the vendors. A company may be able to prove control through its domain registration, payment method, Microsoft licensing records, incorporation records, signed agreements, invoices, and authorized-officer identification.
For Microsoft 365, recovery options depend on how the tenant was created and who currently holds the highest administrative role. Gather the tenant’s verified domain name, billing information, subscription records, and evidence that your organization owns the associated business domain before engaging Microsoft support.
If firewall credentials are withheld, do not factory-reset the device without a documented replacement plan. A reset can erase VPN access, internet configuration, network segmentation, port mappings, and settings tied to access control, cameras, VoIP, or other connected systems.
Instead, preserve evidence of the existing configuration where possible, confirm the firewall’s ownership, identify the ISP circuit details, and plan a controlled replacement if recovery is not feasible. For a shared workspace, that plan should account for member Wi-Fi, private-office connectivity, staff systems, guest access, and management of any smart-building or security technology.
Key figure: verify business ownership and recovery access across 3 core control points - Microsoft 365, the firewall, and administrator credentials - before ending the incumbent relationship.
There are legitimate cases where a provider-owned platform must be replaced rather than transferred. What matters is preserving business continuity and clearly separating the client’s assets from the provider’s proprietary tools or licenses.
Takeaway: A withheld password is a transition problem to document and recover methodically, not a reason to risk an unplanned outage.
How should a Norcross coworking space protect tenants during an IT change?
Coworking operators carry a special responsibility because one network environment supports many independent businesses. Members expect reliable Wi-Fi, private-office connectivity, conference-room uptime, printing, visitor processes, cameras, and badge access without needing to understand the infrastructure behind them.
The transition plan should map each tenant-facing service to its technical dependencies. That means identifying which network switch, firewall rule, SSID, VLAN, ISP circuit, access-control platform, camera system, or cloud account supports each service.
Segmentation should be reviewed carefully. A member guest network should not provide access to coworking staff systems, cameras, access-control administration, printer management, or other sensitive operational resources. Private-office and internal networks should have intentional boundaries appropriate to the environment and risk.
Norcross-area workspaces may host law firms, financial services teams, healthcare-adjacent businesses, logistics-related companies, and remote satellite teams. Even when the coworking operator is not itself a regulated entity, credible security practices can support tenant confidence and reduce avoidable exposure.
Physical infrastructure also belongs in the handover. Confirm access to risers, telecom rooms, rack layouts, low-voltage cabling records, ISP demarcation points, access-control panels, camera network paths, and after-hours building-access procedures. These details can decide whether a small issue becomes a long outage.
GDS’s co-working technology support is designed around the operational reality of shared business environments, where uptime, onboarding, network boundaries, and physical systems directly influence member experience.
Real follow-through matters after the work is complete. Kawal, a professional-services client, said: “GDS followed up the next day to make sure the door sensor issue is resolved. That kind of attention shows real customer service.” That same verification mindset is valuable when validating access-control and network services after an IT transition.
Takeaway: For a coworking space, a successful IT switch protects both the operator’s systems and every member’s daily experience.
What should we expect from the incoming IT provider after the handover?
The transition should end with a usable operating record, not a vague assurance that everything is handled. Your leadership team should receive clear documentation of what the business owns, who has administrative access, how emergencies are escalated, and where critical vendor information is maintained.
Ask the incoming provider to explain the security baseline in plain language. That should cover multifactor authentication, endpoint protection, patching, backup verification, privileged-access controls, logging, incident response contacts, and the process for adding or removing users.
For Microsoft 365, confirm that global administrator access is limited, named, and recoverable by the business. Shared administrator credentials create avoidable risk; individual, role-appropriate accounts create accountability and make future transitions easier.
Your team should also understand the distinction between operational access and ownership. An IT provider needs managed access to support the environment, but the client should retain ultimate authority over its tenant, domain, billing relationships, recovery methods, and business records.
GDS can help organizations review their cybersecurity controls, manage cloud access through cloud services support, and build a documented plan for ongoing technology ownership. For shared commercial properties, its work as a commercial real estate technology partner also recognizes the connection between networks, tenant operations, and building infrastructure.
Request a post-transition review after the first operating period. It should confirm that alerts are reaching the right people, backups are completing, former access is removed, support contacts are correct, and unresolved risks have owners and target dates.
Takeaway: The handover is complete only when your organization has both technical control and documented confidence in how support will work.
Frequently Asked Questions
Can we keep our Microsoft 365 tenant when we change IT providers?
Usually, yes. If your business owns the Microsoft 365 tenant, verified domain, billing relationship, and authorized administrator access, a new provider can generally assume management without moving email or files to a new tenant. Confirm ownership and recovery controls before ending the incumbent relationship.
Should we change all passwords when switching IT companies?
Yes, but rotate credentials in a controlled sequence after the incoming provider has validated access and documented dependencies. Prioritize global administrator accounts, firewall access, domain registrar and DNS accounts, backup platforms, remote-access tools, and password vaults. Remove former-provider accounts once replacement access is tested.
What happens if our old IT company owns the firewall?
If the incumbent owns the firewall, your incoming provider should determine whether it can be transferred, whether its configuration can be documented, or whether a replacement is required. Do not reset it prematurely. Preserve internet settings, VLANs, VPNs, and connected security-system dependencies before any change.
How long should an IT provider transition take for a coworking space?
The timeline depends on the number of locations, users, networks, vendors, and connected systems. A coworking space needs time for discovery, ownership recovery, access testing, network documentation, and post-cutover validation. The right schedule protects member connectivity and avoids unnecessary disruption during high-traffic periods.