Can You Move Microsoft 365 Away from Your Current Provider?

Changing Microsoft 365 provider may mean a simple licensing change, a subscription transfer, an authentication change or a full tenant migration. The correct route depends on how the current service was originally supplied — specifically whether the business owns its own tenant, whether authentication is federated, whether subscriptions are transferable, and whether the provider can or will release control. Confirm all of this before cancelling anything.
A business appoints a new IT provider. The owner expects the process to be straightforward: stop paying the old supplier, buy Microsoft 365 from the new one, and carry on using email. The new IT provider then asks questions the business cannot answer.
What is your tenant ID? Who is the Global Administrator? Is the domain federated? Who supplies the licences? Is the tenant dedicated to your organisation? Can the subscriptions be transferred? Is email filtering bundled? Where is DNS hosted? Is Microsoft 365 backed up?
These are not bureaucratic questions. The answers determine which of four materially different exit routes applies — and which sequence of steps will avoid service disruption.
The risk does not begin when the provider change starts. It begins when nobody has documented who controls the environment.
Changing Microsoft 365 provider can mean a simple licensing change, a subscription transfer, an authentication change or a full tenant migration. These are not the same project.
The Quick Answer
You can usually move Microsoft 365 support and licensing to another provider, but the method depends on how the current service was originally supplied.
The move may involve: replacing licences in the same tenant; transferring eligible subscriptions between Cloud Solution Providers; removing provider federation from the domain; removing delegated administration; or migrating users and data into another tenant.
Before cancelling anything, confirm: the Microsoft tenant identity; Global Administrator access; the current licence supplier; the authentication method; delegated provider relationships; email-security services; DNS and domain ownership; Microsoft 365 backup; replacement licences; and the supported exit procedure.
Do not cancel the current Microsoft 365 service until the target arrangement and technical sequence are confirmed.
What your Microsoft 365 provider may actually control
A business may believe it owns its Microsoft 365 environment because it pays the invoice, owns the domain, staff use the email addresses and Outlook is installed on its computers. None of these things confirms tenant ownership.
Microsoft 365 can be supplied through Microsoft directly, through a Cloud Solution Provider (CSP), through an IT support company, through a telecoms company, through a domain or hosting provider, or through a bundled business-services package. Each arrangement may give the provider different levels of control.
| What the provider may control | Why it matters for exit planning |
|---|---|
| Licence billing | Determines whether subscriptions can transfer or must be replaced |
| Delegated administration | Provider may have access to the tenant even after the contract ends |
| Authentication (federation) | May lock sign-in to the provider's identity system |
| Domain configuration | DNS, MX, SPF and DKIM records may be managed by the provider |
| Email filtering and security | Bundled services may disappear when the contract is cancelled |
| Backup | Microsoft 365 backup connectors may be authenticated under the provider account |
| User provisioning | New user creation may depend on provider-controlled tooling |
| Support access | Admin access may depend on the provider's relationship remaining active |
Your Microsoft 365 tenant is a business asset, not merely an email subscription.
The four common exit scenarios
Most provider changes fall into one of four categories. Identifying which applies before any work begins determines the plan, the cost and the risk.
| Scenario | What changes | Likely complexity | Typical triggers |
|---|---|---|---|
| Same-tenant licence replacement | Licences only; tenant, users and data remain | Low | Business already has independent admin access; authentication is Microsoft-managed |
| CSP subscription transfer | Commercial billing relationship; tenant and data remain | Medium | Moving from one Microsoft partner to another; subscriptions are eligible for transfer |
| Same-tenant defederation or provider release | Authentication and provider control; tenant and data remain | Medium to high | Provider uses federated sign-in; supported release process exists |
| Tenant-to-tenant migration | Entire tenant; users, mailboxes and data move to a new environment | High | Provider cannot release the tenant; shared or provider-managed arrangement; contractual or technical constraints prevent same-tenant move |
The first technical decision is not how to migrate. It is whether a migration is actually required.
