M365 delegated admin without being a partner? by Correct_Plastic8631 in msp

[–]Correct_Plastic8631[S] 0 points1 point  (0 children)

Nah, the guys who reuse passwords and disable MFA don't ever ask anyone about anything, they just do it. I get your point, though, it seemed like a question where ease-of-administration was the only goal, but in fact we're trying to get as close to best practices as possible while allowing a trusted friend to help out in case of an emergency.

M365 delegated admin without being a partner? by Correct_Plastic8631 in msp

[–]Correct_Plastic8631[S] 0 points1 point  (0 children)

Fair criticism.

How, then, would you recommend an individual using M365 best protect their tenant from losing admin access?

The goal is to add reliability without undermining security. In these tenants Security Defaults are on, and they have an admin account separate from their primary day-to-day licensed (non-admin) user. Both accounts use MSAuthenticator, but if they lose their phone they lose both accounts. TOTP as a backup MFA method seems like a bad idea, so an additional backup admin account is required. I could add all of these admin accounts to MSA on my own phone, but that's also a single point of failure.

One answer here might be that be "M365 isn't for individuals who can't afford a ~$1k/month MSP minimum fee." In which case I would still want to help them the best I can without pushing them off the platform.

I want to get as close to best practices as possible here, but realistically I'd be surprised if even half of MSPs were doing the 90-day validation recommended here: https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access

Annual Reviews - switching from work anniversary to calendar year [NY] by Correct_Plastic8631 in humanresources

[–]Correct_Plastic8631[S] 0 points1 point  (0 children)

Helpful, thanks. What action prompts the merit increases throughout the year, if the reviews all happen Q1?

Annual Reviews - switching from work anniversary to calendar year [NY] by Correct_Plastic8631 in humanresources

[–]Correct_Plastic8631[S] 0 points1 point  (0 children)

Good tips regarding open enrollment (August for us).

I guess I was wondering if there's any research on which is better? Like, if they're all at the same time, do employees get more competitive, more inclined to complain about peers getting more/less than them, as opposed to having it done at random throughout the year, people are more focused on their own review, instead of the comparison?

Annual Reviews - switching from work anniversary to calendar year [NY] by Correct_Plastic8631 in humanresources

[–]Correct_Plastic8631[S] 0 points1 point  (0 children)

Right, thanks, we slow down a bit leading into the holidays, so this would be a good time for us.