Microsoft 365 Administration
Microsoft 365 Administration
Microsoft 365 tenant, mailbox, Teams, and identity work — the biggest single source of routine requests.
Microsoft 365 tenant, mailbox, Teams, and identity work — the biggest single source of routine requests.
Anti-Spam Policy Tuning
Tune Exchange Online Protection and Defender anti-spam policies from verdict evidence with scoped overrides and time-limited exceptions.
App Protection Policies
Configure Intune MAM-without-enrollment app protection for BYOD to protect org data in managed apps without managing the personal device.
Archive Mailbox Enablement
Enable Exchange Online In-Place Archive mailboxes to solve quota issues, with license checks, move-policy expectations, and archive caveats.
Autopilot Deployment
Run Windows Autopilot deployments end-to-end: hardware hash registration, profile assignment, ESP behavior, and reset-vs-re-enroll decisions.
B2B Collaboration Setup
Configure Entra B2B cross-tenant collaboration between partner organizations with scoped access settings, MFA and device trust, and rollback.
BitLocker Key Retrieval
Handle BitLocker recovery key requests with identity verification, device-ownership match, secure delivery, key rotation, and audit note.
Break-Glass Account Audit
Audit Entra emergency-access break-glass accounts: Conditional Access exclusions, sealed credentials, sign-in alerting, and quarterly test.
Calendar Permissions
Grant or review Exchange calendar sharing and delegation with least-privilege folder roles, owner consent, and private-items handling.
Conditional Access Review
Inventory a tenant's Conditional Access policies to find overlaps, legacy-auth gaps, unprotected apps, with report-only discipline for changes.
Delegate Access Forensics
Investigate mailbox audit logs to identify Send As, Send on Behalf, and owner actions in delegation disputes and unauthorized-email claims.
Device Wipe Workflows
Choose the right Intune remote action - retire, wipe, fresh start, Autopilot reset, or delete - with data-loss warnings and approval gate.
Distribution vs M365 Groups
Pick between distribution lists, Microsoft 365 Groups, mail-enabled security groups, and dynamic groups, and handle DL-to-M365-Group upgrades.
DKIM Enablement
Enable DKIM signing for a custom domain in Exchange Online: publish selector CNAMEs, activate signing, verify records, and plan key rotation.
Email Connector Setup
Route LOB apps, scanners, and printers through Exchange Online using SMTP AUTH, direct send, or an IP/certificate-scoped relay connector.
Enrollment Restrictions
Configure Intune enrollment restrictions: personal vs corporate device rules, platform blocks, device limits, and corporate identifier logic.
Entra PIM Requests
Handle Entra Privileged Identity Management role requests with eligible vs active assignments, activation justification, and time-boxed access.
GDAP Relationship Review
Audit MSP GDAP delegated-admin relationships across client tenants for least-privilege roles, security-group mapping, expiries, and unused access.
Guest Access Audit
Inventory Entra B2B guest accounts, find stale and never-redeemed ones, and enable access reviews and expiration with approval-gated cleanup.
Intune App Deployment
Deploy, update, or remove Intune apps with packaging choice, required vs available intent, pilot-to-broad rings, and approval before forced installs.
Intune Compliance Policies
Create or change Intune device compliance policies with grace periods and Conditional Access blast radius, piloted before broad enforcement.
Intune Enrollment Troubleshooting
Diagnose Windows Intune enrollment failures via a fixed ladder: user licensing, MDM scope, device state, and Entra join type checks.
Journaling & Compliance Mail
Handle Exchange journaling and compliance-copy requests with legal justification, external journal targets, cost impact, and retention alternatives.
M365 Group Lifecycle
Govern Microsoft 365 Groups lifecycle: creation controls, naming, expiration and renewal, ownership handoff, and clean retirement of dead groups.
M365 License Optimization
Right-size Microsoft 365 licensing from usage evidence: reclaim unused licenses, downgrade over-provisioned users, and rationalize add-ons.
