When we sit down with an owner whose organization has one IT person, one of the first questions we ask is this: if your IT person weren’t available tomorrow, could you log in and manage your Microsoft 365 environment, your domain, your firewall, your internet provider account, and your key vendors? The most common answer is “probably.” The next most common is “I think so,” and every so often someone admits they aren’t sure where those passwords would even be.
IT admin access is the set of top-level logins that let someone change settings, add or remove users, reset passwords, and recover a system when something breaks. Your staff can do their jobs every day without it. When it lives with one person, the business can’t change or recover its own systems without them, and most owners don’t find that out until the day they need it.
Admin access to every critical system should belong to the business, through accounts and records it controls, so one person leaving, or simply taking a day off, can’t lock you out.
What Happened When One Organization Couldn’t Get Back In
One senior living organization we started working with had just let its internal IT person go. Leadership assumed they’d keep control of their own technology. When they went to make an administrative change, they found that admin access to Microsoft 365, their domain environment, and their firewall was either unavailable or still in the former employee’s hands. Passwords, user permissions, and account recovery methods had all been set up under that one person instead of under the business or a proper admin account.
The onboarding team turned up two more problems. The machine everyone called the server was a workstation-class computer that had never been built or managed like business infrastructure, and there was no proper backup behind it. Before anything else could happen, we had to establish who owned what, recover admin access, verify identities, document what existed, and rebuild control so it sat with the company instead of an individual.
Why Nobody Notices Until Someone Leaves
Day to day, that organization looked fine. Employees could log in and do their work, and leadership could use the tools they needed. Everyday user access was never the problem. Nobody needed IT admin access until a change had to be made or someone got locked out, and by then there was no way to recover.
This usually happens without anyone intending it. A system gets set up under the IT person’s own login because that’s quickest, the recovery email goes to their address, and the verification codes go to their phone. Over a few years, access ends up tied to a person instead of a role. In a role-based setup, admin rights belong to a position the business controls, so they can be handed to someone else when people change.
If nobody at your organization owns IT at all, that’s a different situation, and we’ve written about the accidental IT person separately. This article is for organizations that do have someone in charge of IT and assume that means the business is covered.
What Goes Missing Even When the Departure Is Friendly
Even when there’s no conflict and everyone handles the handoff professionally, we find gaps afterward, mostly because things were never written down. These come up most often.
Passwords and recovery methods
Admin logins for core systems, plus the phone numbers and email addresses that verification codes and reset links go to.
Ownership records
Whose name is on the Microsoft 365 subscription, the domain registration, and the internet service.
Network settings
DNS records, firewall logins and configuration, and network diagrams or floor plans showing where equipment sits.
Vendors and licenses
Logins for vendor portals, software licensing records, and a contact at each provider.
Dates and inventory
Warranty end dates, subscription renewals, and a list of the devices the organization owns.
Backups
The login for the backup platform, what it covers, and the steps to get data back out of it.
Lost logins and ownership records can usually be recovered with enough calls to vendors and enough proof of ownership. The harder gap to close is everything the IT person knew and never documented, because there’s no vendor to call for that. Without a list, you find out what’s missing one emergency at a time.
Could You Get In Tomorrow?
Admin Access Self-Check
Go through each one as if your IT person couldn’t be reached today. Check the ones you could handle on your own.
Reading your results
Every box you couldn’t check, or weren’t sure about, is a place where one person holds the keys. Start with your domain and Microsoft 365. Your domain’s settings tell the internet where to deliver your email and where to find your website, and if your email runs on Microsoft 365, that’s where most of your other accounts send their password resets.
An informal check for your own use, not a security assessment. Nothing here is saved or sent.
What You Can Do This Month Without Hiring Anyone
Your IT person can handle most of these, and none of them requires bringing in a new provider.
Put Ownership in the Company’s Name
Ask that the Microsoft 365 tenant, the domain registrar, and the internet provider account each be registered to a company account and a company email address, such as a shared admin mailbox the business controls. A personal Gmail address or an employee’s own mailbox on these accounts is the first thing to change. For domains, ICANN’s registrant responsibilities put sole responsibility for a domain on whoever is listed as its registrant, so that should be the organization.
Set Up Emergency Admin Accounts
Microsoft calls these emergency access or “break-glass” accounts: admin accounts kept for the moment nobody can sign in the normal way. Microsoft’s guidance on emergency access accounts lists the last administrator leaving the organization as one of the reasons to have them, and recommends creating two or more, not tying them to any one person, and checking them again after a change in IT staff. Keep the credentials somewhere secure that you and one other trusted leader can reach.
Move Recovery Methods Off Personal Devices
For every admin login, check where the verification codes and password-reset emails go. If the answer is one person’s cell phone or personal email, that person is the only way back in when something goes wrong. For admin accounts, CISA’s multifactor authentication guidance recommends phishing-resistant methods such as a security key, which also keeps sign-in from depending on anyone’s personal phone.
Write It Down Somewhere the Business Owns
A SharePoint site or a shared folder works fine. List each system, its vendor and a contact there, license and renewal dates, and basic notes on how the network is set up. Keep passwords themselves in a business-owned password manager, separate from the notes. CISA’s Cyber Essentials guide asks small organizations for the same kind of record: inventories of hardware, software, user accounts, and vendor connections.
Confirm the Backups Restore
Ask your IT person when a file or system was last restored from backup as a test, and add the answer to your documentation. Our post on what makes a backup reliable covers what else to look at.
How to Bring It Up With Your IT Person
Asking for this can feel like a vote of no confidence. Frame it around continuity instead: if your IT person is on vacation or out sick, someone else should be able to get in during an emergency. It also takes pressure off them, since they’re no longer the only person who can fix things.
What We Do in the First Two Weeks
When we take on an organization in this situation, the goal for the first one to two weeks is simple: get admin control back with the business, and make sure nothing has been lost or compromised. That usually includes:
- Identifying every critical system, then verifying who owns it and who has admin rights
- Recovering or resetting credentials where needed, and closing or limiting access a former employee still has
- Setting up emergency admin accounts and turning on multifactor authentication (MFA) and other current security controls
- Confirming access to Microsoft 365, the domain and DNS, the firewall, the internet provider account, and line-of-business applications
- Reviewing backups against the 3-2-1 rule in CISA’s data backup guidance: three copies of your data, on two kinds of storage, with one kept off-site
- Documenting systems, vendors, and contacts in shared documentation the organization owns, usually in SharePoint
We also build a responsibility matrix that spells out which jobs belong to us and which stay with your team. If you still have an IT person, this is where co-managed support fits: we work alongside them, so the organization isn’t depending on one person for everything. Our Remote IT and co-managed IT service includes helpdesk support, day-to-day management of the systems assigned to us, a cybersecurity foundation, and, depending on scope, Microsoft 365 administration and backup management, at a flat rate.
Once control is back where it belongs, we put together a longer-term plan for technology decisions and ownership. For some organizations that means ongoing planning and budgeting through our vCIO service.
Technical review by Conner Long, Senior Solutions Architect.
Find Out Who Holds Your Admin Access
If the self-check left you with more question marks than you’d like, see how Remote IT and co-managed support can work around the IT setup you already have.
Frequently Asked Questions
More on Keeping Your Technology Under Your Control
If this raised questions about who’s responsible for what, these pick up from here.

