Checklist

Microsoft 365, set up properly

Useful two ways: as a setup order for a new tenant, and as an audit of one you inherited and have never really looked at.

Work through this in order. The first four items are the ones that cause real damage when they are missed, and they are all free. The rest is tidiness that pays back later.

If you are auditing a tenant you inherited rather than building a new one, the same list works as a set of questions. Anything you cannot answer is worth chasing down, and if several are unanswerable that is technical cleanup rather than a settings job.

Do these first

If you only do four things, do these. Each one is free and each one prevents a category of expensive problem.

  • Confirm who holds global admin. It should be an account owned by the business, not a person's personal login and not a former provider. If nobody knows, start the recovery process now: it takes days, not minutes.
  • Turn on multi-factor authentication for everyone. Admins first, then everybody. This is the highest-value item on the page and it costs nothing.
  • Record the recovery details somewhere the business controls. A recovery address and phone that do not depend on one employee still working there. This is what turns a bad day into a short one.
  • Check for leavers who still have access. Sign-in blocked, mailbox handled, licence released. Do this before anything else on a tenant you inherited.

Then get the structure right

  • Use shared mailboxes for business addresses. Anything like enquiries, accounts or info should be reachable by more than one person. Included on most business plans at no extra licence cost.
  • Set up aliases rather than extra accounts. A second address on the same mailbox does not need a second licence. Buying one is a common and avoidable cost.
  • Match licences to people who actually work there. Compare the assigned list against your payroll. This review frequently pays for itself on the first pass.
  • Create groups that reflect how the business runs now. Not how it ran three years ago. Stale groups quietly grant access nobody intended.
  • Decide where files live, and say so out loud. A shared library the business owns, not somebody's personal drive. The failure mode here is identical to the mailbox one.

Then make sure mail actually arrives

  • SPF published for your domain. Says which servers may send as you. One record only: two SPF records is a common and self-inflicted delivery failure.
  • DKIM enabled and signing. Signs your outgoing mail so receivers can verify it was really you. Needs turning on; it is not automatic.
  • DMARC published, starting in monitoring mode. Tells receivers what to do with mail that fails the other two. Start in monitoring and tighten later once you can see what is actually sending.
  • Send a test to an outside address. Not to a colleague on the same tenant, which proves nothing. Check it does not land in spam.
  • Know where your DNS is actually served from. Usually the surprise. Terms explained in the DNS glossary, and if mail is already going astray see email going to spam.

The part people skip

Write it down. What the tenant is, which plan, who holds admin, what the recovery details are, which shared mailboxes exist and who can reach them.

This is dull and it is the difference between a smooth handover and a fortnight of archaeology. The businesses that suffer most when a person leaves are not the ones with complicated setups. They are the ones where the setup was simple and entirely undocumented, so nobody realised how much depended on one person until that person was gone.

Keep the record somewhere the business controls, and somewhere findable in an emergency. A document nobody can locate during an outage is not a record.

Who this is for

  • Businesses setting up Microsoft 365 for the first time
  • Anyone who inherited a tenant and does not know what state it is in
  • Owners who want to check the basics are covered before assuming they are
  • Teams whose enquiries currently land in one person's inbox

When this is not the right fit

  • Larger organisations with formal security requirements. This is a small business baseline, not a compliance framework.
  • Anyone looking for a step-by-step click path. Microsoft moves the interface regularly and a screenshot guide would be wrong within months. This is the what and the why; the where is in their own documentation.
  • Businesses on Google Workspace. Same principles, different admin centre.

What SolvenceHQ can help with

This list is genuinely usable on your own, and plenty of owners do. Where people ask for help is the recovery cases and the mail authentication, which are the two that punish guessing.

  • Setting up or taking over a tenant properly
  • Recovering admin access nobody currently holds
  • Getting SPF, DKIM and DMARC right so mail arrives
  • Shared mailboxes, aliases and a licence review
  • Moving mail in from another provider
  • Working out what exists when the answer is genuinely unknown
  • Writing the record so the next person does not repeat this

Common questions

Where do I find the admin centre?

It is the Microsoft 365 admin centre, and you can only reach it with an account that holds admin rights. If you sign in and cannot see it, your account is a normal user account, which is itself useful information: somebody else holds the keys.

Finding out who is the first job. If nobody knows, that is a recovery process rather than a settings change, and it is worth starting early because it runs on Microsoft's timetable.

What is the single most important item here?

Multi-factor authentication on every account, and especially on admin accounts. It is free, it takes minutes, and it prevents the great majority of the account compromises that hit small businesses.

The usual objection is that it is one more step at sign-in. That is true. It is also far less disruptive than losing control of the mailbox your invoices go out from.

Should enquiries go to a person or a shared mailbox?

A shared mailbox, nearly always. When enquiries land in one person's inbox, the business cannot see its own leads while that person is away, and it loses the history entirely when they leave.

Shared mailboxes are included on most business plans at no extra licence cost, which surprises people. There is rarely a good reason not to use one for anything addressed to the business rather than to an individual.

What happens to a mailbox when someone leaves?

Do not just delete the account, because the mail goes with it. The usual approach is to block sign-in immediately, convert the mailbox so it is still reachable, and forward or delegate it to whoever is picking up that work.

Then release the licence, which is the step everyone forgets and the reason so many businesses pay for leavers for months.

Get a Quote

Rather have someone just do it

Most of this is an afternoon for someone who does it regularly, and considerably longer for someone doing it once. Tell us what state your tenant is in.

Call now Request a quote