MSADVANCE LOGO
✕
  • Services
    • Microsoft 365 Consulting Services for Businesses
    • Migration to Microsoft 365
    • Microsoft 365 to Google Workspace Migration
    • Azure Cloud Architecture
    • Modern Workplace
    • Microsoft 365 & Azure Cybersecurity Services
    • Managed Microsoft 365 & Azure Services
    • Software License Procurement & Sales for Businesses
  • About Us
    • Success Stories
    • Microsoft Partner
    • Trust Center: Security, Privacy & Access
    • Our Methodology
  • Blog
  • Contact
  • English
    • Español
    • English
  • Services
    Services Microsoft Cloud, from strategy to operations Consulting, migrations, Modern Workplace, cybersecurity, Azure, managed services and Microsoft licensing.
    All services Talk to a specialist
    Azure Advisor
    Assess · decide · govern Microsoft 365 Consulting
    Assessment, architecture, governance, security and roadmaps to evolve Microsoft 365 with clear technical priorities.
    Assessment Health Check Architecture Governance
    Move · separate · consolidate Migrations
    Migrations to Microsoft 365, across tenants and from cloud or on-premises platforms with controlled transition and validation.
    Microsoft 365 Google Google Exchange Online Exchange IMAP POP M&A
    Microsoft Teams
    Productivity · collaboration · endpoints Modern Workplace
    Implementation and evolution of collaboration, devices, productivity and employee experience across Microsoft 365.
    Microsoft Teams Teams Microsoft SharePoint SharePoint Microsoft OneDrive OneDrive Microsoft Intune Intune Microsoft Copilot Copilot
    Microsoft Defender
    Identity · protection · compliance Cybersecurity
    Protection for identities, endpoints, email, data and cloud services across the Microsoft security ecosystem with a Zero Trust approach.
    Microsoft Entra ID Entra Microsoft Defender Defender Microsoft Sentinel Sentinel Microsoft Purview Purview Zero Trust
    Microsoft Azure
    Cloud · architecture · platform Microsoft Azure
    Architecture, configuration, migration, governance, security, resilience and cost optimization for Azure environments.
    Azure Management Groups Landing Zones Azure Virtual Networks Networking Azure Migrate Migration Azure Policy Governance Azure Cost Management FinOps
    Monitoring and operations
    Manage · support · optimize Managed Services
    Ongoing administration, support, security, governance and optimization for Microsoft 365 and Azure after implementation.
    Microsoft 365 Microsoft Azure Azure Microsoft Intune Intune Microsoft Defender Security Azure Cost Management Optimization
    Licensing · capacity · cost Microsoft Licensing
    Procurement, review and optimization of Microsoft 365, Azure, Copilot and related Microsoft licensing for businesses.
    Microsoft Microsoft 365 Microsoft Azure Azure Microsoft Copilot Copilot
    Microsoft Partner 25+ Microsoft certifications 51,000+ users 500+ organizations
    Success Stories Partner & Certifications Methodology Trust Center
    • Microsoft 365 Consulting Services for Businesses
    • Migration to Microsoft 365
    • Microsoft 365 to Google Workspace Migration
    • Azure Cloud Architecture
    • Modern Workplace
    • Microsoft 365 & Azure Cybersecurity Services
    • Managed Microsoft 365 & Azure Services
    • Software License Procurement & Sales for Businesses
  • About Us
    • Success Stories
    • Microsoft Partner
    • Trust Center: Security, Privacy & Access
    • Our Methodology
  • Blog
  • Contact
  • English
    • Español
    • English
Published by MSAdvance on September 6, 2026
Categories
  • Microsoft 365 Consulting
  • Microsoft 365 Audit
Tags
  • Azure AD
  • Exchange Online
  • IT documentation
  • Microsoft 365 admin access
  • Microsoft 365 admin roles
  • Microsoft 365 administration
  • Microsoft 365 audit
  • Microsoft 365 backups
  • Microsoft 365 checklist
  • Microsoft 365 Conditional Access
  • Microsoft 365 Governance
  • Microsoft 365 handover
  • Microsoft 365 IT provider
  • Microsoft 365 IT provider change
  • Microsoft 365 licenses
  • Microsoft 365 MFA
  • Microsoft 365 partner change
  • Microsoft 365 provider change
  • Microsoft 365 review
  • Microsoft 365 Security
  • Microsoft Defender
  • Microsoft Entra ID
  • Microsoft Purview
  • Microsoft Teams
  • OneDrive
  • review Microsoft 365 when changing IT provider
  • SharePoint Online

What to Check in Microsoft 365 When Changing IT Provider: Complete Checklist to Regain Control, Security, and Licensing Governance

Are you changing IT provider and want to review Microsoft 365 before the handover?

