Lock-in is rarely one clause. It is the compound effect of decisions that only become expensive at exit.
You are choosing a provider or platform, or renewing one, and the worry underneath the decision is simple: will you be able to leave if you need to? Lock-in is rarely a single trap clause. It is the compound effect of renewal mechanics, who holds the administrative keys, whether your data can actually be exported and restored, whether the knowledge about your environment lives only in the incumbent's systems, and how vague the transition-out obligations are.
Start with the contract clausesMost lock-in is not malicious. Providers who never intended to trap a customer still end up with control over the tenancy, the admin accounts, the documentation and the timelines, simply because the contract never said otherwise. The defence is not refusing long-term providers or integrated platforms. It is pre-signature specificity: getting the right ownership, evidence and deliverables written down while you still have the leverage to ask. The patterns on this page draw on ACCC enforcement against unfair standard-form terms (including the JJ Richards declaration), ASIC and ASBFEO small-business dispute evidence, ACSC managed service provider guidance, and Microsoft's own platform documentation.
The clauses that create the imbalance are standard-form, not exotic.
ACCC enforcement, ASIC guidance and ASBFEO dispute case studies point to a recurring set of clauses that create power imbalance in standard-form deals.
- Automatic renewal — without a reminder obligation on the provider
- Unilateral price-change rights — fees varied at the provider's discretion
- Suspension rights — service suspended while charging continues
- Undefined transition-out assistance — no named deliverables or timeframes
- Provider ownership of operational materials — your runbooks treated as their IP
- One-sided indemnities — paired with "without cause" termination rights
The working rule for this whole page: if the provider cannot answer these questions specifically before signature, assume they will answer them more slowly after notice is served.
Platform lock-in is about who is the customer of record, not the platform.
Platform lock-in in cloud and Microsoft 365 deployments is rarely about the platform itself. It is about who is the customer of record, whose name is on the subscription, and who controls the billing relationship. A provider that onboards you under its own tenancy or billing holds leverage that has nothing to do with the quality of the technology.
Microsoft's own documentation confirms the friction: Azure subscription transfer is explicitly complex and can require downtime, some Azure resources are not movable between subscriptions, and Azure Lighthouse delegations can persist after a tenant transfer unless they are explicitly removed.
Admin access is the control plane through which the business is recoverable — or held hostage.
Microsoft's older Delegated Admin Privileges (DAP) model let a partner assign Global Administrator to its own employees with no per-employee limit visible to the customer. Microsoft has since moved partners toward Granular Delegated Admin Privileges (GDAP), but the customer still has to insist on it.
The operational risk is concrete: if the relationship deteriorates, if a provider employee's credentials are compromised, or if a transition is disputed, admin access is the control plane through which the business is either recoverable or held hostage.
Knowledge that lives only in the incumbent's systems is lock-in by omission.
Handover failures follow a recurring pattern:
- passwords requested one at a time
- no current runbooks
- network discovery rebuilt from scratch because the provider treats its discovery method as proprietary
- asset registers that never existed
ACSC incident-response guidance is explicit about the baseline that should already exist and be reviewed: standard operating procedures, playbooks and escalation matrices, with service-provider log access and retention established and tested.
“Backup included” is not an answer. The test is a restore, not a green dashboard.
Microsoft's documentation confirms that Microsoft 365 customer data can be extracted during an active subscription and for a limited-function period after termination, but that deletion follows if no action is taken. In practice the backup section of most proposals reads "backup included" with no specification of scope, retention, export format, restore-testing cadence or admin model, and the gaps only surface when a restore is actually attempted.
The defensible position is explicit and written:
- Backup scope by workload — not a single line item
- A retention schedule — stated, not implied
- The storage location disclosed
- An admin model separate from production identity — with its own MFA
- An immutable, offline or segmented copy — where the workload warrants it
Operational knowledge held only in provider tooling is lock-in through the back door.
The common pattern is the provider's "integrated stack": a proprietary remote monitoring platform, a proprietary professional-services-automation tool, proprietary backup or patch management, and automation scripts that never leave the provider's environment.
The same applies to logs. ACSC managed service provider guidance is specific that contracts should include incident-notice requirements, least-privilege and attributable support accounts, detailed logs on request, and log retention periods long enough to investigate an incident.
Sincerity at signature has no operational meaning once notice is served.
This is the category where providers most often say "we will work with you" and mean it sincerely in the moment — and where that sincerity has no operational meaning once notice is served. Data egress charges from major cloud platforms still exist. A multi-year term with a small first-year discount can represent real value, or a multi-year commitment to a provider who stops responding.
And the renewal calendar matters more than most buyers realise: if reminder obligations are weak or absent, the renewal passes silently and the auto-renewal is discovered ninety days after the notice window closed.
Can you name your renewal date, the notice window and the cost of leaving — today, without opening the contract? If not, the leverage is already sitting with the provider.
Bring in an independent view →Some items are not negotiating points. They are refuse-or-rewrite.
The categories above are the full picture. Within them, a short list of specific items is hard-fail: if the provider cannot demonstrate them before signature, the proposal should be refused or rewritten regardless of how strong the rest looks. The logic is asymmetric risk. A weak renewal clause costs a year of leverage. A weak pricing clause costs commercial flexibility. A hard fail on any of these costs control of the business itself.
The environment is only recoverable through the provider.
The business's own name resolves at someone else's discretion.
"Backup included" with nothing to show a restore has ever worked.
Exit assistance exists only as a phrase, not a deliverable.
The price of leaving is discovered only when leaving is already needed.
If any of these five cannot be demonstrated in the proposal in front of you, that is the conversation to have before signature, not after. A senior-led review puts the evidence on the table while you still have the leverage to require it.
Talk through the platform decisionThe pre-signature hour is the highest-leverage hour you will have.
The leverage curve is steep. Before signature, you can require specific wording, specific evidence and specific deliverables. At renewal, amendment is possible but harder. After signature, remediation is partial and usually depends on provider cooperation you no longer have the leverage to command.
Pattern recognition is not difficult once it is visible: customer-held break-glass admin, customer-controlled registrar, a proven restore, a named transition-out schedule, and renewal and egress costs on the table before you sign. That is where an independent view helps: a senior-led review of the specific proposal or renewal in front of you, against the categories, hard-fails and wording patterns on this page — the same discipline covered in how to review an MSP proposal — with findings documented whether or not you keep the incumbent, and a recommendation based on the decision in front of you rather than a pre-set platform preference.
Before signature you can require wording, evidence and deliverables. After signature, remediation depends on cooperation you can no longer command.
FAQs about avoiding vendor lock-in.
Is avoiding lock-in the same as refusing long-term providers or integrated platforms?
What are the five hard-fail items to refuse at signature?
What does good Microsoft 365 admin access look like?
What should the transition-out schedule actually contain?
How is this different from a lawyer's contract review?
Is a proposal or renewal on the table right now?
An independent senior view before you sign is the cheapest leverage you will ever have on the relationship — findings documented whether or not you keep the incumbent, and a recommendation any competent team could execute.
Talk through the platform decision