We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft
  2. Tenant takeover
Microsoft 365 tenant takeover, UAE

Your Microsoft 365 tenant belongs to your company, not to the IT partner who set it up.

If a previous IT provider holds your Global Admin, controls your billing, or has simply stopped answering, control is recoverable in every scenario, including the uncooperative one. Microsoft treats the customer organisation as the tenant owner. Partner access is delegated, and delegated access is removable. Billing moves with a partner-of-record change that never touches your mailboxes or files. The safe sequence is below: audit what the old partner can still reach, put admin in your own name, remove their access, rotate every secret they ever held, then harden what you have recovered. Most takeovers complete in days.

Start the takeoverSee the takeover audit
Microsoft
Microsoft
365
Cloud Solution Partner
  • YoursTenant ownership, by design
  • 2-5 daysTypical takeover duration
  • 0Downtime in a CSP transfer
  • FreeTakeover scoping audit
The takeover audit

Nine things we map before touching anything: what the previous partner can still reach.

A safe takeover starts with a complete picture, because the risk is not what you know they hold, it is what nobody remembers they set up. This audit runs read-only against your tenant and produces a written access map: every account, relationship, app, and rule the previous partner created or controls, with a removal plan for each.

Who holds Global Admin today

Every account in the Global Administrator role, and whose name each one is in. Provider staff accounts, generic admin@ accounts with provider-controlled passwords, and stale admins from partners two changes ago all surface here. The end state is admin in your name and nobody else you have not chosen.

GDAP and legacy DAP relationships

Delegated admin is how a partner manages your tenant without accounts inside it. Modern GDAP grants specific roles for a limited time; legacy DAP granted standing admin rights with no expiry. Both are listed under partner relationships in your own admin center, and both can be ended from your side.

Partner of record and billing

Which CSP relationship bills your subscriptions, what the renewal dates are, and which subscriptions sit on the old partner paper. This determines the CSP transfer sequencing, so licences continue without a gap and nothing lapses mid-takeover.

App registrations and client secrets

Applications the provider registered in your tenant keep authenticating long after the people leave, because the provider still holds the client secrets and certificates. We list every registration, what permissions it carries, and which secrets must rotate or die.

Enterprise apps and OAuth grants

Remote monitoring tools, migration utilities, backup services, and third-party apps the provider consented to on behalf of your whole organisation. Tenant-wide consent granted years ago is a standing door; each grant gets reviewed, kept deliberately, or revoked.

Conditional Access rules that could lock you out

Policies that reference provider accounts, provider office IP ranges as trusted locations, or exclude only the provider from MFA can lock you out of your own tenant the moment their access ends. We map every policy before removal so the takeover never triggers the lockout it is meant to prevent.

Mail rules, forwards, and delegates

Transport rules, mailbox forwarding, inbox rules on key mailboxes, delegate permissions, and connectors. This is where quiet visibility into your email hides if it exists anywhere. Every forward and delegate is listed with who benefits from it, and anything pointing outside the company is flagged.

Service accounts and recovery details

Accounts whose password reset goes to a provider mailbox or a provider mobile number, and the technical contact registered on the tenant itself. Recovery details are the forgotten back door of most takeovers; each one moves to an address and number your company controls.

Audit log coverage for the transition

We confirm unified audit logging is on and capture a baseline before any change, so the transition window is fully recorded. Afterwards the log answers the question every takeover client asks: did anyone touch anything on the way out.

CSP billing transfer, explained

Moving billing away from the old partner, without touching your data.

If the previous partner bought your Microsoft licences through their Cloud Solution Provider relationship, the billing moves with a partner-of-record change. It is a Microsoft-supported administrative step, it is authorised by you in your own admin center, and it is routinely done between partners who are not on speaking terms.

How the change works

  • You authorise it, not the old partner
    The new partner sends a relationship request that you accept inside your own Microsoft 365 admin center. The old partner is not asked for permission and cannot veto the change.
  • Subscriptions move at the right boundary
    Under New Commerce, subscriptions transfer to the new partner or are stood up fresh and sequenced against the old term dates, so there is never a day without licences.
  • GDAP is granted fresh, and scoped
    The new partner receives only the roles you approve, time-limited. This is the moment to end the blanket-admin habit for good.

What happens to your licences

  • Licences keep working throughout
    Users stay licensed during the transfer. Assignment does not reset, and mailboxes do not blink.
  • Nothing needs to be repurchased twice
    Where a subscription cannot transfer mid-term, the replacement starts as the old one ends. Sequencing is the whole job; done right, the finance team notices only that the invoice header changed.
  • Unpaid-invoice standoffs do not strand you
    Your data lives in the tenant, not in the subscription. Even if the old partner cancels their side, equivalent licences provision in hours and reattach to the same users with everything intact.

