Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays connect@crossrivertechnology.com

IT emergencies

Your IT guy stopped answering: how to take back control

When the person who holds all your passwords stops replying, the fix is not panic, it is order: inventory, ownership, reset from the top down, then secure the network and backups.

Written and reviewed by Anthony Omini, Cross River Tech·12 min read·Published · Updated

Our IT guy stopped answering, what do we do?

Start by writing down what you can still log into, then prove ownership of the two things everything else depends on: your domain name and your Microsoft 365 or Google Workspace tenant. Reset administrator passwords from the top down, secure the firewall and confirm a backup is actually running. Most of this you can do without the old provider. In Dallas I can walk an office through it hourly.

Answered by Anthony Omini, Cross River Tech, Dallas

Empty office with unoccupied cubicles and no one working

Key takeaways

  • You almost certainly own your systems, even if you cannot log in to them yet, and ownership is what gets access back.
  • Work from the top down: domain name first, then email tenant, then network, then individual computers.
  • Do not start deleting the old provider's accounts until you have a working administrator login of your own.
  • Backups are the item most often found broken after a provider goes quiet, so check them on day one.
  • Very little of this genuinely requires the old provider's cooperation, and the parts that do have workarounds.

Our IT guy stopped answering, what do we do first?

Spend the first hour taking stock rather than changing anything. The single worst outcome here is locking yourself out of a system while trying to lock somebody else out of it, and that happens when an office starts resetting passwords before it knows which account is the master key. Write down what you can still get into, in your own name, with your own login, and only then start moving.

The good news, and it is genuinely good news, is that a business almost always owns its own systems even when it cannot currently reach them. Your domain name is registered to your company. Your Microsoft 365 or Google Workspace tenant belongs to your company. The firewall in the closet is your property. An absent provider holds keys, not ownership, and there are documented ways to get keys reissued to the owner.

Here is the order for the first day:

  1. Stop and write an inventory. What you can log into, what you cannot, and who in the office knows what.
  2. Find out where your domain name is registered and who is listed as the contact on it.
  3. Find out whether anyone in the business holds a global administrator account for email.
  4. Check the last successful backup date with your own eyes, not from memory.
  5. Send the provider one polite, dated written request for credentials and documentation.
  6. Decide whether anything is actively broken right now, or whether you simply have no support.

That last question matters, because it sets the pace. An office that is running fine but unsupported has a week to do this properly. An office with a dead server has hours, and should call for help immediately rather than working through a checklist alone.

How do we find out what we can still access?

Build a written inventory of accounts before you touch a single password, because the inventory is what tells you which door to open first. Sit down with whoever has been in the business longest, open a document, and go system by system. Include the accounts nobody thinks of, like the internet provider's billing portal and the account the printer lease is under.

Use a table like this one and fill in every row you can. Blank rows are not failures; they are the work list.

SystemWhere it livesWho can log in today
Domain nameRegistrar account
DNS recordsRegistrar or a separate host
Email and filesMicrosoft 365 or Google Workspace
WebsiteHosting account
Firewall and Wi-FiOffice IT closet
Internet serviceISP account portal
BackupsCloud console or local appliance
Antivirus or endpoint securityVendor console
Server and computersLocal administrator accounts
Line-of-business softwareVendor portal
Phone systemProvider portal

Two shortcuts help enormously. The first is your accounting records: whoever pays the bills can usually tell you which company invoices you for the domain, the internet, the phones and the software, and the billing contact email is often the recovery route into the account. The second is your own mailbox, which frequently contains the original setup emails from years ago with account numbers in them. Search it for words like renewal, invoice and account.

How do we prove we own the domain and the Microsoft 365 tenant?

You prove ownership with business paperwork and control of the billing relationship, and both the registrar and Microsoft or Google have a documented process for handing control back to a verified owner. This is the most important section on this page, because your domain name and your email tenant are the two systems everything else hangs from. Get those two back and the rest is housekeeping.

Start with the domain, because whoever controls it controls where your email is delivered. Look it up in a public registration lookup to see which registrar holds it and when it expires. If the registration is in your company's name with a company email address, you can usually reset the password through that address. If it is registered under the old provider's name or their email, you are asking for a change of registrant, and registrars have a form for exactly that. Have your formation documents, a matching business address, an invoice showing you paid for the name, and photo identification for a company officer ready before you call.

For Microsoft 365 or Google Workspace, the recovery path is similar in spirit. If any account in the business still has the global administrator role, you are fine: sign in, create a second administrator account in a real person's name, and store the credentials safely. If nobody has that role, the vendor can reassign the tenant to a verified owner of the domain, which usually means proving domain control and providing company documentation. It takes longer than a password reset and it does not happen the same afternoon, so open the case early. The specific steps for that situation are in locked out of your Microsoft 365 admin account.

Do this in order:

  1. Confirm the registrar and the expiry date of your domain, and set it to auto-renew.
  2. Get a login to the registrar in a company email address you control.
  3. Change the registrar contact details to your own name, address and phone.
  4. Secure a global administrator account for your email tenant, in a named person's account.
  5. Add a second administrator so one departure never repeats this situation.
  6. Record where the DNS records live, since they are sometimes at a different company from the registrar.

