Are you changing IT provider and want to review Microsoft 365 before the handover?
Changing IT provider should not feel like stepping into the unknown. In Microsoft 365, a poorly prepared handover can leave old access still active, licenses incorrectly assigned, unknown mail rules, unreviewed guests, or security policies only half configured.
At MSAdvance, we help review the Microsoft 365 tenant before, during, and after a provider change: we analyze access, licenses, security, email, Teams, SharePoint, Intune, Defender, and Purview so the company stays in control and does not depend on “what the previous provider used to do.”
- Microsoft 365 audit focused on IT provider handover.
- Review of partner relationships, GDAP/DAP, administrators, and service accounts.
- Optimization of Microsoft 365 licenses to avoid duplication and unnecessary costs.
- Minimum security plan: MFA, Conditional Access, Defender, Purview, and Intune.
- Clear report with findings, risks, and priority actions.
Request a Microsoft 365 review View Security & Compliance service
You may also be interested in: Modern Workplace · License procurement and management · All services
When you change your IT provider, the first thing to review in Microsoft 365 is who has access to the tenant: global administrators, partner relationships, delegated permissions GDAP/DAP, service accounts, and applications with permissions. After that, you need to validate licensing, identity security, email, Teams, SharePoint, devices, backups, auditing, and compliance. The goal is to avoid inherited access, overspending, and invisible configurations that could affect the business.
Quick summary: what to check in Microsoft 365 when changing IT provider
- Partner access: review CSP relationships, GDAP/DAP, and delegated permissions from the previous provider.
- Administrators: confirm who has Global Administrator, Exchange Administrator, SharePoint Administrator, Teams Administrator, Intune Administrator, and other critical roles.
- Inherited accounts: locate service accounts, users from the former provider, shared mailboxes, and applications created by third parties.
- Microsoft 365 licenses: review what is being paid for, what is actually used, and which user profiles can be optimized.
- Identity security: MFA, Conditional Access, authentication methods, emergency accounts, and administrator policies.
- Email and DNS: Exchange Online, connectors, transport rules, SPF, DKIM, DMARC, shared mailboxes, and forwarding.
- Teams, SharePoint, and OneDrive: owners, guests, external links, broken permissions, orphaned sites, and document governance.
- Devices: Intune, compliance, profiles, applications, BitLocker, obsolete devices, and BYOD.
- Security and compliance: Defender, Purview, DLP, retention, auditing, and alerts.
- Transition plan: document, close old access, transfer knowledge, and leave a clear operating model in place.
When should you carry out a Microsoft 365 review because of an IT provider change?
You do not need to wait until there is a problem. In fact, the best time to review Microsoft 365 is before cutting ties with the previous provider or just before the new provider takes operational control.
The review helps you understand what exists, who has permissions, which licenses are being paid for, which configurations are critical, and which risks have accumulated over time.
Situations where this review is especially recommended
- IT provider change: the company moves from one MSP, external support provider, or consulting firm to another.
- CSP or licensing partner change: Microsoft 365 subscriptions are transferred to another provider or purchasing model.
- Problematic contract ending: there is little documentation, limited visibility, or doubts over who controls the tenant.
- Internal audit: leadership wants to know whether Microsoft 365 is well administered and secure.
- Security incident: there has been phishing, suspicious access, data loss, or anomalous activity.
- Rapid growth: the company has been creating users, groups, Teams, and sites without clear governance.
- Cost review: there may be oversized licenses, inactive users, or duplicated services.
A company changes provider and discovers that the former partner still had delegated permissions, that there were two administrator accounts without MFA, and that several users were paying for licenses above what they actually needed. None of this was visible day to day, but it still created risk and cost. A prior review would have allowed the company to correct it before the handover.
Introduction: changing provider is also a change of control
Microsoft 365 is often the digital core of a company: email, calendars, Teams, documents, devices, identities, security, and compliance. That is why, when the IT provider changes, it is not enough to “give access to the new one” and “remove the old one.”
