A public sector IT director reached out to us a couple weeks back with a problem we hear more often than you'd think: after ten years with one IT provider, the relationship had broken down, and the provider still held effective control of the organization's Microsoft 365 environment. The client's words for it were blunt. It felt like a bad marriage, and they wanted out.
If you've ever wondered what happens when you want to fire your IT company but they run your Microsoft tenant, this is the situation you're worried about. The good news is that there's a well-established way through it. The key is understanding who owns what, and doing the separation in the right order.
Ownership is not the same as day-to-day management
A lot of small and mid-sized organizations let their IT provider stand up their Microsoft 365 tenant, register the domain, and hold the Global Administrator account. That's convenient right up until you want to leave. At that point you discover the provider controls the front door, and you're a guest in your own house.
The first thing we look at is who holds Global Administrator, who owns the domain registration, and who controls DNS (the Domain Name System, which routes your email and web traffic). In this case the client had, after months of pushback and the threat of a court order, regained Global Admin, the domain, and DNS. That matters, because it changes the whole plan. Once you control those three things, nothing that remains in the old provider's hands can block the move.
When you hire any IT provider, confirm in writing that your organization owns the Microsoft tenant, the domain registration, and at least one Global Admin account that the provider does not control. It's a five-minute conversation that saves months later.
Why a clean new tenant often beats cleaning up the old one
When this client finally got a good look inside the existing tenant, they were surprised at what they found. Hundreds of extra accounts, personal email addresses tied to logins, license counts that had no relationship to the actual number of students and staff, and scripts left running in device management. Trying to audit and untangle all of that can cost more than starting fresh.
So the plan we discussed was to stand up a brand new tenant, provision it cleanly with the right licensing, harden it, and migrate only the data and users that belong there. The old tenant becomes a source you pull from, not something you try to rehabilitate. Microsoft themselves reportedly told the client they didn't see a cleaner path, and that tracks with our experience.
Stabilize before you migrate
Here's the part people miss. If access could change hands mid-transition, you don't want to be halfway through a migration when it does. That's the worst possible moment to lose access, because you'd be stuck with one foot in each tenant and neither one usable.
So the sequence we'd recommend is to first establish a stable, verified baseline in the environment you're migrating from. That means confirming you truly hold admin, the domain, and DNS, identifying any accounts, scripts, or delegated access still tied to the old provider, and giving the source environment a clean bill of health before a single mailbox moves.
We can quantify disruption when we control both ends of the migration. We can't when one end is partly in someone else's hands.
- Confirm and document ownership of Global Admin, the domain, and DNS.
- Inventory the old tenant to find extra accounts, leftover scripts, and access paths the outgoing provider could use.
- Stabilize that environment so it's a reliable source to migrate from.
- Stand up and harden a clean new tenant with correct licensing.
- Migrate verified users and data, then decommission the old tenant and the relationship.
Plan for downtime, and have a backup
Any cutover carries some risk of temporary disruption, and a school district can't have attendance and other daily systems go dark without a plan. This client was already printing paper packets for each school as a fallback. That's smart. Whatever your business, before you cut over, know which systems people rely on every day and how they'll keep working if something hiccups during the transition.
If this sounds familiar
Getting out from under an IT provider who controls your Microsoft environment is stressful, but it's a solved problem when you take it in the right order. If you're in a spot like this, or you just want to confirm you own your own tenant and domain, we're happy to talk it through and help you map out a clean path.