MSP client onboarding checklist
Quick answer
A usable onboarding runs in five phases: paperwork (contract, contacts, authority to work), access (every credential into your password manager, admin accounts created, previous provider offboarded), discovery (what exists, what it runs, what is fragile), baseline (agents on everything, backup verified, MFA and encryption on), and the first 30 days of tightened attention. The checklist below is the version we would actually run; download it and cut what does not apply.
Before day one
- Signed agreement and SLA on file; scope and exclusions written down
- Named contacts: decision maker, day-to-day contact, emergency contact, and who may approve spend
- Authority to hold credentials and act on the client's behalf, in writing
- Offboarding letter sent to the previous provider with a handover deadline
Access and credentials
- Every credential received goes straight into the password manager; nothing lives in email or spreadsheets
- Your own admin accounts created (never shared accounts), with MFA
- Domain registrar, DNS host, email tenancy, backup product, firewall and ISP account access confirmed working
- Previous provider's accounts and API keys disabled once handover completes
Discovery
- Full asset list: servers, workstations, network kit, printers, and who uses what
- Software inventory per machine, licence position for anything paid
- Domains and certificates listed with expiry dates
- Backup: what runs, where it goes, when it last restored successfully
- The fragile things: the machine nobody may reboot, the app pinned to an old OS, the thing only Dave understands
Technical baseline
- Management agent on every machine; anything unreachable gets a plan
- Patch state assessed; catch-up plan for anything more than 60 days behind
- Disk encryption on for laptops, recovery keys escrowed
- MFA on email and anything internet-facing
- EDR or at minimum managed AV on every endpoint
- Backup meeting 3-2-1 (see our backup policy template), restore tested by you, not taken on faith
- Firewall config reviewed; no inbound RDP, no forgotten port-forwards
First 30 days
- Documentation written as you go, in your standard shape
- Ticket triage tightened until the noisy machines are quiet
- First monthly report delivered: what was found, what was fixed, what is next
- Review meeting booked to agree the ongoing roadmap
The discovery phase is a product feature.
Install the Moorfox agent and the asset list, software inventory, disk encryption state and patch age fill themselves in, with a security score per machine to prioritise the baseline work.