We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft
  2. Tenant takeover
Microsoft 365 tenant takeover

The tenant is your property. Whoever configured it years ago is an administrator, not an owner.

Maybe the old provider still holds Global Admin. Maybe the invoices come from them. Maybe the phone just rings out. In all three cases, and in the case where they actively refuse, you get control back. Microsoft regards the customer company as the owner of the tenant, and everything a partner has is delegated, which means it can be withdrawn. Billing moves through a partner-of-record change that leaves mailboxes and files entirely alone. The order that keeps you safe runs like this: find out what they can still reach, stand up admin in your own name first, then take theirs away, then change every credential they ever knew, then lock the whole thing down. Days, in most cases.

Start the takeoverSee the takeover audit
Microsoft
Microsoft
365
Cloud Solution Partner
  • YoursTenant ownership, by design
  • 2-5 daysTypical takeover duration
  • 0Downtime in a billing transfer
  • FreeTakeover scoping audit
The takeover audit

Nine areas we document before a single change is made, because what matters is what they can still get to.

The danger in a handover is never the Global Admin account everybody already knows about. It is the service principal somebody registered in 2019 that nobody has thought about since. So the first pass is read-only and produces a written map: accounts, relationships, applications and rules the old provider set up or still controls, each with a plan for how it comes out.

Who holds Global Admin today

Every holder of Global Administrator, and the actual human behind each one. This is where the provider engineer accounts turn up, along with the generic admin mailbox whose password only they know, and the leftover administrator from the company you used two providers ago. Where it ends is with administration in your name and nobody present that you did not deliberately put there.

GDAP and legacy DAP relationships

Delegation is the mechanism that lets a provider administer your tenant without holding accounts in it. The current model, GDAP, hands over named roles that expire. The one it replaced handed over permanent administrative rights that never did. Both appear under partner relationships in the admin center you control, and both can be terminated by you.

Partner of record and billing

Which partner relationship bills your subscriptions, what the renewal dates are, and which subscriptions sit on the old partner's paper. This determines the transfer sequencing, so licenses continue without a gap and nothing lapses mid-takeover.

App registrations and client secrets

An application the provider registered carries on signing in long after the last engineer has gone, because the secret and the certificate are still sitting on their side. Every registration gets listed with the permissions attached to it, and a decision made per secret: rotate it or retire it.

Enterprise apps and OAuth grants

Monitoring agents, migration tooling, backup platforms and assorted third-party products the provider approved on behalf of everyone in the company. A tenant-wide consent granted years ago is a door left open. Each one gets read, then either kept on purpose or withdrawn.

Conditional Access rules that could lock you out

A policy naming provider accounts, trusting their office address range, or carving them out of the MFA requirement will happily lock you out of your own tenant the second their access disappears. Every policy is read before anything is removed, so that the takeover does not cause the exact lockout it exists to prevent.

Mail rules, forwards, and delegates

Transport rules, forwarding, rules sitting on the important mailboxes, delegate rights and connectors. If anyone still has a quiet view of your email, this is where it will be. Every forward and every delegation gets written down with the beneficiary named, and anything aimed outside the company is called out.

Service accounts and recovery details

Accounts where the reset link lands in the provider inbox, or the code goes to a phone on their desk, plus the technical contact recorded against the tenant. Recovery details are the back door people forget in almost every takeover. Each of them moves to an address and a number your company owns.

Audit log coverage for the transition

We check that unified audit logging is running and take a baseline before anything moves, so the whole handover period is on record. When it is over, the log answers the question every client asks: did they touch anything on the way out.

Billing transfer, explained

Getting the invoice off their paper without going anywhere near your data.

Where the old provider resold your licenses through their CSP agreement, moving the billing is a partner-of-record change and nothing more. Microsoft supports the step, you authorize it yourself from your own admin center, and it happens all the time between companies who are not currently speaking to one another.

How the change works

  • You authorize it, not the old partner
    The incoming partner issues a request, and you accept it from inside your own admin center. Nobody asks the outgoing partner, and they have no ability to block it.
  • Subscriptions move at the right boundary
    Under the New Commerce terms, subscriptions either move across or are created new and lined up against the existing end dates, so there is no gap where somebody cannot sign in.
  • GDAP is granted fresh, and scoped
    Whoever takes over gets only the roles you approve, and only for as long as you set. This is the right moment to stop handing out permanent Global Admin for good.

