Buying Microsoft 365 licences is a procurement decision. Running the tenant is an operations decision. They are routinely confused, which is how a business can be “on Microsoft 365” and still have shared passwords, leftover accounts, and files nobody can quite explain.
Microsoft provides the platform. Someone still has to administer identity, decide who is an administrator, keep email trustworthy, and retire access when people leave. Licences do not do that work on their own.
The tenant is the business, not a side account
Email, files, meetings, devices and a growing number of line-of-business add-ons now sit in one directory. If that directory is untidy, everything built on it is untidy.
Microsoft 365 as Radius talks about it is the tenant as a managed environment: identity, collaboration, licences and hygiene. Microsoft remains the platform vendor. Radius does not become Microsoft, and this article does not claim a partner designation.
Identity, MFA and administrator accounts
Most serious incidents in small Microsoft 365 tenants still start with identity. A guessed password. A reused password. An old account. An administrator who uses the same login for daily email.
MFA should be required for important accounts. “Required” means it is actually enforced, not mentioned in an induction pack. Shared mailboxes should not be an excuse for shared passwords. Guest access should be intentional.
Administrator accounts deserve extra care: named people, used for administration, not for browsing the web. If everyone is a global administrator because it was easier on day one, the tenant is running on luck.
“Microsoft 365 is not “insecure by default”. It is unfinished if nobody is administering it. Those are different statements.”
Joiners, movers and leavers
A new starter who waits a week for email is an operations failure. A leaver who still has a mailbox, Teams access and a laptop login is a security failure. Movers — people who change role — are where permissions quietly accumulate.
The work is boring and it has to be repeatable: a request, a named owner, a checklist that includes group membership, shared mailboxes, files, devices and any connected applications.
This is why supporting people and tenant administration belong together. Account lifecycle is not a separate “HR IT” problem.
Permissions, email authentication and security configuration
Permissions should be granted to roles, not to whoever asked most recently. Review them. Remove what is unused.
Email authentication (SPF, DKIM, DMARC and the related DNS records) is how other systems decide whether your mail is genuine. It is not glamorous. Getting it wrong affects deliverability and impersonation risk. Changing those records is a Microsoft 365 and DNS conversation — and DNS for Radius’s own domain is a separate operational boundary from customer tenants.
Security configuration in the tenant should match how the business actually works: who can enrol devices, what is blocked, what is logged. Cyber security here is maintenance, not a one-off hardening weekend. Protecting the business is the outcome that maintenance is for.
Licence hygiene and data considerations
Licences pile up. Someone leaves and the licence stays assigned. A trial becomes a habit. A heavier SKU is bought for one person and copied to everyone “to be safe”. Hygiene is a scheduled review: who has what, whether they still need it, and whether a cheaper or more appropriate licence would do.
Data considerations are easier to ignore until a Subject Access Request, a dispute, or a ransomware event. Where does important information live — Exchange, SharePoint, OneDrive, a Teams chat, a laptop desktop? Who can export it? What is retained, and on purpose?
Microsoft 365 backup is its own subject. Retention in Microsoft is not the same as an independent recovery copy. If that matters to the business, it should be an explicit decision, not an assumption.
Tenant documentation and ongoing review
Write down the basics: domains, licence mix, who the administrators are, which security defaults or conditional access you rely on, where files live, which third-party apps have been granted access.
Then look at it again. Tenants drift. New apps are consented. Sharing policies loosen. A review on a sensible cadence is cheaper than discovering the drift during an incident.
If you want a structured conversation about whether the tenant is being run or merely occupied, start with a Technology Review.