Our IT Guy Quit and Nobody Has the Passwords: A Recovery Guide

It usually surfaces on a Tuesday. Someone needs to reset a password, or add a new hire to the accounting system, or renew the domain, and the person who set all of it up is gone. Sometimes they left on good terms. Sometimes they left on Friday and stopped answering the phone on Monday.

Either way you are now locked out of systems you own and pay for, and nobody in the building knows how deep the problem goes.

Here is how to work through it.

You probably control more than you think

Before you assume the worst, inventory what you can still get into. Most businesses in this situation still hold at least one of the following, and any one of them is a foothold.

  • The email account that receives billing and renewal notices, which is often the owner’s
  • The credit card the services are billed to, which proves account ownership to most vendors
  • A second administrator account somebody created years ago and forgot
  • Physical access to the server, firewall, or network closet
  • The registrar account for your domain name, or at least the email on file for it

Write down what you can access and what you cannot. That list is the actual scope of the problem, and it is usually smaller than the panic suggests.

Answer one question before you do anything else

Was this person an employee or a vendor?

It changes your options substantially. An employee who walked off with credentials to systems the business owns is one situation. An outside IT provider who is holding access pending a final invoice is a different one, and the path through it is usually commercial rather than technical.

Worth saying plainly, and this is not legal advice: your data and your accounts belong to your business regardless of who configured them. A dispute over an unpaid invoice does not transfer ownership of your Microsoft tenant or your domain name. If someone is treating access as leverage, that is a conversation for your attorney, and it is worth having early rather than after you have paid to make it go away.

In practice, pursue the technical recovery path and the legal one at the same time. Litigation is slow. Vendor account recovery is often faster than people expect.

The first twenty four hours

  1. Secure the domain name first. It is the keystone. Whoever controls your domain controls where your email goes, and email controls password resets for nearly everything else. Log into your registrar if you can. If you cannot, registrars have an account recovery process that generally turns on proving you are the registered organization, using billing records and business documentation.
  2. Then the email tenant. Microsoft and Google both have documented processes for regaining administrative control of a tenant your organization owns but cannot access. They are deliberately slow and they hinge on proving control of the domain through a DNS record, which is why the domain comes first.
  3. Change what you can reach right now. Every account you can still log into, starting with anything financial. Turn on multi-factor authentication as you go.
  4. Cut physical and remote access. Remote access tools, VPN accounts, and any keys or badges. If there is a remote monitoring agent on your machines that you did not knowingly install, find out what it is before you remove it, because some of it may be doing work you still need.
  5. Write down what you find as you find it. You are rebuilding documentation that never existed. Do it now while you are already looking.

What this usually reveals

The lockout is rarely the real finding. What surfaces is that one person held the entire environment in their head, and that no one had ever asked which accounts existed, who paid for them, or what would happen if that person got hit by a bus.

We see the same handful of things almost every time. Services billed to a personal credit card. A domain registered under an individual’s name rather than the company’s. Administrator accounts belonging to people who left two jobs ago. No record of which vendor supports which system. Backups that someone set up once and nobody has verified since.

None of that is unusual and none of it means you were careless. It is what happens when a business grows faster than its documentation.

So it does not happen twice

Four things, and none of them are expensive.

Keep an ownership register. A simple list of every service, what it costs, who the vendor is, which account it bills to, and who has administrative access. Review it twice a year. This one document prevents most of the pain described above.

Create a break glass account. A separate administrator account that belongs to the business rather than to a person, with the credentials stored somewhere the owner can reach without asking anyone. Used almost never, worth everything on the day you need it.

Register domains and critical services to the company. Company name, company billing, a role based email address like accounts or admin rather than one person’s inbox.

Write down the offboarding steps before you need them. Access revoked within twenty four hours, credentials rotated, sessions terminated, and someone signing off that it happened. If you are in a regulated industry this is a control you are already required to have, so you may as well get the operational benefit from it.

The Arizona version of this

Across the East Valley there are a lot of ten to fifty person firms that grew up with one trusted technical person handling everything. It works well, right up until it does not. If your practice or firm handles patient records, tax files, or anything covered by a DoD contract, the same gap that locks you out of your own systems is also a compliance finding. Access control and account management are explicit requirements under HIPAA, the FTC Safeguards Rule, and NIST 800-171 alike.

Which means fixing this is not overhead. It is work you were required to do anyway.

If you are in the middle of this right now

We do emergency access recovery and documentation rebuilds, and we have untangled this more than once. Tell us what you can still log into and we will tell you what is recoverable and roughly how long it takes.

Get fifteen minutes, or see how we handle IT for Arizona businesses.

Scroll to Top