The tenant is your property. Whoever configured it years ago is an administrator, not an owner.
Maybe the old provider still holds Global Admin. Maybe the invoices come from them. Maybe the phone just rings out. In all three cases, and in the case where they actively refuse, you get control back. Microsoft regards the customer company as the owner of the tenant, and everything a partner has is delegated, which means it can be withdrawn. Billing moves through a partner-of-record change that leaves mailboxes and files entirely alone. The order that keeps you safe runs like this: find out what they can still reach, stand up admin in your own name first, then take theirs away, then change every credential they ever knew, then lock the whole thing down. Days, in most cases.
- YoursTenant ownership, by design
- 2-5 daysTypical takeover duration
- 0Downtime in a billing transfer
- FreeTakeover scoping audit
Nine areas we document before a single change is made, because what matters is what they can still get to.
Who holds Global Admin today
Every holder of Global Administrator, and the actual human behind each one. This is where the provider engineer accounts turn up, along with the generic admin mailbox whose password only they know, and the leftover administrator from the company you used two providers ago. Where it ends is with administration in your name and nobody present that you did not deliberately put there.
GDAP and legacy DAP relationships
Delegation is the mechanism that lets a provider administer your tenant without holding accounts in it. The current model, GDAP, hands over named roles that expire. The one it replaced handed over permanent administrative rights that never did. Both appear under partner relationships in the admin center you control, and both can be terminated by you.
Partner of record and billing
Which partner relationship bills your subscriptions, what the renewal dates are, and which subscriptions sit on the old partner's paper. This determines the transfer sequencing, so licenses continue without a gap and nothing lapses mid-takeover.
App registrations and client secrets
An application the provider registered carries on signing in long after the last engineer has gone, because the secret and the certificate are still sitting on their side. Every registration gets listed with the permissions attached to it, and a decision made per secret: rotate it or retire it.
Enterprise apps and OAuth grants
Monitoring agents, migration tooling, backup platforms and assorted third-party products the provider approved on behalf of everyone in the company. A tenant-wide consent granted years ago is a door left open. Each one gets read, then either kept on purpose or withdrawn.
Conditional Access rules that could lock you out
A policy naming provider accounts, trusting their office address range, or carving them out of the MFA requirement will happily lock you out of your own tenant the second their access disappears. Every policy is read before anything is removed, so that the takeover does not cause the exact lockout it exists to prevent.
Mail rules, forwards, and delegates
Transport rules, forwarding, rules sitting on the important mailboxes, delegate rights and connectors. If anyone still has a quiet view of your email, this is where it will be. Every forward and every delegation gets written down with the beneficiary named, and anything aimed outside the company is called out.
Service accounts and recovery details
Accounts where the reset link lands in the provider inbox, or the code goes to a phone on their desk, plus the technical contact recorded against the tenant. Recovery details are the back door people forget in almost every takeover. Each of them moves to an address and a number your company owns.
Audit log coverage for the transition
We check that unified audit logging is running and take a baseline before anything moves, so the whole handover period is on record. When it is over, the log answers the question every client asks: did they touch anything on the way out.
Getting the invoice off their paper without going anywhere near your data.
How the change works
- You authorize it, not the old partnerThe incoming partner issues a request, and you accept it from inside your own admin center. Nobody asks the outgoing partner, and they have no ability to block it.
- Subscriptions move at the right boundaryUnder the New Commerce terms, subscriptions either move across or are created new and lined up against the existing end dates, so there is no gap where somebody cannot sign in.
- GDAP is granted fresh, and scopedWhoever takes over gets only the roles you approve, and only for as long as you set. This is the right moment to stop handing out permanent Global Admin for good.
What happens to your licenses
- Licenses keep working throughoutNobody loses a license while this happens. Assignments hold, and no mailbox goes offline for a second.
- Nothing needs to be repurchased twiceSome subscriptions will not move part way through a term, so the replacement begins on the day the old one finishes. The sequencing is where all the work is. Done properly, the only thing anyone in accounts notices is a different name at the top of the bill.
