Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays connect@crossrivertechnology.com

Hiring an IT company

What access does an IT company need to your systems?

Handing over the keys is the moment most owners hesitate. Here is precisely what a provider needs, why each item exists, what nobody should ever ask you for, and how to take it all back.

Written and reviewed by Anthony Omini, Cross River Tech·10 min read·Published · Updated

What access does an IT company need?

An IT provider needs its own named administrator account in your Microsoft 365 or Google tenant, administrator rights on the computers through a management agent, access to the firewall and network equipment, the backup system, and the domain registrar. It should never need your personal passwords, your online banking or your payroll. I do not ask any Dallas business for a password on a first call.

Answered by Anthony Omini, Cross River Tech, Dallas

Fingers resting on the home keys of a backlit laptop keyboard

Key takeaways

  • A provider should get its own named administrator accounts, never your personal login and never a shared password.
  • Remote access is safe when it is consented to, logged, protected by multi-factor authentication and removable in one action.
  • Passwords belong in a password manager owned by your business, with the provider as a member you can remove.
  • Your Microsoft 365 or Google tenant and your domain must be registered to the business, not to the IT company.
  • No honest provider asks for banking, payroll or personal passwords, and I never ask for any password on a first call.

What access does an IT company need?

Less than people fear, and it should be specific enough to write down. A provider looking after a Dallas office needs six things.

  • A named administrator account in your Microsoft 365 or Google Workspace tenant. Named for the provider, not shared with anyone, with multi-factor authentication on the provider's own device.
  • Administrator rights on the computers, delivered through a management agent installed on each machine rather than a password everyone knows.
  • Access to network equipment: the firewall, the switch and the wireless controller, plus your internet account number so the provider can open a ticket with the circuit provider on your behalf.
  • The backup system, so backups can be configured, monitored and restored.
  • A password manager shared with the business, holding credentials for line-of-business software, vendor portals and equipment.
  • Confirmation of who controls the domain registrar, which is where email and the website ultimately live. The provider does not need to own it; the provider needs to know you do.

That list is the whole job. Anything outside it should have a specific reason attached, and you should feel entirely comfortable asking what that reason is. Access to a payroll system, a bank account or someone's personal email is not IT access, and a good provider will decline it even if you offer.

The principle behind all six items is the same: the provider gets its own identity, not yours. That is what makes the access auditable, and what makes it removable in one action on the day you part ways.

Should I give my IT provider admin passwords?

No. You should give them their own administrator accounts instead, which is a different thing and a better one for both sides.

A shared administrator password means nobody can tell who did what. If three people know the same login, the audit log shows one name for everyone's actions. When somebody leaves, whether an employee or a provider, the password has to be changed everywhere it was used, and something always gets missed. And if that password appears in a data breach, you cannot tell whose habits exposed it.

Named accounts fix all of that. My activity appears under my name in your Microsoft 365 audit log, and the same goes for anyone on my team who works in it. Your office manager's activity appears under hers. When Cross River Tech stops working for you, those accounts are disabled and the access is gone completely, in seconds, without changing a single password your staff use. It also means multi-factor authentication is tied to each named person's own phone rather than to a shared device somebody has to pass around.

There is one exception worth understanding. Some equipment, particularly older firewalls, switches and network printers, only supports a single administrator login. In that case the credential goes into the password manager your business owns, and it gets changed when the relationship ends. Treat that as a limitation of the equipment to be documented, not as normal practice.

One more thing about the beginning of the relationship: I do not ask any business for a password on a first call. The first conversation is about headcount, software, what breaks and what you want fixed. Access is discussed only once you have decided to work with me, and it happens through accounts you create and can see, not through credentials read aloud on the phone. Anyone asking for a password before you have hired them is a reason to stop the conversation, which is one of the tests in how to check that an IT company is legitimate.

Is it safe to give an IT company remote access?

Yes, when it is set up properly, and it is how most problems get fixed without anyone driving across Dallas. The safety comes from four properties, and you can ask any provider whether their tool has all four.