Same-tenant change versus tenant migration
Where a business genuinely controls its own tenant, a provider change often does not require migration at all. Existing identities, mailboxes, SharePoint, OneDrive, Teams and security configuration all remain. The work involves licences, authentication, delegated access and security services — significant, but not a full data migration.
| Aspect | Same-tenant provider change | Tenant-to-tenant migration |
|---|---|---|
| User identities | Remain in place | Must be recreated or migrated |
| Mailboxes | Remain in place | Must be migrated |
| SharePoint | Remains in place | Must be migrated |
| OneDrive | Remains in place | Must be migrated |
| Teams | Largely remains | Significant data loss risk; migration tools are limited |
| Devices | May need re-registration | Must be re-enrolled |
| Applications | Largely unaffected | Must be reconfigured |
| Duration | Days to weeks | Weeks to months |
| User disruption | Low, if sequenced correctly | High |
| Data risk | Low | Higher — proportional to data volume and migration tooling |
Retaining the tenant is normally simpler, but only where the business genuinely controls it and the provider supports the release. Where the provider controls the tenant — or where the domain is attached to a provider-managed or shared environment — a migration may be the only option.
Case study: GoDaddy
GoDaddy provides Microsoft 365 through its own provisioning, billing and sign-in experience. Some GoDaddy arrangements use federated authentication — meaning that user sign-in is redirected through GoDaddy rather than handled directly by Microsoft.
Microsoft now directs customers wishing to move away from GoDaddy's Microsoft 365 to GoDaddy's own supported transfer-away procedure. Microsoft and GoDaddy both warn that unofficial defederation scripts or commands found online may cause sign-in failures, mailbox access problems or SharePoint issues.
Eligible customers may be able to retain the same tenant and the same data. However, the exit process also requires reviewing passwords, MFA registration, bundled email-security services, backup and licence replacement.
GoDaddy is a useful example of same-tenant defederation, but it is not a universal template for every provider. Always use the official supported process for your specific provider.
Case study: BT Business
BT Business provides Microsoft 365 to some business customers through arrangements where the domain is attached to a BT-managed Microsoft environment. Current published BT guidance for some account types describes a process where: mailbox data needs to be backed up; existing email addresses and the domain need to be removed from the BT-managed tenant; a new provider then creates mailboxes in a separate environment; and data is restored or migrated.
This is a materially different process from the GoDaddy same-tenant route. Not all BT Microsoft 365 customers follow this model — other BT account types may behave differently, and the exact process depends on the specific arrangement in place.
A provider-branded Microsoft service may look similar to standard Microsoft 365 while having a very different exit process. Verify the specific arrangement and the provider's current guidance before planning any work.
CSP-to-CSP subscription transfers
Where a business purchases Microsoft 365 through a Cloud Solution Provider, it may be possible to transfer eligible subscriptions to a new CSP rather than cancelling and repurchasing. However, Microsoft's current rules require the participation and approval of both the source and target partners.
Not every subscription type is eligible for transfer. New Commerce Experience (NCE) subscriptions in particular have specific restrictions on mid-term transfers. Subscriptions that cannot be transferred must be allowed to expire or be cancelled subject to any applicable cancellation terms, and replacement licences purchased from the new provider. Any existing contractual obligations to the outgoing provider do not disappear simply because a transfer request has been submitted.
Moving the bill does not automatically move the tenant, and moving the tenant does not automatically transfer the commercial agreement.
A subscription transfer is a commercial and billing change. It does not migrate tenant data, change administrator access, remove federation or alter delegated administration. These must be addressed separately.
Administrator access and tenant ownership
Before any provider exit can proceed safely, the business must confirm that it has independent access to its own tenant — access that does not depend on the outgoing provider remaining cooperative.
Tenant ownership checklist
- Tenant ID and tenant display name — found in the Microsoft Entra ID admin centre
- The onmicrosoft.com domain — the permanent fallback identity that cannot be removed
- All custom domains attached to the tenant
- Global Administrator accounts — at least one must be internal or independently accessible
- A cloud-only emergency-access account with MFA and documented recovery details
- Billing accounts and current licence supplier
- Any Cloud Solution Provider relationships
- Any delegated administration or GDAP relationships
- Data location — which Microsoft region stores the tenant data
- Backup provider and whether backup remains accessible post-exit
- Domain registrar and DNS host
- Email-security provider and how it is connected
Owning the domain does not automatically prove that you control the Microsoft tenant.
