Applicability Note

This article applies when a yacht wants to use Microsoft 365 for email, files, users, devices, and admin control. It is aimed at yachts using a private domain such as `crew@yachtname.com`, not personal Outlook or Gmail accounts.

Applicability depends on who owns the tenant, who pays for licences, who manages DNS, and whether the tenant belongs to the yacht, owner office, or management company.

What You Should Learn

  • Start with the domain and tenant ownership before creating users.
  • Pick licences by role, not by buying the same plan for everyone.
  • Use Microsoft 365 as an admin system, not just email and Office apps.
  • Tighten security for users and admins from day one.
  • Build enough Microsoft knowledge onboard to manage routine changes safely.

Start With The Domain

The private domain is the anchor. If the yacht uses `yachtname.com`, Microsoft 365 needs DNS records for Exchange Online and service verification. That setup usually happens in the Microsoft 365 admin center and at the domain registrar or DNS host.

Do not rush this. Decide who owns the domain and who can change DNS. If the domain is held by a former contractor, a personal account, or an old management company login, fix that before building the tenant.

Use role addresses carefully. `captain@`, `purser@`, `engineering@`, and `it@` are better as shared mailboxes or groups in most cases. Individual crew should still have named accounts. That gives the yacht an audit trail and makes offboarding cleaner.

Account Creation

Create accounts around real roles. A captain, purser, ETO, engineer, seasonal crew member, and shore-side manager do not need the same access.

For each account, record the person, role, start date, licence, MFA method, group membership, mailbox access, and expected offboarding date if temporary. Keep this as a simple admin register. It will save time during crew rotation.

Avoid shared human logins. They feel convenient until someone leaves and nobody knows who read or sent a message. Use shared mailboxes for role addresses and named accounts for people.

Licensing Selection

Microsoft 365 Business Basic can be enough for light users who only need web apps, email, Teams, and files.

Business Standard adds desktop Office apps. That may suit captains, pursers, and office-heavy users who work offline.

Business Premium is usually the better yacht-admin licence. It brings stronger identity, Intune device management, Defender security services, and information protection into the same package.

Do not under-license the admin. The person responsible for users, devices, and security needs the tools to do the job.

Services Worth Using

Exchange Online handles business email and calendars. Outlook gives crew and management a familiar working interface.

OneDrive is for individual work files. SharePoint is for yacht-controlled document spaces. Use SharePoint for technical documents, handover records, purchasing folders, and controlled department libraries.

Teams can work for internal chat, calls, and project spaces. Keep it disciplined. Do not let every refit folder become a permanent access path.

Entra ID is the identity layer. It controls users, groups, MFA, sign-in policy, and admin roles.

Intune matters when the yacht issues or manages laptops, phones, and tablets. It helps apply device policy, app policy, compliance rules, and wipe actions.

Defender for Office 365 and Defender for Business help with email threats and endpoint protection. Purview becomes useful when the yacht needs sensitivity labels, data loss prevention, or better control over sensitive files.

Tightening Security

Start with MFA for everyone. Admin accounts need it without exception.

Use separate admin accounts. The ETO or IT admin should not browse email and open attachments from the same account used to change tenant settings.

Limit admin roles. Give people only the role they need. A user who only resets passwords should not be Global Administrator.

Block legacy authentication unless there is a documented exception. Old mail protocols can bypass modern controls and create avoidable risk.

Review guest access. Contractors, vendors, shipyards, and management users should have clear owners and end dates.

Keep two emergency access accounts. Store them securely and test the process. They are for lockout recovery, not daily work.

Use Secure Score as a review tool, but do not treat the score as the whole security programme. The yacht still needs judgement.

Why This Helps The IT Admin

A well-built Microsoft 365 tenant gives the onboard IT admin one place to manage joiners, leavers, devices, email, shared files, and basic security. It reduces the number of mystery accounts and personal workarounds.

It also makes handover better. A new ETO can see who has access, which devices are managed, where documents live, and which alerts need review.

The practical gain is control. When a crew member leaves, the admin can disable the account, remove mailbox access, revoke sessions, wipe a managed device if needed, and keep the yacht's records.

What The Admin Should Learn

Start with Microsoft 365 administration basics. Learn users, groups, domains, Exchange mailboxes, SharePoint permissions, OneDrive, Teams, and licence assignment.

Then learn identity and security. The key topics are MFA, security defaults, Conditional Access, admin roles, guest access, and sign-in logs.

After that, learn endpoint management. Intune is the route into device compliance, app control, Windows management, and mobile-device policy.

For formal study, Microsoft Learn paths around Microsoft 365 administration, Security Compliance and Identity Fundamentals, Endpoint Administrator, and Microsoft 365 Administrator Expert are the useful ladder. The goal is not certificates for decoration. The goal is enough competence to make safe changes without guessing.

Practical Yacht Scenario

A purser leaves during a busy season. In a weak setup, the yacht changes one password and hopes nothing was missed.

In a managed Microsoft 365 setup, the admin disables the named account, removes shared mailbox access, revokes active sessions, checks forwarding rules, transfers OneDrive files, removes the user from Teams and SharePoint groups, and records the action. The new purser gets a named account and the right role-based access.

That is the difference between email hosting and administration.

References