  1. It identifies the technician. Every session is tied to a named account, protected with multi-factor authentication, so the log shows who connected, to which machine and when.
  2. It is visible. When someone is connected to a staff member's computer, that person can see it. Screen sharing for support should never be invisible to the person sitting at the desk.
  3. It is logged. Sessions are recorded in a history you can request. If you ever want to know whether anyone connected to the bookkeeper's machine last Thursday, the answer exists.
  4. It is removable. Uninstalling the agent, or disabling the provider's account in the tool, ends all access at once.

There are two modes and it is worth knowing the difference. Attended access is when someone in your office starts a session and watches it; that suits a one-off problem on a personal-feeling machine. Unattended access is an agent installed on managed computers so patching, monitoring and after-hours work can happen without anyone present; that is what makes overnight updates and quiet fixes possible. Servers and shared machines are almost always unattended. If you would prefer a specific machine to be attended-only, say so, and that is easy to configure.

What is not safe is remote access nobody documented: an old tool installed by a previous provider, still connected, still holding a login that has never been reviewed. Part of a proper takeover is finding those and removing them, and it is one of the most common things I find in a first-month audit.

Where should passwords actually live?

In a password manager that your business owns, not in the provider's private vault, not in a spreadsheet and not in the practice manager's notebook.

The distinction matters more than it sounds. If credentials live in your provider's system, you are asking permission to see your own keys, and the day the relationship ends you are negotiating for them. If the account belongs to your business and the provider is a member of it, you can export everything, remove the provider and keep working, all in the same afternoon. The subscription cost of a business password manager is small compared with what it prevents.

A sensible structure has three parts: a shared vault for the credentials the business owns, such as the internet account, equipment logins, vendor portals and software licensing; individual vaults for each employee's own work passwords, which no one else can read; and a break-glass record, on paper in a safe, holding the recovery details for the domain registrar and one emergency administrator account. That last item feels old-fashioned and it is the thing that saves businesses whose only administrator left with the phone that had the authentication app on it.

What should not be in there is anyone's personal banking, personal email or anything unrelated to the business. If a provider is holding those, that is a boundary problem regardless of how much you like them.

Who should own your Microsoft 365 or Google tenant?

Your business, always, with no exceptions worth entertaining. The tenant is the container that holds your email, files, accounts and licensing, and whoever owns it controls whether you keep working.

A provider can be given administrator rights inside your tenant, and that is normal and appropriate. What is not appropriate is the tenant itself being created and held under the provider's own account, with your licenses purchased through them in a way that makes leaving mean losing your email. That arrangement is common enough that it is worth checking today rather than discovering later. Sign in to the admin center yourself, look at who holds global administrator rights, and confirm that a person inside your business is one of them.

You should also keep one emergency administrator account that belongs to your business alone, with a long unique password, its recovery details stored offline, and multi-factor authentication using a method that does not depend on any one individual's phone. That account is not for daily use. It exists so that no departure, dispute or lost device can lock you out of your own company. Setting it up takes a few minutes and it is one of the items on my first-month list, along with the rest of the settings covered in Microsoft 365 security for a small business.

Licensing is the related question. Buying licenses through a provider is fine and often convenient; the test is whether the licenses can be transferred to your own billing arrangement if you leave. Ask that before you sign, not after. The wider version of this, covering the domain, firewall configurations, backups and documentation, is in who owns your passwords, domain and equipment.

What should an IT provider never ask for?

Reasonable requestWhy it existsWhat should worry you
A named admin account in your tenantTo manage accounts, licensing and security, traceablyAsking for your personal login and password instead
A management agent on the computersPatching, monitoring, remote support, endpoint protectionA remote tool with no logging and no named accounts
Firewall and network equipment accessConfiguration, firmware, remote access rulesRefusing to hand the configuration back to you later
Membership of your password managerShared operational credentials in one controlled placeInsisting credentials live only in the provider's own vault
Confirmation of domain registrar controlEmail and website depend on it; you must own itMoving the domain into the provider's account
Vendor contact permissionSo the provider can open tickets on your behalfBecoming the only party a vendor will talk to
Nothing else-Online banking, payroll, personal email, a signed blank authorization

Two more warning signs are worth naming. A provider who wants access before there is any written agreement about what they will do with it. And a provider who becomes evasive when you ask for a list of every account and tool they hold. Both are answerable in one email by anyone doing this properly.

How do you revoke everything if you part ways?

Methodically, and in this order, whether the parting is friendly or not. Print this and work down it.

