Introduction

Completed

Someone at Relecloud needs to do exactly one thing: delete an old, unverified domain that's cluttering up the tenant. Nothing else—no password resets, no user changes, no security policy edits. Just that one task.

Handing them Global Administrator to do it also hands them the keys to every mailbox, every user account, and every security policy in the company—none of which this task called for. Is there a role that does only the one thing this job actually needs, and nothing more? There is, and almost nobody assigns it, because almost nobody's heard of it.

That's the choice facing you this week—except a domain isn't the only thing on the line. Relecloud is launching a new brand, "relecloud-ai.com," and the new team's first day is fixed. Before a single employee signs in, you have to get the tenant's identity right: the right domain, verified and live; the right branding, in the right portals; the right tenant-wide defaults—and for each one, an admin role to match. Get any of it wrong, and the mistake doesn't disappear when the task is done: it becomes standing access nobody remembers to remove, a mismatched brand greeting employees on launch day, or a default every future user quietly inherits.

What you'll learn

  • Recognize what a Microsoft 365 tenant is and how it sits on top of Microsoft Entra ID.
  • Assign the least-privileged administrator role for each tenant-identity task instead of defaulting to Global Administrator.
  • Add and verify a custom domain using Domain Connect or manual TXT and DNS records, and know what makes a domain removable later.
  • Apply branding across the two portals that own it—the Microsoft 365 admin center organization theme and Microsoft Entra company branding.
  • Configure the tenant-wide defaults every new user silently inherits, from password expiration and data location to release preferences and per-workload settings.

By the end of this module, you can set up a Microsoft 365 tenant's foundational identity—domain, branding, and organizational defaults—using the least-privileged administrator role for every task along the way.