Common problems discovered during this audit include: the Global Administrator account belonging to a former employee or previous IT provider; the only administrator account being a delegated account controlled by the outgoing provider; the emergency access account never having been created; and MFA not configured on administrator accounts.
The outgoing supplier should not be the only route into the environment being transferred.
Authentication, passwords and MFA
The impact of a provider change on user sign-in depends entirely on the authentication model in use. A simple licence replacement in a tenant using Microsoft-managed authentication may be completely invisible to users. A defederation — moving from provider-controlled sign-in to Microsoft-managed authentication — affects every user's sign-in method, password state and MFA registration.
In a federated arrangement, user passwords may be held by the provider's identity system rather than by Microsoft. After defederation, users may need to set new passwords and re-register MFA. Security Defaults or Conditional Access policies need to be reviewed and configured. Existing Microsoft Authenticator registrations may or may not remain valid depending on the specifics of the defederation process. Service accounts, application sign-ins and mobile device connections must also be reviewed.
A licence change may be invisible to users. An identity change rarely is.
Licences and billing
Licence management during a provider exit requires careful sequencing. The critical principle is that replacement licences must be assigned and confirmed as working before the old licences are removed. Removing licences before assigning replacements strips users of access to Exchange Online, SharePoint, OneDrive, Teams and other services.
Where a subscription transfer is possible, the timing must be coordinated between the source and target providers to avoid a gap. Where subscriptions cannot transfer and must be replaced, the business typically needs to run both sets of licences in parallel for a controlled period, with the old licences removed only after the new ones are confirmed as functioning.
Domain and DNS
Changing Microsoft 365 provider does not automatically require changing the domain registrar or the DNS host. The domain can remain with the same registrar. DNS can remain with the same provider. The domain name itself stays the same. A provider exit is not automatically a domain move.
However, a tenant-to-tenant migration typically requires the domain to be temporarily removed from the existing tenant and added to the new one, because Microsoft does not allow the same custom domain to be attached to two tenants simultaneously. During this period, email delivery using the custom domain is unavailable unless carefully managed. All DNS records — MX, SPF, DKIM, DMARC, Autodiscover, verification records, website records and any records supporting third-party applications or remote access — should be documented before any changes are made.
Do not combine domain registrar, DNS and Microsoft 365 moves into the same change window without a clear reason and a detailed rollback plan for each.
Email security and backup
Some providers bundle email security services — spam filtering, mail gateways, Proofpoint integration, URL rewriting, attachment scanning, archiving, continuity or DMARC monitoring — alongside the Microsoft 365 licence. These services are not part of the Microsoft subscription and do not transfer automatically. They may disappear when the contract with the outgoing provider is cancelled.
Backup is equally easy to overlook. Microsoft 365 does not include a comprehensive backup by default. Where a third-party backup solution is in use, the backup connectors are typically authenticated through an administrator account. If that account belongs to the outgoing provider, backup access may fail once the delegated relationship is removed. Backup authentication must be reviewed and, where necessary, migrated to a new account before the exit.
The mailbox may remain while the protections around it quietly disappear.
Choosing the correct exit route
Decision guide
- 1Does the business have its own dedicated Microsoft tenant? If unknown, begin with discovery and provider confirmation before any other steps.
- 2Does the business have independent Global Administrator access — access that does not depend on the outgoing provider? If not, recover administrator control first.
- 3Is authentication federated through the provider? If yes, use the provider's own supported defederation or release process. Do not use unofficial scripts.
- 4Can eligible subscriptions be transferred to the new CSP? If yes, coordinate source and target provider approval. If no, purchase replacement licences with a controlled overlap period.
- 5Can the tenant and domain remain in place? If yes, complete the same-tenant provider change — licences, authentication, delegated access, security services, backup. If no, plan a full tenant-to-tenant migration.
