Microsoft 365 admin takeover
Your former IT provider still controls your Microsoft 365 — here’s how to take it back
It’s an uncomfortable discovery: the email platform your whole business runs on has admin keys, and they’re in somebody else’s hands — an IT company you’ve left, are leaving, or simply lost touch with. First, breathe. Your mailboxes, files and licences are almost certainly intact, and the subscription belongs to your organisation, not to whoever set it up. There are three routes back to control, depending on what you still hold — and if you control your domain name, you have real leverage, because Microsoft’s own processes are built around proving domain ownership. We’re a family-run Bournemouth firm that has supported Dorset businesses since 1995, and taking over Microsoft 365 from an outgoing provider is a job we do regularly. Here’s exactly how it works. Rated 4.9 on Google.
- ● Family-run, supporting Dorset businesses since 1995
- ● We take over from other IT providers regularly
- ● 4.9 on Google
Start here
First, check which lock-out this actually is
There are three quite different ways to be locked out of Microsoft 365, and they need three different fixes. If you’ve lost your own admin password or the phone that does your MFA codes, you want our guide to a locked-out Microsoft 365 admin account. If you’re moving your email to a different Microsoft 365 tenant altogether, that’s a Microsoft 365 migration. This page is scenario three: a third party holds your keys — typically a former IT company, a consultant who moved on, or a provider you’re part-way through leaving.
Two reassurances before anything else. First, nothing here means your data is at risk of vanishing: mailboxes, OneDrive files and Teams history sit in your tenant regardless of who administers it. Second, this is rarely hostage-taking. In our experience most handovers are amicable — the old provider is often just slow, disorganised, or waiting on a final invoice. The routes below work in every case, from the friendly to the frosty.
Which route applies depends on one question: what do you still hold? Some admin access? Route 1. None at all, but nobody else is admin either? Route 2. They hold Global Admin and won’t hand it over? Route 3. Not sure which you are? That’s a five-minute phone call — 01202 775566.
Route 1 — the straightforward one
You still have some admin access: lock the door from the inside
If anyone in your business can sign in to the Microsoft 365 admin centre — even an account you’d forgotten about — you can do this properly, today, in this order:
- Create your own emergency admin first. Before removing anything, set up a Global Administrator account on your own domain, with a strong password and MFA on a phone you control. That way no later step can lock you out.
- Audit who holds the keys. In the admin centre, go to Users > Active users and filter by admin role. Note every account with Global Administrator — especially any belonging to the old provider or named after their company.
- Remove or demote their accounts. Strip the admin roles, then block sign-in. Pause before deleting outright — occasionally an old admin account has services or licences hanging off it, so demote first and tidy later.
- Revoke the partner relationship. This is the step most people miss. An IT provider can administer your tenant without any account in it, through a reseller or delegated-admin (GDAP) relationship. At the time of writing this lives in the admin centre under Settings > Partner relationships — Microsoft does move these menus around — and you can remove the delegated roles from there.
- Re-point the billing. If licences are billed through the old provider, they can lapse — or be cancelled — mid-divorce. Move the subscription onto your own payment details, or onto a new provider you actually trust.
- Sweep for leftovers. Old admin accounts sometimes leave forwarding rules or app permissions behind. Our guide to securing your Microsoft 365 account walks the full checklist.
It’s a one-shot job with a couple of traps in it, so if you’d rather not click alone: we do exactly this remotely, from £20, while you watch — and we always call before we connect.
Route 2 — no admin at all
Nobody has admin? Microsoft’s takeover route for unmanaged tenants
Sometimes there’s no admin login on either side of the break-up — the person who set it up has vanished, or the tenant grew out of staff signing themselves up for free Microsoft services and no one ever formally administered it. Microsoft calls this an unmanaged tenant, and it documents an internal admin takeover process for exactly this situation.
The shape of it: you sign up for a free self-service Microsoft service (Power BI is the usual example) using your own work email address on the domain in question. From there, Microsoft’s takeover wizard invites you to become the admin — and asks you to prove you own the domain by adding a TXT record to its DNS, at your domain registrar. Add the record, Microsoft verifies it, and you become the Global Administrator of your own tenant.
Notice what the proof is: not an old password, not the blessing of the previous IT company — control of the domain. This is why we say that if you control your domain name, you can win. It’s also why the section below on domain ownership matters so much: if the old provider holds the registrar login too, that’s the thing to untangle first.
One honest caveat: this route applies to genuinely unmanaged tenants. If the old provider still holds a working Global Admin account, the wizard won’t quietly hand the tenant to you over their heads — that’s Route 3.
Route 3 — the hard case
They hold Global Admin and won’t cooperate
This is the situation people fear, and it’s the one with the least official paperwork — so here’s the honest version. Per Microsoft support practice (this is how cases are actually handled, rather than a formal published procedure), you can raise a case with Microsoft support and ask for ownership verification, which is escalated through Microsoft’s data-protection team. You’ll be asked to prove the organisation’s claim to the tenant — typically control of the domain’s DNS or registrar account, plus company registration documents such as your Companies House record.
