01
Write down the jobs you cannot compromise on
Choose three to five recurring tasks: a user and license review, a leaver, a baseline mismatch, a configuration recovery or a suspected account compromise. Add a device or asset workflow if it matters to your service. Treat critical access and recovery requirements as pass/fail.
02
Connect an authorized test customer
Use the technician roles and customer types you actually support. Record consent, delegated access, required Microsoft licenses and connection steps. For MSPControl, verify the organization and provider prerequisites for your identity model; do not assume every workflow is AD-free.
03
Inspect results and deliberate failure paths
Complete approved, reversible test actions. Check task errors and effective Microsoft-side state, not only the confirmation message. Test denied access or an unavailable source safely. A blank result must not become evidence that everything is healthy.
04
Test recovery only for the promised objects
If configuration recovery is required, name the object, captured settings, restore mode and verification step. Keep mailbox and file recovery as separate tests. Exporting an Intune settings template is not proof that you can restore a whole tenant.
05
Calculate the cost for the same scope
Include software, hosting, Microsoft licensing, maintenance, backup, support, onboarding and operator time. Compare the same customer count, technician count, term and currency. Do not assume self-hosting is free to operate or that a hosted fee includes all adjacent services.
06
Plan a controlled handover
Inventory standards, scheduled jobs, permissions, alerts, integrations and recovery copies before replacing anything. Avoid two tools correcting the same setting without an agreed owner. Keep the old workflow available until the new one passes the required tests; then remove obsolete access deliberately.