Microsoft 365
Get the full value of Microsoft 365, deployed, governed and supported around how your teams actually work.
Productivity, done properly
In short: Your tenant deployed, governed and supported around how people work, rather than a fraction of it in use and the rest switched off. If nobody has reviewed sharing, guests or site ownership in a couple of years, start with a posture assessment rather than a project.
Almost every business already pays for Microsoft 365. Far fewer actually use what they're paying for, most run a fraction of the platform while the security, governance and productivity gains sit switched off.
The problem
An unmanaged Microsoft 365 tenant drifts: sprawling SharePoint sites, oversharing nobody's audited, licences assigned and forgotten, and no clear owner for any of it. It works, until a security review, a leaver, or a Copilot rollout exposes exactly how loose it has become.
What we would do
If your tenant has been running for more than a couple of years and nobody has reviewed sharing, guests or site ownership in that time, start with a posture assessment rather than a project. The remediation list it produces is almost always shorter and cheaper than the project people expect.
- If you are about to turn on Copilot, do the permissions and oversharing work first. Copilot inherits your permissions exactly, and the day it goes on is the day historic oversharing becomes visible.
- If you are migrating in from another platform, the governance decisions belong in the migration design rather than after it.
When we are not the answer: If you want Microsoft 365 administered exactly as it is with no questions asked about how it is set up, we will be an irritating supplier. We tend to find things, and saying so is the job.
Microsoft 365 is far more than email. We help you deploy, secure and get real value from the whole platform, from Teams and SharePoint to identity and device management.
More on how we deliver Microsoft 365
Migrations handled cleanly, governance set up correctly, and ongoing support so your people always have the tools they need to do their best work.
Everything you need, managed for you
Cutover or staged migration: which approach fits?
The deciding factors are data volume, user count and how much downtime the business can absorb. A cutover migration moves everyone at a single point, usually over a weekend: mail flow switches once, there is one set of client reconfigurations, and by Monday everybody is on the new platform.
It is simpler, cheaper and lower in coordination overhead, and it works well for smaller estates with manageable mailbox sizes. Its weakness is that it is a single event with no partial rollback: if something is wrong on Monday morning, it is wrong for everyone at once.
A staged or coexistence migration moves users in batches while both environments run in parallel, with mail routing and, ideally, free/busy calendar lookup working across the boundary. It costs more in complexity and takes longer, but it lets you pilot with a tolerant group, catch problems while they affect ten people rather than three hundred, and pause.
Choose it when mailboxes are large, when the migration window is constrained by throttling or bandwidth, when there are shared mailboxes and delegate relationships that must not break mid-move, or when the organisation genuinely cannot be offline.
What does Microsoft 365 governance actually mean?
Governance is the set of decisions about who can create what, who can share what with whom, and what happens to content over time. In a Microsoft 365 tenant it has three practical strands. Sharing: whether external sharing is permitted at all, whether links default to 'anyone with the link' or to named people, whether unauthenticated links expire, and whether guests can be invited by any user.
Two questions that decide most governance outcomes:
- Lifecycle: who can create Teams and SharePoint sites, whether they must have an owner, and whether inactive workspaces are reviewed or expire
- Retention: how long mail, files and chat are kept, what is deleted on schedule, and what is preserved for legal or regulatory reasons
The reason this matters more now than it did five years ago is that search and AI collapse the practical difference between 'technically accessible' and 'findable'. Content buried three levels deep in a forgotten site used to be effectively invisible; a semantic search surfaces it instantly.
If a document was overshared in 2021 and nobody noticed because nobody knew the path, the exposure existed all along; Copilot simply makes it visible. Governance work is therefore not a tidy-up exercise, it is the prerequisite for turning anything on that reads across your data.
Business Premium, E3 or E5: how do you decide?
The first hard boundary is headcount: Microsoft 365 Business Premium is capped at 300 seats, so above that the choice is between E3 and E5 regardless of anything else.
Below 300, Business Premium is unusually good value because it bundles the Office applications with a security stack most organisations otherwise buy separately: Intune for device management, Entra ID P1 for Conditional Access, Defender for Office 365 for link and attachment protection, and Defender for Business for endpoint detection and response. Bought as add-ons, that collection costs considerably more than the difference in seat price.
