Key Takeaway: The first 90 days of a client relationship set the tone for everything that follows. A documented onboarding process is the difference between a client who feels taken care of and a client who wonders what they are paying for. The documentation should be complete enough that any competent technician on your team could support this client without asking you for context.
The first 90 days of a client relationship set the tone for everything that follows. A client who experiences a smooth, professional onboarding process believes they made the right decision. A client who experiences a chaotic, undocumented onboarding process starts questioning it immediately. The difference is not the quality of your technicians. It is whether you have a documented process that your team follows consistently.
This is the MSP onboarding checklist from the provider’s perspective: what you need to do, in what order, to set the client relationship up for success. It is not a client-facing document. It is the internal process that produces the client experience you want to deliver.
Phase 1: Discovery and Documentation (Days 1-14)
The first two weeks are about understanding the client’s environment completely before you change anything. The MSP that starts deploying tools before they understand what they are deploying into creates problems that take months to resolve.
Network discovery. Run a full network scan to identify every device on the network: workstations, servers, printers, network equipment, IoT devices, and anything else connected. Document the network topology. Identify devices that are not managed, not patched, or not accounted for in the client’s asset inventory.
Asset inventory. Create a complete inventory of every device under management: make, model, serial number, operating system, OS version, and patch status. Flag any devices running end-of-life operating systems. Flag any devices that do not meet the minimum hardware requirements for your security stack.
Credential collection. Collect and document all credentials required to manage the environment: domain admin, local admin, network equipment, backup systems, cloud platforms, and line-of-business applications. Store them in your PSA’s credential vault. Verify that every credential works before you need it in an emergency.
Software inventory. Document every application installed across the environment. Identify unlicensed software, end-of-life applications, and applications that create security or compliance risks. This inventory is the foundation of your patch management process.
Security baseline assessment. Assess the current security posture against your standard baseline: MFA status, EDR deployment, backup configuration, DNS filtering, patch compliance, and any other controls in your standard stack. Document the gaps. This assessment drives the remediation work in Phase 2.
Backup verification. Verify that the client’s existing backup is configured correctly, running successfully, and has been tested. If the backup has never been tested, schedule a restore test in the first 30 days. Do not assume the backup works because the job is completing.
Phase 2: Deployment and Remediation (Days 15-45)
Phase 2 is about deploying your standard stack and remediating the gaps identified in Phase 1. The order matters: deploy monitoring before you start making changes, so you can see the impact of what you are doing.
RMM agent deployment. Deploy your RMM agent to every device under management. Configure monitoring alerts according to your standard template. Verify that every device is reporting correctly before you move on.
EDR deployment. Deploy your endpoint detection and response solution to every workstation and server. Verify coverage. Flag any devices where deployment fails and resolve the issue before proceeding.
Backup deployment. Deploy your standard backup solution if the client is not already on it. Configure backup jobs according to your standard template. Verify that the first backup completes successfully. Schedule the first restore test.
DNS filtering deployment. Deploy DNS filtering to all devices and network equipment. Configure policies according to your standard template. Verify that filtering is active and logging correctly.
MFA enforcement. Enforce MFA on all accounts according to your security baseline. This includes email, VPN, remote access, and any cloud platforms. Document the enforcement status for each platform. This documentation is what you will need for the client’s cyber insurance renewal.
Patch remediation. Address the patch gaps identified in Phase 1. Prioritize critical and high-severity vulnerabilities. Document the remediation. Establish the ongoing patch management cadence.
Security awareness training enrollment. Enroll all users in your security awareness training platform. Send the first phishing simulation. Document enrollment and completion rates.
Phase 3: Relationship Establishment (Days 46-90)
Phase 3 is about establishing the relationship patterns that will define the ongoing service experience. The technical work is largely done. The relationship work is just beginning.
First quarterly business review. Schedule and conduct the first QBR within 90 days of onboarding. The agenda: review the onboarding findings, present the technology roadmap draft, discuss the client’s business priorities for the next quarter, and establish the communication cadence for the ongoing relationship.
Technology roadmap draft. Produce the first version of the technology roadmap based on the Phase 1 assessment. It does not need to be comprehensive. It needs to identify the three to five most important technology priorities for the next 12 months and the investments required to address them.
Helpdesk introduction. Introduce the client’s team to your helpdesk process: how to submit tickets, what to expect in terms of response times, and who to contact for different types of issues. This introduction reduces the friction of the first few months and sets expectations that prevent frustration.
Documentation completion. Verify that the client’s environment documentation is complete and current in your PSA. Every device documented. Every credential stored. Every known issue recorded. Every process documented. The documentation should be complete enough that any competent technician on your team could support this client without asking you for context.
Onboarding review. Conduct an internal review of the onboarding process. What went well? What took longer than expected? What gaps were found that were not anticipated? Use the findings to improve the onboarding process for the next client.
The Onboarding Checklist
Use this as a template for your PSA. Every item should be a task assigned to a specific technician with a due date.
Phase 1 (Days 1-14):
- Network discovery scan completed and documented
- Asset inventory complete and in PSA
- All credentials collected and stored in credential vault
- Software inventory complete
- Security baseline assessment complete with gaps documented
- Backup verification complete
- Restore test scheduled
Phase 2 (Days 15-45):
- RMM agent deployed to all devices
- EDR deployed to all devices
- Backup solution deployed and first backup verified
- DNS filtering deployed and active
- MFA enforced on all platforms
- Critical and high patches remediated
- Security awareness training enrollment complete
Phase 3 (Days 46-90):
- First QBR scheduled and conducted
- Technology roadmap draft complete
- Helpdesk introduction complete
- Documentation complete and verified
- Onboarding review conducted
Frequently Asked Questions
How long should MSP onboarding take?
A thorough onboarding for a 25-user client typically takes 30 to 60 days for the technical phases and 90 days to complete the relationship establishment phase. Rushing the technical phases creates problems that take months to resolve. The time invested in a thorough onboarding pays back in reduced support burden and stronger client relationships.
What if the client’s environment is in worse shape than expected?
Document everything you find and present it to the client in the first QBR. The client who understands the state of their environment before you started is a client who appreciates the work you are doing. The client who discovers problems after the fact is a client who wonders why you did not catch them sooner. Transparency about what you found is a trust-building opportunity, not a liability.
Should I charge for onboarding?
Yes. Onboarding is a significant investment of technician time. An onboarding fee of $500 to $2,000 depending on the size and complexity of the environment is standard and appropriate. The fee covers the discovery, documentation, and deployment work that makes the ongoing service possible. Clients who understand what onboarding involves will accept the fee. Clients who do not are worth educating.
About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He helps MSPs operate with greater maturity and helps business owners make IT choices that make them more secure and more efficient. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.