Microsoft 365 tenants do not decay dramatically. They drift. A policy gets switched off for a project and never switched back, a guest joins for a bid that finished in March, licences follow people who left. Nothing breaks, and that is precisely the problem.

In short: A quarterly pass of about thirty minutes catches most tenant drift. Check global administrator count and any Conditional Access exclusions that have accumulated, review guest accounts by last activity, look for licences assigned to disabled or departed accounts, confirm no Conditional Access policy has been left in report only or off, review new enterprise applications and consent grants, check device compliance percentage, and confirm your break glass account still works. Write down what you changed, because the value compounds only if the next pass can see the last one.

Why quarterly, and why short

Annual reviews are too infrequent to catch the thing that was switched off in month two. Monthly is more than most of this needs and does not survive a busy quarter. Three months is short enough that drift stays small and long enough that the meeting is worth having.

Keeping it to thirty minutes matters more than being thorough. A short check that happens every quarter beats a comprehensive one that happens once and then gets abandoned, and this list is deliberately the items where drift is both common and consequential.

The checks

  • Global administrators. Count them. The number should be small and you should recognise every name. Privileged roles accumulate during projects and rarely get handed back. While you are there, check nothing has been granted permanently that should be time bound.
  • Conditional Access exclusions. This is the highest value item on the list. Exclusions get added to unblock someone urgently and are almost never removed. Open each policy and look at who is excluded and why. An MFA policy with eleven exclusions is not an MFA policy.
  • Policies in report only or off. Someone set it to report only to test it and moved on. It looks configured on a dashboard and enforces nothing.
  • Guest accounts by last activity. Sort by last sign in, not alphabetically. Anything dormant for a quarter is a candidate for removal. Guests from finished projects are a standing route into your tenant that nobody is monitoring.
  • Licences on disabled or departed accounts. The most reliable money on this list, and the reason it belongs in the same pass as the security items, since offboarding usually removes access but leaves the subscription attached.
  • New enterprise applications and consent grants. What has connected to your tenant since last quarter, and what did it ask for? This is where unsanctioned AI tools show up, which is the discovery pass in finding shadow AI in your business.
  • Device compliance percentage. Not the policy, the actual number. If compliance has slipped from 94 to 78 percent, something changed and it is better to know now.
  • Break glass account. Confirm it exists, is still excluded from every Conditional Access policy, and that someone can actually retrieve the credential. Test it. An untested emergency account is a belief, not a control.
  • Sharing settings and any new anyone links. Defaults get changed for a reason that has since passed.
  • Secure Score movement. Not as a target to chase, but as a direction indicator. A score that has fallen since last quarter is a prompt to ask what changed.

"Almost every incident we review has an exclusion in it. Someone needed access on a Friday, and nobody put it back."

Four quarterly Microsoft 365 tenant checks: licensing, guest accounts, policies and devices
Four passes, thirty minutes. Enough to catch drift before it compounds.

Record what you found

The check is worth roughly double if the next one can see the last one. A short note per quarter, three or four lines, listing what you changed and what you decided to leave, turns a repeated task into a trend you can read.

It also answers a question that arrives sooner or later from an insurer, an auditor or a customer's procurement team: how do you know your configuration has not drifted? A dated record of quarterly reviews is a far better answer than a policy document saying you intend to do them.

Who should do it

Ideally not the person who made the changes. A second pair of eyes catches the exclusion added for a good reason that has since become permanent, because the person who added it remembers the reason and not the exception.

If nobody has the time, that is worth naming rather than absorbing. Configuration drift is quiet until it is not, and this list is the cheapest insurance available against the failure modes we see most. It is a standing part of our managed IT service, and if you want to see where a tenant sits before setting up a routine, the Microsoft 365 security posture assessment is a good starting point.

SC
Systech Cloud Team

The Systech IT Solutions cloud team, helping UK businesses get more from their Microsoft investment.