The entire foundation needs to be reviewed: who administers, which permissions each person has, which services are configured, which licenses are paid for, and which risks remain open.
This guide is designed for companies that want to handle the handover calmly, without losing control of the tenant and without relying on information that only the previous provider knew. Throughout the article, we will see what to check in Microsoft 365 when changing IT provider, which mistakes to avoid, and how MSAdvance can support the process.
1. Review methodology: before, during, and after the handover
In practice: the review should turn an uncertain transition into a controlled, documented, and measurable process.
Changing IT provider affects people, contracts, and technology. If it is done without a method, the company can spend days or weeks with duplicated access, unclear support ownership, or configurations nobody dares to touch.
1.1 Recommended phases
- Initial inventory: users, roles, licenses, active services, domains, security, devices, and applications.
- Access review: partner relationships, GDAP/DAP, administrators, accounts from the former provider, and applications with permissions.
- Risk analysis: what can affect security, continuity, compliance, or cost.
- Transition plan: what is removed, what is kept, what is handed over to the new provider, and what is corrected before the change.
- Closure and stabilization: remove old access, validate operations, document the environment, and define follow-up KPIs.
1.2 Recommended RACI for the provider change
| Activity | Responsible | Approves | Consulted | Informed |
|---|---|---|---|---|
| Microsoft 365 inventory | MSAdvance / IT | Leadership / IT | Outgoing provider | New provider |
| Removal of previous provider permissions | IT / MSAdvance | Leadership / Security owner | Legal / Procurement | Key users |
| License review | MSAdvance | Finance / IT | HR / Business | Leadership |
| Security hardening | MSAdvance / Security | IT / CISO | New provider | Users |
| Final documentation | MSAdvance / IT | IT | New provider | Leadership |
Do not turn the handover into a provider dispute. The goal is not to “find someone to blame,” but to regain control, document the environment, and close inherited risks.
2. Partner relationships, CSP, GDAP, and DAP: who can administer your tenant
In practice: the first step is to know which partners have a relationship with your tenant and which permissions they retain.
In Microsoft 365, a provider can access the tenant through a partner relationship, delegated permissions, or accounts created within the environment itself. If you change provider, this layer must be reviewed very carefully.
2.1 What to review
- Partner relationships: which partners are associated with the tenant.
- GDAP: delegated granular permissions, more limited and with a defined duration.
- Legacy DAP: broad delegated permissions, especially sensitive if they remain active.
- CSP relationship: who supplies or manages the licenses and whether there is contractual dependency.
- Provider users: accounts with the corporate domain created for external technicians.
2.2 What to do when changing provider
- Identify all partners in the Microsoft 365 admin center.
- Review which permissions each partner has and whether they are still necessary.
- Remove roles from the previous provider when they should no longer operate the tenant.
- Grant the new provider only the required permissions, preferably following least privilege.
- Keep evidence of the change for internal audit.
The company believes the previous provider “no longer has access” because the contract ended. But delegated permissions or technical accounts still appear in the portal. Contract termination and technical offboarding do not always happen at the same time. You need to verify it.
3. Administrators and critical roles: reduce privileges without blocking operations
In practice: too many global administrators is one of the easiest ways to increase risk.
The Global Administrator role must be tightly controlled. Not every technician, provider, or internal owner needs that level of access. A provider change is a good time to apply the principle of least privilege: each person should have only the role they need to do their job.
3.1 Roles worth reviewing
- Global Administrator: maximum privilege; must be highly restricted.
- Privileged Role Administrator: can manage role assignments.
- Exchange Administrator: controls email, connectors, and rules.
- SharePoint Administrator: controls sites, OneDrive, and sharing.
- Teams Administrator: controls Teams, meetings, calling, and policies.
- Intune Administrator: controls devices, applications, and compliance.
- Security Administrator / Compliance Administrator: controls security, alerts, and compliance.
