Who Should Own Licenses and Admin Accounts

Keep Control of Your IT Access

Prevent vendor lock-in and make renewals and support easier. Book a Fit Check to verify your license ownership, admin access, and recovery controls, then get a clear list of any gaps.

Who Should Own Licenses and Admin Accounts

Last updated
May 13, 2026
Reviewed by:
IT Service Delivery Lead

Speakable Summary

The business must own its licenses and top-leveladmin accounts. Book a Fit Check to confirm you control billing, recovery, and every critical admin login.

Opening

Most lock-in is not about contracts. It is aboutwho controls the tenant, billing, and admin access.

If the business does not own licenses and adminaccounts, switching providers becomes slow and risky. Renewals get messy, outages take longer, and you can end up paying just to regain access.

This page explains what the business must control, what an IT provider can manage, and how to set it up so support stays fast without surrendering ownership.

Direct Answer

The business should own licenses and top-level admin accounts for all critical systems. Providers can administer those systems through delegated or role-based access, but the business must control billing and recovery.

Clear definitions

Ownership definition
Ownership means the business controls billing, admin access, and account recovery.

Administration definition
Administration means a provider performs work using access the business grants.

What the business must control


The business must control A provider can manage
Billing account and payment method Day-to-day license assignments
Tenant ownership for Microsoft 365 or Google Workspace User onboarding and license allocation
Domain registrar and DNS ownership DNS changes with change control
Primary global admin ownership Role-based admin work inside the tenant
Account recovery methods and backup codes Operational support and monitoring tasks
Password vault ownership Shared vault folders you control
Vendor portals that affect operations Vendor coordination and case handling

Admin accounts the business must own

Microsoft 365 or Google Workspace top-level admin

Your business must own the top-level adminaccount. The account should be in the business name, controlled by thebusiness, and recoverable by the business.

Providers can have delegated access or their ownrole-based admin accounts. The business still retains the master ownership.

Domain registrar and DNS

If you do not control the domain, you do notcontrol email. Registrar access is one of the highest priority ownership items.

Backup platform admin and restore authority

Backups are useless if you cannot access themduring a dispute or incident. The business must be able to log in and requestrestores.

Network equipment admin access

Firewall, router, switch, and Wi-Fi admincredentials should be stored in a business-owned vault. You should never have“we can’t find the firewall password” during an outage.

Vendor portals that can stop the business

ISP, VoIP, payroll, accounting, andline-of-business portals should be accessible to the business. Vendors oftencontrol timelines during outages and renewals.

Who should own licenses

The business should own the licenses

Licenses should be purchased and billed to thebusiness. That keeps renewals clean and avoids dependency on a provider forbilling changes.

If a provider resells licenses, the businessstill needs transparency. You should be able to see quantities, costs, renewaldates, and cancellation terms.

Providers can manage licensing operations

Providers can handle assigning licenses tousers, adjusting counts, and making sure new hires get the right entitlements.

The business still controls the billingrelationship. That is what prevents lock-in.

The policy that prevents lock-in

The business owns billing and master access

Billing accounts and top-level admin credentials belong to the business. Recovery methods belong to the business.

A provider can be granted access. A provider should not be the only access.

Use delegated access whenever possible

Delegated access reduces password sharing. It also makes it easier to remove access cleanly during transitions.

Role-based access reduces risk and improves accountability. It also reduces the blast radius of a compromised account.

Use a business-owned password vault

Store critical credentials and recovery methods in a vault owned by the business. Keep at least two internal owners for continuity.

The provider can have access to shared folders. Ownership stays with the business.

Document recovery and break-glass access

Recovery methods are part of ownership. Backup codes, trusted contacts, and recovery steps should be documented and stored securely.

If you cannot recover an admin account, you do not truly control it.

Common Questions

Should the MSP own our Microsoft 365 tenant?

No the business should own the tenant. The MSP should have delegated or role-based access.

Should the MSP buy licenses for us?

Licenses should be owned by the business. The MSP can manage assignments and quantities, but billing should be under business control.