Changing IT provider should not feel like stepping into the unknown. In Microsoft 365, a poorly prepared handover can leave old access still active, licenses incorrectly assigned, unknown mail rules, unreviewed guests, or security policies only half configured.

At MSAdvance, we help review the Microsoft 365 tenant before, during, and after a provider change: we analyze access, licenses, security, email, Teams, SharePoint, Intune, Defender, and Purview so the company stays in control and does not depend on “what the previous provider used to do.”

  • Microsoft 365 audit focused on IT provider handover.
  • Review of partner relationships, GDAP/DAP, administrators, and service accounts.
  • Optimization of Microsoft 365 licenses to avoid duplication and unnecessary costs.
  • Minimum security plan: MFA, Conditional Access, Defender, Purview, and Intune.
  • Clear report with findings, risks, and priority actions.

Request a Microsoft 365 review View Security & Compliance service

You may also be interested in: Modern Workplace · License procurement and management · All services

When you change your IT provider, the first thing to review in Microsoft 365 is who has access to the tenant: global administrators, partner relationships, delegated permissions GDAP/DAP, service accounts, and applications with permissions. After that, you need to validate licensing, identity security, email, Teams, SharePoint, devices, backups, auditing, and compliance. The goal is to avoid inherited access, overspending, and invisible configurations that could affect the business.

Quick summary: what to check in Microsoft 365 when changing IT provider

  1. Partner access: review CSP relationships, GDAP/DAP, and delegated permissions from the previous provider.
  2. Administrators: confirm who has Global Administrator, Exchange Administrator, SharePoint Administrator, Teams Administrator, Intune Administrator, and other critical roles.
  3. Inherited accounts: locate service accounts, users from the former provider, shared mailboxes, and applications created by third parties.
  4. Microsoft 365 licenses: review what is being paid for, what is actually used, and which user profiles can be optimized.
  5. Identity security: MFA, Conditional Access, authentication methods, emergency accounts, and administrator policies.
  6. Email and DNS: Exchange Online, connectors, transport rules, SPF, DKIM, DMARC, shared mailboxes, and forwarding.
  7. Teams, SharePoint, and OneDrive: owners, guests, external links, broken permissions, orphaned sites, and document governance.
  8. Devices: Intune, compliance, profiles, applications, BitLocker, obsolete devices, and BYOD.
  9. Security and compliance: Defender, Purview, DLP, retention, auditing, and alerts.
  10. Transition plan: document, close old access, transfer knowledge, and leave a clear operating model in place.

Guide table of contents

  1. Quick summary: what to check in Microsoft 365 when changing IT provider
  2. When should you carry out a Microsoft 365 review because of an IT provider change?
  3. Introduction: changing provider is also a change of control
  4. 1. Review methodology: before, during, and after the handover
  5. 2. Partner relationships, CSP, GDAP, and DAP: who can administer your tenant
  6. 3. Administrators and critical roles: reduce privileges without blocking operations
  7. 4. Service accounts, former provider users, and registered applications
  8. 5. Microsoft 365 licenses: optimize cost before renewal or CSP change
  9. 6. Identity and access: MFA, Conditional Access, and emergency accounts
  10. 7. Exchange Online: email, connectors, forwarding, DKIM, SPF, and DMARC
  11. 8. Teams, SharePoint, and OneDrive: permissions, guests, and shared links
  12. 9. Intune and devices: who manages computers, mobile devices, and compliance
  13. 10. Microsoft Defender: email, endpoint, and identity security
  14. 11. Microsoft Purview: auditing, retention, DLP, and sensitive data
  15. 12. Backups, recovery, and continuity: what is not always clear
  16. 13. Documentation the outgoing provider should deliver
  17. 14. Transition plan: how to make the change without disrupting the business
  18. 15. Practical checklists: before, during, and after
  19. 16. Common mistakes when changing IT provider
  20. 17. Frequently asked questions (FAQ)
  21. 18. Official resources and useful links
  22. 19. Conclusion and next steps

When should you carry out a Microsoft 365 review because of an IT provider change?

