MICROSOFT 365 · MANAGED RIGHT
Microsoft 365 Management for Small Businesses
Licenses trimmed to what you use, MFA on every account, mail that reaches inboxes, and SharePoint organized — your whole tenant, run properly for a flat rate.
Microsoft 365 management means your tenant gets run like it matters: licenses right-sized so you stop paying for seats and add-ons nobody uses, MFA and conditional access enforced on every account, mail flow tuned so invoices reach customers, and SharePoint structured so files are findable instead of scattered across personal OneDrives.
It’s for businesses with 1–50 employees whose 365 setup grew by accident — a license here, a site there, admin rights everywhere. Flat rate per user, no contract, and the license savings alone frequently cover most of our fee.
What we manage
License Right-Sizing
We audit every seat and add-on, downgrade what’s oversized, and cancel what’s abandoned. Most tenants we take over are quietly overpaying Microsoft.
MFA & Conditional Access
Multi-factor authentication enforced everywhere, with conditional access rules that block logins from places your business has never operated.
Mail Flow & Deliverability
SPF, DKIM, and DMARC set correctly, spam filtering tuned, and transport rules cleaned up — so your email arrives and impostors’ email doesn’t.
SharePoint & OneDrive Order
A sensible site and folder structure with group-based permissions — so company files stop living in seventeen personal OneDrives nobody can access.
Business Basic, Standard or Premium — which tier your team actually needs
Microsoft 365 Business plans are capped at 300 seats, which means they were designed for exactly the size of company reading this. The three tiers differ in two dimensions: whether you get installable desktop applications, and how much security tooling comes with the licence. Everything else — Exchange Online mailboxes, SharePoint Online, OneDrive for Business, Teams, and Entra ID (the identity service formerly called Azure AD) — is present across all of them.
| Business Basic | Business Standard | Business Premium | |
|---|---|---|---|
| Rough price band | ~$6–$8 /user/mo | ~$12–$15 /user/mo | ~$22–$26 /user/mo |
| Desktop Office apps | No — web and mobile only | Yes — on 5 PCs/Macs, 5 tablets, 5 phones per user | Yes, same as Standard |
| Mailbox size | 50 GB | 50 GB | 50 GB |
| OneDrive storage | 1 TB per user | 1 TB per user | 1 TB per user |
| Teams, SharePoint, Exchange Online | Yes | Yes | Yes |
| Conditional access | No — security defaults only | No — security defaults only | Yes — includes Entra ID P1 |
| Email threat protection | Baseline anti-spam and anti-malware | Baseline anti-spam and anti-malware | Defender for Office 365 P1 — Safe Links, Safe Attachments, anti-phishing policies |
| Device and endpoint management | No | No | Intune plus Defender for Business (EDR) |
| Data protection | — | — | Information protection, DLP policies, remote wipe of company data from a lost phone |
| Best fit | Frontline and shift staff who mainly need email and Teams | Most office roles doing heavy Excel, Outlook and document work | Regulated work, client data, or any account whose compromise would be serious |
Two practical points. First, licences can be mixed inside one tenant — there is no rule that everyone must have the same SKU. A dental practice might put the practice manager and the two clinicians on Premium and the front-desk team on Basic. Second, Premium looks expensive next to Standard until you price the alternative: a separate EDR product, a separate MDM platform and a separate email security gateway typically cost more than the difference, and they will not talk to each other. For a 15-person firm holding client financial or health data, Premium is usually the cheaper security posture, not the more expensive one.
Annual commitment pricing is roughly 15–20% below monthly, but locks the seat count for twelve months. If your headcount moves, monthly billing is worth the premium.
The tenant settings small businesses get wrong
Microsoft 365 is easy to buy and easy to leave misconfigured. The same handful of gaps turn up in almost every tenant that has never been properly reviewed.
MFA is available but not actually enforced
Multi-factor authentication being “switched on” and being enforced are different states. Security defaults enable a reasonable baseline for new tenants, but older tenants often have them disabled, or an administrator granted per-user exclusions during a busy week and never removed them. Check the sign-in logs: if anyone is authenticating with a password alone, the control does not exist for that account. Legacy authentication protocols — POP, IMAP, SMTP basic auth — are the classic bypass, since they cannot present an MFA challenge at all.
No conditional access, and no break-glass account
On Premium licensing, conditional access lets you block sign-ins from countries you never operate in, require a compliant device for access to SharePoint, and stop prompting people repeatedly on trusted machines — which is the single best way to make MFA tolerable. Two things go wrong here: the policies never get written, or they get written so tightly that an administrator locks themselves out. Always keep one excluded emergency account with a long unique password stored offline.
Ex-employees still holding licences and sessions
Reviewing a 20-person tenant commonly turns up 3–6 active licensed accounts for people who left months ago. That is $500–$2,000 a year of pure waste, and worse, every one of those accounts is a live credential nobody is watching.
Paying full price for what should be a shared mailbox
Addresses like info@, accounts@, bookings@ and support@ do not need a licensed user. A shared mailbox in Exchange Online is free, holds up to 50 GB, and can be opened by any number of licensed staff alongside their own inbox. Likewise, a distribution list costs nothing and simply forwards to a group. Companies routinely pay for four or five licensed mailboxes that exist only to receive mail — convert them and the saving is immediate and permanent.
SPF, DKIM and DMARC never configured
These three DNS records decide whether your mail is trusted. SPF lists which servers may send as your domain. DKIM cryptographically signs outbound mail so tampering is detectable. DMARC tells receiving servers what to do when a message fails those checks, and sends you reports on who is sending as you.
Skip them and two things follow. Your legitimate quotes and invoices land in customers’ spam folders, and anyone can spoof your domain to defraud your clients. Google and Yahoo now enforce authentication requirements on bulk senders, so this stopped being optional. The correct implementation is SPF with a hard fail, DKIM signing enabled in the Microsoft 365 admin center for your custom domain, and DMARC started at p=none to gather reports, then moved to quarantine and finally reject once you have confirmed every legitimate sender — your mailing platform, your accounting software, your booking system — is passing.
Mail flow rules and auditing left at defaults
Useful rules most small tenants lack: an external-sender warning banner, blocking auto-forwarding to outside domains (the standard business email compromise move), and quarantining executable attachments. Also confirm the unified audit log is enabled — without it, an investigation after an incident has nothing to read.
Onboarding and offboarding done properly
Both of these should be a checklist, not a memory exercise. The offboarding one matters more, because the cost of getting it wrong compounds quietly.
New starter, before day one
- Create the account in Entra ID with the correct licence SKU, usage location and job title.
- Add to the security and distribution groups that grant SharePoint and Teams access — group-based permissions, never one-off file shares.
- Register MFA on first sign-in, ideally with the Authenticator app rather than SMS.
- Enrol the device in Intune where Premium is in use, apply the compliance policy, confirm disk encryption.
- Configure OneDrive Known Folder Move so Desktop and Documents sync — this is what makes a lost laptop a non-event.
- Assign any shared mailbox access, set the email signature, and add the address to the right aliases.
The day someone leaves — in this order
- Block sign-in and revoke active sessions. Resetting the password alone is not enough; existing refresh tokens keep working, sometimes for hours. Revoke them explicitly.
- Check for mail forwarding rules and inbox rules. A departing employee quietly forwarding client correspondence to a personal address is common enough that this step is non-negotiable. It is also where a compromised account hides.
- Place the mailbox on litigation hold if there is any chance of a dispute — do this before touching the licence, because hold requires the appropriate plan.
- Transfer OneDrive content to a manager or a SharePoint library. Setting a delegate before removing the licence gives you a 30-day window; miss it and the files are gone.
- Convert the mailbox to a shared mailbox. Colleagues keep access to the history, incoming mail still arrives, and it costs nothing.
- Reclaim the licence and either reassign it or reduce the subscription count so billing actually drops.
- Remove from all groups and Teams, wipe company data from personal phones, and rotate any shared credentials the person knew — the Wi-Fi PSK, the bank portal, the domain registrar.
- Set an auto-reply or forward so customers writing to that address reach a human rather than silence.
Done in the right sequence this takes about fifteen minutes. Done in the wrong sequence — licence removed first — you lose the mailbox and the OneDrive after 30 days and there is no undo.
Frequently asked questions
Should we move from Business Standard to Premium?
If you handle client financial records, health information, legal matters, or you have staff working from personal devices, yes — conditional access, Intune and Defender for Business close gaps you would otherwise buy separately at higher cost. If your team is five people doing general office work on company-owned machines already covered by a managed EDR product, Standard plus that product is a reasonable stopping point.
How long does a mailbox migration take?
For a 10–20 person business moving from Google Workspace, an older Exchange server, or a hosted IMAP provider, expect a week of preparation and a weekend cutover. Mail is pre-synced in advance, so the actual switch is a DNS MX record change plus reconfiguring Outlook profiles. The variables are mailbox size, the volume of shared calendars, and how many public folders or archives are involved.
Our email keeps going to customers’ spam folders. What is wrong?
Almost always authentication. Check that SPF exists once and only once, that DKIM is signing for your custom domain rather than the default onmicrosoft.com one, and that a DMARC record is published. Also check whether your domain or sending IP appears on a blocklist, which happens after a compromised account has been used to send spam.
Do we need a third-party backup if everything is in Microsoft 365?
Yes. Microsoft guarantees the service, not your content — that is the shared responsibility model. Deleted items are recoverable for roughly 14–30 days in Exchange and 93 days in SharePoint and OneDrive, after which they are unrecoverable. A folder deleted in March and noticed in July is gone. Third-party 365 backup costs a few dollars per user per month and covers that gap.
Talk to a real technician today
Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.
