Tenant rollout
Domains, accounts, groups and baseline policies set up so that they can still be maintained a year later.
MICROSOFT 365 AND EXCHANGE
Deployment, migration and daily administration of Microsoft 365 and company mail. I can build the environment from scratch or take over what you already have.
Ask about Microsoft 365Good configuration balances user convenience, cost control and access security.
Domains, accounts, groups and baseline policies set up so that they can still be maintained a year later.
Mailboxes, aliases, distribution groups, transport rules and SPF, DKIM and DMARC records.
Moving from legacy mail with a plan that limits downtime and preserves message history.
Licences matched to roles, an account lifecycle from hire to leaver, and control over subscription cost.
MFA, access rules and a review of risky sign-ins — the cheapest change with the largest impact.
Outlook, Teams and daily work with Microsoft services, explained without jargon.
Getting mail to work is not the point — anyone can do that. The point is that a year from now the configuration still makes sense, and adding an employee does not require guessing what they are entitled to.
Microsoft 365 starts up in an hour, which is both its strength and its problem. The initial configuration works, so nobody revisits it — until it starts getting in the way.
New hires get their permissions by cloning a colleague’s account.
There are no roles or groups, so copying an existing account is the fastest route.
I introduce role-based groups and licence assignment through those groups. Cloning an account also copies permissions nobody remembers granting.
The company domain is used to phish its own employees.
DMARC is missing, or the policy has sat at p=none since rollout and was never tightened.
I set up SPF, DKIM and DMARC, start in reporting mode and only move to reject after reviewing the reports. Doing it the other way round can cut off the company’s mail.
The company pays for licences on accounts nobody uses.
Offboarding stops at blocking sign-in — the licence stays assigned.
I review assignments and agree a leaver procedure: convert the mailbox, release the licence, hand the data to the manager.
MFA is “switched on”, but some accounts do not have it.
It was enabled account by account, and newer accounts were never covered.
I replace per-account settings with conditional access policies, so new accounts are covered automatically rather than by somebody remembering.
After a migration, old messages, calendars or shared mailbox access are missing.
Primary mailboxes were moved while archives, delegations and inbox rules were not.
Before migrating I inventory what is genuinely in use — including delegated permissions and rules that users forget they created.
Four stages, after which mail should simply work.
Accounts, domains, licences and current mail. We agree what moves and what should be closed.
A migration, security and communication plan with a switchover date.
Data and services move according to plan, in a window agreed with the company.
User support in the first days and continued administration afterwards.
The questions that come up most often about this service.
Usually it does not have to. I copy the data before we switch DNS, so by the time of the switch most mail is already in place. The real risk is a few hours when messages may arrive in two places — which is why I schedule the switch outside working hours and warn staff in advance.
Not always, though in small companies it usually should. Running your own mail server means updates, certificates, IP reputation and backups — a cost that rarely pays off at a dozen mailboxes. If you have a reason to stay, I will tell you what needs fixing on it instead.
No. Plans differ mainly in security and compliance features, some of which will never be used. A more common answer is different plans for different roles — one for management, another for a shop-floor workstation. I match them after establishing who actually uses what.
Your company. I create it under the company’s details and hand over the global administrator account. I work from an account with the permissions I need, which you can revoke at any time. A tenant registered to the contractor is a problem that only surfaces when you part ways.
Yes, if it is handled in time. A mailbox can be converted to shared and kept without a licence, and files moved to the manager. Once the account is deleted the window is limited, which is why the leaver procedure matters more than it appears.
No specification required. A few sentences about your company and what currently does not work is enough to start.
Go to contact