3.2 Best practices during the handover
- Reduce the number of global administrators.
- Require strong MFA for all administrators.
- Avoid shared accounts such as
admin@company.comwithout individual traceability. - Review active sessions and authentication methods.
- Create protected and documented emergency accounts.
4. Service accounts, former provider users, and registered applications
In practice: many critical dependencies are not found in normal users, but in technical accounts and applications that nobody reviews.
When a provider manages Microsoft 365 for a long time, it often creates accounts for scripts, integrations, backups, ticketing tools, monitoring, or deployments. Some are necessary. Others have been forgotten.
4.1 What to look for
- Accounts with names such as
svc-,backup-,sync-,admin-,it-. - Users from the former provider with corporate email addresses.
- Applications registered in Entra ID with Microsoft Graph permissions.
- Secrets or certificates close to expiry.
- Enterprise applications with admin consent.
- Automation scripts using personal accounts or old credentials.
4.2 What to do with them
- Classify them as necessary, unknown, obsolete, or risky.
- Assign an internal owner or an owner from the new provider.
- Change credentials, certificates, or secrets if the account is kept.
- Remove anything with no justification.
- Document purpose, permissions, review date, and owner.
A service account created for an old migration still has administrator permissions. Nobody uses it, but it is still active. For an attacker, that kind of account is an open door. For the company, it is an invisible risk.
5. Microsoft 365 licenses: optimize cost before renewal or CSP change
In practice: changing provider is an excellent opportunity to stop paying for licenses that are unused or not aligned with each profile.
The IT provider often manages onboarding, offboarding, and license purchases. Over time, it is common to accumulate unused licenses, plans that are too advanced for certain profiles, or add-ons nobody remembers why they were purchased.
5.1 What to review
- Users without a license who should have one.
- Users with a license but no activity.
- Former employees or blocked accounts still consuming a license.
- Duplicated licenses or add-ons already included in another plan.
- Differences between Business Basic, Business Standard, Business Premium, E3, E5, and add-ons.
- Critical services that depend on a specific license: Intune, Defender, Purview, Teams Phone, Power BI, etc.
| Profile | Common risk | Recommended review |
|---|---|---|
| Office users | Licenses that are too basic for real work or too advanced without actual use | Adjust based on desktop apps, security, and collaboration needs |
| Leadership and finance | Exposure of sensitive data without enough protection | Review MFA, Conditional Access, DLP, Defender, and retention |
| Temporary users | Licenses still active after the contract ends | Offboarding process and monthly review |
| Frontline / light profiles | Oversized plan | Check whether a more appropriate plan covers the needs |
| Administrators | Licenses without the necessary security capabilities | Review Entra, Defender, Intune, and auditing |
MSAdvance can help review licensing, detect savings opportunities, and propose a profile-based model.
Related service: Software license procurement and sales for businesses.
6. Identity and access: MFA, Conditional Access, and emergency accounts
In practice: identity is the first line of defense. If access is poorly configured, everything else is exposed.
During a provider change, it is important to review how users and administrators authenticate. It is not enough to “have MFA enabled for some users.” You need to check whether policies cover critical profiles and whether dangerous exceptions exist.
6.1 Points worth reviewing
- MFA: covered users, covered administrators, allowed methods, and exceptions.
- Conditional Access: policies by risk, location, device, and user type.
- Security Defaults: whether they are enabled or whether custom policies are used.
- Emergency accounts: protected, documented, and excluded with clear criteria.
- Old methods: basic authentication, POP, IMAP, SMTP AUTH, legacy protocols.
- Guest users: review of external users with access to the tenant.
6.2 Warning signs
- Administrators without MFA.
- Conditional Access policies created but not applied to all the correct groups.
- Permanent “just in case” exceptions.
- Old guest users who no longer collaborate with the company.
- Shared accounts without traceability.