You do not need to wait until there is a problem. In fact, the best time to review Microsoft 365 is before cutting ties with the previous provider or just before the new provider takes operational control.

The review helps you understand what exists, who has permissions, which licenses are being paid for, which configurations are critical, and which risks have accumulated over time.

Situations where this review is especially recommended

  • IT provider change: the company moves from one MSP, external support provider, or consulting firm to another.
  • CSP or licensing partner change: Microsoft 365 subscriptions are transferred to another provider or purchasing model.
  • Problematic contract ending: there is little documentation, limited visibility, or doubts over who controls the tenant.
  • Internal audit: leadership wants to know whether Microsoft 365 is well administered and secure.
  • Security incident: there has been phishing, suspicious access, data loss, or anomalous activity.
  • Rapid growth: the company has been creating users, groups, Teams, and sites without clear governance.
  • Cost review: there may be oversized licenses, inactive users, or duplicated services.
Typical example

A company changes provider and discovers that the former partner still had delegated permissions, that there were two administrator accounts without MFA, and that several users were paying for licenses above what they actually needed. None of this was visible day to day, but it still created risk and cost. A prior review would have allowed the company to correct it before the handover.

Introduction: changing provider is also a change of control

Microsoft 365 is often the digital core of a company: email, calendars, Teams, documents, devices, identities, security, and compliance. That is why, when the IT provider changes, it is not enough to “give access to the new one” and “remove the old one.”

The entire foundation needs to be reviewed: who administers, which permissions each person has, which services are configured, which licenses are paid for, and which risks remain open.

This guide is designed for companies that want to handle the handover calmly, without losing control of the tenant and without relying on information that only the previous provider knew. Throughout the article, we will see what to check in Microsoft 365 when changing IT provider, which mistakes to avoid, and how MSAdvance can support the process.

1. Review methodology: before, during, and after the handover

In practice: the review should turn an uncertain transition into a controlled, documented, and measurable process.

Changing IT provider affects people, contracts, and technology. If it is done without a method, the company can spend days or weeks with duplicated access, unclear support ownership, or configurations nobody dares to touch.

1.1 Recommended phases

  1. Initial inventory: users, roles, licenses, active services, domains, security, devices, and applications.
  2. Access review: partner relationships, GDAP/DAP, administrators, accounts from the former provider, and applications with permissions.
  3. Risk analysis: what can affect security, continuity, compliance, or cost.
  4. Transition plan: what is removed, what is kept, what is handed over to the new provider, and what is corrected before the change.
  5. Closure and stabilization: remove old access, validate operations, document the environment, and define follow-up KPIs.

1.2 Recommended RACI for the provider change

Recommended roles during the transition
ActivityResponsibleApprovesConsultedInformed
Microsoft 365 inventoryMSAdvance / ITLeadership / ITOutgoing providerNew provider
Removal of previous provider permissionsIT / MSAdvanceLeadership / Security ownerLegal / ProcurementKey users
License reviewMSAdvanceFinance / ITHR / BusinessLeadership
Security hardeningMSAdvance / SecurityIT / CISONew providerUsers
Final documentationMSAdvance / ITITNew providerLeadership
Practical advice:

Do not turn the handover into a provider dispute. The goal is not to “find someone to blame,” but to regain control, document the environment, and close inherited risks.

2. Partner relationships, CSP, GDAP, and DAP: who can administer your tenant

In practice: the first step is to know which partners have a relationship with your tenant and which permissions they retain.

In Microsoft 365, a provider can access the tenant through a partner relationship, delegated permissions, or accounts created within the environment itself. If you change provider, this layer must be reviewed very carefully.

2.1 What to review

  • Partner relationships: which partners are associated with the tenant.
  • GDAP: delegated granular permissions, more limited and with a defined duration.
  • Legacy DAP: broad delegated permissions, especially sensitive if they remain active.
  • CSP relationship: who supplies or manages the licenses and whether there is contractual dependency.
  • Provider users: accounts with the corporate domain created for external technicians.

