Managed IT
Most Microsoft 365 tenants were configured once, during migration, by whoever was available, and have run on those settings ever since. Everything works, so nothing prompts a review. The gap between a tenant that functions and a tenant that is configured properly is invisible right up until it is the subject of an incident report.
Microsoft 365 arrives working. Mail flows, files sync, Teams connects, and nobody has any reason to open the admin center again. That is precisely the problem: the settings that matter most are the ones nothing forces you to revisit, and a tenant left on defaults is not a neutral starting point so much as a set of decisions somebody else made for a different organization.
What a default tenant actually costs you
CoreView's State of Microsoft 365 research reports that 45% of large organizations have suffered a security or compliance incident caused by a Microsoft 365 misconfiguration. Not a breach of Microsoft. A setting in their own tenant.
The same research found 87% of organizations have MFA disabled for some or all administrator accounts. Those are the accounts with the most authority in the environment and the ones attackers look for first. It is rarely a decision anyone made deliberately, and much more often an exception granted during a migration that nobody went back to close.
There is an upside figure too. Microsoft's WorkLab research reports an average 9 hours of monthly time savings per user from Copilot, with the significant caveat that it applies once the thing is actually configured and adopted. Licensing it is not the same as deploying it, and plenty of organizations are paying for the first while waiting for the second.
Three things drift quietly
Security posture. Conditional access, admin roles, external sharing and legacy authentication all default to something, and the defaults favor compatibility over restriction.
Licensing. Seats accumulate for people who left, licenses sit at the wrong tier, and nobody reconciles assigned against used because the invoice looks normal.
Configuration. Retention, DLP, sharing rules and mailbox policies stay wherever migration left them, which is generally wherever required the least resistance that week.
Professional and Advanced, side by side
The Comparison
Both tiers cover day-to-day user support. The difference is whether Aureon also owns the tenant itself: its policies, its configuration and the engineering-level access that goes with that.
What is included
Professional Support
Logins · Password resets · Mailbox support · Licensing questions
Professional covers the requests your users actually raise: getting into an account, resetting a password, a mailbox behaving oddly, a question about a license. It is the right fit when you have internal capability to own the tenant and simply want the user-facing volume handled by somebody else. Application troubleshooting, tenant policy configuration, suite setup, Premium and E3/E5 add-on support, email encryption licensing, Active Directory sync and advanced role access are not part of this tier. If you need those, you need Advanced.
What is included
Advanced Support
Everything in Professional · App troubleshooting · Tenant policy · Suite configuration · AD sync
Advanced keeps all the everyday user support and adds ownership of the environment. That means application troubleshooting across Word, Excel, Outlook and the rest; Premium, E3 and E5 add-ons configured and supported; Aureon best-practice policies applied to the tenant; full M365 suite setup and ongoing configuration; email encryption licensing; Active Directory sync; and engineering-level access with an advanced roles and tenant overview. This is the tier for businesses that would rather Aureon owned the configuration than advised on it.
Where the line actually falls
The split is not really about difficulty. Professional answers questions about the environment. Advanced changes the environment. Everything in the second list is work that alters how the tenant behaves for everyone, which is why it sits behind engineering-level access rather than a support queue.
Available on either tier
Some work sits outside the tiers entirely and is available on both, on a time-and-materials basis: on-demand and project-based support, eDiscovery, migrations, Azure AD setup, journaling, compromised email remediation and onsite support. Copilot licensing, custom application consulting and full compliance audits run through Aureon's Professional Consulting team rather than either support tier.
Worth knowing when comparing, because a one-off migration does not require moving tier, and an ongoing configuration need is not solved by a project.
How to tell which one fits
The deciding question is not budget or size. It is whether somebody internal is genuinely accountable for the tenant.
Professional tends to fit when
You have an internal IT function that owns configuration and wants the user-facing ticket volume taken off its desk. Somebody in-house understands conditional access, retention and admin roles, reviews them periodically, and would notice if they drifted. Your tenant is relatively settled, and the work you need is ongoing support rather than ongoing change.
Advanced tends to fit when
Nobody internally can tell you when tenant policies were last reviewed, or the honest answer is that they were set during migration. You are paying for E3 or E5 and are not confident you are using what you pay for. Compliance or insurance requirements mean somebody needs to own the configuration and be able to evidence it. Or your IT capacity exists but is fully consumed by projects, which is the most common version of this.
The practical test
Work through the checklist below. If you can answer the security posture and configuration questions confidently, Professional is likely enough and you are buying capacity. If several of those answers are that you would have to go and look, the gap is ownership rather than volume, and adding user support will not close it.
Tenant Health Checklist
The Checklist
Fifteen questions across security posture, license usage and configuration. Tick the ones you can answer without going and looking in the admin center, and the score updates as you go. Use it yourself or share it with your team.
Tick what you can answer without checking. The blanks are the gaps.
Security Posture
Do all administrator accounts have MFA enforced?
CoreView found 87% of organizations have it disabled for some or all admins. These are the accounts attackers look for first.
How many global administrators do you have?
Most tenants have more than they need, often including a departed consultant and a break-glass account nobody documented.
Is legacy authentication blocked?
If it is still permitted, an older protocol accepts a password on its own and your conditional access policies never see it.
Can anyone share a file with anyone outside the business?
External sharing defaults toward permissive. Most organizations have never checked what theirs allows.
When were conditional access policies last reviewed?
A date, not a shrug. Policies set during migration have usually never been revisited.
License Usage
How many licenses are assigned to people who have left?
Offboarding that removes access but not the license leaves you paying for former employees.
Is anyone on E3 or E5 using only the basic features?
The largest per-seat waste in most tenants, and the least examined because blanket licensing is simpler.
Do you know your unassigned license count?
Seats bought for a hiring plan that changed sit on the invoice indefinitely unless somebody looks.
If you pay for Copilot, is it actually configured and adopted?
Microsoft reports around nine hours saved per user monthly, but only once deployed. Licensing is not deployment.
When is your renewal, and what is the notice period?
The decision window closes before the renewal date, which is where seat reductions get missed.
Configuration Gaps
Are retention policies configured, or left at default?
Retention determines what you can produce for a legal hold or an audit. Defaults are rarely what you would have chosen.
Is data loss prevention configured for anything?
DLP ships available and inactive. Available is not the same as protecting anything.
Do you know what happens to a mailbox when someone leaves?
An undefined offboarding path produces either lost data or licensed mailboxes for former staff.
Is Microsoft 365 data backed up separately?
Retention is not backup. Microsoft's own guidance puts data protection responsibility with the customer.
Who would notice if a tenant setting changed tomorrow?
If the answer is nobody, configuration drift is invisible until it appears in an incident report.
Frequently asked questions
Both tiers cover everyday user support such as logins, password resets, mailbox issues and licensing questions. Advanced adds ownership of the tenant itself: application troubleshooting across the Office apps, Premium and E3 or E5 add-ons configured and supported, Aureon best-practice tenant policies applied, full M365 suite setup and ongoing configuration, email encryption licensing, Active Directory sync, and engineering-level access with an advanced roles and tenant overview. Professional answers questions about the environment while Advanced changes the environment.
It depends on whether somebody internal is genuinely accountable for the tenant. Professional fits when you have in-house capability that owns configuration and simply wants user-facing ticket volume handled elsewhere. Advanced fits when nobody can say when tenant policies were last reviewed, when you are paying for E3 or E5 without confidence you are using it, or when compliance and insurance require somebody to own the configuration and evidence it. If the same issues keep recurring, the gap is ownership rather than support volume.
No. Professional covers everyday user support only: logins, password resets, mailbox support and licensing questions. Application troubleshooting, tenant policy configuration, M365 suite setup and configuration, Premium and E3 or E5 add-on support, email encryption licensing, Active Directory sync and advanced role access all sit in the Advanced tier. This matters when comparing, because a business that needs configuration work and buys Professional will not get it.
Yes. On-demand and project-based work sits outside the tiers and is available on either one on a time-and-materials basis, including eDiscovery, migrations, Azure AD setup, journaling, compromised email remediation and onsite support. Copilot licensing, custom application consulting and full compliance audits run through Aureon's Professional Consulting team rather than through either support tier. A one-off project does not require changing tier, and an ongoing configuration need is not solved by a project.
A tenant health check reviews the settings a Microsoft 365 environment is actually running on rather than the ones people assume it has. It typically covers security posture such as administrator MFA, global admin count, legacy authentication and external sharing; license usage including seats assigned to departed staff and users on tiers they do not need; and configuration including retention, data loss prevention, offboarding and backup. Most tenants have never been reviewed since migration, so findings are common.
Because a default tenant works, so nothing prompts anyone to revisit it. CoreView's State of Microsoft 365 research reports that 45 percent of large organizations have suffered a security or compliance incident caused by a Microsoft 365 misconfiguration, and that 87 percent have MFA disabled for some or all administrator accounts. Those are rarely deliberate decisions. They are usually exceptions granted during a migration that nobody went back to close, in an environment where the settings that matter most generate no symptoms.
Retention policies are not the same as backup, and Microsoft's own shared responsibility guidance places data protection with the customer rather than with Microsoft. Retention governs how long items are kept and when they are purged, which does not help with accidental deletion discovered late, malicious deletion by a compromised account, or ransomware affecting synced files. If Microsoft 365 holds business-critical data, a separate backup with its own retention is worth having.
Compare three numbers: licenses purchased, licenses assigned, and licenses genuinely in use. The most common waste is seats still assigned to people who have left, because offboarding often removes access without releasing the license. After that comes users on E3 or E5 who only use the basic feature set, which is usually the largest per-seat cost, and unassigned licenses bought for a hiring plan that changed. Check the renewal notice period too, since seat reductions have to be made before that window closes.
Not sure what your tenant is running on?
Get a free tenant review. We'll go through the checklist with you and show you what the defaults are still set to.


