Your Microsoft 365 tenant belongs to your company, not to the IT partner who set it up.
If a previous IT provider holds your Global Admin, controls your billing, or has simply stopped answering, control is recoverable in every scenario, including the uncooperative one. Microsoft treats the customer organisation as the tenant owner. Partner access is delegated, and delegated access is removable. Billing moves with a partner-of-record change that never touches your mailboxes or files. The safe sequence is below: audit what the old partner can still reach, put admin in your own name, remove their access, rotate every secret they ever held, then harden what you have recovered. Most takeovers complete in days.
- YoursTenant ownership, by design
- 2-5 daysTypical takeover duration
- 0Downtime in a CSP transfer
- FreeTakeover scoping audit
Nine things we map before touching anything: what the previous partner can still reach.
Who holds Global Admin today
Every account in the Global Administrator role, and whose name each one is in. Provider staff accounts, generic admin@ accounts with provider-controlled passwords, and stale admins from partners two changes ago all surface here. The end state is admin in your name and nobody else you have not chosen.
GDAP and legacy DAP relationships
Delegated admin is how a partner manages your tenant without accounts inside it. Modern GDAP grants specific roles for a limited time; legacy DAP granted standing admin rights with no expiry. Both are listed under partner relationships in your own admin center, and both can be ended from your side.
Partner of record and billing
Which CSP relationship bills your subscriptions, what the renewal dates are, and which subscriptions sit on the old partner paper. This determines the CSP transfer sequencing, so licences continue without a gap and nothing lapses mid-takeover.
App registrations and client secrets
Applications the provider registered in your tenant keep authenticating long after the people leave, because the provider still holds the client secrets and certificates. We list every registration, what permissions it carries, and which secrets must rotate or die.
Enterprise apps and OAuth grants
Remote monitoring tools, migration utilities, backup services, and third-party apps the provider consented to on behalf of your whole organisation. Tenant-wide consent granted years ago is a standing door; each grant gets reviewed, kept deliberately, or revoked.
Conditional Access rules that could lock you out
Policies that reference provider accounts, provider office IP ranges as trusted locations, or exclude only the provider from MFA can lock you out of your own tenant the moment their access ends. We map every policy before removal so the takeover never triggers the lockout it is meant to prevent.
Mail rules, forwards, and delegates
Transport rules, mailbox forwarding, inbox rules on key mailboxes, delegate permissions, and connectors. This is where quiet visibility into your email hides if it exists anywhere. Every forward and delegate is listed with who benefits from it, and anything pointing outside the company is flagged.
Service accounts and recovery details
Accounts whose password reset goes to a provider mailbox or a provider mobile number, and the technical contact registered on the tenant itself. Recovery details are the forgotten back door of most takeovers; each one moves to an address and number your company controls.
Audit log coverage for the transition
We confirm unified audit logging is on and capture a baseline before any change, so the transition window is fully recorded. Afterwards the log answers the question every takeover client asks: did anyone touch anything on the way out.
Moving billing away from the old partner, without touching your data.
How the change works
- You authorise it, not the old partnerThe new partner sends a relationship request that you accept inside your own Microsoft 365 admin center. The old partner is not asked for permission and cannot veto the change.
- Subscriptions move at the right boundaryUnder New Commerce, subscriptions transfer to the new partner or are stood up fresh and sequenced against the old term dates, so there is never a day without licences.
- GDAP is granted fresh, and scopedThe new partner receives only the roles you approve, time-limited. This is the moment to end the blanket-admin habit for good.
What happens to your licences
- Licences keep working throughoutUsers stay licensed during the transfer. Assignment does not reset, and mailboxes do not blink.
- Nothing needs to be repurchased twiceWhere a subscription cannot transfer mid-term, the replacement starts as the old one ends. Sequencing is the whole job; done right, the finance team notices only that the invoice header changed.
- Unpaid-invoice standoffs do not strand youYour data lives in the tenant, not in the subscription. Even if the old partner cancels their side, equivalent licences provision in hours and reattach to the same users with everything intact.
