Outsourcing Microsoft 365 administration should leave the business able to understand its accounts, recover its information, and change providers without losing control.

Keep business ownership visible

Record the tenant identifier, verified domains, billing relationships, license commitments, and business owner. Identify who controls domain registration and DNS, because those accounts can affect email and sign-in. Maintain the inventory in a business-approved location that remains accessible if the provider relationship ends. Administration can be delegated without making the provider the only party able to establish ownership.

Document privileged and emergency access

Ask for named administrative roles, approval rules, and a process for reviewing provider access. Microsoft publishes specific guidance for emergency access accounts in Entra ID. Have the administrator implement and test the appropriate design against that guidance; do not treat an untested password envelope as a recovery plan. Record who monitors emergency use and who reviews it afterward.

Define the recovery problem before selecting a product

List the workloads and scenarios you need to recover: an individual deletion, a damaged shared library, a departed employee’s information, or widespread unwanted changes. For each, record acceptable data loss, target restoration time, retention needs, and who validates the restored content. These requirements should drive a documented recovery design instead of a blanket assumption that cloud data is covered.

Verify current backup scope and limits

Microsoft offers a Microsoft 365 Backup service with documented capabilities. Review the current product documentation and any third-party proposal for supported workloads, retention, restore options, permissions, billing, and exclusions. Do not equate a productivity license, recycle bin, retention policy, or service resilience with your complete recovery requirement. Ask the MSP to demonstrate the selected recovery scenario safely.

Control license and configuration changes

Ask who approves license upgrades, security policy changes, guest access, and new integrations. Require a record of what changed and why. Separate service labor from software commitments so a change of provider does not unexpectedly alter the licensing term. Review inactive accounts with the business owner before removing anything that could have a retention or operational dependency.

Make departure and provider exit repeatable

For an employee departure, coordinate access termination, device handling, business data transfer, and retention decisions through authorized owners. For provider exit, verify replacement administration and recovery access before revoking the former team’s permissions. Reconcile integrations and service accounts afterward. Use a secure transfer mechanism for credentials and keep a record of the handover.

Sources and further reading

Primary references for the topics identified below. Examples, checklists, and purchasing recommendations are editorial guidance.

About this guidance

Published by Bay Area Managed IT. Examples are illustrative; they are not provider quotes, audited results, or local market survey findings. Read our editorial approach →

Continue the research

OPERATIONS GUIDEBuild a reliable employee onboarding and offboarding processTRANSITION GUIDEHow to switch managed service providers without losing controlRESILIENCE GUIDEBackup and disaster recovery questions to ask an MSP

Bring these questions to your next provider conversation.

Use a common scope and keep the evidence beside each answer.

Prepare your RFP →