Service · Microsoft 365 & Cloud

Microsoft 365,
set up the way it should have been.

Most tenants we inherit were stood up once, years ago, by whoever was available — then never touched again. We design the tenant, move the mail without losing a weekend, lock down identity, and manage it from there.

Tenant design
Delivered remotely
Email migration
Entra ID & Intune
Ongoing administration
01 · The problem

A license is not a configuration.

Buying Microsoft 365 gets you mailboxes and Office apps. It does not get you MFA on every account, a working backup, sane sharing rules, or any idea who has access to what. Those are decisions someone has to make — and in most of the tenants we take over, nobody ever did. What we find on a typical takeover:

Global admin rights handed out to three or four people who don't need them
Legacy authentication still enabled, quietly bypassing MFA
Shared mailboxes with a password and a licensed sign-in
Ex-employee accounts still active months after the last day
OneDrive and SharePoint links shared with "anyone with the link," permanently
No tenant backup, on the assumption Microsoft keeps a copy (it doesn't, not the way you'd want)

None of that is exotic. It's what happens when M365 is bought as a product instead of built as a system.

02 · Tenant design & buildout

Built once, correctly, so it stays that way.

Whether you're new to Microsoft 365 or replacing a tenant that grew sideways, we start with the same structure.

Identity

Named admin accounts, break-glass account, role-based admin (no permanent global admins).

Authentication

MFA enforced tenant-wide, legacy auth blocked, Conditional Access policies scoped to your risk.

Email

Exchange Online with SPF, DKIM, and DMARC published and monitored.

Files

SharePoint and OneDrive structure that matches how your teams actually work, with sharing defaults locked down.

Groups & Teams

Naming standard, ownership rules, and an expiry policy so the sprawl stops.

Devices

Enrollment path into Intune from day one, not bolted on later.

Backup

Third-party backup of mail, OneDrive, SharePoint, and Teams with tested restores.

Every tenant we build gets documented and handed to you. It's your tenant, your data, and your admin credentials — we just run it.

03 · Migration

Move the mail. Keep the business open.

We've migrated from Google Workspace, on-prem Exchange, IMAP hosts, GoDaddy, and other MSPs' tenants. The mechanics differ; the standard doesn't.

  1. 1

    Discovery

    Mailbox sizes, shared mailboxes, distribution groups, public folders, calendar permissions, third-party integrations, and anything hardcoded to an old address.

  2. 2

    Tenant prep

    Domains verified, DNS staged, licensing assigned, security baseline applied before a single mailbox moves.

  3. 3

    Pre-sync

    Mail, calendars, and contacts copied in the background while everyone keeps working in the old system.

  4. 4

    Cutover

    Scheduled after hours or over a weekend. MX flips, delta sync runs, and we watch mail flow.

  5. 5

    Day one on-site or on-call

    Outlook profiles, phones, scan-to-email, and the printer that only sends through the old relay.

  6. 6

    Cleanup

    Old system decommissioned on a schedule, not abandoned.

What we plan for that people forget: the copier that emails scans, the alarm system that sends alerts, the accounting software with SMTP credentials saved in 2017, and the shared calendar the whole front office lives in.

04 · Entra ID & Intune

One identity, every device, one set of rules.

Entra ID — identity

  • Conditional Access: block sign-ins from countries you don't do business in, require compliant devices for sensitive apps, step up authentication on risky logins
  • Single sign-on for the line-of-business apps that support it
  • Self-service password reset, so a lockout isn't a phone call
  • Joiner/mover/leaver process: accounts provisioned on day one and disabled the hour someone leaves

Intune — devices

  • Windows and macOS enrollment, with Autopilot for new hardware that ships straight to the user
  • Baseline policies: disk encryption, screen lock, firewall, patch rings
  • App deployment and updates without touching each machine
  • Mobile: protect company mail on personal phones without managing the whole phone
  • Remote wipe of company data on a lost or stolen device

The point of both is the same: access follows the person and the device, not the network they happen to be sitting on. For the full identity engagement, see Entra ID & Intune.

05 · Securing the tenant

The controls that actually stop the attacks we see.

Business email compromise is the most common incident we respond to for small business. It rarely involves malware. Someone gets a password, sets an inbox rule, waits for an invoice, and changes the bank details.

MFA everywhere

With phishing-resistant methods where the role warrants it.

Conditional Access

Rules tuned to your locations and devices.

Email security

In front of the mailbox, to catch phishing and impersonation before delivery.

Inbox rule and forwarding alerts

So a mailbox rule pointing at an external address gets flagged the same day.

Audit logging enabled and retained

Which matters enormously if you ever need to prove what happened.

Tenant backup with tested restores

The copy Microsoft does not keep for you.

Admin tiering

So a compromised user account can't become a compromised tenant.

If you carry cyber insurance, most of this is now on the application form. We can map what you have against what your carrier is asking for. Related: Email Security, Backup & Disaster Recovery, and the AllTech Top 10.

06 · Licensing

Pay for what you use. Use what you pay for.

Microsoft's licensing is genuinely confusing, and most organizations land in one of two ditches: paying Business Premium prices for features nobody turned on, or running Business Basic and wondering why security is thin.

WE DO A LICENSING REVIEW AS PART OF EVERY ENGAGEMENT

Right-size each user to the license they actually need — frontline, Basic, Standard, Premium
Reclaim licenses from departed staff and unused shared mailboxes
Flag the security features you're already paying for and haven't enabled (this is common with Business Premium)
Tell you plainly when a cheaper tier plus a third-party tool beats the upgrade

We're not a licensing reseller with a quota. If the answer is "keep what you have and turn three things on," that's the answer.

07 · Ongoing administration

Someone responsible for it, permanently.

User onboarding and offboarding, usually same-day
License management and monthly true-up
Secure Score monitoring and remediation
Mail flow troubleshooting, quarantine review, spoof and impersonation tuning
Message Center monitoring, so Microsoft's changes don't surprise you
Backup verification and periodic restore tests
Quarterly review of admin roles, guest accounts, and external sharing

This runs as part of Managed IT, or standalone if you already have internal IT and just want the tenant handled.

08 · FAQ

Common questions

Does Microsoft back up my data?

Microsoft guarantees the service, not your content. Retention windows are short and recovery options are limited once they pass. Deleted items, ransomware encryption, and departed-employee data are all your responsibility. We deploy third-party backup for every tenant we manage.

How long does a migration take?

For most businesses under 50 users, two to three weeks from kickoff to cutover, with the disruptive part confined to a single evening or weekend. Larger or messier environments take longer, and we'll tell you that upfront.

Can you take over a tenant another provider set up?

Yes, and we do it often. We start with a tenant assessment, document what is there, and give you a prioritized list of what needs fixing before we assume day-to-day management.

Will my staff lose access to email during the move?

No. Mail is pre-synced ahead of cutover, and the switch happens outside business hours. The visible change on Monday is usually a one-time Outlook sign-in.

Do you support Google Workspace too?

We support and migrate from it. For businesses that want to stay on Google, we'll be straight with you about which of the above we can and can't replicate there.

Do we have to use Intune?

No, but we'll recommend it. Without device management, "MFA is enabled" is a much weaker statement than it sounds.

Start with a tenant assessment.

We'll review your existing Microsoft 365 environment — identity, mail flow, sharing, licensing, and backup — and give you a written summary of what's solid, what's exposed, and what we'd fix first. No obligation to move anything.

Trusted by dozens of businesses