Learning state
Track this guide
Saved in this browser only. No account required.
Microsoft 365 Administration Master Class
Practical Microsoft 365 operations guide for tenant administration, Exchange Online, Teams, SharePoint, OneDrive, licensing, Purview, audit evidence, and safe governance workflows.
Table of Contents
- Operating Model
- Tenant Inventory
- Exchange Online Administration
- Teams Administration
- SharePoint and OneDrive Governance
- Licensing and User Lifecycle
- Purview and Compliance
- Audit and Evidence
- Operational Review Checklist
Operating Model
Microsoft 365 administration spans identity, messaging, collaboration, data governance, and compliance. Treat tenant operations as production infrastructure: read first, export evidence, change in small scopes, and document rollback.
Safe defaults
- Use read-only reports before tenant changes.
- Avoid broad external sharing changes without owner review.
- Review mail forwarding and inbox delegation regularly.
- Preserve audit evidence before remediation.
- Keep licensing changes tied to a user lifecycle process.
Connect-MgGraph -Scopes "User.Read.All","AuditLog.Read.All","Directory.Read.All"
Connect-ExchangeOnline
Get-MgContext
Get-EXOMailbox -ResultSize 10 -PropertySets Minimum
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100
Tenant Inventory
Start with tenant context, user inventory, admin roles, and service health assumptions. Inventory prevents operating in the wrong tenant or changing the wrong population.
Connect-MgGraph -Scopes "User.Read.All","Group.Read.All","Directory.Read.All","AuditLog.Read.All"
Get-MgContext
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabled,UserType
Get-MgGroup -All -Property Id,DisplayName,SecurityEnabled,MailEnabled,GroupTypes
Get-MgAuditLogDirectoryAudit -Top 25
Review questions
- Which users are active, disabled, guests, or shared accounts?
- Which groups drive app access or collaboration access?
- Which admin activities happened recently?
- Which evidence exports should be retained before changes?
Exchange Online Administration
Exchange Online operations include mailbox inventory, forwarding review, delegation review, transport configuration, and audit searches.
Connect-ExchangeOnline
Get-EXOMailbox -ResultSize 25 -PropertySets Minimum
Get-EXOMailbox -ResultSize 25 -Properties ForwardingSmtpAddress,DeliverToMailboxAndForward | Select-Object DisplayName,ForwardingSmtpAddress,DeliverToMailboxAndForward
Get-EXOMailboxPermission -Identity USER@DOMAIN.COM | Where-Object { -not $_.IsInherited }
High-value checks
- Mailboxes with forwarding enabled.
- Shared mailboxes with stale delegates.
- Unexpected full-access permissions.
- Litigation hold and retention assumptions.
- Mailbox audit availability.
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations MailItemsAccessed -ResultSize 100
Disconnect-ExchangeOnline -Confirm:$false
Teams Administration
Teams governance covers team creation, guest access, external access, meeting policy, app policy, and lifecycle review. Keep Teams policy changes staged and tied to communication plans.
Connect-MgGraph -Scopes "Group.Read.All","Directory.Read.All","AuditLog.Read.All"
Get-MgGroup -All -Property Id,DisplayName,GroupTypes,Visibility,SecurityEnabled,MailEnabled | Where-Object { $_.GroupTypes -contains 'Unified' }
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations TeamCreated,MemberAdded -ResultSize 100
Governance questions
- Who can create teams?
- Are guests allowed in sensitive teams?
- Which teams are ownerless or stale?
- Are private channels used for sensitive access separation?
SharePoint and OneDrive Governance
SharePoint and OneDrive controls define external sharing, retention, sensitivity labeling, and access review posture.
Connect-MgGraph -Scopes "Sites.Read.All","AuditLog.Read.All","Directory.Read.All"
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations SharingSet,SharingInvitationCreated,FileAccessed -ResultSize 100
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Operational checks
- External sharing activity.
- Guest user lifecycle.
- Sensitive sites with broad membership.
- Orphaned OneDrive ownership after departures.
- Retention and eDiscovery requirements.
Licensing and User Lifecycle
Licensing connects HR lifecycle, security posture, and cost control. Operators should review disabled users, guest users, and license assignment consistency.
Connect-MgGraph -Scopes "User.Read.All","Directory.Read.All"
Get-MgUser -Filter "accountEnabled eq false" -Property Id,DisplayName,UserPrincipalName,AccountEnabled
Get-MgUser -Filter "userType eq 'Guest'" -Property Id,DisplayName,UserPrincipalName,UserType
Get-MgUser -All -Property Id,DisplayName,UserPrincipalName,AssignedLicenses
Lifecycle checkpoints
- New hire license assignment.
- Role-based group membership.
- Departed user disablement and mailbox handling.
- Guest expiration and sponsor review.
- License reclamation after offboarding.
Purview and Compliance
Microsoft Purview covers compliance search, audit, retention, sensitivity labels, eDiscovery, and data lifecycle. Start with evidence discovery before changing retention or labels.
Connect-ExchangeOnline
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -Operations UserLoggedIn,FileAccessed,MailItemsAccessed -ResultSize 100
Compliance review topics
- Audit log retention requirements.
- eDiscovery role assignments.
- Data retention policies.
- Sensitivity label adoption.
- Insider risk and DLP policy ownership.
Audit and Evidence
Audit evidence should show who accessed data, who changed settings, and which policies were active. Store exports with timestamps and change-ticket references.
Connect-MgGraph -Scopes "AuditLog.Read.All","Directory.Read.All"
Get-MgAuditLogDirectoryAudit -Top 50
Get-MgAuditLogSignIn -Top 50
Search-UnifiedAuditLog -StartDate "2026-01-01" -EndDate "2026-01-02" -ResultSize 100
Evidence pack
- Mailbox forwarding report.
- Mailbox permissions report.
- Guest user inventory.
- External sharing audit sample.
- Unified audit log query export.
- Directory audit export.
Operational Review Checklist
- Confirm tenant and admin context.
- Export user and guest inventory.
- Review mailbox forwarding.
- Review mailbox permissions for sensitive users.
- Review Teams and Microsoft 365 group ownership.
- Review SharePoint/OneDrive external sharing evidence.
- Confirm audit log search works.
- Document findings, owners, and remediation sequence.