Skip to content
Exchange & EmailProject guide

Moving Off GoDaddy Microsoft 365: How Defederation Actually Works

GoDaddy-hosted Microsoft 365 isn't a normal tenant. Here's what's different, the two ways out, and the traps that delete mailboxes or lock everyone out.

If your company bought Microsoft 365 through GoDaddy, you have a real Microsoft 365 tenant, but GoDaddy sits in front of it. They control the admin experience, hold the global admin role, and in most cases your domain is federated to GoDaddy's sign-in system. That's why you can't reach half the admin center, and why "just cancel GoDaddy and buy direct" is the fastest way to lose your company's email.

This runbook explains what's going on under the hood, the two paths out, and the order of operations that keeps mail flowing.

Why GoDaddy tenants are different

A normal Microsoft 365 tenant authenticates users directly against Microsoft Entra ID. A GoDaddy tenant is usually set up differently:

  • The domain is federated. Sign-ins for you@yourcompany.com are redirected to GoDaddy's identity service, which is why the login page looks like GoDaddy, not Microsoft.
  • GoDaddy is the licensing partner. The licenses are billed through GoDaddy as a Microsoft partner. If you cancel the GoDaddy subscription, the licenses go away, and once the licenses are gone, the mailboxes eventually go with them.
  • Your admin access is limited. GoDaddy's portal exposes a simplified view. Many settings, including Conditional Access, Intune, and parts of Exchange Online, are hard or impossible to reach.
  • Passwords live at GoDaddy. Because authentication is federated, Microsoft doesn't hold usable passwords for your users. When federation is removed, every user needs a new password.

Check what you actually have

Before choosing a path, confirm how your tenant is set up. From any PC, check whether the domain is federated:

text
https://login.microsoftonline.com/getuserrealm.srf?login=user@yourcompany.com&xml=1

Look at NameSpaceType. Federated means sign-ins go through GoDaddy. Managed means Microsoft handles authentication directly, which makes the move much simpler.

Then gather the basics:

  • Number of users and shared mailboxes, and total mailbox size
  • Which licenses you're paying for (Business Basic, Standard, or Premium)
  • Who has access to your domain's DNS (often GoDaddy too, but not always)
  • Whether anyone uses OneDrive, SharePoint, or Teams heavily, not just email

Path 1: Defederate and keep the tenant

You keep the same tenant and mailboxes and remove GoDaddy from the picture. No mail is copied anywhere.

At a high level:

  1. Get admin control. Create a new global admin account on the tenant's .onmicrosoft.com domain that isn't federated, and make sure you can sign in with it.
  2. Buy replacement licenses directly from Microsoft or another partner, and assign them alongside the GoDaddy licenses.
  3. Convert the domain from federated to managed authentication, which removes GoDaddy's sign-in service.
  4. Reset every user's password and get everyone signed back in on Outlook, phones, and Teams.
  5. Remove GoDaddy's licenses and partner relationship, then cancel the GoDaddy subscription.

Pros: no mailbox migration, no Outlook profile rebuilds, fast. Cons: there's a hard cutover moment where every user needs a new password, and you inherit whatever GoDaddy configured (or didn't).

Path 2: Migrate to a fresh tenant

You create a brand-new Microsoft 365 tenant that you own from day one, migrate mail, calendars, and contacts into it with a migration tool, then move the domain over.

Pros: a clean tenant with no GoDaddy leftovers, and a chance to set up security properly from day one. Cons: more work. The domain can only exist in one tenant at a time, so there's a cutover window, and users get new Outlook profiles.

Cutover-day traps

These are the issues that turn a Friday-evening cutover into a Monday-morning outage:

  • Phones stop syncing. After a password reset, mobile mail apps quietly fail until someone re-enters the password. Tell users in advance, in writing.
  • Shared mailboxes and delegates. Permissions survive defederation, but anyone signed in only through GoDaddy's portal may lose access to things they didn't realize they had.
  • MFA registration. Users who had MFA through GoDaddy need to register again with Microsoft. Plan that rollout; don't let users discover it at sign-in.
  • DNS TTLs. If the move involves DNS changes, lower the TTLs days ahead, not the same afternoon.
  • Scanners and apps that send mail. Copiers, line-of-business apps, and website forms that send through Microsoft 365 with a stored password will break silently.

After the move

Once GoDaddy is out of the picture, you finally have a full tenant, and it's usually running on defaults. At a minimum, plan to:

// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.