Microsoft 365 SME Checklist NZ
Tenant basics, admin accounts, MFA redundancy, mailbox hygiene, and safe handover notes that prevent an access issue becoming a multi-week lockout.
Reading path
A practical order to reduce downtime: lock down identity/access, confirm tenant basics, and stabilise the devices and network the business depends on.
Start here
In SMEs, the highest-risk failures are usually not the laptop. They are lost admin access, missing MFA redundancy, and undocumented recovery paths. Fix the control plane first.
Tenant basics, admin accounts, MFA redundancy, mailbox hygiene, and safe handover notes that prevent an access issue becoming a multi-week lockout.
Use this for new or inherited tenants where the work is setup-specific: admin baseline, MFA methods, Teams/SharePoint structure, DNS records, and first-week verification.
When you want hands-on follow-up in Christchurch, this page describes the workflow: scope, access details, what evidence to capture, and how handover notes are written.
Use this when the problem is sign-in, MFA recovery, mailbox rules, admin ownership, DNS authentication, or evidence for escalation.
Use this when mail bounces, lands in spam, or depends on SPF, DKIM, DMARC, sender inventory, and bounce evidence.
Use this when the support session needs clear screenshots, secure access steps, and a written record without an onsite visit.
Microsoft 365 cluster
These pages now divide the Microsoft 365 work into useful search and support intents. Setup is for building the baseline; support is for restoring access or fixing a symptom; deliverability is for SPF, DKIM, DMARC, bounces, sender inventory, and spam-folder evidence.
Microsoft 365 setup Christchurch covers tenant ownership, admin/MFA baseline, DNS setup, Teams/SharePoint/OneDrive structure, and first-week checks.
Microsoft 365 support NZ covers sign-in, MFA methods, mailbox rules, forwarding, compromise checks, and escalation evidence.
Email deliverability support NZ covers sender inventory, SPF, DKIM, DMARC, bounce evidence, and safe policy tightening.
SME DNS and Email Checklist NZ maps registrar, DNS host, mail provider, records, and rollback notes.
Continuity
SME IT support is often continuity work: making sure one lost phone, failed laptop, forgotten password, or missing admin login does not stop invoices, bookings, emails, or customer follow-up.
Keep at least two safe admin paths for Microsoft 365, domain, hosting, email, and key business tools. Document recovery details before they are needed.
Know which files, apps, browser profiles, printers, email accounts, and MFA methods must move when a laptop is replaced or rebuilt.
Record shared mailboxes, aliases, forwarding, signatures, mobile setup, and who receives billing or security alerts.
Write down who hosts the domain, DNS, email, phones, internet, backups, and website so support does not start with provider guesswork.
Email risk
Email issues sit on a spectrum. Some are setup or deliverability problems; others are recovery problems after a suspicious sign-in, forwarding rule, or mailbox compromise. The reading path should steer those cases to the right evidence-first page.
Use when there are suspicious sign-ins, mailbox rules, forwarding, MFA changes, or recovery steps after a compromise.
A first-day response path for containment, rule review, password/MFA checks, and evidence capture.
Use when the symptom is bounce, spam placement, sender authentication, third-party senders, or DMARC reporting.
Use when mail or websites behave differently across networks, nameservers, TTL, DNS records, or provider routing are involved.
Control plane
Microsoft 365 support gets risky when the tenant, domain, DNS, billing, and MFA recovery paths are all unclear. Before fixing a mailbox or device, prove who controls the systems that could lock the business out.
Identify the active admin accounts, the backup admin path, the tenant ID if available, and whether any admin account depends on one person's phone.
Confirm the registrar, DNS host, nameservers, MX records, SPF, DKIM, DMARC, and whether the website or forms also send mail.
Record who receives billing notices, which plan is active, renewal dates, and whether subscription changes could affect mailboxes or storage.
Keep a private handover note with recovery contacts, support ticket IDs, original setup details, and a dated list of changes made.
Support pack
A small amount of preparation makes support faster and safer. The goal is not to expose private information; it is to capture enough context to diagnose the issue without guessing.
Which account is affected, what changed recently, whether MFA still works, and whether another administrator can still sign in.
Device model, Windows or macOS version, recent updates, error messages, backup status, and whether the issue follows the user or stays with the device.
Whether the issue happens on Wi-Fi, wired, mobile hotspot, one site, all sites, one app, or every device in the office.
Whether the problem is receiving, sending, spam placement, forwarding, shared mailboxes, a website form, or a third-party app sending as the domain.
Official references
Public checklists should point back to official sources where the underlying control matters. These references help frame MFA, admin recovery, domain DNS records, SPF/DKIM/DMARC, and SME cyber hygiene.
Microsoft explains multifactor authentication as the extra verification step that helps protect sign-ins beyond a password.
Microsoft Entra guidance covers emergency access administrator accounts so organisations are not locked out during failures.
Microsoft's domain setup guidance covers the DNS records used when a custom domain is connected to Microsoft 365.
CERT NZ's critical controls are useful NZ context for MFA, backups, updates, and security awareness in small organisations.
Use the path
IT support work goes better when the control plane is safe before the device-level troubleshooting begins. Confirm admin access, recovery methods, and tenant basics first, then move through devices, backups, Wi-Fi, and provider escalation in a repeatable order.
Confirm admin accounts, MFA methods, backup administrators, domain ownership, mail flow, and recovery details.
Check backups, storage, updates, account state, warranty position, and whether the issue follows the user or the machine.
Separate Wi-Fi, router, fibre, DNS, and provider issues before replacing hardware or changing plans.
Leave clear notes showing what changed, what was tested, and what should be monitored after the support session.
Devices
A lot of random problems are predictable once you capture the symptoms, backups, storage health, and login state. Do the safe triage first, then escalate.
A checklist to capture what matters: backups, disk space, OS state, login/account context, and hardware notes.
A repeatable workflow to protect the data, isolate the failing layer, and decide repair vs replace without guessing.
When you cannot do onsite work, remote support still works best with structured handover notes and clear evidence.
Network
Internet is slow usually has two different causes: Wi-Fi instability or a real upstream fibre/provider issue. The quickest fix path is to isolate which layer is failing and capture timestamps.
Fault-domain isolation, comparable tests, and an ISP escalation pack that reduces back-and-forth.
Router placement, mesh vs access points, roaming issues, and what to measure before buying new hardware.
Coverage checks, interference triage, router stability, and clean notes so changes are reversible.
Support handoff
Once the issue is narrowed down, capture the next action in a place the business can reuse: which control point is affected, who owns it, what changed, and when it should be checked again.
Use the services hub when the support issue crosses identity, devices, Microsoft 365, DNS/email, networking, fibre, or VoIP.
Use the calendar when Microsoft 365, backups, devices, DNS/email, profile accuracy, and access reviews need recurring checks.
Use this path when the Microsoft 365 issue depends on registrar control, nameservers, MX/TXT records, sender authentication, or rollback notes.
Use remote support when the next step is evidence gathering, screenshots, account checks, provider notes, or written handover.
Use the repair path when the Microsoft 365 symptom is tied to a slow, unstable, or replacement-ready device.
Use the tools hub when a checklist or small helper is enough to structure the next maintenance or handover task.