Microsoft 365 Administrator On Demand — Tenant Administration Support
Microsoft 365 Administrator On Demand provides recurring on-demand administration support for organizations that need help with irregular Microsoft 365 tenant administration tasks, such as creating new users or managing existing Exchange Online transport rules. Support is available by phone, through a Microsoft Teams session, or remotely.
What this engagement is
IT Partner provides on-demand support for Microsoft 365 tenant issues and irregular administration chores. The service is delivered by engineers with competencies and skills intended to help solve Microsoft 365 tenant problems quickly and professionally.
Success criteria
What you receive
How the work unfolds
Service onboarding and request intake: confirm the customer tenant, billing arrangement, authorized contacts, support channels, and the types of Microsoft 365 administration tasks expected under the recurring service.
Access and permissions validation: establish or confirm appropriate delegated Microsoft 365 administrative access, security requirements, and any required access to DNS, identity, or hybrid infrastructure before work begins.
Request submission and triage: receive administration requests by the agreed support channel, clarify business need, affected users or services, urgency, and whether the request is within the Microsoft 365 tenant administration scope.
Change review and approval: identify the administrative action required, confirm risks or user impact where relevant, and obtain customer approval for changes that could affect sign-in, mail flow, licensing, DNS, or security posture.
Remote administration execution: perform the approved Microsoft 365 tenant administration task, such as user or group changes, license reassignment where included in full-service billing support, MFA updates, DNS-related changes, password resets, transport rule updates, AD Connect review, or system alert/report work.
Validation and customer confirmation: verify the requested change was completed, perform reasonable administrative checks, and ask the customer or affected user to confirm the expected outcome where end-user validation is required.
Documentation and closure: record the completed action, note any follow-up items, identify requests that require a separate project or additional-cost service, and close the request through the agreed support process.
Prerequisites
Who does what
IT Partner
- DNS configuration
- Microsoft 365 User/Group Administration
- Employee onboarding or termination
- User creation or deactivation
- Password changes/resets
- Configure Microsoft 365/Entra ID groups
- Modify password expiration policies
- Report license use and reassign licenses as needed (included in full-service billing support)
- Multi-factor authentication
- Microsoft Entra Connect (formerly Azure AD Connect)
- Single Sign On/Federation with ADFS
- System Alerts and Reports
Your team
- Designate authorized contacts for Microsoft 365 administration requests and approvals.
- Provide timely, accurate request information, including affected users, groups, domains, required timing, and business context.
- Provide or approve the administrative access required for IT Partner to perform the requested Microsoft 365 tenant tasks.
- Maintain appropriate Microsoft 365 licensing and subscriptions for the services and features being administered.
- Provide access to DNS hosting, domain registrar, on-premises AD Connect servers, ADFS servers, or other related systems when those systems are involved in the request.
- Approve changes that may affect users, mail flow, sign-in, licensing, security policies, or domain configuration before implementation.
- Communicate planned changes to internal users when customer communication is required.
- Validate completed requests from the business or end-user perspective when IT Partner cannot directly confirm the user outcome.
What's not included
Limitations & technical notes
Frequently asked questions
What is Microsoft 365 Administrator On Demand?
Microsoft 365 Administrator On Demand is a recurring support service for organizations that need help with irregular Microsoft 365 tenant administration tasks. IT Partner engineers provide on-demand assistance for Microsoft 365 tenant issues and administration chores by phone, through a Microsoft Teams session, or remotely.
What Microsoft 365 administration tasks are included?
The service includes Microsoft 365 tenant administration tasks such as DNS configuration, Microsoft 365 user and group administration, employee onboarding or termination, user creation or deactivation, password changes or resets, Microsoft 365 and Entra ID group configuration, password expiration policy changes, license use reporting and reassignment where included in full-service billing support, multi-factor authentication, Microsoft Entra Connect (formerly Azure AD Connect), ADFS federation or single sign-on, and system alerts and reports. It is designed as supplementary professional help for Microsoft 365 tenant administration, not as a general IT support package.
Is this service for one-time projects or ongoing support?
Microsoft 365 Administrator On Demand is a recurring service. It is intended for organizations that need ongoing access to professional help for irregular Microsoft 365 tenant administration needs rather than a single fixed-scope project.
How is support delivered?
Support is available by phone, through a Microsoft Teams session, or remotely. The appropriate method depends on the request and what access or interaction is required to resolve the Microsoft 365 tenant administration issue.
How much does Microsoft 365 Administrator On Demand cost?
Microsoft 365 Administrator On Demand is $15 per seat per month, billed as a recurring 30-day service. Confirm eligible user counts and any full-service billing support arrangements with IT Partner before purchasing.
Does the service include Microsoft 365 user onboarding and offboarding?
Yes. Employee onboarding or termination, user creation or deactivation, password resets, and group administration are included within the stated Microsoft 365 administration scope. License use reporting and license reassignment are listed as included when they are part of full-service billing support.
Can IT Partner manage Exchange Online transport rules under this service?
Yes, the service description specifically identifies managing existing Exchange Online transport rules as an example of an irregular Microsoft 365 tenant administration task. Requests should still be confirmed with IT Partner if they involve broader mail flow design, security policy changes, or work outside routine tenant administration.
Does the service include DNS configuration for Microsoft 365?
Yes. DNS configuration is listed as an included deliverable and IT Partner responsibility, which can be relevant for Microsoft 365 services such as Exchange Online, Teams, and domain verification.
Does the service include multi-factor authentication configuration?
Yes. Multi-factor authentication is included in the stated service deliverables. The exact configuration approach should be confirmed with IT Partner based on the organization’s Microsoft 365 tenant, licensing, and security requirements.
Does the service include AD Connect or federation support?
Yes. Microsoft Entra Connect (formerly Azure AD Connect, AD Sync, or DirSync) and single sign-on or federation with ADFS are included areas of support. Because identity synchronization and federation can affect user sign-in, the exact task, impact, and required access are reviewed with IT Partner before changes are made.
What is not included in Microsoft 365 Administrator On Demand?
The service does not include training of the customer team, desktop software settings, or issues that are not directly related to Microsoft 365. It is focused on Microsoft 365 tenant administration and related support tasks.
What does the customer need to provide before IT Partner can perform administration tasks?
The customer designates authorized contacts, provides accurate request details — affected users, groups, domains, licenses, and timing — grants the agreed administrative access, and approves changes that may affect authentication, mail flow, licensing, or security before implementation. Access to DNS hosting or on-premises identity infrastructure is needed when those systems are involved.