Table of Contents
So Many Applications, So Many Settings, Poor Interaction at Times, and AI on Top
A recent Reddit thread asked whether Microsoft 365 has become too complex for any one person to truly understand. It’s a good question because it goes beyond technical administration. Who does a CIO or CTO turn to when they need a clear understanding of how a tenant functions, where risks exist, and how different services interact?
Fifteen years ago, Microsoft launched Office 365. The transition from on-premises versions of applications like Exchange Server and SharePoint Server could seem complicated, but looking back on the situation now, it really wasn’t. Microsoft removed the need for server management and added layers to handle licensing and billing. Migration and coexistence in hybrid environments were the hardest problems to solve, largely due to the immaturity of some of the tools.
The challenges facing someone moving from being an on-premises administrator seemed daunting in 2011 because the cloud was so new. The cloud is no longer new, but acquiring and maintaining the knowledge needed to understand the Microsoft 365 ecosystem has become far more difficult.

I meet very few people who are genuine experts in more than one Microsoft 365 service. The challenge is no longer mastering a single workload. The challenge is understanding how workloads interact and depend on one another to deliver business outcomes.
Here are some brief notes about the challenges I see administrators face in major parts of Microsoft 365.
Entra ID
The primary task for Entra ID specialists is to protect the tenant and ensure that its operations remain secure. In doing so, they figure out conditional access and the introduction of passkeys to replace older authentication methods, understand how an ever-growing set of roles are used in production and control who is assigned those roles. Guest and external access is of huge importance, so managing guest accounts and tenant relationships is a critical task.
Entra ID administrators must also understand applications and service principals, permissions assigned to the apps and why those permissions are needed. Entra ID keeps on adding functionality and features, most of which require P1 or P2 licenses, creating an administrative need to decide what extra capabilities the tenant needs and how much these will cost.
SharePoint Online
SharePoint Online administrators are the most challenged of all when it comes to the introduction of AI. The flaws and shortcomings in SharePoint deployments are mercilessly exposed by Microsoft 365 Copilot, and usually not in a good way. Microsoft has poured effort into capabilities like Restricted Content Discovery (RCD) and advanced SharePoint management reports to help administrators control what content is available to AI, including the third-party connectors that can process SharePoint Online and OneDrive for Business content.
Managing document storage doesn’t get any easier because Microsoft continues to store just about everything that it can in SharePoint Online and OneDrive for Business, not to mention SharePoint Embedded. Throw in changes like the removal of unlicensed OneDrive accounts after 365 days (a challenge for those who schedule Teams meetings from shared mailboxes) and the introduction of Microsoft 365 archiving, now available at file level, and SharePoint is a busy place.
Teams
Teams illustrates the complexity of modern Microsoft 365 better than almost any other application because it is fundamentally dependent on a wide range of services, including Exchange Online, SharePoint Online, OneDrive for Business, Entra ID, Planner, and Azure microservices. The number of moving parts and complex interactions means that Teams is an application that could never be built for on-premises deployments.
Teams isn’t just the messaging app that appeared in late 2016. Online meetings and events became much more important when the Covid-19 pandemic flared up and that situation continues today. Then there’s the role of Teams as an app platform, and the extra features available through Teams Premium, not to mention the world of telephony enabled by Teams Phone. Add the need to manage numbers for users and Teams devices for meeting rooms and other hardware and a Teams administrator is a busy person.
Exchange Online
In some ways, the transition of Exchange to the cloud was the quickest and simplest. The current version of Exchange Online is very different to Exchange Server SE because the mission has changed. Exchange Online is all about providing messaging services to apps across the Microsoft 365 ecosystem. Those services include the capture of compliance data as mail items stored in Exchange mailboxes, including hidden mailboxes maintained for guest accounts, a capability most recently exploited by Planner. Exchange mailboxes moved to the cloud quickly and since then Exchange Online has been a prime target for attack, meaning that administrators must pay attention to Exchange Online Protection and Microsoft Defender for Office 365, including making sure that shared mailboxes which are exposed to external email are correctly licensed.
Microsoft has done a remarkable, if lengthy, job of eliminating basic authentication from Exchange Online while maintaining support for a broad range of clients and devices. Clients include mobile clients and the new Outlook, which might eventually replace Outlook classic sometime after 2029. The effort to eliminate basic authentication still has a way to go as devices and applications must move from basic authentication for the SMTP client submission protocol to OAuth2 authentication. High Volume Email (HVE) seemed like a way forward, but its development has been too slow and the transition to OAuth2 authentication remains too complex for many apps and devices.
Purview
Microsoft has poured massive development resources into Purview over the last five years. Understanding the core Purview capabilities requires a great deal of knowledge because it sits above the workloads rather than within them. Retention, eDiscovery, data loss prevention, and sensitivity labels all depend on understanding how Exchange Online, SharePoint Online, OneDrive for Business, Teams, and other services store and process information.
