August 7, 2026
Microsoft 365 Admin Checklist for Beginners (What to Check First)
There's a familiar situation a lot of people reading this are probably in: you've just been handed Microsoft 365 admin access — maybe because you're the most technical person in the room, maybe because the last person left — and there's no documentation, no handoff notes, and no clear sense of what's actually been configured. You're not alone, and it's a genuinely common way people end up here.
Rather than trying to review everything at once, here's an ordered checklist for the first week that covers the things most likely to actually matter.
1. Confirm who has Global Admin
Start here, before anything else. Go to the Microsoft 365 admin center, find the list of Global Administrators, and just look at who's on it. You're checking for two things: is the list smaller than you'd expect (a single admin is a risk — see our guide on the right number of Global Admins), or is it larger than makes sense for the size of the company (a sign that admin access has been handed out too casually over time).
Don't remove anyone yet — just get an accurate picture of who currently has the highest level of access.
2. Confirm MFA is registered on those admin accounts specifically
Before you worry about MFA coverage for the whole company, check it for the Global Admins first. A Global Admin account without MFA registered is the single most urgent gap a new admin can find — it's the highest-value target in the tenant, and it's usually a quick, low-risk fix (unlike, say, changing a Conditional Access policy that might affect everyone).
3. Review guest, stale, and unlicensed accounts
Three quick checks, all in the user list:
- Guest accounts — external users who've been granted access to the tenant. Old projects and past collaborations tend to leave these behind long after they're needed.
- Stale accounts — users who haven't signed in for months. Could be a departed employee whose account was disabled but never fully offboarded, or just an account nobody's using anymore.
- Unlicensed accounts still consuming access — less common, but worth a glance.
None of these are usually emergencies, but they're the kind of thing that accumulates invisibly for years if nobody ever looks.
4. Check license counts and assignments
Pull up the licensing page in the admin center and compare purchased seats to assigned seats. It's common — genuinely common, not a sign anything was done wrong — for a meaningful chunk of purchased licenses to sit unassigned or attached to inactive accounts. (See our breakdown of exactly how common, with real numbers.) This is also usually the easiest of the four items to act on: reclaiming an unused license has no downside.
What this checklist deliberately leaves out
This is a first-week list, not a complete security audit. It doesn't cover Conditional Access policy configuration, Exchange mail flow rules, SharePoint sharing settings, or a dozen other things a full review would eventually touch. The point of these four checks specifically is that they're high-impact, low-risk to look at, and give you an honest baseline picture fast — without requiring you to already be a Microsoft 365 security expert on day one.
The shortcut, once you've done this manually once
Doing this checklist by hand is a completely reasonable way to get oriented the first time. If you're doing it across more than one tenant, or doing it again next quarter to see what's changed, a scan that runs these same checks automatically — Global Admin count and MFA status, guest exposure, license waste — turns this from an afternoon into a few minutes.