2.2 What to do when changing provider

  1. Identify all partners in the Microsoft 365 admin center.
  2. Review which permissions each partner has and whether they are still necessary.
  3. Remove roles from the previous provider when they should no longer operate the tenant.
  4. Grant the new provider only the required permissions, preferably following least privilege.
  5. Keep evidence of the change for internal audit.
Official documentation: Manage partner relationships in Microsoft 365 · Terminate a GDAP relationship from the customer side · Official GDAP FAQ
Common situation

The company believes the previous provider “no longer has access” because the contract ended. But delegated permissions or technical accounts still appear in the portal. Contract termination and technical offboarding do not always happen at the same time. You need to verify it.

3. Administrators and critical roles: reduce privileges without blocking operations

In practice: too many global administrators is one of the easiest ways to increase risk.

The Global Administrator role must be tightly controlled. Not every technician, provider, or internal owner needs that level of access. A provider change is a good time to apply the principle of least privilege: each person should have only the role they need to do their job.

3.1 Roles worth reviewing

  • Global Administrator: maximum privilege; must be highly restricted.
  • Privileged Role Administrator: can manage role assignments.
  • Exchange Administrator: controls email, connectors, and rules.
  • SharePoint Administrator: controls sites, OneDrive, and sharing.
  • Teams Administrator: controls Teams, meetings, calling, and policies.
  • Intune Administrator: controls devices, applications, and compliance.
  • Security Administrator / Compliance Administrator: controls security, alerts, and compliance.

3.2 Best practices during the handover

  • Reduce the number of global administrators.
  • Require strong MFA for all administrators.
  • Avoid shared accounts such as admin@company.com without individual traceability.
  • Review active sessions and authentication methods.
  • Create protected and documented emergency accounts.
Official documentation: Best practices for roles in Microsoft Entra · Administrator account security in Microsoft 365

4. Service accounts, former provider users, and registered applications

In practice: many critical dependencies are not found in normal users, but in technical accounts and applications that nobody reviews.

When a provider manages Microsoft 365 for a long time, it often creates accounts for scripts, integrations, backups, ticketing tools, monitoring, or deployments. Some are necessary. Others have been forgotten.

4.1 What to look for

  • Accounts with names such as svc-, backup-, sync-, admin-, it-.
  • Users from the former provider with corporate email addresses.
  • Applications registered in Entra ID with Microsoft Graph permissions.
  • Secrets or certificates close to expiry.
  • Enterprise applications with admin consent.
  • Automation scripts using personal accounts or old credentials.

4.2 What to do with them

  1. Classify them as necessary, unknown, obsolete, or risky.
  2. Assign an internal owner or an owner from the new provider.
  3. Change credentials, certificates, or secrets if the account is kept.
  4. Remove anything with no justification.
  5. Document purpose, permissions, review date, and owner.
Realistic example

A service account created for an old migration still has administrator permissions. Nobody uses it, but it is still active. For an attacker, that kind of account is an open door. For the company, it is an invisible risk.

5. Microsoft 365 licenses: optimize cost before renewal or CSP change

In practice: changing provider is an excellent opportunity to stop paying for licenses that are unused or not aligned with each profile.

The IT provider often manages onboarding, offboarding, and license purchases. Over time, it is common to accumulate unused licenses, plans that are too advanced for certain profiles, or add-ons nobody remembers why they were purchased.

5.1 What to review

  • Users without a license who should have one.
  • Users with a license but no activity.
  • Former employees or blocked accounts still consuming a license.
  • Duplicated licenses or add-ons already included in another plan.
  • Differences between Business Basic, Business Standard, Business Premium, E3, E5, and add-ons.
  • Critical services that depend on a specific license: Intune, Defender, Purview, Teams Phone, Power BI, etc.
Practical license review during an IT provider change
ProfileCommon riskRecommended review
Office usersLicenses that are too basic for real work or too advanced without actual useAdjust based on desktop apps, security, and collaboration needs
Leadership and financeExposure of sensitive data without enough protectionReview MFA, Conditional Access, DLP, Defender, and retention
Temporary usersLicenses still active after the contract endsOffboarding process and monthly review
Frontline / light profilesOversized planCheck whether a more appropriate plan covers the needs
AdministratorsLicenses without the necessary security capabilitiesReview Entra, Defender, Intune, and auditing

MSAdvance can help review licensing, detect savings opportunities, and propose a profile-based model.

Related service: Software license procurement and sales for businesses.

6. Identity and access: MFA, Conditional Access, and emergency accounts

In practice: identity is the first line of defense. If access is poorly configured, everything else is exposed.

During a provider change, it is important to review how users and administrators authenticate. It is not enough to “have MFA enabled for some users.” You need to check whether policies cover critical profiles and whether dangerous exceptions exist.