Understanding the basic Purview solutions requires a great deal of knowledge about the solutions and the underlying applications. A case can be argued that Purview administrators often need more knowledge and experience than any other type of Microsoft 365 administrator. Purview basics that every administrator should understand include data lifecycle management (retention), including adaptive protection, eDiscovery, data loss prevention, and information protection (sensitivity labels). It’s a full-on role.
Automation
Administrators have automated on-premises tasks since the first on-premises servers appeared. The tools available in Microsoft 365 are more sophisticated, complete, secure, and capable, but they take a lot of work to master. Understanding the Microsoft Graph delivers great insight into how applications work, but mastering the Graph and being able to use its APIs to automate processes is harder than it should be, even with tools like the Microsoft Graph PowerShell SDK.
An Agentic World
On top of existing administrative demands, Microsoft is attempting to lead customers into an agentic future where the management of agents, including data access, governance, and reporting, is currently immature. Like everything else that has gone before, improvements will come over time to close the knowledge gap and deliver the necessary tools. I’m sure everything will be ready by 2030.
And More
There’s much more in Microsoft 365 when it comes to administrative challenges. Work and complexity grow all the time, and the ever-changing nature of the ecosystem through hundreds of software updates applied annually doesn’t help. I guess the hope is that artificial intelligence will solve the problem by helping human administrators to understand what needs to be done and how to do it.
AI can help administrators find answers faster, but it does not remove the need to understand how Microsoft 365 actually works and be able to understand how a specific tenant works. If anything, the rise of AI makes that understanding more important because the quality of AI-driven outcomes depends on the quality of the tenant beneath it. For example, if your SharePoint Online deployment contains lots of outdated information, Microsoft 365 Copilot will use that information in its responses.
The challenge for Microsoft 365 administrators is no longer in mastering individual technologies. It is understanding how an increasingly interconnected ever-changing ecosystem fits together. Add organizational and business knowledge to the mix, and a Microsoft 365 administrator who can handle everything is a rare being in anything but a small tenant. The acid test for executives is how to replace the current administrator if they left. Finding the right person is harder than ever before and isn’t going to get any easier.
The Microsoft 365 for IT Pros eBook can’t deal with organizational politics or business demands. We can help tenant administrators to keep up to date and understand what’s going on inside Microsoft 365. It’s what we do, and what we’ve done since May 2015.
I totally agree with your observations and your point about Purview is very true, that product is getting a few updates every week and it’s integration with Fabric and networking is making it even more complicated
Is Microsoft 365 Too Complex for Humans to Understand? That’s as true a statement I’ve ever heard.
Pity those of us who are the sole IT person in small orgs and are expected to somehow understand and properly administer every feature of M365.
I know so much more about M365 services than I did, say a year ago– to say nothing of five or six years ago when I started working with it– but I’ve resigned myself to the fact that what I know will always be dwarfed by what I don’t.
I used to stress about that, but now I just try to learn as much as I reasonably can, do the best job I can, and try to be Zen about the rest.
This site– and the books– have been a great help in that regard, and for that, I thank you!
No worries… this site is all about knowledge sharing.
Speaking about agents. A few last days i am trying to figure out management for one customer. There is Copilot menu in M365. And there is Agents. And some menus are locked as you don’t have Agent 365. Customer has thousands of agents already. But if agent was created in Studio, it must be managed and published there. As a global admin i cannot open Copilot Studio portal as i need to add permission and a Studio license. And this permission must be added via Power Platform portal, where i again need another role. Just going in circles all the time…
Agents are definitely a confusing area. That’s why we added a chapter on Copilot and agents in the Microsoft 365 for IT Pros (2027 edition) eBook…
Great piece, thank you for this. It’s been validating, as I’ve been saying similar for years. Leading up to my retirement earlier this summer, I tried to hammer these points home to anyone who’d listen. It felt like I was screaming into the darkness.
It’s a giant beast ecosystem with dozens of moving parts that are all tangled up together. To understand one aspect of it requires knowing a lot about many other parts of the platform. It’s intimidating to a lot of people, even seasoned tech veterans. The scarier part is that the platform houses or facilitates all of the information exchange in the company. One wrong setting or missed Message Center bulletin and really bad things can happen.
Managing M365 is in no way a one person job for tenants of any size. Most companies still can’t come to grips with that reality. The ones that do should be taking really good care of their administrators because you are correct – they’re a lot harder to replace than one might think.
Completely agree. I’d add that licensing is part of the same complexity problem. When technical requirements, procurement decisions and user assignments are managed separately, even a well-run tenant becomes difficult to understand.
A practical approach is to define role-based license bundles, clear owners for exceptions and a fixed review cycle. This article explores that governance angle in more detail:
https://www.axeti.com/blog/microsoft-licensing-governance-for-enterprise-it