Insights/Operational Resilience

When a North Texas Business Changes Hands, the Buyer Inherits Every Forgotten Password

Published July 19, 2026Updated July 19, 2026

In Brief

  • Financial due diligence establishes what a company owns. It does not establish whether a buyer can log in, make changes, restore data or remove the previous owner's access — and those are the capabilities that determine whether the business runs after closing.
  • The technology assets most likely to disrupt a transition are the ones least likely to appear in a schedule of assets: domain registrations, administrator accounts, vendor portals, backup jobs and carrier contracts.
  • Control transfers through verification, not through assurance. The seller's confidence that something works is not evidence that it works, and closing day is a poor time to discover the difference.

Executive Summary

Acquisitions in North Texas are typically well advised on the financial and legal side. Quality of earnings gets scrutinized. Leases get reviewed. Customer contracts get read closely. The technology environment, when it is examined at all, is usually reduced to a line item — a list of computers, a software inventory, perhaps a note that the company uses Microsoft 365.

That treatment misses the actual risk. The risk in a technology transition is rarely that the equipment is old. It is that operational control of the systems sits somewhere the buyer does not own and cannot reach: a domain registered under a departing owner's personal email, a Microsoft tenant whose only global administrator left eighteen months ago, a backup job running under an MSP agreement that terminates with the seller, a main business phone number attached to a personal carrier account.

None of that shows up in financial diligence, because none of it is an ownership question. It is a control question. And control is what a buyer needs on the first Monday after closing.

The distinction has practical consequences. A buyer who owns a domain but cannot access the registrar account cannot change email routing, cannot renew the registration and cannot stop a former owner from redirecting the website. A buyer who inherits a Microsoft 365 environment with no documented administrator cannot onboard employees, cannot revoke departed users and cannot respond to a security incident. These are not edge cases. They are the ordinary consequence of treating technology as an asset schedule rather than as a set of controls.

The remedy is not complicated, but it has to happen before the wire goes out. This piece sets out what buyers actually inherit, what has to be verified rather than represented, and a structure — the Technology Control Transfer — for working through it in the weeks before closing rather than the weeks after.

Direct Answer

What should a buyer review before acquiring a business, and why does technology matter? Because financial due diligence confirms what a company owns while technology due diligence determines whether the buyer can control and operate it. Those are different questions with different answers. Ownership passes by contract at closing; administrative control passes only when specific accounts, credentials, registrar records, tenant roles, vendor relationships and recovery systems are identified, transferred and independently verified. A buyer who skips the second question can acquire full legal title to a business and still be locked out of the systems that run it — unable to route email, restore a file, remove a former employee's access or prove to an insurer that controls exist. The practical implication is that technology review belongs in the diligence period alongside financial and legal work, not in the integration phase after closing, because the seller's cooperation, the departing staff's knowledge and the leverage of an unsigned agreement are all available before closing and diminish sharply afterward.

Executive Summary Table

Business Issue

What the Buyer Assumes

What Is Often True

Consequence at Closing

Leadership Action

Domain and web presence

The company owns its domain

Registered to a personal account or a former vendor

Cannot control email routing or the website

Confirm registrar account control before closing

Email and productivity

Administrator access comes with the business

No documented global administrator

Cannot onboard, offboard or investigate

Identify and document tenant administrators

Data protection

Backups exist and work

Backups run under the seller's vendor agreement

Backup coverage lapses on the termination date

Verify a restore, not a backup report

Vendor relationships

Contracts assign automatically

Many require consent or are personally held

Service interruption or renegotiation under pressure

Inventory contracts and assignment terms early

Access after closing

Former staff lose access at closing

Accounts persist in systems nobody inventoried

Unmonitored access to company data

Build a revocation list before day one

Definitions Worth Agreeing On Early

Technology due diligence is the pre-closing review of whether a buyer will be able to operate, administer and recover the systems a business depends on — distinct from an inventory of technology assets.

Administrative control is the practical ability to change a system's configuration, access and permissions. It is held by whoever possesses the credentials and roles, which is not necessarily whoever owns the asset.

Registrant is the legal holder of a domain name, recorded with the registrar. The registrant may differ from whoever pays for or manages the domain.