What happens to your licenses

  • Licenses keep working throughout
    Nobody loses a license while this happens. Assignments hold, and no mailbox goes offline for a second.
  • Nothing needs to be repurchased twice
    Some subscriptions will not move part way through a term, so the replacement begins on the day the old one finishes. The sequencing is where all the work is. Done properly, the only thing anyone in accounts notices is a different name at the top of the bill.
  • Unpaid-invoice standoffs do not strand you
    The data sits in the tenant, not in the subscription attached to it. Even in the worst case, where the old provider cancels out of spite, replacement licenses appear within hours and reattach to the same people with nothing lost.

What does not change

  • Your data, mailboxes, files, and Teams
    Changing partner of record alters who bills and who supports you at Microsoft. No content is moved, exported or opened at any point.
  • Your users and their sign-ins
    Nobody re-enters a password because of a billing transfer. End users cannot tell it happened.
  • Your ownership of the tenant
    It was your tenant on Monday and it is your tenant on Friday. What changed is the name on the support and billing arrangement.
Why run the takeover with us

Four reasons companies hand us the recovery.

Partner-of-record transfers are routine work for us

The mechanics of a transfer, the way licenses have to be ordered, and the places it goes wrong are all well-trodden ground for us. We have done these as friendly handovers and as recoveries against total silence. The list of steps is identical. Only the speed differs.

The Microsoft process, run through partner channels

Where the job needs Microsoft directly, whether that is verifying ownership, moving subscriptions or escalating a support case, it goes through partner channels rather than the public queue, with the paperwork put together in the format Microsoft expects to receive.

Named engineers from audit to hardening

Whoever carries out the audit is the same person who performs the removals and picks up the phone afterwards. An urgent takeover does not sit in a queue behind a nameless service desk, and nothing falls through the cracks between stages because one person owns all of them.

GDAP least-privilege from day one

We hold only the delegated roles the work actually needs, for a limited period, and we show you the page where you can see them and end them. A takeover that finishes with a different company holding permanent Global Admin has relocated the problem rather than solved it. This one finishes with the keys in your hands and our access narrow, visible and revocable.

The situations we take over from

Six ways companies arrive at this page.

The order below does not vary. What varies is how fast it has to happen and how much of it proceeds without the previous provider involved.

The provider has gone quiet or shut down

Nobody picks up, the address is empty, and it is entirely possible the business no longer exists. There is no handover coming, and nothing has been lost. The tenant, the data and the route back to control all carry on existing whether or not the provider does.

Mid-dispute and worried about access

A bill in dispute or a disagreement over terms, and the distinctly uncomfortable knowledge that the other side holds Global Admin while it all plays out. Getting administrative control back is a separate exercise from the argument and can run quietly in parallel with it, leaving the contract to your attorney.

An amicable switch, done properly

The outgoing provider is helpful and behaves well, and the takeover is just the Microsoft portion of a broader change of supplier. Access moves across cleanly, credentials are changed on an agreed date, and both parties end up with a written record of exactly when the old access stopped.

New management inherits an unknown tenant

After an acquisition, or when a new IT manager or owner starts asking questions, it emerges that a company nobody remembers hiring holds administrative rights over everything. The audit turns that unknown into a list, and the list into a clean handover to whoever ought to hold it today.

You suspect the old partner still has eyes inside

An email that turned up somewhere it should not have, or simply a bad feeling after an unpleasant parting. The audit looks in the places where quiet access genuinely hides, meaning forwards, delegations, transport rules and application grants, and the log review across the handover period establishes what was and was not opened.

The tenant was created under the provider account

They created the tenant, verified the domain and have held every credential since the beginning. Creating something does not make it yours. A tenant carrying your verified domain and your licensed staff belongs to your company, and the way back runs exactly as it does in every other situation on this page.

The safe takeover sequence

Five steps, arranged so that you never end up locked out of your own tenant.

Getting the order right matters more than moving fast. Your access goes in before theirs comes out, the ways you could be locked out are mapped before any policy is edited, and everything removed is recorded. Two to five days covers most of these. The emergency version squeezes the same steps into hours without leaving any of them out.
  1. 1

    Verify ownership and run the audit

    Day 1

    First establish that the tenant is yours to reclaim, with the verified domains, the licensing and the corporate paperwork ready in case the Microsoft ownership route is required. Then the read-only audit documents every account, delegation, application secret, Conditional Access rule and mail rule within the old provider reach. Not one thing is altered at this stage.

  2. 2

    Put admin in your own name

    Day 1-2

    A fresh Global Administrator in your company name, plus a sealed pair of emergency accounts kept outside every Conditional Access rule capable of shutting them out, all protected by multifactor on hardware you own. Once that exists, nobody else can halt the takeover, which is precisely why it comes before anything is taken away.

  3. 3

    Remove the delegated and direct access

    Day 2-3

    Delegated relationships of both generations ended from your side, provider administrator accounts disabled or deleted, consents for their tooling withdrawn, and the technical contact on the tenant replaced. Every removal is checked against the Conditional Access map before it happens and written to the record afterward.

