Nothing your company owns matters more than the tenant, and almost nobody runs it that way.
One tenant holds the entire company: every mailbox, every document, every Teams thread, every identity, and every administrative right anyone has ever been granted. Almost every American business we meet configured it once, years ago, and has had no owner since. We treat the tenant as something that has to be run rather than something that was installed, covering identity, licensing, security posture, the joiner and leaver process, and governance, with one named engineer answerable for its condition month by month.
- GDAPLeast-privilege access
- MonthlyTenant health report
- 9Standing disciplines
- 2-4Global admins, right-sized
Nine disciplines a managed tenant actually needs.
Admin roles and RBAC hygiene
Every permanent administrative right gets justified or removed. Admin work moves onto dedicated accounts rather than the mailbox somebody reads email in, multi-factor is mandatory on every privileged role, the emergency accounts are tested rather than assumed to work, and the whole list is revisited quarterly. Tenants arrive with five to ten global administrators as a matter of routine. Two to four is almost always the correct number.
License lifecycle management
Licenses matched to the people you employ now rather than the people you employed last year. Anything belonging to a leaver comes back inside the offboarding window, the mix of subscriptions is checked against features anyone actually uses, renewal dates are tracked, and commitment terms are chosen deliberately instead of arriving by automatic renewal. The first review almost always finds money sitting on the table.
Security posture and Secure Score
Secure Score is tracked every month and every movement is explained in writing rather than left as a number. Conditional access policies are maintained as the business changes, legacy authentication stays blocked, and new Microsoft defaults get assessed before they switch themselves on. A regression is caught the month it occurs rather than during a SOC 2 fieldwork week or an insurance renewal.
Joiner, mover, leaver lifecycle
Every arrival, move, and departure follows the same written process. New starters have the right license, the right groups, and an enrolled device waiting on their first morning. People changing role have access rebuilt around the new job rather than layered on top of the old one. Leavers are disabled, signed out everywhere, their mail and files transferred, and their license returned, every time, leaving a trail an auditor can follow.
Guest and external access governance
Every external account is traceable to who invited them, what they can currently reach, and the date their access ends. Teams carrying a lot of outside people get periodic access reviews, sharing rules are set per site according to how sensitive the content is rather than one blanket setting, and inactive guests are removed on a schedule. An ungoverned tenant almost always still has guests from engagements that closed years ago.
Domain and DNS integrity
Your domains sit verified in a registrar account your company owns rather than in a supplier one. Mail authentication stays at enforcement so nobody can send as you, the routing and discovery records are correct, and DNS or certificate changes go through change control instead of through whoever happens to remember the registrar password.
Backup and retention posture
A straight answer about what is protected and what is not. Microsoft runs a shared responsibility model, and neither a retention policy nor a recycle bin is a backup, whatever anyone told you at signing. We establish what genuinely needs backing up, deploy it where the case holds, set retention and legal hold to match your actual obligations, and then prove a restore works rather than assuming it.
Reporting and tenant evidence
One report a month, written so a non-technical director can read it: how the score moved, where licensing stands, which administrative rights changed hands, how many guests there are, which sign-ins looked risky, and what is still open and with whom. Audit logging is configured and retained properly, so that when an assessor, a carrier, or an enterprise customer questionnaire asks something, answering it is an export rather than a two-week investigation.
Configuration change control
Settings change on purpose and get recorded, so the configuration described in your audit is the configuration actually running. Microsoft pushes changes that affect your tenant continuously through the Message Center. We read them, work out which ones touch you, and either apply or defer each one deliberately, rather than finding out when a user calls.
The specific tenant problem you came here with.
Starting, moving, or taking over a tenant
There are three ways this work usually starts: building a tenant properly from nothing, a transaction that forces data to move between tenants, or recovering an existing tenant from whoever currently holds the keys.
- Microsoft 365 tenant setupA tenant built correctly at the first attempt: naming, domains, identity, the security baseline, and licensing, all registered to you from the opening day.
- Tenant-to-tenant migrationAcquisitions, disposals, and rebrands, where mail, files, Teams content, and identities all have to move between tenants against a planned cutover.
- Tenant takeover from a previous partnerTake administrative control back, cut the previous provider access without breaking anything, and settle who actually owns the tenant and the domain.
Multi-tenant and cross-tenant operations
For groups running more than one tenant, deliberately or by accident. Holding companies, PE-backed roll-ups, joint ventures, and companies mid-acquisition all live here.
- Microsoft 365 Lighthouse multi-tenant managementA single view across every tenant in the group, with the same baselines applied, delegated access, and posture visible for each company separately.
- Cross-tenant sync and collaborationPeople in different tenants working as one org: cross-tenant synchronization, trust settings, and shared channels done safely.
Governance and security posture
Two things determine whether a tenant stays healthy once the project team leaves: knowing who outside the company can reach your data, and having the secure configuration written down rather than remembered.
- Guest and external access governanceEveryone from outside the company accounted for, access that lapses without anybody remembering to revoke it, and sharing rules that follow how sensitive the data is.
- Tenant security baselineYour security configuration written down and actually enforced across identity, mail, sharing, and devices, with the evidence to back each control.
Four reasons US businesses hand us the tenant.
Microsoft partner with an operations discipline
Tenant operations is the core of what we do, not an upsell beside license resale. The engineer who reviews your Secure Score is on the same team that handles your escalations to Microsoft, and the monthly report is written by people who actually made the changes it describes.
