Before changing IT providers, establish which organization, accounts and agreements control each part of your Microsoft 365 arrangement. The useful outcome is a documented access and responsibility picture, rather than a single name labelled owner.
Separate administration, subscriptions and contractual rights
Record the tenant identifier, organization details, subscription arrangements and the people authorized to act for the business. Review delegated partner relationships separately from accounts in your own directory. Ask the provider to explain any record that appears inconsistent with the agreement.
| Area | Ask to review | Keep distinct |
|---|---|---|
| Administrative access | Privileged accounts, partner permissions and responsible owners | Technical access and contractual rights are different questions. |
| Subscriptions | Who supplies licences, renewal dates and applicable terms | Buying through a reseller does not alone determine tenant ownership. |
| Domain registration | Registrant records, registrar access and recovery contacts | The domain and the Microsoft 365 tenant are separate records. |
| Exit arrangements | Responsibilities, deadlines and access handover under the agreement | Do not assume a licence transfer or provider change is automatic. |
A discrepancy is a question to resolve. Ask for supporting records and an explanation before concluding that an arrangement prevents your business from retaining control. Contract interpretation belongs with your adviser.
How to review privileged access
Ask which accounts and partner relationships can administer the service today. For each, record the permissions, purpose, responsible owner and how authorization is reviewed. Identify emergency and service accounts explicitly.
Your provider or internal administrator should choose the appropriate reporting access. Do not request unrestricted administrator credentials simply to read a report, or send passwords in a routine email.
The emergency-access question
Microsoft's current guidance calls for at least two emergency accounts, phishing-resistant authentication, monitoring and validation at least every 90 days. It also specifies how to handle Conditional Access restrictions. Ask your administrator to check the maintained guidance linked below and explain how your arrangement meets it.
- Who is authorized to use emergency access, and how are credentials protected?
- How is use monitored and investigated?
- When was access last validated, and what did the check establish?
- Which dependencies could prevent access during the emergency the accounts are intended to address?
This is an oversight checklist, not a configuration procedure. Have qualified administrators plan changes and their consequences. Avoid creating an unmonitored fallback account or removing protections merely to satisfy a checklist.
Before you switch provider
Write down the access and handover steps before a transition. Use the provider-switching guide to distinguish the delivery decision from exit preparation and compare proposals against the responsibilities you need covered.
Add unresolved access questions to your provider review. If you need a second view of the records and responsibilities, discuss the scope of an independent IT audit. No single access report replaces review of the agreements that govern the relationship.