Privileged account is any account with elevated rights — global administrator, domain administrator, firewall administrator, root — capable of changing a system's security posture.

Restoration test is the act of recovering data from backup and confirming the recovered data is complete and usable. A successful backup job is not a restoration test.

What Buyers Actually Inherit

Consider a scenario common enough across Dallas, Fort Worth and the surrounding counties to be unremarkable: a profitable, thirty-year-old specialty contractor in Tarrant County with sixty employees and a founder who has decided to retire. The financials are clean. The customer relationships are durable. The deal closes on a Friday.

On Monday, the buyer's operations lead tries to add a new project manager to the email system and discovers no one present has the rights to do it. The founder's son-in-law set up Microsoft 365 in 2018 and has not worked at the company since 2021. His account is still the only global administrator, and it is secured with multi-factor authentication tied to a phone number that is no longer in service.

By Wednesday the list has grown. The domain is registered to the founder's personal email address at a registrar nobody at the company has logged into in six years. The accounting system's nightly backup runs through the outgoing MSP, whose agreement was with the founder personally and terminates at the end of the month. The main phone number — printed on every truck, every invoice and every job sign in three counties — sits on a carrier account in the founder's name. The website is maintained by a marketing agency that has the only copy of the content management credentials and has not been paid since April.

Not one of these facts appeared in financial diligence, because not one of them is a financial fact. The company genuinely owned its data, its systems and its goodwill. What it did not have — and what the buyer therefore did not acquire — was documented, transferable control over the mechanisms that make those things usable.

A buyer can own the company and still lack control of the systems required to operate it.

The founder is not being obstructive in this scenario. He is retired, traveling, and genuinely unsure which email address he used in 2018. That is the ordinary case. Adversarial sellers are a real but secondary problem; the common problem is undocumented control held by people who have left, forgotten or moved on.

The Technology Assets Missing From the Balance Sheet

Asset schedules capture things that were purchased. Control lives in things that were configured. The gap between those two categories is where transitions fail.

Identity infrastructure. Microsoft 365 and Google Workspace tenants, the administrator roles inside them, conditional access policies, and the multi-factor authentication methods bound to privileged accounts. A tenant is not transferred so much as it is taken over, and taking it over requires a person who currently holds administrative rights to grant them to someone else.

Namespace and routing. Domain registrations, DNS hosting, and the records that direct email and web traffic. These are frequently split across three providers with three different accounts and three different owners, only one of which anyone remembers.

Vendor and MSP relationships. The outgoing managed service provider often holds remote monitoring agents, administrative credentials, backup infrastructure and documentation. The relationship may be contractual with the entity, personal with the owner, or informal. Each transfers differently, and one of them does not transfer at all.

Network and perimeter. Firewalls, switches and wireless controllers hold configurations that took years to accumulate and are typically documented nowhere. Administrative passwords are often shared, unchanged since installation, and known to former employees and former vendors.

Line-of-business systems. Accounting, estimating, dispatch, practice management, ERP. These frequently have their own user directories, their own administrator accounts and their own vendor relationships, entirely separate from the company's primary identity system.

Communications. Phone numbers, carrier accounts, hosted voice platforms, text-message capability. Business phone numbers are portable, but porting requires an authorized account holder and a matching service address, and a number tied to a personal account creates a dependency on an individual's cooperation after they have stopped being an employee.

Public-facing accounts. Website hosting, content management, social profiles, review platforms, payment processors and merchant gateways. Payment systems in particular tend to be bound to an individual's identity for underwriting reasons, which means they may need to be re-established rather than transferred.

Common Acquisition Misconceptions

"The purchase agreement transfers everything, so access will follow." A purchase agreement can transfer title to an asset without transferring the ability to use it. A domain name can be legally assigned to the buyer while the registrar account that controls it remains under someone else's login. Legal ownership and administrative control are separate, and only one of them is self-executing.

"The seller will help after closing." Sellers usually intend to. Their availability, recall and motivation all decline steeply once the proceeds have cleared, and any transition-services obligation left vague in the agreement becomes difficult to enforce over a forgotten password. Cooperation is most reliable when it is scheduled before closing and specified in writing.