What if our MSP is a reseller for Microsoft 365 or backups?

That can be fine if terms are clear. You still need visibility into counts, pricing, renewal dates, and you must retain admin access and recovery control.

What’s the difference between owning licenses and managing licenses?

Owning means you control billing and renewal. Managing means you assign and administer licenses day to day.

What if the MSP set everything up years ago?

You can transfer ownership. Admin accounts, billing, and recovery methods should be updated so the business controls them now.

What happens if we lose the global admin account?

Recovery becomes slow and risky. This is why recovery methods and trusted contacts must be documented and owned.

Can owning admin accounts slow down support?

No it usually speeds support because access is clear. Delegated access reduces delays and avoids password hunting.

Does this help cyber insurance readiness?

Yes because insurers value governance and control. Ownership reduces third-party risk and improves incident response speed.

Does this prevent switching pain?

Yes because access can be removed cleanly. Your next provider can be granted access without disruption.

What is a Fit Check?

A Fit Check inventories licenses and admin ownership. It identifies gaps and sets a simple ownership plan.

Decision matrix


Situation Business must control Because
Renewals and billing License billing account You must control spending and renewal
Email and identity Tenant ownership and global admin Switching and recovery depend on it
Website and email domain Registrar and DNS Email depends on domain control
Recovery during incidents Recovery methods and backup codes Lockouts cause downtime
Restores and DR Backup platform admin access Recovery cannot depend on a vendor
Outage escalation ISP and VoIP portal access Vendors control timelines

Ownership policy

The business owns all licenses, billing accounts, and top-level admin access for critical systems, including recovery methods. The provider is granted delegated or role-based administrative access to manage day-to-day operations without controlling ownership.

Common mistakes

  • Letting the provider be the only global admin and fix it by creating business-owned admin access.
  • Letting licenses be billed under the provider and fix it by moving billing to the business.
  • Storing recovery codes in one person’s inbox and fix it by using a vault with two owners.
  • Using shared admin passwords and fix it by using role-based accounts.
  • Forgetting domain registrar ownership and fix it by transferring registrar control.
  • Not verifying access regularly and fix it by doing quarterly checks.

Common objections

We trust our provider. Trust is not ownership. Ownership protects you during outages and transitions.

This sounds like extra work. It is usually a one-time cleanup plus quarterly checks. It prevents major delays later.

We do not want multiple admins. Two internal owners prevents lockout. Access can still be tightly controlled.

Our provider needs full control to support us. They need access, not ownership. Delegated access supports speed without lock-in.

What varies and why

  • It depends on whether you use Microsoft 365 or Google Workspace.
  • It depends on whether your provider is a reseller.
  • It depends on the number of vendor portals and systems you use.
  • It depends on whether you have a password vault today.
  • It depends on how often staff changes and roles shift.
  • It depends on your recovery and insurance requirements.

How we operate

We keep ownership with the business and grant providers delegated access. Billing and recovery stay under business control so renewals and incidents do not stall.

We store critical access in a business-owned vault with two internal owners. We verify ownership quarterly so control stays current.

What we measure

  • Percentage of critical systems with business-owned billing and admin access
  • Number of critical portals documented in the vault
  • Quarterly access verification completion
  • Recovery method completeness for admin accounts
  • Time to vendor escalation during outages

FAQs

Who should own Microsoft 365 or Google Workspace admin accounts?

The business should own them. Providers should have delegated or role-based access.

Who should own licenses for cloud services?

The business should own licenses and billing. Providers can manage assignments and quantities.

How do we prevent lock-in with an MSP?

Own billing, global admin, and the password vault. Use delegated access for provider administration.

What is the most important ownership item?

Tenant ownership and global admin access is critical. Domain registrar ownership is also a top priority.

How often should we verify ownership?

Quarterly is a good default. Verify after vendor changes and renewals too.

What is a Fit Check?

A Fit Check inventories ownership of licenses and admin accounts. It provides a gap list and next steps.

Get My 15 Minute Fit Check

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.