Mission

IT Provider Won't Release Your Data? Do This

IT Provider Won't Release Your Data? Do This

Know what attackers see before they do. See a sample Radar scan report →

Picture this: you've finally decided to leave your MSP after months of slow response times and ballooning invoices. You sign with a new provider, schedule the Microsoft 365 tenant migration, and then — nothing. Your old provider stops responding to ticket requests. Your staff can't access their mailboxes. Sixty-plus gigabytes of email, calendars, and client records are sitting behind credentials you don't control, held by a company that has every incentive to stall.

This isn't a hypothetical. It's a pattern that plays out in IT forums regularly — medical offices locked out of patient communication channels, small businesses discovering their domain registrar login belongs to their departing MSP, and service distributors blocking license transfers over unpaid invoices that are themselves in dispute. The technical term is vendor lock-in. The operational reality is a hostage situation.

Why Email Is the Master Key to Everything

Before we get to the survival guide, it's worth understanding why your email data is so dangerous in the wrong hands — or inaccessible in the right ones.

According to Schneier on Security, the security of virtually every business account cascades from control of a single email address. Lose access to that inbox — whether to a bad actor or an uncooperative vendor — and you lose the recovery path for every SaaS tool, banking portal, and vendor account tied to it. Password resets, MFA backup codes, billing alerts: all of it routes through email.

That risk isn't theoretical. According to The Hacker News, a Russian espionage group recently exploited a Zimbra zero-day to exfiltrate 90 days of email, full organizational directories, browser-saved passwords, and two-factor authentication recovery codes. The attackers didn't need to break down the front door — they walked through the email platform. When a third party controls your Microsoft 365 tenant and you have no documented exit rights, your exposure profile looks uncomfortably similar.

And it's not just hostile nation-states you need to worry about. A Vatican prayer app recently exposed over 700,000 users' names, emails, locations, and account data through a porous API — a stark reminder that organizations often have no visibility into what a third-party vendor can access, or under what conditions, until a crisis forces the question. Small businesses handing full tenant control to an IT provider face the same blind spot at a smaller scale with equally devastating consequences.

Act One: The Crisis Scenario

Here's how the data hostage situation typically unfolds:

  1. You announce you're leaving. The MSP relationship sours immediately. Tickets go unanswered. "Transition support" evaporates.
  2. Credentials are withheld. Your Microsoft 365 Global Admin account is tied to the MSP's partner tenant. They own the top-level access. You don't.
  3. Licenses get frozen. If your licenses were provisioned through the MSP's distributor account (common with PAX8, Ingram, etc.), a billing dispute can freeze service transfers — even if your contract is current.
  4. Time pressure mounts. Every day without email access is lost revenue, compliance exposure, and eroding client trust.

We covered the downstream security risks of this exact scenario in our post on MSP transition security risks your old IT provider left behind — including the ghost admin accounts and lingering remote access tools that often survive the breakup.

Act Two: The Security Dimension

Vendor lock-in is usually framed as a contract problem. It's actually a security problem.

When your IT provider controls your Microsoft 365 tenant as a delegated admin — and you have no documented process for revoking that access — you have an unmonitored privileged account sitting in your environment indefinitely. If that MSP gets breached, your tenant is in scope. If a disgruntled employee at that MSP decides to cause problems, your data is the leverage.

This is why data sovereignty — knowing where your data lives, who can access it, and under what conditions — isn't just an offboarding concern. It's an ongoing security posture question. As we outlined in our Microsoft 365 breach prevention guide for small businesses, the tenant admin layer is where the highest-impact attacks land. Leaving that layer in a third party's hands without contractual exit rights is an active vulnerability.

Act Three: The Survival Checklist

Before You Sign Anything

  • Demand a data portability clause. Your contract should explicitly state that all credentials, licenses, and data are returned within a defined window (5-10 business days is reasonable) upon termination.
  • Own your own domain registrar account. Never let a provider register your domain in their name or their registrar account.
  • Require a Global Admin account in your name from day one. You should have at least one Microsoft 365 Global Admin that the MSP does not control.
  • Clarify license ownership. Ask whether your licenses are provisioned directly under your tenant or through the MSP's distributor account. If it's the latter, get the transfer process documented in writing.
  • Get the offboarding SLA in the contract. What happens if they don't cooperate? What's the penalty?

If You're Already Locked In

  • Contact Microsoft directly. If you own the domain, Microsoft has a domain verification process that can help you establish tenant ownership. Start at the Microsoft 365 Admin Center and document everything.
  • File a support ticket with Microsoft Partner Support. If a partner is blocking a legitimate tenant transfer, Microsoft can intervene — but you need to escalate through official channels with documentation.
  • Engage a third-party IT attorney. A cease-and-desist letter citing your contract terms often moves faster than any technical escalation.
  • Document every communication. Timestamps, ticket numbers, email threads — you'll need these if this becomes a legal dispute or a regulatory matter (especially if you're in healthcare or handle government contracts).
  • Check your cyber insurance policy. Some policies cover business interruption caused by vendor failures. This is also a good reason to have coverage in the first place — as we discussed in our post on Radar and cyber insurance.

After You're Out

  • Immediately audit and revoke all delegated admin access from the previous provider.
  • Rotate every credential the old provider could have touched.
  • Review your Conditional Access policies — a departing MSP may have created exceptions or bypass rules you don't know about.
  • Run a vulnerability scan to establish a clean baseline before your new provider inherits the environment.

The Bottom Line

Your IT provider is a trusted partner right up until they're not. The businesses that survive a hostile offboarding are the ones that treated data portability as a security requirement from the beginning — not an afterthought they negotiated in a panic at 11 PM when staff can't open their email.

Control of your Microsoft 365 tenant, your domain, and your license agreements isn't a technical detail to leave to your MSP. It's the foundation of your business continuity — and your security posture.


Take Action

If you're mid-transition or just starting to ask the right questions about your current IT setup, one of the fastest ways to understand your exposure is an external vulnerability scan. Attackers don't wait for your vendor dispute to resolve — they probe your perimeter regardless.

Oscar Six Security's Radar gives you an affordable, independent view of your attack surface for $99/scan — no MSP relationship required, no vendor access needed. It's the kind of clean-baseline assessment that tells you exactly what a new provider (or a bad actor) would see from the outside.

Focus Forward. We've Got Your Six.

Frequently Asked Questions

What can I do if my IT provider won't give me access to my Microsoft 365 tenant?

Start by contacting Microsoft support directly — if you own the domain, Microsoft has processes to help you establish or recover tenant ownership. Document every communication with your old provider and consider engaging an IT attorney to send a formal demand letter. If the provider is a Microsoft partner, you can escalate through Microsoft's partner support channel.

Can an MSP legally hold my data hostage over an unpaid invoice?

This is a gray area that depends on your contract terms and jurisdiction, but in most cases withholding access to your own business data — especially if it disrupts operations — creates significant legal exposure for the provider. A lawyer familiar with IT service contracts can send a cease-and-desist that often resolves the standoff faster than technical escalation. Always document the financial dispute separately from the data access issue.

What should I put in my IT provider contract to protect my data?

At minimum, require a data portability clause with a defined return window (5-10 business days after termination), confirm that domain registration and Microsoft 365 Global Admin credentials are held in your name, and get the offboarding process documented in writing. Also clarify whether your Microsoft 365 licenses are provisioned directly under your tenant or through the MSP's distributor account, since the latter can complicate transfers.

How much does a vulnerability scan cost for a small business?

Entry-level vulnerability scans for small businesses typically range from $99 to several hundred dollars depending on scope. Oscar Six Security's Radar product offers external attack surface scanning for $99 per scan — a practical option for establishing a clean baseline when switching IT providers or auditing your current exposure without needing MSP access.

Is vendor lock-in with an IT provider a security risk or just a contract problem?

It's both, but the security dimension is often underestimated. When an MSP holds Global Admin access to your Microsoft 365 tenant without documented exit rights, that's an unmonitored privileged account in your environment — if the MSP gets breached, your tenant is in scope. Treating data portability as a security requirement from the start, not just a contract clause, is the right frame.

Step-by-Step Guide

  1. Audit current admin access

    Log into your Microsoft 365 Admin Center and identify every Global Admin account and every delegated admin relationship tied to your MSP. Document who controls what before you begin any transition conversation.

  2. Verify domain ownership

    Confirm that your business domain is registered in your name at a registrar you control — not your MSP's account. If it isn't, initiate a domain transfer to your own registrar account before announcing you're leaving.

  3. Review your IT contract for exit terms

    Locate your current MSP agreement and identify any clauses covering data return, credential handover timelines, and license transfer procedures. If these terms are absent or vague, document that gap before negotiating your exit.

  4. Contact Microsoft support if access is blocked

    If your provider refuses to cooperate, open a support case with Microsoft directly. Provide proof of domain ownership and your business registration — Microsoft has escalation paths for tenant ownership disputes involving partners.

  5. Rotate all credentials post-transition

    After gaining full control of your tenant, immediately revoke all delegated admin access from the previous provider and rotate every credential they could have touched, including email accounts, service accounts, and any shared passwords stored in their systems.

  6. Run a baseline vulnerability scan

    Before your new provider takes over, run an external vulnerability scan to document your current attack surface. This protects you from inheriting unresolved issues and gives your new provider a clean starting point.

Find out what's exposed. Radar scans your external attack surface and shows you exactly what needs fixing. See a sample report →