Services
Email and Microsoft 365
We provision Microsoft 365: mail, Teams, and the DNS and security that keep it from becoming an open relay with a nice login screen.
- Domain and DNS
- Tenant setup
- Mailbox migration

Overview
What this is
The short version, before we get into what is included and how it runs.
Microsoft 365 is the mailboxes, calendars, Teams and files most businesses already assume they have, plus the settings behind them that decide who can sign in and from where. The problems are rarely dramatic, it is usually mail quietly landing in spam, or a former employee who somehow still has an active mailbox.
We either set up your account or take over the one you have, connect your domain, move the mail across, and configure the authentication that lets other mail servers tell your messages from an impersonation. Then two-factor sign-in, shared mailboxes and Teams, and we write down who holds the administrator accounts.
Licensing is part of the job. There are several Microsoft plans and they differ mainly in the security features they include, so we will tell you which one actually matches what you need rather than defaulting to the most expensive option.
Deliverables
What you get
Everything below is part of email and microsoft 365 as standard, rather than something added to the invoice later.
- Domain and DNS
- The domain records that prove the account is yours and route your mail correctly, set up so nothing is left pointing at a server nobody looks after any more.
- Tenant setup
- A Microsoft 365 account that belongs to your business, with the right domain on it, named administrators, and no leftover trial attached to someone’s personal account.
- Mailbox migration
- Mail, calendar, and contacts moved from the old host. Cutover, staged, or IMAP, chosen for the source. Users get a time window, not a surprise Friday.
- Sender authentication
- One clear record listing every system allowed to send email as your business. Getting this wrong is the usual reason mail suddenly starts bouncing after someone makes a small change to the domain.
- Message signing
- DomainKeys signatures on outbound mail from Exchange Online, with the selector published in DNS. If a third-party sender needs a include, we add it on purpose.
- Spoofing protection
- A policy that starts at monitor (p=none), reports on who is sending as you, then moves to quarantine or reject when the picture is clean. We do not jump to p=reject on day one and watch payroll mail die.
- Shared mailboxes and groups
- Addresses like info@ and jobs@, plus the distribution groups people actually use. Shared mailboxes do not need their own license, so we set them up that way rather than paying for addresses nobody signs into.
- MFA
- Multifactor authentication for every user who can sign in. Break-glass accounts are named, stored offline, and not used for daily mail.
- Conditional access
- A small set of rules: require MFA, block legacy auth, and restrict admin portals to places you expect. We explain each policy in English before we turn it on. We do not drop twenty templates on a ten-person firm.
- Teams
- The org, the teams that match how you work, and guest access set to a decision rather than the default. Teams is not a second file server unless you want it to be.
- Licensing guidance
- Which plan each person needs, what it covers and what it does not. If the security setup we have recommended requires a higher tier, we will say so rather than quote you the cheaper one and quietly leave the features off.
- Admin handover
- Who holds global admin, where the bills go, and a short note of the policies we set. You should be able to fire us and still sign in.
Process
How it works
In order. Each stage starts once the one before it is signed off.
- 01
Inventory
Mailboxes, aliases, devices, where your mail currently lives, and who believes they are the administrator. We find the existing account, or confirm there is not one.
- 02
Tenant and DNS
Connect the domain and set the records Microsoft needs, while leaving mail flowing to the old host until we are ready to switch.
- 03
Migrate
Move mail in a window you can staff. Users keep the old password story until we tell them the new one. We do not migrate the intern’s 40GB of deleted items by accident.
- 04
Authenticate
We set up sender authentication and message signing first, then turn on spoofing protection in reporting mode and watch for a while before tightening it.
- 05
Harden
MFA, disable legacy auth, conditional access, named admins. Then Teams and the shared mailboxes.
- 06
Handover
Licenses confirmed, billing in your own account, written documentation, and a week of “I cannot open Outlook” questions that we actually pick up.
FAQ
Questions we get asked
If yours is not here, use the contact form and we will answer it directly.
Will mail go down during the move?
There is a cutover window. For a clean Exchange or Microsoft 365 to Microsoft 365 move it can be short. IMAP from a cPanel box takes longer and we run it in batches. We pick a quiet period, we tell people, and we do not do it the night before a month-end.
We already have Microsoft 365. Why hire you?
Often, yes. Plenty of accounts were set up years ago with mail still routing through an old host, no message signing, no two-factor, and an administrator named after someone who left. We audit before we migrate and tell you plainly what we find.
How do you stop someone spoofing our email?
Three things work together: one record lists the systems allowed to send email as you, a signature proves a message genuinely came from you, and a policy tells other mail servers what to do if either check fails. We start in reporting mode, read what comes back, and tighten it once we know what is legitimately sending on your behalf. Rushing that last step is how a payroll notification quietly stops arriving.
Do we need new computers?
No. Outlook, Apple Mail, and the mobile apps work on what you have. Conditional access can block a genuinely ancient device that cannot do MFA. We will name those before we flip the policy.
Can you migrate from Google Workspace?
Yes. It is a planned migration with a dual-delivery or cutover window, not an export-to-PST everyone does at home. Drive files are a separate conversation if you want them in OneDrive or SharePoint.
Who owns the account if we leave?
You do. The billing, the domain and the administrator accounts are all in your name, and that is written into the handover. Leaving should be a decision, not an obstacle course.
Is Teams included?
On the SKUs we will recommend, yes. We set it up as part of the baseline. If you do not want Teams, we will still license a plan that can do MFA and Conditional Access rather than strip you to a mailbox-only SKU that cannot.
Tell us what you need built.
No pitch deck and no discovery fee. Most engagements start with a single site, and we add the rest only when it earns its place.
- Send a short brief, or just a link to the site you have now.
- We reply within two business days with questions, or a time to talk.
- You get scope, sequence and a price range in writing before anything starts.