Microsoft 365 and Microsoft Entra administration planning. Available controls depend on licences, roles and workload; verify each setting in the current tenant.
Stuart Kerr Spindlow has confirmed personal use and testing of the software covered by Happy SysAdm. The assessments here distinguish documented behaviour from measured results; worked scenarios are labelled and are not personal test records.Confirm ownership and recovery access
Prioritise recoverable administration, identity lifecycle and data ownership before lower-impact cosmetic settings. A tenant can appear healthy while only one person can recover access or while a departing employee still owns a critical workflow. Native administration controls are a better starting point than another dashboard when the underlying ownership and recovery paths have not been established.
Record the tenant identifiers, verified domains, billing owner and authorised administrators in a controlled location. Check domain renewal and access to the registrar. An expired domain or inaccessible billing account can create an operational failure outside the admin centre.
Maintain emergency access according to current Microsoft guidance and test it through an approved process. Keep its authentication dependencies distinct from everyday access where practical. Do not create a blanket MFA bypass as a shortcut; protect and monitor emergency identities carefully.
Review the tenant beyond the admin centre
- Ownership
- Tenant, domain renewal, billing and responsible administrators.
- Identity and lifecycle
- Privileged roles, emergency access and joiner/mover/leaver changes.
- Service and data
- Service notices, recovery coverage and accepted restore exercises.
Review roles and lifecycle
Use named privileged accounts and only the roles each task needs. Review guest users, service principals and delegated relationships as well as employees. Document who approves new access and how role changes reach the administration team.
Reconcile active users with the organisation’s joiner, mover and leaver records. Check licence assignment and mailbox or OneDrive ownership where responsibilities have changed. Do not remove a licence or account before understanding the retention and transfer consequences for the relevant workload.
Check service and data operations
Review service health, message-centre changes and the impact of upcoming platform changes on your workflows. Verify backup coverage or native recovery arrangements for each workload and test the recovery actions that matter to the business.
Use the table to assign recurring checks. A retention policy, recycle bin and independent backup have different purposes and limits. Record the configuration actually in force rather than assuming that a Microsoft 365 subscription includes every recovery behaviour you need.
| Area | Evidence |
|---|---|
| Ownership | Tenant, domains, billing and responsible roles |
| Access | Privileged-role review and emergency-access check |
| Lifecycle | Joiners, movers, leavers and data transfers |
| Recovery | Coverage and accepted restore exercise |
| Change | Service notices assessed and exceptions assigned |
Keep evidence and exceptions
Record the review date, reviewer, scope and material exceptions. Assign an owner and follow-up date for expired credentials, missing coverage or excessive privileges. Keep evidence in an access-controlled store without exporting unnecessary personal information.
After changes, test a representative user and administrator workflow. Check that access removals took effect and that emergency recovery remains possible. Revisit the checklist when licences, identity architecture or major services change.
Use Microsoft’s explicit emergency-access baseline
Microsoft recommends two or more cloud-only emergency access accounts and validation at least every 90 days. These are vendor guidance values, not measurements of your tenant. Their purpose is to reduce dependence on one account or a failed federation path; simply counting two accounts does not show that their recovery methods are independent.
A useful review result distinguishes the number of configured accounts from the number successfully validated under the approved procedure. Keep the date, authorised reviewer and exceptions with the tenant record. Role reviews and workload recovery checks need their own scope; a successful emergency sign-in does not certify the rest of Microsoft 365.