Microsoft 365 Provider Exit Checklist
Changing Microsoft 365 provider can mean a licence replacement, a CSP subscription transfer, a supported defederation or a full tenant migration — and these are not the same project. This checklist covers everything a business needs to confirm before changing provider: tenant identity, administrator access, authentication, licences, email security, DNS, backup and the correct exit route.
Changing Microsoft 365 provider is not always straightforward. The method depends entirely on how the current service was originally supplied — specifically whether the business owns its own tenant, whether authentication is federated, whether subscriptions are transferable, and whether the provider can or will release control. Work through this checklist before any exit work begins.
Do not cancel the current Microsoft 365 service until the target arrangement and technical sequence are confirmed. Removing licences before replacements are assigned strips users of access to email, SharePoint, OneDrive and Teams.
THE FOUR EXIT ROUTES
| Route | What changes | When it applies |
|---|---|---|
| Same-tenant licence replacement | Licences only; tenant and data remain | Business has independent admin access; authentication is Microsoft-managed |
| CSP subscription transfer | Billing relationship; both partners must approve | Moving between Microsoft partners; subscriptions are eligible |
| Supported defederation | Provider authentication removed; tenant and data remain | Provider uses federated sign-in; official release process exists |
| Tenant-to-tenant migration | All users, mailboxes and data move to a new tenant | Provider cannot release the tenant; shared or provider-managed arrangement |
TENANT IDENTITY
- Confirm the tenant ID — found in the Microsoft Entra ID admin centre
- Record the onmicrosoft.com domain — this is permanent and cannot be removed
- List all custom domains attached to the tenant
- Confirm whether the tenant is dedicated to the organisation or shared
Owning the domain does not automatically prove that you control the Microsoft tenant.
ADMINISTRATOR ACCESS
- Confirm at least one Global Administrator account independent of the outgoing provider
- Confirm a cloud-only emergency-access account exists with MFA and documented recovery
- Confirm MFA is configured on all administrator accounts
- Review all Cloud Solution Provider relationships in the Microsoft 365 admin centre
- Review all GDAP (Granular Delegated Admin Privileges) relationships
- Plan to remove old delegated access after the exit is complete
The outgoing supplier should not be the only route into the environment being transferred.
AUTHENTICATION
- Confirm whether any domain is federated — sign-in redirected to the provider's identity system
- Identify the provider's supported defederation or release process
- Prepare a password-reset plan — federated users may need to set new passwords after defederation
- Prepare an MFA re-registration plan for all affected users
- Review all service accounts, application sign-ins and mobile device configurations
A licence change may be invisible to users. An identity change rarely is.
LICENCES AND BILLING
- Record all licence types, quantities and costs
- Note contract renewal dates and any notice periods
- Confirm whether subscriptions are eligible for CSP transfer
- Arrange replacement licences before removing old ones
- Plan a licence overlap period to avoid access gaps
EMAIL SECURITY
- Identify all email security services — spam filter, mail gateway, third-party filters, archiving, DMARC monitoring
- Confirm which services are bundled with the outgoing provider contract
- Arrange replacement security services before the contract ends
- Check Defender for Office 365 configuration and licensing
- Review quarantine, URL rewriting and attachment scanning settings
The mailbox may remain while the protections around it quietly disappear.
DOMAIN AND DNS
- Export all DNS records — MX, SPF, DKIM, DMARC, Autodiscover, verification records
- Record website, remote-access and third-party application DNS records
- Confirm the domain registrar and DNS host
- Assess whether a domain move is genuinely required — in most same-tenant exits it is not
- If a tenant migration is required, plan for the domain to be temporarily unavailable
BACKUP AND RECOVERY
- Confirm backup coverage — mailboxes, OneDrive, SharePoint, Teams
- Complete a restore test before the exit begins
- Confirm that backup authentication does not depend on the outgoing provider account
- Confirm that backup access will remain after the exit
- Review departed-user data retention
PROVIDER EXAMPLES
| Provider type | Typical arrangement | Exit notes |
|---|---|---|
| GoDaddy Microsoft 365 | May use federated authentication through GoDaddy | Use GoDaddy's official transfer-away process. Do not use unofficial scripts. |
| BT Business Microsoft 365 | Some arrangements use a BT-managed tenant | Some account types may require mailbox backup, domain release and migration. Confirm the specific arrangement with BT. |
| CSP or IT support provider | Business typically has its own tenant | May require subscription transfer, licence replacement and delegated access removal only. |
Verify these examples against your specific account. The same provider may use different arrangements for different customers.
Exit and handover
- Confirm the supported provider exit process using official documentation only
- Prepare user communications covering sign-in changes, password resets and timeline
- Define rollback — what happens if each step fails and how service is restored
- Review and update all SMTP device and scanner configurations
- Remove old delegated access and GDAP relationships after the exit is complete
- Export and retain audit logs from before, during and after the exit
- Cancel old services only after written sign-off that all checks have passed
When the tenant model is unclear, discovery is not a delay — it is the first stage of the migration.
Plain-English Takeaway
Confirm tenant ownership, administrator access, authentication, licences, security services, DNS and backup before cancelling anything. Do not cancel the current service until the replacement arrangement and technical sequence are fully confirmed.
Downloadable guide
Download the Microsoft 365 Provider Exit Checklist
A printable A4 PDF with a structured checklist for changing Microsoft 365 provider — covering tenant identity, admin access, authentication, licences, email security, DNS, backup and the four exit routes.
Download ChecklistFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Cyber Resilience Readiness Guide
Review your critical systems, IT suppliers, incident response, backups and business-continuity arrangements.
View guideOperational Heartbeat Checklist
A plain-English checklist for business owners to assess whether their IT provider is monitoring the right things. Covers backups, servers, Microsoft 365, firewalls, security, certificates, storage and more.
View guideHow to Evaluate a Breakthrough Energy Claim
A structured checklist for assessing experimental energy claims before treating a laboratory result as a practical technology. Covers the claim, the evidence, replication, scale, engineering viability, economics and misleading headlines.
View guide