We won’t dress this up: the outcome rests with Microsoft, there’s no published timescale, and we’ve never seen anyone credibly promise one. What genuinely improves your position:
- Put your request in writing to the former provider — polite, specific, dated. Ask for Global Admin access, the domain registrar login, and written confirmation when their access is removed. Keep every reply.
- Check your contract. Many IT support agreements have off-boarding terms, and many stand-offs are really billing disputes wearing a scarier costume. Settling the final invoice often opens the door faster than any escalation.
- Gather your evidence early — registrar access, Companies House documents, proof the domain and email addresses are yours — so the Microsoft case starts strong rather than stalling on paperwork.
- Consider a solicitor’s letter. We’re not solicitors and this isn’t legal advice, but where a provider is withholding access to a business’s own systems, a short letter from yours often concentrates minds. Speak to your solicitor about whether it’s warranted.
Meanwhile, your day-to-day email usually keeps working throughout — this fight is about the keys, not the building.
Check this before anything else
The domain name is the real key — find out who holds it
Every route above leans on one thing: control of your domain name (the bit after the @ in your email addresses). Route 2 proves ownership through DNS. Route 3’s evidence starts with the registrar. So before you do anything else, find out where the domain is registered and whose name is on it.
Run a WHOIS lookup on your domain, or ask your web person which registrar it sits with, and check: can anyone in your business log in to that registrar account? It’s remarkably common for a small business’s domain to have been registered by the old IT provider — sometimes in the provider’s own name — because that was easiest at the time. Nobody was being sinister; it was 2011 and everyone just wanted email working.
If the old provider holds the registrar login, that handover moves to the top of your list: ask for the account credentials or a formal transfer of the domain into an account you own. If the domain is registered in their name rather than the business’s, that’s precisely the moment to loop in your solicitor — and your Companies House records, invoices showing you’ve paid for the domain, and years of public use of the email addresses all help establish whose domain it really is.
Once the domain is in your hands, everything else on this page gets easier.
Free to take — and to share
The leaving checklist: what to demand from any outgoing IT provider
Whether your split is friendly or fraught, this is what a proper Microsoft 365 handover includes. Send it to the outgoing provider as a list; tick items off in writing.
- Global Administrator access — a Global Admin account in your own name, on your own domain. Not their account renamed, not a promise.
- Domain registrar login — or a transfer of the domain into an account the business owns. This is the master key; don’t leave without it.
- DNS control and a copy of the records — a simple export or screenshot of your DNS zone, so email doesn’t silently break the day something changes.
- Backups — what was backed up, where it lives, how to reach it, and a handover copy. If the answer is “Microsoft keeps it all”, read our honest guide to whether Microsoft 365 needs a backup before accepting that.
- Licence inventory — which Microsoft 365 licences you have, who’s assigned what, renewal dates, and who bills them.
- The wider password book — router and Wi-Fi admin, website hosting, antivirus console, and any other systems they managed for you.
- Written confirmation their access has been removed — admin accounts, the partner relationship, remote-access software on your machines, the lot.
If a provider bristles at this list, that tells you something. When customers leave us, this is the handover they get — because it’s simply what a professional exit looks like.
How we work
What happens when 365 Techies takes over
We’ve supported Dorset businesses since 1995, and taking over Microsoft 365 from an outgoing provider is routine work for us — here’s exactly what happens, with no drama:
- An honest triage call first. We work out which route you’re in and what you already hold. If it turns out you can fix it yourself in ten minutes, we’ll say so.
- Simple jobs, remotely, from £20 — removing old admin accounts and partner relationships while you watch. We always call before we connect, so you know it’s us on your screen. Bigger untangles — domain disputes, Microsoft ownership cases — are quoted honestly after we’ve seen what’s involved, because guessing a fixed price for Route 3 would be a fiction.
- Then, if you want us as your new admin: managed Microsoft 365 at £4.85 per user per month — licences assigned, renewals watched, admin access held properly in your name with us as delegated support, never the other way round. Broader cover via our business support plans from £24.38 per computer per month, with a written Service Report after each visit so you always know what was done and why. We’re not VAT registered, so those are the prices you actually pay.
- Same faces every time. You’ll deal with the same small family team on every call — the opposite of the experience that usually brings people to this page.
Remote-first, with on-site visits across Bournemouth, Poole, Christchurch and the rest of Dorset when hands-on is needed, and by-appointment meetings at the Kinson Community Centre — no walk-in shop. Mon–Fri 9–5, on 01202 775566, or text 07520 615332. And when you eventually leave us? You get the checklist above, completed, in writing. That’s the whole point.
