← All Blogs

Could You Leave Your IT Provider If You Had To?

Exit readiness is not a plan to leave your IT provider. It is a test of whether you could. Your provider may own the licences, the domain and the only copy of your documentation, and no law requires most of it back. Seven checks establish where you stand.

A transfer request blocked by an approval gate it cannot pass on its own
A transfer request blocked by an approval gate it cannot pass on its own
Key takeaways
  • Microsoft states that customers don't initiate a CSP licence transfer.
  • A partner is under no obligation to approve one, and disputes are not mediated.
  • The registrant is now the only party who can approve a domain transfer.
  • No law requires your provider to return diagrams, runbooks or credentials.
  • California, unlike four other states, sets no end-of-contract deletion duty.

Why test an exit you are not planning?

Test it because a dependency you have never measured is a dependency you cannot manage. Nothing here assumes you want to leave your IT provider. The point is narrower and more useful: if leaving would be slow, expensive or impossible, that fact is shaping the relationship right now, whether or not anyone has said so out loud.

A transfer request blocked by an approval gate it cannot pass on its own
A transfer request blocked by an approval gate it cannot pass on its own

Regulators already treat this as a test rather than a document. DORA requires that exit plans be comprehensive, documented, sufficiently tested and reviewed periodically, and that financial entities be able to exit without disruption to business activities. The phrase worth borrowing is <strong>sufficiently tested</strong>. A plan nobody has exercised is a belief, not a plan.

Most businesses are not banks and no regulator will ask them for this. The mechanics are identical anyway, and so is the failure mode: the answer arrives on the day it is most expensive to be wrong.

One correction worth making early, because it shapes what follows. CISA's guidance for MSP customers does mention a transition plan, twice, and both times it means integrating a provider you are hiring. There is no exit section. What CISA does say is more practical anyway: maintain your own offsite backups of essential records and network activity logs, because backups and logs also let you authenticate vendor activity. Those two artefacts are what make leaving possible.

Who actually controls your Microsoft 365 licences?

Your provider does, if it bought them for you through the Cloud Solution Provider programme. This is the single most surprising thing most businesses discover during an exit test, and Microsoft states it plainly in its own documentation rather than leaving it to be inferred.

The mechanics: partner transfers can only occur if both the source and target partner approve it, and customers don't initiate the transfer process. Read that twice. The business paying for the licences is not a party to the transaction that moves them.

It gets more direct. Microsoft writes that partners are under no obligation to approve or send transfer requests, and that Microsoft will not override a CSP subscription transfer without the source partner's approval, and disputes between partners are not mediated. There is no escalation path. If nothing happens, the request expires after 30 days.

If your provider is an indirect reseller, add a layer. Indirect resellers need their indirect provider, the billing owner of the subscription, to send or approve a transfer request. The approval you need then sits with a distributor you have never spoken to and hold no contract with.

None of this is misconduct by anyone. It is a design decision about who the customer of record is, and it is worth knowing which side of it you are on before you need to move.

What can you take back without anyone's permission?

Take back administrative access, immediately and unilaterally. That part is genuinely yours. A customer can see which partners have granular delegated admin privileges and remove a partner's GDAP from their tenant, after which those users no longer have access to administer services.

Two levers, one you control and one your provider controls
Two levers, one you control and one your provider controls

Do not mistake that for ending the relationship. Microsoft is explicit that removing a partner's admin roles does not remove the partner relationship, and a customer who no longer wants to work with a partner must contact that partner to end it. Access and billing are separate levers, and you hold only one of them.

The contrast with the same class of product elsewhere is stark. On Google Workspace, a super administrator generates a transfer authorization to move a subscription to Google or to a named reseller, and transfers don't affect data or availability. No incumbent approval step exists. Two vendors, one product category, opposite answers to who holds the key, which makes this a commercial design choice rather than a technical necessity.

Google's version has its own edges worth knowing: transfers are nonreversible and cannot be made to resellers more than twice in a calendar year. Knowing the constraint beforehand is the entire point of testing.

Who is listed as the registrant on your domain?

Check the registrant field today, because if it names your provider rather than your business, you have no standing at all. ICANN's current Transfer Policy is unambiguous: the Registered Name Holder is the only party that has the authority to approve or deny a transfer request to the gaining registrar. Not weaker standing. None.

This changed. The older policy also let the administrative contact approve a transfer, and plenty of guidance still online reflects that. The operative rule since 2024 concentrates the authority in the registrant alone, so the field that used to be a formality is now the whole question.

If your business is the registrant, you are in good shape and the rules protect you. A registrar must not refuse to release an AuthInfo code or remove ClientTransferProhibited solely because of a payment dispute, and it must supply that code within five calendar days of your request where it offers no self-service route.

If your provider is the registrant, you need a Change of Registrant, which requires confirmation from both parties and then triggers a lock. A registrar must impose a 60-day inter-registrar transfer lock following a Change of Registrant unless the holder opted out beforehand. ICANN's own advice is to move registrar first and change registrant second, which avoids the lock entirely and is the kind of ordering nobody discovers under pressure.

What data are you legally entitled to get back?

Less than most people assume, and what you get depends entirely on which rule reaches your data. There is no single law that says your IT provider must hand everything back.

Under HIPAA the duty exists but carries an escape hatch. At termination a business associate must, if feasible, return or destroy all protected health information and retain no copies, or if that is not feasible extend the contract's protections and limit further use. <strong>If feasible</strong> is doing real work in that sentence, and the fallback lets a provider keep the data indefinitely.

There is a sharper trap underneath. The duty lives in the Privacy Rule. The Security Rule's separate requirements for business associate contracts list only compliance with the subpart, subcontractor flow-down and security incident reporting, with no duty to return or destroy data. An agreement drafted against the security provisions alone simply does not contain it.

The GDPR wording is what a strong clause looks like. A processor must, at the choice of the controller, delete or return all the personal data after the end of the provision of services and delete existing copies unless law requires storage. The controller chooses, and copies are named. Ask for backups specifically, because the ICO accepts that data in backups may not be deleted immediately provided it is put beyond use and deleted on the next destruction cycle.

Four state privacy laws require return or deletion at contract end and one does not
Four state privacy laws require return or deletion at contract end and one does not

US state law splits, and the split is counterintuitive. Virginia requires a processor to delete or return all personal data at the controller's direction at the end of the provision of services, and Texas requires the same after the provision of the service is completed. Colorado and Connecticut match them. California, the state everyone names first, is the outlier: its required service provider contract terms contain no end-of-contract obligation to return or delete personal information.

Why is none of your documentation covered?

None of it is covered because every duty above is about personal data, and your documentation is not personal data. This is the most useful finding in this article and it is a negative one.

Documentation sitting outside the boundary that data protection law draws
Documentation sitting outside the boundary that data protection law draws

Network diagrams, asset inventories, licence records, firewall configurations, runbooks, monitoring configuration and administrative credentials are reached by none of HIPAA, the GDPR, the FTC Safeguards Rule or the state privacy statutes. Whether you get them back is decided by your contract and nothing else.

The Safeguards Rule illustrates the gap precisely. It requires a financial institution to securely dispose of customer information no later than two years after its last use, and reaches service providers only by requiring safeguards through contract. The obligation lands on you. Your provider is bound only to the extent you wrote it down.

Even HIPAA's own drafters treat handover as optional. HHS notes that an agreement could also provide for the business associate to transmit protected health information to another business associate at termination, which is a standard-setter flagging that provider-to-provider transfer is something you must add yourself.

Australia's ISM is the clearest statement of the fix. It requires that data be stored in a portable manner enabling backups, service migration and service decommissioning without any loss of data, documented in contractual arrangements, and separately that types of data and its ownership are documented. Ownership, written down, before it matters.

What do regulators consider reasonable exit terms?

Reasonable terms have actually been written down, in the EU Data Act, and they make a useful yardstick even where they do not bind your provider. The Act sets a mandatory maximum transitional period of 30 calendar days for switching, a maximum notice period of two months to initiate it, and a minimum data retrieval period of at least 30 calendar days afterwards. It also obliges providers to support the customer's exit strategy, including by providing all relevant information, and bars switching charges entirely from 12 January 2027.

Be precise about scope. The Data Act defines a data processing service in cloud-computing terms, so it binds cloud providers rather than a local managed IT firm. It does not give a US or UK business a legal right to exit its MSP. What it gives you is a benchmark written by a legislature instead of by a vendor, and any contract can be measured against it.

Other authorities converge on the same shape. Australia's ISM requires a minimum notification period of one month for the cessation of any services by a service provider. NIST advises establishing negotiated agreements for relationship termination to ensure a safe and secure termination, such as removing data from cloud environments. DORA requires the transition period be contractual for critical functions.