What does not change

  • Your data, mailboxes, files, and Teams
    A partner-of-record change is a billing and support relationship change at Microsoft. Content is never migrated, exported, or touched.
  • Your users and their sign-ins
    Nobody re-enters a password because of a CSP transfer. End users cannot tell it happened.
  • Your ownership of the tenant
    The tenant was yours before, during, and after. The transfer changes who supports and bills it, nothing more.
Why run the takeover with us

Four reasons companies hand us the recovery.

Direct Microsoft CSP, verifiable

We hold direct Cloud Solution Provider authorisation from Microsoft with an active, discoverable listing on Microsoft AppSource. When your takeover needs the Microsoft side of the process, ownership verification, subscription transfers, support escalation, we run it through partner channels rather than the public queue.

40+ tenants moved partner-of-record

The transfer mechanics, the licence sequencing, and the failure modes are familiar ground. We have done this for cooperative handovers and for silent ones, and the checklist is the same either way; only the pace changes.

Named UAE engineers, in the same time zone as your crisis

15+ engineers based in Business Bay, Dubai. The engineer who runs your audit is the one who executes the removal and answers the phone afterwards. An urgent takeover does not queue behind an offshore desk.

GDAP least-privilege from day one

We take only the delegated roles the work requires, time-limited, and we show you where to see and revoke them. A takeover that ends with a new partner holding blanket admin has only moved the problem; ours ends with you holding the keys and us holding a scoped, visible, revocable delegation.

The situations we take over from

Six ways companies arrive at this page.

The sequence below is the same in every case. What changes is the urgency, and how much of the process runs without the old partner.

The provider has gone quiet or shut down

Calls unanswered, the office empty, maybe the company wound down entirely. Nobody is coming to hand anything over, and nothing is lost: the tenant, the data, and the recovery path all exist independently of the provider still existing.

Mid-dispute and worried about access

An invoice standoff or a contract disagreement, and the uncomfortable awareness that the other party holds Global Admin while it plays out. Taking administrative control back is separate from the dispute and can proceed calmly alongside it, while legal advice handles the contract.

An amicable switch, done properly

The old partner is cooperative and professional, and the takeover is simply the Microsoft-specific lane of a wider provider switch: access transferred cleanly, secrets rotated on a known date, and both sides left with a written record of when the old access ended.

New management inherits an unknown tenant

An acquisition, a new IT manager, or a new owner discovers that a provider nobody remembers appointing holds admin over everything. The audit turns the unknown into a list, and the list into a clean handover to whoever should hold it now.

You suspect the old partner still has eyes inside

A forwarded email that should not have been seen, or just unease after a bad ending. The audit checks the places visibility actually hides, forwards, delegates, transport rules, app grants, and the transition-window log review shows what was and was not touched.

The tenant was created under the provider account

The provider registered the tenant, verified your domain, and kept every credential since day one. Creation does not confer ownership: the tenant of your verified domain and your licensed users belongs to your organisation, and the recovery path is the same as every other case here.

The safe takeover sequence

Five steps, in an order that never locks you out.

The sequence matters more than the speed. Access is added before anything is removed, lockout paths are mapped before policies change, and every removal is logged. Most takeovers complete in two to five days; the emergency version compresses the same steps into hours, it never skips them.
  1. 1

    Verify ownership and run the audit

    Day 1

    Confirm the tenant is yours to take: verified domains, licensing, and company documentation lined up in case the Microsoft ownership path is needed. Then the read-only audit maps every account, delegated relationship, app secret, Conditional Access rule, and mail rule the old partner can reach. Nothing changes yet.

  2. 2

    Put admin in your own name

    Day 1-2

    New Global Admin in your company name plus a sealed break-glass pair, excluded from every Conditional Access rule that could lock them out, secured with MFA on devices you control. From this moment the takeover cannot be stopped by anyone else, so it happens before any removal.

  3. 3

    Remove the delegated and direct access

    Day 2-3

    GDAP and legacy DAP relationships terminated from your side, provider admin accounts removed or disabled, enterprise-app consents for provider tooling revoked, and the partner technical contact replaced. Each removal is checked against the Conditional Access map first, then logged.

  4. 4

    Rotate every credential and secret

    Day 3-5

    Every password the old partner ever knew stops working on a known date: admin accounts, service accounts, shared mailboxes, and the client secrets and certificates on app registrations they created. Integrations that must survive get re-keyed; orphaned ones get retired. Recovery emails and phone numbers move to addresses you control.

