Picture this: you've finally decided to leave your MSP after months of slow response times and ballooning invoices. You sign with a new provider, schedule the Microsoft 365 tenant migration, and then — nothing. Your old provider stops responding to ticket requests. Your staff can't access their mailboxes. Sixty-plus gigabytes of email, calendars, and client records are sitting behind credentials you don't control, held by a company that has every incentive to stall.
This isn't a hypothetical. It's a pattern that plays out in IT forums regularly — medical offices locked out of patient communication channels, small businesses discovering their domain registrar login belongs to their departing MSP, and service distributors blocking license transfers over unpaid invoices that are themselves in dispute. The technical term is vendor lock-in. The operational reality is a hostage situation.
Why Email Is the Master Key to Everything
Before we get to the survival guide, it's worth understanding why your email data is so dangerous in the wrong hands — or inaccessible in the right ones.
According to Schneier on Security, the security of virtually every business account cascades from control of a single email address. Lose access to that inbox — whether to a bad actor or an uncooperative vendor — and you lose the recovery path for every SaaS tool, banking portal, and vendor account tied to it. Password resets, MFA backup codes, billing alerts: all of it routes through email.
That risk isn't theoretical. According to The Hacker News, a Russian espionage group recently exploited a Zimbra zero-day to exfiltrate 90 days of email, full organizational directories, browser-saved passwords, and two-factor authentication recovery codes. The attackers didn't need to break down the front door — they walked through the email platform. When a third party controls your Microsoft 365 tenant and you have no documented exit rights, your exposure profile looks uncomfortably similar.
And it's not just hostile nation-states you need to worry about. A Vatican prayer app recently exposed over 700,000 users' names, emails, locations, and account data through a porous API — a stark reminder that organizations often have no visibility into what a third-party vendor can access, or under what conditions, until a crisis forces the question. Small businesses handing full tenant control to an IT provider face the same blind spot at a smaller scale with equally devastating consequences.
Act One: The Crisis Scenario
Here's how the data hostage situation typically unfolds:
- You announce you're leaving. The MSP relationship sours immediately. Tickets go unanswered. "Transition support" evaporates.
- Credentials are withheld. Your Microsoft 365 Global Admin account is tied to the MSP's partner tenant. They own the top-level access. You don't.
- Licenses get frozen. If your licenses were provisioned through the MSP's distributor account (common with PAX8, Ingram, etc.), a billing dispute can freeze service transfers — even if your contract is current.
- Time pressure mounts. Every day without email access is lost revenue, compliance exposure, and eroding client trust.
We covered the downstream security risks of this exact scenario in our post on MSP transition security risks your old IT provider left behind — including the ghost admin accounts and lingering remote access tools that often survive the breakup.
Act Two: The Security Dimension
Vendor lock-in is usually framed as a contract problem. It's actually a security problem.
When your IT provider controls your Microsoft 365 tenant as a delegated admin — and you have no documented process for revoking that access — you have an unmonitored privileged account sitting in your environment indefinitely. If that MSP gets breached, your tenant is in scope. If a disgruntled employee at that MSP decides to cause problems, your data is the leverage.
This is why data sovereignty — knowing where your data lives, who can access it, and under what conditions — isn't just an offboarding concern. It's an ongoing security posture question. As we outlined in our Microsoft 365 breach prevention guide for small businesses, the tenant admin layer is where the highest-impact attacks land. Leaving that layer in a third party's hands without contractual exit rights is an active vulnerability.
Act Three: The Survival Checklist
Before You Sign Anything
- Demand a data portability clause. Your contract should explicitly state that all credentials, licenses, and data are returned within a defined window (5-10 business days is reasonable) upon termination.
- Own your own domain registrar account. Never let a provider register your domain in their name or their registrar account.
- Require a Global Admin account in your name from day one. You should have at least one Microsoft 365 Global Admin that the MSP does not control.
- Clarify license ownership. Ask whether your licenses are provisioned directly under your tenant or through the MSP's distributor account. If it's the latter, get the transfer process documented in writing.
- Get the offboarding SLA in the contract. What happens if they don't cooperate? What's the penalty?
If You're Already Locked In
- Contact Microsoft directly. If you own the domain, Microsoft has a domain verification process that can help you establish tenant ownership. Start at the Microsoft 365 Admin Center and document everything.
- File a support ticket with Microsoft Partner Support. If a partner is blocking a legitimate tenant transfer, Microsoft can intervene — but you need to escalate through official channels with documentation.
- Engage a third-party IT attorney. A cease-and-desist letter citing your contract terms often moves faster than any technical escalation.
- Document every communication. Timestamps, ticket numbers, email threads — you'll need these if this becomes a legal dispute or a regulatory matter (especially if you're in healthcare or handle government contracts).
- Check your cyber insurance policy. Some policies cover business interruption caused by vendor failures. This is also a good reason to have coverage in the first place — as we discussed in our post on Radar and cyber insurance.
After You're Out
- Immediately audit and revoke all delegated admin access from the previous provider.
- Rotate every credential the old provider could have touched.
- Review your Conditional Access policies — a departing MSP may have created exceptions or bypass rules you don't know about.
- Run a vulnerability scan to establish a clean baseline before your new provider inherits the environment.
The Bottom Line
Your IT provider is a trusted partner right up until they're not. The businesses that survive a hostile offboarding are the ones that treated data portability as a security requirement from the beginning — not an afterthought they negotiated in a panic at 11 PM when staff can't open their email.
Control of your Microsoft 365 tenant, your domain, and your license agreements isn't a technical detail to leave to your MSP. It's the foundation of your business continuity — and your security posture.
Take Action
If you're mid-transition or just starting to ask the right questions about your current IT setup, one of the fastest ways to understand your exposure is an external vulnerability scan. Attackers don't wait for your vendor dispute to resolve — they probe your perimeter regardless.
Oscar Six Security's Radar gives you an affordable, independent view of your attack surface for $99/scan — no MSP relationship required, no vendor access needed. It's the kind of clean-baseline assessment that tells you exactly what a new provider (or a bad actor) would see from the outside.
Focus Forward. We've Got Your Six.