6.1 Points worth reviewing

  • MFA: covered users, covered administrators, allowed methods, and exceptions.
  • Conditional Access: policies by risk, location, device, and user type.
  • Security Defaults: whether they are enabled or whether custom policies are used.
  • Emergency accounts: protected, documented, and excluded with clear criteria.
  • Old methods: basic authentication, POP, IMAP, SMTP AUTH, legacy protocols.
  • Guest users: review of external users with access to the tenant.

6.2 Warning signs

  • Administrators without MFA.
  • Conditional Access policies created but not applied to all the correct groups.
  • Permanent “just in case” exceptions.
  • Old guest users who no longer collaborate with the company.
  • Shared accounts without traceability.
Official documentation: Security Defaults in Microsoft Entra ID · Plan Conditional Access · Require MFA for administrators

7. Exchange Online: email, connectors, forwarding, DKIM, SPF, and DMARC

In practice: email often hides old rules, unknown connectors, and forwarding nobody remembers.

Exchange Online is one of the most sensitive areas when the provider changes. A poorly documented connector, an old transport rule, or external forwarding can affect security, mail delivery, or privacy.

7.1 What to review in Exchange Online

  • Accepted domains and associated DNS records.
  • SPF, DKIM, and DMARC records.
  • Inbound and outbound connectors.
  • Transport rules.
  • External forwarding in mailboxes.
  • Shared mailboxes and delegation permissions.
  • Send As, Send on Behalf, and Full Access permissions.
  • Distribution lists and Microsoft 365 Groups.
  • Anti-spam, anti-phishing, and anti-malware policies.

7.2 Typical mistakes

  • A former provider leaves a connector configured for a tool that is no longer used.
  • There is external forwarding from leadership or billing mailboxes.
  • DKIM is not enabled on all active domains.
  • DMARC exists, but it is not monitored or hardened.
  • Transport rules have undocumented exceptions.
Official documentation: Recommended settings for EOP and Defender for Office 365 · Anti-phishing policies · Connectors and mail authentication

8. Teams, SharePoint, and OneDrive: permissions, guests, and shared links

In practice: this is where real work information usually lives: documents, projects, minutes, proposals, contracts, and conversations.

When the IT provider changes, collaboration should be reviewed. Not only for security, but also for order. Many tenants grow with Teams and SharePoint sites created without a clear strategy.

8.1 Microsoft Teams

  • Teams without owners.
  • Abandoned or duplicated teams.
  • External guests.
  • Private and shared channels.
  • Meeting, recording, and transcription policies.
  • Apps installed in Teams.

8.2 SharePoint Online

  • Orphaned sites or sites without a business owner.
  • Inherited and broken permissions.
  • Anonymous or external links.
  • Critical libraries without versioning or document control.
  • Sensitive content without labels or protection.

8.3 OneDrive

  • Files shared externally.
  • OneDrive accounts for offboarded users.
  • Owners and delegated access.
  • Synchronization and device policies.
Related MSAdvance reading: Modern Workplace · SharePoint as a document management system · Document automation with SharePoint and Power Automate

9. Intune and devices: who manages computers, mobile devices, and compliance

In practice: if the provider managed devices, Intune must be reviewed before the handover leaves endpoints without support.

Microsoft Intune is often one of the most delicate areas in a provider change because it affects laptops, mobile devices, applications, encryption, compliance, and access to corporate data.

9.1 What to review

  • Enrolled devices and compliance status.
  • Personal devices (BYOD) and corporate devices.
  • Compliance policies.
  • Configuration profiles.
  • Deployed applications.
  • BitLocker and recovery keys.
  • Windows Autopilot.
  • Intune administrators and scopes.

9.2 Key questions

  • Who can remotely wipe a computer or mobile device?
  • Where are the BitLocker recovery keys?
  • What happens if a user loses their laptop?
  • Which devices have access to email and documents?
  • Do the policies depend on groups created by the previous provider?

Related service: Modern Workplace with Microsoft 365, Intune, and Defender.

10. Microsoft Defender: email, endpoint, and identity security

In practice: you need to check whether security tools are purchased, enabled, properly configured, and monitored.

Many companies have licenses that include security capabilities, but that does not mean those capabilities are well deployed. When changing provider, it is worth checking whether Defender is genuinely protecting the environment or merely appearing on the invoice.

