Scope & evidence

Microsoft 365 and Microsoft Entra administration planning. Available controls depend on licences, roles and workload; verify each setting in the current tenant.

Stuart Kerr Spindlow has confirmed personal use and testing of the software covered by Happy SysAdm. The assessments here distinguish documented behaviour from measured results; worked scenarios are labelled and are not personal test records.

Confirm ownership and recovery access

Prioritise recoverable administration, identity lifecycle and data ownership before lower-impact cosmetic settings. A tenant can appear healthy while only one person can recover access or while a departing employee still owns a critical workflow. Native administration controls are a better starting point than another dashboard when the underlying ownership and recovery paths have not been established.

Record the tenant identifiers, verified domains, billing owner and authorised administrators in a controlled location. Check domain renewal and access to the registrar. An expired domain or inaccessible billing account can create an operational failure outside the admin centre.

Maintain emergency access according to current Microsoft guidance and test it through an approved process. Keep its authentication dependencies distinct from everyday access where practical. Do not create a blanket MFA bypass as a shortcut; protect and monitor emergency identities carefully.

Decision map

Review the tenant beyond the admin centre

Ownership
Tenant, domain renewal, billing and responsible administrators.
Identity and lifecycle
Privileged roles, emergency access and joiner/mover/leaver changes.
Service and data
Service notices, recovery coverage and accepted restore exercises.
Review map. Use the evidence table to assign owners and record exceptions; this is not an admin-centre screenshot. Evidence sources.

Review roles and lifecycle

Use named privileged accounts and only the roles each task needs. Review guest users, service principals and delegated relationships as well as employees. Document who approves new access and how role changes reach the administration team.

Reconcile active users with the organisation’s joiner, mover and leaver records. Check licence assignment and mailbox or OneDrive ownership where responsibilities have changed. Do not remove a licence or account before understanding the retention and transfer consequences for the relevant workload.

Check service and data operations

Review service health, message-centre changes and the impact of upcoming platform changes on your workflows. Verify backup coverage or native recovery arrangements for each workload and test the recovery actions that matter to the business.

Use the table to assign recurring checks. A retention policy, recycle bin and independent backup have different purposes and limits. Record the configuration actually in force rather than assuming that a Microsoft 365 subscription includes every recovery behaviour you need.

AreaEvidence
OwnershipTenant, domains, billing and responsible roles
AccessPrivileged-role review and emergency-access check
LifecycleJoiners, movers, leavers and data transfers
RecoveryCoverage and accepted restore exercise
ChangeService notices assessed and exceptions assigned

Keep evidence and exceptions

Record the review date, reviewer, scope and material exceptions. Assign an owner and follow-up date for expired credentials, missing coverage or excessive privileges. Keep evidence in an access-controlled store without exporting unnecessary personal information.

After changes, test a representative user and administrator workflow. Check that access removals took effect and that emergency recovery remains possible. Revisit the checklist when licences, identity architecture or major services change.

Use Microsoft’s explicit emergency-access baseline

Microsoft recommends two or more cloud-only emergency access accounts and validation at least every 90 days. These are vendor guidance values, not measurements of your tenant. Their purpose is to reduce dependence on one account or a failed federation path; simply counting two accounts does not show that their recovery methods are independent.

A useful review result distinguishes the number of configured accounts from the number successfully validated under the approved procedure. Keep the date, authorised reviewer and exceptions with the tenant record. Role reviews and workload recovery checks need their own scope; a successful emergency sign-in does not certify the rest of Microsoft 365.

References

Next useful steps

Read our editorial and corrections policy.