Skip to content
Essential or OperateSingle tenant or tenant portfolio

Your Microsoft 365 tenant, operated as a controlled production platform.

We run the operational layer across Microsoft Entra, Exchange Online, Teams, SharePoint, OneDrive, Intune, and the Microsoft 365 admin centre. Every material change receives an owner, authority, verification record, and evidence link.

Essential builds a tenant your own team can operate. Operate includes the mobilisation needed to validate that foundation or build what is missing, then keeps the queue, Microsoft change cycle, access model, and operating evidence current.

Do not send credentials, tenant IDs, administrative exports, recovery codes, or personal data through the public contact form. Scoped access is arranged after approval through a secure channel.

2

Clear service levels

Essential foundation or recurring Operate

10

Named runbooks

Readable operating procedures in the delivery kit

Read-only

First access mode

Observation before production change

Client-owned

Operating record

Decisions, evidence, and handover stay with you

The operational gap

The work that falls between Microsoft admin centres.

A tenant rarely fails because one portal is missing. It becomes expensive when ownership, authority, exceptions, Microsoft changes, and verification live in different places.

Requests live in inboxes

Mailbox permissions, guest access, Teams policies, and licence exceptions arrive as messages. The decision disappears once the request is closed. We move material work into one queue with an owner, authority, verification, and evidence record.

Administration is broader than the task

Routine work should not require Global Administrator or a shared account. Roles are mapped to the job, activated only when needed where the tenant supports PIM, and separated per tenant through GDAP when partner access fits.

Microsoft changes arrive without an owner

Message Center posts can affect user experience, policy behaviour, data handling, or feature retirement. We assess relevance, assign an owner, record the action, and connect the change to communication and validation.

The tenant drifts between admin centres

Entra, Exchange, Teams, SharePoint, OneDrive, Intune, and the Microsoft 365 admin centre all change independently. A shared baseline and exception ledger make the operating state inspectable.

Operating coverage

One operating surface across six workload groups.

The scope follows the tenant, subscriptions, internal ownership, and business dependencies. Workload projects stay separate. Operate covers the routine administration and governance paths explicitly agreed in the service catalogue.

Identity lifecycle

Connect joiner, mover, leaver, guest, group, and administrator work to named business authority.

  • User, group, and role ownership register
  • Joiner, mover, and leaver paths with exception handling
  • Guest sponsor and expiry review coordination
  • Routine roles separated from emergency access
  • PIM and access reviews where the selected licences support them

Exchange Online

Operate mail changes as controlled production work instead of isolated admin clicks.

  • Mailbox, shared mailbox, delegation, and forwarding requests
  • Accepted-domain and connector ownership
  • Distribution group and mail-enabled group administration
  • Transport and organisational setting changes
  • Microsoft support escalation with a retained case record

Teams, SharePoint, and OneDrive

Keep collaboration usable while ownership, sharing, and lifecycle remain visible.

  • Team and site ownership decisions
  • External-sharing and guest-access exceptions
  • Orphaned team, group, and site review
  • Sharing-link and collaboration setting changes
  • Copilot content-discoverability dependencies recorded where relevant

Intune and applications

Coordinate routine device and app administration where Intune is selected in the scope.

  • Policy and application assignment requests
  • Pilot group and rollout ownership
  • Configuration conflict and deployment follow-up
  • Exception and temporary exclusion review
  • Major endpoint projects scoped separately

Service health and Microsoft change

Distinguish a Microsoft incident from a tenant action, then keep stakeholders working from the same record.

  • Service Health incident and advisory assessment
  • Message Center relevance and action review
  • Stakeholder communication ownership
  • Microsoft support case coordination
  • Change calendar and retirement tracking

Licence and service governance

Record why a licence exists, who approved an exception, and when the decision must be revisited.

  • Group-based assignment model and direct-assignment exceptions
  • Inactive-account and licence reconciliation
  • Usage evidence where Microsoft exposes it
  • Renewal and service dependency register
  • Procurement kept separate from the technical recommendation

Tenant operations ledger

Inspect the queue, one change record, and the delivery kit.

The mechanism is deliberately practical. Work appears with an owner and authority question. A material change moves through explicit gates. The reason and evidence remain after the portal view changes.

Loading the interactive console

Privileged access

Least privilege is part of the service.

Routine operations do not justify routine Global Administrator. The access model separates daily tasks, time-bound privilege, partner delegation, and customer-owned emergency access.

Emergency access stays outside normal administration.

The client remains the custodian. The operating model records monitoring, exclusions, validation, authority, and what must happen if an emergency identity is used.

Read-only first

The baseline begins with observation. Credentials, tenant IDs, exports, and administrative data are exchanged only through an approved secure channel after scope approval.

No routine Global Administrator

Routine work uses the least-privileged role for the task. PIM provides eligible or time-bound role activation where the selected Microsoft Entra licence supports it.