7. Exchange Online: email, connectors, forwarding, DKIM, SPF, and DMARC
In practice: email often hides old rules, unknown connectors, and forwarding nobody remembers.
Exchange Online is one of the most sensitive areas when the provider changes. A poorly documented connector, an old transport rule, or external forwarding can affect security, mail delivery, or privacy.
7.1 What to review in Exchange Online
- Accepted domains and associated DNS records.
- SPF, DKIM, and DMARC records.
- Inbound and outbound connectors.
- Transport rules.
- External forwarding in mailboxes.
- Shared mailboxes and delegation permissions.
- Send As, Send on Behalf, and Full Access permissions.
- Distribution lists and Microsoft 365 Groups.
- Anti-spam, anti-phishing, and anti-malware policies.
7.2 Typical mistakes
- A former provider leaves a connector configured for a tool that is no longer used.
- There is external forwarding from leadership or billing mailboxes.
- DKIM is not enabled on all active domains.
- DMARC exists, but it is not monitored or hardened.
- Transport rules have undocumented exceptions.
9. Intune and devices: who manages computers, mobile devices, and compliance
In practice: if the provider managed devices, Intune must be reviewed before the handover leaves endpoints without support.
Microsoft Intune is often one of the most delicate areas in a provider change because it affects laptops, mobile devices, applications, encryption, compliance, and access to corporate data.
9.1 What to review
- Enrolled devices and compliance status.
- Personal devices (BYOD) and corporate devices.
- Compliance policies.
- Configuration profiles.
- Deployed applications.
- BitLocker and recovery keys.
- Windows Autopilot.
- Intune administrators and scopes.
9.2 Key questions
- Who can remotely wipe a computer or mobile device?
- Where are the BitLocker recovery keys?
- What happens if a user loses their laptop?
- Which devices have access to email and documents?
- Do the policies depend on groups created by the previous provider?
Related service: Modern Workplace with Microsoft 365, Intune, and Defender.
10. Microsoft Defender: email, endpoint, and identity security
In practice: you need to check whether security tools are purchased, enabled, properly configured, and monitored.
Many companies have licenses that include security capabilities, but that does not mean those capabilities are well deployed. When changing provider, it is worth checking whether Defender is genuinely protecting the environment or merely appearing on the invoice.
10.1 What to review
- Defender for Office 365: Safe Links, Safe Attachments, anti-phishing, spoof intelligence, Explorer, and alerts.
- Defender for Endpoint: device onboarding, exposure level, recommendations, and alerts.
- Defender for Identity: if there is on-premises Active Directory and risk of lateral movement.
- Defender XDR: incident correlation across identity, email, endpoint, and applications.
10.2 Important questions
- Who receives alerts?
- Who investigates them?
- Are there playbooks or a response procedure?
- Are recommendations reviewed, or are they only checked when something happens?
- Do critical users have enhanced protection?
11. Microsoft Purview: auditing, retention, DLP, and sensitive data
In practice: compliance is not just “having it licensed”; you need to know which policies exist, where they apply, and who reviews them.
Microsoft Purview helps govern data: auditing, retention, eDiscovery, sensitivity labels, and data loss prevention. If the provider changes, you need to review whether policies are aligned with the business or whether they were configured once and never touched again.
11.1 What to review
- Unified auditing and permissions to search it.
- Retention policies in Exchange, SharePoint, OneDrive, and Teams.
- Sensitivity labels.
- DLP for email and documents.
- eDiscovery and open cases.
- Compliance alerts.
- External administrator access to sensitive data.
11.2 What is often missing
- Policies created without a business owner.
- DLP permanently left in test mode.
- Retention applied generically without reviewing legal impact.
- Labels that exist, but nobody uses.
- Auditing without a review procedure.
12. Backups, recovery, and continuity: what is not always clear
In practice: Microsoft 365 has retention and recovery capabilities, but that does not always equal a complete backup strategy.
