Skip to main content
50 skills in this category.

Anti-Spam Policy Tuning

Adjust Exchange Online Protection / Defender anti-spam policies from evidence, never from complaints alone — scoped overrides over broad allow-lists, time-limited exceptions, and the verdict data to justify each change. Use when a client says "too much spam getting through" or "legitimate mail keeps getting filtered."

App Protection Policies

Set up MAM-without-enrollment for BYOD — what app protection actually protects (org data in managed apps) and doesn't (the device), with the user-experience honesty that makes BYOD adoption work. Use for "protect company mail on personal phones", MAM policy requests, or "can we wipe company data without touching their photos".

Archive Mailbox Enablement

Enable an Exchange Online archive (In-Place Archive) when it actually solves the quota problem — license check, move-policy expectations, and auto-expanding archive caveats stated honestly. Use when a mailbox is full and archiving is on the table, or a ticket asks to "turn on the archive."

Autopilot Deployment

Work Windows Autopilot requests end-to-end — hardware hash registration, profile assignment, ESP behavior — and make the reset-vs-re-enroll call when a deployment goes sideways. Use for "set this device up with Autopilot", "Autopilot is stuck", or "white glove / ESP hanging" tickets.

B2B Collaboration Setup

Set up cross-tenant collaboration between a client and a partner organization — scoped cross-tenant access settings, MFA/device trust decisions, and a documented rollback. Use when a ticket asks to "let <partner org>'s users into our tenant", fix double-MFA for external users, or restrict which domains can be invited.

BitLocker Key Retrieval

Handle "I need my BitLocker recovery key" requests — identity verification FIRST, device-ownership match, key delivered over a verified channel, key rotated after use, audit note without the key. Use whenever anyone asks for a BitLocker recovery key or a device is stuck at the blue recovery screen.

Break-Glass Account Audit

Verify a tenant's emergency-access accounts actually work when everything else is broken — CA exclusions on every policy, sealed credentials, sign-in alerting, and a quarterly test sign-in. Use for periodic break-glass audits, before any CA change, or when nobody can say where the emergency credentials are.

Calendar Permissions

Grant, change, or review calendar sharing and delegation with scope discipline — the minimum folder role that satisfies the ask, owner consent, and private-items handling stated. Use when a ticket asks for calendar access, an assistant managing a calendar, or "why can't I see their calendar."

Conditional Access Review

Periodic inventory and gap review of a tenant's Conditional Access policies — overlaps, legacy-auth gaps, unprotected apps, and report-only discipline for any change. Use for "review <client>'s CA policies", posture assessments, or after an incident that a CA policy should have stopped.

Delegate Access Forensics

Answer "who sent/deleted/read what as whom" from the mailbox audit log — Send As vs Send on Behalf vs owner actions distinguished, logon types read correctly, findings reported neutrally. Use for delegation disputes, "I never sent that email," or "someone deleted messages from my mailbox."

Device Wipe Workflows

Choose the right Intune remote action — retire, wipe, fresh start, Autopilot reset, or delete — with explicit data-loss warnings and an approval gate before anything destructive runs. Use whenever a ticket asks to "wipe", "reset", "clean up", or "remove company data from" a device.

Distribution vs M365 Groups

Choose the right group type for the ask — distribution list, M365 Group, mail-enabled security group, or dynamic — and handle DL-to-M365-Group upgrades with the blockers checked first. Use when a ticket asks for "a group email," "a team," or wants to modernize an old distribution list.

DKIM Enablement

Enable DKIM signing for a custom domain in Exchange Online — publish the two selector CNAMEs, flip signing on, verify, and plan key rotation. Use when a ticket asks to "set up DKIM," a deliverability or DMARC project needs signing enabled, or keys need rotating.

Email Connector Setup

Get LOB apps, scanners, and printers sending mail through Exchange Online the least-privileged way — pick between SMTP AUTH submission, direct send, and an IP/certificate-scoped relay connector, and never build an open relay. Use when a device or application "needs to send email" or scan-to-email broke.

Enrollment Restrictions

Configure or explain Intune enrollment restrictions — personal vs corporate device rules, platform blocks, device limits, and how "corporate" is actually determined. Use for "stop personal devices from enrolling", "block Android from management", or when a restriction is bouncing legitimate enrollments.

Entra PIM Requests

Handle privileged-role requests through Privileged Identity Management — eligible vs active assignments, activation justification, and time-boxing — instead of handing out standing admin. Use when a ticket asks to "make <user> an admin", grant a directory role, or activate/extend a PIM assignment.

GDAP Relationship Review

Audit the MSP's delegated-admin (GDAP) relationships across client tenants — least-privilege roles, security-group mapping, expiring relationships, and unused access — before an expiry locks the MSP out mid-support. Use for periodic GDAP reviews, "what access do we have to <client>'s tenant", or a GDAP expiry warning.

