You prepare and compile; technicians execute every tenant change. Apply the Write Guardrails base skill — never invent data, and when in doubt about
authorization or standing third-party access, do nothing and escalate.
1. Access — GDAP first, least-privilege roles mapped to MSP security groups, not Global
Admin for everyone (gdap-relationship-review owns the role standard and expiry). No
shared "admin@" credentials, no standing GA accounts for convenience.
2. Safety rails before any policy work — two break-glass accounts per
break-glass-account-audit: cloud-only, phishing-resistant or sealed credentials, excluded
from CA, sign-in alerting, quarterly test. They exist BEFORE step 3, no exceptions, so
nothing done later can lock everyone out.
3. Baseline — security defaults vs Conditional Access. Run security-defaults-vs-ca: licensing, exception needs and maintenance capacity decide it.
Record the decision, rationale and a named approver. If CA, build the baseline with a
report-only soak per conditional-access-review; if defaults, verify they are on.
4. Inventory — trust nothing, count everything. All dated and labelled point-in-time:
- Admin-role holders (global-admin-audit). Takeover tenants routinely still carry the
previous MSP's accounts — offboarding line items with a deadline.
- Users, licenses assigned versus purchased, obvious waste.
- Guests (guest-access-audit), devices and management state, MFA method quality
(mfa-methods-audit).
- Existing CA policies, mail rules, third-party app consents worth flagging.
- Legacy authentication: blocked or not, and does anything still use it? Sign-in-log
evidence, window stated. Live traffic is a remediation ticket with named dependencies,
never a same-day block.
Where a Liongard M365/Entra inspector exists, confirm it last ran and state the dataprint
age; otherwise the tech takes console exports (Connector Degradation base skill: name the
missing integration and carry on). Apply Sweep Honesty — "at least
N", plus what you could not check.
5. Documentation. Tenant details, GDAP scope and expiry, break-glass procedure (where the
credentials live, never the credentials), the baseline decision, the inventories, and
deviations from the standard with reasons. Flag the gap if nothing is connected.
6. Ticketize. Each checklist item is a ticket with an owner; remediations found above get
their own. On a takeover, removing the previous MSP's access is approval-gated
with the client and scheduled — never silently skipped: standing third-party admin access
is the top takeover risk. Schedule the quarterly break-glass test, CA review, guest audit
and GDAP expiry check. Close with a summary note — items done, open remediations,
decisions and approvers (PSA Note Discipline base skill: plain text, no markdown or
emojis).