  5. 5

    Review the transition window and harden

    Day 5-10

    The audit log for the transition period is reviewed end to end: sign-ins, mailbox access, rule changes, deletions. Findings go to you in writing. Then the post-takeover hardening lands, MFA, break-glass, alerting, and the access register, so the tenant ends the engagement safer than it has ever been.

If the previous partner will not cooperate

The takeover works without them. Here is the honest version of how.

A minority of takeovers happen against silence, a billing standoff, or an outright refusal to hand anything over. It feels alarming, and it is almost always the easier case than it looks, because Microsoft designed tenant control to survive exactly this. Delegated access ends from your side. Ownership disputes have a defined resolution path. Nothing the old partner holds is irrecoverable.

  • Put every request in writing with a deadline and keep the dated trail. Behaviour often changes the moment the process is visibly documented.
  • If any admin account exists in your own name, the takeover proceeds immediately: we use it to add your new admins, end the partner relationship, and remove their accounts. Their cooperation stops being relevant at that point.
  • If no admin exists in your name at all, Microsoft has a data-protection and ownership-verification process for precisely this situation. You prove the organisation owns the tenant, typically through control of the verified domain and company documentation such as the trade licence, and Microsoft restores administrative access to the rightful owner. It takes days, not months.
  • GDAP and legacy delegated admin relationships can be terminated from the customer side in the admin center. The partner does not need to agree.
  • Where the refusal is tangled up with a contract or invoice dispute, keep the two tracks separate: settle undisputed amounts, document disputed ones, and seek legal advice on the contract itself. The technical takeover is an administrative process and does not need to wait for the commercial question to resolve.
Get help with a difficult takeover
“Our old IT company stopped replying in the middle of a billing disagreement, and we realised nobody in our business had ever held an admin login. I assumed we were hostages. GR had their own admin accounts established on day one, the old access was gone by day three, and the audit log review showed nothing had been touched on the way out. The part I did not expect was the access register at the end; for the first time we can see exactly who can reach what.”
Finance Director
Finance leadership · Trading company, DMCC
Full tenant control recovered in four days, zero downtime
The hour after takeover

What we harden immediately, so this can never happen to you twice.

The takeover ends with the old partner out. The engagement ends with the tenant in a state where no future partner, including us, can hold it over you. These are applied in the same visit as the access removal, not left for a phase two.

  • MFA enforced on every admin account, with no exclusions carried over from the old setup.
  • A break-glass admin pair in your own name, excluded from Conditional Access lockout paths, with credentials sealed and held by your management, not by any provider.
  • Legacy authentication disabled, so rotated passwords cannot be replayed through older protocols.
  • Alerts on the events that matter after a transition: new admin role assignments, new partner relationships, new mail forwards, and new app consents.
  • A written access register: every admin, every delegated relationship, every app secret, with named owners. The document your old partner never gave you.
See the full tenant security baseline
Tenant takeover FAQ

The questions people ask when a partner holds their Microsoft account.

A holder of Global Admin can grant themselves access to any mailbox, and forwards, delegate permissions, and transport rules can create quieter visibility that outlasts the admin account itself. That is the honest answer, and it is why the takeover audit checks every one of those places rather than only the admin list. The reassuring half is that mailbox access and rule changes leave traces in the audit log, so after access is removed we can review the transition window and tell you in writing whether anything was accessed, not just assure you.

Someone holding Global Admin has destructive capability until it is removed, which is exactly why the safe sequence adds your access first and removes theirs early rather than negotiating for weeks while they still hold the keys. Three things temper the risk: deletion at scale is loud and fully visible in the audit log, deleted content in Microsoft 365 sits in retention and recoverable states for a window rather than vanishing instantly, and in practice destructive exits are rare because they are traceable and self-incriminating. If you believe deletion has already happened, tell us that at the first call; recovery windows are generous but they are windows.

No. A partner-of-record change moves the billing and support relationship, not your content. Mailboxes, files, Teams, SharePoint, and user sign-ins are untouched, licence assignments carry through, and end users cannot tell the transfer happened. The only thing that requires care is sequencing subscriptions against their term dates so nothing lapses in between, which is the part we manage. What you gain is that the partner relationship, like the tenant, ends up in a form you can see and end at will.