"We will change all the passwords on day one." This is the right instinct applied at the wrong point in the sequence. You cannot change credentials for systems you have not yet discovered, and the discovery exercise is the hard part. A password reset campaign against an incomplete inventory produces a false sense of completion while leaving the unknown accounts untouched.

"The MSP will simply keep working." The outgoing provider's contract may terminate on the change of control, may be personally held by the seller, or may contain assignment restrictions. Where the relationship does continue, it continues on terms negotiated by someone else for a different business. Neither outcome is a plan.

"Changing the domain registrant is a quick administrative step." Under ICANN's Transfer Policy, registrars must apply a sixty-day lock preventing transfer to another registrar following a change to the registrant's name, organization or email address. Sequencing matters: a well-intentioned update to registrant details immediately after closing can prevent the buyer from moving the domain to their own registrar for two months. This is the kind of detail that is trivial when planned and disruptive when discovered.

The Metro Relay Technology Control Transfer

Control does not transfer as a single event. It transfers across seven distinct areas, each with its own mechanics, and each requiring the same four-part discipline: identify what exists, transfer what can be transferred, verify independently rather than accepting representation, and change what must not persist past closing.

The verification step is the one most often skipped and the one that most often matters. A seller can state in good faith that backups run nightly. That statement is compatible with backups that have been failing silently since a server was replaced. The only way to know is to restore something and look at it.

Executive Table: The Seven Control Areas

Control Area

Identify

Transfer

Verify Independently

Change Immediately After Closing

Identity

Every tenant, directory and administrator role; MFA methods bound to privileged accounts

Global administrator rights to a named buyer-side individual

Log in as an administrator and add, then remove, a test account

Rotate privileged credentials; re-enroll MFA; remove seller-side admins

Infrastructure

Firewalls, switches, wireless controllers, servers, hypervisors, remote access

Administrative credentials and configuration backups

Authenticate to each device and export a current configuration

Change device administrator passwords; revoke old VPN and remote-access accounts

Data

Where business records live, who can reach them, what retention obligations apply

Ownership of storage locations and file shares

Confirm the buyer can read, write and audit access in each location

Remove standing access for departed staff and outside parties

Vendors

Every technology vendor, what access each holds, and assignment terms

Contracts assigned or renegotiated in the buyer's name

Ask each vendor to confirm, in writing, who they take instruction from

Terminate access for vendors not continuing; re-paper those that are

Licenses

Software entitlements, seat counts, transferability

License agreements reissued to the acquiring entity

Reconcile licensed seats against actual users

Reclaim licenses assigned to departed users

Recovery

What is backed up, how often, where copies sit, who controls the backup platform

The backup platform account and its administrative rights

Perform a restoration test and inspect the recovered data

Re-establish backups under buyer-controlled accounts and credentials

Evidence

Documentation, network diagrams, runbooks, insurance representations

Written records rather than institutional memory

Confirm documentation matches what is actually deployed

Record the closing-day state as a baseline for future change

The framework is deliberately ordered. Identity comes first because it governs access to nearly everything else; a buyer who secures administrative control of the identity platform is positioned to work through the remaining six areas. Evidence comes last because it is cumulative — it is the record of what the other six areas established, and it is what an insurer, a lender or a future buyer will eventually ask to see.

What Must Be Verified Before Closing

Verification differs from disclosure. Disclosure is the seller telling the buyer what exists. Verification is the buyer confirming it independently. A workable pre-closing sequence:

Confirm the registrant of record for every domain the business uses, including the ones nobody mentions — the misspelling registered defensively, the domain from the acquisition three years ago, the one used only for email. Confirm who can log into each registrar account.

Establish that at least one global administrator account in each identity platform is accessible to a person who will remain after closing, and that the multi-factor method attached to it is one the buyer can control. This single step prevents a substantial share of transition failures.

Obtain a written vendor list with the access each vendor holds and the assignment terms of each agreement. Where an MSP is involved, request the documentation the provider maintains — network diagrams, credential inventories, backup configurations — and treat its absence as a material finding, because it is one.

Test a restoration. Choose a file or a database from a meaningful system, restore it, open it, and confirm it is complete and current. A backup report is a claim about the past. A restoration is a demonstration of capability.

Reconcile the software inventory against actual usage. Unlicensed deployments and orphaned subscriptions both create post-closing cost, and both are easier to negotiate before the price is fixed.

