Who Should Own Licenses and Admin Accounts
Keep Control of Your IT Access
Prevent vendor lock-in and make renewals and support easier. Book a Fit Check to verify your license ownership, admin access, and recovery controls, then get a clear list of any gaps.
Who Should Own Licenses and Admin Accounts
Last updated
May 13, 2026
Reviewed by:
IT Service Delivery Lead
Speakable Summary
The business must own its licenses and top-leveladmin accounts. Book a Fit Check to confirm you control billing, recovery, and every critical admin login.
Opening
Most lock-in is not about contracts. It is aboutwho controls the tenant, billing, and admin access.
If the business does not own licenses and adminaccounts, switching providers becomes slow and risky. Renewals get messy, outages take longer, and you can end up paying just to regain access.
This page explains what the business must control, what an IT provider can manage, and how to set it up so support stays fast without surrendering ownership.
Direct Answer
The business should own licenses and top-level admin accounts for all critical systems. Providers can administer those systems through delegated or role-based access, but the business must control billing and recovery.
Clear definitions
Ownership definition
Ownership means the business controls billing, admin access, and account recovery.
Administration definition
Administration means a provider performs work using access the business grants.
What the business must control
Admin accounts the business must own
Microsoft 365 or Google Workspace top-level admin
Your business must own the top-level adminaccount. The account should be in the business name, controlled by thebusiness, and recoverable by the business.
Providers can have delegated access or their ownrole-based admin accounts. The business still retains the master ownership.
Domain registrar and DNS
If you do not control the domain, you do notcontrol email. Registrar access is one of the highest priority ownership items.
Backup platform admin and restore authority
Backups are useless if you cannot access themduring a dispute or incident. The business must be able to log in and requestrestores.
Network equipment admin access
Firewall, router, switch, and Wi-Fi admincredentials should be stored in a business-owned vault. You should never have“we can’t find the firewall password” during an outage.
Vendor portals that can stop the business
ISP, VoIP, payroll, accounting, andline-of-business portals should be accessible to the business. Vendors oftencontrol timelines during outages and renewals.
Who should own licenses
The business should own the licenses
Licenses should be purchased and billed to thebusiness. That keeps renewals clean and avoids dependency on a provider forbilling changes.
If a provider resells licenses, the businessstill needs transparency. You should be able to see quantities, costs, renewaldates, and cancellation terms.
Providers can manage licensing operations
Providers can handle assigning licenses tousers, adjusting counts, and making sure new hires get the right entitlements.
The business still controls the billingrelationship. That is what prevents lock-in.
The policy that prevents lock-in
The business owns billing and master access
Billing accounts and top-level admin credentials belong to the business. Recovery methods belong to the business.
A provider can be granted access. A provider should not be the only access.
Use delegated access whenever possible
Delegated access reduces password sharing. It also makes it easier to remove access cleanly during transitions.
Role-based access reduces risk and improves accountability. It also reduces the blast radius of a compromised account.
Use a business-owned password vault
Store critical credentials and recovery methods in a vault owned by the business. Keep at least two internal owners for continuity.
The provider can have access to shared folders. Ownership stays with the business.
Document recovery and break-glass access
Recovery methods are part of ownership. Backup codes, trusted contacts, and recovery steps should be documented and stored securely.
If you cannot recover an admin account, you do not truly control it.
Common Questions
Should the MSP own our Microsoft 365 tenant?
No the business should own the tenant. The MSP should have delegated or role-based access.
Should the MSP buy licenses for us?
Licenses should be owned by the business. The MSP can manage assignments and quantities, but billing should be under business control.
What if our MSP is a reseller for Microsoft 365 or backups?
That can be fine if terms are clear. You still need visibility into counts, pricing, renewal dates, and you must retain admin access and recovery control.
What’s the difference between owning licenses and managing licenses?
Owning means you control billing and renewal. Managing means you assign and administer licenses day to day.
What if the MSP set everything up years ago?
You can transfer ownership. Admin accounts, billing, and recovery methods should be updated so the business controls them now.
What happens if we lose the global admin account?
Recovery becomes slow and risky. This is why recovery methods and trusted contacts must be documented and owned.
Can owning admin accounts slow down support?
No it usually speeds support because access is clear. Delegated access reduces delays and avoids password hunting.
Does this help cyber insurance readiness?
Yes because insurers value governance and control. Ownership reduces third-party risk and improves incident response speed.
Does this prevent switching pain?
Yes because access can be removed cleanly. Your next provider can be granted access without disruption.
What is a Fit Check?
A Fit Check inventories licenses and admin ownership. It identifies gaps and sets a simple ownership plan.
Decision matrix
Ownership policy
The business owns all licenses, billing accounts, and top-level admin access for critical systems, including recovery methods. The provider is granted delegated or role-based administrative access to manage day-to-day operations without controlling ownership.
Common mistakes
- Letting the provider be the only global admin and fix it by creating business-owned admin access.
- Letting licenses be billed under the provider and fix it by moving billing to the business.
- Storing recovery codes in one person’s inbox and fix it by using a vault with two owners.
- Using shared admin passwords and fix it by using role-based accounts.
- Forgetting domain registrar ownership and fix it by transferring registrar control.
- Not verifying access regularly and fix it by doing quarterly checks.
Common objections
We trust our provider. Trust is not ownership. Ownership protects you during outages and transitions.
This sounds like extra work. It is usually a one-time cleanup plus quarterly checks. It prevents major delays later.
We do not want multiple admins. Two internal owners prevents lockout. Access can still be tightly controlled.
Our provider needs full control to support us. They need access, not ownership. Delegated access supports speed without lock-in.
What varies and why
- It depends on whether you use Microsoft 365 or Google Workspace.
- It depends on whether your provider is a reseller.
- It depends on the number of vendor portals and systems you use.
- It depends on whether you have a password vault today.
- It depends on how often staff changes and roles shift.
- It depends on your recovery and insurance requirements.
How we operate
We keep ownership with the business and grant providers delegated access. Billing and recovery stay under business control so renewals and incidents do not stall.
We store critical access in a business-owned vault with two internal owners. We verify ownership quarterly so control stays current.
What we measure
- Percentage of critical systems with business-owned billing and admin access
- Number of critical portals documented in the vault
- Quarterly access verification completion
- Recovery method completeness for admin accounts
- Time to vendor escalation during outages
FAQs
Who should own Microsoft 365 or Google Workspace admin accounts?
The business should own them. Providers should have delegated or role-based access.
Who should own licenses for cloud services?
The business should own licenses and billing. Providers can manage assignments and quantities.
How do we prevent lock-in with an MSP?
Own billing, global admin, and the password vault. Use delegated access for provider administration.
What is the most important ownership item?
Tenant ownership and global admin access is critical. Domain registrar ownership is also a top priority.
How often should we verify ownership?
Quarterly is a good default. Verify after vendor changes and renewals too.
What is a Fit Check?
A Fit Check inventories ownership of licenses and admin accounts. It provides a gap list and next steps.