Provider exit checklist
- 1Identify the tenant — ID, display name, onmicrosoft.com domain and custom domains
- 2Verify Global Administrator access independent of the outgoing provider
- 3Confirm the current provider relationship — CSP, delegated admin, GDAP
- 4Confirm authentication type — Microsoft-managed or federated
- 5Inventory users, groups, licences and active services
- 6Record licence types, quantities and contract renewal or cancellation dates
- 7Identify all email-security products and how they are connected
- 8Export and document all DNS records before any changes
- 9Confirm backup coverage, test a restore, and check backup authentication
- 10Decide whether the tenant can and should remain — same-tenant or migration
- 11Confirm the supported provider exit process — use official documentation only
- 12Arrange replacement licences or confirmed subscription transfer with dates
- 13Prepare user communications covering sign-in changes, password resets and timeline
- 14Define rollback — what happens if each step fails and how service is restored
- 15Test critical services — email, Teams, SharePoint, SMTP devices, remote workers
- 16Cancel old services only after written sign-off that all checks have passed
Common mistakes
- Assuming every provider exit is a defederation — many are not
- Treating a licence transfer and a tenant migration as the same thing
- Cancelling the existing licences before replacement licences are confirmed and working
- Having no independent administrator account before the exit begins
- Using unofficial PowerShell scripts or online guides instead of the provider's supported process
- Overlooking contractual notice periods and cancellation terms
- Failing to document bundled security services before they disappear
- Forgetting that backup connectors may be authenticated through the outgoing provider account
- Moving the domain registrar or DNS host unnecessarily during an already complex change
- Failing to check SMTP devices, scanners and applications that send email
- Assuming Teams data and channels migrate automatically — Teams migration tooling has significant limitations
- Not testing remote workers and mobile devices before declaring the migration complete
- Failing to remove old delegated access and GDAP relationships after the exit
- Failing to retain audit log evidence from before and during the migration
- Assuming domain ownership is equivalent to tenant ownership
Warning signs
Pause and complete additional discovery before proceeding where:
- The tenant identity is unknown or cannot be confirmed
- Global Administrator access is unavailable or depends entirely on the outgoing provider
- Every administrator account is owned or controlled by the outgoing provider
- The federation status of the domain is unknown
- The tenant may be shared with other organisations or customers
- Replacement licences cannot be confirmed before the old ones are due to end
- Source-provider approval is required for a transfer but has not been obtained
- Email filtering and security services are undocumented
- Backups have not been tested or backup authentication is unclear
- The domain is attached to another organisation's or provider's tenant
- The proposed approach relies on an unofficial script found online
- User passwords cannot be reset safely without provider involvement
- No rollback plan or user communications plan exists
When the tenant model is unclear, discovery is not a delay — it is the first stage of the migration.
Other provider types
IT support companies and CSPs often provide Microsoft 365 in a way that gives the business straightforward tenant control. The exit may require only new licences, removal of the provider's delegated or GDAP access, and a handover of support responsibilities.
Telecoms companies may bundle Microsoft 365 with broadband, telephony, domain hosting, email security and support. Each bundled element needs to be identified and a replacement arranged before the contract ends.
Domain and hosting providers may control DNS, email provisioning, authentication and licence billing simultaneously, making the exit dependencies more complex.
Where the Global Administrator account was originally set up by a former employee, a web developer or an external consultant who is no longer reachable, ownership recovery must be addressed before any provider exit can proceed. Microsoft has processes for this, but they take time.
Practical business implications
What this means in practice
Tenant control is more important than supplier brand
The same provider may use different technical arrangements for different customers. The logo on the invoice tells you very little about the exit route.
Not every exit requires migration
Where the business genuinely controls its own tenant, a provider change may need nothing more than licence replacement, authentication adjustment and delegated-access removal.
Not every tenant can be retained
Some arrangements — provider-managed tenants, shared environments, some telecoms and domain-provider bundled services — may require a full migration regardless of preference.
Commercial and technical transfers are different
Moving the subscription billing does not move data, authentication or delegated access. These must each be addressed as separate workstreams.
Administrator access must be independent
Every business should have at least one Global Administrator account and one cloud-only emergency account that are not controlled by any external provider.
Bundled services create hidden dependencies
Email security, backup, DMARC monitoring and continuity services may disappear when the provider contract is cancelled, leaving the mailboxes in place but unprotected.
