Name | Technical E-mail | Telephone Number |
---|---|---|
Acestara | [email protected] | 01218090309 |
Unified Audit Log | Security defaults | Days until password expiry |
---|---|---|
Enabled | Unknown | 730 |
Active Sync | POP | IMAP | MAPI | SMTP | OAuth2 |
---|---|---|---|---|---|
Enabled | Enabled | Enabled | Enabled | Enabled | Enabled |
Name | ID | Users included | Users excluded | Groups included | Groups excluded | Roles included | Roles excluded | State |
---|---|---|---|---|---|---|---|---|
SecurityPolicy1 | 5a4c8f90-21b4-46d9-9f4f-15bb6e7decab | [email protected], [email protected] | a82038a9-ee9f-43d0-b82c-eed88b7d940c>Marketing | Billing Administrator | enabled |
Admin Role | Name | MFA Status | Is Licensed | Is Blocked | E-mail Address |
---|---|---|---|---|---|
Global Administrator | Bert Dirtha | Enforced | yes | no | [email protected] |
Global Administrator | Jennifer Aurelli | Disabled | no | no | [email protected] |
Global Administrator | Quinn Evans | Disabled | yes | no | [email protected] |
Global Administrator | Andrew test | Enabled (CA) | no | no | [email protected] |
Global Administrator | tempaccount | Disabled | no | no | [email protected] |
Global Administrator | Andrew Demo Admin account | Enforced | no | no | [email protected] |
Domain Name | Verification Status | Default | DKIM enabled |
---|---|---|---|
acestara.onmicrosoft.com | Verified | No | Enabled |
acestara.com | Verified | Yes | Disabled |
Information |
---|
Information: No azure AD registered applications were found. |
Name | AppID | Created on |
---|---|---|
Microsoft Graph PowerShell | 14d82eec-204b-4c2f-b7e8-296a70dab67e | 2022/10/20 10:58 |
Nine for Office 365 | 516e4bcb-86da-4cfe-92cb-435c1e8dbf71 | 2022/09/11 09:42 |
Information |
---|
Information: No Users were found with Strong Password Enforcement disabled |
Name | Primary Email Address | Is Licensed | MFA Status | Password Expiry Policy |
---|---|---|---|---|
Bert Dirtha | [email protected] | True | Enforced | Never Expires |
Ben Dover | [email protected] | True | Enforced | Never Expires |
Admin Role | Name | MFA Status | Is Licensed | Is Blocked | E-mail Address |
---|---|---|---|---|---|
Billing Administrator | Andrew test | Enabled (CA) | no | no | [email protected] |
Billing Administrator | Equipment | Enforced | no | no | [email protected] |
Exchange Administrator | Mark Potts | Disabled | no | no | [email protected] |
Exchange Administrator | Ralph Higgins | Enabled | no | no | [email protected] |
Global Administrator | Bert Dirtha | Enforced | yes | no | [email protected] |
Global Administrator | Jennifer Aurelli | Disabled | no | no | [email protected] |
Global Administrator | Quinn Evans | Disabled | yes | no | [email protected] |
Global Administrator | Andrew test | Enabled (CA) | no | no | [email protected] |
Global Administrator | tempaccount | Disabled | no | no | [email protected] |
Global Administrator | Andrew Demo Admin account | Enforced | no | no | [email protected] |
Groups Administrator | Mark Potts | Disabled | no | no | [email protected] |
Helpdesk Administrator | Ralph Higgins | Enabled | no | no | [email protected] |
Helpdesk Administrator | Ben Dover | Enforced | yes | yes | [email protected] |
Intune Administrator | Ben Dover | Enforced | yes | yes | [email protected] |
Teams Administrator | Perry Scope | Enabled | no | no | [email protected] |
Name | Primary E-mail address | Licenses | Email Type | Last Logon date | Days since last logon | Reset Password at Next Logon | Is Blocked | MFA Status | MFA Capable | MFA Registered | Default MFA Method | MFA Methods Registered | Self Service Password reset capable | Self Service Password reset registered | Self Service Password reset enabled | Passwordless Capable | ActiveSync | POP | IMAP | MAPI | SMTP | OWA | E-mail Aliases |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Bert Dirtha | [email protected] | AZURE ACTIVE DIRECTORY PREMIUM P1, MICROSOFT 365 BUSINESS BASIC | UserMailbox | 2023-03-24 10:27:38 | 6 | False | No | Enforced | True | True | mobilePhone | mobilePhone, microsoftAuthenticatorPush, softwareOneTimePasscode | False | False | False | False | Enabled | Enabled | Disabled | Enabled | Enabled | Enabled | [email protected], [email protected] |
Alfie McDee | [email protected] | Not Active | Not available | Not available | False | No | Enforced | True | True | none | microsoftAuthenticatorPush | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | ||
Andrew test | [email protected] | Not Active | 2023-03-27 14:50:25 | 2 | False | No | Enabled (CA) | True | True | mobilePhone | mobilePhone | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | ||
