Microsoft 365 setup, migration and support
Microsoft 365 is where most small businesses now keep their email, files and meetings. Set up carefully it runs for years without attention, and set up in a hurry it loses mail, leaks files and costs more than it should.
What we do
- Migrating mail from POP, IMAP or Google Workspace
- Choosing licences that match how people actually work
- Shared mailboxes, aliases and distribution groups
- Teams, SharePoint and OneDrive with sensible permissions
- Multi-factor sign-in and conditional access rules
- Backing up 365 data and offboarding staff properly
Moving across without losing email
Most migrations we do come from one of three places: mail downloaded by POP into Outlook on one PC, IMAP mailboxes sitting on a web host, or Google Workspace. Each moves differently, and the risk is not the mail itself so much as everything attached to it.
Before anything changes we check who controls the domain and its DNS, list every mailbox, alias, shared mailbox, distribution list and forwarding rule, and find out what is only on somebody's desktop. POP setups are the dangerous ones, because years of mail can exist in a single file on a single machine with no copy anywhere.
Mail is then copied into the new mailboxes while the old system keeps running, so nothing is offline during the copy. Only once the copy matches do we change the MX records, and the old mailboxes stay in place for a while afterwards to catch stragglers. Then we reconnect Outlook, phones and anything that sends mail, like the scanner or the accounting software.
Licences in plain language
The business range sorts roughly into three levels. The cheapest gives you the mailbox and the web and mobile apps. The middle one adds the installed Office programs on the desktop. The top one adds device management and the extra security controls, including the conditional access tools most small businesses only meet when an insurer asks about them.
There are also cheaper licences aimed at staff who only need email and web apps, which suit shift workers, casuals and site staff. Mixing licence types across a business is normal and usually cheaper than putting everyone on the same plan.
Get the count right as well as the type. Businesses routinely pay for licences belonging to people who left, and equally often put a full licence on a mailbox nobody signs into. We go through the list with you once a year and cancel what is not being used.
Shared mailboxes, aliases and groups
An address like accounts@ or info@ should almost never be a user account with a password passed around the office. A shared mailbox does the same job, lets several people work the same inbox under their own sign-ins, and in most cases does not need a licence of its own.
Aliases are for extra addresses that land in an existing mailbox, such as an old name or a second trading name. Distribution groups and shared mailboxes suit different jobs: a group fans a message out to everybody's inbox, a shared mailbox keeps the conversation in one place where replies are visible to the team.
Getting this right early avoids the usual mess of somebody's personal mailbox quietly holding the business's sales history, which becomes a problem the day they resign.
Teams, SharePoint and OneDrive
The three fit together more simply than they look. OneDrive is your own work files. SharePoint is the shared files the team works on. A Teams channel is a conversation with a SharePoint folder behind it, which is why files dropped in a chat end up somewhere people cannot find later.
The decision worth making up front is where shared files live and who can reach them. A structure built around how the business actually works, with access given to groups rather than to individuals one at a time, stays manageable as people come and go.
For anyone used to a mapped drive on a server, syncing the shared library to File Explorer keeps the old habits intact. We set it up with files on demand so a laptop is not trying to hold the entire company on a small drive, and we explain what the sync icons mean, because that is where the confusion starts.
Multi-factor sign-in and conditional access
Multi-factor sign-in is the single most valuable change most small businesses can make to their email, and it needs to be on for everyone, administrators first. An approval in an authenticator app is better than a code by text message, because text messages can be intercepted or redirected.
Conditional access is the next layer, available on the higher licence levels. It sets rules about the circumstances of a sign-in rather than just the password: block sign-ins from countries you never work in, require a managed device for administrative accounts, or force a fresh sign-in on anything unfamiliar.
The related job is closing the old doors. Legacy mail protocols that cannot do multi-factor are still enabled in plenty of older tenants, and they are exactly what password-guessing attacks use. We check what is still on and turn off what nothing needs.
Backup and offboarding staff
Microsoft works on a shared responsibility model, and it is worth reading that phrase carefully. Microsoft is responsible for keeping the service running and the platform secure. Your data inside it remains yours to protect, and the recycle bins and retention windows built into 365 are measured in days and weeks rather than years.
That gap is why a separate backup of 365 exists. It covers the ordinary disasters: a mailbox deleted along with a departed staff member, a SharePoint library wiped by accident or by ransomware syncing from an infected laptop, and the discovery six weeks later that something important is gone. Our backup and disaster recovery page goes into how we set that up.
Offboarding deserves the same care. When someone leaves we block the sign-in and revoke active sessions rather than only changing the password, check for forwarding rules and mailbox delegates they may have set, convert the mailbox to shared so the history stays reachable, move their OneDrive content to a manager, and only then remove the licence.
Typical jobs
A typical job: a business with five mailboxes on a web host, where mail has been downloading into Outlook on one desktop for years. We copy the mail into 365, move the MX records, set up phones and Outlook, and make sure the years of history on that one machine end up in the new mailbox rather than on a drive that fails later.
A typical job: an office where info@ and accounts@ are user accounts with passwords three people share. We convert both to shared mailboxes, give each person their own sign-in with multi-factor, and set replies to come from the shared address so customers see a consistent name.
A typical job: a staff member leaves and takes the only copy of the client folder with them in their OneDrive. We convert the mailbox to shared, transfer the OneDrive contents to their manager, check for forwarding rules left behind, and remove the licence once everything has been recovered.
Questions
Will we lose email during the migration?
Can you move us from Google Workspace?
Does Microsoft back up our data already?
Do we need multi-factor on every account?
Can you support 365 remotely, or do you need to come out?
Microsoft 365: work we have done


Serving Mount Druitt and 12km around
Ready to get it sorted?
Call for a chat about what you need. Onsite and business work is quoted per job or per visit.
