You told your IT provider you were leaving, and the passwords stopped coming. Maybe it is open stonewalling. More often it is softer: unreturned emails, "we will get that over to you," an invoice that has to be settled first, a transition fee nobody mentioned before. Either way, the effect is the same. Someone else is holding the keys to your own business.
Take a breath. This situation is common, it is usually resolvable in days or weeks, and you have more leverage than it feels like right now. Here is the reality of who owns what, and the practical path to getting it all back.
Start here: those accounts belong to you
The accounts that run your business belong to your business. Your domain registration, your DNS, your Microsoft 365 or Google Workspace tenant, your website hosting, your backups, your software licenses: these are your assets, purchased for your benefit, usually with your money. An MSP is an administrator acting on your behalf, not an owner. Holding a client's own credentials to extract payment or prevent departure is widely considered unethical in the industry, and depending on the circumstances and your agreement, withholding them can create real legal exposure for the provider. We are not lawyers and this is not legal advice, but you should walk into this dispute knowing the ground you stand on, because the provider is counting on you not knowing it.
One honest caveat: the provider's own tools are theirs. Their monitoring platform, their internal documentation system, their ticketing history live inside their business. What you are owed is your data and your credentials, in usable form, not a copy of their toolset.
Step 1: Inventory what is actually held
Before demanding anything, list it. The usual suspects:
- Domain registrar login (GoDaddy, Namecheap, and the like), and whose email is on the account
- DNS management, if separate from the registrar
- Microsoft 365 or Google Workspace global admin
- Firewall, switches, and Wi-Fi admin
- Server and workstation admin passwords
- Backup platform and any offsite copies
- Website hosting and content management logins
- Software licenses and vendor portals registered under the provider's email
For each, note whether the account itself is registered to your email or theirs. That distinction decides whether you need a password handed over or an account transferred, and the transfers are the slow part.
Step 2: Make one clean, written request
Send a single email from the owner, with the list attached: "Please provide administrative credentials and account transfers for the items listed by [date, one to two weeks out]. These accounts and the data in them are the property of [company]." Calm, specific, dated. No threats yet; you may still get everything within the week, and most disputes end right here. Keep every reply. If your agreement has an offboarding or termination-assistance clause, quote it.
A note on unpaid invoices: if you legitimately owe money, expect that to come up, and consider paying undisputed amounts promptly. It removes the provider's most defensible reason to stall and isolates the indefensible ones.
Step 3: Recover from the vendor side
Here is what stonewalling providers hope you never learn: for the accounts that matter most, you can often go around them. Vendors have ownership recovery processes precisely because this happens all the time:
- Domain registrars have formal ownership dispute and account recovery processes. Documentation showing your business is the registrant (or should be) goes a long way.
- Microsoft and Google both have admin takeover and ownership verification processes for businesses locked out of their own tenant. Proving domain ownership and business identity is central to both, which is one more reason the registrar comes first.
- Line-of-business vendors will usually re-key the account contact to an owner who can verify the business relationship and billing history.
These processes take days, occasionally weeks, and they demand paperwork. But they convert "we are locked out forever" into "this is a process," and once a provider realizes you know the vendor-side route exists, cooperation tends to improve on its own.
Step 4: When a lawyer's letter earns its fee
If the deadline passes and the stonewall holds, a short letter from an attorney changes the temperature. Not a lawsuit, a letter: identifying the withheld property, the business harm accruing, and a firm date. Providers who ignore business owners rarely ignore law firms, because they understand what the next letter would be. In our experience the letter usually resolves it; actual litigation over credential handover is rare because the provider's position is so hard to defend. Talk to your attorney about your specific situation; the point here is simply that the letter is a normal, proportionate step, not an escalation to be ashamed of.
Step 5: Rotate everything, trust nothing
Whatever way the credentials come back, treat every one of them as compromised. Change all of them, remove the old provider's accounts and email addresses from every system, revoke their remote access tools, and check for lingering admin accounts you do not recognize. A departing provider with leftover access is a risk even when the breakup was friendly, and this one was not.
Never be here again
The vaccine is boring: keep the master inventory yourself, register every account to an email your business controls, and insist any provider work as a delegated admin inside your accounts rather than the owner of them. A trustworthy provider will volunteer all of this. In fact, "we could not see our own documentation" is one of the red flags we tell owners to catch early, before it hardens into the situation this article is about, and the feeling that you cannot leave is the last of the nine signs it is time to fire your provider.
If you are in the middle of this right now, you do not have to run the recovery alone. This is a standard part of every switch we manage: we inventory what is held, draft the requests, work the vendor-side recoveries, and make the calls to the old provider ourselves, while your new support is already running in parallel. Most of the time, the whole thing, recovery included, fits inside the normal one-to-three-week switch timeline.
Get your keys back
Tell us what is being withheld. You get a written recovery and switch plan in 48 hours, and we handle the provider so you do not have to.
Start the Switch