Confirm what the cyber-insurance application will require. Policies increasingly condition coverage on specific controls, and a buyer who discovers a gap after binding coverage is in a materially worse position than one who discovers it during diligence.

What Must Change Immediately After Closing

Some actions should not wait for an integration plan. Privileged credentials across identity platforms, firewalls, network devices and line-of-business systems should be rotated on a defined schedule beginning at closing. Multi-factor authentication for privileged accounts should be re-enrolled to devices the buyer controls.

Access for departing individuals — the seller, family members, former employees still carried in systems, and vendors not continuing — should be revoked against a list built during diligence rather than assembled from memory afterward. Backups should be re-established under buyer-controlled accounts so that coverage does not depend on a terminating agreement. Remote-access paths, including any left open for the outgoing MSP, should be closed or reissued.

The closing-day configuration should be documented as a baseline. It is the reference point for every subsequent change, and it is the artifact that makes the next transition — an integration, a system replacement, an eventual sale — substantially easier.

Metro Relay Observations

  • The control problems that surface after closing are almost never caused by malice. They are caused by documentation that was never created, held by people who have since left.
  • Identity is the highest-leverage area to resolve first. Administrative control of the identity platform makes most other problems tractable; without it, most other problems compound.
  • Backup verification produces findings at a rate that surprises most buyers, because backup software reports success on the job it was configured to run, not on the data the business actually depends on now.
  • Phone numbers and payment systems generate disproportionate disruption relative to their apparent simplicity, because both are frequently bound to an individual rather than an entity.
  • The cost of resolving these questions before closing is consistently lower than the cost of resolving them afterward, for the straightforward reason that leverage and cooperation are both higher before the transaction completes.

Leadership Considerations

For a buyer, the decision is about sequencing rather than spending. Technology control review is inexpensive relative to transaction costs and is most valuable in the window when the seller is still engaged. Moving it into that window is largely a matter of adding it to the diligence checklist.

For a seller, the same review is a value-protection measure. A business whose technology control is documented, whose administrator accounts are known, whose vendor agreements are assignable and whose backups demonstrably restore is a cleaner asset. Buyers discount uncertainty, and a seller who can answer these questions crisply removes a source of late-stage friction and price adjustment.

For both, the useful framing is that this is an operational readiness question, not a technology-quality question. The systems can be modern and well maintained and still be uncontrollable by the buyer. The systems can be dated and still transfer cleanly. What matters is whether control is documented, transferable and verified.

Strategic Recommendations

Begin technology control review when financial diligence begins, not after the letter of intent has been signed and certainly not after closing. The findings frequently affect deal terms, and terms are easier to adjust before they are agreed.

Name a single accountable individual on the buyer's side who will hold administrative control at closing. Diffuse responsibility for privileged access reliably produces the situation where nobody holds it.

Treat the seven control areas as a checklist with an evidence requirement attached to each. For every area, the standard is not "the seller says this is handled" but "we confirmed it ourselves."

Negotiate transition assistance in specific terms — named individuals, defined duration, enumerated systems — rather than as a general cooperation clause. General clauses are unenforceable in practice against a retired founder who cannot remember a password.

Build the post-closing revocation list during diligence. It is easier to compile while people are available to ask, and it is the difference between a controlled cutover and an open-ended exposure.

Document the closing-day state and keep it current. The baseline created at transition is the foundation for continuing operations, insurance representations and the eventual next transaction.

Conclusion

The most consequential technology risk in an acquisition is not obsolescence. It is the quiet gap between owning a system and being able to operate it. That gap is invisible in financial diligence because it is not a financial question, and it becomes visible on the first business day after closing, when someone tries to add a user, restore a file or change where email is delivered and discovers that the person who could do that is no longer reachable.

The seven control areas — identity, infrastructure, data, vendors, licenses, recovery and evidence — are not exotic. They are the ordinary surface area of a functioning business. What makes the difference is treating each of them as something to verify rather than something to assume, and doing that verification while the seller is still at the table.

Buyers and sellers across Dallas, Fort Worth, Plano, Frisco, McKinney and the wider North Texas market are transacting at a healthy pace. The businesses changing hands are, for the most part, well run. The control questions are answerable. They simply have to be asked early enough to matter.