A very useful question during a provider change is: “if tomorrow someone deletes important information, who restores it, from where, and within what timeframe?”. The answer is not always documented.
12.1 What to review
- Which backup tools exist for Microsoft 365.
- What they cover: Exchange, OneDrive, SharePoint, Teams, Planner, etc.
- Where backups are stored.
- Who has access to restore.
- Backup frequency and expected recovery times.
- Real restore tests.
- Relationship between backup, retention, and compliance.
“When was the last time you restored a mailbox, a SharePoint document, or a Teams workspace in a real test?” If nobody knows, you do not have a validated strategy: you have an assumption.
13. Documentation the outgoing provider should deliver
In practice: a transition without documentation turns the new provider into a detective and the client into a hostage of missing knowledge.
A professional provider should facilitate an orderly exit. The company should request enough documentation so the new team can operate without relying on emergency calls.
Recommended minimum documentation
- Inventory of users, groups, and administrative roles.
- Existing partner relationships and delegated permissions.
- License summary and purchasing model.
- Configuration of domains and DNS related to Microsoft 365.
- Exchange Online: connectors, rules, shared mailboxes, and special flows.
- Teams: policies, critical teams, guests, and apps.
- SharePoint/OneDrive: critical sites, special permissions, and external sharing.
- Intune: profiles, compliance, applications, and Autopilot.
- Defender/Purview: policies, alerts, retention, and procedures.
- Backups, external tools, and integrations.
- Operational procedures: joins, leavers, changes, incidents, and escalations.
Request documentation before cutting access. After the cutover, everything costs more: more time, more tension, and a higher risk that something remains unexplained.
14. Transition plan: how to make the change without disrupting the business
In practice: the handover should be carried out in phases, with clear owners and without improvising critical permissions.
14.1 Before the change
- Inventory of access, licenses, and services.
- Identification of critical risks.
- Internal communication plan.
- Agreement on what the outgoing provider must deliver.
- Controlled onboarding of the new provider with the minimum required permissions.
14.2 During the change
- Validate that the new provider can operate without excessive permissions.
- Remove previous provider access at the agreed time.
- Monitor sign-ins, administrative changes, and alerts.
- Review email and critical services after the change.
14.3 After the change
- Final review of partner relationships and administrators.
- Report on closed and pending findings.
- Priority-based remediation plan.
- Review of licenses and costs.
- Operational documentation for the new support model.
Do you want an independent review before changing IT provider?
MSAdvance can carry out a Microsoft 365 audit focused on the handover: access, partners, roles, licenses, security, email, collaboration, devices, and compliance.
15. Practical checklists: before, during, and after
In practice: a checklist prevents the change from depending on memory, trust, or intuition.
15.1 Before changing provider
- Identify partner relationships and delegated permissions.
- List administrators and critical roles.
- Review previous provider accounts.
- Export license inventory.
- Document domains and DNS.
- Review Exchange connectors and rules.
- Review guests in Teams, SharePoint, and Entra ID.
- Confirm who manages devices in Intune.
- Request documentation from the outgoing provider.
15.2 During the handover
- Give access to the new provider with the minimum required roles.
- Remove or reduce access from the previous provider.
- Review sign-ins and administrative changes.
- Validate email, Teams, SharePoint, OneDrive, and Intune.
- Confirm the support channel for users.
15.3 After the change
- Verify that no old accounts remain active.
- Confirm that no unnecessary delegated permissions remain.
- Optimize licenses.
- Harden priority security controls.
- Document the new operation.
- Schedule a periodic Microsoft 365 review.