10.1 What to review

  • Defender for Office 365: Safe Links, Safe Attachments, anti-phishing, spoof intelligence, Explorer, and alerts.
  • Defender for Endpoint: device onboarding, exposure level, recommendations, and alerts.
  • Defender for Identity: if there is on-premises Active Directory and risk of lateral movement.
  • Defender XDR: incident correlation across identity, email, endpoint, and applications.

10.2 Important questions

  • Who receives alerts?
  • Who investigates them?
  • Are there playbooks or a response procedure?
  • Are recommendations reviewed, or are they only checked when something happens?
  • Do critical users have enhanced protection?
Official documentation: Threat Explorer and real-time detections · Email security reports

11. Microsoft Purview: auditing, retention, DLP, and sensitive data

In practice: compliance is not just “having it licensed”; you need to know which policies exist, where they apply, and who reviews them.

Microsoft Purview helps govern data: auditing, retention, eDiscovery, sensitivity labels, and data loss prevention. If the provider changes, you need to review whether policies are aligned with the business or whether they were configured once and never touched again.

11.1 What to review

  • Unified auditing and permissions to search it.
  • Retention policies in Exchange, SharePoint, OneDrive, and Teams.
  • Sensitivity labels.
  • DLP for email and documents.
  • eDiscovery and open cases.
  • Compliance alerts.
  • External administrator access to sensitive data.

11.2 What is often missing

  • Policies created without a business owner.
  • DLP permanently left in test mode.
  • Retention applied generically without reviewing legal impact.
  • Labels that exist, but nobody uses.
  • Auditing without a review procedure.
Official documentation: Auditing solutions in Microsoft Purview · Data Loss Prevention in Microsoft Purview

12. Backups, recovery, and continuity: what is not always clear

In practice: Microsoft 365 has retention and recovery capabilities, but that does not always equal a complete backup strategy.

A very useful question during a provider change is: “if tomorrow someone deletes important information, who restores it, from where, and within what timeframe?”. The answer is not always documented.

12.1 What to review

  • Which backup tools exist for Microsoft 365.
  • What they cover: Exchange, OneDrive, SharePoint, Teams, Planner, etc.
  • Where backups are stored.
  • Who has access to restore.
  • Backup frequency and expected recovery times.
  • Real restore tests.
  • Relationship between backup, retention, and compliance.
An uncomfortable but necessary question

“When was the last time you restored a mailbox, a SharePoint document, or a Teams workspace in a real test?” If nobody knows, you do not have a validated strategy: you have an assumption.

13. Documentation the outgoing provider should deliver

In practice: a transition without documentation turns the new provider into a detective and the client into a hostage of missing knowledge.

A professional provider should facilitate an orderly exit. The company should request enough documentation so the new team can operate without relying on emergency calls.

Recommended minimum documentation

  • Inventory of users, groups, and administrative roles.
  • Existing partner relationships and delegated permissions.
  • License summary and purchasing model.
  • Configuration of domains and DNS related to Microsoft 365.
  • Exchange Online: connectors, rules, shared mailboxes, and special flows.
  • Teams: policies, critical teams, guests, and apps.
  • SharePoint/OneDrive: critical sites, special permissions, and external sharing.
  • Intune: profiles, compliance, applications, and Autopilot.
  • Defender/Purview: policies, alerts, retention, and procedures.
  • Backups, external tools, and integrations.
  • Operational procedures: joins, leavers, changes, incidents, and escalations.
Advice:

Request documentation before cutting access. After the cutover, everything costs more: more time, more tension, and a higher risk that something remains unexplained.

14. Transition plan: how to make the change without disrupting the business

In practice: the handover should be carried out in phases, with clear owners and without improvising critical permissions.

14.1 Before the change

  • Inventory of access, licenses, and services.
  • Identification of critical risks.
  • Internal communication plan.
  • Agreement on what the outgoing provider must deliver.
  • Controlled onboarding of the new provider with the minimum required permissions.

14.2 During the change

  • Validate that the new provider can operate without excessive permissions.
  • Remove previous provider access at the agreed time.
  • Monitor sign-ins, administrative changes, and alerts.
  • Review email and critical services after the change.

14.3 After the change

  • Final review of partner relationships and administrators.
  • Report on closed and pending findings.
  • Priority-based remediation plan.
  • Review of licenses and costs.
  • Operational documentation for the new support model.

