This checklist assumes MFA (multi-factor authentication, a password plus a second step) is already on. It isn't a setup guide. Think of it as the clean-up pass that keeps admin access small, named, and easy to explain.
Small Microsoft 365 tenants pick up clutter over time. Someone's daily mailbox ends up holding Global Admin. A former contractor's guest account is still there. A shared office@ password gets passed around. None of that is unusual, and each item takes a few minutes to fix once you can see it.
It's written for an owner or office manager with admin access, or one who can sit next to whoever has it. Plan on about an hour the first time, and less each quarter after that.
How should a small business manage Microsoft 365 admins? Give admin work its own accounts, separate from everyday email. Keep Global Admin to a short list of named people. Give everyone else the smallest role that does the job. Each quarter, remove stale admins and guests, confirm the audit log is on, check that admin-change alerts reach a person, and review which apps users can approve.
Shared mailbox, not shared password
A shared mailbox like office@ or billing@ is fine. A shared password isn't.
Microsoft's shared mailbox guidance says every shared mailbox has a user account with a system-generated password "that isn't known or intended for use," and it adds: "Always block sign-in for the shared mailbox account and keep it blocked." People get to the mailbox through permissions on their own accounts, so each action traces back to one person.
| Habit | Who signed in? | What to do |
|---|---|---|
Three people know the office@ password | Can't tell | Convert to a shared mailbox, grant each person access, block sign-in |
| Shared mailbox, each person uses their own account | Each named person | Keep it |
Shared admin login like admin@ | Can't tell | Give each admin their own admin account |
CISA's (the Cybersecurity and Infrastructure Security Agency) Cybersecurity Performance Goals 2.0 cover this in goal 3.C, Create Unique Credentials: every service gets its own login, passwords are never reused, and admin passwords are never the same ones used day to day.
Give admin work its own account
CPG 2.0 goal 3.G, Administrators Maintain Separate User and Privileged Accounts, says "User accounts do not have administrator privileges." Admins keep a separate account "for activities unrelated to their admin role, such as business email and web browsing," and privileges "are re-evaluated on a recurring basis."
In practice, the owner has two sign-ins: a daily account for mail, Teams, and files, and an admin account used only in the admin centers. Nobody reads mail or browses the web from the admin account.
Emergency access accounts
Microsoft's emergency access guidance recommends two or more emergency access (break-glass) accounts, so a lost phone or a locked-out admin doesn't lock out the whole tenant. These accounts keep MFA. Microsoft says to use phishing-resistant methods, such as FIDO2 security keys or certificate-based authentication, "that are different from your normal admin accounts." Store the keys and passwords so two trusted people know where they are. If you've never set one up, the MFA setup guide covers the first one.
Fewer Global Admins, smaller roles
Global Admin is the top Microsoft 365 role, and it can change nearly every setting.
Microsoft's admin roles overview says to "have as few global administrators as possible" and to assign the least permissive role. Its example is someone who resets passwords. They don't need Global Admin, because a role like Password Administrator or Helpdesk Administrator will do. Microsoft's Entra role best practices recommend assigning Global Administrator "to fewer than five people in your organization."
For a team of 5 to 50, that usually means a short list: the owner's admin account, a second trusted admin, and the emergency accounts. Your IT host may need a role too, so ask which one and whether it really has to be Global Admin.
Legacy authentication, in plain English
Legacy authentication means older sign-in methods used by some old mail apps and devices. Microsoft's Security Defaults page says it plainly: "Legacy authentication doesn't support multifactor authentication." With Security Defaults on, "all authentication requests made by an older protocol will be blocked."
Microsoft's MFA for Microsoft 365 page says organizations "can use security defaults or Conditional Access policies, but not both at the same time." So confirm which one your tenant uses. If it's Security Defaults, legacy sign-in is blocked by that setting. If it's Conditional Access, ask your IT host to show you the policy that blocks legacy authentication. Conditional Access needs a license that includes it, such as Entra ID P1 or Business Premium; the MFA setup guide has the license table. Either path works, as long as you don't stack them.
For this pass, your job as owner is the inventory: list any old mail apps, scanners, or copiers that send mail, and ask your host whether each one still relies on an older sign-in. Microsoft warns to make sure administrators aren't using older protocols before Security Defaults is turned on.