- Unpaid-invoice standoffs do not strand youThe data sits in the tenant, not in the subscription attached to it. Even in the worst case, where the old provider cancels out of spite, replacement licenses appear within hours and reattach to the same people with nothing lost.
What does not change
- Your data, mailboxes, files, and TeamsChanging partner of record alters who bills and who supports you at Microsoft. No content is moved, exported or opened at any point.
- Your users and their sign-insNobody re-enters a password because of a billing transfer. End users cannot tell it happened.
- Your ownership of the tenantIt was your tenant on Monday and it is your tenant on Friday. What changed is the name on the support and billing arrangement.
Four reasons companies hand us the recovery.
Partner-of-record transfers are routine work for us
The mechanics of a transfer, the way licenses have to be ordered, and the places it goes wrong are all well-trodden ground for us. We have done these as friendly handovers and as recoveries against total silence. The list of steps is identical. Only the speed differs.
The Microsoft process, run through partner channels
Where the job needs Microsoft directly, whether that is verifying ownership, moving subscriptions or escalating a support case, it goes through partner channels rather than the public queue, with the paperwork put together in the format Microsoft expects to receive.
Named engineers from audit to hardening
Whoever carries out the audit is the same person who performs the removals and picks up the phone afterwards. An urgent takeover does not sit in a queue behind a nameless service desk, and nothing falls through the cracks between stages because one person owns all of them.
GDAP least-privilege from day one
We hold only the delegated roles the work actually needs, for a limited period, and we show you the page where you can see them and end them. A takeover that finishes with a different company holding permanent Global Admin has relocated the problem rather than solved it. This one finishes with the keys in your hands and our access narrow, visible and revocable.
Six ways companies arrive at this page.
The provider has gone quiet or shut down
Nobody picks up, the address is empty, and it is entirely possible the business no longer exists. There is no handover coming, and nothing has been lost. The tenant, the data and the route back to control all carry on existing whether or not the provider does.
Mid-dispute and worried about access
A bill in dispute or a disagreement over terms, and the distinctly uncomfortable knowledge that the other side holds Global Admin while it all plays out. Getting administrative control back is a separate exercise from the argument and can run quietly in parallel with it, leaving the contract to your attorney.
An amicable switch, done properly
The outgoing provider is helpful and behaves well, and the takeover is just the Microsoft portion of a broader change of supplier. Access moves across cleanly, credentials are changed on an agreed date, and both parties end up with a written record of exactly when the old access stopped.
New management inherits an unknown tenant
After an acquisition, or when a new IT manager or owner starts asking questions, it emerges that a company nobody remembers hiring holds administrative rights over everything. The audit turns that unknown into a list, and the list into a clean handover to whoever ought to hold it today.
You suspect the old partner still has eyes inside
An email that turned up somewhere it should not have, or simply a bad feeling after an unpleasant parting. The audit looks in the places where quiet access genuinely hides, meaning forwards, delegations, transport rules and application grants, and the log review across the handover period establishes what was and was not opened.
The tenant was created under the provider account
They created the tenant, verified the domain and have held every credential since the beginning. Creating something does not make it yours. A tenant carrying your verified domain and your licensed staff belongs to your company, and the way back runs exactly as it does in every other situation on this page.
Five steps, arranged so that you never end up locked out of your own tenant.
- 1
Verify ownership and run the audit
Day 1
First establish that the tenant is yours to reclaim, with the verified domains, the licensing and the corporate paperwork ready in case the Microsoft ownership route is required. Then the read-only audit documents every account, delegation, application secret, Conditional Access rule and mail rule within the old provider reach. Not one thing is altered at this stage.
- 2
Put admin in your own name
Day 1-2
A fresh Global Administrator in your company name, plus a sealed pair of emergency accounts kept outside every Conditional Access rule capable of shutting them out, all protected by multifactor on hardware you own. Once that exists, nobody else can halt the takeover, which is precisely why it comes before anything is taken away.
