How to recover admin access to company systems after an acquisition
To recover admin access after an acquisition, list every system, ask the seller to add two company-controlled admins under the purchase agreement's cooperation clause, and use each vendor's recovery process, which usually means proving control of the domain or billing account, where the seller cannot help. Then remove personal logins and test that exports work.
The short answer: get a company-controlled admin in place first
The quickest way to recover admin access after an acquisition is the cooperative route: the seller, the departed IT person or the outgoing managed service provider signs in once and adds two admin accounts that the company controls. When that person cannot or will not help, each vendor has its own recovery process, and most of them ask you to prove you control the company's domain or billing account.
The order matters because whoever holds the top admin role (the global admin in Microsoft 365, the super admin in Google Workspace, the primary admin in most accounting and field service tools) can change retention settings, delete mailboxes, cancel subscriptions and lock everyone else out. Until the company holds that role itself, it does not fully control its own records.
Who usually holds the only admin login
In owner-run companies, admin rights tend to accumulate with whoever set each tool up, often years ago.
| Who holds it | Typical situation | Risk after closing | First move |
|---|---|---|---|
| The seller | Accounts opened with the founder's personal email long before the sale | Seller can reset passwords or cancel tools after leaving | Ask for company admins to be added during the transition period |
| A departed IT or office manager | The only person who knew the tenant password left before the sale | No one can change settings or recover deleted data | Reach them through the seller; fall back to vendor recovery |
| The outgoing MSP | Admin roles held under the MSP's own partner account | Access can become leverage in a contract dispute | Require a written handover of every admin role |
| A reseller or freelancer | Subscriptions billed through a third party | Renewals lapse when the relationship ends | Move billing and the owner role to the company |
| A former parent company | The business was carved out of a larger group and still sits in its tenant | Records are mixed with the seller's other businesses | Agree a separation plan; see separating a shared email tenant |
What to have in hand before you start
Recovery goes faster when the paperwork is ready, because vendors and registrars will ask who you are and why the account is yours.
- Closing documents showing which entity you bought and whether it was a stock or an asset purchase; after an asset deal, some accounts may still sit in the seller's entity name
- Access to the domain registrar and DNS, or a clear path to it
- Bank and card statements for the last 12 months, which show every subscription the company pays for
- A company email address on a domain you control, never a personal mailbox
- The purchase agreement's transition, cooperation and further-assurances clauses
- Contact details for the seller, former IT staff and the outgoing MSP
Step-by-step: regaining control system by system
- List every system from the money trail. Go through card statements, the accounts payable vendor list and expense reports, then rank systems by how much damage a lost login could cause: domain registrar and DNS first, then email and identity, then finance (accounting, payroll, bank portals), then files, then line-of-business tools such as CRM, ERP and field service.
- Secure the domain registrar. Many email tenant recoveries depend on proving domain control, so whoever holds the registrar account holds the master key. If it sits in the seller's personal account, ask for a transfer to a company account now.
- Send a written request to the seller or MSP. Ask them to add two named company admins to each system, transfer owner or primary admin roles, and hand over recovery codes and any hardware security keys. Cite the purchase agreement's cooperation clause and set a short deadline.
- Use vendor recovery where cooperation fails. Microsoft and Google both publish admin recovery processes for tenants with no reachable admin, and both can involve proving control of the domain, for example by adding a DNS record. Follow the vendor's current support article, because the steps change.
- Handle finance tools with an officer's request. Banks add signers through their own forms and corporate resolutions. Accounting and payroll providers typically let the current primary admin transfer that role, and some will verify an officer of the company when the old admin is gone.
- Work through line-of-business tools. Vendors of CRM, ERP and field service software generally have a process for reassigning the account owner, usually on a request from a company officer with proof of billing.
- Lock it down. Create two break-glass admin accounts held by the company, enforce multi-factor sign-in, record every admin in a register, and only then remove the seller's and former employees' admin roles.
- Prove you can get records out. Run a test export from each core system: one mailbox, one shared drive, a multi-year general ledger report, a CRM export. Check retention settings before deprovisioning anyone, because on many platforms deleting a user also deletes that user's mailbox and files after a short grace period.
Common mistakes that cost history
| Mistake | Why it hurts | Fix |
|---|---|---|
| Deleting former employees' accounts to save license costs | Their mail and files can be purged permanently | Convert, archive or export them first |
| Signing in with the seller's personal password | No audit trail, and the seller can still reset it | Get an admin account created in the company's name |
| Leaving the MSP as the only admin | A contract dispute can block access | Keep company-held break-glass accounts; see choosing an MSP after an acquisition |
| Leaving the domain in the seller's registrar account | Whoever controls DNS can redirect email | Transfer the registrar account in the first week |
| Switching off a legacy system before exporting it | Years of history disappear | Export in full and keep a read-only archive |
| Waiting until the transition period ends | The seller's cooperation fades | Make access the first transition task |
Illustrative example: a distributor whose only admin moved away
Illustrative and fictional: a search fund buys Harbor Line Supply, a fictional 70-person industrial supplies distributor. In week one the new CEO finds that the founder's nephew, who left two years earlier, is the only global admin, the accounting file is owned by the founder's personal email, and the domain sits in the nephew's registrar account.
The CEO sends one written request citing the purchase agreement's cooperation clause. The nephew adds two company admins and transfers the registrar account within days, and the founder hands over the accounting owner role at the next transition meeting. Before cutting licenses, the new controller sees that former staff mailboxes go back nine years and archives them instead of deleting them. That history stays available for audits, customer disputes and any later decision about the company's records.
Why admin access matters if the company ever licenses its data
Admin access is a precondition for almost any later use of the company's records. One of SourceX's red flags is a company where nobody can export the data; another is a company that has deleted its archives. A company in either position cannot complete a data inventory, so it cannot be assessed.
Once access is secure, an acquired business with 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to its records and an authorized sponsor can be checked against who qualifies, and the page on what happens after a company applies walks through what follows. Searchers, holdco operators and the MSPs who help them recover access are often first to see which acquired companies have deep, intact histories. Where a parent runs IT centrally, holding company IT shared services explains the extra step of separating control from ownership.
Next step
If you help acquirers sort out access and records, the network opportunity finder helps you work out which companies in your circle are worth a look, and you can register as a partner to introduce the ones that fit. Owners can apply directly at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
What can we do if the seller refuses to hand over admin access after closing?
Put the request in writing, cite the purchase agreement's cooperation or transition clause and set a deadline. If that fails, use each vendor's admin recovery process, which usually asks you to prove control of the domain or the billing account, and ask your deal counsel about enforcing the agreement. Do not try to guess or reset the seller's personal passwords.
How long does vendor admin recovery usually take?
It varies by vendor and by how quickly you can prove ownership. Recoveries that rely on a DNS record can move quickly once you control the domain, while those that need a vendor review of business documents take longer. Secure the domain registrar first so the DNS step never holds you up, and keep the seller cooperation route open in parallel.
Should we delete former employees' accounts once we have admin rights?
Not before checking what deletion does on each platform. On many systems, deleting a user removes their mailbox and files after a short grace period. Export or archive those accounts first and check retention settings. The history often holds customer correspondence, pricing decisions and project records that an acquirer, auditor or future licensee may need.
Is it acceptable to keep using the seller's login while we sort things out?
Treat it as a short stopgap at most. A shared personal login leaves no record of who changed what, the seller can still reset it, and it may breach the vendor's terms. Use it, if at all, only to add a company-owned admin account, then stop using it and ask the seller to remove their own access once yours is confirmed.
Does a company need working admin access before it can be considered for data licensing?
In practice, yes. A company must be able to export its records to complete a data inventory and, later, to deliver under a signed agreement. If nobody can export, or archives were deleted, the company is not ready. Recovering admin access and preserving history comes first, and the qualification screen can follow once that is done.
Related pages
- How to separate a shared Google Workspace or Microsoft 365 tenant after buying a business
- How to choose an MSP after an acquisition without losing years of records
- Which US businesses are a fit for a SourceX data licensing introduction
- What happens after a company applies to SourceX?
- Holding company IT shared services: who controls subsidiary data and who owns it
- Map your network to potential US data referral opportunities
Free resources
- Portfolio data opportunity scanner — Screen several companies in one session.
- Working capital calculator — Net working capital, current ratio and quick ratio.
- Due diligence checklist generator — A tailored document request list by deal type.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment