Microsoft 365 Tenant Handover Checklist – What to Check on Day One

by Tomasz Szulczewski | Aug 13, 2026 | Cybersecurity | 0 comments

Every environment I inherit gets the same Microsoft 365 tenant handover checklist before I change a single setting. Not because I am a pedant - I am not - but because I want to know where I stand. And because from the day you start, whatever eventually explodes lands on your name, not on the person who left three months ago. You are not scared? Imagine this... Two weeks into a new job, you notice a forgotten account with administrator rights signing in from a country nobody in the company has ever visited.

That is the moment you find out what you actually inherited.

Here it is, in the order I work through it. It applies whether you are a new admin, a consultant taking over a client environment, or an owner who just took IT back in-house.

Microsoft 365 Tenant Handover Checklist - What to Check on Day One
Microsoft 365 Tenant Handover Checklist - What to Check on Day One

Start your Microsoft 365 tenant handover checklist with identity

Count your Global Administrators.

Open the Microsoft 365 admin centre, go into Entra ID, and check how many users hold the Global Administrator role.

The safe number is 2 to 4. Exactly as many as you need, not one more.

If you see 8, 10 or 15, that is a red flag. Half of them usually turn out to be old service accounts or employees who left long ago. And no, the person in accounting does not need Global Admin so her application works. That someone wrote a badly designed application is not a security problem you solve with permissions.

Any Global Admin account you cannot map by name to a currently employed human - disable it. Everyone will be better off.

Check MFA on every admin account.

Every admin account must have MFA. No exceptions. Verify it in the sign-in report or user settings in Entra ID.

An admin account without MFA is a safe without a lock. It looks serious and protects nothing.

Then check which MFA. Not all second factors are equal. It's not a good idea to use SMS texts for the global administrator's extra security because swapping SIM cards is simple to do. One of the large US casino breaches happened precisely because attackers pulled off a SIM swap.

Look for Conditional Access. Any at all.

Well-built Conditional Access policies are, in my view, the single thing that most defines how secure a company actually is.

MFA alone does not protect you from as much as people assume. If an attacker steals a session cookie, then without proper Conditional Access that MFA might as well not exist. Conditional Access decides when access gets checked: is the device company-managed, is this account suddenly signing in from the other side of the world, and so on.

Zero policies means anyone can sign into M365 from anywhere, on anything, with no restrictions.

No good admin on hand and no idea where to start? Enable Security Defaults in Entra ID. It is not sophisticated, and it is far better than nothing.

Next point on my Microsoft 365 tenant handover checklist is the security posture

Read the Secure Score honestly.

When you start a new job, they usually show you a picture of a beautifully secured environment. Secure Score verifies that picture rather bluntly.

By the way, improving the security score is probably the most common type of project on my Upwork profile. Again, it is the most straightforward assessment: where is your tenant security? Microsoft takes existing settings and tells you how secure you actually are. 

Open the Defender portal and look at the number. The point is not to hit 100 - that usually requires top-tier licensing anyway. The point is to know where you stand and what matters most. A score of 30 in a 100-person company means there is a great deal of work ahead.

Review the recommendations too. They tell you which fixes give the biggest gain for the least effort.

An aside worth saying: some companies buy expensive extra vulnerability scanners. In a very large, complex organisation that can make sense. In an ordinary 100-person company, what is in Defender is enough. Another scanner adds nothing when the findings you already have are not being remediated. Do what Defender recommends first, then consider something specialised.

Verify Defender for Office is actually doing something.

Microsoft's defaults beat nothing, but companies frequently leave policies in audit-only mode or switch them off entirely.

Check:

  • Anti-phishing - is impersonation protection enabled?
  • Safe Links and Safe Attachments - are links and attachments actually being scanned?
  • Anti-spam - are there overly generous exceptions?

If you are unsure what to configure, use Preset Security Policies. Turning on Standard protection is a good balance between secure and manageable, without generating a flood of false positives.

Confirm the audit log is on.

Microsoft 365 keeps a record of who signed in, who opened what, who changed which setting. For that to exist, audit logging has to be enabled.

Check the status in Microsoft Purview. If it is off, you have no trace of anything that happened in this tenant and no ability to investigate an incident. This is two minutes of work and it is the difference between "we know what happened" and "we have no idea".

Read the mail flow rules. This is where attacks hide.

Open the Exchange admin centre and look at mail flow rules and mailbox forwarding.

You may find that mail for the CEO is forwarded to a former admin's account. Or something worse - every message arriving for the CFO quietly forwarded to an external address, so an attacker knows exactly which invoices arrive and from whom.

That is the classic Business Email Compromise setup. The attacker gets into the mailbox, sets a silent rule - anything with "invoice" in the subject goes to my address - and collects for weeks. The user never notices.

External forwarding that nobody can explain is a security incident, not a configuration mistake. Disable it immediately, then investigate.

Finish with tenant hygiene

Licences: what are you actually paying for?

Verify the number of purchased licenses, assigned licenses, and existing real users. In practically every company I walk into, there are several licences floating in mid-air.

At Business Premium around EUR 22 a month, ten unnecessary licences is over EUR 2,600 a year going nowhere. That is a conversation any owner will happily have with you in week one.

Devices: is Intune deployed?

Check whether Intune is configured and how many devices are enrolled. If the company has 80 employees and Intune shows zero devices, nobody is managing those machines. No compliance policies. No disk encryption requirement. Any laptop could already be in the wrong hands and nobody would know.

Intune also lets you configure machines so users are not local administrators by default. The idea that an ordinary user should hold local admin in 2026 is genuinely hard to defend. I know developers will disagree. The accounting team does not need it.

Without device control, you cannot claim the company is secure or properly managed.

Bottom line

Work the handover checklist before you change anything. One hour of audit tells you what you inherited before you break something or miss an incident that is already running.

And when the owner tells you nothing has happened in two years, remember what that sentence actually means. In cybersecurity, "nothing happened" does not mean secure. It means you have been lucky so far.

Once you know what you inherited, the next step is fixing it. Start with the Microsoft 365 Business Premium security settings that are switched off in most tenants.

Written by Tomasz Szulczewski

Hi, my name is Tomasz Szulczewski, and I have been in love with information technology for over 25 years, but I still have an IT passion and feel like a geek. I am a person who is problem solver who thinks that not all people must be experts in IT.

Related Posts

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *