Scope & evidence

Microsoft 365 and Microsoft Entra administration planning. Available controls depend on licences, roles and workload; verify each setting in the current tenant.

Research-based; no hands-on test claim.

Confirm ownership and recovery access

Record the tenant identifiers, verified domains, billing owner and authorised administrators in a controlled location. Check domain renewal and access to the registrar. An expired domain or inaccessible billing account can create an operational failure outside the admin centre.

Maintain emergency access according to current Microsoft guidance and test it through an approved process. Keep its authentication dependencies distinct from everyday access where practical. Do not create a blanket MFA bypass as a shortcut; protect and monitor emergency identities carefully.

Review roles and lifecycle

Use named privileged accounts and only the roles each task needs. Review guest users, service principals and delegated relationships as well as employees. Document who approves new access and how role changes reach the administration team.

Reconcile active users with the organisation’s joiner, mover and leaver records. Check licence assignment and mailbox or OneDrive ownership where responsibilities have changed. Do not remove a licence or account before understanding the retention and transfer consequences for the relevant workload.

Check service and data operations

Review service health, message-centre changes and the impact of upcoming platform changes on your workflows. Verify backup coverage or native recovery arrangements for each workload and test the recovery actions that matter to the business.

Use the table to assign recurring checks. A retention policy, recycle bin and independent backup have different purposes and limits. Record the configuration actually in force rather than assuming that a Microsoft 365 subscription includes every recovery behaviour you need.

AreaEvidence
OwnershipTenant, domains, billing and responsible roles
AccessPrivileged-role review and emergency-access check
LifecycleJoiners, movers, leavers and data transfers
RecoveryCoverage and accepted restore exercise
ChangeService notices assessed and exceptions assigned

Keep evidence and exceptions

Record the review date, reviewer, scope and material exceptions. Assign an owner and follow-up date for expired credentials, missing coverage or excessive privileges. Keep evidence in an access-controlled store without exporting unnecessary personal information.

After changes, test a representative user and administrator workflow. Check that access removals took effect and that emergency recovery remains possible. Revisit the checklist when licences, identity architecture or major services change.

References

Next useful steps

Read our editorial and corrections policy.