Treat published switching timelines with suspicion. The commonly repeated 30 to 60 day figure has no study, survey or sample behind it that we could find, and every source quoting it sells the migration it is describing. The numbers above are worth more precisely because the bodies that set them are not selling the service.

What should you check this quarter?

Check the seven items below, and check them while nothing is wrong. Each one resolves to a fact you either have or do not have, so the test takes an afternoon rather than a project.

The seven checks in an exit readiness test
The seven checks in an exit readiness test

The UK NCSC reduces this to one sentence for small organisations, advising you to be clear that contract duration works with your business objectives and gives flexibility if your organisation changes direction or you are unhappy with service quality. That is sound, and it is also the entire exit section of a national cyber authority's guidance, which tells you how little settled advice exists here.

Keep the proportion right. A provider that holds your tenant, your domain and your only copy of the documentation is not necessarily behaving badly. It is simply a provider you cannot leave, and that is worth knowing while you are still happy with it.

A tenant moving through four lifecycle stages toward deletion
A tenant moving through four lifecycle stages toward deletion

One last thing to know before any cancellation. A Microsoft 365 subscription normally moves through Active, Expired, Disabled and Deleted, which for most offers is 30 days then 90 days, and data left behind might be deleted after 90 days and will be deleted no later than 180 days. But an explicit deletion skips those statuses and SharePoint Online content, including OneDrive, is immediately deleted. Note also that CSP-purchased subscriptions follow a separate lifecycle, so the grace period you are counting on may not be the one that applies.

FAQ

Does GDPR give my business a right to data portability from my IT provider?

No. Article 20's portability right belongs to a data subject, meaning an individual, and applies to personal data that person provided to a controller. A business leaving its IT provider is a controller dealing with a processor, so it cannot invoke Article 20. The relevant provision is Article 28(3)(g), which requires the contract to say that the processor will, at the controller's choice, delete or return all the personal data after the end of the provision of services. Marketing copy conflates the two routinely.

Can my IT provider refuse to release my domain name over an unpaid invoice?

A registrar cannot, and that matters more than what your provider prefers. ICANN's Transfer Policy states that a registrar must not refuse to remove ClientTransferProhibited or release an AuthInfo code to the Registered Name Holder solely because of a payment dispute, and that transfers may not be denied for nonpayment of a pending or future registration period. The catch is that all of this protects the Registered Name Holder. If your provider is listed as the registrant rather than your business, you are not the party those rules protect.

Who owns the Microsoft 365 licences my provider bought for us?

Billing ownership sits with the partner if they were bought through the Cloud Solution Provider programme. Microsoft documents that customers don't initiate the transfer process, that both the source and target partner must approve, that partners are under no obligation to approve or send transfer requests, and that Microsoft will not override a transfer without the source partner's approval and does not mediate disputes between partners. You can always remove a partner's delegated admin access yourself, but that is separate from moving the subscription.

Is my provider legally required to hand back our network documentation?

No law we found requires it. HIPAA, the GDPR and the UK GDPR, the FTC Safeguards Rule and the US state privacy statutes all create duties about personal data or customer information. Network diagrams, asset inventories, licence records, firewall configurations, runbooks and credentials fall outside every one of them. Whether you receive that material at the end of a contract depends entirely on what your agreement says, which is why the check is a contract review rather than a legal question.

How long does switching IT providers actually take?

No independent figure exists that we could verify. The widely quoted 30 to 60 day range traces only to firms that sell migration services, with no study, survey instrument or sample size behind it. The defensible numbers come from bodies not selling the work: the EU Data Act sets a maximum two-month notice period, a mandatory maximum 30-day transition and a minimum 30-day retrieval window afterwards, and Australia's Information Security Manual requires a minimum one-month notification period for cessation of services.

Does removing our provider's admin access end the relationship?

No. Microsoft states that removing a partner's admin roles does not remove the partner relationship, and that a customer who no longer wants to work with a partner must contact that partner to end it. The two levers are separate: you can withdraw administrative access to your tenant immediately and unilaterally, while billing ownership of subscriptions bought through the partner still requires that partner to act.

Sources

Compare managed IT providers in your city

Best IT MSP is an independent directory of managed IT providers across the US and Canada. We rank on verified rating and firmographic data, we label paid placement, and we do not sell IT services.

Browse Vetted Providers

← All Blogs