The IT Club view
IT Club editorial position
The problem is not that businesses buy Microsoft 365 through providers. That is a reasonable and often cost-effective arrangement. The problem is that many businesses never document the tenant, who has administrator access, who supplies the licences, how authentication works, what delegated control exists, where DNS is managed, whether there is a backup and what the exit process would be.
GoDaddy is a useful example because it has a recognisable, supported defederation route and Microsoft has published clear guidance. BT is useful because it demonstrates that another provider may require a materially different approach — in some cases, backup and full data migration — even when the Microsoft 365 service appears superficially similar.
There is no universal 'defederate Microsoft 365' button for every provider.
IT Club recommends: identifying the exact tenant model before any exit planning begins; maintaining independent admin access at all times; documenting every provider relationship, licence, delegated account and bundled service; separating the licensing change from any migration work; following only provider-supported processes; planning licence overlap to avoid access gaps; testing backup before and after; keeping complete documentation of the exit process; and reviewing delegated access regularly — not only when changing provider.
The right exit plan depends less on the logo on the invoice and more on how the tenant was built, authenticated, licensed and controlled.
Plain-English takeaway
Most businesses can change Microsoft 365 provider, but the correct route depends on how the current service was supplied. Some can retain the same tenant and replace or transfer licences. Others need provider-supported defederation, and some require a full tenant migration. Confirm tenant ownership, administrator access, authentication, licences, security services, DNS and backup before cancelling anything.
Related business questions
| Question | Answer |
|---|---|
| Can we move Microsoft 365 to a new IT provider? | Usually yes, but the method depends on how the current service was originally supplied. It may be a simple licence change, a subscription transfer, a defederation or a full tenant migration. |
| What is a Microsoft 365 tenant? | The organisation's Microsoft cloud environment, containing identities, mailboxes, SharePoint, OneDrive, Teams, groups, licences and security configuration. It is identified by a unique tenant ID and an onmicrosoft.com domain. |
| Who owns our Microsoft 365 tenant? | The organisation that has Global Administrator access and controls the billing relationship. This is not always the business that pays the invoice — confirm by checking who holds the Global Administrator accounts in Microsoft Entra ID. |
| What is the difference between a licence change and a tenant migration? | A licence change replaces the subscriptions billing the existing tenant. A tenant migration moves users, mailboxes and data into a completely different tenant. These are separate processes with very different complexity and risk. |
| What is defederation? | Changing a domain from federated authentication — where sign-in is redirected to a provider's identity system — to Microsoft-managed authentication, where Microsoft handles sign-in directly. |
| Does defederation delete our data? | No, where done correctly through the provider's supported process. Data remains in the tenant. However, passwords, MFA registrations and sign-in behaviour are affected. |
| What is a CSP subscription transfer? | Moving eligible Microsoft 365 subscriptions from one Cloud Solution Provider billing partner to another. Both the existing and new partner must participate. Not all subscription types are eligible. |
| Can we just cancel the old provider and buy from the new one? | Only if the business already has independent tenant control and does not need to transfer subscriptions. Cancelling licences before replacements are confirmed strips users of access. Never cancel first. |
| What is delegated administration? | Permissions that allow a provider to administer part or all of the tenant. These remain after the contract ends unless the relationship is explicitly removed from the tenant. |
| What is GDAP? | Granular Delegated Admin Privileges — a more controlled form of partner access that grants specific roles for defined time periods. GDAP relationships must be reviewed and removed when changing provider. |
| Does changing provider mean changing our email address? | Not if the domain remains and the tenant is retained. Email addresses are associated with the domain, which stays the same. Only a tenant migration without a domain transfer temporarily affects delivery. |
| What happens to Teams data if we migrate tenants? | Teams channels, chat history and meeting recordings have significant migration limitations. Teams data should be specifically assessed — do not assume it transfers automatically. |
| Do we need to move our domain registrar? | No. The domain name, registrar and DNS can all remain the same when changing Microsoft 365 provider, provided the tenant is retained. A domain move is a separate decision. |
| What happens to DNS during a provider change? | DNS records should be documented in full before any changes. Where the same tenant is retained, DNS updates are typically minor. Where a tenant migration is required, the domain must be temporarily removed and re-added, causing a period where the custom domain is unavailable. |
