Takeover checklist
What to check when you take over a client's IT
You've won the client. The outgoing provider's handover tells you what they thought was there. These 32 checks tell you what is: the ones that turn into outages, breaches and unpaid work if they wait until month three. Each says why it matters and how to check it by hand.
Most of them take minutes. Do the first two groups in week one; they decide whether you can recover the client if something goes wrong while you're still finding your way round. The commands are PowerShell for a Windows estate, run as an administrator, and most of the Active Directory ones need the ActiveDirectory module on a domain controller or a machine with the management tools.
Accounts and access
Who can do what, before anyone else finds out first.
List every administrator
Why it matters. Old staff, the previous provider and forgotten service accounts tend to sit in the privileged groups long after anyone remembers why.
How to check. List the members of Domain Admins, Enterprise Admins and Administrators, and account for every name.
Get-ADGroupMember -Identity "Domain Admins" -Recursive | Select-Object Name, SamAccountNameCheck that every admin account signs in with MFA
Why it matters. A Microsoft 365 or Entra administrator protected by a password alone is the account attackers go for first.
How to check. In the Entra admin centre, Protection, Authentication methods, User registration details shows who has registered a second factor. Then check that Conditional Access or security defaults require it, and list who holds the Global Administrator role.
Find accounts unused for 90 days
Why it matters. A leaver's enabled account is a working login that no one will notice being used.
How to check.
Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 -UsersOnly | Select-Object Name, LastLogonDateFind passwords that don't expire, and the service accounts
Why it matters. A password set years ago and shared around is still valid. Service accounts with a service principal name can have their password guessed offline.
How to check.
Get-ADUser -Filter 'PasswordNeverExpires -eq $true' | Select-Object Name, SamAccountName Get-ADUser -Filter 'ServicePrincipalName -like "*"' -Properties ServicePrincipalName | Select-Object Name, ServicePrincipalNameCheck the local administrators on the machines
Why it matters. The same local admin password on every PC means one stolen laptop opens all of them. Everyday users with local admin rights install whatever they like.
How to check. Look for a LAPS policy in Group Policy or Intune. On a sample of machines, list who is in the local Administrators group:
Get-LocalGroupMember -Group AdministratorsFind the shared and generic logins
Why it matters. "reception", "scanner" and "admin" accounts are used by several people, so nothing they do can be traced to a person, and their passwords rarely change.
How to check. Read the user list for names that aren't people, and ask who uses each one. Do the same for shared mailboxes that allow direct sign-in.
Backups
Whether you could recover the client if something broke this week.
Find the last successful backup of every system
Why it matters. A job that has been warning for months still looks like a backup in the handover document.
How to check. In the backup console's job history, note the date of the last successful run for each protected system, and every system that isn't protected at all.
Restore something
Why it matters. A backup is only proven by a restore. Encryption keys, passwords to the backup store and missing drivers turn up during the first real one.
How to check. Restore one file to a different location, and if there are servers, start one server from its backup in an isolated network. Time both.
Check that one copy can't be deleted by the admins
Why it matters. Ransomware operators look for the backup console and delete what they find. A copy that the domain admin credentials can't reach is the one that survives.
How to check. Find out where the copies live, and whether any is offsite and immutable or held under separate credentials.
Find out whether Microsoft 365 is backed up
Why it matters. Microsoft keeps deleted mail and files for a limited time. That isn't a backup you control, and clients often assume it is.
How to check. Ask, then confirm in whichever product is meant to back up mail, OneDrive, SharePoint and Teams that it has completed recently for every user.
Patching and age
What's out of support, and whether updates are reaching the machines at all.
Count the systems past end of support
Why it matters. They get no security fixes. Windows 10 reached end of support on 14 October 2025; Windows Server 2012 and 2012 R2 on 10 October 2023.
How to check.
Get-ADComputer -Filter * -Properties OperatingSystem | Group-Object OperatingSystem | Select-Object Count, NameSee when each machine last installed updates
Why it matters. A patch policy in the RMM says what should happen; the machine says what did.
How to check. The newest installed updates, and whether a reboot is waiting:
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5 Test-Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired'Check that patching works at all
Why it matters. A machine whose update agent is broken fails the same update every night and reports itself as managed.
How to check. Look for repeated installation failures (event 20) in the Windows Update client log:
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-WindowsUpdateClient/Operational'; Id=20} -MaxEvents 20Check third-party software versions
Why it matters. Browsers, PDF readers, runtimes and remote tools are patched separately from Windows, and they're where many attacks start.
How to check. List what's installed and compare the versions with the vendors' current releases:
Get-ItemProperty 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*','HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*' | Where-Object DisplayName | Select-Object DisplayName, DisplayVersion, Publisher | Sort-Object DisplayNameCheck the firmware on the network equipment
Why it matters. Firewalls and VPN appliances on old firmware are among the most exploited devices on the internet, and they don't get patched by accident.
How to check. Note the model and firmware version of the firewall, switches and access points, and compare each with the vendor's current release and end-of-support list.
Note each machine's age and warranty
Why it matters. It's the replacement budget you'll be asked about, and the machines most likely to fail first.
How to check. The serial number and firmware date, then the vendor's warranty lookup:
Get-CimInstance Win32_BIOS | Select-Object SerialNumber, ReleaseDate
Security controls
The defences the client believes they have.
Check antivirus on every machine
Why it matters. A security product that's disabled, out of date or missing from a few machines looks fine in a summary.
How to check. For Microsoft Defender, on each machine:
Get-MpComputerStatus | Select-Object AMServiceEnabled, RealTimeProtectionEnabled, IsTamperProtected, AntivirusSignatureLastUpdatedFor another product, compare its console's device list with the machine list from item 11: a machine missing from the console is the finding.
