The short answer

Whoever is named on each account and holds the admin login, and that is not always the business paying the bills. For a .au domain, the licence holder is whoever the auDA WHOIS record names, regardless of who pays the renewals or knows the password. Eight keys matter most: your domain, DNS, website, Microsoft 365, network, backups, business software, and your phone numbers and online profiles. Most keys that have drifted come back after one polite conversation, and you can check all of them in an afternoon.

It usually starts with something small. The website needs a new page. A domain renewal notice never arrived. A new starter needs adding to a system nobody has logged into for a while. Someone asks, quite reasonably, “who has the login for that?” and the room goes quiet.

The answer is often a web designer you have not spoken to in years, a staff member who has since left, a previous IT provider, or the personal email address of whoever set things up when the business started. Nobody did anything wrong. Things were set up quickly, by whoever was available, and the business grew around them.

Most of the time it does not matter. It matters on the day you need the key and cannot reach the person holding it, and that is rarely a quiet day. It is the day the website goes down, a key person resigns, you change providers, or a buyer’s accountant asks you to prove the business owns its assets.

Owning it and holding the key are not the same thing

Ask most owners whether they own their domain name, their website and their Microsoft 365 account, and they will say yes without hesitating. They pay the invoices, after all.

But paying and controlling are two different things. For every system the business relies on, two questions matter: whose name is on it, the legal account holder, or for a domain, the registrant; and who can get in, whose login, tied to whose email address, has the administrator rights to change it.

Domain names show the gap most clearly. auDA, which administers the .au domain, allows a web developer to register a .com.au on your behalf with your explicit written permission. It also says they should use your details, including your ABN, because those details determine who holds the domain name licence. And it is blunt about the result when they do not: if your company name is not in the WHOIS record, you are not recorded as the licence holder, even if you have the passwords and access.

So a Dandenong manufacturer can pay for its domain every year for a decade and still not hold it.

The eight keys every business should account for

The keyWhat it controlsWhere it often ends up
Domain nameYour web address and your email addresses. If it lapses, both stop working.Registered by a web designer or previous provider, or renewal notices going to someone who has left.
DNSWhere your website and email point, and the records that stop scammers sending email in your name.A separate hosting or DNS account that nobody remembers setting up.
Website and hostingYour website content and the server it runs on.The web designer’s hosting account and admin login.
Microsoft 365Email, files, Teams and every staff account. A Global Administrator can change anything.The first person who signed up, a former staff member, or a previous IT company.
Network and internetYour firewall, Wi-Fi, router and internet service account.Default passwords on a sticker, or the installer’s account.
BackupsThe copies of your data and the ability to restore them.A vendor or previous provider’s console.
Business softwareAccounting, payroll, CRM, and practice or job management systems.One staff member as the only administrator.
Phone numbers and online profilesYour business phone numbers, Google Business Profile, and Facebook and LinkedIn pages.A carrier account in one person’s name, or a page run from someone’s personal profile.

Microsoft 365. The account used to sign up for Microsoft 365 automatically becomes a Global Administrator, with control over every user and setting. Microsoft recommends at least two emergency access accounts, sometimes called “break glass” accounts, that are not assigned to any one person and are only used when normal admin access fails. It also recommends keeping the Global Administrator role to fewer than five people. If you have changed IT support companies at any point, it is worth checking which partners still have admin rights: a Global Administrator can see this under Settings > Partner relationships in the Microsoft 365 admin centre, and can remove a partner’s roles there.

DNS. The company your domain is registered with and the company that hosts your DNS are often two different businesses. Both are keys. DNS is also where the records that protect your email live, which we covered in how to stop scammers sending email in your business name.

Phone numbers. If your numbers sit in an account under one person’s name, that person is usually the one who has to authorise any change, including moving the numbers to a new provider. Make sure the account holder is the business.

Online profiles. Your Google Business Profile, Facebook page and LinkedIn page are part of how customers find you. Make sure at least two current team members have admin access, so the page does not depend on one person’s personal account.

Where the keys usually end up

When we look at who holds what, whether for a Frankston accounting practice or a Peninsula trades business, the same few places come up again and again: the web designer who registered the domain in their own name to get the site live quickly; a staff member who was good with computers and set things up using their own email address, and has since moved on; a previous managed services provider that held the admin login and was never asked to hand it back; the owner’s personal email address, used on day one of the business and never changed; a family member or friend who helped out in the early years.

None of these is a scandal. Almost all of them started with someone being helpful. The problem is that the business’s ability to operate now depends on the goodwill and availability of someone who does not work there.

How to check, in an afternoon

You do not need technical skills for most of this. You need a list, a few lookups and some emails.