Do you want an independent review before changing IT provider?

MSAdvance can carry out a Microsoft 365 audit focused on the handover: access, partners, roles, licenses, security, email, collaboration, devices, and compliance.

Request a Microsoft 365 audit View Security & Compliance

15. Practical checklists: before, during, and after

In practice: a checklist prevents the change from depending on memory, trust, or intuition.

15.1 Before changing provider

  • Identify partner relationships and delegated permissions.
  • List administrators and critical roles.
  • Review previous provider accounts.
  • Export license inventory.
  • Document domains and DNS.
  • Review Exchange connectors and rules.
  • Review guests in Teams, SharePoint, and Entra ID.
  • Confirm who manages devices in Intune.
  • Request documentation from the outgoing provider.

15.2 During the handover

  • Give access to the new provider with the minimum required roles.
  • Remove or reduce access from the previous provider.
  • Review sign-ins and administrative changes.
  • Validate email, Teams, SharePoint, OneDrive, and Intune.
  • Confirm the support channel for users.

15.3 After the change

  • Verify that no old accounts remain active.
  • Confirm that no unnecessary delegated permissions remain.
  • Optimize licenses.
  • Harden priority security controls.
  • Document the new operation.
  • Schedule a periodic Microsoft 365 review.

16. Common mistakes when changing IT provider

In practice: most problems do not appear on the day of the change, but weeks later, when someone tries to operate something nobody documented.

MistakeWhat can happenHow to avoid it
Not removing permissions from the previous providerRisk of unauthorized access or uncontrolled changesReview partner relationships, GDAP/DAP, and external accounts
Giving the new provider Global Administrator “for convenience”Excessive privileges and a larger attack surfaceApply least privilege and specific roles
Not reviewing licensesRecurring overspend or missing critical capabilitiesLicense audit by profile and real usage
Ignoring email connectors and rulesDelivery failures, security bypasses, or improper forwardingComplete Exchange Online review
Not reviewing guestsExternal users with access to old Teams, SharePoint sites, or documentsRecertification of guests and shared links
Not documenting operationsThe new provider loses time investigating the environmentFormal documentation delivery and basic runbook

17. Frequently asked questions (FAQ) about changing IT provider in Microsoft 365

What is the first thing I should review in Microsoft 365 when changing provider?

The first thing is access: partner relationships, GDAP/DAP, global administrators, accounts from the previous provider, service accounts, and applications with permissions. After that, it is advisable to review licenses, security, email, collaboration, and devices.

Can the previous provider still have access even if they no longer work with us?

Yes, this can happen if delegated permissions, partner relationships, or accounts created inside the tenant are not removed. That is why a technical review matters, not only contract closure.

What is the difference between GDAP and DAP?

GDAP allows more granular delegated permissions with a defined duration. DAP is a broader legacy model. When changing provider, both should be reviewed and only what is necessary should remain.

Can I change CSP without migrating the whole tenant?

In many cases, yes. Changing the license provider or CSP does not necessarily mean migrating email, files, or Teams. Even so, it is advisable to review licenses, access, and support to avoid interruptions.

Should I remove all administrators from the previous provider?

If the provider no longer delivers service, the normal approach is to remove its access. If there is still a transition phase, temporary and minimal permissions can be maintained, always documented and with a removal date.

Which licenses should be reviewed during the change?

All of them: Microsoft 365 Business, Enterprise, Defender, Intune, Teams Phone, Power BI, Visio, Project, Copilot, and add-ons. The goal is to verify whether they are used, correctly assigned, and aligned with each profile.

What happens if the previous provider does not deliver documentation?

A large part of the environment can be reconstructed from the admin portals, logs, and current configuration. Even so, it will take longer and should be done through a structured audit.

Can MSAdvance carry out an independent review even if another provider will manage support later?

Yes. MSAdvance can perform a one-off Microsoft 365 audit, deliver findings and recommendations, and leave documentation so the client or the new provider can operate more securely.

Does the Microsoft 365 review include security?

Yes. It reviews identities, MFA, Conditional Access, administrators, email, Defender, devices, guests, external sharing, auditing, and compliance, depending on the agreed scope.

