Skip to content

MICROSOFT 365 AND EXCHANGE

Mail that simply gets out of the way.

Deployment, migration and daily administration of Microsoft 365 and company mail. I can build the environment from scratch or take over what you already have.

Ask about Microsoft 365
Scope
M365, Exchange, mail server
Model
rollout or takeover
Migrations
history preserved
WHAT IT COVERS

A tenant
that stays tidy.

Good configuration balances user convenience, cost control and access security.

Tenant rollout

Domains, accounts, groups and baseline policies set up so that they can still be maintained a year later.

Exchange and mail flow

Mailboxes, aliases, distribution groups, transport rules and SPF, DKIM and DMARC records.

Migrations

Moving from legacy mail with a plan that limits downtime and preserves message history.

Accounts and licences

Licences matched to roles, an account lifecycle from hire to leaver, and control over subscription cost.

Secure sign-in

MFA, access rules and a review of risky sign-ins — the cheapest change with the largest impact.

User support

Outlook, Teams and daily work with Microsoft services, explained without jargon.

WHAT YOU GET

A tenant
that stays maintainable.

Getting mail to work is not the point — anyone can do that. The point is that a year from now the configuration still makes sense, and adding an employee does not require guessing what they are entitled to.

  • Domains with correct SPF, DKIM and DMARC records
  • Multi-factor authentication enforced through conditional access policies
  • Role-based groups instead of copying permissions from another account
  • Licences assigned through groups, not by hand at every hire
  • Mail flow and anti-spoofing rules for your domain
  • A written joiner and leaver procedure
  • A review of unused licences and risky sign-ins
  • Tenant configuration documented on the client side
WHAT I USUALLY FIND

Five things
visible in almost every tenant.

Microsoft 365 starts up in an hour, which is both its strength and its problem. The initial configuration works, so nobody revisits it — until it starts getting in the way.

01

Symptom

New hires get their permissions by cloning a colleague’s account.

Cause

There are no roles or groups, so copying an existing account is the fastest route.

What I do

I introduce role-based groups and licence assignment through those groups. Cloning an account also copies permissions nobody remembers granting.

02

Symptom

The company domain is used to phish its own employees.

Cause

DMARC is missing, or the policy has sat at p=none since rollout and was never tightened.

What I do

I set up SPF, DKIM and DMARC, start in reporting mode and only move to reject after reviewing the reports. Doing it the other way round can cut off the company’s mail.

03

Symptom

The company pays for licences on accounts nobody uses.

Cause

Offboarding stops at blocking sign-in — the licence stays assigned.

What I do

I review assignments and agree a leaver procedure: convert the mailbox, release the licence, hand the data to the manager.

04

Symptom

MFA is “switched on”, but some accounts do not have it.

Cause

It was enabled account by account, and newer accounts were never covered.

What I do

I replace per-account settings with conditional access policies, so new accounts are covered automatically rather than by somebody remembering.

05

Symptom

After a migration, old messages, calendars or shared mailbox access are missing.

Cause

Primary mailboxes were moved while archives, delegations and inbox rules were not.

What I do

Before migrating I inventory what is genuinely in use — including delegated permissions and rules that users forget they created.

MIGRATION

A good rollout
is invisible.

Four stages, after which mail should simply work.

01

Audit

Accounts, domains, licences and current mail. We agree what moves and what should be closed.

02

Preparation

A migration, security and communication plan with a switchover date.

03

Transfer

Data and services move according to plan, in a window agreed with the company.

04

Care

User support in the first days and continued administration afterwards.

QUESTIONS ABOUT MICROSOFT 365

Worth settling
before the migration.

The questions that come up most often about this service.

Does a mail migration mean downtime?

Usually it does not have to. I copy the data before we switch DNS, so by the time of the switch most mail is already in place. The real risk is a few hours when messages may arrive in two places — which is why I schedule the switch outside working hours and warn staff in advance.

We run Exchange on our own server. Does it have to go?

Not always, though in small companies it usually should. Running your own mail server means updates, certificates, IP reputation and backups — a cost that rarely pays off at a dozen mailboxes. If you have a reason to stay, I will tell you what needs fixing on it instead.

Do I need the most expensive plan?

No. Plans differ mainly in security and compliance features, some of which will never be used. A more common answer is different plans for different roles — one for management, another for a shop-floor workstation. I match them after establishing who actually uses what.

Who owns the tenant?

Your company. I create it under the company’s details and hand over the global administrator account. I work from an account with the permissions I need, which you can revoke at any time. A tenant registered to the contractor is a problem that only surfaces when you part ways.

Can data be recovered after somebody leaves?

Yes, if it is handled in time. A mailbox can be converted to shared and kept without a licence, and files moved to the manager. Once the account is deleted the window is limited, which is why the leaver procedure matters more than it appears.

NEXT STEP

Describe the problem.
You get a straight answer.

No specification required. A few sentences about your company and what currently does not work is enough to start.

Go to contact