MICROSOFT 365 · MANAGED RIGHT

Microsoft 365 Management for Small Businesses

Licenses trimmed to what you use, MFA on every account, mail that reaches inboxes, and SharePoint organized — your whole tenant, run properly for a flat rate.

Get a Free Assessment See pricing →

Microsoft 365 management means your tenant gets run like it matters: licenses right-sized so you stop paying for seats and add-ons nobody uses, MFA and conditional access enforced on every account, mail flow tuned so invoices reach customers, and SharePoint structured so files are findable instead of scattered across personal OneDrives.

It’s for businesses with 1–50 employees whose 365 setup grew by accident — a license here, a site there, admin rights everywhere. Flat rate per user, no contract, and the license savings alone frequently cover most of our fee.

What we manage

🧹

License Right-Sizing

We audit every seat and add-on, downgrade what’s oversized, and cancel what’s abandoned. Most tenants we take over are quietly overpaying Microsoft.

🔑

MFA & Conditional Access

Multi-factor authentication enforced everywhere, with conditional access rules that block logins from places your business has never operated.

📨

Mail Flow & Deliverability

SPF, DKIM, and DMARC set correctly, spam filtering tuned, and transport rules cleaned up — so your email arrives and impostors’ email doesn’t.

📂

SharePoint & OneDrive Order

A sensible site and folder structure with group-based permissions — so company files stop living in seventeen personal OneDrives nobody can access.

Business Basic, Standard or Premium — which tier your team actually needs

Microsoft 365 Business plans are capped at 300 seats, which means they were designed for exactly the size of company reading this. The three tiers differ in two dimensions: whether you get installable desktop applications, and how much security tooling comes with the licence. Everything else — Exchange Online mailboxes, SharePoint Online, OneDrive for Business, Teams, and Entra ID (the identity service formerly called Azure AD) — is present across all of them.

 Business BasicBusiness StandardBusiness Premium
Rough price band~$6–$8 /user/mo~$12–$15 /user/mo~$22–$26 /user/mo
Desktop Office appsNo — web and mobile onlyYes — on 5 PCs/Macs, 5 tablets, 5 phones per userYes, same as Standard
Mailbox size50 GB50 GB50 GB
OneDrive storage1 TB per user1 TB per user1 TB per user
Teams, SharePoint, Exchange OnlineYesYesYes
Conditional accessNo — security defaults onlyNo — security defaults onlyYes — includes Entra ID P1
Email threat protectionBaseline anti-spam and anti-malwareBaseline anti-spam and anti-malwareDefender for Office 365 P1 — Safe Links, Safe Attachments, anti-phishing policies
Device and endpoint managementNoNoIntune plus Defender for Business (EDR)
Data protectionInformation protection, DLP policies, remote wipe of company data from a lost phone
Best fitFrontline and shift staff who mainly need email and TeamsMost office roles doing heavy Excel, Outlook and document workRegulated work, client data, or any account whose compromise would be serious

Two practical points. First, licences can be mixed inside one tenant — there is no rule that everyone must have the same SKU. A dental practice might put the practice manager and the two clinicians on Premium and the front-desk team on Basic. Second, Premium looks expensive next to Standard until you price the alternative: a separate EDR product, a separate MDM platform and a separate email security gateway typically cost more than the difference, and they will not talk to each other. For a 15-person firm holding client financial or health data, Premium is usually the cheaper security posture, not the more expensive one.

Annual commitment pricing is roughly 15–20% below monthly, but locks the seat count for twelve months. If your headcount moves, monthly billing is worth the premium.

The tenant settings small businesses get wrong

Microsoft 365 is easy to buy and easy to leave misconfigured. The same handful of gaps turn up in almost every tenant that has never been properly reviewed.

MFA is available but not actually enforced

Multi-factor authentication being “switched on” and being enforced are different states. Security defaults enable a reasonable baseline for new tenants, but older tenants often have them disabled, or an administrator granted per-user exclusions during a busy week and never removed them. Check the sign-in logs: if anyone is authenticating with a password alone, the control does not exist for that account. Legacy authentication protocols — POP, IMAP, SMTP basic auth — are the classic bypass, since they cannot present an MFA challenge at all.

No conditional access, and no break-glass account

On Premium licensing, conditional access lets you block sign-ins from countries you never operate in, require a compliant device for access to SharePoint, and stop prompting people repeatedly on trusted machines — which is the single best way to make MFA tolerable. Two things go wrong here: the policies never get written, or they get written so tightly that an administrator locks themselves out. Always keep one excluded emergency account with a long unique password stored offline.

Ex-employees still holding licences and sessions

Reviewing a 20-person tenant commonly turns up 3–6 active licensed accounts for people who left months ago. That is $500–$2,000 a year of pure waste, and worse, every one of those accounts is a live credential nobody is watching.