If you want the background on who is entitled to what in this situation, who owns your passwords, domain and equipment covers it plainly.

In what order should we reset passwords?

Reset from the top down: domain registrar first, then email tenant, then network equipment, then servers and computers, then everything that logs in with an email address. Working in that order means each reset is protected by the one before it, and it stops the common disaster of resetting an account whose recovery emails go to a mailbox you no longer control.

Before you begin, make sure you have somewhere safe to put the new credentials. A password manager in the company's name is the right answer. A spreadsheet on the shared drive is not, and neither is a notebook in a drawer that leaves with whoever retires next.

  1. Registrar and DNS. New password, new recovery email pointing to an account you control, and two-step verification switched on.
  2. Email tenant. New global administrator password, verification enabled, and a review of every account holding administrator rights. Remove any that belong to the old provider once your own account works.
  3. Firewall and Wi-Fi. New administrator password, and note the current configuration before you change anything else.
  4. Internet provider portal. Contact details and password updated to the business.
  5. Server and local administrator accounts. New passwords, stored, and old service accounts identified rather than deleted blindly.
  6. Backup and security consoles. New passwords, plus confirmation that the subscription is paid and in your name.
  7. Remote access tools. Any software that let the old provider connect to a computer without asking gets removed, not just reset.
  8. Staff accounts. Only after all of the above, because a mass password change is disruptive and pointless if the administrator layer is still exposed.

Two cautions. Do not delete accounts you do not recognize on a server until you know what they run, because some of them are how the backup job or the practice management software authenticates, and deleting one takes a system down. And do not remove the old provider's remote access tool from a machine you rely on remotely until you have your own way back into it.

What about the firewall, the network and the backups?

Treat the firewall and the backups as the two urgent technical items, because a firewall with a stranger's password on it is an open door, and a backup nobody has checked is usually not a backup. Everything else on the network can wait a week; these two should be dealt with in the first few days.

For the firewall and network gear, the question is not only who knows the password but what the device is doing. Providers commonly leave remote management enabled so they can log in from outside, and that access does not switch off when they stop answering the phone. Somebody should log in, change the credentials, look at what is allowed in from the internet, and disable remote management unless there is a reason for it.

For backups, do not accept a green tick on a dashboard as proof. A restore test is proof. Pick a real file, restore it somewhere harmless, and open it. If the backup turns out to be a copy of the server sitting on a drive plugged into the same server, in the same room, you do not have a backup, you have a second copy that a fire, a theft or ransomware would take with the original.

ItemWhat to checkWhat good looks like
FirewallAdmin password, remote management, firmware agePassword held by you, remote access closed or restricted
Wi-FiAdmin login, guest network, staff password ageGuest traffic separated from office systems
SwitchesAdmin login, whether anyone can reach themDocumented and not reachable from the internet
Backup coverageWhich systems are actually includedServer, files and email all covered
Backup locationWhere the copy physically sitsAt least one copy offsite and not writable by the network
Restore testWhen one was last doneA file restored and opened, recently, by a person
Endpoint securityWhether the subscription is still paidActive on every computer, visible in one console

If the security tools were bought under the old provider's licensing, they may stop working when that account lapses, quietly and without warning. That is worth checking now rather than discovering later. My cybersecurity, backup and disaster recovery page describes how I set this up when I take an office over.

What genuinely needs the old provider, and what does not?

Very little truly needs them: almost everything can be recovered as the owner, and the exceptions are mostly about time and money rather than possibility. It is worth being precise about this, because offices often stall for weeks waiting on someone who is not coming back, when the recovery path was open the whole time.

Before going further, a word about tone. I do not know why your provider went quiet, and neither do you yet. Illness, a family emergency, a business that failed, a person who simply burned out running everything alone. I have seen all of those. Nothing in this process requires you to think badly of them, and staying civil in writing keeps doors open that anger closes.

ItemDo you need them?How it gets solved without them
Domain nameNoRegistrar change-of-registrant process with company documents
Microsoft 365 or Google WorkspaceNoVendor reassigns the tenant to a verified domain owner
Computers and serverRarelyLocal administrator access can be re-established onsite
Firewall and switchesNoFactory reset and reconfigure, ideally after hours
Their own management softwareNoUninstall it and deploy your own
Backups stored in their accountSometimesMay be unrecoverable, so start a fresh backup immediately
Software licenses bought in their nameSometimesVendor can often transfer, otherwise repurchase
Undocumented custom configurationYes, ideallyRebuild and document properly this time

The two rows that cost real money are the last three. Backup history held inside a provider's own account can be genuinely lost, which is why a new backup starts today rather than when the handover finishes. Licenses bought under a reseller agreement sometimes have to be repurchased in your name. And undocumented configuration, the little script that moves files at night or the mapped drive nobody can explain, is rebuilt by observation.

Nothing on that list requires waiting. If you would rather not run it yourself, this is exactly the kind of work I do hourly at my published break/fix rates, with no contract, whether or not you go on to hire me monthly.

How do we document all this so it never happens again?

