Leaving Your MSP? How to Regain Admin Access

August 3, 2026

Leaving a managed service provider can come across like trying to change the tires while the car is still moving. You still need email, Teams, line-of-business apps, and your website to work tomorrow morning. But the moment you decide to transition, a scary question shows up fast: Do you actually control your own environment—or does your MSP?

You’re not simply transferring vendors if your provider is in charge of your domain registrar, has the Microsoft 365 global admin role, or is the only one with “master” passwords and documentation. You are restoring administrative power throughout your company and recovering your credentials.

The MSP is in charge of tenant admin, passwords, domains, documentation, and possibly even the billing connection in the real-world scenario described in this article. When you leave your MSP provider, you want to know how to get back admin access without causing any problems. Disruption or retaliation are not the objectives. It’s pure ownership, security, and continuity.

First, get clear on what “admin access” actually means

When people say “we don’t have admin,” they often mean one of three things—and each requires a different recovery path.

In Microsoft 365, the big one is global admin. If you can’t access at least one global admin account that you own, you don’t fully control identity, security settings, licensing, and recovery options. But global admin is only part of the picture.

You must also maintain control over your domain registrar (where your domain is registered), DNS hosting (where email and website records are kept), and billing relationship (who pays Microsoft, who owns the licenses, and who can cancel or transfer them). The “shadow layer” consists of security portals, backup systems, documentation, endpoint management tools, and password managers.

The safest mindset is this: you’re not “taking passwords.” You’re re-establishing ownership over systems that are legally and operationally yours.

The safe recovery sequence

A lot of SMBs make the same mistake: they start rotating passwords immediately. That feels decisive, but it can accidentally lock you out of the exact systems you’re trying to recover—especially if the MSP set up conditional access, MFA tied to their devices, or admin accounts that only they can reset.

Identify, verify, recover, secure, transfer, and document are a regulated sequence that should be used instead.

Step 1: Inventory the systems your MSP touches

Start with a plain-language map of your environment. You’re trying to answer: “If the MSP disappeared today, what would stop working, and what would we be unable to access?”

At minimum, list your Microsoft 365 tenant, Azure/Entra ID, domain registrar, DNS host, website hosting, email security gateway, backups, endpoint management (Intune/RMM), firewall, VPN, and any critical SaaS apps (accounting, CRM, payroll).

This step is important because it avoids a common scenario in which you reclaim Microsoft 365 global admin from your MSP, but your domain is still under the control of someone else, making it impossible to verify ownership, modify DNS, or finish recovery.

If you’re missing documentation, don’t panic. You can still reconstruct a lot from invoices, WHOIS records, Microsoft admin portals (once you’re in), and your internal knowledge of what tools you use day-to-day.

Step 2: Verify domain control

Before you escalate, you should have a plan if your MSP has domain registrar access. Email routing, website accessibility, and frequently identity verification are all controlled by your domain.

Start by determining where the domain is registered. Use a WHOIS lookup to find the registrar. Then confirm who the registrant is and what email address is tied to the account. In many SMB situations, the registrar account is in the MSP’s name or uses an MSP-controlled email address. That’s a risk indicator—and it’s fixable, but it must be handled carefully.

Your goal is to move registrar access to an account owned by your business (with a distribution email you control) and ensure your team or your new provider can make DNS changes. If the MSP refuses to cooperate, you may need to work with the registrar’s support team and provide proof of business ownership. This is also one of the moments where involving legal counsel may speed up cooperation.

Don’t change DNS records yet unless you fully understand what they do. One wrong edit can take down email or your website.

Step 3: Regain Microsoft 365 global admin from the MSP

If you’re trying to regain Microsoft 365 global admin from MSP control, the safest route is to create or confirm at least two admin accounts that are owned by your business—not the MSP.

Ideally, you already have an internal admin account. If you don’t, you’ll need cooperation from the MSP or a formal recovery path through Microsoft.

If the MSP is compliant, request that they:

  • Create a new global admin account under your domain (or elevate an existing internal account)
  • Ensure MFA is tied to your company-owned phone numbers or authenticator devices
  • Remove any conditional access policies that block your logins (or temporarily exempt your admin account)

If the MSP is not cooperative, you may need to pursue tenant recovery through Microsoft support. This process normally requires proof that your business owns the domain and the tenant. That’s why Step 2 matters.

Once you have access, resist the urge to remove the MSP’s accounts immediately. First, you need to understand what they configured and what services depend on their identities.

Step 4: Set up break-glass accounts

Every SMB should have “break-glass” admin accounts—accounts designed for emergency access when MFA systems fail, when a provider relationship breaks down, or when identity policies accidentally lock everyone out.

A break-glass account setup checklist SMB teams can follow should be simple, not theoretical. You want at least two emergency accounts that:

  • Are cloud-only (not synced from on-prem AD unless you have a specific reason)
  • Have long, distinct passwords stored in a secure vault
  • Are excluded from risky conditional access policies that could lock you out
  • Have MFA configured in a way that your business controls (or, in some designs, no MFA but heavily restricted and monitored—this is a nuanced decision)

The point isn’t to weaken security. It’s to prevent a single point of failure. Break-glass accounts should be monitored, rarely used, and tested on a schedule.

Step 5: Rotate credentials after MSP termination—safely, in waves

Now you can start the part everyone thinks of first: password and credential rotation. The key is sequencing. If you rotate everything at once, you’ll break integrations, backups, scanners, and line-of-business apps.

A safe approach to rotate credentials after MSP termination is to do it in waves:

  • First wave: ownership and recovery credentials. These include Microsoft 365 admin accounts, domain registrar logins, DNS hosting, primary email distribution lists used for recovery, and password manager admin access.
  • Second wave: infrastructure and security portals. Firewall admin, VPN, endpoint management, backup portals, email security gateways.
  • Third wave: service accounts and integrations. Anything that uses stored credentials—SMTP relays, scanners, accounting integrations, third-party apps connected to Microsoft 365.

As you rotate, document what changed, when, and why. Also document what broke and how it was fixed. That documentation becomes your future “exit plan,” even if you never change providers again.

Step 6: Transfer licenses and billing from MSP to client

Licensing is where transitions get messy. If your MSP is the reseller, they may control the subscription, and a sudden cancellation can turn off mailboxes and services.

To transfer licenses and billing from MSP to client, you need to determine which model you’re in:

  • You may need to take away the MSP’s assigned admin access and make sure that the billing contacts are yours if you pay Microsoft directly (by credit card or invoice).
  • If the MSP resells licenses (common in CSP relationships), you may need to purchase licenses directly or through a new provider and plan a clean cutover date. The goal is continuity: licenses should overlap briefly so there’s no service interruption.

This is also a place to be careful with “who owns what.” You own your tenant and data, but the MSP may own the reseller relationship. The practical fix is usually straightforward: establish your own billing, confirm subscriptions, then end the old agreement.

Step 7: Remove MSP access only after you’ve validated everything

Once you have verified global admin access, domain control, break-glass accounts, and stable licensing, you can start removing the MSP’s access.

This usually includes removing delegated admin relationships, deactivating MSP admin accounts, removing their MFA methods, and revoking tokens/sessions. But do this after you confirm backups, endpoint management, and security monitoring aren’t going to fail silently.

If the MSP managed your backups, you also need to confirm you have access to past backups and that you have a new backup strategy in place. Otherwise, you may “win” admin access but lose your recovery posture.

Signs your MSP controls too much

Not every MSP relationship is adversarial. Many providers set things up this way out of convenience or habit. But there are clear indicators that control has crossed into risky territory.

One red flag is when your business cannot name a single internal global admin account, or when all admin accounts are tied to the MSP’s email domain. Another is when the domain registrar is registered under the MSP’s company name, or the only recovery email is an MSP-controlled mailbox.

You should also be cautious if documentation is consistently “coming later,” if passwords are stored only in the MSP’s vault, or if you’re told that changing anything will “definitely break everything” without a clear explanation. Healthy providers can explain dependencies and provide a transition plan.

The core issue is simple: your business should never be one disagreement away from losing access to its own identity, domains, and data.

When to hire legal counsel or cyber insurance during an MSP exit

Most transitions can be handled professionally with a written request, a timeline, and a cooperative handoff. However, there are moments when you should escalate.

If the MSP refuses to provide access to accounts that belong to your business, threatens service disruption, or withholds domain registrar credentials, it’s time to retain legal counsel. A short letter from an attorney can quickly change the mood.

You should also consider involving your cyber insurance provider if you suspect malicious activity, unauthorized access, data exfiltration, or if the MSP relationship is ending due to a security incident. Cyber insurance often comes with breach coaches and incident response resources that can guide evidence preservation and communication.

Even if you don’t believe there’s a breach, treat the transition as a higher-risk period. Access changes, policy edits, and account handoffs are exactly when mistakes (or bad behavior) can happen.

The outcome you’re aiming for: calm control, not chaos

The best MSP exits aren’t dramatic. They’re boring—in the best way. Email keeps flowing. The website stays up. Users keep working. And behind the scenes, you quietly regain ownership over the systems that make your business run.

If you take one thing from this guide, let it be this: don’t start with password changes. Start with verification and recovery. Confirm domain control, regain Microsoft 365 global admin access, set up break-glass accounts, then rotate credentials and transfer billing in a controlled sequence.

Get an Admin Access Audit before you make the switch

If you’re planning a transition—or you’re already mid-exit and feeling that “uh oh” moment—an admin access audit can show you exactly where control lives today and what needs to change first.

In an admin access audit, you validate global admin ownership, domain registrar control, recovery methods, licensing/billing dependencies, and the hidden systems that can lock you out. You leave with a step-by-step recovery plan customized to your environment, so you can regain admin access when leaving your MSP provider without breaking anything.

FAQs

1) If my MSP is the only global admin, can I still regain access to Microsoft 365?

Yes, but you need to treat it like a recovery project, not a password reset. The cleanest path is cooperation: have the MSP create or elevate a company-owned admin and hand over MFA to your team. If they won’t, you’ll likely need Microsoft support and proof you own the tenant and the domain. That’s why confirming domain ownership early matters.

2) What if the MSP holds domain registrar access—what do I do first?

First, identify the registrar and confirm who the registrant is. Then request that the registrar account be moved to a business-owned login and recovery email you control. Avoid making DNS changes until you’ve documented current records and understand dependencies, because a single incorrect edit can take down email or your website.

3. Should I rotate all passwords the day we terminate the MSP?

Not all at once. Rotate in waves so you don’t break integrations and service accounts. Start with ownership and recovery credentials (global admin, registrar, DNS, password vault), then security and infrastructure portals, then service accounts and app integrations. Document every change so you can troubleshoot quickly.

4. How do I transfer licenses and billing from the MSP to the client without downtime?

You want overlap, not a hard stop. If the MSP is your reseller, establish direct billing with Microsoft (or a new provider) and confirm subscriptions are active before ending the old agreement. The goal is to keep mailboxes and services licensed continuously while you remove MSP access.

5. When should I involve legal counsel or cyber insurance during an MSP exit?

Involve legal counsel if the MSP refuses to provide access to business-owned systems, withholds registrar credentials, or threatens disruption. Involve cyber insurance if you suspect unauthorized access, data exposure, or you’re exiting due to a security incident—especially because they can provide incident response guidance and help preserve evidence.

About the Author

Chris McAree, CEO

Chris McAree is the founder and CEO of LeafTech, where over 20 years of IT experience meet a passion for people and innovation. In 2007, he launched LeafTech to make technology more human—and more helpful. Since then, he’s led the company through growth, transformation, and plenty of innovation.