M365 Administration
Runbook Series
A complete Microsoft 365 tenant built from scratch for a fictional company "Magister Operis Systems" demonstrating real-world admin workflows from user creation to security policy enforcement.
The Lab Setup
To practise M365 administration hands-on, I designed a realistic fictional scenario: Magister Operis Systems (MOS), a Berlin company with 23 simulated users across 7 departments. I built their full M365 tenant from scratch, treating it exactly as I would a real client environment.
What a Runbook Is
Each runbook is a step-by-step admin guide with real screenshots from the M365 Admin Center, Entra ID, and Teams, documenting exactly what I did, what errors appeared, and how I resolved them.
Why I Built This
To demonstrate M365 administration in a structured, professional way, not just knowing the theory, but executing and documenting it as an IT Systems Administrator would on the job.
All 6 Runbooks
Download & Explore
Each runbook covers a distinct admin workflow. Click a card to download the PowerPoint file.
- Create a single user (Chris Vogel) via Admin Center
- Build and validate a bulk import CSV file
- Diagnose and fix real CSV import errors
- Understand Error 530035, auth vs. licencing
- Enable Security Defaults in Entra ID Properties
- Use the legacy Per-User MFA interface
- Enable MFA for Anfreas Schutz and Claudia Hartmann
- Understand MFA status: Not enabled / Enabled / Enforced
- Create MOS IT Support Team via Teams Admin Center
- Add members and channels (Incidents, Announcements)
- Understand that Teams auto-creates the SharePoint site
- Set Site Owner and Member permission levels
- Policy 1 : Block sign-ins from outside Germany
- Policy 2 : Require MFA for all admin accounts
- Policy 3 : Block legacy authentication protocols
- Documented from Microsoft Learn, not executed in tenant
- Block sign-in and revoke active sessions immediately
- Reset password and remove all group memberships
- Convert mailbox to shared (preserves email, frees licence)
- Remove licence, freed for the next new hire
- Enable SSPR for all 23 MOS users in Entra ID
- Require 2 authentication methods (email + phone)
- Configure registration and notification settings
- Verify SSPR portal at aka.ms/sspr
Skills & Competencies
Want to See More?
Explore more hands-on infrastructure and networking projects, or reach out directly if you have questions about this M365 portfolio work.
