Key takeaways

  • Microsoft 365 is not just email; it also covers identity, files, collaboration and security policies.
  • Teams, OneDrive and SharePoint serve different purposes - confusing them leads to disorganised documents.
  • MFA, secure sharing and separate administrator accounts should form the foundation of the environment.
  • Licences should be selected according to each user's requirements, rather than assigning the same one to everyone.
  • Before migration, you need to organise accounts, domains, data, permissions and working practices.

Why does this matter?

A Microsoft 365 implementation often begins with email and ends up with numerous independent teams, libraries, sharing links and ownerless accounts. The mere presence of cloud services does not guarantee order or security. The most important decisions concern the identity model, data structure, guest access, devices and responsibility for administration.

A well-planned environment makes it easier to work from anywhere, while reducing accidental file sharing, account compromise and data loss when an employee leaves.

Key applications and their roles

Exchange Online and Outlook

Email, calendars, groups and message protection rules. They require organised domains, shared mailboxes and anti-spam policies.

Teams

Chat, meetings and project channels. Channel files are stored in SharePoint, so the team structure affects how documents are organised.

OneDrive

A user's personal working files, with synchronisation and version history. It should not replace a shared company library.

SharePoint

Shared libraries, sites, intranet and team permissions. It requires owners, naming conventions and sharing rules.

How should you assess the current situation?

  • Does every account have an owner and relate to a current employee?
  • Do administrators use separate privileged accounts?
  • Does MFA cover all users and administrators?
  • Is it clear where team documents are stored and who can share them?
  • Are former employees' accounts blocked and their sessions and tokens revoked?
  • Are company devices encrypted, updated and managed?
  • Is there an independent backup of mailboxes, OneDrive, SharePoint and Teams?
  • Does the business know its licence costs and how assigned plans are being used?

Identity and security

Entra ID and MFA

Entra ID is the identity layer for Microsoft 365 and cloud applications. MFA reduces the impact of password theft, but it should be supported by Conditional Access policies, administrator account protection and reviews of risky sign-ins.

Devices and Intune

Intune can manage computer and phone configurations, applications, BitLocker encryption, updates and remote data removal. Deployment requires a clear definition of which devices are company-owned and which conditions they must meet.

Sharing and data

It is worth restricting public links and establishing rules for guest access, site and library owners, and retention. Sensitivity labels and DLP can support data protection, but they require information classes to be defined first.

How should you select licences and control costs?

Plans differ in their email, office applications, security, device management and compliance features. It is best to list requirements first and only then assign a plan to each user role. An office worker, support role, shared device and administrator may each require a different scope.

User scope

Number of accounts, shared mailboxes, need for desktop applications, Teams, OneDrive and mobile working.

Security

MFA, Conditional Access, email protection, Intune, DLP, auditing and organisational requirements.

Scale and variability

Seasonal staffing, shared devices, guests and temporary accounts.

Total cost

Not only the licence, but also administration, backup, migration, training and users' time.

How should you plan a migration?

  1. Inventory accounts and domains. Remove unused mailboxes and check aliases and data owners.
  2. Define the target structure. Plan teams, channels, libraries, naming conventions and roles.
  3. Prepare security. Enable MFA, secure administrator accounts and establish access rules.
  4. Run a pilot. Test email, calendars, files and devices with a small group.
  5. Move data in stages. Define communications, change windows, copies and a process for handling exceptions.
  6. Document and monitor. Record the configuration, service owners and the employee leaver procedure.

Common mistakes

One licence for everyone

Standardising plans may be convenient, but it can create unnecessary costs or leave critical accounts without the protection they need.

Using Teams to store everything

Without rules for owners, naming and retention, the number of outdated teams and hard-to-find files grows.

No independent backup

In-service retention and recycle bins do not replace an independent copy that enables recovery after an error or incident.

Security and risks

  • Enable MFA for all users, especially administrators.
  • Separate administrator accounts and limit the number of Global Administrators.
  • Establish rules for guest access and public sharing.
  • Protect devices through encryption, updates and compliance controls.
  • Configure SPF, DKIM and DMARC for email domains.
  • Provide an independent Microsoft 365 data backup and test recovery.

What can the business do itself?

You can begin by listing accounts, licences, domains, teams and data owners. It is also worth disabling confirmed unused accounts, establishing basic naming rules and preparing onboarding and offboarding checklists.

When is specialist support needed?

Support is useful when migrating a large number of mailboxes, integrating with on-premises AD, deploying Intune, changing domains, organising permissions, and whenever an incorrect change could stop many users from working.

Frequently asked questions

Can Microsoft 365 operate without an on-premises server?

Yes. It can operate entirely in the cloud or in a hybrid model if the business still uses on-premises systems that require a domain.

Does Microsoft 365 replace backup?

No. Retention and recycle bins are not an independent backup. Backup should cover mailboxes, OneDrive, SharePoint and Teams data, and it should be tested.

Can services be introduced in stages?

Yes. Businesses often begin with email and MFA, then organise files, Teams, devices and data protection policies.

Does every user need the same plan?

No. The plan should reflect the user's role, applications, devices and security requirements.

Where should we start when organising the environment?

Start with an inventory of accounts, licences, data, devices and permissions. Only then should you design the target structure and policies.

Related service

Do you need to organise Microsoft 365, licences, security or migration?

View Microsoft 365 administration

Related reading

Active Directory and accessAccounts, groups, roles and on-premises or hybrid models.Email migration to Microsoft 365How to reduce risk and disruption.Backup and data recoveryCopies, retention and recovery tests.