Taking on new work
Remote UK-wide · On-site North West
— / Microsoft 365 setup

Microsoft 365, set up the way it should be.

Most tenants I get called into were set up by whoever happened to be nearest a computer that week. Email works, so nobody looks again — until a mailbox gets taken over, or someone leaves and the files go with them.

Timescale
Days, not weeks

A straightforward tenant is usually done inside a week, with the mail cutover out of hours.

Disruption
One evening, at most

Staff finish on the old setup and start on the new one. No week of everyone half-working.

You get
Written handover

Every setting, every admin account, every DNS record — written down and handed to you.

01 / What's involved

The order it has to happen in, and why.

Microsoft 365 is not one product, it is about a dozen wearing a trench coat. A setup that skips the identity and device work gets you a working inbox and nothing else — which is exactly what most small businesses end up with, and exactly why the first bad email costs them a fortnight.

Here is what I actually do, roughly in the order I do it.

  • 01Domain and DNS. MX records for mail delivery, then SPF, DKIM and DMARC for authentication. Without those last three your mail lands in other people's junk folders and anyone in the world can send email that appears to come from you. This is the single most commonly skipped step and it is free.
  • 02Licensing, honestly. I will tell you which tier you actually need rather than the biggest one. The thing worth knowing: the security features people assume are in Microsoft 365 — conditional access, device management, the good anti-phishing — largely are not, unless you are on Business Premium. If security matters to you, that is the tier where it exists.
  • 03Identity. Multi-factor authentication on every account including yours, conditional access policies so sign-ins from odd places get challenged, and a break-glass admin account kept out of the day-to-day. No shared logins, ever — when three people use one account, nobody is accountable and nothing can be traced.
  • 04Devices. Laptops and phones enrolled in Intune, disk encryption on, screen lock enforced, and the ability to wipe a device that goes missing. A stolen laptop should be an inconvenience, not an incident.
  • 05Files. A SharePoint structure that matches how you actually work, OneDrive set to back up Desktop and Documents automatically, external sharing set to something sensible rather than the wide-open default, and a retention policy so deleted things stay recoverable.
  • 06Leavers. A written process for what happens when someone goes: licence reclaimed, mailbox converted to shared, files reassigned, sessions revoked. Most businesses have never thought about this until the first person leaves badly.
02 / What you end up with

A tenant you could hand to anyone.

The point of doing it properly is that the next person who touches it — me, an employee, a different consultant in five years — can understand it in an afternoon. That means writing it down.

  • —Mail flowing on your own domain, authenticated, and passing SPF, DKIM and DMARC checks.
  • —Every account behind MFA, with a documented recovery path if someone loses their phone.
  • —A named, short list of who has admin rights — and a reason next to each name.
  • —Company files in SharePoint with permissions that reflect your actual org chart.
  • —A handover document covering every setting I changed, so you are not dependent on me.
03 / Questions I get asked

The things people ask before they commit.

Can you do this without downtime?
Effectively, yes. The DNS time-to-live gets dropped a day ahead so changes propagate in minutes rather than hours, and the mail cutover happens out of hours. In practice people finish on Friday and start on Monday without noticing much beyond re-entering a password.
Do I really need Business Premium?
Not always. If you are three people who need email and file storage and nothing else, a cheaper tier is fine and I will say so. But if you handle client data, have staff on their own laptops, or anyone has ever asked you to fill in a security questionnaire, Premium is the tier where the tools to answer that questionnaire actually exist.
We already have Microsoft 365 and it's a mess.
That is most of the work I do. I review what is there, write down what is wrong and what it would take to fix, and we sort it in order of what will actually hurt you first. Nothing gets ripped out on day one.
Do you need to come to our office?
Almost never. This is all done remotely. On-site is for the physical jobs — a network cabinet, cabling, a machine that will not start — and for those I cover the North West.
What happens if we stop using you?
You keep everything. The tenant is yours, the domain is in your name, the admin accounts are yours, and the handover document tells the next person what I did. There is no lock-in and nothing you have to ask my permission for.
04 / Where I work

Remote first. On site when it needs hands.

Almost all of this is done remotely, so where you are rarely matters. When something genuinely needs someone in the room — a cabinet, a cable, a machine that will not boot — these are the places I cover in person.

WiganSt HelensWarringtonBoltonManchesterSalfordLiverpoolWirralChorleyPrestonCheshireLancashireMerseysideRemote — UK-wide

Tell me what's going wrong.

A couple of lines is plenty — you don't need the right technical words for it. I'll come back within one working day with a sensible first step, and I'll tell you if you don't actually need me.