What does not change
- Your data, mailboxes, files, and TeamsA partner-of-record change is a billing and support relationship change at Microsoft. Content is never migrated, exported, or touched.
- Your users and their sign-insNobody re-enters a password because of a CSP transfer. End users cannot tell it happened.
- Your ownership of the tenantThe tenant was yours before, during, and after. The transfer changes who supports and bills it, nothing more.
Four reasons companies hand us the recovery.
Direct Microsoft CSP, verifiable
We hold direct Cloud Solution Provider authorisation from Microsoft with an active, discoverable listing on Microsoft AppSource. When your takeover needs the Microsoft side of the process, ownership verification, subscription transfers, support escalation, we run it through partner channels rather than the public queue.
40+ tenants moved partner-of-record
The transfer mechanics, the licence sequencing, and the failure modes are familiar ground. We have done this for cooperative handovers and for silent ones, and the checklist is the same either way; only the pace changes.
Named UAE engineers, in the same time zone as your crisis
15+ engineers based in Business Bay, Dubai. The engineer who runs your audit is the one who executes the removal and answers the phone afterwards. An urgent takeover does not queue behind an offshore desk.
GDAP least-privilege from day one
We take only the delegated roles the work requires, time-limited, and we show you where to see and revoke them. A takeover that ends with a new partner holding blanket admin has only moved the problem; ours ends with you holding the keys and us holding a scoped, visible, revocable delegation.
Six ways companies arrive at this page.
The provider has gone quiet or shut down
Calls unanswered, the office empty, maybe the company wound down entirely. Nobody is coming to hand anything over, and nothing is lost: the tenant, the data, and the recovery path all exist independently of the provider still existing.
Mid-dispute and worried about access
An invoice standoff or a contract disagreement, and the uncomfortable awareness that the other party holds Global Admin while it plays out. Taking administrative control back is separate from the dispute and can proceed calmly alongside it, while legal advice handles the contract.
An amicable switch, done properly
The old partner is cooperative and professional, and the takeover is simply the Microsoft-specific lane of a wider provider switch: access transferred cleanly, secrets rotated on a known date, and both sides left with a written record of when the old access ended.
New management inherits an unknown tenant
An acquisition, a new IT manager, or a new owner discovers that a provider nobody remembers appointing holds admin over everything. The audit turns the unknown into a list, and the list into a clean handover to whoever should hold it now.
You suspect the old partner still has eyes inside
A forwarded email that should not have been seen, or just unease after a bad ending. The audit checks the places visibility actually hides, forwards, delegates, transport rules, app grants, and the transition-window log review shows what was and was not touched.
The tenant was created under the provider account
The provider registered the tenant, verified your domain, and kept every credential since day one. Creation does not confer ownership: the tenant of your verified domain and your licensed users belongs to your organisation, and the recovery path is the same as every other case here.
Five steps, in an order that never locks you out.
- 1
Verify ownership and run the audit
Day 1
Confirm the tenant is yours to take: verified domains, licensing, and company documentation lined up in case the Microsoft ownership path is needed. Then the read-only audit maps every account, delegated relationship, app secret, Conditional Access rule, and mail rule the old partner can reach. Nothing changes yet.
- 2
Put admin in your own name
Day 1-2
New Global Admin in your company name plus a sealed break-glass pair, excluded from every Conditional Access rule that could lock them out, secured with MFA on devices you control. From this moment the takeover cannot be stopped by anyone else, so it happens before any removal.
- 3
Remove the delegated and direct access
Day 2-3
GDAP and legacy DAP relationships terminated from your side, provider admin accounts removed or disabled, enterprise-app consents for provider tooling revoked, and the partner technical contact replaced. Each removal is checked against the Conditional Access map first, then logged.