Guest Access Audit

Inventory a tenant's B2B guest accounts, find the stale and never-redeemed ones, and put access reviews and expiration in place — cleanup gated behind approval. Use for "who are all these external users", periodic guest hygiene, or audit/insurance questions about external access.

Intune App Deployment

Process requests to deploy, update, or remove applications via Intune — packaging choice, required vs available intent, pilot-to-broad rings — with approval before any forced install or uninstall. Use for "push <app> to all machines", "make <app> available in Company Portal", or "remove <app> from the fleet".

Intune Compliance Policies

Handle requests to create or change Intune device compliance policies — what will mark devices noncompliant, grace periods, and the Conditional Access blast radius — piloted before broad enforcement. Use for "require encryption/min OS on devices", "why is this device noncompliant", or any compliance-rule change request.

Intune Enrollment Troubleshooting

Diagnose why a device won't enroll in Intune by walking a fixed ladder — user licensing, MDM user scope, device state, AAD join type — before touching the device. Use when a ticket says a Windows device "won't enroll", "isn't showing in Intune", or auto-enrollment silently never happened.

Journaling & Compliance Mail

Handle journaling and compliance-copy requests — legal/regulatory justification required, journal target must be external to the tenant, storage and third-party-archive implications costed, and retention/hold offered first where it fits. Use when a ticket asks to journal mail, BCC-copy all messages somewhere, or feed an external compliance archive.

M365 Group Lifecycle

Govern the full life of Microsoft 365 Groups — who can create them, naming, expiration/renewal, ownership, and clean retirement — and keep the group-vs-DL-vs-security-group decision straight. Use when a client asks to control group sprawl, set who can make groups/teams, handle expiring or ownerless groups, or clean up dead groups.

M365 License Optimization

Right-size a client's Microsoft 365 licensing from evidence — reclaim unused/unassigned licenses, downgrade over-provisioned users, and rationalize add-ons — as a proposal the client approves before anything is removed. Use when a client asks to cut M365 cost, review license usage, or "are we paying for licenses we don't use."

M365 Tenant Health Report

Produce an advisory digest of a client tenant's Microsoft 365 Service Health incidents and Message Center posts — what's degraded now and what change is coming — as a plain-language brief, not an action. Use when someone asks "is anything wrong with <client>'s M365," "what Microsoft changes are coming," or wants a periodic tenant health/roadmap digest.

Mail Flow Reports

Produce a periodic mail flow health summary for a client — volume trends, spam/malware catch rates, top senders and recipients, connector health, and forwarding anomalies — with flags on what changed since last period. Use for monthly/quarterly email health reviews or "is our mail filtering actually working" asks.

Mail Forwarding Audit

Inventory every forwarding path in a tenant or mailbox — mailbox-level forwarding, inbox rules, and transport rules — and treat external forwarding as the security surface it is. Use when a ticket asks "is anything forwarding out," a security review needs a forwarding sweep, or mail is arriving somewhere it shouldn't.

Mail Trace Investigation

Run a disciplined Exchange Online message trace — tight timeframe, sender/recipient pair, verdict reading, and the extended (historical) trace path for anything older than 10 days. Use when a ticket needs proof of what happened to a specific message or mail between two parties.

Mailbox Migration Prep

Build the pre-migration checklist for tenant-to-tenant or on-prem-to-cloud mailbox moves — full inventory, the list of things that break, holds and licensing checks, and the user comms plan. Use when a migration is being scoped or scheduled, before anyone touches a migration batch.

Mailbox Permissions Audit

Inventory who can access what across mailboxes — Full Access, Send As, Send on Behalf, and folder-level grants — and flag unexpected grants. Use when a ticket asks "who has access to this mailbox," a security review needs a delegation inventory, or offboarding needs a permission sweep.

Mailbox Quota Management

Investigate a full or filling mailbox and choose the right fix — targeted cleanup, archive enablement, or a license upgrade — based on where the size actually lives. Use when a ticket says "mailbox full," "can't send or receive," or quota warnings are firing.

MFA Methods Audit

Audit WHICH authentication methods users have registered — phone-only risk, push without number matching, missing phishing-resistant methods for admins — and plan the upgrade path. Use for "how good is <client>'s MFA really", SMS-deprecation planning, or FIDO2/passkey upgrade requests.

OneDrive Storage Governance

Set OneDrive policy deliberately — storage quotas, retention on leaver accounts, sync scope (which devices/domains can sync), and external-sharing posture. Use when a client asks about OneDrive limits, "what happens to files when someone leaves," blocking personal-device sync, or tightening OneDrive sharing.

Out-of-Office on Behalf

Set an automatic reply on an absent user's mailbox at someone else's request — authorization from manager/HR verified first, message content kept minimal and neutral, end date always set. Use when a ticket asks to "turn on OOO for" someone who is out sick, on leave, or departed.

