Isn’t Microsoft 365 secure enough out of the box?
The platform is sound; the defaults are written for everyone, which means they are tuned for no one. Out of the box, a tenant typically allows sign-ins it should question, keeps logs shorter than an investigation needs, and leaves powerful admin roles broader than any small firm requires. None of that is a scandal. It is simply configuration work nobody was assigned. Assigning it is the job.
What does a hardened tenant look like?
Sign-ins that require phishing-resistant authentication, admin roles trimmed to the people who need them, mail authentication set up so others cannot send as you, logging that reaches back far enough to answer questions, and retention that matches how long your records actually need to live. We document the decisions as we make them, so the tenant’s shape is written down and survivable rather than folklore.
Can we stop emailing sensitive files to clients?
Yes, and for some firms that single change is the biggest risk reduction of the year. Client documents that live in inboxes are one forwarded thread away from being nobody’s secret. We set up secure file exchange inside the tenant you already pay for, so tax documents, matter files, and statements move through a controlled door with access you can review, instead of riding as attachments.
Are we paying for the right licenses?
Frequently not, in both directions. We find seats for people who left last year, premium features nobody turned on, and, just as often, a firm paying for a lower tier while separately buying tools the higher tier already includes. A license review is short, unglamorous work that regularly pays for itself. Right-sizing is the goal; the bill should describe the business as it is.
Can you move us into Microsoft 365, or between tenants?
Yes, and migrations are where the calm-rhythm habit earns its keep. Mail, files, and calendars move on a written plan, in stages, with the old system kept warm until the new one has proven itself. Most moves we see start from an aging on-premise server, from consumer email that grew up with the business, or from a tenant inherited in a merger that nobody fully owns. The bar we plan to, and measure the move against, is unglamorous and strict: no lost folders, no missed client email, and a cutover that lands on a day you chose rather than a day a dying server chose for you. The hardening pass runs on the new tenant from the first login, so the fresh start actually starts fresh.
Who holds the keys to our tenant?
You do. That is policy, not preference. Global admin custody sits with the business, documented, with our access granted the way any vendor’s should be: least privilege, logged, and revocable on your say-so. Plenty of owners have learned during a provider divorce that they never actually held their own keys. Our guide on leaving an IT provider exists because of those stories, and we set every client up to never be one.
Quick answers
We only have a handful of people. Is this overkill?
The hardening scales down cleanly. A five-person firm needs fewer decisions made, not weaker ones; the same doors get locked, there are simply fewer of them.