You just purchased a Microsoft 365 subscription. What’s next?
Buying Microsoft 365 is only the first step. To get value quickly and avoid security, licensing, and migration surprises, use the first 30 days to confirm your tenant, assign licenses correctly, secure identities, prepare email, and set up collaboration, devices, backup, and user training.
Start with the tenant basics
Sign in to the Microsoft 365 admin center and confirm who owns the tenant, who has Global Administrator access, your tenant ID, and your default .onmicrosoft.com domain. Document your billing contacts, technical contacts, partner relationship, and emergency access process. Add and verify your custom domain, then configure required DNS records for Exchange Online, Teams, and device/user sign-in as needed. Current Microsoft references: Microsoft 365 admin center overview at https://learn.microsoft.com/microsoft-365/admin/admin-overview/admin-center-overview, add users at https://learn.microsoft.com/microsoft-365/admin/add-users/add-users, assign licenses at https://learn.microsoft.com/microsoft-365/admin/manage/assign-licenses-to-users, create a shared mailbox at https://learn.microsoft.com/microsoft-365/admin/email/create-a-shared-mailbox, and add a domain at https://learn.microsoft.com/microsoft-365/admin/setup/add-domain.
Understand your licensing before you assign everything
If you purchased through a Cloud Solution Provider, your subscription is likely governed by Microsoft’s New Commerce Experience (NCE). Review whether each subscription is monthly, annual, or multi-year, whether it is billed monthly or upfront, the renewal date, and the cancellation or seat-reduction window. Annual commitments can help with pricing predictability but usually limit reductions until renewal. Monthly subscriptions provide more flexibility but typically cost more. Before assigning licenses, map users by role: full users, frontline users, shared mailbox users, contractors, administrators, and service accounts. Also review service plan toggles so users receive only the workloads they need. If IT Partner manages your tenant, delegated access should use Microsoft Granular Delegated Admin Privileges (GDAP), not legacy broad delegated administration.
Create users, groups, and admin roles with least privilege
Create user accounts with a consistent naming standard, assign licenses, and use groups for access wherever possible. Avoid giving daily-use accounts Global Administrator permissions. Instead, use the least-privileged Microsoft Entra ID role required for each task, such as Exchange Administrator, Teams Administrator, SharePoint Administrator, Helpdesk Administrator, or Billing Administrator. Keep at least two emergency access accounts, protect them with strong credentials, exclude them from risky Conditional Access dependencies, and monitor their use. If your licensing includes Microsoft Entra ID P2, consider Privileged Identity Management for just-in-time admin access.
Secure identity first: MFA, Conditional Access, and sign-in hygiene
Identity is the control plane for Microsoft 365. Enable multifactor authentication for all users. Smaller tenants may start with security defaults, while organizations with Microsoft 365 Business Premium, Microsoft 365 E3/E5, or Entra ID P1/P2 can use Conditional Access for more precise rules such as requiring MFA for admins, blocking legacy authentication, restricting risky locations, and requiring compliant devices for sensitive apps. Configure self-service password reset where appropriate, review external user settings, and make sure audit logging and alerting are enabled in Microsoft Purview and Microsoft Defender portals.
Prepare email before moving production mail
For Exchange Online, confirm mailbox licensing, aliases, shared mailboxes, distribution groups, Microsoft 365 Groups, and mail flow requirements before changing MX records. Configure SPF, DKIM, and DMARC for your domain to reduce spoofing and improve deliverability. Shared mailboxes generally do not need a license if they stay within Microsoft’s limits and do not require features such as an archive or litigation hold, but verify your scenario before relying on that. If you are migrating from another mail platform, plan batches, cutover timing, Outlook profile changes, mobile device reconfiguration, and a rollback or support plan for the first business day after cutover.
Set up Teams, SharePoint, and OneDrive with governance
Microsoft 365 collaboration works best when Teams, SharePoint, and OneDrive are planned together. Decide who can create teams and Microsoft 365 Groups, how naming and expiration should work, which sites are company-wide versus department-specific, and what external sharing rules are acceptable. Configure guest access and external sharing intentionally rather than leaving defaults unreviewed. For users, make OneDrive the default place for personal work files and SharePoint or Teams the default for team-owned content. For Windows devices, consider Known Folder Move so Desktop, Documents, and Pictures are protected in OneDrive.
Enroll and protect devices with Microsoft Intune where licensed
If your plan includes Microsoft Intune, such as Microsoft 365 Business Premium or applicable enterprise suites, use it to manage Windows, macOS, iOS, and Android devices. Start with enrollment, compliance policies, baseline security settings, BitLocker or FileVault, Microsoft Defender configuration, app deployment, and update rings. For new Windows devices, Windows Autopilot can simplify provisioning. Device compliance can also feed Conditional Access so sensitive data is available only from trusted devices.
Turn on Microsoft 365 threat protection appropriate to your plan
Review what security features are included in your subscription. Microsoft 365 Business Premium includes Microsoft Defender for Business and additional identity and device controls. Defender for Office 365 adds advanced email and collaboration protection such as Safe Links, Safe Attachments, anti-phishing policies, attack simulation training, and improved investigation tools depending on the plan. At minimum, review anti-spam, anti-malware, anti-phishing, impersonation, and quarantine policies. Security should be configured before users begin relying on the tenant for daily work.
Plan retention, eDiscovery, and backup separately
Microsoft 365 includes recycle bins, version history, retention labels and policies, litigation hold, eDiscovery, and audit capabilities depending on licensing. These features are not the same as a complete third-party backup strategy. Retention policies are designed for governance and compliance, not always fast point-in-time recovery after accidental deletion, ransomware, sync problems, or malicious activity. Decide what data must be retained, for how long, who can search or export it, and whether your risk profile requires dedicated Microsoft 365 backup for Exchange, SharePoint, OneDrive, and Teams data.
Help users adopt the tools
A successful rollout is not just technical. Provide short training for Outlook, Teams meetings and chat, OneDrive file sharing, SharePoint document collaboration, and Microsoft 365 Apps. Explain where files should be stored, how to share safely, how to report phishing, and how to get support. Use Microsoft’s current end-user training resources and supplement them with company-specific guidance so users understand your rules, not only the product features.
First 30 days checklist
Week 1: confirm tenant ownership, partner access, licensing, domains, admin roles, MFA, and emergency accounts. Week 2: configure DNS, email security, users, groups, shared mailboxes, and migration readiness. Week 3: set up Teams, SharePoint, OneDrive, external sharing, and device management policies. Week 4: finalize backup and retention decisions, train users, review secure score and alerts, document support procedures, and schedule a post-launch optimization review.
Key takeaways
- A Microsoft 365 subscription needs a structured setup plan; purchasing licenses is not the same as being production-ready.
- Use current terminology and controls: Microsoft 365, Microsoft Entra ID, GDAP, Conditional Access, Microsoft Defender, Microsoft Purview, and Microsoft Intune.
- Review NCE subscription terms before changing license counts, because monthly and annual commitments have different flexibility and renewal implications.
- Secure identity first with MFA, least-privilege admin roles, emergency access accounts, and Conditional Access where licensed.
- Email readiness should include migration planning plus SPF, DKIM, DMARC, shared mailbox rules, and phishing protection.
- Retention, eDiscovery, and backup solve different problems; decide what recovery and compliance outcomes your business actually needs.
Need help turning a new Microsoft 365 tenant into a secure, production-ready environment? IT Partner can assist with Microsoft 365 licensing, tenant setup, migration, security hardening, Intune management, and backup planning.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.