| What is the GoDaddy defederation process? | GoDaddy provides a supported transfer-away process for its Microsoft 365 customers. Microsoft directs customers to GoDaddy's own official procedure. Unofficial scripts found online are not recommended. |
| What about BT Business Microsoft 365? | Some BT-managed Microsoft 365 arrangements may require mailbox data to be backed up, addresses and the domain removed from the BT-managed tenant, and mailboxes recreated in a new environment. Other BT account types may behave differently — confirm the specific arrangement with BT. |
| What is an onmicrosoft.com domain? | The permanent Microsoft-assigned domain for a tenant, such as yourcompany.onmicrosoft.com. It cannot be removed from the tenant and can be used as a fallback during DNS changes. |
| What is a Global Administrator? | The highest privilege role in Microsoft 365 and Entra ID, with full control over the tenant. Every organisation should have at least one Global Administrator account that is not controlled by an external provider. |
| What is an emergency access account? | A cloud-only account held for break-glass scenarios, where normal administrator access is unavailable. It should have MFA configured with documented recovery details and should not be used for day-to-day work. |
| How do we check if our domain is federated? | An IT professional can check the domain federation status using Microsoft Entra ID or PowerShell. Signs of federation include being redirected to a provider's sign-in page when logging into Microsoft 365. |
| What email security services should we check? | Spam filtering, mail gateways, Proofpoint or similar third-party filters, Defender for Office 365, archiving, journalling, email continuity, DMARC monitoring and quarantine. Check which are bundled with the current provider contract. |
| Does Microsoft 365 include backup? | Microsoft provides some retention and recovery features, but not a comprehensive point-in-time backup. Third-party backup solutions are recommended and widely used. These must be reviewed when changing provider. |
| What are SMTP devices and why do they matter? | Printers, scanners and other devices that send email through the Microsoft 365 tenant. They are often configured with specific accounts or relay settings that need to be updated when authentication or licences change. |
| What notice period should we give the current provider? | Check the contract. Many Microsoft 365 provider agreements include notice periods of 30 to 90 days. Commercial obligations do not end simply because a migration has begun. |
| Should we keep audit logs during the exit? | Yes. Export and retain audit logs from before, during and after the exit. These are important for troubleshooting and for demonstrating compliance with any data processing or retention obligations. |
| How long does a Microsoft 365 provider change take? | A simple same-tenant licence replacement may take days. A defederation may take one to four weeks. A full tenant-to-tenant migration for a medium-sized business typically takes two to four months with careful planning. |
| What should we do if we cannot access our tenant? | Contact Microsoft support with evidence of business ownership. Microsoft has processes for administrator recovery, but they require identity verification and take time. This is why maintaining independent admin access at all times is strongly recommended. |
Technical note for administrators and IT professionals
The tenant ID is the globally unique identifier for the Microsoft Entra ID (formerly Azure Active Directory) tenant. It is visible in the Entra ID admin centre and in the Azure portal. The onmicrosoft.com domain is permanent and cannot be removed — it provides the fallback UPN suffix and service identity during domain removal and re-addition.
Custom domain federation status can be confirmed using the Get-MgDomain PowerShell cmdlet or via the Entra ID admin centre under Domains. A managed domain uses Microsoft-managed authentication; a federated domain redirects sign-in to an external identity provider configured in the tenant's authentication settings.
CSP subscription transfers are initiated via Partner Centre. The target partner submits a transfer request which the source partner must approve. NCE annual subscriptions have a limited transfer window (typically within 30 days of subscription start or renewal). NCE monthly subscriptions are more flexible. Subscriptions that cannot transfer must be allowed to expire or cancelled subject to terms, and equivalent licences purchased from the new partner. Delegated administration and GDAP relationships are separate from subscription billing — they must be managed independently via the partner relationships section of the Microsoft 365 admin centre.
For same-tenant defederation, the domain federation setting is changed from 'Federated' to 'Managed' using the Convert-MgDomainFederatedToManaged cmdlet (or equivalent Entra ID admin centre action). This resets user passwords if they were held by the external identity provider rather than Entra ID. A Temporary Access Pass (TAP) or alternative password-reset method must be prepared before defederation begins. MFA registrations may also be affected depending on the provider's federation configuration.