  4. 4

    Rotate every credential and secret

    Day 3-5

    On a date you can name, every credential they have ever seen stops working. Administrator accounts, service accounts, shared mailboxes, and the secrets and certificates attached to any application they registered. Integrations that have to keep running are re-keyed, and the ones nobody can account for are retired. Recovery addresses and phone numbers move to contacts your company controls.

  5. 5

    Review the transition window and harden

    Day 5-10

    The audit log covering the handover is read from one end to the other: sign-ins, mailbox access, rule changes, deletions. What we find comes to you in writing. Then the hardening goes in, meaning multifactor, the emergency accounts, the alerting and the access register, so the tenant finishes the engagement in better shape than it has ever been in.

If the previous partner will not cooperate

None of this needs their cooperation. Here is how that actually works.

A fraction of these run against a wall of silence, an argument about an invoice, or a flat refusal. It is unsettling from the inside, and it is usually less difficult than it feels, because the whole model was built to survive this exact scenario. Delegation ends at your end. Disputes over ownership have a defined route. There is nothing they hold that cannot be recovered.

  • Every request goes in writing, carries a date by which you expect an answer, and is kept. Conduct tends to improve noticeably once it is obvious that a record is being built.
  • Where even one administrator account already sits in your name, work starts the same day. That account creates your new administrators, ends the partner relationship and removes theirs. From that moment on, whether they cooperate is no longer a question anybody has to ask.
  • When there is no administrator in your name anywhere, Microsoft runs an ownership verification process built for exactly this. You demonstrate that the company owns the tenant, normally by proving control of the verified domain and producing corporate records such as your articles of incorporation, and administrative access is handed back to the rightful owner. That is a matter of days rather than months.
  • Both GDAP and the older delegated relationships end from the customer side, in your own admin center. Their agreement is not part of the process.
  • Where the refusal is bound up with an unpaid invoice or a contract argument, run the two on separate tracks. Pay what is not in question, put in writing what is, and take legal advice on the agreement itself. Recovering the tenant is an administrative exercise and does not have to wait for the commercial side to be settled.
Get help with a difficult takeover
Tenant takeover FAQ

The questions that come up when somebody else is holding your Microsoft environment.

Anybody with Global Admin can give themselves a mailbox, and forwarding, delegation and transport rules all create quieter forms of access that survive the deletion of the account that created them. That is the straight answer, and it is the reason the audit goes through every one of those places rather than stopping at the list of administrators. The better half of the answer is that opening a mailbox and editing a rule both leave marks in the audit log, so once access is gone we can read the handover window and put in writing whether anything was touched, rather than simply telling you it probably was not.

Whoever holds Global Admin can do damage right up until the moment it is taken away, which is exactly why the sequence puts your access in first and theirs out early rather than spending three weeks negotiating while they still have the keys. Three things reduce the exposure. Deleting at any scale is extremely noisy and sits plainly in the audit log. Content removed from Microsoft 365 goes into retention and recoverable states for a period rather than evaporating. And in practice this almost never happens, because it is traceable and it incriminates the person who did it. If you think something has already been deleted, say so on the first call. The recovery periods are generous, but they do end.

No. Changing partner of record moves who bills and supports you, and nothing else. Mailboxes, files, Teams, SharePoint and sign-ins are all untouched, license assignments carry straight through, and nobody using the system will notice a thing. The one part needing attention is lining subscriptions up against their end dates so nothing lapses in between, and that is the piece we handle. What you get out of it is a partner relationship that, like the tenant, is visible to you and endable at your discretion.

It completes regardless, and knowing that changes how the conversation goes. Delegated relationships end from your side whether they agree or not. If one administrator account exists in your name, we use it and their position stops mattering that same day. If none does, the Microsoft ownership route restores access to the company that owns the verified domain, on the strength of DNS control and your formation documents. Refusing adds days at the outside. It cannot prevent the outcome.

Microsoft regards the customer company as the owner, not whoever happens to be servicing the account. The ownership processes exist to put administrative control back with the verified owner. You show that the organization owns the tenant, normally through control of the verified domain plus corporate documentation, and administrative access is re-established in your name. What Microsoft will not do is referee the commercial argument between the two of you. It answers the question of who controls the tenant, and it answers it in favor of the company the tenant belongs to.

The same day. Where there is a real reason to think somebody is still active in the tenant, the first moves land within hours of ownership being confirmed. Your own Global Administrator stood up, the emergency pair created, delegations terminated, and the most dangerous credentials changed first. The whole sequence, meaning the audit, the removals, the rotation, the log review and the hardening, still runs through over the days that follow, because the urgent version compresses the order rather than dropping any of it. Tell us it is urgent on the form and it is treated that way.

