← Back to blog

2026-10-09 · Identity & Access

Microsoft 365 Admin Hygiene Checklist for Small Teams

A quarterly admin hygiene pass for Microsoft 365 teams of 5–50: separate admin accounts, fewer Global Admins, stale admins and guests removed, the audit log, alerts, and app consent.

This checklist assumes MFA (multi-factor authentication, a password plus a second step) is already on. It isn't a setup guide. Think of it as the clean-up pass that keeps admin access small, named, and easy to explain.

Small Microsoft 365 tenants pick up clutter over time. Someone's daily mailbox ends up holding Global Admin. A former contractor's guest account is still there. A shared office@ password gets passed around. None of that is unusual, and each item takes a few minutes to fix once you can see it.

It's written for an owner or office manager with admin access, or one who can sit next to whoever has it. Plan on about an hour the first time, and less each quarter after that.

How should a small business manage Microsoft 365 admins? Give admin work its own accounts, separate from everyday email. Keep Global Admin to a short list of named people. Give everyone else the smallest role that does the job. Each quarter, remove stale admins and guests, confirm the audit log is on, check that admin-change alerts reach a person, and review which apps users can approve.

Shared mailbox, not shared password

A shared mailbox like office@ or billing@ is fine. A shared password isn't.

Microsoft's shared mailbox guidance says every shared mailbox has a user account with a system-generated password "that isn't known or intended for use," and it adds: "Always block sign-in for the shared mailbox account and keep it blocked." People get to the mailbox through permissions on their own accounts, so each action traces back to one person.

HabitWho signed in?What to do
Three people know the office@ passwordCan't tellConvert to a shared mailbox, grant each person access, block sign-in
Shared mailbox, each person uses their own accountEach named personKeep it
Shared admin login like admin@Can't tellGive each admin their own admin account

CISA's (the Cybersecurity and Infrastructure Security Agency) Cybersecurity Performance Goals 2.0 cover this in goal 3.C, Create Unique Credentials: every service gets its own login, passwords are never reused, and admin passwords are never the same ones used day to day.

Give admin work its own account

CPG 2.0 goal 3.G, Administrators Maintain Separate User and Privileged Accounts, says "User accounts do not have administrator privileges." Admins keep a separate account "for activities unrelated to their admin role, such as business email and web browsing," and privileges "are re-evaluated on a recurring basis."

In practice, the owner has two sign-ins: a daily account for mail, Teams, and files, and an admin account used only in the admin centers. Nobody reads mail or browses the web from the admin account.

Emergency access accounts

Microsoft's emergency access guidance recommends two or more emergency access (break-glass) accounts, so a lost phone or a locked-out admin doesn't lock out the whole tenant. These accounts keep MFA. Microsoft says to use phishing-resistant methods, such as FIDO2 security keys or certificate-based authentication, "that are different from your normal admin accounts." Store the keys and passwords so two trusted people know where they are. If you've never set one up, the MFA setup guide covers the first one.

Fewer Global Admins, smaller roles

Global Admin is the top Microsoft 365 role, and it can change nearly every setting.

Microsoft's admin roles overview says to "have as few global administrators as possible" and to assign the least permissive role. Its example is someone who resets passwords. They don't need Global Admin, because a role like Password Administrator or Helpdesk Administrator will do. Microsoft's Entra role best practices recommend assigning Global Administrator "to fewer than five people in your organization."

For a team of 5 to 50, that usually means a short list: the owner's admin account, a second trusted admin, and the emergency accounts. Your IT host may need a role too, so ask which one and whether it really has to be Global Admin.

Legacy authentication, in plain English

Legacy authentication means older sign-in methods used by some old mail apps and devices. Microsoft's Security Defaults page says it plainly: "Legacy authentication doesn't support multifactor authentication." With Security Defaults on, "all authentication requests made by an older protocol will be blocked."

Microsoft's MFA for Microsoft 365 page says organizations "can use security defaults or Conditional Access policies, but not both at the same time." So confirm which one your tenant uses. If it's Security Defaults, legacy sign-in is blocked by that setting. If it's Conditional Access, ask your IT host to show you the policy that blocks legacy authentication. Conditional Access needs a license that includes it, such as Entra ID P1 or Business Premium; the MFA setup guide has the license table. Either path works, as long as you don't stack them.