18. Official resources and useful links

Official Microsoft documentation

  • Manage partner relationships in Microsoft 365
  • Terminate a GDAP relationship from the customer side
  • GDAP FAQ
  • Best practices for roles in Microsoft Entra
  • Security Defaults in Microsoft Entra
  • Plan Conditional Access
  • Recommended settings for Defender for Office 365
  • Data Loss Prevention in Microsoft Purview

MSAdvance services and resources

  • Contact MSAdvance
  • Microsoft 365 Security & Compliance
  • Microsoft 365 Modern Workplace
  • Software license procurement and sales for businesses
  • Microsoft 365 security audit
  • All services

19. Conclusion and next steps

Changing IT provider is an opportunity to bring order to Microsoft 365. It is not only about changing who answers tickets: it is about confirming who has access, which licenses are being paid for, which security controls are active, and which configurations support the business.

A good Microsoft 365 review prevents three very common problems: hidden risk, unnecessary cost, and dependency on undocumented knowledge.

Recommended next steps

  • Create an inventory of administrators, partners, and technical accounts.
  • Review licenses and inactive users.
  • Validate MFA, Conditional Access, and email security.
  • Review guests, permissions, and shared links.
  • Document the environment before removing the previous provider.

Do you want MSAdvance to review your Microsoft 365 before the provider change?

We can help you with a clear, prioritized, and actionable review: access, licenses, security, email, collaboration, devices, and compliance.

Request a Microsoft 365 review View Security & Compliance

· We can also help with Modern Workplace, licensing, and Microsoft 365 and Azure services.

What to Check in Microsoft 365 When Changing IT Provider
MSAdvance
Microsoft 365 · Azure · Cybersecurity

Specialist consulting for Microsoft 365, Azure and cybersecurity.

MSAdvance provides Microsoft 365 consulting, migration, Modern Workplace, cybersecurity, Azure, managed services and Microsoft licensing. We work alongside the client team with a clearly defined scope, technical documentation and control throughout each phase of the project.

Microsoft Partner 25+ Microsoft certifications Established 2010 International projects
Project enquiries

Would you like us to review a project or prepare a proposal?

Send us the current environment, planned scope and target date. We will review the information and come back with the next steps and, where appropriate, a proposal.

Contact MSAdvance View success stories
info@msadvance.comInternational remote delivery
01 Services
  • All services
  • Microsoft 365 Consulting
  • Microsoft 365 Migrations
  • Modern Workplace
  • Microsoft Cybersecurity
  • Microsoft Azure
  • Managed Services
  • Microsoft Licensing
02 MSAdvance
  • About Us
  • Microsoft Partner & Certifications
  • Success Stories
  • Our Methodology
  • Trust Center
  • Blog & Technical Guides
03 Contact
General info@msadvance.com
Projects sales@msadvance.com
Support support@msadvance.com
Delivery International remote delivery
Remote delivery for organizations across Europe, the Americas and other international markets. Contact form

© 2026 MSAdvance. All rights reserved.

Legal NoticePrivacyCookies
ESEN
MSAdvance
Gestionar consentimiento
Para ofrecer las mejores experiencias, utilizamos tecnologías como las cookies para almacenar y/o acceder a la información del dispositivo. El consentimiento de estas tecnologías nos permitirá procesar datos como el comportamiento de navegación o las identificaciones únicas en este sitio. No consentir o retirar el consentimiento, puede afectar negativamente a ciertas características y funciones.
Funcional Always active
El almacenamiento o acceso técnico es estrictamente necesario para el propósito legítimo de permitir el uso de un servicio específico explícitamente solicitado por el abonado o usuario, o con el único propósito de llevar a cabo la transmisión de una comunicación a través de una red de comunicaciones electrónicas.
Preferencias
El almacenamiento o acceso técnico es necesario para la finalidad legítima de almacenar preferencias no solicitadas por el abonado o usuario.
Estadísticas
El almacenamiento o acceso técnico que es utilizado exclusivamente con fines estadísticos. El almacenamiento o acceso técnico que se utiliza exclusivamente con fines estadísticos anónimos. Sin un requerimiento, el cumplimiento voluntario por parte de tu proveedor de servicios de Internet, o los registros adicionales de un tercero, la información almacenada o recuperada sólo para este propósito no se puede utilizar para identificarte.
Marketing
El almacenamiento o acceso técnico es necesario para crear perfiles de usuario para enviar publicidad, o para rastrear al usuario en una web o en varias web con fines de marketing similares.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Ver preferencias
  • {title}
  • {title}
  • {title}