Who Should Own Your Microsoft 365 Tenant, Domains and Backups?

A practical checklist for Australian businesses to verify ownership of the IT accounts and assets that keep your organisation running.

In brief: Your business — not your MSP — should be the legal owner of your Microsoft 365 tenant, domain names, backup data, and key supplier accounts. Delegating management to a provider is standard practice; delegating ownership creates risk. This guide helps you audit what you own, what you don't, and what to do about it.

Note: This guide is intended as general guidance. Verify current Microsoft licensing and administration requirements against Microsoft's official documentation. For legal matters relating to account ownership or contracts, seek independent legal advice.

1

Microsoft 365 Tenant Ownership

Your Microsoft 365 tenant is the container for your entire cloud identity — email, files, Teams, SharePoint, user accounts, licences, and security policies. Whoever holds the Global Admin credentials controls everything.

Why the Business Must Own the Tenant

  • If you change MSP, you need to be able to revoke the old provider's access and grant access to the new one — without losing your data, email, or user accounts.
  • If the MSP ceases trading, your tenant and data must remain accessible to your business.
  • Microsoft recommends the organisation hold at least two Global Admin accounts to prevent lockout. These should be controlled by the business, not exclusively by a third party.
  • Your Microsoft 365 tenant is tied to your business's identity (Entra ID / Azure AD). Losing control means losing control of your identity platform.

How to Check Current Ownership

  1. 1 Sign in to admin.microsoft.com with your business credentials. If you cannot sign in, that is your first red flag.
  2. 2 Navigate to Users → Active users and filter by Admin roles. Identify who holds Global Admin. If only MSP staff accounts appear, the business does not hold admin control.
  3. 3 Check Billing → Your products to confirm licences are billed to the business. If the MSP resells licences via a CSP (Cloud Solution Provider) arrangement, confirm you understand the terms — particularly what happens if the relationship ends.
  4. 4 Check Settings → Partner relationships to see which partners have delegated admin access to your tenant.

Delegated Admin vs. Global Admin

Modern best practice is for MSPs to use Granular Delegated Admin Privileges (GDAP) — this gives the MSP specific, time-limited admin roles without requiring Global Admin credentials. If your MSP still uses the older Delegated Admin Privileges (DAP) model, ask them about migrating to GDAP. Microsoft has been transitioning partners away from DAP since 2023.

2

Domain Registrar Accounts

Your domain name is your identity online. If someone else is the registrant, they legally control the domain — even if you've been paying for it and using it for years.

How to Check Domain Ownership

Step-by-Step

  1. 1
    Run a WHOIS lookup — for .com.au domains, use whois.com.au. For international domains, use lookup.icann.org.
  2. 2 Check the Registrant Name — this should be your business entity (e.g. your company name or ABN-registered trading name). If it shows your MSP's name, a web developer's name, or an individual's name, you do not own the domain.
  3. 3 Check the Registrar — note which registrar the domain is registered with (e.g. VentraIP, Crazy Domains, GoDaddy, Cloudflare). Confirm you have login credentials for this registrar account.
  4. 4 Check the expiry date — ensure auto-renewal is enabled and billing details are current. Domain lapses can result in someone else registering your domain.

Warning Signs

  • The WHOIS registrant is your MSP or IT provider's business name
  • You do not have login credentials for the registrar account
  • The registrant is an individual (e.g. a former employee or a freelance web developer)
  • You don't know when the domain expires or who is paying for renewal

Note for .com.au domains: The .au Domain Administration (auDA) requires that the registrant of a .com.au domain must be an Australian entity with a valid ABN/ACN. If your MSP registered the domain under their own ABN, they are the legal registrant. A registrant transfer (change of registrant) may be required to move it to your business.

3

DNS Management vs. Domain Ownership

This is a common source of confusion. DNS management and domain ownership are two separate things. Understanding the difference is essential when evaluating your IT asset ownership.

DNS Delegation (Standard Practice)

  • You remain the domain registrant (owner)
  • You point your nameservers to the MSP's DNS platform
  • The MSP can create and manage DNS records (MX, A, CNAME, TXT, etc.)
  • You can redirect nameservers back at any time — no permission required from the MSP
  • This is normal and widely used — similar to pointing your domain to Cloudflare or another DNS provider

Domain Ownership Transfer (Caution)

  • The MSP becomes the registrant (legal owner) of the domain
  • The MSP controls renewal, transfer, and DNS settings
  • You cannot redirect nameservers without the MSP's cooperation
  • If the relationship ends badly, recovering the domain can be difficult and slow
  • There is rarely a legitimate reason for an MSP to be the registrant of your business domain

Key takeaway

It is perfectly fine for your MSP to manage your DNS records — that's delegation, and it's standard practice. What's not fine is your MSP being the registrant (owner) of your domain. You should always be able to log in to the registrar, see your domain, and change nameservers if you need to.

4

Backup Ownership and Data Sovereignty

Microsoft 365 does not provide comprehensive backup by default. Most businesses rely on a third-party backup solution (often managed by their MSP) for Exchange Online, SharePoint, OneDrive, and Teams data. The question is: who owns and controls that backup data?

Questions to Ask About Your Backups

Who controls the backup platform account?

If the backup solution (e.g. Veeam, Datto, AvePoint, Acronis) is set up under the MSP's master account, you may have no independent access. Ask whether your organisation has its own login to the backup portal.

Where is the backup data stored?

Understand which data centre or cloud region stores your backup data. For many Australian businesses — particularly those in healthcare, legal, financial services, or government — data sovereignty is a consideration. Confirm whether data remains within Australia.

Can you access and restore independently?

In a well-structured arrangement, you should be able to log into the backup portal, view protected data, and initiate restores without waiting for the MSP. If you cannot, you are entirely dependent on the MSP for data recovery — including during a dispute.

Can you export your data?

If you switch MSPs, can you export the backup archive? Or does the data remain locked in the old provider's platform? Understand the data portability terms before you need them.

What is the retention period?

Confirm how long backup data is retained. Some solutions default to short retention periods (e.g. 30 or 90 days). Depending on your industry and compliance obligations, you may need longer retention — sometimes years.

Data Sovereignty for Australian Businesses

While not all Australian businesses are legally required to store data onshore, many industries have regulatory or contractual requirements around data residency. The Australian Privacy Act 1988 and the Notifiable Data Breaches scheme apply to organisations with an annual turnover of more than $3 million (with some exceptions). If your backup data is stored overseas, understand which country's laws apply and how that may affect your obligations under Australian privacy law.

Microsoft's Native Retention vs. Third-Party Backup

Microsoft 365 includes some retention and recovery features (e.g. deleted item recovery, litigation hold, retention policies), but these are not the same as a backup. Microsoft's own Shared Responsibility Model makes clear that Microsoft is responsible for infrastructure availability, while the customer (or their MSP) is responsible for data protection. A third-party backup solution provides point-in-time recovery, longer retention, and protection against accidental or malicious deletion that goes beyond what Microsoft provides natively.

5

Other Supplier Accounts

Beyond Microsoft 365, domains, and backups, there are typically several other accounts and services that your business should verify ownership of.

ISP / Internet Account

Your internet service should be contracted in the business's name. Confirm you have the account number, login credentials, and can make changes to the service directly.

Risk if MSP-owned: Difficulty changing providers or addresses; potential service disruption during MSP transitions.

Firewall / Security Appliances

Firewalls, UTM devices, and security appliances often have web-based management portals and vendor cloud dashboards. Confirm the business holds admin credentials — not just the MSP.

Risk if MSP-owned: You cannot grant a new MSP access, reconfigure rules, or respond to a security incident independently.

Cloud Subscriptions

Azure, AWS, Google Cloud, or other cloud subscriptions should be in the business's name. Confirm billing ownership and admin-level access to the management console.

Risk if MSP-owned: Data and workloads may be inside the MSP's subscription, making migration complex and dependent on their cooperation.

SSL/TLS Certificates

SSL certificates for your website and services should be purchased under an account the business controls. Understand where they are managed and when they expire.

Risk if MSP-owned: Certificate expiry or renewal issues can take down your website or cause browser security warnings.

VoIP / Phone System

Cloud phone systems (e.g. Microsoft Teams Phone, 3CX, 8x8, RingCentral) should be in the business's name with admin access available to the business.

Risk if MSP-owned: You may lose phone numbers or call routing during a provider transition.

Endpoint Protection / Antivirus

Endpoint security platforms (e.g. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint) have management consoles. Confirm whether the business has owner-level access.

Risk if MSP-owned: A new MSP may be unable to manage or transition endpoint protection without the old MSP's cooperation.

Ownership Audit Checklist

Work through this checklist to audit the ownership status of your critical IT assets. Print it, share it with your team, or use it as a starting point for a conversation with your current MSP.

Microsoft 365 Tenant

  • Confirmed which Microsoft 365 tenant your organisation uses (check the tenant ID in the Azure AD / Entra ID portal)
  • Verified the tenant was created under the business's name — not the MSP's
  • Business holds at least two Global Admin accounts with credentials known to authorised business personnel
  • MSP access is provided via delegated admin privileges (GDAP) or a separate named admin account — not by sharing the business's Global Admin credentials
  • Multi-factor authentication (MFA) is enabled on all admin accounts
  • Emergency access ('break glass') account exists with credentials stored securely (e.g. sealed envelope in a safe, or a password manager controlled by the business)
  • Licensing subscriptions are billed to the business — either directly from Microsoft or via a CSP arrangement where the business understands the terms
  • You can log in to admin.microsoft.com independently and see your users, licences, and billing

Domain Names

  • Performed a WHOIS lookup on every domain the business uses (including .com.au, .com, .net.au, etc.)
  • Confirmed the registrant for each domain is the business entity — not the MSP, web developer, or an individual
  • Confirmed you have login credentials for the domain registrar account (e.g. VentraIP, Crazy Domains, GoDaddy, Cloudflare)
  • Checked domain expiry dates — domains are set to auto-renew and billing details are current
  • Verified domain lock (registrar lock) is enabled to prevent unauthorised transfers
  • If the MSP manages DNS, confirmed this is via nameserver delegation — not because they are the domain registrant
  • You have a documented list of all domains owned by the business