Plus Addressing & Aliases

Handle requests for extra email addresses on a mailbox — plus addressing for self-service tagging, proxy aliases for real alternate addresses, and the send-from-alias caveats stated before anyone promises it. Use when a ticket asks for "another email address for," signup-tracking addresses, or "reply coming from the wrong address" complaints.

Power Automate Governance

Bring Power Automate under control — find orphaned flows owned by leavers, reassign ownership before it breaks, and govern which connectors staff can use. Use when a client asks who owns their flows, reports an automation that "just stopped," offboards a power user, or wants to restrict Power Platform connectors.

Purview DLP Policy

Scope, test, and roll out a Microsoft Purview Data Loss Prevention policy the safe way — test-mode first, narrow scope, evidence before enforce — so a new rule doesn't block legitimate business overnight. Use when a client asks to "stop staff emailing credit-card/SSN/PHI data," prevent data exfiltration, or meet a compliance requirement with DLP.

Resource Mailbox Setup

Create and configure room or equipment mailboxes — booking policies, auto-accept vs delegate approval, recurring-meeting and duration limits — so bookings behave the way the client expects. Use when a ticket asks for a bookable meeting room, projector, vehicle, or "why does the room double-book / never respond."

Retention Policy Requests

Handle requests to change retention or deletion policies in Microsoft Purview — confirm exact scope, warn about legal-hold interaction and irreversible deletion, and gate on documented authorization. Use when a ticket asks to keep mail for N years, auto-delete old items, or change what's retained.

Safe Attachments and Links Policy

Tune Defender for Office 365 Safe Attachments and Safe Links policies from evidence — dynamic delivery, detonation action, URL rewriting/scanning, and scoped exceptions — without breaking legitimate mail flow. Use when a client reports attachment delivery delays, blocked links, or asks to strengthen (or loosen) Defender for O365 protection.

Security Defaults vs Conditional Access

Decide whether a tenant should stay on security defaults or move to Conditional Access — and when migrating, sequence it so there is never an unprotected gap. Use for "should <client> turn off security defaults", small-tenant posture questions, or any request that requires a CA exception on a defaults tenant.

Sensitivity Labels

Roll out Microsoft Purview sensitivity labels deliberately — a small taxonomy first, auto-labeling in simulation before it goes live, and the encryption consequences understood before anyone clicks apply. Use when a client asks for document classification, "Confidential/Internal labels," data classification for compliance, or auto-labeling of sensitive files.

Shared Mailbox Creation

Create a new Exchange Online shared mailbox end-to-end — naming, license implications at the 50GB threshold, initial delegation, and the documentation note. Use when a ticket asks for a new shared mailbox, team inbox, or group email address that people need to work out of.

SharePoint Site Provisioning

Stand up a new SharePoint site or document library the right way — site type, permission model, and sharing defaults decided deliberately instead of inherited by accident. Use when a client asks for "a new SharePoint site," "a place to store X," "a document library for the team," or a shared file area.

SSPR Rollout

Plan and execute self-service password reset enablement for a tenant — method choices, registration campaign, hybrid writeback checks — framed around the helpdesk-ticket impact it is meant to deliver. Use when a client asks to "let users reset their own passwords" or an SSPR rollout is proposed to cut password tickets.

Stale Device Cleanup

Clean up stale Entra device objects on a last-activity threshold — with the BitLocker-key-loss warning, Autopilot exclusions, and a disable-first pattern before any delete. Use for "there are hundreds of old devices in Entra", periodic device hygiene, or pre-migration directory cleanup.

Teams Phone Admin

Configure Microsoft Teams Phone for a client — assign/reassign phone numbers, apply calling and caller-ID policies, and stand up basic auto-attendants and call queues. Configuration only, not live call control. Use when a client asks to give a user a phone number, change calling permissions, or set up a main-line menu / hunt group in Teams.

Tenant Onboarding Checklist

Bring a new M365 tenant under management the disciplined way — GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory, documentation — as a tracked checklist of tickets. Use when the MSP signs a new client with an existing tenant or stands up a fresh one.

Transport Rule Management

Inspect, add, or change Exchange Online mail flow (transport) rules safely — document the current state, test mode before enforce, respect rule order, disable instead of delete. Use when a ticket asks to add a disclaimer, block/allow a pattern, redirect mail, or asks "why is this rule doing that."

Windows Hello for Business

Roll out or troubleshoot Windows Hello for Business — prerequisites by join type, tenant-wide vs targeted enablement, and the "a PIN is stronger than a password" user conversation. Use for "enable Hello/PIN sign-in", "provisioning never launches", or hybrid users who can't reach on-prem resources after WHfB sign-in.