Defined implementation

Hold the keys to your own Microsoft 365, whoever leaves.

Ownership of the tenant and the domain is verified. Admin and emergency access come under your control, partner access is reviewed, and passwords are rotated where you authorize it. The map of vendors and what depends on what goes to the new owner.

PricePrice fixed after a short scope call.

DeliveryThe proposal names the start date, the change windows and the completion date before anything is agreed.

What you receive · illustrative sample

The client keeps control and the handover record.

Illustrative tenant ownership checklist. A provider release and a data migration are different scopes.

ControlWhat is verifiedHandover
AdministrationAuthorized client administrator can sign inAccess record
Mail and licensesMail-flow tests and license assignment checksValidation sheet
OwnershipDomain, billing and provider responsibilities agreedOwner register

Related delivery record

Provider exit: administrative control and messaging continuity

Read what changed and how it was checked ↗

Engagement context

When this engagement applies.

Your IT provider, your administrator, or the one person who knew how it all worked is leaving. Nobody can prove the business still controls its own Microsoft 365.

Scope considerations

  • You get the handover, not a binder
  • Passwords changed only with your written go-ahead
  • Handover reviewed with the new owner

The defined work

Engagement scope.

  1. 01

    Tenant and domain ownership is verified against the registrar and the tenant, and moved where it is not already with the business.

  2. 02

    Global Administrator access is cut back to a named, approved list, and emergency access accounts are created or rebuilt under the business’s own control.

  3. 03

    Partner and delegated administrative relationships are reviewed, and the ones that should not survive the handover are removed.

  4. 04

    Privileged credentials, service accounts and API keys in scope are rotated where authorized, in a sequence that does not break the things depending on them.

  5. 05

    Registrar, DNS, CSP, backup, security and application vendors are mapped, with what each one holds and who now owns the relationship.

  6. 06

    Whatever is left unresolved is assigned by name rather than left in a document as a finding.

Acceptance

Completion has an agreed standard.

  • Tenant and domain ownership is verified and held by the business

  • The Global Administrator list matches the approved named list, and emergency access is under the business’s control and alerting

  • Partner and delegated access is reviewed, with obsolete relationships removed

  • Authorized credential rotations are complete and the dependent systems still work

  • The vendor, registrar, DNS, backup and application map is complete

  • Every unresolved dependency has a named owner and a date

  • The handover record has been walked through with the incoming owner

Commercial basis

Price, scope and timing are considered together.

Engagement price

Price fixed after a short scope call.

The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:

What determines the scope

  • Number of tenants and domains
  • Number of privileged accounts, service accounts and shared credentials in scope
  • Number of vendors and third-party integrations to map
  • Whether the outgoing party is cooperating
  • Whether Azure subscriptions and on-premises systems are included

Delivery calendar

The proposal names the start date, the change windows and the completion date before anything is agreed.

How engagements work

Scope & responsibilities

The full engagement boundary.

Review the exclusions, required client participation, change controls and operational handover for this engagement.

Exclusions
  • Legal or contractual dispute with the outgoing provider
  • Recovery of access the outgoing party refuses to release, which becomes its own scoped work
  • Ongoing administration after handover
  • Help desk and end-user support
  • Rebuilding systems found to be badly set up, which is quoted as its own job
Client responsibilities
  • Authorize each credential rotation in writing before it happens
  • Provide the approved list of who should hold administrative access afterwards
  • Name the incoming owner who will take the handover walkthrough
  • Own the commercial conversation with the outgoing vendor
Change and rollback method
  • Rotation runs after the dependency map, never before it: a credential is changed only once what depends on it is known and has an owner standing by.
  • Access is removed in a staged order with the business’s own access proven working first, so no step can leave the tenant unadministered.
Operational record and handover
  • The ownership record: tenant, domains, registrar, and who holds each
  • The before-and-after privileged access list
  • The partner and delegated access review, with the removals made
  • The rotation log, and what depended on each credential
  • The vendor and dependency map
  • The handover record, signed off by the incoming owner

Before you commit

A clear first step.
You stay in control.

Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.

Check client feedback on Upwork ↗

Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.

Who will actually do the work?

Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.

What happens before you get access?

We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.

How do we know the change worked?

Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.

Will we need an ongoing retainer?

A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.

Discuss the fit ↗Read the delivery process ↗

Discuss this engagement

Put the scope in context.

Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.

Plan the Tenant Handover