Microsoft 365

Getting your tenant back

When the person who set up Microsoft 365 has gone, or a provider relationship has ended, the business often cannot administer its own email. There is a route back, and it starts with the domain.

The domain is the lever. If your business can prove it owns the domain your email runs on, there is a documented route to administrative control of the Microsoft 365 tenant attached to it, whoever currently holds the password.

The usual situations are undramatic. A contractor set it up years ago on their own account. An employee who has left is the only global admin. A provider relationship ended badly. In each case the business has been paying for something it cannot administer.

,

What the job involves

The order matters. Trying to tidy a tenant before you control it wastes the work.

  • Establish what actually exists. Which tenant, which domains are attached, how many accounts, which licences, and who holds administrative roles today.
  • Confirm domain ownership. Who the domain is registered to and whether the business can reach that registrar account. This decides everything that follows.
  • Regain administrative control. Either from the current holder, or through Microsoft's process for a business proving ownership of its domain.
  • Separate ownership from people. A global admin account that belongs to the business, not to an individual, with recovery details held by the business.
  • Remove access that should not persist. Former providers, former staff, and applications nobody remembers consenting to.
  • Document the environment. Accounts, licences, mailboxes, domains, DNS and where the recovery details live.
  • Fix what the inventory exposed. It almost always exposes something, and that is remediation rather than takeover.
,

How it usually goes

  1. A conversation about what you know

    Often less than people expect, which is fine. The domain name is enough to start.

  2. Check the domain and the registrar

    This is the first real question, and occasionally it turns out the domain is the bigger problem.

  3. Agree the route and the scope

    Cooperative handover where possible, the ownership process where it is not. Written scope and price before starting.

  4. Take control and secure it

    Business owned admin account, MFA on it, recovery details recorded.

  5. Inventory and document

    The written record most businesses have never had.

  6. Decide what happens next

    Fix the findings, keep us running it, or take it in house now that there is something to hand over.

,

Who this is for

  • The person who set up Microsoft 365 has left the business.
  • A provider holds the admin account and the relationship is ending.
  • Nobody is certain which accounts have administrative rights.
  • You are paying Microsoft but cannot make changes yourself.

When this is not the right fit

  • You want access to a tenant your business does not own. We will not help with that, and Microsoft's process exists to prevent it.
  • The dispute is really a legal one between two parties. Get that resolved first.
  • You only need day to day administration on a tenant you already control. That is Microsoft 365 administration.
,
,

What Tech True Point can help with

What usually follows:

  • A review of what the inventory turned up, ranked by what matters.
  • Remediation of anything urgent, starting with access that should not exist.
  • Ongoing administration so ownership does not drift back to one person.
  • Broader untangling beyond Microsoft 365, which is technical cleanup.
,

Common questions

Nobody knows the admin password. Is it recoverable?

Usually, and it depends on whether you control the domain. Microsoft has a process for proving that a business owns a domain and taking administrative control of the tenant attached to it. It is paperwork and it takes time rather than minutes.

Where it gets harder is when somebody else holds the domain registration as well. That becomes two recoveries rather than one, and it is worth starting early.

Our previous IT provider will not hand it over.

This happens, and it is more often disorganisation than malice: the accounts were never separated and nobody wants to admit what a mess it is.

Either way you are not stuck. If the business owns the domain, the route back exists regardless of who is holding the keys. What we would avoid is a fight over credentials while your mail is still flowing through their setup.

Can you do this without interrupting our email?

Usually, because taking administrative ownership and changing mail routing are separate things. Regaining control does not require moving anybody's mailbox.

Where mail is at risk is when the recovery ends up requiring a domain move. We would tell you before that point, not during.

What do we get at the end?

Administrative control in an account the business owns, with the recovery details recorded somewhere you can reach without asking anyone. A written record of what exists: accounts, licences, domains, mailboxes, who had access.

Most businesses have never had that document, and it is worth as much as the access itself.

,
Get a Quote

Not sure who holds your tenant

Tell us what you do know: the domain, roughly how many people, and who set it up. That is usually enough to work out which route applies.

Call now Request a quote