- 3
Remove the delegated and direct access
Day 2-3
Delegated relationships of both generations ended from your side, provider administrator accounts disabled or deleted, consents for their tooling withdrawn, and the technical contact on the tenant replaced. Every removal is checked against the Conditional Access map before it happens and written to the record afterward.
- 4
Rotate every credential and secret
Day 3-5
On a date you can name, every credential they have ever seen stops working. Administrator accounts, service accounts, shared mailboxes, and the secrets and certificates attached to any application they registered. Integrations that have to keep running are re-keyed, and the ones nobody can account for are retired. Recovery addresses and phone numbers move to contacts your company controls.
- 5
Review the transition window and harden
Day 5-10
The audit log covering the handover is read from one end to the other: sign-ins, mailbox access, rule changes, deletions. What we find comes to you in writing. Then the hardening goes in, meaning multifactor, the emergency accounts, the alerting and the access register, so the tenant finishes the engagement in better shape than it has ever been in.
None of this needs their cooperation. Here is how that actually works.
A fraction of these run against a wall of silence, an argument about an invoice, or a flat refusal. It is unsettling from the inside, and it is usually less difficult than it feels, because the whole model was built to survive this exact scenario. Delegation ends at your end. Disputes over ownership have a defined route. There is nothing they hold that cannot be recovered.
- Every request goes in writing, carries a date by which you expect an answer, and is kept. Conduct tends to improve noticeably once it is obvious that a record is being built.
- Where even one administrator account already sits in your name, work starts the same day. That account creates your new administrators, ends the partner relationship and removes theirs. From that moment on, whether they cooperate is no longer a question anybody has to ask.
- When there is no administrator in your name anywhere, Microsoft runs an ownership verification process built for exactly this. You demonstrate that the company owns the tenant, normally by proving control of the verified domain and producing corporate records such as your articles of incorporation, and administrative access is handed back to the rightful owner. That is a matter of days rather than months.
- Both GDAP and the older delegated relationships end from the customer side, in your own admin center. Their agreement is not part of the process.
- Where the refusal is bound up with an unpaid invoice or a contract argument, run the two on separate tracks. Pay what is not in question, put in writing what is, and take legal advice on the agreement itself. Recovering the tenant is an administrative exercise and does not have to wait for the commercial side to be settled.
The questions that come up when somebody else is holding your Microsoft environment.
What gets locked down straight away, so nobody can put you here a second time.
Removing the old provider is where the takeover finishes. Where the engagement finishes is with a tenant that nobody, ourselves included, can ever use as leverage against you. All of it happens alongside the access removal rather than being parked in a later phase.
- Multifactor required on every administrative account, and not one exclusion inherited from the previous arrangement.
- Two emergency accounts in your company name, kept clear of every Conditional Access rule that could shut them out, with the credentials sealed and held by your own leadership rather than by anybody you contract with.
- Older authentication protocols switched off, so a rotated password cannot simply be replayed through a legacy endpoint.
- Alerting on the handful of events that actually matter after a handover: a new administrative role assignment, a new partner relationship, a new forwarding rule, a new application consent.
- A written register of access. Every administrator, every delegation, every application secret, each with a named owner. Precisely the document nobody ever handed you.
What a well-run tenant looks like after the takeover.
Microsoft 365 Tenant Management
What ongoing, accountable tenant administration looks like once control is back in your hands.
Tenant Security Baseline
The hardening standard we apply after every takeover: MFA, Conditional Access, and admin hygiene.
Tenant to Tenant Migration
The other exit path: when the inherited tenant is beyond saving and a fresh tenant you own is the cleaner answer.
Start with the free takeover audit and see exactly what the old partner can still reach.
Tell us the situation, cooperative, silent, or mid-dispute, and we will map every account, relationship, and secret the previous partner holds, then give you the findings and the removal plan in writing. If it is urgent, say so and we start the same day. The tenant is yours; getting it back is a process, not a fight.
Related Services
Explore more solutions that work great with this service