16. Common mistakes when changing IT provider
In practice: most problems do not appear on the day of the change, but weeks later, when someone tries to operate something nobody documented.
| Mistake | What can happen | How to avoid it |
|---|---|---|
| Not removing permissions from the previous provider | Risk of unauthorized access or uncontrolled changes | Review partner relationships, GDAP/DAP, and external accounts |
| Giving the new provider Global Administrator “for convenience” | Excessive privileges and a larger attack surface | Apply least privilege and specific roles |
| Not reviewing licenses | Recurring overspend or missing critical capabilities | License audit by profile and real usage |
| Ignoring email connectors and rules | Delivery failures, security bypasses, or improper forwarding | Complete Exchange Online review |
| Not reviewing guests | External users with access to old Teams, SharePoint sites, or documents | Recertification of guests and shared links |
| Not documenting operations | The new provider loses time investigating the environment | Formal documentation delivery and basic runbook |
17. Frequently asked questions (FAQ) about changing IT provider in Microsoft 365
What is the first thing I should review in Microsoft 365 when changing provider?
The first thing is access: partner relationships, GDAP/DAP, global administrators, accounts from the previous provider, service accounts, and applications with permissions. After that, it is advisable to review licenses, security, email, collaboration, and devices.
Can the previous provider still have access even if they no longer work with us?
Yes, this can happen if delegated permissions, partner relationships, or accounts created inside the tenant are not removed. That is why a technical review matters, not only contract closure.
What is the difference between GDAP and DAP?
GDAP allows more granular delegated permissions with a defined duration. DAP is a broader legacy model. When changing provider, both should be reviewed and only what is necessary should remain.
Can I change CSP without migrating the whole tenant?
In many cases, yes. Changing the license provider or CSP does not necessarily mean migrating email, files, or Teams. Even so, it is advisable to review licenses, access, and support to avoid interruptions.
Should I remove all administrators from the previous provider?
If the provider no longer delivers service, the normal approach is to remove its access. If there is still a transition phase, temporary and minimal permissions can be maintained, always documented and with a removal date.
Which licenses should be reviewed during the change?
All of them: Microsoft 365 Business, Enterprise, Defender, Intune, Teams Phone, Power BI, Visio, Project, Copilot, and add-ons. The goal is to verify whether they are used, correctly assigned, and aligned with each profile.
What happens if the previous provider does not deliver documentation?
A large part of the environment can be reconstructed from the admin portals, logs, and current configuration. Even so, it will take longer and should be done through a structured audit.
Can MSAdvance carry out an independent review even if another provider will manage support later?
Yes. MSAdvance can perform a one-off Microsoft 365 audit, deliver findings and recommendations, and leave documentation so the client or the new provider can operate more securely.
Does the Microsoft 365 review include security?
Yes. It reviews identities, MFA, Conditional Access, administrators, email, Defender, devices, guests, external sharing, auditing, and compliance, depending on the agreed scope.
18. Official resources and useful links
Official Microsoft documentation
- Manage partner relationships in Microsoft 365
- Terminate a GDAP relationship from the customer side
- GDAP FAQ
- Best practices for roles in Microsoft Entra
- Security Defaults in Microsoft Entra
- Plan Conditional Access
- Recommended settings for Defender for Office 365
- Data Loss Prevention in Microsoft Purview
MSAdvance services and resources
19. Conclusion and next steps
Changing IT provider is an opportunity to bring order to Microsoft 365. It is not only about changing who answers tickets: it is about confirming who has access, which licenses are being paid for, which security controls are active, and which configurations support the business.
A good Microsoft 365 review prevents three very common problems: hidden risk, unnecessary cost, and dependency on undocumented knowledge.
Recommended next steps
- Create an inventory of administrators, partners, and technical accounts.
- Review licenses and inactive users.
- Validate MFA, Conditional Access, and email security.
- Review guests, permissions, and shared links.
- Document the environment before removing the previous provider.
Do you want MSAdvance to review your Microsoft 365 before the provider change?
We can help you with a clear, prioritized, and actionable review: access, licenses, security, email, collaboration, devices, and compliance.
Request a Microsoft 365 review View Security & Compliance
· We can also help with Modern Workplace, licensing, and Microsoft 365 and Azure services.