No. Whoever pressed the button has no bearing on who owns the result. The tenant holds your verified domain, your licensed staff and your company data, it is licensed to your organization, and the Microsoft ownership processes are decided on exactly that basis. A provider who built it on day one occupies the same position as one who picked it up five years later: an administrator by delegation, removable by the owner. It is among the most common fears people raise and the one with the tidiest answer.

Yes, and it is an ordinary place to start rather than an unusual predicament. Where the old provider is willing, they create an administrator in your name and the normal sequence proceeds. Where they are not, the Microsoft ownership route applies: prove you control the domain, prove the organization is who it says it is, and administrative access is restored to your company. That adds days rather than months, and once past that first step the work is identical to every other takeover.

They should notice nothing. Identities, mailboxes, files, and Teams do not move; the work happens in the administrative layer above them. The only user-visible moments are deliberate ones we schedule with you, such as rotating a shared-mailbox password or re-keying an integration, and those are sequenced into quiet windows with the affected people told first. Zero disruption is a design goal of the sequence, not a lucky outcome.

Each one gets a decision rather than a default. The audit lists every app registration and enterprise app with the permissions it holds and the secrets that authenticate it. Integrations your business depends on, connectors, backup tools, line-of-business apps, are re-keyed with fresh secrets you own. Provider tooling, such as their monitoring agents and their remote-access consents, is revoked. Orphaned registrations nobody can explain are disabled first and deleted after a safe interval. The end state is an app inventory where every entry has a named owner and a known purpose.

Administrative control of the tenant and the commercial dispute are separate tracks, and keeping them separate helps both. The takeover is a technical process built on Microsoft mechanisms and your ownership of the tenant; it does not depend on how the contract question resolves. Our standing guidance is practical: settle undisputed amounts promptly, document disputed ones in writing, and seek legal advice on the contract itself, because that part is outside what an IT partner should be advising on. What we can say from experience is that recovering control calmly tends to lower the temperature of the dispute rather than raise it.

You do not lose anything that matters, because your data lives in the tenant and the tenant is yours; licenses are the metering on top. Subscriptions bought through the old partner's reseller relationship either transfer to the new partner of record or are replaced with equivalent subscriptions sequenced against the old term dates, so users stay licensed throughout. Even in the worst case, an old partner cancelling their side out of spite, equivalent licenses provision within hours and reattach to the same users with mailboxes and files exactly as they were. A license gap is an inconvenience measured in hours; it is not data loss.
The hour after takeover

What gets locked down straight away, so nobody can put you here a second time.

Removing the old provider is where the takeover finishes. Where the engagement finishes is with a tenant that nobody, ourselves included, can ever use as leverage against you. All of it happens alongside the access removal rather than being parked in a later phase.

  • Multifactor required on every administrative account, and not one exclusion inherited from the previous arrangement.
  • Two emergency accounts in your company name, kept clear of every Conditional Access rule that could shut them out, with the credentials sealed and held by your own leadership rather than by anybody you contract with.
  • Older authentication protocols switched off, so a rotated password cannot simply be replayed through a legacy endpoint.
  • Alerting on the handful of events that actually matter after a handover: a new administrative role assignment, a new partner relationship, a new forwarding rule, a new application consent.
  • A written register of access. Every administrator, every delegation, every application secret, each with a named owner. Precisely the document nobody ever handed you.
See the full tenant security baseline
Related guides

What a well-run tenant looks like after the takeover.

Microsoft 365 Tenant Management

What ongoing, accountable tenant administration looks like once control is back in your hands.

Learn more

Tenant Security Baseline

The hardening standard we apply after every takeover: MFA, Conditional Access, and admin hygiene.

Learn more

Tenant to Tenant Migration

The other exit path: when the inherited tenant is beyond saving and a fresh tenant you own is the cleaner answer.

Learn more
Locked out, or just uneasy?

Start with the free takeover audit and see exactly what the old partner can still reach.

Tell us the situation, cooperative, silent, or mid-dispute, and we will map every account, relationship, and secret the previous partner holds, then give you the findings and the removal plan in writing. If it is urgent, say so and we start the same day. The tenant is yours; getting it back is a process, not a fight.

Book the takeover auditSee Microsoft 365 services

Related Services

Explore more solutions that work great with this service

M365 Tenant Management

Your tenant run properly, end to end

Learn more

Tenant Security Baseline

Documented controls mapped to CIS

Learn more

M365 Administration

Expert Microsoft 365 tenant management

Learn more

Microsoft Entra

Identity and access management solutions

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA