Skip to content

“Is anyone actually watching our tenant, or do we find out when something breaks?”

Turn “light tenant check-ins” into a specific watch list.

The Plus plan already names light tenant check-ins as one of three additions over Essential. Most buyers read that line and picture something different from what it actually is. This page says exactly what gets watched during that check-in, and what happens when something is worth a closer look.

What a check-in actually looks at

Four things worth a regular look, not a guess.

Service health history

Microsoft 365 service incidents that touched your tenant, reviewed for a pattern rather than reacted to one at a time.

Mailbox & storage quotas

Accounts approaching a size or quota limit before it quietly blocks someone.

Licence utilization

Assigned-but-unused licences, or a mismatch between a person’s role and their licence tier.

Sign-in risk signals

Unusual sign-in reports worth a second look, named clearly rather than buried in a dashboard nobody opens.

What a flagged item actually looks like

Three examples of what the desk names during a check-in.

A mailbox nearing its limit

An account is approaching a storage quota that would otherwise start bouncing incoming mail. The desk flags it during the check-in and names the routine fix or archiving option, applied once approved.

A licence that does not match the role

Someone is assigned a higher tier than their role uses, or a former project’s licence was never reassigned. The desk names the mismatch; deciding whether to change it stays a business call.

See how licence spend fits a check-in →

An unusual sign-in pattern

A sign-in report shows an unfamiliar location or repeated failed attempts. The desk names what was seen and hands it to your business or a security specialist to investigate properly.

See phishing and email security triage →

Set the expectation

Named plainly, on purpose.

Is this 24/7 automated monitoring?
No. Light tenant check-ins are a periodic review during the support relationship, not a continuously staffed operations centre.
Is this a security-incident response service?
No. A flagged sign-in risk is named and handed to your business or a security specialist for a real investigation, not resolved as an incident case.
Is there a published alerting SLA?
No. No response-time guarantee is published for this or any other part of the service.
Is it included with Essential?
No. It is a named Plus-plan addition, published at $49 CAD per user per month.

Common questions

What a check-in finds, and what happens next.

What happens when a check-in finds something?

It is named plainly: a routine fix the desk can apply once approved, or a finding handed to your business or a security specialist with the facts attached.

Do you monitor our devices as well as the tenant?

Device compliance and patch status are a related but separate topic—see Intune device management for that side of things.

Can Essential add this on its own?

No. Light tenant check-ins are published as a Plus-only addition alongside priority queue position and light security-baseline support.

Who actually looks at these reports?

The same desk that already owns everyday support does the review, on the cadence set by the support relationship—not a separate security team or a third-party tool added on top.

Compare the plans

See this alongside the rest of what Plus adds.

Discuss tenant check-ins →Compare Essential and Plus →