⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Microsoft 3656 min read

End of Financial Year IT Checklist for M365 Admins

By Jamie Hamilton · Published

End of financial year is a good prompt for a Microsoft 365 review, and not for sentimental reasons. Renewals cluster around it, next year's budget is being set, and it is the one time of year somebody is already looking at what the business spends. That makes it the cheapest moment to change a licence count.

What follows is ordered deliberately. The parts that recover money come first, because they fund the rest and because they have a deadline attached. The parts that need a decision from somebody else come next, because those take the longest. Everything else can happen in July.

Licences, first, because this is the part with a deadline

Every licence assigned to somebody who no longer works there is billed until somebody removes it, and the annual commitment you are about to renew is calculated on the count you have today.

  • •Reconcile the assigned licence list against your current payroll, name by name. Not the headcount, the names.
  • •Reclaim licences from departed staff, after converting their mailboxes to shared mailboxes rather than before.
  • •Look for people on a plan that does not match what they do, in both directions. Paying for capability nobody uses is the visible waste; the invisible one is somebody handling sensitive material on a plan without the security features to protect it.
  • •Check for add-ons purchased separately that the base plan already includes, which happens most often after a plan upgrade nobody revisited.

Do this before you sign the renewal rather than after. A licence removed in July is money spent in August.

Access, which is where the year has quietly changed things

Role changes accumulate. People move between jobs internally and gain permissions without losing the previous ones, which is how somebody ends up able to reach three departments' files with nobody having ever decided that.

  • •Confirm every account belongs to a current employee, and check for the ones that belong to nobody at all
  • •Review administrative roles against who actually needs them now, not who needed them when they were granted
  • •Remove guest accounts with no live engagement behind them
  • •Check partner relationships in the admin centre for IT providers you no longer use, which is a different screen from the user list and survives changing providers

Shared mailboxes and distribution lists

The unglamorous one, and the one that reliably turns up something.

  • •For each shared mailbox, ask who reads it. If the answer takes more than a few seconds, that is the finding.
  • •Remove departed staff from distribution lists, which nothing forces because nothing breaks when it is skipped
  • •Update lists that no longer match the teams they were named after

Security configuration

A once-a-year read of the things that drift:

  • •Secure Score, and specifically which recommended actions are newly open since last year
  • •MFA coverage for every active user, including the exceptions and whether they are still justified
  • •Conditional Access policies and their exclusion groups, which is where the interesting answers are
  • •SPF, DKIM and DMARC for every domain you send from, not just the primary one

Backup, and the assumption worth testing

Microsoft's obligation under the shared responsibility model is to keep the service running. It is not to recover your data from a mistake you made, and the retention windows that feel like a backup are shorter than people assume and are not designed for the job.

If you have no third party backup covering Exchange Online, SharePoint and Teams, end of financial year is the right time to price it, because it is a budget decision rather than a technical one. If you do have one, the question worth asking is not whether it runs. It is when somebody last restored something from it and checked the contents.

Applications with access to your data

Review enterprise applications in Entra ID. Over a year, people consent to third party applications reaching their mail and files, usually for a good reason at the time, and the consent outlives the reason.

Anything nobody can identify is worth removing. It is easy to grant again if somebody complains, and nobody usually does.

Then plan, while somebody is still listening

The findings above are worth more in June than they are in September, because in June there is a budget conversation happening and in September there is not.

Turn the list into three things: what gets fixed now at no cost, what needs money next year and roughly how much, and what needs a decision rather than a purchase. A small business with those three lists at the start of the financial year is in a better position than one with a larger budget and no plan for it.

Frequently asked questions

What should be on an end of financial year Microsoft 365 checklist?

Licences first, because that part has a deadline attached and funds the rest: reconcile assigned licences against your actual payroll before you sign the renewal. Then access and administrative roles, shared mailboxes and distribution lists, security configuration including MFA and email authentication, backup coverage, and third party applications with access to your data. Finish by turning the findings into a plan while the budget conversation is still open.

How do I find Microsoft 365 licences we are wasting money on?

Reconcile the assigned licence list against your payroll by name rather than by headcount, because the two match often enough to hide the problem. Look for departed staff still licensed, people on a plan heavier than their role needs, and add-ons bought separately that the base plan already covers, which happens most often after an upgrade nobody revisited. Convert mailboxes to shared before reclaiming the licence, not after.

Does Microsoft back up my Microsoft 365 data?

Not in the sense most people mean. Microsoft’s obligation under the shared responsibility model is keeping the service available and recovering from their own failures. Recovering your data after somebody deletes the wrong thing, or after a mailbox is compromised, is your responsibility. The built-in retention windows feel like a backup and are shorter than people assume and were not designed for the job.

Why does end of financial year matter for IT licences?

Because annual commitments are calculated on the licence count you hold when you renew, and because it is the one time of year somebody is already examining what the business spends. A licence removed the week before a renewal changes what you pay for the following year. The same removal a month later changes nothing until the year after.

What is the most commonly missed item in an annual Microsoft 365 review?

Two compete. Distribution lists still containing people who left, because nothing breaks when it is skipped so nothing prompts anybody to do it. And administrative access held by IT providers the business no longer works with, which lives under partner relationships in the admin centre rather than in the user list, and does not go away when the relationship ends.

Want an end of year review done properly? Available after hours and weekends.

Health Check, $599

or call 0403 401 250