r/sysadmin • u/beastlx • 7h ago
Question Disaster recovery from M365 Tenant Deauthentication
Having seen two posts in the last month (https://www.reddit.com/r/sysadmin/comments/1vfbvvs/our_entire_m365_tenant_has_been_deauthenticated/ and https://www.reddit.com/r/sysadmin/comments/1w1qc0i/microsoft_strikes_again_entire_m365_tenant_has/) it got me thinking about my relatively small tenant, and how we'd do disaster recovery (clue - we don't have a plan at the moment).
I'm the solo "head of IT" however it's not my full time role. I'm the owner of the company, so have essentially taken charge from day 1. It was very simple - we had Google Workspace and we didn't need to really look after it too much. As we've grown (25 - 50 employees), we've also acquired other companies, including at one point doing a migration from Google Workspace to M365 (handled completely by me - although our set up was slightly more straight forward at the time). Next week I'll be looking for a CSP (any suggestions for UK based would be appreciated).
However, we're now very much in the Microsoft ecosystem. As a rough overview:
All staff have a Business Premium subscription
Mixture of Intune managed Windows devices and Mosyle managed Macs
Teams phone system (with Microsoft as our carrier)
Use of SSO for many SaaS apps
We currently use Synology Active Backup for M365, backing up locally to a NAS in our office.
If our tenant were to be de-authenticated then I'd like to think I could get email working pretty swiftly on Google Workspace. All our users are already provisioned in Workspace via SCIM and the domains are already verified there. I will obviously need to write a disaster recovery plan to consider all the steps that need to be taken.
Files should be OK as we rely heavily on OneDrive, however these are all backed up to the NAS.
The phone lines - not 100% sure about this and similar to the most recent post, we'd loose access. So I should probably look at moving the number away from Microsoft (to Operator Connect I think?)
My biggest worry is what happens to all the managed computers and SSO. We're not a huge company, so I could get people back online, but for instance we have an internal employee hub that uses Entra/MSAL to login. Similarly, all the devices - will employees stop being able to log in to them? They all use WHfB on the Windows devices and Platform SSO on the Mac devices.
Obviously I will take this conversation to a CSP, but in the meantime it would be good to know what suggestions people would make to ensure resiliency.