If your company bought Microsoft 365 through GoDaddy, you have a real Microsoft 365 tenant, but GoDaddy sits in front of it. They control the admin experience, hold the global admin role, and in most cases your domain is federated to GoDaddy's sign-in system. That's why you can't reach half the admin center, and why "just cancel GoDaddy and buy direct" is the fastest way to lose your company's email.
This runbook explains what's going on under the hood, the two paths out, and the order of operations that keeps mail flowing.
Why GoDaddy tenants are different
A normal Microsoft 365 tenant authenticates users directly against Microsoft Entra ID. A GoDaddy tenant is usually set up differently:
- The domain is federated. Sign-ins for
you@yourcompany.comare redirected to GoDaddy's identity service, which is why the login page looks like GoDaddy, not Microsoft. - GoDaddy is the licensing partner. The licenses are billed through GoDaddy as a Microsoft partner. If you cancel the GoDaddy subscription, the licenses go away, and once the licenses are gone, the mailboxes eventually go with them.
- Your admin access is limited. GoDaddy's portal exposes a simplified view. Many settings, including Conditional Access, Intune, and parts of Exchange Online, are hard or impossible to reach.
- Passwords live at GoDaddy. Because authentication is federated, Microsoft doesn't hold usable passwords for your users. When federation is removed, every user needs a new password.
Check what you actually have
Before choosing a path, confirm how your tenant is set up. From any PC, check whether the domain is federated:
https://login.microsoftonline.com/getuserrealm.srf?login=user@yourcompany.com&xml=1Look at NameSpaceType. Federated means sign-ins go through GoDaddy. Managed means Microsoft handles authentication directly, which makes the move much simpler.
Then gather the basics:
- Number of users and shared mailboxes, and total mailbox size
- Which licenses you're paying for (Business Basic, Standard, or Premium)
- Who has access to your domain's DNS (often GoDaddy too, but not always)
- Whether anyone uses OneDrive, SharePoint, or Teams heavily, not just email
Path 1: Defederate and keep the tenant
You keep the same tenant and mailboxes and remove GoDaddy from the picture. No mail is copied anywhere.
At a high level:
- Get admin control. Create a new global admin account on the tenant's
.onmicrosoft.comdomain that isn't federated, and make sure you can sign in with it. - Buy replacement licenses directly from Microsoft or another partner, and assign them alongside the GoDaddy licenses.
- Convert the domain from federated to managed authentication, which removes GoDaddy's sign-in service.
- Reset every user's password and get everyone signed back in on Outlook, phones, and Teams.
- Remove GoDaddy's licenses and partner relationship, then cancel the GoDaddy subscription.
Pros: no mailbox migration, no Outlook profile rebuilds, fast. Cons: there's a hard cutover moment where every user needs a new password, and you inherit whatever GoDaddy configured (or didn't).
Path 2: Migrate to a fresh tenant
You create a brand-new Microsoft 365 tenant that you own from day one, migrate mail, calendars, and contacts into it with a migration tool, then move the domain over.
Pros: a clean tenant with no GoDaddy leftovers, and a chance to set up security properly from day one. Cons: more work. The domain can only exist in one tenant at a time, so there's a cutover window, and users get new Outlook profiles.
Cutover-day traps
These are the issues that turn a Friday-evening cutover into a Monday-morning outage:
- Phones stop syncing. After a password reset, mobile mail apps quietly fail until someone re-enters the password. Tell users in advance, in writing.
- Shared mailboxes and delegates. Permissions survive defederation, but anyone signed in only through GoDaddy's portal may lose access to things they didn't realize they had.
- MFA registration. Users who had MFA through GoDaddy need to register again with Microsoft. Plan that rollout; don't let users discover it at sign-in.
- DNS TTLs. If the move involves DNS changes, lower the TTLs days ahead, not the same afternoon.
- Scanners and apps that send mail. Copiers, line-of-business apps, and website forms that send through Microsoft 365 with a stored password will break silently.
After the move
Once GoDaddy is out of the picture, you finally have a full tenant, and it's usually running on defaults. At a minimum, plan to:
- Set up SPF, DKIM, and DMARC properly (see SPF, DKIM, and DMARC for Microsoft 365).
- Turn on MFA for everyone and block legacy authentication (see MFA rollout without lockouts).
- Review who has admin roles, and create break-glass accounts.