For tenant-to-tenant migration, Microsoft provides cross-tenant mailbox migration capabilities for Exchange Online, including the Prepare-MoveRequest.ps1 approach and the more recent migration endpoint tooling. Cross-tenant SharePoint migration uses the SharePoint Migration Tool (SPMT) or Microsoft SharePoint Premium. Teams migration has limited official tooling — Teams channels, membership, tabs and chat history have varying degrees of migrability, and some data loss should be expected. Third-party migration tools (Quest On Demand Migration, BitTitan MigrationWiz, AvePoint Fly and others) provide additional capabilities.
Domain removal from the source tenant requires that no users, groups or applications use the domain as their primary address or UPN. All objects must be transitioned to the onmicrosoft.com domain before removal. The domain is then removed from the source tenant, propagation confirmed, and added to the target tenant — verified using a TXT or MX DNS record. MX records should not be updated until mailboxes are ready to receive mail in the target environment. SMTP relay configuration on printers, scanners and legacy applications must be updated separately.
Backup connectors (Veeam Backup for Microsoft 365, Acronis, Barracuda, Datto SaaS Protection, Druva and others) authenticate through a Microsoft 365 service account or modern authentication application registration. These must be re-authenticated or migrated to new accounts before the outgoing provider's admin accounts are removed. Backup data retained by the existing provider under their storage may not be transferable — confirm data ownership, portability and retention in the provider contract.
After the exit, partner relationships should be removed from the Microsoft 365 admin centre under Settings > Partner relationships. Any remaining GDAP assignments should be reviewed and removed. Exchange mail-flow connectors used for third-party email gateways should be reviewed and updated or removed as appropriate. Conditional Access policies, Security Defaults and any named-location policies should be confirmed as correctly configured for the new authentication state.
Operational Heartbeat
Microsoft 365 provider arrangements need an Operational Heartbeat: tenant ownership, administrator access, licences, delegated providers, authentication, DNS, security, backup and exit plans should be reviewed rather than assumed to remain under control.
A regular review should check: tenant ID and administrator accounts; emergency access account status; MFA configuration on all admin accounts; current authentication model; all CSP and GDAP relationships; licences and contract renewal dates; registrar and DNS host; email security products; backup coverage and recent restore test; supplier documentation and exit procedures; and any previous incidents or corrective actions.
Set a next review date. Tenant arrangements change — staff leave, providers are acquired, contracts renew automatically and authentication settings drift. A documented review is not a one-off exercise.
Plain-English Takeaway
Most businesses can change Microsoft 365 provider, but the correct route depends on how the current service was supplied. Some can retain the same tenant and replace or transfer licences. Others need provider-supported defederation, and some require a full tenant migration. Confirm tenant ownership, administrator access, authentication, licences, security services, DNS and backup before cancelling anything.
Need the practical steps?
A short, instruction-led version of this topic is available in the Knowledge Centre.
View the Knowledge Centre GuideRelated Articles
How Do You Prove Your Business Can Be Trusted?
Every business claims to be reliable, professional and secure. But how can a customer, supplier or partner actually tell? Independent certification provides evidence that goes beyond marketing claims.
Read articleIs AI Saving Your Staff Time—or Creating More Admin?
AI can reduce the time required for individual tasks while creating additional work around them — particularly when tools, data and approval processes remain disconnected. Research from Workday found that one in four UK workers spends seven or more hours each week manually managing disconnected systems. This article explains why faster tasks do not always produce a faster business and what to measure to find out whether AI is genuinely helping.
Read articleCould AI Turn Your Business Information into a Personal Podcast?
AI tools can now convert documents, research and links into personalised podcast-style audio. Google NotebookLM Audio Overviews are available now, Spotify is experimenting with personal AI podcasts, and Microsoft has announced it is retiring its generated Podcasts feature from consumer Copilot in August 2026. Businesses could find uses in training, research and meeting preparation — but generated audio carries accuracy, privacy and ownership risks that require careful management.
Read article