M365 Tenant Health Report
Produce an advisory digest of Microsoft 365 Service Health incidents and Message Center posts for a client tenant as a plain-language brief.
Mail Flow Reports
Produce periodic Exchange Online mail flow health summaries: volume trends, spam/malware catch rates, top senders, connector health, forwarding.
Mail Forwarding Audit
Inventory every mail forwarding path in a tenant or mailbox: mailbox forwarding, inbox rules, and transport rules, treating external forwarding as risk.
Mail Trace Investigation
Run disciplined Exchange Online message traces with tight timeframes, sender/recipient pairs, verdict reading, and historical traces beyond 10 days.
Mailbox Migration Prep
Build the pre-migration checklist for tenant-to-tenant or on-prem mailbox moves: inventory, breakage list, holds and licensing, and user comms.
Mailbox Permissions Audit
Inventory Exchange mailbox access grants: Full Access, Send As, Send on Behalf, and folder-level permissions, flagging unexpected delegations.
Mailbox Quota Management
Investigate full or filling Exchange mailboxes and choose targeted cleanup, archive enablement, or license upgrade based on where size lives.
MFA Methods Audit
Audit Entra MFA authentication methods per user: phone-only risk, push without number matching, and missing phishing-resistant methods for admins.
OneDrive Storage Governance
Set OneDrive governance: storage quotas, leaver-account retention, sync scope by device or domain, and external-sharing posture for the tenant.
Out-of-Office on Behalf
Set automatic replies on an absent user's mailbox by request: manager or HR authorization verified, message kept minimal, and an end date set.
Plus Addressing & Aliases
Handle requests for extra mailbox addresses: plus addressing for self-service tagging, proxy aliases, and the send-from-alias caveats stated.
Power Automate Governance
Bring Power Automate under control: find orphaned flows from leavers, reassign ownership before breakage, and restrict Power Platform connectors.
Purview DLP Policy
Scope, test, and roll out Microsoft Purview DLP policies with test-mode first, narrow scope, and evidence before enforce to protect PII and PHI.
Resource Mailbox Setup
Create Exchange room and equipment mailboxes with booking policies, auto-accept or delegate approval, and recurring-meeting and duration limits.
Retention Policy Requests
Change Microsoft Purview retention and deletion policies with scope confirmed, legal-hold interaction flagged, and authorization documented.
Safe Attachments and Links Policy
Tune Defender for Office 365 Safe Attachments and Safe Links policies with dynamic delivery, URL rewriting, and scoped exceptions from evidence.
Security Defaults vs Conditional Access
Decide whether a tenant should stay on Entra security defaults or migrate to Conditional Access, sequenced so there is never an unprotected gap.
Sensitivity Labels
Roll out Microsoft Purview sensitivity labels with a small taxonomy, auto-labeling in simulation, and encryption consequences understood upfront.
Shared Mailbox Creation
Create Exchange Online shared mailboxes: naming, licensing at the 50GB threshold, initial delegation, and documentation for team inboxes.
SharePoint Site Provisioning
Provision new SharePoint sites and document libraries with site type, permission model, and sharing defaults chosen deliberately not inherited.
SSPR Rollout
Plan and execute Entra self-service password reset: method choices, registration campaign, hybrid writeback checks, and helpdesk-ticket impact.
Stale Device Cleanup
Clean up stale Entra device objects on a last-activity threshold with BitLocker-key-loss warnings, Autopilot exclusions, and disable-before-delete.
Teams Phone Admin
Configure Microsoft Teams Phone: assign numbers, apply calling and caller-ID policies, and build basic auto-attendants and call queues.
Tenant Onboarding Checklist
Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.
Transport Rule Management
Inspect, add, or change Exchange Online transport rules safely: document current state, test mode before enforce, and disable instead of delete.
Windows Hello for Business
Deploy or troubleshoot Windows Hello for Business: prerequisites by join type, tenant-wide vs targeted enablement, and hybrid on-prem access issues.
Was this page helpful?
⌘I