Skip to content
// Industries

Regulated, deadline-bound, and allergic to downtime.

Microsoft 365, configured like someone owns it.

Most tenants are set up once and never revisited. Licences drift, MFA has gaps, external sharing was never reviewed, and half the security you already pay for was never switched on.

You are almost certainly paying for security you have never switched on.

Microsoft ships a great deal of capability inside licences small businesses already hold. The problem is that none of it is on by default, and the defaults that do exist are tuned for frictionless adoption rather than for your risk. A tenant review usually finds four or five controls that cost nothing to enable and materially change your exposure.

01 · What we configure

Six areas, and what each one actually prevents.

This is the working list from a real tenant hardening engagement. Nothing here requires additional licensing beyond what most clients already hold.

Microsoft 365 areas, what is configured, and what it prevents
Area What we configure What it prevents
01Identity What we configureMFA on every account, conditional access by device and location, admin roles time-bound and named What it preventsStolen passwords becoming access; permanent standing admin rights
02Devices What we configureIntune enrolment, compliance policies, disk encryption, remote wipe What it preventsCompany data sitting unencrypted on a laptop left in a taxi
03Email What we configureAnti-phishing and impersonation rules, SPF / DKIM / DMARC, retention policy What it preventsInvoice fraud and spoofed internal senders; silent loss of records
04Files What we configureSharePoint structure, sharing defaults, external access review What it preventsAnonymous links to client files that nobody remembers creating
05Teams What we configureCreation governance, guest rules, lifecycle for dormant teams What it preventsSprawl — data scattered across channels nobody owns
06Licensing What we configureAssignment reviewed against actual usage, quarterly What it preventsPaying for departed staff and for tiers nobody uses

The licensing row usually pays for a meaningful share of the engagement in the first year. It is also the one nobody else volunteers to look at.

02 · Migrations

Done once, properly, on a weekend.

Whether you are coming from an old on-premises server, Google Workspace, or a tenant someone else set up badly, the shape of the work is the same.

See managed IT
Two people at desks in different places, each with the same document open on their laptop, joined by a single line across the middle.
01

Audit before anything moves

Mailbox sizes, shared drives, permissions, the applications that authenticate against your directory, and the printer nobody documented. Surprises found in week one are cheap; surprises found on cutover weekend are not.

02

Pilot with the difficult users

Not the enthusiastic ones — the person with three mailboxes, the one with a bespoke Outlook add-in, and the partner who works entirely offline from a cottage. If it works for them it works for everyone.

03

Cutover out of hours

Data pre-seeded and synced in advance, so the actual switch is short. We are on site or on call for the first working morning, because that is when the real questions arrive.

04

Aftercare for two weeks

A named engineer, elevated attention, and a written list of everything that changed for staff. Migrations fail on the small stuff — a scanner that no longer emails, a shortcut that broke.

03 · How a migration runs

Five stages, no surprises.

Typical timeline for a twenty-to-fifty person business. Larger or more regulated environments stretch the audit and pilot stages, not the cutover.

Week 1

Audit

Inventory of accounts, data, permissions and dependencies. You get the findings whether or not you proceed.

Week 2

Design

Target structure, licence plan, security baseline and rollback position, agreed in writing before anything moves.

Week 3

Pilot

A small group runs live on the new tenant. Every issue found here is one that does not happen at scale.

Weekend

Cutover

Final sync and switch, out of hours. On call from the first Monday morning.

Weeks 4–5

Stabilise

Elevated support, staff guidance, and the handover document that becomes part of your permanent record.

// What you receive

A tenant configuration document, a licence position with renewal dates, the security baseline as applied, and a plain-English summary of what changed for staff. All of it yours, kept current at the quarterly review rather than filed and forgotten.

04 · Tenant review

Configuration drifts. So it gets checked.

Monthly Access hygiene. New starters, leavers, guests, and any account that has quietly acquired admin rights since last month.
Quarterly Licence position. Assignment against real usage, renewal dates, and anything Microsoft has changed in the plans you hold.
Quarterly Security baseline. Conditional access and device compliance checked against the documented intent, not against memory.
Annually Structure review. SharePoint sprawl, dormant Teams, retention against your actual obligations. Housekeeping nobody does voluntarily.

Microsoft changes something material roughly every quarter. Someone has to read those release notes, and it should not be you. Two of the recurring questions are already written up: Business Premium versus Standard, and which workloads are actually worth moving. If the tenant also needs something built on top of it — a booking flow, a client portal, an internal tool — that is web and software.

05 · Questions

The ones people actually ask.

If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.

Usually four things: turn on conditional access, remove permanent admin rights, fix external sharing defaults in SharePoint, and right-size licences. None of it is exotic. It is the work that gets skipped when a tenant is set up by whoever was free that week.

Often the opposite. The first licence review typically finds seats assigned to people who left, Business Premium where Business Basic would do, and duplicate tooling Microsoft already includes. We show you the numbers and you decide.

Cutover happens on a weekend and most staff notice a password prompt on Monday. What makes it disruptive is skipping the pilot — so we always run one, with the people whose setup is most complicated, two weeks ahead.

Yes, and sometimes you should. A line-of-business application with a local database, or a scanner that only speaks to a local share, does not need to move to justify a cloud project. Hybrid done deliberately is fine; hybrid by accident is not.

Rules about who can sign in, from where, on what. A managed laptop in Ottawa signs in normally; an unknown device from another country does not, regardless of whether the password is correct. It is the single highest-value control in the tenant and most small businesses have it switched off.

Yes, through Intune — compliance policies, disk encryption, app deployment and remote wipe for a lost laptop. Windows, macOS, iOS and Android. Mixed fleets are normal.

You do, always. It is registered to your organisation, we work inside it with named accounts, and if you leave we hand back full control and remove our access. We never hold a client tenant under our own agreement.

Boring is the deliverable.

Start with a tenant review. You get a written picture of your current configuration, licence position and the gaps worth closing first.