A cloud-based identity and access management service for securing user authentication and resource access
Microsoft can’t grant administrative access to an existing Microsoft 365 tenant or disclose its credentials based solely on a request, even when there is a court decision. Tenant ownership and admin access changes always require identity and ownership verification through Microsoft’s standard support and data protection processes.
Use these approaches depending on the situation:
- If there is still an accessible global admin or IT partner
- Contact the existing global admin or the Microsoft partner/reseller that manages the tenant and have them:
- Add your organization’s admin account as a Global Administrator in that tenant, or
- Transfer internal ownership of subscriptions and billing profiles within the same tenant (for example, using the Product Transfer Request Tool where applicable).
- Note that entitlements and nonprofit benefits cannot be moved across tenants; they can only be reassigned within the same tenant.
- Contact the existing global admin or the Microsoft partner/reseller that manages the tenant and have them:
- If no one has admin access (loss of tenant access)
- This is treated as a tenant access recovery scenario. The only supported path is via Microsoft 365 support and the Microsoft Data Protection/Identity Verification process.
- Steps:
- Go to the Microsoft 365 support entry point and choose the option for “I can’t sign in or access my tenant.”
- Submit a support request stating that the company is in insolvency, that operations (including email) have been transferred to you by court decision, and that no prior admin is available.
- Be prepared to provide:
- Official court documents showing your appointment and authority over the company.
- Evidence of organizational identity and domain ownership.
- Any existing tenant identifiers you may know (tenant name, primary domain, admin email patterns, etc.).
- Microsoft’s support and Data Protection teams will validate identity and ownership and, if successful, will help you regain or establish admin access. This process cannot be bypassed or handled via forums.
- If the tenant was created via self-service and is unmanaged
- If the tenant is an unmanaged (“shadow”) directory created by self-service signup, an internal admin takeover can be performed by an eligible user with the company’s domain:
- Use a work email on the company’s domain to sign up for a supported self-service product (for example, via Power BI as described in the internal admin takeover process).
- Follow the admin takeover wizard to become the admin for that unmanaged tenant.
- This only applies if the tenant is currently unmanaged (no global admin). If it is already a managed tenant, the takeover path does not apply and you must use support/Data Protection as above.
- If the tenant is an unmanaged (“shadow”) directory created by self-service signup, an internal admin takeover can be performed by an eligible user with the company’s domain:
- Retrieving the tenant ID (once you have or regain access)
- After admin access is established, the Microsoft 365 tenant ID can be viewed in the Microsoft Entra admin center on the Tenant Overview page in the Tenant ID field.
- The tenant ID is a GUID and is used for configuration and API scopes, but it is not a substitute for admin credentials.
- What cannot be done
- Microsoft for Nonprofits or any other program cannot:
- Bypass identity verification.
- Directly provide tenant admin credentials.
- Transfer entitlements or benefits between different tenants.
- All ownership and access decisions are handled only through Microsoft 365 support and the Data Protection/identity verification process, even when legal or court documents are involved.
- Microsoft for Nonprofits or any other program cannot:
In summary, to obtain exclusive administrative access, initiate a formal tenant access recovery or admin change through Microsoft 365 support, provide court and organizational documentation, and work with the Data Protection team to have admin rights assigned to your organization. Direct retrieval of credentials or forced transfer outside these processes is not supported.
References: