Stop 5 of 9 · Weekly
Microsoft 365 admin
Licences, shared mailboxes, conditional access and Intune policies: Claude drafts the steps and the command, you run them, and the change note writes itself.
Where the admin centre time actually goes
Tariq's Microsoft 365 work is not hard, it is fiddly and it is spread across four portals. A leaver needs a licence removed, a mailbox converted to shared, a delegate added, an Intune record retired and a note written for the file. None of those steps is difficult. Remembering all five in the right order at 16:40 on a Friday is.
Claude is useful here as the person who has read the documentation more recently than you have. It drafts the sequence, gives you the exact command where a command is faster than clicking, tells you what you should see when it worked, and writes the change note. You run everything.
The pattern
| Claude does | Tariq does |
|---|---|
| Drafts the ordered steps and the verification for each | Runs them in the portal or PowerShell |
| Writes the Graph or Exchange command | Reads every line before running it |
| Names the pilot group and the rollback | Assigns the pilot, watches, then widens |
| Produces the change note | Files it and dates it |
Two rules make this safe. Nothing tenant-wide goes out before a pilot group, and conditional access always starts in report-only mode, which is the same idea as a dry run: the policy evaluates and logs, and locks nobody out while you read the results.
Prompts for the common jobs
Write me the full offboarding sequence for a leaver at Grantham and Reed. Microsoft 365 with Exchange Online and SharePoint, Entra ID joined Windows 11 laptops in Intune, the leaver is a senior associate with a delegated shared mailbox and a company phone. Give me the steps in the order they must happen, and for each step: the portal or command, what I should see when it worked, and whether it can be reversed. Flag the steps that must wait for the manager to confirm data handover. End with a four-line change note I can paste into the file.
Here is our licence assignment export from the M365 admin centre. Tell me which licences are assigned to accounts that are blocked or unused, which users have two licences that overlap in what they provide, and what the tidy-up would save in seats. Give me the changes as a list I can work through, and mark any change that would remove a feature a user might actually be using. [paste or upload the licence export]
Draft a conditional access policy that blocks legacy authentication for all users at Grantham and Reed, with a break-glass account excluded. Give me the settings exactly as they appear in the Entra portal, the report-only configuration first, what I should look for in the sign-in logs after seven days before I enable it, and what the user-visible failure looks like if I have got the exclusions wrong.