For this pass, your job as owner is the inventory: list any old mail apps, scanners, or copiers that send mail, and ask your host whether each one still relies on an older sign-in. Microsoft warns to make sure administrators aren't using older protocols before Security Defaults is turned on.

The quarterly review

Stale admins and ex-employees

Open Users > Active users in the Microsoft 365 admin center. Mark anyone who has left, plus contractors whose work is done. CPG 2.0 goal 3.D, Revoking Credentials for Departing Staff, includes contractors and vendors and asks for "a defined and enforced administrative process to off board staff." Microsoft's remove a former employee series walks through blocking sign-in first, then handling mail and OneDrive. Check that their admin roles are gone, not just their license.

Guests

Guests are outside people invited into Teams, SharePoint, or groups. Microsoft's access reviews overview suggests checking for "invited guests or partners that haven't been removed after being assigned to do an administrative task" (the automated access-review feature needs Entra ID Governance; the manual check below doesn't). Open Users > Guest users, list each guest, and ask the person who invited them whether the project is still active. If nobody can vouch for a guest, remove them.

Admin role count

List every account with an admin role and write down why it has that role. Compare the Global Admin count against Microsoft's "fewer than five." Move anyone who only resets passwords or manages billing to a smaller role.

Audit log

The audit log records who changed what. Microsoft's audit search page says audit log search "is turned on by default for Microsoft 365 and Office 365 enterprise organizations," and tells admins to verify the current setting. That wording says enterprise organizations, so if you're on a Business plan, confirm with your IT host that it's on. Ask your host to confirm it's on for your tenant, then run one search for admin role changes in the last 90 days.

Alerts

Microsoft's alert policies include the Exchange admin-role alert, "Elevation of Exchange admin privilege." It covers Exchange Online role changes only, not Entra roles like Global Administrator. Availability depends on your plan; ask your IT host. Its description: "Generates an alert when someone is assigned administrative permissions in your Exchange Online organization." The check is simple. Who gets these alerts, and does that person read them? If the answer is a former employee's mailbox, update it.

App consent

Some apps ask users to "accept" access to their mail or files. Microsoft's user consent settings page says that, to reduce the risk of malicious apps tricking users, "we recommend that you allow user consent only for applications that have been published by a verified publisher." Note your current setting, and ask your host whether it matches that recommendation.

Printable quarterly checklist

#CheckWhere to lookPass looks likeScreenshot to saveDate / initials
1Shared mailboxes have sign-in blockedActive users, each shared mailboxBlocked; people use their own accountsSign-in status
2Admins use separate admin accountsRoles list vs daily mailboxesNo daily mailbox holds an admin roleRole assignments
3Global Admin countRoles > Role assignments > Global AdministratorShort named list, fewer than fiveMember list (redacted)
4Emergency accounts exist and keep MFAYour emergency access recordTwo accounts, phishing-resistant method different from daily adminsRecord page, no secrets
5One path: Security Defaults or Conditional Access (licensing)Entra admin centerOne path, legacy sign-in blockedSetting or policy
6Leavers and finished contractors removedActive usersNone remain; no leftover rolesUser list
7Stale guests removedGuest usersEach guest has a named sponsorGuest list (redacted)
8Audit log onPurview AuditSearch returns resultsSearch page
9Exchange admin-role alert reaches a personAlert policiesCurrent recipient; availability depends on your plan, ask your IT hostRecipient setting
10App consent setting knownEntra consent settingsMatches what your host recommendsSetting

Redact names in screenshots if the folder is shared. Save them in the same evidence folder as your MFA and backup logs, with the date in the file name. CISA's Four Cybersecurity Essentials for Businesses is a good one-page companion for the rest of the baseline.

How this fits with the MFA drill

This pass doesn't replace enrollment. A clean admin list still needs every person signed up for MFA. Run the MFA coverage drill first if you haven't this quarter, then this pass. The drill asks "is everyone enrolled?" This checklist asks "who has admin power, and should they?"

Related guides


Educational content only — not legal, insurance, or compliance advice.

Need help implementing this in Houston?

Houston Secure IT can walk through MFA, backups, and a practical baseline with you.

713-364-8666 — Houston Secure IT / shop line