DNS Management

  • Identified where DNS is hosted (the registrar, a third-party DNS provider, or the MSP's platform)
  • Confirmed you can access and view current DNS records independently
  • Documented all critical DNS records (MX, SPF, DKIM, DMARC, CNAME, A records) in a format stored outside the DNS platform
  • If DNS is delegated to the MSP, confirmed you can redirect nameservers back to the registrar if needed
  • Understood that changing nameservers away from the MSP will affect all DNS records — have a migration plan documented

Backup and Data Protection

  • Identified what backup solution is in use for Microsoft 365 data (e.g. Veeam, Datto, AvePoint, Acronis, or similar)
  • Confirmed whether the backup platform account is owned by the business or by the MSP
  • Verified you have independent portal access to the backup platform (not dependent on the MSP logging in for you)
  • Confirmed where backup data is physically stored — and whether it remains within Australia if that is a business requirement
  • Checked whether you can initiate data restores independently
  • Confirmed you can export backup data in a standard format if you change providers
  • Reviewed the backup retention period and confirmed it meets your business and compliance requirements
  • Confirmed what data is being backed up — Exchange Online, SharePoint, OneDrive, Teams (including chat data) — and what is not

Other Supplier and Service Accounts

  • ISP account: confirmed the account is in the business's name with login credentials available
  • Firewall / security appliance: confirmed admin credentials are held by the business (not only by the MSP)
  • Antivirus / endpoint protection portal: confirmed the business has owner or admin-level access
  • Cloud subscriptions (Azure, AWS, Google Cloud): confirmed the subscription is in the business's name
  • SSL/TLS certificates: confirmed who purchased them and whether they are tied to a specific account
  • VoIP / phone system portal: confirmed the business has admin access
  • Website hosting: confirmed the hosting account is in the business's name
  • Password manager / IT documentation platform: confirmed the business owns the account or has export access

What to Do If Your MSP Currently Owns These Assets

If you've worked through the checklist above and discovered that your MSP is the owner of accounts that should belong to your business, don't panic. In many cases, this isn't malicious — it may have happened by convenience when the MSP originally set up your environment. Here's how to approach the conversation.

Step-by-Step Approach

  1. 1

    Document the current state

    Before initiating any changes, document exactly which accounts and assets are in question — who the current owner is, what credentials you do and don't have, and what data or services are affected.

  2. 2

    Request a full asset inventory from your MSP

    Ask your MSP to provide a complete list of all accounts, subscriptions, licences, and services they manage on your behalf — along with who is the account holder or registrant for each. A good MSP will be transparent about this.

  3. 3

    Approach the conversation professionally

    Frame this as good governance, not an accusation. Something like: "As part of our business continuity planning, we're auditing ownership of all IT assets. We'd like to ensure accounts are in the business's name — can you help us with that?" Most MSPs will cooperate willingly.

  4. 4

    Work through transfers systematically

    Transfer ownership one account at a time, verifying access works correctly before moving to the next. For critical services like Microsoft 365, plan transfers during low-activity periods and confirm everything functions before revoking old credentials.

  5. 5

    Secure new credentials properly

    Once accounts are transferred, store credentials securely. Use a business password manager, enable MFA on all accounts, and ensure at least two authorised people in the business know how to access critical accounts.

  6. 6

    Update your contracts going forward

    Once ownership is resolved, ensure your MSP contract clearly states that the business retains ownership of all accounts, data, domains, and licences — and that the MSP will facilitate transfer of all assets upon termination of the agreement.

If Your MSP Is Uncooperative

If your MSP refuses to transfer ownership of accounts or assets that your business pays for and uses, seek legal advice. In most cases, the business that pays for a service is entitled to ownership of the associated accounts and data. For domain disputes, .au domain matters can be escalated through auDA or through the .au Dispute Resolution Policy. For Microsoft 365 tenant disputes, Microsoft's support can sometimes assist where the business can demonstrate it is the legitimate tenant owner — but this is not guaranteed and can be a slow process.

What Good Looks Like

A trustworthy MSP will proactively ensure your business owns all accounts and assets from day one. They'll use delegated access (like GDAP for Microsoft 365) rather than holding your Global Admin credentials. They'll register domains in your name, give you portal access to backup platforms, and maintain documentation you can access independently. If your MSP already does this, that's a strong signal you're in good hands.

Expert Review Note

This guide is intended as general guidance for Australian businesses evaluating ownership and control of their IT assets. It does not constitute legal, financial, or professional IT advice. Verify current Microsoft licensing, administration requirements, and best practices against Microsoft's official documentation. For matters relating to domain registration and disputes, refer to auDA (for .au domains) or your registrar's policies. For data sovereignty and privacy obligations, consult the Office of the Australian Information Commissioner (OAIC).

Need Help Auditing Your IT Asset Ownership?

If you're unsure about the ownership status of your Microsoft 365 tenant, domains, or other IT assets, a qualified managed IT provider can help you audit and, if necessary, reclaim control. Use our free comparison tool to find MSPs in your area who can assist.

Compare Managed IT Providers