The first thirty days decide whether a new client trusts you. A missing admin password, an agent that never reported in or a user who couldn’t log in on day one will be remembered long after the contract was signed.
Signing a new managed services client is the easy part. Then your team has to take over an environment somebody else built, often with no documentation, credentials scattered across sticky notes and an outgoing provider who is in no hurry to help. Everything you later promise the client, from the SLA and patching to backups and the monthly report, depends on getting that takeover right. This free MSP client onboarding checklist covers the technical side of onboarding: collecting and securing access, running discovery, deploying the RMM, EDR and backup agents, building the documentation, going live on the service desk and closing out with a 30-day review. It is written for service managers, onboarding engineers and vCIOs who want every new client onboarded the same way, whichever engineer is assigned. A conditional phase handles the handover from an incumbent IT provider, so it only appears when there is one.
Commercial Onboarding Is a Welcome Pack. Technical Onboarding Is a Takeover.
Most client onboarding advice is about the relationship: a kickoff call, a welcome email, introductions to the account team. That matters, and our general client onboarding checklist covers it well. An MSP has a second, harder job running alongside it. You are taking operational responsibility for a network, a cloud tenant and every device in the building, usually within a few weeks, and usually from someone who knew it better than you do.
The failures in MSP onboarding are rarely dramatic. They are small gaps that stay hidden until they cost something: a laptop that never got the RMM agent and so was never patched, a domain registrar login that only the old provider had, a backup that was configured but never tested, a firewall rule nobody can explain. A checklist closes those gaps by making every step explicit and making discovery reconcile against deployment, so that “every device” means every device.
Done when: every in-scope device is managed, protected, backed up and documented.
Risk if missed: an unmanaged device, an untested backup or a lockout, discovered during an incident.
What the MSP Client Onboarding Checklist Covers
Seven phases take a new client from signed agreement to steady-state service. Phase 3 appears only when an incumbent IT provider is handing over.
Phase 1
Phase 1: Sales Handover & Kickoff
Review the sales handover — signed agreement, service tier, sites, user and device counts, anything promised during the sale and the target go-live date
Set up the client in the PSA — company, contacts, agreement, SLA plan and billing, so tickets and time can be logged from day one
Hold the kickoff meeting — introduce the onboarding lead, confirm the primary and escalation contacts and agree the cutover date
Record authorised contacts — who at the client can approve changes, request new users and ask for access to data
Agree the end-user communication plan — when staff hear about the change, how they will raise tickets and who sends the message
Phase 2
Phase 2: Access & Credentials
Credentials go straight into your password vault or documentation platform. Never collect them by email or spreadsheet.
Collect administrative access — domain, Microsoft 365 or Google Workspace, firewall, Wi-Fi, DNS and domain registrar, ISP portals and line-of-business applications
Create named admin accounts for your engineers — each protected by MFA, instead of sharing the client’s own global admin account
Secure break-glass access — confirm the client holds an emergency admin account that does not depend on your tools
Store every credential in the vault — linked to the client, with the owner and the date collected
Collect vendor and licensing contacts — software vendors, support contracts, licence keys and renewal dates
Phase 3 — If Replacing a Provider
Phase 3: Incumbent Provider Handover
Shown only when the client is moving from another IT provider. Conditional logic removes it for clients with no incumbent.
Request the handover pack in writing — credentials, documentation, network diagrams, licence records and open tickets, with a deadline
Confirm ownership of key accounts — domain registrar, Microsoft 365 tenant and licensing are in the client’s name, not the outgoing provider’s
Agree the removal of the old provider’s tools — a date to uninstall their RMM and remote access agents, and to revoke their admin accounts
Revoke the outgoing provider’s access on cutover — admin accounts, VPN, remote support tools and any delegated admin relationships
Phase 4
Phase 4: Discovery & Baseline
Run network discovery — scan every site and record all workstations, servers, network devices, printers and IoT devices
Document the network — IP ranges, VLANs, firewall rules, VPNs, wireless networks and internet circuits
Inventory the cloud estate — tenants, SaaS applications, licences in use and who administers each one
Identify existing protection — current backup, antivirus or EDR, and email security, and whether each one is actually working
Record baseline risks — unsupported operating systems, accounts without MFA, remote desktop exposed to the internet, missing backups
Phase 5
Phase 5: Agent Deployment & Tooling
Deploy the RMM agent — to every in-scope device, then reconcile the agent list against the discovery inventory until nothing is missing
Deploy endpoint protection — install your antivirus or EDR agent and confirm the previous product is removed cleanly
Configure backups — servers, endpoints in scope and cloud tenants, then run the first job and a test restore
Apply monitoring and patch policies — alert thresholds, patch windows and maintenance schedules, as defined in the agreement
Connect alerting to the PSA — make sure RMM, backup and security alerts create tickets in the right queue
Phase 6
Phase 6: Documentation
Build the client record in your documentation platform — sites, contacts, network diagram, configurations and vendor list
Record client-specific procedures — new user requests, printer quirks, line-of-business application support and anything that differs from your standard
Link the records — assets, configurations and passwords connected across the PSA, RMM and documentation platform
Write up the baseline findings — each risk found in discovery, with a recommended fix and an estimate
Phase 7
Phase 7: Go-Live & 30-Day Review
Cut over the service desk — switch the support phone number, email and portal to your team on the agreed date
Send the welcome message to users — how to get help, support hours and what to expect in the first week
Run hypercare for the first week — priority handling for the new client’s tickets, and a daily check that every device is reporting
Hold the 30-day review with the client — open issues, first impressions and the remediation plan from the baseline findings
Hand over to the service team — close the onboarding project in the PSA and start the recurring schedules for patching, the monthly report and the QBR
Onboarding time depends on the size of the client and the state of what you inherit. A ten-seat office with a cooperative outgoing provider can be done in a fortnight, while a multi-site client with no documentation can take a quarter. Most small and mid-sized clients fit a 30-day plan like the one below. Agree it with the client at kickoff, so everyone knows when the cutover will happen.
