Ask Actually

Who Owns Your Microsoft 365 Tenant?

In short

Check your organization's Microsoft 365 records, administrative access, partner permissions and subscription arrangements separately. A provider's administrator role does not by itself determine legal ownership. Record who can act for your business, how emergency access is governed and what the agreement requires if the provider relationship changes.

Before changing IT providers, establish which organization, accounts and agreements control each part of your Microsoft 365 arrangement. The useful outcome is a documented access and responsibility picture, rather than a single name labelled owner.

Separate administration, subscriptions and contractual rights

Record the tenant identifier, organization details, subscription arrangements and the people authorized to act for the business. Review delegated partner relationships separately from accounts in your own directory. Ask the provider to explain any record that appears inconsistent with the agreement.

Questions to resolve before a transition
AreaAsk to reviewKeep distinct
Administrative accessPrivileged accounts, partner permissions and responsible ownersTechnical access and contractual rights are different questions.
SubscriptionsWho supplies licences, renewal dates and applicable termsBuying through a reseller does not alone determine tenant ownership.
Domain registrationRegistrant records, registrar access and recovery contactsThe domain and the Microsoft 365 tenant are separate records.
Exit arrangementsResponsibilities, deadlines and access handover under the agreementDo not assume a licence transfer or provider change is automatic.

A discrepancy is a question to resolve. Ask for supporting records and an explanation before concluding that an arrangement prevents your business from retaining control. Contract interpretation belongs with your adviser.

How to review privileged access

Ask which accounts and partner relationships can administer the service today. For each, record the permissions, purpose, responsible owner and how authorization is reviewed. Identify emergency and service accounts explicitly.

Your provider or internal administrator should choose the appropriate reporting access. Do not request unrestricted administrator credentials simply to read a report, or send passwords in a routine email.

The emergency-access question

Microsoft's current guidance calls for at least two emergency accounts, phishing-resistant authentication, monitoring and validation at least every 90 days. It also specifies how to handle Conditional Access restrictions. Ask your administrator to check the maintained guidance linked below and explain how your arrangement meets it.

  • Who is authorized to use emergency access, and how are credentials protected?
  • How is use monitored and investigated?
  • When was access last validated, and what did the check establish?
  • Which dependencies could prevent access during the emergency the accounts are intended to address?

This is an oversight checklist, not a configuration procedure. Have qualified administrators plan changes and their consequences. Avoid creating an unmonitored fallback account or removing protections merely to satisfy a checklist.

Before you switch provider

Write down the access and handover steps before a transition. Use the provider-switching guide to distinguish the delivery decision from exit preparation and compare proposals against the responsibilities you need covered.

Add unresolved access questions to your provider review. If you need a second view of the records and responsibilities, discuss the scope of an independent IT audit. No single access report replaces review of the agreements that govern the relationship.

Common questions

Who owns my Microsoft 365 tenant?
An administrator-role list alone cannot answer a legal ownership question. Review the organization's records, subscription and provider agreements, administrative control and domain registration separately. Resolve unclear contractual rights with the relevant parties and your adviser.
How do I check administrator access?
Ask for a dated list of privileged accounts and delegated partner relationships, including permissions, purposes and responsible owners. Include service and emergency accounts, rather than assuming every account maps to one employee.
What is an emergency access account?
It is a highly privileged account reserved for situations where normal administration is unavailable. Its authentication, storage, monitoring and testing need deliberate management. Ask a qualified administrator to follow Microsoft's current emergency-access guidance, rather than relying on a spare password.
Is provider administrator access a problem?
Authorized access can be necessary for contracted work. Review whether its permissions, duration and oversight fit that work, and how your organization retains appropriately governed access. A reseller or delegated-access relationship alone does not establish wrongdoing.
Sources

This is one question. An independent review answers the rest, with evidence.

Request an Independent Review