Anne Teak | [email protected] | Not Active | Not available | Not available | False | No | Enabled (CA) | True | True | none | microsoftAuthenticatorPush | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | ||
Art Deco | [email protected] | EXCHANGE ONLINE KIOSK | UserMailbox | Not available | Not available | False | No | Enforced | True | True | none | microsoftAuthenticatorPush | False | False | False | False | Enabled | Disabled | Disabled | Disabled | Disabled | Enabled | [email protected] |
Ben Dover | [email protected] | MICROSOFT POWER AUTOMATE FREE, EXCHANGE ONLINE KIOSK | UserMailbox | Not available | Not available | False | Yes | Enforced | Not available | Not available | Not available | Not available | Not available | Not available | Not available | Not available | Enabled | Disabled | Disabled | Disabled | Disabled | Enabled | [email protected] |
chee | [email protected] | UserMailbox | Not available | Not available | False | No | Enforced | True | True | none | microsoftAuthenticatorPush | False | False | False | False | Enabled | Enabled | Disabled | Enabled | Enabled | Enabled | [email protected], [email protected] | |
Chris Anthemum | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Andrew Demo Admin account | [email protected] | Not Active | 2022-06-16 12:44:19 | 287 | False | No | Enforced | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Equipment | [email protected] | EquipmentMailbox | Not available | Not available | False | No | Enforced | True | True | none | microsoftAuthenticatorPush | False | False | False | False | Enabled | Disabled | Disabled | Enabled | Disabled | Enabled | [email protected] | |
Ginger Plant | [email protected] | Not Active | Not available | Not available | False | No | Enforced | True | True | none | microsoftAuthenticatorPush | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | ||
Holly Bush | [email protected] | Not Active | Not available | Not available | False | No | Disabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | [email protected] | ||
Hugo First | [email protected] | EXCHANGE ONLINE KIOSK | UserMailbox | Not available | Not available | False | No | Enforced | False | False | none | False | False | False | False | Enabled | Disabled | Disabled | Disabled | Disabled | Enabled | [email protected] | |
Jennifer Aurelli | [email protected] | SharedMailbox | 2020-05-26 13:57:30 | 1037 | False | No | Disabled | False | False | none | False | False | False | False | Enabled | Enabled | Enabled | Enabled | Enabled | Enabled | [email protected], [email protected], [email protected], [email protected] | ||
Kevin Dowling | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | [email protected] | ||
Liz Erd | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Mal Ajusted | [email protected] | Not Active | Not available | Not available | False | No | Disabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Mark Potts | [email protected] | Not Active | Not available | Not available | False | No | Disabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | [email protected] | ||
Mark Ateer | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Meeting Room | [email protected] | RoomMailbox | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Enabled | Disabled | Disabled | Disabled | Disabled | Enabled | [email protected] | ||
Michael Hello | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Neil Down | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Olive Yew | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Paulo | Paulo_gpostpc321.com#EXT#@acestara.onmicrosoft.com | GuestMailUser | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | [email protected] | ||
Perry Scope | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Peter Owt | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
Quinn Evans | [email protected] | MICROSOFT POWER AUTOMATE FREE, MICROSOFT 365 BUSINESS BASIC | UserMailbox | 2022-05-24 07:27:53 | 310 | False | No | Disabled | False | False | none | False | False | False | False | Enabled | Enabled | Disabled | Enabled | Enabled | Enabled | [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected] | |
Ralph Higgins | [email protected] | SharedMailbox | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Enabled | Enabled | Disabled | Enabled | Enabled | Enabled | [email protected] | ||
Ray Sincar | [email protected] | Not Active | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
hotel | [email protected] | SharedMailbox | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Enabled | Disabled | Disabled | Disabled | Disabled | Enabled | [email protected], [email protected], [email protected] | ||
Rhea Lax | [email protected] | Not Active | Not available | Not available | False | No | Disabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | [email protected] | ||
Simon Sais | [email protected] | Not Active | Not available | Not available | False | Yes | Enabled | Not available | Not available | Not available | Not available | Not available | Not available | Not available | Not available | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | ||
Support | [email protected] | SharedMailbox | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Enabled | Disabled | Disabled | Enabled | Enabled | Enabled | [email protected] | ||
sydney | sydney_Asw342A.com#EXT#@acestara.onmicrosoft.com | GuestMailUser | Not available | Not available | False | No | Enabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | [email protected] | ||
tempaccount | [email protected] | Not Active | 2022-04-05 15:40:36 | 358 | False | No | Disabled | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled | |||
toot toot | [email protected] | MailUniversalDistributionGroup | Not available | Not available | False | No | Enforced | False | False | none | False | False | False | False | Disabled | Disabled | Disabled | Disabled | Disabled | Disabled |
Name | Total Amount | Assigned Licenses | Unassigned Licenses |
---|---|---|---|
EXCHANGE ONLINE KIOSK | 5 | 3 | 2 |
EXCHANGE ONLINE (PLAN 1) | 1 | 0 | 1 |
AZURE ACTIVE DIRECTORY PREMIUM P1 | 1 | 1 | 0 |
MICROSOFT 365 BUSINESS BASIC | 2 | 2 | 0 |
Name | Users allocated this license |
---|---|
Exchange Online Kiosk | [email protected], [email protected], [email protected] |
Azure Active Directory Premium P1 | [email protected] |
Microsoft 365 Business Basic | [email protected], [email protected] |
Name | Primary E-Mail | Mailbox Type | Users who can access this mailbox |
---|---|---|---|
Bert Dirtha | [email protected] | UserMailbox | |
Art Deco | [email protected] | UserMailbox | |
Ben Dover | [email protected] | UserMailbox | |
chee | [email protected] | UserMailbox | [email protected],[email protected],[email protected] |
Equipment | [email protected] | EquipmentMailbox | |
Hugo First | [email protected] | UserMailbox | |
Jennifer Aurelli | [email protected] | SharedMailbox | [email protected],[email protected],[email protected],[email protected],[email protected],[email protected] |
Quinn Evans | [email protected] | UserMailbox | [email protected],[email protected] |
Ralph Higgins | [email protected] | SharedMailbox | [email protected],[email protected],[email protected] |
hotel | [email protected] | SharedMailbox | |
Support | [email protected] | SharedMailbox | [email protected],[email protected] |
Primary Email Address | Display Name | Name | Device Model | Device Type | Device OS | Development Name | Device Id | Client Type | Client Version | Mobile Operator | First Sync | Last Sync | Last Sync Attempt |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
[email protected] | Bert Dirtha | admin | Pixel 6 Pro | Android | Android 13.8927612 | raven | 4E696E65394439424130423243353937 | EAS | 16.1 | O2 - UK | 2022/09/11 08:42 | 2022/09/11 08:42 | 2022/09/11 08:42 |
[email protected] | Bert Dirtha | admin | Default string | UniversalOutlook | WINDOWS | GLENN-PC | 68D2A8DA190E4BF189497A4C4548A4F8 | Outlook | 1.0 | 2022/09/11 08:36 | 2022/09/11 08:36 | Not available |
Name | E-mail Address |
---|---|
Sydney | [email protected] |
Name | Primary E-Mail | E-mail Aliases |
---|---|---|
Paulo | [email protected] | |
sydney_Asw342A.com#EXT# | [email protected] |
Name | Primary E-Mail | E-mail Aliases |
---|---|---|
Meeting Room | [email protected] |
Name | Primary E-Mail | E-mail Aliases |
---|---|---|
Equipment | [email protected] |
Name | Type | Members | External Members | E-mail Address | ID |
---|---|---|---|---|---|
Acestara | Microsoft 365 Group | [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected] | [email protected], [email protected] | [email protected] | c3c914eb-08ea-4b38-95da-40e0e9c9f265 |
Sales | Distribution List | [email protected], [email protected], [email protected], [email protected], [email protected], [email protected] | [email protected], [email protected] | [email protected] | e7bd86de-a161-4bf8-ba2f-62ed33497b13 |
Primary Email Address | Display Name | Has email forwarded to this address |
---|---|---|
[email protected] | Equipment | [email protected] |
[email protected] | Quinn Evans | [email protected] |
[email protected] | Ralph Higgins | [email protected] |
[email protected] | Support | [email protected] |
Information |
---|
Information: No Users with external forwarding rules were found. |
Transport Rule Name | Description |
---|---|
Block IP and delete - TENANT | If the message: sender ip addresses belong to one of these ranges: '1.1.2.3' Take the following actions: Delete the message without notifying the recipient or sender |
whitelist MSP Easy Tools | If the message: sender's address domain portion belongs to any of these domains: 'mspeasytools.co.uk' or 'office365security.info' or 'mspet.co.uk' or 'micromonty.com' or 'mspeasytools.sk' or 'promptmapper.com' Take the following actions: Set the spam confidence level (SCL) to '-1' |
Whitelist gdsq.uk | If the message: sender's address domain portion belongs to any of these domains: 'gdsq.uk' Take the following actions: Set the spam confidence level (SCL) to '-1' |
AlertsNotJunk | If the message: Is received from '[email protected]' Take the following actions: Set the spam confidence level (SCL) to '-1' |
Whitelist ff.oi | If the message: sender's address domain portion belongs to any of these domains: 'ff.oi' Take the following actions: Set the spam confidence level (SCL) to '-1' |
Whitelist gdsq.co.uk | If the message: sender's address domain portion belongs to any of these domains: 'gdsq.co.uk' Take the following actions: Set the spam confidence level (SCL) to '-1' |
whitelist MSPETUK | If the message: sender's address domain portion belongs to any of these domains: 'mspet.uk' or 'mspetduk.onmicrosoft.com' or 'msptools.co.uk' Take the following actions: Set the spam confidence level (SCL) to '-1' |
MSPET-RD-MSP EasyTools info | If the message: Is received from '[email protected]' and Includes these patterns in the message subject: 'Further information' Take the following actions: Redirect the message to '[email protected]' |
Forward to Home | If the message: Is sent to '[email protected]' and Includes these words in the message subject: 'Sydney' Take the following actions: Redirect the message to '[email protected]' |
Internal plus2 | If the message: Is sent to '[email protected]' Take the following actions: Blind carbon copy(Bcc) the message to '[email protected]' |
Secret messages | If the message: Includes these words in the message subject or body: 'Bank details' Take the following actions: Redirect the message to '[email protected]' |
Sent to 'Ralph Higgins' | If the message: Is sent to '[email protected]' Take the following actions: Prepend the subject with 'Hello Ralph' |
Transport Rule Name | Description |
---|---|
Forward to Home | If the message: Is sent to '[email protected]' and Includes these words in the message subject: 'Sydney' Take the following actions: Redirect the message to '[email protected]' |
Internal plus2 | If the message: Is sent to '[email protected]' Take the following actions: Blind carbon copy(Bcc) the message to '[email protected]' |
Secret messages | If the message: Includes these words in the message subject or body: 'Bank details' Take the following actions: Redirect the message to '[email protected]' |
User Email Address | Inbox Rule Name | Description |
---|---|---|
[email protected] | Emails from Jennifer | If the message: the message was received from 'Jennifer Aurelli' Take the following actions: move the message to folder 'Jennifer' and stop processing more rules on this message |
[email protected] | Emails from Mark | If the message: the message was received from '[email protected]' Take the following actions: delete the message and stop processing more rules on this message |
[email protected] | Emails from Ralph | If the message: the message was received from 'Ralph Higgins' Take the following actions: move the message to folder 'Ralph' and stop processing more rules on this message |
[email protected] | For all messages from Acestara Team | If the message: the message was received from 'Jennifer Aurelli' Take the following actions: move the message to folder 'Jennifer' and stop processing more rules on this message |
[email protected] | to me | If the message: the body of the message contains the words 'pigs' Take the following actions: delete the message and stop processing more rules on this message |
[email protected] | External Send | If the message: the message includes specific words in the subject 'Finance' Take the following actions: forward the message to '[email protected]' and stop processing more rules on this message |
User Email Address | Inbox Rule Name | Description |
---|---|---|
[email protected] | External Send | If the message: the message includes specific words in the subject 'Finance' Take the following actions: forward the message to '[email protected]' and stop processing more rules on this message |
Display Name | Id | Description | State | Created Date | Modified Date | Included Users | Excluded Users | Included Groups | Excluded Groups | Included Roles | Excluded Roles | Included AppIDs | Excluded AppIDs | Include User Actions | Included Authentication Context Class References | Client App type conditions | Client Apps Include Service Principals | Client Apps Exclude Service Principals | Filter for Devices Mode | Filter for Devices Rule | Included Locations | Excluded Locations | Included Platforms | Excluded Platforms | Service Principal Risk Levels | Sign In Risk Levels | User Risk Levels | Grant controls | Operator for multiple controls | Custom Authentication Factors | Grant controls Terms Of Use | Application enforced restrictions enabled | Cloud App Security Type | Cloud App Security enabled | Disable Resilience Defaults | Persistent Browser mode | Persistent Browser mode enabled | Sign in frequency interval | Sign in frequency interval value | Sign in frequency interval unit | Sign in frequency Authentication Type | Sign in frequency interval enabled |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
SecurityPolicy1 | 5a4c8f90-21b4-46d9-9f4f-15bb6e7decab | enabled | 11/11/2021 11:49:13 AM | 4/28/2022 4:03:49 PM | [email protected], [email protected] | Marketing | Billing Administrator | None | all | mfa | OR | |||||||||||||||||||||||||||||||
remembermfa | 928f26f0-7437-4276-888c-8fa34a7ab748 | enabled | 6/17/2022 7:42:23 AM | All | Global Administrator | All | all | False | always | True | timeBased | 1 | hours | primaryAndSecondaryAuthentication | True |
Action Points
The below summarises recommended important points to act upon, taken from the entire security report. Where possible you should aim to make as many of the items below show as a green thumbs up. If due to required legacy compatibilty you are unable to fully address all points then you should tightly control and document anything that can't be changed for compliancy purposes. Action points are colour / icon coded for ease of use. A green thumbs up requires no action on your part. A red thumbs down represents a significant security / misconfiguration issue and should be addressed. An amber pointing finger should still be addresed but may be of less significance in comparison to a thumbs down. A blue 'info' icon is not necesarily a concern but is something that you need to be aware of.
Unified Audit Log
The Unified Audit log is enabled
Password Expiry Policy
Passwords set to expire after 730 days
OAuth2
OAuth2 (Modern Authentication) is enabled in the tenant
Active Sync
Active Sync is enabled for at least one account in the tenant
POP
POP is enabled for at least one account in the tenant
IMAP
IMAP is enabled for at least one account in the tenant
MAPI
MAPI is enabled for at least one account in the tenant
SMTP
SMTP is enabled for at least one account in the tenant
MFA Conditional Access Policy
All configured conditional access policies that enforce MFA are enabled
MFA Conditional Access Policy Exceptions
All configured conditional access policies that enforce MFA do not contain exceptions
Domain Verification
All registered domains are verified in Microsoft 365
DKIM status
At least one of your registered domains does not have DKIM enabled
Azure AD App creation
No Applications are registered in your Azure AD
Strong Password Requirement
No users found with strong password enforcement disabled
MFA and password expiry
No users found with no password expiry and MFA disabled
No password expiry
Users found with Password expiry disabled but MFA enabled
Global Admins
Multiple global admins detected
Admin Multifactor Authentication
At least one admin in the tenant is not using MFA
User Multifactor Authentication
At least one user in the tenant is not using MFA
Blocked users
At least one user is blocked from signing in
License allocation
No license assignments exceed their specified usage limits
License usage
There are unused licenses in the tenant
Delegated mailbox access
There are users with delegated mailboxes in the tenant
Microsoft 365 Mail Users
Microsoft 365 Mail Users exist in the tenant
Groups with external members
Mail enabled groups exist with external members
External Forwarding
No Users with external forwarding rules were found.
External Transport Rules
Externally forwarding transport rules were found
External inbox Rules
Externally forwarding inbox rules were found
Conditional Access Policies
Enabled conditional access policies were found.
Term | Explanation |
---|---|
Active Sync | Active Sync is a legacy protocol that is used to access Exchange servers. It does not fully support MFA so ideally should not be used. However, most mobile devices use Active Sync to access emails, blocking active sync will stop mobile devices retrieving email when using most email apps. |
Admin | A user or entity that has control over your Microsoft 365 tenant |
Azure AD applications | An Azure AD application is a registered applicaition in the Active directory of a Microsoft 365 tenant. Azure applications can be granted permissions to perform a multitude of actions both within the tenant and potentially upon any partner tenants too. |
Billing Administrator | Makes purchases, manages subscriptions, opens and manages support tickets, and monitors service health. |
Conditional Access Policy | A conditional access policy enforces specified conditions on user, group members or roles within the Azure active directory. For example it could be used to enforce MFA on users that are members of a particular group. |
Contact | An external contact that has been added to the Microsoft 365 contacts list. These users do not have access to any of your Microsoft 365 content. |
CRM Service Administrator | Also known as a Dynamics 365 service admin, can sign in to the Dynamics 365 admin center to manage instances. A person with this role cannot do functions restricted to the Microsoft 365 global admin such as manage user accounts, manage subscriptions, access settings for Microsoft 365 apps like Exchange or SharePoint. |
Customer LockBox Access Approver | Can approve Microsoft support requests to access customer organizational data. Manages Customer Lockbox requests in your organisation. They receive email notifications for Customer Lockbox requests and can approve/deny requests from the Microsoft 365 Admin Center. They can also turn on/off the Customer Lockbox feature. |
Default domain | The primary domain registered in your Microsoft 365 tenant |
Distribution List | Sometimes referred to as a Distribution Group. A Microsoft 365 distribution group is a group of users that is mail-enabled (you can send emails to this group email account, and by doing that, all listed users will also be emailed automatically rather than having to email them all individually |
DKIM | DKIM (DomainKeys Identified Mail) is an email security standard designed to make sure messages aren't altered in transit between the sending and recipient servers. It uses public-key cryptography to sign email with a private key as it leaves a sending server. |
Domain | The part of your email address after @. Domains listed are all the ones that are valid in this tenant. |
Email Alias | An alternate email address that can be used to send to a recipient. They will not be able to send out using this address. Only the primary email address can be used to send email. |
Equipment Mailbox | An equipment mailbox is a resource mailbox assigned to a resource that's not location specific, such as a portable computer, projector, microphone, or a company car. After an administrator creates an equipment mailbox, users can easily reserve the piece of equipment by including the corresponding equipment mailbox in a meeting request. |
Exchange Administrator | Manages email, mailboxes and anti-spam policies for your business, using the Exchange admin center. Can view all the activity reports in the Microsoft 365 admin center, manage support tickets, and monitor service health. |
Global Administrator | A user that has total control over all aspects of your Microsoft 365 tenant. There is nothing this user cannot access or do to your tenant. This is the only user that can assign admin roles to other users |
Group | A group in Microsoft 365 can be used to apply privileges/permissions to a group of people, or to email a list of users simultaneously |
Helpdesk Administrator | Sometimes referred to as a password administrator. Resets passwords, manages support tickets, and monitors service health. Helpdesk admins can't reset passwords for global admins. Only other global admins can do that. |
IMAP | IMAP is a legacy protocol that is used to access email accounts. It does not support MFA so should not be used. If IMAP is enabled MFA can be bypassed to access your email. For maximum security it is recommended to block the use of IMAP to access email in Microsoft 365. |
Last Mailbox login | The last time a user logged into their mailbox |
License | The Microsoft 365 license that is assigned to a user |
License Administrator | Adds, removes, and updates license assignments for users, groups (using group-based licensing), and manages the usage location of users. |
Licensed | A user is licensed if they are assigned an Microsoft 365 license in your tenant. It is possible to have a user without a license. They can access the portal but won't be able to do anything or access your data unless they are an admin. |
Mail User | An external user. However, unlike a mail contact, a mail user has logon credentials in your Exchange or Microsoft 365 organization and can access resources. These users appear if content is shared or access given to anything within your Microsoft 365 tenant. |
MAPI | MAPI is a legacy protocol that is used to access email accounts. Disabling MAPI could increase security. However, disabling MAPI will prevent the use of Outlook to access email in Exchange mode, this is generally not recommended |
Message Centre Reader | Monitors changes to the service and can view all posts to the Message center in Microsoft 365 and share Message center posts with others through email. People assigned this role also have read-only access to some admin center resources, such as users, groups, domains, and subscriptions. |
MFA Status | The Multi Factor Authentication status of the user. All admins should have MFA enabled! |
OAuth2 (Modern Authentication) | OAuth2 or Modern Authentication fully supports all forms of Multifactor Authentication. For security and compliance the it is recommended that OAuth2 should always be enabled |
Password Expiry Policy | For security compliance all users should regularly change their password. Passwords should not be set to 'Never Expire' without a good reason |
POP | POP is a legacy protocol that is used to access email accounts. It does not support MFA so should not be used. If POP is enabled MFA can be bypassed to access your email. For maximum security it is recommended to block the use of POP to access email in Microsoft 365. |
Power BI Administrator | A person assigned to the Power BI admin role will have access to Microsoft 365 Power BI usage metrics. They'll also be able to control your organization's usage of Power BI features. |
Primary email address | The main email address of a user that is used to log into Microsoft 365 and is also the address seen by recipients of an email from this user |
Privileged Role Administrator | A customised administrator that can be given control over indivdually specified items in your Microsoft 365 tenant |
Reports Reader | Can view all the activity reports in the Microsoft 365 admin center. |
Reset Password at next login | Shows if the user will be required to reset their password the next time they log in |
Room Mailbox | A room mailbox is a resource mailbox that's assigned to a physical location, such as a conference room, an auditorium, or a training room. With room mailboxes, users can easily reserve these rooms by including room mailboxes in their meeting requests. When they do this, the room mailbox uses options you can configure to decide whether the invite should be accepted or denied. |
Security Defaults | Security defaults makes it easier to help protect your organisation from identity related attacks with preconfigured security settings. Requires all users to register for MFA. Requires Admins to do Multifactor AUthentication. Requires users to do Multifactor authentication when necessary (DOES NOT ENFORCE MFA IN ALL SITUATIONS). Blocks legacy authentication protocols. Protects privileged activities like access to the Azure Portal. Security defaults are useful if a tenant has only free tier Azure AD. They are generally not considered suitable if the tenant has premium licenses, uses conditional access policies, or has complex security requirements. |
Security Group | A security group is used to assign permission to a set of users to grant access to things, such as to a SharePoint Site, Web Pages, an entire SharePoint List or Document Library, or even just some files, etc. |
Service Support Administrator | Opens support tickets with Microsoft and views the service dashboard and message center. They have 'view only' permissions except for opening support tickets and reading them. |
Shared Mailbox | A shared mailbox does not take a Microsoft 365 license. A shared mailbox can only be accessed by someone that is given delegated permission to access it. It can function in exactly the same way as a regular mailbox but is not acessible independently. |
Sharepoint Administrator | Manages file storage for your organization in SharePoint Online and OneDrive. They do this in the SharePoint admin center. They can also assign other people to be site collection administrators. |
Site Collection Administrator | Controls one specified sharepoint site on your tenant. This role can be set by a Sharepoint administrator |
Skype Administrator | Configures Skype for Business for your organization and can view all the activity reports in the Microsoft 365 admin center. Can open and manage support tickets. |
SMTP | SMTP is a legacy protocol that is used to send email. SMTP does not support MFA. If SMTP is enabled MFA can be bypassed to send email from your accounts. For maximum security, and to prevent your accounts being spoofed, it is recommended to block the use of SMTP in Microsoft 365. |
Teams Communications Administrator | Can manage calling and meeting features of Microsoft Teams, including phone number assignments and meeting policies. They can also use call analytics tools to troubleshoot issues. |
Teams Communications Support Engineer | Can troubleshoot communication issues in Teams using call analytics tools, and can view full call record information for all participants involved. |
Teams Communications Support Specialist | Can troubleshoot communication issues in Teams using call analytics tools, and can view call record information for the specific user being searched for. |
Teams Service Administrator | Can manage all aspects of Microsoft Teams except license assignment. This includes policies for calling, messaging, and meetings; use of call analytics tools to troubleshoot telephony issues, and management of users and their telephony settings. This role additionally grants the ability to create and manage all Microsoft 365 Groups, manage support tickets, and monitor service health. |
Tenant | The instance of your Microsoft 365 that includes all of your content |
Unified Audit Log | The Unified Audit Log UAL, keeps a record of most events that occur in Microsoft 365. Without the unified audit log keeping track of events is in most cases impossible. For security and compliance the UAL should always be enabled |
User Account Administrator | Resets passwords, monitors service health, adds and deletes user accounts, manages support tickets, adds and removes members from Microsoft 365 groups. The user management admin can't delete a global admin, create other admin roles, or reset passwords for global, billing, Exchange, SharePoint, Compliance, and Skype for Business admins. This role also includes the ability to update license assignments for users and for groups (using group-based licensing), and manage the usage location of users. |
User Mailbox | The place where Microsoft 365 stores all of a user's email |
Verification Status | Shows if the domain is valid and ready to be used in your tenant |