Microsoft 365, configured like someone owns it.
Most tenants are set up once and never revisited. Licences drift, MFA has gaps, external sharing was never reviewed, and half the security you already pay for was never switched on.
You are almost certainly paying for security you have never switched on.
Microsoft ships a great deal of capability inside licences small businesses already hold. The problem is that none of it is on by default, and the defaults that do exist are tuned for frictionless adoption rather than for your risk. A tenant review usually finds four or five controls that cost nothing to enable and materially change your exposure.
Six areas, and what each one actually prevents.
This is the working list from a real tenant hardening engagement. Nothing here requires additional licensing beyond what most clients already hold.
| Area | What we configure | What it prevents |
|---|---|---|
| 01Identity | What we configureMFA on every account, conditional access by device and location, admin roles time-bound and named | What it preventsStolen passwords becoming access; permanent standing admin rights |
| 02Devices | What we configureIntune enrolment, compliance policies, disk encryption, remote wipe | What it preventsCompany data sitting unencrypted on a laptop left in a taxi |
| 03Email | What we configureAnti-phishing and impersonation rules, SPF / DKIM / DMARC, retention policy | What it preventsInvoice fraud and spoofed internal senders; silent loss of records |
| 04Files | What we configureSharePoint structure, sharing defaults, external access review | What it preventsAnonymous links to client files that nobody remembers creating |
| 05Teams | What we configureCreation governance, guest rules, lifecycle for dormant teams | What it preventsSprawl — data scattered across channels nobody owns |
| 06Licensing | What we configureAssignment reviewed against actual usage, quarterly | What it preventsPaying for departed staff and for tiers nobody uses |
The licensing row usually pays for a meaningful share of the engagement in the first year. It is also the one nobody else volunteers to look at.
Done once, properly, on a weekend.
Whether you are coming from an old on-premises server, Google Workspace, or a tenant someone else set up badly, the shape of the work is the same.
See managed IT
Audit before anything moves
Mailbox sizes, shared drives, permissions, the applications that authenticate against your directory, and the printer nobody documented. Surprises found in week one are cheap; surprises found on cutover weekend are not.
Pilot with the difficult users
Not the enthusiastic ones — the person with three mailboxes, the one with a bespoke Outlook add-in, and the partner who works entirely offline from a cottage. If it works for them it works for everyone.
Cutover out of hours
Data pre-seeded and synced in advance, so the actual switch is short. We are on site or on call for the first working morning, because that is when the real questions arrive.
Aftercare for two weeks
A named engineer, elevated attention, and a written list of everything that changed for staff. Migrations fail on the small stuff — a scanner that no longer emails, a shortcut that broke.
Five stages, no surprises.
Typical timeline for a twenty-to-fifty person business. Larger or more regulated environments stretch the audit and pilot stages, not the cutover.
Audit
Inventory of accounts, data, permissions and dependencies. You get the findings whether or not you proceed.
Design
Target structure, licence plan, security baseline and rollback position, agreed in writing before anything moves.
Pilot
A small group runs live on the new tenant. Every issue found here is one that does not happen at scale.
Cutover
Final sync and switch, out of hours. On call from the first Monday morning.
Stabilise
Elevated support, staff guidance, and the handover document that becomes part of your permanent record.
A tenant configuration document, a licence position with renewal dates, the security baseline as applied, and a plain-English summary of what changed for staff. All of it yours, kept current at the quarterly review rather than filed and forgotten.
Configuration drifts. So it gets checked.
Microsoft changes something material roughly every quarter. Someone has to read those release notes, and it should not be you. Two of the recurring questions are already written up: Business Premium versus Standard, and which workloads are actually worth moving. If the tenant also needs something built on top of it — a booking flow, a client portal, an internal tool — that is web and software.
The ones people actually ask.
If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.
Usually four things: turn on conditional access, remove permanent admin rights, fix external sharing defaults in SharePoint, and right-size licences. None of it is exotic. It is the work that gets skipped when a tenant is set up by whoever was free that week.
Often the opposite. The first licence review typically finds seats assigned to people who left, Business Premium where Business Basic would do, and duplicate tooling Microsoft already includes. We show you the numbers and you decide.
Cutover happens on a weekend and most staff notice a password prompt on Monday. What makes it disruptive is skipping the pilot — so we always run one, with the people whose setup is most complicated, two weeks ahead.
Yes, and sometimes you should. A line-of-business application with a local database, or a scanner that only speaks to a local share, does not need to move to justify a cloud project. Hybrid done deliberately is fine; hybrid by accident is not.
Rules about who can sign in, from where, on what. A managed laptop in Ottawa signs in normally; an unknown device from another country does not, regardless of whether the password is correct. It is the single highest-value control in the tenant and most small businesses have it switched off.
Yes, through Intune — compliance policies, disk encryption, app deployment and remote wipe for a lost laptop. Windows, macOS, iOS and Android. Mixed fleets are normal.
You do, always. It is registered to your organisation, we work inside it with named accounts, and if you leave we hand back full control and remove our access. We never hold a client tenant under our own agreement.
Next
Boring is the deliverable.
Start with a tenant review. You get a written picture of your current configuration, licence position and the gaps worth closing first.