Write the documentation as you recover, in the same week, because the knowledge you are gathering right now is the exact knowledge that vanished when your provider did. Documentation written later never gets written. Documentation written during a recovery is accurate, because you are looking at every system anyway.

It does not need to be elaborate. A password manager owned by the business, plus a short document a stranger could follow, covers almost everything a ten-person office needs.

  1. An account register: every system, who the vendor is, what the account number is, who pays for it and when it renews.
  2. A network page: what internet service you have, what the firewall is, how many switches, where the Wi-Fi access points are, what the IP range is.
  3. A computer list: make, model, age, who uses it, whether it is under warranty.
  4. A backup page: what is backed up, where the copies live, how a restore is done, when one was last tested.
  5. An administrator list: every account with elevated rights and the human being responsible for it.
  6. A vendor contact sheet: internet, phones, printers, and your practice or line-of-business software.
  7. An emergency page: what to do if the server, internet or email goes down, and who to call.

Two ownership rules make the difference. Every account is registered to a company email address, never to an individual's personal address and never to a supplier's. And at least two people in the business can reach the password manager, so that a resignation, an illness or a holiday is an inconvenience rather than an incident. That is also the standard I hold myself to, because a client of mine should always be able to leave me without a fight. The wider security picture for a small office is in Microsoft 365 security for a small business.

How do we replace an unresponsive IT provider in Dallas?

Bring somebody new in for an assessment first, on an hourly basis with no commitment, and let the recovery work double as the handover. When the old provider has gone quiet there is nothing to overlap with, so the usual advice about running two providers in parallel does not apply. What replaces it is a documented assessment, a stabilisation phase, then a decision about ongoing support once you can see clearly.

A sensible sequence for a Dallas office looks like this:

  1. Assessment. A few hours of somebody walking every system, producing the written inventory and a risk list. This stands on its own even if you hire someone else afterwards.
  2. Stabilise. Ownership of domain and tenant recovered, administrator passwords reset, firewall secured, a working backup running and tested.
  3. Document. The register described above, handed to you in your own password manager.
  4. Decide. Hourly support when something breaks, or a monthly plan where updates, security, backups and monitoring are simply handled.

What I offer, so you can judge it against anyone else you talk to: I am Anthony Omini, the owner of Cross River Tech, a small IT company in Dallas, with over 15 years of IT experience, supporting small businesses across Dallas–Fort Worth onsite and anywhere in Texas remotely. Managed IT is priced per user or per device, month-to-month, cancel anytime. Hourly work is at published rates with a one-hour minimum. You get my number, not a queue, and I write down what I do as I do it. My team handles the routine monitoring and updates behind me; I stay your point of contact.

The limits, stated honestly: onsite visits are by appointment rather than instant, and I work remote-first because it is faster and cheaper for you. If you are also weighing a planned exit rather than an abandonment, the process is different and gentler, and how to switch IT companies without downtime walks through it. If your current person is winding down rather than vanishing, the retirement handover plan is the one to read. Either way, tell me where things stand and I will tell you what I would do first.

Questions people ask

Our IT company disappeared, how do we get our passwords?

You do not get their copy of the passwords, you replace them as the owner. Recover the domain name through the registrar's change-of-registrant process with your company documents, then recover your Microsoft 365 or Google Workspace tenant by proving you control the domain. From there you reset the firewall, server and computer administrator accounts yourself. The old provider's cooperation makes it faster, but it is not required.

Can they lock us out of our own email?

Not permanently. A tenant belongs to the organization that owns the domain, and both Microsoft and Google have a process for reassigning administrative control to a verified owner. It is paperwork rather than a phone call, so expect it to take days rather than minutes. Meanwhile your email keeps flowing normally, because delivery does not depend on anyone logging in to administer it.

Should we change every password straight away?

No, change them in order. Start with the domain registrar, then the email tenant, then network equipment, then servers and computers, and only then staff accounts. Resetting a staff mailbox before you control the tenant achieves nothing, and resetting an account whose recovery messages go somewhere you cannot read can lock you out. Get a working administrator login of your own before you remove anybody else's.

How long does it take to recover everything?

For a small office where somebody still has an administrator login, the practical work is usually a couple of days spread over a week, plus a little vendor paperwork. Where nobody has any administrator access, allow one to three weeks, because domain and tenant recovery moves at the vendor's pace. Backups and the firewall should still be dealt with in the first few days regardless.

What if the backups were in the old provider's account?

Assume that history may be lost and start a fresh backup today rather than waiting to find out. Ask the provider in writing for an export, since some will supply one. In parallel, set up a new backup of your server, your important files and your email, keep one copy offsite that the network cannot overwrite, and test a restore. A tested new backup is worth more than a disputed old one.

Do we have to sign a contract to get help with this?

No. I do recovery work like this hourly, with a one-hour minimum, at published break/fix rates and no ongoing commitment. The assessment and the documentation belong to you whatever you decide afterwards. Plenty of offices use hourly help to stabilise, take a breath, and then choose between staying hourly or moving to a month-to-month managed plan once they can see the whole picture.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Your provider has gone quiet. Where do you start? Tell me what you can still log into and I will tell you the order to do the rest in, hourly and with no commitment.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080