Check the Windows firewall profiles
Why it matters. A profile switched off to fix one problem years ago is still off.
How to check.
Get-NetFirewallProfile | Select-Object Name, EnabledCheck disk encryption and where the recovery keys are
Why it matters. An unencrypted laptop is a reportable breach when it's stolen, and an encrypted one without a recovery key is lost data.
How to check. Run
manage-bde -status C:on laptops first, then find the recovery keys: Active Directory, Entra ID, or a spreadsheet.Check what's reachable from the internet
Why it matters. Remote Desktop open to the internet, and old port forwards for systems that no longer exist, are how many break-ins start.
How to check. With the client's permission, scan their public addresses from outside, and read the port forwards on the firewall. Remote Desktop (3389) answering from the internet is the finding.
Check the domain's email authentication
Why it matters. Without SPF, DKIM and DMARC, anyone can send mail that appears to come from the client.
How to check.
Resolve-DnsName -Type TXT example.co.uk Resolve-DnsName -Type TXT _dmarc.example.co.ukFor Microsoft 365, check that DKIM signing is turned on for the domain in the Defender portal.
Find mail forwarded outside the company
Why it matters. A forwarding rule to a personal or unknown address is a leak, and a classic sign of a compromised mailbox.
How to check. With the Exchange Online PowerShell module:
Get-Mailbox -ResultSize Unlimited | Where-Object { $_.ForwardingSmtpAddress -or $_.ForwardingAddress } | Select-Object Name, ForwardingSmtpAddress, ForwardingAddressThen check the inbox rules on the mailboxes that matter most with
Get-InboxRule -Mailbox.
Machines and logs
What the machines have been saying while no one was reading.
Ask the disks how they are
Why it matters. Drives report their own decline long before they fail, and a full system drive stops updates and backups.
How to check.
Get-PhysicalDisk | Select-Object FriendlyName, MediaType, HealthStatus, OperationalStatus Get-PhysicalDisk | Get-StorageReliabilityCounter | Select-Object DeviceId, Wear, ReadErrorsTotal, Temperature Get-VolumeRead the system log for the last 30 days
Why it matters. Unexpected restarts, disk errors and services that keep crashing are the outages the client hasn't reported yet.
How to check. Count the events that matter: unexpected shutdowns (41, 6008), disk errors (7, 51, 153) and services that stopped unexpectedly (7031, 7034):
Get-WinEvent -FilterHashtable @{LogName='System'; Id=41,6008,7,51,153,7031,7034; StartTime=(Get-Date).AddDays(-30)} | Group-Object Id, ProviderName | Sort-Object Count -Descending | Select-Object Count, NameFind the programs that keep crashing
Why it matters. The line-of-business application that crashes ten times a day becomes your first support ticket, and its cause is usually in the log.
How to check. Group the application errors (event 1000) by the program that crashed:
Get-WinEvent -FilterHashtable @{LogName='Application'; Id=1000; StartTime=(Get-Date).AddDays(-30)} | Group-Object { $_.Properties[0].Value } | Sort-Object Count -Descending | Select-Object Count, NameLook for failed sign-ins and lockouts
Why it matters. A steady run of failures against one account is either a forgotten device using an old password or somebody guessing.
How to check. On a domain controller, with auditing on, lockouts are event 4740 in the Security log and failed Kerberos pre-authentication is 4771; on a single machine, failed sign-ins are 4625.
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4740; StartTime=(Get-Date).AddDays(-7)}
What's installed
Software the client didn't know about, and the tools the last provider left behind.
Find software the client didn't approve
Why it matters. Remote access tools, file-sharing clients and browser toolbars installed by users are how data leaves and how attackers stay in.
How to check. Read the installed software list from item 14 against what the client says they use, and the running services:
Get-Service | Where-Object Status -eq 'Running' | Sort-Object DisplayName | Select-Object Name, DisplayNameFind the previous provider's tools
Why it matters. Their monitoring agent, remote access tool, scheduled scripts and accounts still work. Remove them once yours are in place, and not before.
How to check. Look for their agents in the installed software and services, their accounts in item 1, and the scheduled tasks that aren't Microsoft's:
Get-ScheduledTask | Where-Object TaskPath -notlike '\Microsoft\*' | Select-Object TaskPath, TaskName, State
Ownership and paperwork
Who holds the keys to things that can't be fixed with a password reset.
Find out who owns the domain and the DNS
Why it matters. If the outgoing provider is the registrant, or holds the only login, they can take the client's email and website offline by accident or on purpose.
How to check. Look up the registrar and renewal date, and get the client's own login to the registrar and to whoever hosts the DNS. Note the expiry date.
List the certificates and when they expire
Why it matters. An expired certificate on the VPN or the mail server is an outage on a date you can know today.
How to check. Open each public service in a browser, or check its certificate, and note the expiry date of every one.
Reconcile the licences
Why it matters. Too few is an audit risk; too many is money the client is wasting and will thank you for finding.
How to check. In the Microsoft 365 admin centre, Billing, Licenses, compare assigned and purchased. Collect the keys and contracts for the line-of-business software and the server licences.
Collect the passwords, the contracts and the diagrams
Why it matters. The firewall's admin password, the ISP contract number and the network diagram are hardest to get after the last provider has gone.
How to check. Get every administrative credential in the handover (firewall, switches, Wi-Fi, printers, backup console, registrar, Microsoft 365), then change them. Note the renewal dates and notice periods of the internet, phone and software contracts.