- 4
Rotate every credential and secret
Day 3-5
Every password the old partner ever knew stops working on a known date: admin accounts, service accounts, shared mailboxes, and the client secrets and certificates on app registrations they created. Integrations that must survive get re-keyed; orphaned ones get retired. Recovery emails and phone numbers move to addresses you control.
- 5
Review the transition window and harden
Day 5-10
The audit log for the transition period is reviewed end to end: sign-ins, mailbox access, rule changes, deletions. Findings go to you in writing. Then the post-takeover hardening lands, MFA, break-glass, alerting, and the access register, so the tenant ends the engagement safer than it has ever been.
The takeover works without them. Here is the honest version of how.
A minority of takeovers happen against silence, a billing standoff, or an outright refusal to hand anything over. It feels alarming, and it is almost always the easier case than it looks, because Microsoft designed tenant control to survive exactly this. Delegated access ends from your side. Ownership disputes have a defined resolution path. Nothing the old partner holds is irrecoverable.
- Put every request in writing with a deadline and keep the dated trail. Behaviour often changes the moment the process is visibly documented.
- If any admin account exists in your own name, the takeover proceeds immediately: we use it to add your new admins, end the partner relationship, and remove their accounts. Their cooperation stops being relevant at that point.
- If no admin exists in your name at all, Microsoft has a data-protection and ownership-verification process for precisely this situation. You prove the organisation owns the tenant, typically through control of the verified domain and company documentation such as the trade licence, and Microsoft restores administrative access to the rightful owner. It takes days, not months.
- GDAP and legacy delegated admin relationships can be terminated from the customer side in the admin center. The partner does not need to agree.
- Where the refusal is tangled up with a contract or invoice dispute, keep the two tracks separate: settle undisputed amounts, document disputed ones, and seek legal advice on the contract itself. The technical takeover is an administrative process and does not need to wait for the commercial question to resolve.
“Our old IT company stopped replying in the middle of a billing disagreement, and we realised nobody in our business had ever held an admin login. I assumed we were hostages. GR had their own admin accounts established on day one, the old access was gone by day three, and the audit log review showed nothing had been touched on the way out. The part I did not expect was the access register at the end; for the first time we can see exactly who can reach what.”
What we harden immediately, so this can never happen to you twice.
The takeover ends with the old partner out. The engagement ends with the tenant in a state where no future partner, including us, can hold it over you. These are applied in the same visit as the access removal, not left for a phase two.
- MFA enforced on every admin account, with no exclusions carried over from the old setup.
- A break-glass admin pair in your own name, excluded from Conditional Access lockout paths, with credentials sealed and held by your management, not by any provider.
- Legacy authentication disabled, so rotated passwords cannot be replayed through older protocols.
- Alerts on the events that matter after a transition: new admin role assignments, new partner relationships, new mail forwards, and new app consents.
- A written access register: every admin, every delegated relationship, every app secret, with named owners. The document your old partner never gave you.
The questions people ask when a partner holds their Microsoft account.
The wider switch, and what a well-run tenant looks like after.
Switching IT Provider
The complete provider-wide playbook: contracts, credentials beyond Microsoft, and the parallel-run switch.
Microsoft 365 Tenant Management
What ongoing, accountable tenant administration looks like once control is back in your hands.
Tenant Security Baseline
The hardening standard we apply after every takeover: MFA, Conditional Access, and admin hygiene.
Start with the free takeover audit and see exactly what the old partner can still reach.
Tell us the situation, cooperative, silent, or mid-dispute, and we will map every account, relationship, and secret the previous partner holds, then give you the findings and the removal plan in writing. If it is urgent, say so and we start the same day. The tenant is yours; getting it back is a process, not a fight.
Related Services
Explore more solutions that work great with this service
Switching IT Provider
The safe, zero-downtime path away from your current provider
Microsoft CSP
Microsoft Cloud Solution Provider for UAE businesses
M365 Administration
Expert Microsoft 365 tenant management
Microsoft Entra
Identity and access management solutions
M365 Licensing
Optimize your Microsoft 365 licensing costs