  1. Confirm you can get in first. Sign in to your tenant with a business-owned global administrator account and to your domain registrar. Do nothing else until both work.
  2. Disable, do not delete, the provider's administrator accounts. Disabling is instant and reversible; deletion can remove things attached to the account.
  3. Remove any delegated or partner relationship in the Microsoft 365 or Google admin center, which is a separate switch from the account itself and is frequently missed.
  4. Uninstall or disable the remote access and management agents on every machine, then check a sample of computers to confirm they are actually gone.
  5. Change the shared credentials the provider knew: firewall, switches, wireless controller, printers, backup system, internet account, vendor portals.
  6. Rotate the break-glass account password and re-enroll multi-factor authentication on a device the business controls.
  7. Export the password manager content into your own account and remove the provider's membership.
  8. Review the audit log for sign-ins and administrative changes over the following couple of weeks. This is the step that catches anything forgotten.

A whole handover done properly takes an afternoon plus a follow-up check. If you are in the middle of it and something is missing, or the previous provider has stopped responding entirely, the recovery route is in your IT guy stopped answering, how to take back control.

What do I ask for, and what do I put in writing?

Here is my own practice, so you can compare it with anyone else you are considering. On the first call I ask no passwords at all. After you decide to work with me, you create a named administrator account for me in your tenant, and one for each member of my team who will work in it, each enrolled in multi-factor authentication on that person's own phone. A management agent goes on the computers, with the tool identifying every technician by name and logging every session. Shared equipment credentials go into a password manager that your business owns and pays for, with me as a member you can remove.

Your domain stays at your registrar in your name. Your tenant stays registered to your business. Your firewall configuration is documented and a copy of the configuration file is stored where you can reach it. Backups are configured in an account belonging to you. And the documentation of all of it, every device, account, license, vendor and recovery step, is written down for you rather than kept in my head.

Everything above is part of managed IT support and it is written into what you receive, not offered as a favor. If you want the security side looked at more broadly, including endpoint protection, email filtering and tested backups, that is cybersecurity, backup and disaster recovery. If you would like to talk it through before granting anything to anyone, get in touch or call (214) 612-7080; I am happy to spend a call helping you audit the access you have already given out.

Questions people ask

Can I give an IT provider limited access instead of full admin?

You can, and for some tasks it works well, but limited rights often turn a five-minute fix into a call asking you to approve something. A better balance is full administrator rights inside a named account with multi-factor authentication and complete audit logging, so every action is attributable and access can be removed instantly. Restrict what nobody needs, such as finance systems, rather than restricting the IT work itself.

Should my IT company know my banking password?

No. There is no IT support task that requires access to business banking, payroll or anyone's personal accounts. If a provider needs to work on a computer used for banking, they work on the computer, not on the account. Keep those credentials in individual vaults no one else can read, and treat any request for them as a serious warning sign regardless of who is asking.

Can I see what my IT provider has been doing on our systems?

Yes, and you should be able to without asking permission. Microsoft 365 and Google Workspace both keep audit logs showing administrative actions by account. Remote support tools keep session histories showing who connected to which machine and when. Ask your provider to show you where those live during onboarding. Anyone reluctant to walk you through them is telling you something useful.

What happens to remote access when an employee leaves?

The management agent stays on the computer because the computer belongs to the business, but the employee's account is disabled and their sessions revoked, which cuts their own access immediately. If the device is not coming back, it can be wiped remotely. The important part is that the employee never held the administrator credentials in the first place, so nothing has to be changed across the office.

Do you need access to our building or server room?

For onsite work, yes, and it should be scheduled rather than open-ended. Most support is remote because it is faster and cheaper for you, so building access matters mainly for hardware, cabling and equipment in the network closet. Whether that means a key, a badge or someone letting me in is your call, and a note of the arrangement belongs in your documentation like everything else.

Is it normal for an IT company to install software on every computer?

Yes. A management agent is how patching, monitoring, endpoint protection and remote support work at all; without one, every update becomes a manual visit. What is not normal is being unable to say what the agent is, what it does or how to remove it. Ask for the product names in writing during onboarding, and keep that list in your own documentation.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Not sure who already has access to your systems? Call (214) 612-7080 or send a note. I will help you list every account, agent and login that touches your business, and remove what should not be there.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080