⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Microsoft 3656 min read

The 5 Things I Check First When I Take On a New M365 Tenant

By Jamie Hamilton · Published

After 25 years in IT and the last decade on Microsoft 365, I have looked at a lot of tenants. These five checks take about half an hour between them and they predict the state of the rest better than anything else I have tried.

They are not the whole review. They are the part that tells me what kind of review this is going to be, and whether the conversation I am about to have is a short one.

1. How many Global Administrators are there?

Global Administrator is the top of the tree. An attacker holding one owns the environment: every mailbox, every file, the ability to add accounts and to turn off the logging that would have shown what they did.

What I want to see is a small number of dedicated accounts that nobody uses for daily email. What I usually find is somewhere between two and twelve, at least one of them being the business owner's ordinary account, and often a former IT provider still in the list.

The count matters less than the type. Two Global Admins that are also two people's everyday logins is worse than four dedicated ones, because an everyday account reads mail, clicks links and follows the same risks as any other user, while carrying the keys to everything.

2. Is MFA actually enforced, or just switched on?

I read the authentication methods report in Entra ID rather than asking, because the answer to the question is almost always yes and the report almost always disagrees.

The gaps follow a pattern. Users who never completed registration and have been quietly skipped ever since. Accounts excluded from a policy to fix an urgent problem, with the exclusion never removed. A shared login for a line of business application that could not handle a prompt. And legacy authentication still permitted somewhere, which does not prompt at all: it is a path that predates modern authentication and it goes around MFA rather than through it.

The word to distrust is enabled. What matters is enforced, for everyone, with the exceptions written down and justified.

3. What does the DMARC record say?

This one takes thirty seconds and it is the most informative thirty seconds available, because it is a public record and I can read it before anybody gives me access to anything.

It tells me two things at once. Whether the domain can be forged, which is the direct answer. And whether anybody has ever thought about email authentication here, which is the more useful signal, because a domain with a considered DMARC record almost never has a chaotic tenant behind it, and the reverse holds too.

Roughly half the tenants I look at have no DMARC record at all. Most of the rest are at p=none, which asks receiving servers to do nothing.

4. Are there obvious orphaned accounts?

I sort the user list by last sign-in and read from the bottom. Anything licensed and unblocked with no activity in 90 days gets a question.

There are nearly always a few, usually belonging to people who left, sometimes still on the most expensive licence in the tenant. That costs money, which gets attention, but the reason I look is that it tells me whether anybody owns offboarding. If departed staff are still licensed, then nothing else about departures is happening either: the sessions were not revoked, the forwarding rules were not checked, and the group ownership was not transferred.

One orphaned account is an oversight. Four is a missing process.

5. What does Secure Score say, and which actions are open?

I look at the open recommendations rather than the number. The number depends on your licence type and can be moved by doing things that do not make the business safer.

Most small business tenants I see are well below what their existing licences already permit, and that is the interesting part: it is almost always capability that has been paid for and never switched on. The gap between what you own and what you have configured is usually larger than the gap between what you own and what you would need to buy.

What the five together tell me

Fewer than one in ten of the small business tenants I review come through all five without at least one significant finding. That is not a criticism of anybody. Microsoft 365 is a large product that changes monthly, and it is nobody's actual job in a business of fifteen people.

The pattern I am really reading is whether there is an owner. A tenant with one careless area and four solid ones has somebody looking after it who missed something. A tenant with five soft answers has nobody, and that is a different conversation, because fixing the five findings will not stop them coming back.

Frequently asked questions

How many Global Admins should a small business have?

A small number of dedicated accounts, not somebody’s everyday login. The type matters more than the count: two Global Administrators that are also two people’s daily email accounts is a worse position than four accounts used only for administration, because a daily account reads mail and clicks links like any other while holding the keys to the entire tenant.

What is the difference between MFA being enabled and enforced?

Enabled means the capability is switched on. Enforced means every account actually has to use it, with no gaps. The usual gaps are users who never finished registering, accounts excluded from a policy to solve an urgent problem years ago, a shared login for an application that could not handle a prompt, and legacy authentication protocols still permitted, which bypass MFA entirely rather than prompting for it.

Why check DMARC before getting access to the tenant?

Because it is published in public DNS, so it can be read without permission from anybody, and it is unusually informative for the effort. It answers directly whether the domain can be forged, and indirectly whether anybody has thought about email authentication, which turns out to predict the state of the rest of the environment well. A considered DMARC record rarely sits in front of a chaotic tenant.

What counts as an orphaned account?

A licensed, unblocked account with no sign-in activity for 90 days or more. The cost is the obvious problem, particularly when the account is on an expensive plan. The more useful signal is what it says about process: if departed staff are still licensed then the rest of offboarding is not happening either, so the sessions were never revoked, the forwarding rules were never checked, and group ownership was never transferred.

Is a low Secure Score a problem?

Not by itself, and the number is the least useful part of it. What matters is which recommended actions are open and whether they are realistic for a business your size. Most small business tenants sit well below what their existing licences already permit, which means the gap is usually capability already paid for and never switched on rather than anything that needs buying.

Want somebody to run these five checks and the rest of them on your tenant?

Health Check, $599

or call 0403 401 250