Key Takeaways

  • Financial due diligence confirms ownership; technology due diligence confirms operability. A buyer needs both, and only one of them is standard practice.
  • The highest-risk technology assets are usually absent from the asset schedule: domains, administrator roles, vendor portals, backup platforms and carrier accounts.
  • Administrative control does not transfer automatically with legal title. It transfers only when specific credentials and roles are moved to named people on the buyer's side.
  • Verification means testing, not asking. Restore a file rather than reading a backup report; log in as an administrator rather than accepting an assurance that access exists.
  • Sequencing matters in specific technical ways — including that a change to domain registrant details triggers a sixty-day registrar transfer lock under ICANN policy.
  • The post-closing revocation list should be built during diligence, while the people who know the answers are still available to ask.
  • Sellers who can document technology control present a cleaner asset and face less late-stage price friction.
  • Work through the seven control areas — identity, infrastructure, data, vendors, licenses, recovery, evidence — before the wire goes out, not after.

Frequently Asked Questions

What is technology due diligence in an acquisition? The pre-closing review of whether a buyer will be able to operate, administer and recover the systems the business depends on. It examines who holds administrative control of identity platforms, domains, network equipment, vendor relationships and backups — and whether that control can be transferred to the buyer. It answers a different question than an asset inventory, which establishes what was purchased rather than who can currently change it.

How is technology due diligence different from an IT assessment? An IT assessment evaluates quality: whether systems are current, well configured and appropriately sized. Technology due diligence evaluates transferability: whether the buyer can take control of them. A well-maintained environment can be nearly impossible to take over, and a dated one can transfer cleanly. In a transaction, transferability is the more urgent question, because it determines whether the business operates on the first Monday.

When should technology due diligence start? When financial diligence starts. Findings frequently affect deal terms, and terms are easier to adjust before they are agreed. The practical reason is leverage: the seller's engagement, the departing staff's recollection and the influence of an unsigned agreement are all at their maximum before closing and decline sharply afterward.

Does the purchase agreement transfer access to the company's systems? No. A purchase agreement transfers legal title. Administrative control transfers only when specific credentials, roles, registrar logins and vendor relationships are moved to named individuals on the buyer's side. A domain can be legally assigned to the buyer while the account controlling it remains under someone else's login. Ownership is contractual and automatic; control is operational and manual.

Who should hold administrative control at closing? One named individual on the buyer's side, identified before closing, with a documented deputy. Diffuse responsibility for privileged access reliably produces the outcome where nobody actually holds it, which is discovered at the moment it is first needed. This person should hold administrative rights in each identity platform, with multi-factor authentication bound to a device the buyer controls.

What is the sixty-day domain transfer lock and how does it affect a deal? Under ICANN's Transfer Policy, registrars must apply a sixty-day lock preventing transfer to a different registrar after a change to the registrant's name, organization or email address. A well-intentioned update to registrant details immediately after closing can therefore block the buyer from moving the domain to their own registrar for two months. Sequencing the registrar account transfer before updating registrant details avoids the problem entirely.

How do you verify backups during due diligence? By restoring something and examining it. Select a file or database from a system the business actually depends on, restore it, open it, and confirm it is complete and current. Backup software reports success against the job it was configured to run, which may no longer match what the business uses. A backup report is a claim about the past; a restoration is a demonstration of capability.

What should a seller do to prepare technology for a sale? Document who holds administrative control of each system, confirm the company rather than an individual is the registrant and account holder for domains, phone numbers and payment platforms, review vendor agreements for assignment terms, and verify that backups restore. Buyers discount uncertainty. A seller who can answer these questions crisply removes a common source of late-stage friction and price adjustment.


Before You Close the Deal

Metro Relay helps North Texas buyers and sellers identify who controls the company's identities, infrastructure, data, vendors, licenses and recovery systems before ownership changes — and confirms it through testing rather than representation.

→ Technology Control Review

Bring what you have. A review is most productive when it can work from the material already assembled for the transaction:

  • Asset lists and equipment schedules
  • Vendor contracts, including any MSP agreement
  • Cyber-insurance applications or requirements
  • Software and subscription inventories
  • Administrator and account records, however incomplete
  • The acquisition timeline and expected closing date