Paying full price for what should be a shared mailbox

Addresses like info@, accounts@, bookings@ and support@ do not need a licensed user. A shared mailbox in Exchange Online is free, holds up to 50 GB, and can be opened by any number of licensed staff alongside their own inbox. Likewise, a distribution list costs nothing and simply forwards to a group. Companies routinely pay for four or five licensed mailboxes that exist only to receive mail — convert them and the saving is immediate and permanent.

SPF, DKIM and DMARC never configured

These three DNS records decide whether your mail is trusted. SPF lists which servers may send as your domain. DKIM cryptographically signs outbound mail so tampering is detectable. DMARC tells receiving servers what to do when a message fails those checks, and sends you reports on who is sending as you.

Skip them and two things follow. Your legitimate quotes and invoices land in customers’ spam folders, and anyone can spoof your domain to defraud your clients. Google and Yahoo now enforce authentication requirements on bulk senders, so this stopped being optional. The correct implementation is SPF with a hard fail, DKIM signing enabled in the Microsoft 365 admin center for your custom domain, and DMARC started at p=none to gather reports, then moved to quarantine and finally reject once you have confirmed every legitimate sender — your mailing platform, your accounting software, your booking system — is passing.

Mail flow rules and auditing left at defaults

Useful rules most small tenants lack: an external-sender warning banner, blocking auto-forwarding to outside domains (the standard business email compromise move), and quarantining executable attachments. Also confirm the unified audit log is enabled — without it, an investigation after an incident has nothing to read.

Onboarding and offboarding done properly

Both of these should be a checklist, not a memory exercise. The offboarding one matters more, because the cost of getting it wrong compounds quietly.

New starter, before day one

  • Create the account in Entra ID with the correct licence SKU, usage location and job title.
  • Add to the security and distribution groups that grant SharePoint and Teams access — group-based permissions, never one-off file shares.
  • Register MFA on first sign-in, ideally with the Authenticator app rather than SMS.
  • Enrol the device in Intune where Premium is in use, apply the compliance policy, confirm disk encryption.
  • Configure OneDrive Known Folder Move so Desktop and Documents sync — this is what makes a lost laptop a non-event.
  • Assign any shared mailbox access, set the email signature, and add the address to the right aliases.

The day someone leaves — in this order

  • Block sign-in and revoke active sessions. Resetting the password alone is not enough; existing refresh tokens keep working, sometimes for hours. Revoke them explicitly.
  • Check for mail forwarding rules and inbox rules. A departing employee quietly forwarding client correspondence to a personal address is common enough that this step is non-negotiable. It is also where a compromised account hides.
  • Place the mailbox on litigation hold if there is any chance of a dispute — do this before touching the licence, because hold requires the appropriate plan.
  • Transfer OneDrive content to a manager or a SharePoint library. Setting a delegate before removing the licence gives you a 30-day window; miss it and the files are gone.
  • Convert the mailbox to a shared mailbox. Colleagues keep access to the history, incoming mail still arrives, and it costs nothing.
  • Reclaim the licence and either reassign it or reduce the subscription count so billing actually drops.
  • Remove from all groups and Teams, wipe company data from personal phones, and rotate any shared credentials the person knew — the Wi-Fi PSK, the bank portal, the domain registrar.
  • Set an auto-reply or forward so customers writing to that address reach a human rather than silence.

Done in the right sequence this takes about fifteen minutes. Done in the wrong sequence — licence removed first — you lose the mailbox and the OneDrive after 30 days and there is no undo.

Frequently asked questions

Should we move from Business Standard to Premium?

If you handle client financial records, health information, legal matters, or you have staff working from personal devices, yes — conditional access, Intune and Defender for Business close gaps you would otherwise buy separately at higher cost. If your team is five people doing general office work on company-owned machines already covered by a managed EDR product, Standard plus that product is a reasonable stopping point.

How long does a mailbox migration take?

For a 10–20 person business moving from Google Workspace, an older Exchange server, or a hosted IMAP provider, expect a week of preparation and a weekend cutover. Mail is pre-synced in advance, so the actual switch is a DNS MX record change plus reconfiguring Outlook profiles. The variables are mailbox size, the volume of shared calendars, and how many public folders or archives are involved.

Our email keeps going to customers’ spam folders. What is wrong?

Almost always authentication. Check that SPF exists once and only once, that DKIM is signing for your custom domain rather than the default onmicrosoft.com one, and that a DMARC record is published. Also check whether your domain or sending IP appears on a blocklist, which happens after a compromised account has been used to send spam.

Do we need a third-party backup if everything is in Microsoft 365?

Yes. Microsoft guarantees the service, not your content — that is the shared responsibility model. Deleted items are recoverable for roughly 14–30 days in Exchange and 93 days in SharePoint and OneDrive, after which they are unrecoverable. A folder deleted in March and noticed in July is gone. Third-party 365 backup costs a few dollars per user per month and covers that gap.

Talk to a real technician today

Free IT assessment for US small businesses. Flat monthly rate, no contracts, same-day remote response.

Get a Free Assessment +1 (202) 960-2022