Tenant-specific partner access

Where GDAP fits, each tenant grants granular, time-bound, explicitly approved access. Shared administrator accounts and universal credentials are excluded.

Customer-owned emergency access

Emergency-access accounts stay outside normal administration. They remain under client control, are monitored for use, and are validated through a scheduled operating test.

Client decision authority

Tenant-wide consent, data deletion, retention changes, security-control reduction, emergency access, and high-impact enforcement require explicit authority defined in the scope.

Two service levels

Essential builds the operating system. Operate keeps it alive.

Both service levels include client ownership, explicit boundaries, and a documented exit. Operate adds recurring administration and operating cadence, with capacity and response objectives fixed in the SoW.

A fixed-scope operating foundation

Tenant Operations Foundation

Essential

An internal IT team that inherited a fragmented tenant and needs one documented way to run it.

Essential establishes ownership, authority, baselines, runbooks, and the operating backlog. It can stand alone or become the mobilisation stage for Operate.

Included

  • Read-only tenant and workload inventory
  • Admin role, delegated-access, and emergency-access operating model
  • Authority matrix for requests, approvals, execution, and accepted risk
  • Joiner, mover, leaver, guest, group, and licence operating design
  • Exchange, Teams, SharePoint, OneDrive, and Intune decisions for the agreed scope
  • Service Health and Message Center triage workflow
  • Configuration snapshot, exception ledger, and prioritised backlog
  • Ten named runbooks, evidence templates, handover walkthrough, and Exit Kit

Operating arc

  • Observe the current tenant without enforcement changes
  • Agree ownership, authority, scope, and operational dependencies
  • Build the registers, runbooks, baseline, and ranked backlog
  • Validate the handover with the client team

Outcome

A documented tenant your own team or a successor provider can operate.

A recurring operating service

Managed Tenant Operations

Operate

An organisation that wants the tenant queue, Microsoft change cycle, and operating evidence actively maintained.

Operate includes a scoped mobilisation to validate an equivalent operating foundation or build what is missing, then keeps the agreed administration service running through named work queues and client-controlled change authority.

Included

  • Managed work queue and agreed production change windows
  • Approved identity lifecycle and routine workload administration
  • Licence assignment and exception reconciliation
  • Guest, group, site-owner, and privileged-access review coordination
  • Message Center impact assessment and Service Health triage
  • Microsoft support case coordination and retained case record
  • Drift review against the agreed baseline with approved remediation
  • Quarterly operating review, updated runbooks, evidence pack, and Exit Kit
  • Optional tenant-portfolio rollout with separate GDAP and evidence per tenant
  • Service hours, response objectives, included capacity, and escalation authority fixed in the SoW

Operating arc

  • Triage the agreed queue within the contracted service window
  • Assess, approve, apply, verify, and record material changes
  • Review Microsoft changes, health, licences, access, and exceptions
  • Refresh the operating backlog and client-owned evidence

Outcome

A tenant with a named operating cadence, a visible queue, and evidence for every material action.

Managing a tenant portfolio?

Operate can use a shared standard with local overlays, separate access, evidence, owners, and rollout decisions for each tenant. Microsoft 365 Lighthouse is used only where its requirements are met.

Plan a tenant portfolio

What lands

An operating pack a successor can inspect.

Every artefact answers a practical question: who owns the service, who may approve the change, which role was used, what changed, how it was verified, and what remains open.

Evidence supports operations. It does not issue assurance.

Framework mapping can be added for agreed control objectives. The pack is not legal advice, certification, regulator approval, or a guarantee that every Microsoft audit record is retained indefinitely.

Tenant operating baseline

TENANT-OPERATING-BASELINE.md

In-scope workloads, owners, authoritative sources, current state, known exceptions, dependencies, and the ranked operating backlog.

Admin and delegated-access register

ADMIN-ACCESS-REGISTER.md

Named identities, roles, assignment type, GDAP relationship, PIM requirement, approver, purpose, expiry, and review result.

Change and exception ledger

CHANGE-AND-EXCEPTION-LEDGER.md

Request, owner, authority, role used, before and after state, reversal path, verification, evidence, residual risk, and review date.

Service ownership matrix

TENANT-SERVICE-REGISTER.md

Workload, business owner, technical owner, approver, escalation route, support dependency, and communication audience.

Licence decision ledger

LICENCE-ASSIGNMENT-LEDGER.md

Assignment method, business need, usage evidence when available, exception, renewal dependency, decision owner, and next review.

Microsoft change and health record

MICROSOFT-CHANGE-AND-HEALTH-LOG.md

Message Center items, Service Health incidents, affected services, required actions, stakeholder updates, support cases, and closure notes.

Ten operating runbooks

runbooks/

Human-readable procedures for identity lifecycle, licences, guests, sharing, Microsoft changes, emergency access, and transfer-out.

