Microsoft 365 Admin – Day-1 Real-World Setup (Beginner Friendly)

By | December 18, 2025

🎯 Goal of Day-1

Set up a new Microsoft 365 tenant securely and professionally, just like a real IT/M365 administrator would do on Day-1 in an organization.


🧱 DAY-1 TASK BREAKDOWN (Industry-Style)


1️⃣ Access Microsoft 365 Admin Center

Steps

  1. Open: https://admin.microsoft.com
  2. Sign in using Global Admin credentials
  3. Verify you can access:
    • Users
    • Teams & groups
    • Security
    • Billing
    • Settings

Real-World Tip

First login should always be done using Global Admin, but daily work should use a non-admin account.


2️⃣ Verify & Add Custom Domain

Why?

  • Professional email addresses (@company.com)
  • Required for production use

Steps

  1. Admin Center → Settings → Domains
  2. Click Add domain
  3. Enter domain name
  4. Copy TXT record
  5. Add TXT record in domain provider (GoDaddy / Namecheap / Hostinger)
  6. Click Verify
  7. Set domain as Default

DNS Records to Add

TypePurpose
TXTDomain verification
MXEmail delivery
CNAMEAutodiscover
SPFAnti-spoofing

3️⃣ Create Core Admin Accounts (Must-Have)

Accounts to Create

AccountRole
globaladmin@domain.comGlobal Admin
m365admin@domain.comAdmin tasks
breakglass@domain.comEmergency access

Steps

  1. Users → Active users → Add user
  2. Assign licenses later
  3. Assign admin roles

Best Practice

🚨 Break Glass Account

  • No MFA initially
  • Very strong password
  • Used only during tenant lockout

4️⃣ Enable Security Defaults / MFA

Steps

  1. Admin Center → Identity → Azure AD
  2. Properties → Manage Security Defaults
  3. Enable Security Defaults

What This Enables

✔ MFA for admins
✔ MFA for users
✔ Legacy auth blocked


5️⃣ License Assignment (Basic Setup)

Common Licenses

  • Microsoft 365 Business Basic
  • Business Standard
  • Business Premium

Steps

  1. Billing → Licenses
  2. Assign license to admin & test user
  3. Verify services:
    • Exchange
    • OneDrive
    • Teams
    • SharePoint

6️⃣ Create Initial Test Users

Example Users

NamePurpose
user1@domain.comRegular employee
hr@domain.comHR mailbox
it.support@domain.comSupport mailbox

Steps

  1. Users → Add user
  2. Assign license
  3. Login once to initialize mailbox

7️⃣ Exchange Online – Day-1 Checks

Tasks

  • Verify mailbox creation
  • Check Outlook Web Access
  • Confirm MX records working

Optional (But Good)

  • Create shared mailbox
  • Assign permissions

8️⃣ Teams & SharePoint Validation

Teams

  • Login as user
  • Open Teams Web/App
  • Confirm chat & meeting access

SharePoint

  • Open SharePoint Admin Center
  • Check default site
  • Verify OneDrive access

9️⃣ Baseline Security Checks

Must-Do

  • Confirm MFA working
  • Disable legacy protocols
  • Check sign-in logs

Tools

  • Entra ID → Sign-in logs
  • Microsoft Defender portal

🔟 Documentation (Very Important)

What to Document

  • Tenant name
  • Admin accounts
  • Domain DNS records
  • License type
  • MFA status

📌 This is what real admins must do but beginners often skip.


📌 Day-1 Outcome (What You Achieved)

✔ Tenant ready
✔ Custom domain active
✔ Secure admin access
✔ Users created
✔ Email + Teams working
✔ Security baseline applied


Next Steps (Day-2 Ideas)

  • Conditional Access
  • Mail flow rules
  • Anti-phishing
  • Intune basics
  • Backup strategy

Leave a Reply

Your email address will not be published. Required fields are marked *