I recently became the head of IT for a company transitioning its IT operations in-house from a Managed Service Provider (MSP). We're set to officially offboard from the MSP in February, but I've held off on creating a backup global admin account because I didn't want to disturb the MSP. However, I've discovered that they have revoked our Azure P2 licenses, leaving us without any Privileged Identity Management (PIM) roles or access to the Microsoft 365 tenant. I reached out to Microsoft Support about taking over admin privileges, but they refused to assist since the MSP is still listed as our partner, fearing there might be unpaid invoices. The MSP claims they can't help because their GDAP access has also been revoked. Has anyone experienced this situation before and can provide some guidance?
5 Answers
It’s crucial to have a break glass account set up, even if your offboarding isn’t complete. But it seems like things are moving too quickly here. Ideally, a co-managed phase with the MSP for a few more months would have smoothed this process out. Keep trying to work with them to regain access, and hopefully, you'll find a way back in.
The MSP should be able to initiate a support ticket with Microsoft, especially if they have Premier support. They need to make sure to include all relevant case numbers to expedite the process. It's highly unusual not to have a break glass account; they’re a key part of any disaster recovery plan.
You might want to involve legal counsel in this situation. If the MSP is obstructing your access without reason, it could be seen as a breach of their obligations. Having a legal perspective can help clarify things.
Getting the MSP to log a support ticket with Microsoft is definitely the best strategy. They should be able to leverage their partner status to help recover your admin access. If they get involved, MS Support will likely be willing to assist.
You won’t be able to take over admin access until the MSP clears their access first. It’s important to resolve that issue first, and then you can focus on setting up an emergency admin account for the future.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures