<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Marcus Reid</title>
    <description>The latest articles on DEV Community by Marcus Reid (@marcus_reid_de93ee92687f4).</description>
    <link>https://dev.to/marcus_reid_de93ee92687f4</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4175958%2F2a706c8e-6434-4864-a7fd-73b3f38bc59d.png</url>
      <title>DEV Community: Marcus Reid</title>
      <link>https://dev.to/marcus_reid_de93ee92687f4</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/marcus_reid_de93ee92687f4"/>
    <language>en</language>
    <item>
      <title>5 M365 Admin Tasks You're Probably Doing Without Documentation</title>
      <dc:creator>Marcus Reid</dc:creator>
      <pubDate>Sat, 10 Oct 2026 20:52:29 +0000</pubDate>
      <link>https://dev.to/marcus_reid_de93ee92687f4/5-m365-admin-tasks-youre-probably-doing-without-documentation-4jeo</link>
      <guid>https://dev.to/marcus_reid_de93ee92687f4/5-m365-admin-tasks-youre-probably-doing-without-documentation-4jeo</guid>
      <description>&lt;p&gt;I inherited an M365 tenant with zero documentation. Here are the five procedures — offboarding order, license audits, contractor guest accounts, Temporary Access Pass, and phishing triage — that made the biggest difference once I wrote them down.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5 M365 Admin Tasks You're Probably Doing Without Documentation&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I started my current gig and inherited an M365 tenant with exactly zero documentation. Not "outdated docs." Zero. Every password reset, every onboarding, every offboarding was just in people's heads.&lt;/p&gt;

&lt;p&gt;The breaking point was my coworker going on vacation for a week. Two new hires started that Monday. I had a sticky note that said "licenses in the spreadsheet" and there was no spreadsheet.&lt;/p&gt;

&lt;p&gt;So I started writing everything down. Not fancy. Just "when X happens, do Y" in the order you actually do it. Here's the stuff that bit us hardest before it was written down.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Offboarding&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Everyone thinks it's "disable the account." It's not. The order matters and I learned this the embarrassing way: we offboarded someone, blocked their sign-in, and their phone stayed logged into Teams for over an hour because nobody revoked the active sessions first. Now the doc says: revoke sessions, reset password, block sign-in, THEN strip groups, pull them from the address list, convert the mailbox to shared, drop the license, give the manager access. In that order. Every time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Licenses&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We had people on Business Standard who only ever opened Outlook on the web. That's double the cost of Basic for nothing. I went through the whole tenant one afternoon and the savings were stupid. My rule now: email only gets Basic. If you need the desktop apps you get Standard. That's it. Visio and Project people get add-ons. Nobody gets Standard "just in case" anymore.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Contractors&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We used to spin up full accounts for three-week contractors. Guest accounts exist. They're free. Use them. Full account only if they actually need licensed apps, and put an expiration date on it so you're not paying for someone who left in March.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The &lt;em&gt;Temporary Access Pass&lt;/em&gt; thing&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I didn't know about this for way too long. You can issue a TAP before someone's start date so their laptop and account are ready when they walk in day one. Microsoft even has a built-in onboarding workflow for it. Before I found this, every first morning was chaos.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Phishing reports&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The only two questions that matter when someone reports one: did you click anything, and did you type your password anywhere. That's the difference between "delete the email" and "lock the account, reset the password, kill the sessions, make them re-register MFA, block the sender." Ask those two things first and you'll know which one you're dealing with in ten seconds.&lt;/p&gt;




&lt;p&gt;That's five of the ten I wrote up. The full set (password resets, MFA headaches, shared mailboxes, distribution lists, OneDrive recovery, Teams issues, license audits) is packaged as a template pack if you want the finished versions:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://marcreid74.gumroad.com/l/It-sop-template-pack" rel="noopener noreferrer"&gt;IT SOP Template Pack — $19&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;But honestly the five above are the ones that would've saved me the most grief. Start there.&lt;/p&gt;

</description>
      <category>tutorial</category>
      <category>beginners</category>
      <category>microsoft</category>
      <category>sysadmin</category>
    </item>
  </channel>
</rss>
