Microsoft Cloud4 min read200 lines

Learning state

Track this guide

Saved in this browser only. No account required.

Microsoft 365 Administration Master Class

Practical Microsoft 365 operations guide for tenant administration, Exchange Online, Teams, SharePoint, OneDrive, licensing, Purview, audit evidence, and safe governance workflows.

Table of Contents


Operating Model

Microsoft 365 administration spans identity, messaging, collaboration, data governance, and compliance. Treat tenant operations as production infrastructure: read first, export evidence, change in small scopes, and document rollback.

Safe defaults

  • Use read-only reports before tenant changes.
  • Avoid broad external sharing changes without owner review.
  • Review mail forwarding and inbox delegation regularly.
  • Preserve audit evidence before remediation.
  • Keep licensing changes tied to a user lifecycle process.
Connect-MgGraph -Scopes "User.Read.All","AuditLog.Read.All","Directory.Read.All"
Connect-ExchangeOnline
Get-MgContext
Get-EXOMailbox -ResultSize 10 -PropertySets Minimum
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100

Tenant Inventory

Start with tenant context, user inventory, admin roles, and service health assumptions. Inventory prevents operating in the wrong tenant or changing the wrong population.

Connect-MgGraph -Scopes "User.Read.All","Group.Read.All","Directory.Read.All","AuditLog.Read.All"
Get-MgContext
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabled,UserType
Get-MgGroup -All -Property Id,DisplayName,SecurityEnabled,MailEnabled,GroupTypes
Get-MgAuditLogDirectoryAudit -Top 25

Review questions

  • Which users are active, disabled, guests, or shared accounts?
  • Which groups drive app access or collaboration access?
  • Which admin activities happened recently?
  • Which evidence exports should be retained before changes?

Exchange Online Administration

Exchange Online operations include mailbox inventory, forwarding review, delegation review, transport configuration, and audit searches.

Connect-ExchangeOnline
Get-EXOMailbox -ResultSize 25 -PropertySets Minimum
Get-EXOMailbox -ResultSize 25 -Properties ForwardingSmtpAddress,DeliverToMailboxAndForward | Select-Object DisplayName,ForwardingSmtpAddress,DeliverToMailboxAndForward
Get-EXOMailboxPermission -Identity USER@DOMAIN.COM | Where-Object { -not $_.IsInherited }

High-value checks

  • Mailboxes with forwarding enabled.
  • Shared mailboxes with stale delegates.
  • Unexpected full-access permissions.
  • Litigation hold and retention assumptions.
  • Mailbox audit availability.
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations MailItemsAccessed -ResultSize 100
Disconnect-ExchangeOnline -Confirm:$false

Teams Administration

Teams governance covers team creation, guest access, external access, meeting policy, app policy, and lifecycle review. Keep Teams policy changes staged and tied to communication plans.

Connect-MgGraph -Scopes "Group.Read.All","Directory.Read.All","AuditLog.Read.All"
Get-MgGroup -All -Property Id,DisplayName,GroupTypes,Visibility,SecurityEnabled,MailEnabled | Where-Object { $_.GroupTypes -contains 'Unified' }
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations TeamCreated,MemberAdded -ResultSize 100

Governance questions

  • Who can create teams?
  • Are guests allowed in sensitive teams?
  • Which teams are ownerless or stale?
  • Are private channels used for sensitive access separation?

SharePoint and OneDrive Governance

SharePoint and OneDrive controls define external sharing, retention, sensitivity labeling, and access review posture.

Connect-MgGraph -Scopes "Sites.Read.All","AuditLog.Read.All","Directory.Read.All"
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations SharingSet,SharingInvitationCreated,FileAccessed -ResultSize 100
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabled

Operational checks

  • External sharing activity.
  • Guest user lifecycle.
  • Sensitive sites with broad membership.
  • Orphaned OneDrive ownership after departures.
  • Retention and eDiscovery requirements.

Licensing and User Lifecycle

Licensing connects HR lifecycle, security posture, and cost control. Operators should review disabled users, guest users, and license assignment consistency.

Connect-MgGraph -Scopes "User.Read.All","Directory.Read.All"
Get-MgUser -Filter "accountEnabled eq false" -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Get-MgUser -Filter "userType eq 'Guest'" -Property Id,DisplayName,UserPrincipalName,UserType
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AssignedLicenses

Lifecycle checkpoints

  • New hire license assignment.
  • Role-based group membership.
  • Departed user disablement and mailbox handling.
  • Guest expiration and sponsor review.
  • License reclamation after offboarding.

Purview and Compliance

Microsoft Purview covers compliance search, audit, retention, sensitivity labels, eDiscovery, and data lifecycle. Start with evidence discovery before changing retention or labels.

Connect-ExchangeOnline
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations UserLoggedIn,FileAccessed,MailItemsAccessed -ResultSize 100

Compliance review topics

  • Audit log retention requirements.
  • eDiscovery role assignments.
  • Data retention policies.
  • Sensitivity label adoption.
  • Insider risk and DLP policy ownership.

Audit and Evidence

Audit evidence should show who accessed data, who changed settings, and which policies were active. Store exports with timestamps and change-ticket references.

Connect-MgGraph -Scopes "AuditLog.Read.All","Directory.Read.All"
Get-MgAuditLogDirectoryAudit -Top 50
Get-MgAuditLogSignIn -Top 50
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100

Evidence pack

  • Mailbox forwarding report.
  • Mailbox permissions report.
  • Guest user inventory.
  • External sharing audit sample.
  • Unified audit log query export.
  • Directory audit export.

Operational Review Checklist

  • Confirm tenant and admin context.
  • Export user and guest inventory.
  • Review mailbox forwarding.
  • Review mailbox permissions for sensitive users.
  • Review Teams and Microsoft 365 group ownership.
  • Review SharePoint/OneDrive external sharing evidence.
  • Confirm audit log search works.
  • Document findings, owners, and remediation sequence.