← System Owner · Practitioner

Knowledge material · ~6 min read

System Owner · Practitioner

You run tenants and configure policy, not just users.

Overview

Now you own systems end-to-end. You decide what an M365 (Microsoft 365) tenant should look like, push device policies through Intune or the RMM (Remote Monitoring and Management), and design a backup strategy that survives a ransomware Sunday. Every change you make should be reversible, documented, and visible in a report.

M365 administration with intent

  • ▸Conditional Access — block legacy auth, require MFA (Multi-Factor Authentication), scope by location/device.
  • ▸License math — E3 vs Business Premium vs F3; right-size per user role.
  • ▸Exchange Online — connectors, transport rules, anti-phish policy.
  • ▸Purview — DLP (Data Loss Prevention), retention, eDiscovery. Set retention before you need it.

Intune / RMM device policy

  • ▸Configuration profiles for BitLocker, Defender, firewall, Wi-Fi.
  • ▸Compliance policies feed Conditional Access — non-compliant = blocked.
  • ▸App deployment via Win32 packages or store; assign to groups, not users.
  • ▸Pilot ring → broad ring → all. Always.

3-2-1 backup, modernized

3 copies of data, 2 different media, 1 off-site. Today's version: production + on-prem appliance + immutable cloud copy. Test restores monthly; an untested backup is a hope.

Reporting the work

  • ▸Monthly QBR (Quarterly Business Review) data: tickets closed, SLA (Service Level Agreement) hit %, patch compliance, backup success.
  • ▸Trend > snapshot. One bad month means nothing; six months means a story.
  • ▸Translate metrics to outcomes: 'avoided 4 hours of downtime' beats 'patched 312 endpoints'.

Glossary

Conditional Access
If-this-then-require policy gating sign-ins.
Compliance policy
Rules a device must meet (encryption, AV (Antivirus), OS (Operating System) version).
Immutable backup
Write-once copy that ransomware can't encrypt.
QBR
Quarterly Business Review — client-facing meeting.

Common pitfalls

Practice drills