Tenant Onboarding
End-to-end guide for onboarding a new tenant to the CONFIG365 platform — from initial discovery through production deployment and handoff.
Process Overview
Pre-Onboarding Checklist
- Tenant's Microsoft 365 tenant access confirmed
- Global Administrator contact identified for admin consent
- CONFIG365 portal access ready (credentials from your MSP admin)
- Signed MSA (Master Service Agreement)
- Security and compliance requirements documented
Tenant Discovery
Initial Assessment
Schedule a discovery session to understand the tenant environment:
Technical
- – M365 license type (E3, E5, Business Premium)
- – Number of users
- – Third-party integrations
- – Custom applications
Security
- – Compliance standards (HIPAA, SOC 2, GDPR)
- – Authentication requirements
- – Conditional Access needs
- – Device management scope
Business
- – Organizational structure
- – Department-specific needs
- – External collaboration requirements
- – Change management processes
Document Current State
- 1. Onboard the tenant in the CONFIG365 portal — this creates the Gitea repo automatically
- 2. Click Backup on the tenant dashboard card to trigger an immediate backup
- 3. Review backup output in the
backups/folder in Gitea (or via the Policy Viewer in the portal)
Repository Setup
Get Admin Consent
Send this consent URL to the tenant's Global Administrator:
https://login.microsoftonline.com/organizations/adminconsent?client_id=YOUR-APP-CLIENT-ID After they accept, collect their Tenant ID (Entra admin center → Overview) and optionally their Exchange org name.
Onboard tenant in the CONFIG365 portal
Portal onboarding (recommended — no Gitea access required)
- 1. Open the CONFIG365 portal → Tenants → + Onboard
- 2. Enter domain, Tenant ID, and Client ID; click Save
- 3. The portal automatically creates
tenant-contosoin Gitea and seeds workflow files
Note: Tenant credentials (Tenant ID, Exchange org name) are stored encrypted in the portal's SQLite database and automatically injected as Gitea org-level secrets at onboarding time. No manual secret management is needed.
Configuration Review
Create Baseline Exclusions
If the tenant shouldn't receive certain baseline policies, create a .baseline-ignore file in the tenant repo:
# Exclude specific policies conditional-access/policies/Baseline - Block Legacy Auth.json # Exclude an entire category intune/windows-updates/* # Exclude by pattern **/Baseline - MSP*.json
Protect Existing Resources
For manually-managed resources that shouldn't be touched by automation, add CONFIG365:IGNORE to the resource's Description field in the Entra admin center.
Custom group managed by IT. CONFIG365:IGNORE Testing & Validation
Run the Plan Stage
- 1. Go to Pipelines → Select Tenant pipeline → Run pipeline
- 2. Review the Plan stage output: what will be created, updated, and deleted
- 3. Share the Plan output with the tenant for confirmation
- 4. Address any concerns and verify exclusions worked correctly
Test Checklist
Conditional Access
- MFA enforced for users
- Emergency accounts can bypass
- Legacy auth blocked
Groups
- Baseline groups created
- Dynamic membership working
- Correct visibility
Intune
- Compliance policies applied
- Config profiles deployed
- App protection active
Production Deployment
Pre-Deployment Checklist
- Plan reviewed and approved by tenant
- Exclusions configured in .baseline-ignore
- Protected resources marked with CONFIG365:IGNORE
- Tenant notified of deployment timeline
- Rollback plan documented
Deploy
- 1. Go to the Tenant pipeline → Run pipeline
- 2. Wait for the Plan stage to complete
- 3. Click Review → Approve
- 4. Monitor the Apply stage — watch for any errors
Post-Deployment Verification
Microsoft Entra
- Conditional Access policies active
- Baseline groups created
- Authentication methods configured
Microsoft Intune
- Device configurations deployed
- Compliance policies active
- App protection policies applied
Handoff & Training
Documentation to Provide
- – Repository access and pipeline documentation
- – Variable group configuration reference
- – Exclusion instructions (.baseline-ignore)
- – Protection marker instructions (CONFIG365:IGNORE)
- – Escalation procedures
Suggested Training Sessions
Session 1: Overview (30 min)
- – How the system works
- – Repository structure
- – Daily backup process
Session 2: Day-to-Day Operations (1 hour)
- – Running deployments
- – Reviewing Plan output
- – Approving changes
- – Checking backup status
Session 3: Customization (30 min)
- – Excluding baseline policies
- – Protecting resources
- – Requesting changes
Common Challenges
Existing Configurations
Problem: Tenant has existing CA policies, groups, etc.
Solution: Run a discovery backup first. Add CONFIG365:IGNORE to resources the tenant wants to keep managing manually, or align existing resource names with the baseline naming.
Phased Rollout
Problem: Tenant wants gradual deployment.
Solution: Use the pipeline trigger options to select which sections to run (e.g. groups only, then CA, then Intune). Enable additional sections as the tenant approves each phase.
Custom Requirements
Problem: Tenant needs policies different from the baseline.
Solution: Use .baseline-ignore to exclude the policies that don't fit the tenant. Configure those policies manually in the portal instead. This keeps the baseline clean while accommodating tenant-specific requirements.
GCC High / Special Clouds
Problem: Tenant is in GCC High or another special cloud.
Solution: Create a tenant-specific app registration in their tenant. Save the per-tenant Client ID and Secret in the CONFIG365 portal tenant settings — the token-api automatically uses tenant-specific credentials when present.