The E3 versus E5 decision is mostly about whether you would otherwise buy the security and compliance components separately, and whether you have anyone to operate them. E5 adds Entra ID P2, which brings risk-based Conditional Access, Privileged Identity Management for just-in-time administrative access, and access reviews; it adds the higher Defender tiers and the fuller Purview capabilities.
The honest test is whether those capabilities will be configured and monitored. E5 licences generating alerts nobody reviews are shelfware with a compliance story attached, and a mixed estate (E5 for administrators, finance and executives, E3 for everyone else) is often the right shape.
Intune or Group Policy: do you need both?
If your devices are domain-joined and never leave the network, Group Policy still works. If they are Entra-joined laptops that connect from home and only see a domain controller when someone happens to be in the office, Group Policy stops applying reliably and you are managing a fleet on trust.
Intune applies policy over the internet against the device's identity rather than its network location, which is the whole point: the setting lands whether the laptop is in the office, at home or in an airport. It also does the things Group Policy never did:
- Application deployment
- Compliance state feeding Conditional Access
- Remote wipe of company data
- Enrolment straight out of the box via Autopilot
Migration is rarely a clean switch. Intune's settings catalogue and ADMX-backed policies cover the large majority of what most GPO estates actually use, and Group Policy analytics will import your existing GPOs and report what has a direct equivalent (a useful reality check, because most estates find a meaningful share of their policies are obsolete rather than untranslatable).
What genuinely does not carry over are logon scripts that depend on domain resources, drive mappings to on-premises file servers, and policies for legacy applications that assume a domain context.
How should Teams, SharePoint and OneDrive fit together?
Each has one job, and most tenants get into trouble by blurring them. OneDrive is for work in progress that belongs to one person. SharePoint is the system of record for content the organisation owns, structured into sites that reflect how the business is organised.
Teams is the collaboration surface over the top: every team you create silently provisions a Microsoft 365 group and a SharePoint site behind it, and the Files tab in a channel is a folder in that site. Understanding that relationship prevents the most common mistake, which is treating Teams and SharePoint as competing places to put things when they are the same place with two front doors.
The structural decisions that matter are how many sites you create and how you handle permissions. Flat and broad beats deep and nested: a smaller number of purposeful sites with clear ownership is easier to secure and easier to search than a hierarchy that mirrors an org chart from three restructures ago.
Permissions should be granted through groups rather than to individuals, and unique permissions on individual folders should be rare, because they are invisible to anyone browsing and become impossible to audit at scale.
What actually breaks in a rushed migration?
The failures are consistent, and almost all of them come from discovery that was skipped rather than execution that went wrong. Shared mailboxes and delegate access break when permissions are not mapped before the move, so a PA who has managed a director's calendar for years suddenly cannot see it.
Distribution lists get missed. Public folders, which nobody remembers exist, turn out to hold a decade of shared correspondence. Applications, scanners, copiers and line-of-business systems that relayed mail through the old server stop sending, and nobody notices until an invoice run silently fails.
The second category is identity and mail hygiene. If SPF, DKIM and DMARC are not corrected as part of the cutover, your legitimate mail starts landing in junk folders at exactly the moment the business is most sensitive to disruption.
And if governance is deferred until after go-live, the tenant is built on defaults that permit broad external sharing and unrestricted site creation, which is far harder to unwind later than to set correctly at the start. The pattern is that migration problems are discovery problems.
Does Microsoft back up your Microsoft 365 data?
Not in the way most people assume. Microsoft's shared responsibility model makes them accountable for the availability and resilience of the service, and you accountable for your data within it.
What the platform provides is recycle bins, versioning, retention policies and litigation hold: controls designed for accidental deletion and legal preservation. They will not restore a tenant after any of these:
- A malicious administrator
- A compromised account that deleted at scale
- A ransomware event that encrypted synced files
Recycle bins have finite windows, and once they lapse the content is gone.
The related question is what happens to a leaver's content, because that is where organisations lose data quietly. When a user account is deleted, their OneDrive is retained for a limited default period before permanent deletion, and their mailbox goes the same way unless it was placed on hold before the licence was removed.
Both of those are configurable, but only in advance. The decision about how much history you need, for how long, and whether platform retention alone is sufficient is a business and regulatory question that should be answered deliberately rather than inherited from a default.