Exit Kit

EXIT-KIT.md

Current owners, access removal, baselines, registers, runbooks, open work, evidence locations, and successor-provider handover.

Scope boundaries

Your team keeps decision authority.

Managed administration works when the request catalogue, authority, service window, capacity, and escalation boundaries are explicit. Operate is not an unlimited support promise.

Inside the agreed service

  • The selected Microsoft 365 workloads and standard request catalogue
  • Named queue, change control, role activation, verification, and evidence
  • Identity lifecycle, collaboration, licence, health, and Microsoft change work agreed in the SoW
  • Support-case coordination and stakeholder updates during the contracted service window
  • Runbook maintenance, operating review, Exit Kit, and access removal

Client authority and inputs

  • Authoritative HR, identity, asset, licence, and business-owner information
  • Named requestors, approvers, risk owners, and communication contacts
  • Appropriate Microsoft subscriptions for selected features
  • Approved secure access, evidence location, change windows, and user communication
  • An internal or retained on-call path for work outside the contracted service window

Separate project or provider

  • Unlimited end-user helpdesk, deskside support, or hardware logistics
  • 24/7 SOC, MDR, live breach command, forensics, or legal notification decisions
  • Tenant hardening projects, Defender XDR deployment, backup, migration, or major Intune rollout
  • Microsoft 365 Copilot rollout, adoption programme, or custom agent implementation
  • Certification, regulator approval, legal advice, or a guarantee of Microsoft service availability

Public operating guidance

The model is grounded in Microsoft administration guidance.

These references support the access, change, service-health, and multi-tenant mechanics described on this page. Service scope still depends on the actual tenant and subscriptions.

Microsoft relationship

CSP Indirect Reseller

CSP Indirect Reseller active. PLA 7113951.

Delivery

Founder-led

The person scoping the operating model remains directly involved in delivery.

Administration

Least privilege

Named identities, scoped roles, explicit approvals, and no shared Global Administrator.

Exit

Client-owned

Registers, runbooks, evidence, and handover records stay in the approved client repository.

Questions before the scope

The boundaries buyers should see before signing.

Do you replace our internal IT team?

No. Essential gives the internal team a documented operating model. Operate can own the agreed recurring queue while business authority and strategic decisions remain with the client.

Is Operate an unlimited end-user helpdesk?

No. The SoW defines the workloads, standard request types, service window, included capacity, response objectives, escalation path, and overflow treatment. End-user helpdesk and deskside support are separate.

Do you make production changes without approval?

Only pre-authorised standard changes may follow a standing approval model. Normal and emergency changes follow the client's documented authority matrix. High-impact actions always require explicit authority.

What administrative access do you need?

Read-only roles are used first. Routine work uses the least-privileged workload role. GDAP provides granular and time-bound partner access where appropriate. PIM is used for just-in-time role activation where the tenant is licensed for it.

Do you need Global Administrator?

Not for routine operations. A time-bound high-privilege role may be required for a narrowly approved task when Microsoft has no lower-privilege path. Customer-owned emergency-access accounts remain outside the normal administration route.

What happens during a Microsoft outage?

Operate checks Service Health, distinguishes a Microsoft incident from a tenant issue, coordinates the support case where appropriate, records impact, and updates named stakeholders during the contracted service window. ITSailor cannot repair Microsoft's service or guarantee its availability.

Are Intune, Purview, PIM, access reviews, and Copilot always included?

No. Their availability and control depth depend on the subscriptions in the tenant and the agreed service scope. Major deployments remain separate projects. The operating model records missing prerequisites rather than promising unavailable features.

Can you manage several tenants?

Yes. Each tenant keeps a separate GDAP relationship, access group, operating baseline, exception register, evidence location, and local owner. Microsoft 365 Lighthouse can support portfolio visibility where the tenants and partner relationship meet its requirements.

Does this include security incident response?

Operate can execute a client-triggered and pre-authorised containment step that is explicitly written into a runbook and the SoW. Continuous monitoring, threat hunting, forensics, breach command, MDR, and 24/7 response are separate.

Can the evidence certify DORA, NIS2, GDPR, or ISO 27001 compliance?

No. The operating record can support control-to-evidence mapping for agreed objectives. It is implementation evidence, not legal advice, certification, assurance, or regulator approval.

What remains if we stop Operate?

The current baseline, access register, service ownership, change and exception ledger, licence decisions, Microsoft change record, runbooks, backlog, evidence locations, and access-removal confirmation remain in the Exit Kit.

Who actually performs the work?

Delivery is founder-led. The SoW names the delivery and client roles without inventing a larger service team. If retained specialist coverage or an external provider is required, that dependency is stated before the scope is signed.

Decide who owns the tenant work before the next change arrives.

Send the workloads, tenant count, internal ownership, current request path, service window and the work your team wants to keep. We scope Essential, Operate, or say when a separate project is the honest answer.