The takeover completes anyway, and knowing that changes the conversation. Delegated admin relationships end from your side without their consent. If any admin account exists in your name, we use it and their cooperation becomes irrelevant the same day. If none exists, the Microsoft ownership-verification route restores admin access to the organisation that owns the verified domain, on evidence such as DNS control and your trade licence. Refusal slows a takeover by days at most; it cannot stop one.

Microsoft treats the customer organisation, not the servicing partner, as the owner of the tenant. Its data-protection and ownership processes exist to restore administrative control to the verified owner: you demonstrate the organisation owns the tenant, typically through control of the verified domain and company documentation, and admin access is re-established in your name. What Microsoft does not do is arbitrate the commercial dispute between you and the old partner; it resolves who controls the tenant, and it resolves that in favour of the organisation the tenant belongs to.

Same day. If there is credible concern about active access, the first moves happen in hours once ownership is confirmed: your own Global Admin established, the break-glass pair created, delegated relationships ended, and the riskiest credentials rotated first. The full sequence, audit, removal, rotation, log review, hardening, still runs to completion over the following days, because the emergency version compresses the order, it never skips steps. Call rather than email if it is urgent.

No. Who clicked the create button does not determine ownership. The tenant carries your verified domain, your licensed users, and your company data; it is licensed to your organisation, and Microsoft ownership processes resolve on that basis. A provider who set up the tenant on day one is in exactly the same position as one who inherited it later: an administrator by delegation, removable by the owner. This is one of the most common worries we hear and the one with the cleanest answer.

Yes, and it is a routine starting point rather than a special case. If the old partner is cooperative, they add an admin in your name and the normal sequence runs. If they are not, the Microsoft ownership-verification route applies: proof of domain control and organisational identity, then administrative access restored to your company. It adds days to the timeline, not months, and everything after that first step is identical to any other takeover.

They should notice nothing. Identities, mailboxes, files, and Teams do not move; the work happens in the administrative layer above them. The only user-visible moments are deliberate ones we schedule with you, such as rotating a shared-mailbox password or re-keying an integration, and those are sequenced into quiet windows with the affected people told first. Zero disruption is a design goal of the sequence, not a lucky outcome.

Each one gets a decision rather than a default. The audit lists every app registration and enterprise app with the permissions it holds and the secrets that authenticate it. Integrations your business depends on, connectors, backup tools, line-of-business apps, are re-keyed with fresh secrets you own. Provider tooling, such as their monitoring agents and their remote-access consents, is revoked. Orphaned registrations nobody can explain are disabled first and deleted after a safe interval. The end state is an app inventory where every entry has a named owner and a known purpose.

Administrative control of the tenant and the commercial dispute are separate tracks, and keeping them separate helps both. The takeover is a technical process built on Microsoft mechanisms and your ownership of the tenant; it does not depend on how the contract question resolves. Our standing guidance is practical: settle undisputed amounts promptly, document disputed ones in writing, and seek legal advice on the contract itself, because that part is outside what an IT partner should be advising on. What we can say from experience is that recovering control calmly tends to lower the temperature of the dispute rather than raise it.

You do not lose anything that matters, because your data lives in the tenant and the tenant is yours; licences are the metering on top. Subscriptions bought through the old partner CSP relationship either transfer to the new partner of record or are replaced with equivalent subscriptions sequenced against the old term dates, so users stay licensed throughout. Even in the worst case, an old partner cancelling their side out of spite, equivalent licences provision within hours and reattach to the same users with mailboxes and files exactly as they were. A licence gap is an inconvenience measured in hours; it is not data loss.
Related guides

The wider switch, and what a well-run tenant looks like after.

Switching IT Provider

The complete provider-wide playbook: contracts, credentials beyond Microsoft, and the parallel-run switch.

Learn more

Microsoft 365 Tenant Management

What ongoing, accountable tenant administration looks like once control is back in your hands.

Learn more

Tenant Security Baseline

The hardening standard we apply after every takeover: MFA, Conditional Access, and admin hygiene.

Learn more
Locked out, or just uneasy?

Start with the free takeover audit and see exactly what the old partner can still reach.

Tell us the situation, cooperative, silent, or mid-dispute, and we will map every account, relationship, and secret the previous partner holds, then give you the findings and the removal plan in writing. If it is urgent, say so and we start the same day. The tenant is yours; getting it back is a process, not a fight.

Book the takeover auditCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Switching IT Provider

The safe, zero-downtime path away from your current provider

Learn more

Microsoft CSP

Microsoft Cloud Solution Provider for UAE businesses

Learn more

M365 Administration

Expert Microsoft 365 tenant management

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

M365 Licensing

Optimize your Microsoft 365 licensing costs

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy