Operations

Tenant Onboarding

End-to-end guide for onboarding a new tenant to the CONFIG365 platform — from initial discovery through production deployment and handoff.

7 min read Updated March 22, 2026

Process Overview

1
Pre-Onboarding Checklist
2
Tenant Discovery
3
Repository Setup
4
Configuration Review
5
Testing & Validation
6
Production Deployment
7
Handoff & Training
1

Pre-Onboarding Checklist

  • Tenant's Microsoft 365 tenant access confirmed
  • Global Administrator contact identified for admin consent
  • CONFIG365 portal access ready (credentials from your MSP admin)
  • Signed MSA (Master Service Agreement)
  • Security and compliance requirements documented
2

Tenant Discovery

Initial Assessment

Schedule a discovery session to understand the tenant environment:

Technical

  • – M365 license type (E3, E5, Business Premium)
  • – Number of users
  • – Third-party integrations
  • – Custom applications

Security

  • – Compliance standards (HIPAA, SOC 2, GDPR)
  • – Authentication requirements
  • – Conditional Access needs
  • – Device management scope

Business

  • – Organizational structure
  • – Department-specific needs
  • – External collaboration requirements
  • – Change management processes

Document Current State

  1. 1. Onboard the tenant in the CONFIG365 portal — this creates the Gitea repo automatically
  2. 2. Click Backup on the tenant dashboard card to trigger an immediate backup
  3. 3. Review backup output in the backups/ folder in Gitea (or via the Policy Viewer in the portal)
3

Repository Setup

Get Admin Consent

Send this consent URL to the tenant's Global Administrator:

https://login.microsoftonline.com/organizations/adminconsent?client_id=YOUR-APP-CLIENT-ID

After they accept, collect their Tenant ID (Entra admin center → Overview) and optionally their Exchange org name.

Onboard tenant in the CONFIG365 portal

Portal onboarding (recommended — no Gitea access required)

  1. 1. Open the CONFIG365 portal → Tenants → + Onboard
  2. 2. Enter domain, Tenant ID, and Client ID; click Save
  3. 3. The portal automatically creates tenant-contoso in Gitea and seeds workflow files

Note: Tenant credentials (Tenant ID, Exchange org name) are stored encrypted in the portal's SQLite database and automatically injected as Gitea org-level secrets at onboarding time. No manual secret management is needed.

4

Configuration Review

Create Baseline Exclusions

If the tenant shouldn't receive certain baseline policies, create a .baseline-ignore file in the tenant repo:

# Exclude specific policies
conditional-access/policies/Baseline - Block Legacy Auth.json

# Exclude an entire category
intune/windows-updates/*

# Exclude by pattern
**/Baseline - MSP*.json

Protect Existing Resources

For manually-managed resources that shouldn't be touched by automation, add CONFIG365:IGNORE to the resource's Description field in the Entra admin center.

Example description
Custom group managed by IT. CONFIG365:IGNORE
5

Testing & Validation

Run the Plan Stage

  1. 1. Go to Pipelines → Select Tenant pipeline → Run pipeline
  2. 2. Review the Plan stage output: what will be created, updated, and deleted
  3. 3. Share the Plan output with the tenant for confirmation
  4. 4. Address any concerns and verify exclusions worked correctly

Test Checklist

Conditional Access

  • MFA enforced for users
  • Emergency accounts can bypass
  • Legacy auth blocked

Groups

  • Baseline groups created
  • Dynamic membership working
  • Correct visibility

Intune

  • Compliance policies applied
  • Config profiles deployed
  • App protection active
6

Production Deployment

Pre-Deployment Checklist

  • Plan reviewed and approved by tenant
  • Exclusions configured in .baseline-ignore
  • Protected resources marked with CONFIG365:IGNORE
  • Tenant notified of deployment timeline
  • Rollback plan documented

Deploy

  1. 1. Go to the Tenant pipeline → Run pipeline
  2. 2. Wait for the Plan stage to complete
  3. 3. Click Review → Approve
  4. 4. Monitor the Apply stage — watch for any errors

Post-Deployment Verification

Microsoft Entra

  • Conditional Access policies active
  • Baseline groups created
  • Authentication methods configured

Microsoft Intune

  • Device configurations deployed
  • Compliance policies active
  • App protection policies applied
7

Handoff & Training

Documentation to Provide

  • – Repository access and pipeline documentation
  • – Variable group configuration reference
  • – Exclusion instructions (.baseline-ignore)
  • – Protection marker instructions (CONFIG365:IGNORE)
  • – Escalation procedures

Suggested Training Sessions

Session 1: Overview (30 min)

  • – How the system works
  • – Repository structure
  • – Daily backup process

Session 2: Day-to-Day Operations (1 hour)

  • – Running deployments
  • – Reviewing Plan output
  • – Approving changes
  • – Checking backup status

Session 3: Customization (30 min)

  • – Excluding baseline policies
  • – Protecting resources
  • – Requesting changes

Common Challenges

Existing Configurations

Problem: Tenant has existing CA policies, groups, etc.

Solution: Run a discovery backup first. Add CONFIG365:IGNORE to resources the tenant wants to keep managing manually, or align existing resource names with the baseline naming.

Phased Rollout

Problem: Tenant wants gradual deployment.

Solution: Use the pipeline trigger options to select which sections to run (e.g. groups only, then CA, then Intune). Enable additional sections as the tenant approves each phase.

Custom Requirements

Problem: Tenant needs policies different from the baseline.

Solution: Use .baseline-ignore to exclude the policies that don't fit the tenant. Configure those policies manually in the portal instead. This keeps the baseline clean while accommodating tenant-specific requirements.

GCC High / Special Clouds

Problem: Tenant is in GCC High or another special cloud.

Solution: Create a tenant-specific app registration in their tenant. Save the per-tenant Client ID and Secret in the CONFIG365 portal tenant settings — the token-api automatically uses tenant-specific credentials when present.