When
What happens
Done when
Checklist phase
Before day 1
Sales handover, PSA setup, kickoff
Cutover date and authorised contacts agreed
Phase 1
Week 1
Credentials collected, incumbent handover requested, discovery run
Admin access verified and a full device inventory exists
Phases 2–4
Week 2
RMM, EDR and backup agents deployed
Agent list matches the inventory, and the first backup has been test-restored
Phase 5
Week 3
Documentation built, service desk cutover
Any engineer can support the client from the documentation alone
Phases 6–7
Day 30
30-day review and handover to the service team
Remediation plan presented and recurring schedules running
Phase 7
Two rules make the timeline hold. First, don’t cut over the service desk until the RMM agent is on every device you are responsible for. Tickets from machines you can’t see are the fastest way to miss an SLA in week one. Second, don’t fix everything you find during discovery. Record it, price it and present it at the 30-day review, so remediation is agreed and paid for rather than absorbed.
Why Onboard New MSP Clients in CheckFlow?
1
One template, every new client
Build the onboarding process once and launch it for each new client with the client name, service tier and onboarding engineer filled in. Conditional logic adds the incumbent handover phase only when there is one, so you don’t need a separate version for every situation.
2
Every onboarding in flight, in one view
When three clients are onboarding at once, the grid view shows where each one stands: who is still waiting for credentials, whose agents are deployed and which cutover dates are close. Nothing depends on one engineer remembering what they were up to.
3
A live view the client can follow
Share a read-only view of the onboarding checklist with the client’s contact, under your brand, so they can see progress without chasing. It shows your process to a new client in their first week, when they are most likely to be watching.
Client onboarding is the first process most MSPs standardise, and the one with the most visible payoff. The MSP process management guide covers the other core processes to standardise next, and CheckFlow for MSPs shows how they run across every client from one place.
Once the client is live, the Monthly Managed Services Report Checklist takes over. The baseline findings from discovery become the first recommendations in the client’s first monthly report and QBR.
It is the process of taking over operational responsibility for a new client’s IT. It covers collecting and securing administrative access, discovering and documenting the environment, deploying your management, security and backup tools, cutting the service desk over and reviewing the result with the client. It differs from general client onboarding because the MSP is inheriting live systems, not just starting a relationship.
How long does MSP client onboarding take?
+
For most small and mid-sized clients, two to six weeks. The main variables are the number of sites and devices, how much documentation exists and how cooperative the outgoing provider is. Agree a target cutover date at kickoff and track against it. If discovery turns up far more than expected, move the date deliberately rather than letting it slip.
How is this different from a general client onboarding checklist?
+
A general client onboarding checklist, like the one in our client onboarding guide, focuses on the relationship: kickoff, welcome, expectations and first deliverables. This template covers the technical takeover specific to managed services: credentials, incumbent handover, discovery, agent deployment, documentation and service desk cutover. Most MSPs run both, with the account manager owning the first and the onboarding engineer the second.
What if the outgoing provider won’t cooperate?
+
Start early and put requests in writing, with deadlines. Most important accounts can be recovered by the client directly, because the domain registrar, the Microsoft 365 tenant and the licensing should be in the client’s name. Phase 3 checks exactly that. Where the outgoing provider controls something the client should own, the client usually needs to make the request, so brief them at kickoff.
Should we fix the problems we find during discovery?
+
Fix anything that is an immediate risk, such as an exposed remote desktop service or an admin account without MFA, and tell the client you have done it. Record everything else as a baseline finding with a recommendation and an estimate, and present it at the 30-day review. That gives the client a clear starting position and keeps remediation from quietly eating your onboarding margin.
Can the template handle clients of different sizes or service tiers?
+
Yes. The template is fully editable, and conditional logic can show or hide tasks by service tier. For example, it can add security awareness training setup only for clients on a security bundle, or add co-managed handover tasks when the client has its own IT staff. One template handles the variations without maintaining separate copies.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Onboard Every Client the Way Your Best Engineer Would
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more