Questions we hear a lot
Can you migrate us to Microsoft 365 from another platform?
Yes. We handle migrations from on-premises Exchange, Google Workspace and other tenants, moving mail, files and identity cleanly, with governance and security configured correctly from day one rather than bolted on later.
Which Microsoft 365 licence is right for my business?
For most SMBs up to 300 users, Microsoft 365 Business Premium is the best-value option because it bundles the productivity apps with the security stack most businesses are otherwise missing. We'll right-size licences to your actual headcount and usage so you're not paying for shelfware.
Do you provide ongoing Microsoft 365 support or just setup?
Both. We can run a one-off migration or governance project, then support the tenant on an ongoing basis, handling administration, licence optimisation, security and user adoption so it keeps delivering value.
How long does a Microsoft 365 migration take?
It depends on measurable things rather than on a standard timeline, which is why the honest answer comes after a scoping exercise. The variables are total data volume rather than user count, since one 90GB mailbox takes longer than twenty small ones; your available upload bandwidth; Microsoft's service throttling, which is applied to protect the platform and cannot be negotiated away; the number of shared mailboxes and delegate relationships that need mapping; and how many line-of-business systems relay mail. Preparation and discovery routinely take longer than the data movement itself.
Will users lose email or files during a migration?
They should not, and the design of the migration is what determines that. Mail is copied, not moved, so the source remains intact until the project is signed off, which means a rollback position exists throughout. In a staged migration mail flow is maintained across both environments, so messages sent during the transition are delivered rather than bounced. What users typically do experience is short interruption while their client reconnects and rebuilds its local cache. The genuine risks are around content that was never in scope: PST files on individual desktops, or a shared mailbox nobody declared.
Do we still need an on-premises Exchange server after moving to the cloud?
Only if you are still synchronising identity from an on-premises Active Directory. In that arrangement your on-premises directory remains authoritative for the synchronised attributes, so you need a supported way to manage recipients on-premises. Microsoft provides a management-only licensing arrangement for the server that remains, so you are not paying for a server hosting no mailboxes, but it still has to be patched and kept in support like any other internet-facing system: Exchange has been the subject of serious actively exploited vulnerabilities. If you move fully to cloud-managed identity and retire directory synchronisation, the requirement disappears.
Can two Microsoft 365 tenants be merged after an acquisition?
Yes, though it is a genuine project rather than a setting. A tenant-to-tenant migration means moving mailboxes, OneDrive and SharePoint content, Teams and identities into the target tenant. Domain names can only exist in one tenant at a time, so the source domain has to be released and re-verified in the target, which dictates the cutover sequence. User principal names, group memberships and permissions have to be mapped rather than copied, Teams chat history migrates less cleanly than mail and files, and devices need re-enrolling. It is best approached with a staged plan and a coexistence period.
What's the difference between Entra ID P1 and P2?
P1 gives you the controls that decide who gets in: Conditional Access policies based on user, device, location and application, self-service password reset, dynamic group membership and group-based licence assignment. It is included in Microsoft 365 Business Premium, E3 and E5. P2 adds the controls for detecting and containing misuse of legitimate access: Entra ID Protection, which scores sign-in and user risk so Conditional Access can respond automatically; Privileged Identity Management, which makes administrative roles time-limited and approval-gated; and access reviews. For most organisations P1 is the baseline and P2 earns its place first for administrators and high-risk roles.
Do we need Teams Phone, or can we keep our existing phone system?
Both are viable and the choice is about how you want calls routed and licensed. Teams Phone with a Microsoft calling plan is the simplest arrangement, with Microsoft acting as your carrier. Direct Routing keeps your existing telephony provider and connects them to Teams through a session border controller, which suits organisations with an existing contract or number ranges they want to keep. Operator Connect sits between the two. Keeping a separate PBX is also legitimate, particularly where you have contact centre queuing, regulatory call recording, or analogue devices like door entry and lift lines that still need a home.
Microsoft 365 is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Harrogate, Huddersfield, Scarborough, Bradford, Hull and Leeds and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
Know your Microsoft 365 security posture
Book a free security posture review and we'll show you where your Microsoft 365 and identity setup is exposed, and the fastest way to close the gaps.
Technology partners
Best-of-breed technology we use to deliver Microsoft 365.
See all technology partners →