The quarterly review
Stale admins and ex-employees
Open Users > Active users in the Microsoft 365 admin center. Mark anyone who has left, plus contractors whose work is done. CPG 2.0 goal 3.D, Revoking Credentials for Departing Staff, includes contractors and vendors and asks for "a defined and enforced administrative process to off board staff." Microsoft's remove a former employee series walks through blocking sign-in first, then handling mail and OneDrive. Check that their admin roles are gone, not just their license.
Guests
Guests are outside people invited into Teams, SharePoint, or groups. Microsoft's access reviews overview suggests checking for "invited guests or partners that haven't been removed after being assigned to do an administrative task" (the automated access-review feature needs Entra ID Governance; the manual check below doesn't). Open Users > Guest users, list each guest, and ask the person who invited them whether the project is still active. If nobody can vouch for a guest, remove them.
Admin role count
List every account with an admin role and write down why it has that role. Compare the Global Admin count against Microsoft's "fewer than five." Move anyone who only resets passwords or manages billing to a smaller role.
Audit log
The audit log records who changed what. Microsoft's audit search page says audit log search "is turned on by default for Microsoft 365 and Office 365 enterprise organizations," and tells admins to verify the current setting. That wording says enterprise organizations, so if you're on a Business plan, confirm with your IT host that it's on. Ask your host to confirm it's on for your tenant, then run one search for admin role changes in the last 90 days.
Alerts
Microsoft's alert policies include the Exchange admin-role alert, "Elevation of Exchange admin privilege." It covers Exchange Online role changes only, not Entra roles like Global Administrator. Availability depends on your plan; ask your IT host. Its description: "Generates an alert when someone is assigned administrative permissions in your Exchange Online organization." The check is simple. Who gets these alerts, and does that person read them? If the answer is a former employee's mailbox, update it.
App consent
Some apps ask users to "accept" access to their mail or files. Microsoft's user consent settings page says that, to reduce the risk of malicious apps tricking users, "we recommend that you allow user consent only for applications that have been published by a verified publisher." Note your current setting, and ask your host whether it matches that recommendation.
Printable quarterly checklist
| # | Check | Where to look | Pass looks like | Screenshot to save | Date / initials |
|---|---|---|---|---|---|
| 1 | Shared mailboxes have sign-in blocked | Active users, each shared mailbox | Blocked; people use their own accounts | Sign-in status | |
| 2 | Admins use separate admin accounts | Roles list vs daily mailboxes | No daily mailbox holds an admin role | Role assignments | |
| 3 | Global Admin count | Roles > Role assignments > Global Administrator | Short named list, fewer than five | Member list (redacted) | |
| 4 | Emergency accounts exist and keep MFA | Your emergency access record | Two accounts, phishing-resistant method different from daily admins | Record page, no secrets | |
| 5 | One path: Security Defaults or Conditional Access (licensing) | Entra admin center | One path, legacy sign-in blocked | Setting or policy | |
| 6 | Leavers and finished contractors removed | Active users | None remain; no leftover roles | User list | |
| 7 | Stale guests removed | Guest users | Each guest has a named sponsor | Guest list (redacted) | |
| 8 | Audit log on | Purview Audit | Search returns results | Search page | |
| 9 | Exchange admin-role alert reaches a person | Alert policies | Current recipient; availability depends on your plan, ask your IT host | Recipient setting | |
| 10 | App consent setting known | Entra consent settings | Matches what your host recommends | Setting |
Redact names in screenshots if the folder is shared. Save them in the same evidence folder as your MFA and backup logs, with the date in the file name. CISA's Four Cybersecurity Essentials for Businesses is a good one-page companion for the rest of the baseline.
How this fits with the MFA drill
This pass doesn't replace enrollment. A clean admin list still needs every person signed up for MFA. Run the MFA coverage drill first if you haven't this quarter, then this pass. The drill asks "is everyone enrolled?" This checklist asks "who has admin power, and should they?"
Related guides
- MFA setup for Microsoft 365: turn on MFA and set up the first emergency account
- MFA coverage drill: confirm every person is enrolled
- 5 security mistakes Houston SMBs make: why admin accounts and daily email should be separate
- Ask your IT host these 8 questions: get dated proof before you renew
- Resources: CISA and NIST references
Educational content only — not legal, insurance, or compliance advice.