Nobody Told You That Your Old IT Company Kept the Keys

You own the business. But do you actually control your own technology?

Here's a scenario we've seen more times than we'd like: a business decides to part ways with their IT provider. Maybe the service declined. Maybe they found a better fit. Maybe the relationship just ran its course.

They send the breakup email. The old IT company says "understood, good luck." And then the business tries to move forward.

That's when the problems start.

The admin account for Microsoft 365? It's registered to the old IT company's email address. The DNS records for your website? Managed through a portal that's logged in under their account. Your domain registration? Same thing. Your firewall? Configured with credentials only they have. Your antivirus dashboard? Tied to their license.

You own all of this. It's your business, your data, your infrastructure. But you can't actually access any of it without your old IT provider's cooperation. And depending on how that breakup went, cooperation may or may not be forthcoming.

How this happens

It's usually not malicious. When an IT company sets up your environment, they use their own accounts, their own portals, and their own license pools because it's easier. They can manage all their clients from one dashboard. It's efficient for them.

The problem is that efficiency creates dependency. Your technology is woven into their systems. And unwinding it requires them to actively participate in the transition creating new admin accounts, transferring DNS control, handing over credentials, exporting configurations.

Some IT companies do this professionally. They recognize that the client owns the infrastructure and they facilitate a clean handoff. Others drag their feet. They take weeks to respond. They "forget" to hand over certain credentials. They make the transition so painful that the client considers just staying to avoid the hassle.

And a few a small but real minority essentially hold the infrastructure hostage. Not overtly. Just through inaction, delays, and the fact that they know you can't move forward without their cooperation.

What's at risk

This isn't a theoretical problem. If you can't access your own admin accounts, you can't add or remove users. You can't change security settings. You can't manage your own email. You can't update your website's DNS if you need to switch hosting providers.

If you can't access your firewall configuration, your new IT provider can't properly secure your network without a factory reset which means rebuilding everything from scratch.

If your domain registration is under your old provider's account and they don't transfer it, your business's web address is technically in someone else's control.

For a property management company or construction firm, where email downtime means missed tenant communications and lost project coordination, these aren't inconveniences. They're operational risks.

How to protect yourself starting now

Whether you're happy with your current IT provider or not, you should know the answers to these questions right now.

Who is the global admin on your Microsoft 365 or Google Workspace account? It should be someone at your company ideally the owner or a trusted manager not your IT provider. Your IT provider should have admin access, but you should have the top level account.

Where is your domain registered, and who controls the account? You should have login credentials to your domain registrar. If you don't know what that means, ask your IT provider to show you.

Where are your DNS records managed? Same principle. You should have access. Your IT provider can manage them day to day, but you should be able to log in independently.

What credentials would you need to hand a new IT provider if you switched today? If you can't answer this question, you have a dependency problem. And you should address it while your current relationship is still healthy, not during a breakup.

What we do differently

When we set up a client's environment, the client owns the admin accounts. Period. We have the access we need to do our job, but the top level credentials belong to the business. If they decide to leave for any reason they have everything they need to walk away cleanly.

We also maintain a master credential document that's shared with the client. It lists every account, every login, every admin portal, every license. Updated continuously. If we disappeared tomorrow, our clients could hand that document to any competent IT company and they'd have full access to everything within the hour.

That's not generosity. That's how it should work. Your IT provider is a partner, not a gatekeeper. And if your current provider has structured things so that leaving them feels impossible, that structure wasn't built for your benefit

Next
Next

The Worst Time to Find an IT Company Is When You Need One