GDAP least-privilege access, in writing
Our access runs through Granular Delegated Admin Privileges: named roles, granted by you, expiring on a date, and fully auditable. You can see precisely what we are able to touch from inside your own admin center and withdraw it yourself in a few clicks. There is no shared administrator account and no access you cannot inspect.
A monthly report your management can actually read
Not a dashboard link and a shrug. A written report each month covering what changed, which way the score moved and for what reason, how licensing compares against current headcount, how many administrators and guests exist, and every open item with a name and a date beside it. The same document serves as the evidence pack whenever an assessor, a carrier, or a large customer asks.
We work beside your IT team, or we are the IT team
Some companies have an IT manager who wants the tenant properly governed without losing control of it. Others have nobody at all. Both arrangements work here: we sit behind your internal IT as the standing tenant authority with the boundaries written down, or we are the entire function. In either case one named engineer is accountable for the state of the tenant.
Four situations where tenant management stops being optional.
No IT manager, and the tenant shows it
Companies between ten and a hundred and fifty people where Microsoft 365 was stood up by a founder, a contractor, or whoever had a free afternoon, and has never been deliberately reviewed since. The symptoms never vary: too many administrators, licenses paid for and unused, no offboarding worth the name, and a Secure Score nobody has opened. We become the owner your organization chart never had.
Fast-growing, and the setup is not keeping up
Headcount doubling, new departments appearing, and the first SOC 2 request or enterprise security questionnaire landing in someone inbox. A tenant that worked perfectly well at fifteen people becomes a liability at eighty. We get lifecycle, licensing, and access governance running properly before growth converts an informal setup into an incident report.
Post-incident, and it must not happen again
After a mailbox was compromised, a payment nearly went to the wrong account, or someone discovered a former employee still had access. The immediate hole is usually plugged by the time we arrive. What is missing is the ongoing discipline that stops it recurring. We harden the tenant and then keep it hardened, producing monthly evidence that the controls still hold. Your cyber carrier will ask for exactly that evidence sooner or later.
Multi-entity groups and roll-ups
A holding company or private equity platform with operating companies spread across several states, each running its own tenant, or worse, all crowded into one tenant nobody governs. We run the estate as a whole: identical baselines applied through Lighthouse, reporting broken out per company, and clean answers when each entity auditor, lender, or prospective buyer asks its own set of questions.
Could you name everyone with administrative rights over your tenant today?
Across every tenant we assess, the most serious recurring finding is never a missing security product. It is that nobody in the room can say who holds Global Administrator, and the actual list turns out to include the agency that built the website, a provider replaced two years ago, and somebody who left for a competitor. Checking takes ten minutes, and the answer reorders every other priority you have.
- In the Microsoft 365 admin center, open Roles and read the Global Administrator list end to end. Every single name should be a current employee you trust, working from a dedicated admin account with multi-factor enforced on it.
- Then look under Settings for partner relationships. A provider you stopped working with keeps genuine administrative reach into your tenant for as long as that relationship sits there unremoved.
- Last, find out whose name the domain is registered in. Whoever controls the registrar account decides where your mail is delivered, and no setting inside your tenant overrides that.
- Almost none of this is anyone acting in bad faith. It is simply what builds up when nobody owns the environment. It remains the largest single exposure most mid-market American companies carry, and it is fast to correct once somebody has actually looked.
Roughly four weeks from the first look to a tenant running properly.
- 1
Tenant access and posture check
Day 1, no charge
We establish who holds administrative roles, whether any old partner relationships are still live, who owns the domain, how far multi-factor actually reaches, where the score sits, and how licensing compares with headcount. The findings come in writing and are yours regardless of what happens next.
- 2
Scope and GDAP grant
Days 2-5
We settle how this will work: which parts we own, which stay with your team, how escalation runs, and how often you get reported to. You then approve the delegated access yourself, from your own admin center, with each least-privilege role named in the request.
- 3
Stabilize the tenant
Weeks 1-3
Surplus administrative rights come off, dormant accounts and forgotten guests are cleared out, multi-factor and conditional access are enforced properly, mail authentication moves to enforcement, wasted licensing is reclaimed, and the process for arrivals, moves, and departures is written down and running.
- 4
Steady state with monthly evidence
From week 4
The ongoing work begins: handling lifecycle changes, applying change control to tenant settings, tracking posture, and issuing the monthly report. Every quarter, administrative roles, the guest population, and the license mix all get reviewed from end to end.
What US businesses ask before handing over the tenant.
Where to go next.
Microsoft 365 Administration
The day-to-day admin layer: users, mailboxes, Teams, and SharePoint operations under one accountable team.
Tenant Security Baseline
The written hardening standard we apply and re-check: identity, mail, sharing, devices, monitoring, and data.
Microsoft 365 Services
The wider Microsoft 365 practice, covering build, migration, the applications themselves, and everyday support.
Start with the free tenant access and posture check.
Give us the domain and we will run the check: who holds administrative rights over your tenant right now, where the score and the licensing sit, and the three changes worth making first. The findings arrive in writing whether or not anything follows. If the tenant turns out to be in good order, you will hear that too.
Related Services
Explore more solutions that work great with this service
M365 Administration
Expert Microsoft 365 tenant management
Learn moreMicrosoft Entra
Identity and access management solutions
Learn moreMicrosoft Intune
Device management and endpoint security
Learn moreMicrosoft Defender
Advanced endpoint and email threat protection
Learn moreM365 Tenant Setup
New tenants configured securely from day one
Learn moreTenant Security Baseline
Documented controls mapped to CIS
Learn more