1. Look up your domain. Go to the .au WHOIS tool and check the Registrant and Registrant ID fields. They should show your business and its ABN or ACN. While you are there, check that the registrant contact email is one you actually monitor. For a .com or other international domain, ask your domain provider who the registrant is.

2. Check your Microsoft 365 administrators. List everyone with the Global Administrator role, and check Settings > Partner relationships for any IT partners with admin access.

3. List every subscription. Three months of card statements will surface almost every recurring service, the same approach we described in why bad onboarding causes messy offboarding. For each one, note who holds the admin login and which email address it is tied to.

4. Ask each supplier one question, in writing. “Who is the account holder, and who has administrator access?” Keep the replies.

5. Write it all down in one register. Download our free Keys Register and work through it; it also includes supplier and software sheets for when you are ready to go further. Record who holds each key, never the passwords themselves. Passwords belong in a business password manager that the business, not one person, owns.

Expect a few surprises. That is normal, and finding them on a quiet afternoon is much better than finding them during an outage.

Getting a key back without a fight

Start with a conversation. Most people holding a key for you will hand it back willingly when asked, and many will be relieved to be rid of the responsibility.

Put the request in writing. Be specific about what you need: for example, the domain registrant changed to your business entity and ABN, or admin access moved to an account your business controls.

Use the proper process for .au domains. If your domain was registered in a developer’s name by mistake, auDA says you can request a correction. Your domain provider can walk you through it.

Close the old door. Once you hold the key, change the password and remove the previous holder’s admin access. A handover is not finished while the old login still works.

Get advice if it has become a dispute. If the relationship has broken down, or there is real money involved, speak to a lawyer before you act.

The best time to do all of this is now, while everyone is still on good terms. It is far harder to sort out after a falling out, or on the day something breaks.

What good looks like

The business is the legal holder of every key: your entity and your ABN, not a supplier’s or an individual’s. Admin logins use business-owned email addresses, ideally role-based ones such as admin@, rather than one person’s inbox or a personal Gmail. Renewal notices cannot get lost: for your domain, add a second contact address that does not depend on the domain itself, because if the domain lapses, emails to that domain stop arriving too, including the renewal reminder. At least two people can get in to every critical system, and for Microsoft 365 that includes emergency access accounts not tied to any one person. Multi-factor authentication is on for every admin account. There is one register of every key, reviewed whenever someone leaves, a supplier changes, or at least once a year. And your IT partner manages access on your behalf, and can show you, at any time, where every key sits and who can use it.

Where Agile IT fits

“Your Business IT, Our Responsibility” means we take responsibility for managing your technology. It does not mean we take ownership of it. We have said it before when writing about switching managed IT providers: you should hold the master credentials, not your provider.

We need admin access to do our job well. We should never be the only way in. A good IT partner should be able to tell you, at any time, where each of your keys sits and who can use it. If yours cannot, that is worth a conversation. Whether your IT support comes from a managed services provider like us, a one-person computer support business, or someone internal, the test is the same: they manage access on your behalf, never instead of you.

Working through a register like this, and closing the gaps it finds, is a standing policy step in our AgileSTRATEGY business reviews: any key held outside the business becomes a recorded risk with a recommendation. If you run your own IT, the register works just as well without us, and AgileASSURE is there if you want a second set of eyes. We look after businesses of 5 to 50 staff across Melbourne and the Mornington Peninsula. If you are not sure who holds your keys, start with a conversation.

Frequently asked questions

How do I check who owns my .com.au domain name?
Search for it on auDA’s .au WHOIS tool at whois.auda.org.au. The Registrant field shows who holds the domain name licence, and the Registrant ID shows their ABN or other identifier. If that is not your business, you are not the recorded licence holder, even if you pay the renewals.
Our web designer registered our domain. Is that a problem?
Not necessarily. auDA allows a developer to register a .au domain for you with your written permission, as long as they use your business details. It becomes a problem if they used their own details, because the licence then sits with them and the renewal notices go to them. If that has happened, you can ask for it to be corrected.
How many people should have admin access to Microsoft 365?
Fewer than you might think. Microsoft recommends keeping the Global Administrator role to fewer than five people, plus two emergency access accounts that are not assigned to any individual. Every admin account should have multi-factor authentication switched on.
Should our IT provider have our admin passwords?
Your provider needs admin access to manage your systems, ideally through its own named accounts or Microsoft’s partner access, so every action can be traced. What matters is that your business also keeps its own independent admin access and never relies on the provider as the only way in.
Should we write passwords in the keys register?
No. The register records who holds each key and where the login is kept. The passwords themselves belong in a business-owned password manager with multi-factor authentication switched on.