Most small businesses end up on Microsoft 365 because somebody needed Outlook. It gets set up in an afternoon, everyone gets an address, and nobody looks at it again until a laptop is stolen or an employee leaves badly.
The setup that prevents those days takes about two extra hours at the start.
Get the licensing right first
The plans look similar and the differences matter.
The basic plan gives you email, calendars, file storage and the browser versions of Word and Excel. No installed desktop apps. Genuinely fine for a lot of teams, especially anyone who mostly answers email and works in shared documents.
The standard plan adds the installed desktop applications on up to five devices per person.
The premium plan adds device management and security controls. This is the one worth understanding, because it is the difference between “we can wipe that phone” and “we cannot.”
You do not have to give everyone the same license. A field crew that only needs email on a phone does not need the desktop suite. An office manager who lives in spreadsheets does. Mixing licenses is normal and saves real money.
Accounts belong to the business
This is the one that causes lasting damage when it is wrong.
The account that owns the whole tenant should be a business account, not a personal address, and not an individual employee’s. Set up a dedicated administrator account with a strong password, keep the credentials somewhere the owners can reach, and use ordinary accounts for daily work.
The failure this prevents: the office manager set everything up under her own login, left in 2023, and now nobody can add a user or reset a password. This happens constantly and untangling it takes weeks.
Turn on multi-factor authentication
Not optional. Business email is the most attacked thing your company owns, because it is the route to your bank, your suppliers, and your customers.
The most common serious incident for a small business is not ransomware. It is somebody reading your mail quietly for a month, then emailing your customer new bank details for an invoice. Multi-factor authentication stops nearly all of it, and it costs nothing.
Turn it on for everyone, including the person who says they do not need it.
Mail that reaches the inbox
Your domain needs three records in its settings that tell the world which systems are allowed to send mail as you, and what should happen to mail that fails the check.
You do not need to understand the format. You do need someone to set them up, and you need to know they exist, because two things depend on them:
- Your mail landing in inboxes rather than spam folders.
- Nobody being able to send convincing mail as you. Without these records, anyone can put your domain in the From field.
If your business sends anything through another service, a marketing tool, an invoicing system, a booking platform, each one needs to be added. Adding a sending service and forgetting this step is the usual reason a business suddenly finds its mail going to spam.
Ask whoever manages your domain: “Are our mail authentication records set up, and does the policy tell receivers to reject impersonation?” A yes with specifics is what you want.
Shared mailboxes, not shared logins
Every business has an address like the main contact one, checked by several people. There are two ways to do it and only one is right.
Right: a shared mailbox, with permissions granted to the individuals who need it. No license required, no password shared, and access is removed by removing a permission.
Wrong: a user account with the password written down and passed around. Nobody can tell who sent what, multi-factor authentication becomes impractical, and when someone leaves you have to change a password everyone depends on.
Storage, with one decision made early
Files go in one of two places: someone’s personal drive, or a shared team space. The distinction seems trivial and determines whether your files survive turnover.
Anything the business needs goes in a shared space. Personal drives are for drafts and scratch work. If an employee leaves and the quote templates go with them, that decision was made two years earlier by whoever saved them in the wrong place.
Set up the shared structure on day one, before habits form. Changing it later means moving files people have linked to.
The offboarding step nobody writes down
When someone leaves, most businesses delete the account. That deletes the mailbox, and with it any thread a customer might reply to.
Better sequence:
- Reset the password and sign the account out of everything.
- Convert the mailbox to a shared one, so it stays reachable without a license.
- Give a manager access to it.
- Set a forward if customers still write to that address.
- Transfer anything in their personal file space to the team space.
- Remove the license, which stops the billing.
- Delete the account after a few months, once nothing is still arriving.
Write this down as a checklist now, while nobody is leaving. It is a fifteen minute job done calmly and a bad afternoon done in a hurry.
What this looks like in practice
A five person business, properly set up, is one administrator account the owners control, five user accounts with multi-factor authentication, a mix of license levels, one or two shared mailboxes, a team file space with a sensible folder structure, mail authentication records in place, and a written offboarding checklist.
That is a couple of hours of work and it removes most of the ways a small business loses access to its own systems.



