
Who owns your Microsoft 365 tenant when an IT provider buys the licenses, creates the accounts, and handles support? In this article, "ownership" means practical customer control: the ability to identify the tenant, control the verified domain, retain business data and emergency access, review provider permissions, and remove or replace the provider. Contract and licensing obligations still need separate review.
This is not only an exit question. It determines whether the owner can respond to an incident, change providers, recover from a failed relationship, and prove who is authorized to manage the company’s email and files.
Your license reseller should not control the tenant
A Microsoft reseller can sell subscriptions and help manage the environment without owning the customer's organization. The tenant is the Microsoft Entra and Microsoft 365 directory containing the users, domains, roles, policies, email, SharePoint, Teams, and other business data.
The provider may have a billing relationship and administrative permissions. That does not mean the provider should hold the only Global Administrator account or register the business domain in its own unrelated tenant.
The owner should be able to identify the tenant, see the subscriptions, confirm the verified domains, and access at least one customer-controlled administrative recovery path.
Delegated administration is the clean provider model
Microsoft delegated administration lets a Cloud Solution Provider administer a customer tenant through roles assigned from the provider's own tenant. The newer Granular Delegated Admin Permission model specifies which roles the provider needs and how long the relationship lasts.
That is cleaner than creating a shared admin@ account that every technician uses. Delegated access preserves provider accountability and gives the customer a visible relationship it can remove. Microsoft says a Global Administrator in the customer tenant must approve a new granular relationship.
The honest drawback is that delegated access takes setup and maintenance. Roles have to match the support work, relationships can expire, and technicians still need individual controls inside the provider organization. But the structure is far safer than one permanent shared super-admin password.
Who owns your Microsoft 365 tenant during an emergency?
Delegated access should not be the only way into the tenant. If the provider has an outage, loses its relationship, or is the party the business needs to remove, the owner needs an independent recovery path.
Microsoft recommends two or more emergency access accounts. They should be cloud-only, use phishing-resistant credentials, avoid dependencies that could fail with normal administrator access, and be tested regularly. They are not daily email accounts.
For a small business, this does not mean the owner carries Global Administrator permissions in Outlook every day. It means the company has documented, protected credentials that can restore control when normal administration fails.
Your IT provider should be able to manage the tenant. Your business should be able to remove the provider.
What the customer should control
- The business domain and domain registrar account
- The Microsoft tenant identity and verified domains
- Emergency-access accounts and recovery materials
- Billing visibility and subscription records
- Backups and the ability to restore business data
- Documentation showing current administrators and delegated partners
- An exit process for removing a provider without losing service
The provider can operate these systems day to day. Control means the business can verify ownership, retrieve records, and authorize a transition. It does not mean the owner must personally administer Microsoft 365 every morning.
Red flags before you change providers
Ask for a tenant and access inventory before announcing the switch. Confirm who owns the domain, which Global Administrators exist, what delegated relationships are active, where backups live, and which billing commitments remain.
Ask the current provider for these seven items:
- The tenant ID and primary
onmicrosoft.comdomain - The list of verified business domains
- Current Global Administrator accounts
- Active delegated partner relationships and their expiration dates
- The emergency-access procedure and most recent test date
- Subscription commitments, quantities, and renewal dates
- The backup location, customer ownership, and restore responsibility
Do not ask the owner to publish emergency credentials in an email or transition spreadsheet. The purpose is to prove that a protected customer-controlled recovery path exists, not to make the credentials easier to copy.
A provider that refuses to identify the tenant, will not name the administrator roles, or says the business will lose its email if it leaves is not describing a healthy managed relationship. There can be legitimate licensing commitments and transition fees in an agreement, but the underlying business data and domain should not become leverage.
The existing MSP questions article covers the broader provider decision, and the contractor vendor checklist makes the same ownership point across cameras, firewalls, and AV systems.
A clean transition protects both sides
A professional outgoing provider documents the environment, removes its delegated relationship when the transition is complete, and helps maintain service continuity within the agreement. A professional incoming provider requests only the roles it needs, confirms the customer owns the tenant, and verifies emergency access before making major changes.
GTZ's managed IT model is built around customer control with provider administration. We are an IT provider explaining how IT providers should behave, so use a simple test: does the advice make it easier for a customer to leave us cleanly if the relationship stops working?
A contractor with a Pueblo office and active Colorado Springs jobs cannot afford an email outage while two providers debate access. Changing providers should be a controlled handoff, not a hostage negotiation. The best time to verify control is before the relationship is under stress.
Free Consultation
Questions About Your IT?
Book a free assessment with Efrain. No sales pitch, no obligation.
Get Your Free Assessment