// RELATED
- Locked out of your Microsoft 365 admin account — when it’s your own password or MFA that’s the problem, not a third party.
- Microsoft 365 migration — moving to a different tenant or provider properly, once the keys are yours.
- How to secure your Microsoft 365 account — the post-takeover sweep: MFA, forwarding rules and leftover access.
- Does Microsoft 365 need a backup? — the honest answer to “Microsoft keeps it all, right?” before you accept it from an outgoing provider.
- An employee left and you don’t know the passwords — the in-house cousin of this problem.
- Microsoft 365 support — everything we do around Microsoft 365, managed from £4.85 per user per month.
- Business IT support plans — ongoing cover from £24.38 per computer per month, with a written Service Report after each visit.
FAMILY-RUN SINCE 1995 · ★ 4.9 ON GOOGLE · 200+ COMPUTERS UNDER OUR CARE · NO FIX, NO FEE · SAME-DAY REMOTE SUPPORT
// GOOD QUESTIONS
Frequently asked
Can our old IT company legally keep control of our Microsoft 365?
We’re not solicitors, so this isn’t legal advice — but practically, the tenant and its data belong to your organisation, and Microsoft’s ownership processes revolve around proving control of your domain and your company’s registration documents, not around who clicked “create” years ago. Where a provider is withholding access, the routes on this page usually resolve it; where there’s a genuine contract dispute, speak to your solicitor.
Will our email stop working while we take back control?
It shouldn’t. Removing admin accounts and partner relationships doesn’t touch mailboxes, files or Teams — staff carry on working throughout. The genuine risks are billing (licences lapsing if they were billed through the old provider) and DNS changes, which is why re-pointing the billing and getting registrar access are on the checklist. Done in the right order, nobody in the business notices anything.
What is a Global Administrator, in plain English?
The master key to your Microsoft 365. A Global Administrator can create and delete users, reset passwords, read billing, change security settings and grant access to mailboxes. It’s normal for an IT provider to hold this while they look after you — and normal to take it back when they stop.
What is a “partner relationship” and why does it matter?
Microsoft lets an IT provider administer your tenant through a reseller or delegated-admin (GDAP) relationship — without having any user account inside it. That means deleting “their” admin account isn’t enough on its own. At the time of writing you can review and remove these under Settings > Partner relationships in the Microsoft 365 admin centre, and it’s the step most DIY takeovers miss.
What if the old provider owns our domain name too?
Then that’s job one, because the domain is the master key — Microsoft’s takeover and ownership processes both prove your claim through DNS. Run a WHOIS lookup, find the registrar, and ask for the account login or a formal transfer into an account the business owns. If the domain was registered in the provider’s own name, gather your Companies House records and invoices and consider a solicitor’s letter.
How long does Microsoft’s ownership process take?
Honestly: the DNS-based takeover for unmanaged tenants can be quick once the TXT record is in place, but the support route through Microsoft’s data-protection team has no published timescale, and we won’t invent one. What speeds it up is arriving with your evidence ready — registrar access, DNS control and company registration documents.
Can the old provider read our email right now?
Technically, a Global Administrator can grant themselves access to mailboxes — that’s what the role is. In practice the overwhelming majority of IT providers are professionals and do no such thing, so don’t panic; but it’s exactly why a tidy handover ends with written confirmation their access is removed, and a pass through our guide to securing your Microsoft 365 account.
Do we have to sign up with you to get help taking control back?
No. Plenty of businesses just want the keys back in their own hands, and we’ll do that as a one-off — simple remote jobs from £20, bigger untangles quoted honestly once we’ve seen them. If you’d then like us to run Microsoft 365 for you, it’s £4.85 per user per month managed, but there’s no obligation and no hard sell.
Our old IT person was an employee who left, not a company — same process?
Very similar, and often easier because the accounts are on your own domain. Audit the admin roles, remove theirs, check for partner relationships anyway, and change anything they knew. We’ve a separate guide for the wider problem of an employee leaving with passwords in their head — and it pairs well with the leaving checklist on this page.
Do you have an office we can visit to sort this out?
No walk-in premises — we’re remote-first, which suits this job well since it all happens in the Microsoft 365 admin centre anyway. We visit businesses across Bournemouth, Poole, Christchurch and Dorset when on-site work is needed, and can meet at the Kinson Community Centre by appointment. Call 01202 775566 or text 07520 615332, Mon–Fri 9–5.
Locked out of your own Microsoft 365 by an old IT provider?
Call 01202 775566 or text 07520 615332, Mon–Fri 9–5. We’ll tell you honestly which route applies to you — often in one phone call, before you’ve spent a penny. Remote-first, and we always call before we connect. On-site across Bournemouth, Poole, Christchurch & Dorset when it’s needed.
01202 775566 · help@365techies.co.uk · MON–FRI 9AM–5PM