top of page

Case Study: How a Landscaping Company Took Back Control of Its IT

Apr 10, 2025
13 min read

Updated: Aug 27



IT for landscaping companies case study showing how a landscaping business moved from leased equipment to owning and improving its IT infrastructure.
A real landscaping company IT case study showing how better ownership, ongoing maintenance, Microsoft 365 management and network improvements transformed its technology over several years.

When I first started working with this landscaping company, the owner was frustrated with the amount of money they were spending on IT and the support they were receiving in return. One of the first things that stood out was a three year equipment contract that would cost the company approximately $6,300 for equipment they did not own. They were leasing their firewall and wireless equipment, paying for server maintenance, paying for a backup service, and still having technology problems that were affecting the business.


A server failure was one of the issues that brought me deeper into their environment. The server they relied on for QuickBooks went down after its power supply failed. While troubleshooting it, I also discovered that the battery in the existing UPS was dead. They had a battery backup connected to the server, but the battery itself was no longer providing the protection they thought they had. I replaced the failed server power supply, got the server running again and had them purchase a more robust battery backup.


Once I started looking beyond that immediate problem, I found quite a bit more. The server was approximately six months behind on updates even though the company was paying for server maintenance. Employees were complaining about laptops losing their WiFi connections. Their computers were a mixture of local Windows accounts and devices connected to what Microsoft then called Azure AD, now Microsoft Entra ID. Shared company files were being stored in the OneDrive account of an employee who had left the company several years earlier, and they were still paying for that former employee's Microsoft 365 license because someone needed access to the mailbox and OneDrive to keep sharing those files with current employees.


This did not turn into one giant project where I replaced everything at once. I have continued working with this company over the years, and we have changed the environment as their business needs have changed. They are not on a traditional Managed IT contract with me either. They own their technology, and I continue helping them maintain, troubleshoot and improve it. Looking at where we started and where the company is today is a good example of what taking control of a small business IT environment can actually look like.


Why Was a Small Business Paying $6,300 to Lease Network Equipment?

I do not think leasing technology is automatically a bad decision. There can be legitimate financial or operational reasons for a business to lease equipment. In this particular environment, however, the numbers did not make sense to me for what the client actually needed. Their three year contract totaled approximately $6,300, and they would not own the equipment when the agreement ended.


Instead of replacing that contract with another lease, I had the company purchase its own firewall. The firewall cost roughly one quarter of what they would have spent over the three year equipment lease. They had also been leasing their wireless access point, so we replaced that with a newer access point that they purchased and owned.


Ownership does not mean equipment can be installed and forgotten about. Firewalls, switches and wireless access points still need firmware maintenance, and eventually every piece of equipment reaches a point where the manufacturer no longer supports it. The difference is that this business now owns the equipment and can make replacement decisions based on the condition of the environment, the manufacturer's support lifecycle and what the company actually needs rather than automatically entering another three year equipment contract.


Fixing the WiFi Required More Than Buying a New Access Point

The wireless access point was a good example of why I do not like treating small business IT as a shopping list. Employees had been complaining about their laptops losing wireless connectivity in the office. I did replace the leased access point with a newer one that the company owned, but I also relocated it within the office so we could improve coverage where employees were actually working. That resolved the connection complaints they had been experiencing.


I configured the new firewall for their environment as well, including its security services and VPN access. Later, as the network evolved, I had the company purchase a managed switch so I could begin separating different types of network traffic with VLANs. Their internal business network, server environment used for Remote Desktop access and guest WiFi did not all need to remain together on one flat network.


That network continues to evolve today. We have recently been discussing adding security cameras around the property, including coverage at some of the other buildings. I have already provided the client with a proposal that includes using wireless backhaul equipment to extend network connectivity to some of those locations. If the camera project moves forward, I plan to put the cameras on their own VLAN as well. That project has not been implemented yet, so I cannot tell you how it performs, but it is a good example of why I like building a network with room to change as the business changes.


A Failed QuickBooks Server Exposed a Bigger Maintenance Problem

Getting the QuickBooks server running again solved the immediate problem that day, but it also led me to look more closely at how the server was being maintained. That was when I discovered that it was approximately six months behind on updates even though the company was paying another provider for server maintenance.


We canceled the maintenance service they had been paying for, and I brought the server current. Even though this company is not on a Managed IT contract with me, I still perform monthly server updates for them. I also apply applicable firmware updates to the firewall, managed switch and wireless access point. Owning technology does not eliminate the need for maintenance, and having a maintenance service on an invoice does not necessarily tell a business owner whether that maintenance is actually happening. Someone still needs to verify it.


We also changed their backup arrangement. The company had been paying for a backup service associated with the firewall, and instead I had them purchase a backup solution that they own. I also configured Shadow Copies on the server for the location containing the QuickBooks company file, which has since helped us recover from problems more than once.


In one situation, there was a problem after an attempt was made to change the QuickBooks company file name. In another, the company file became corrupted following work with QuickBooks support. Because I had previous versions available locally on the server, I was able to recover a usable copy without waiting for the company's slow Internet connection to restore the file from its separate backup.


Shadow Copies are not a replacement for a proper backup, and I do not treat them as one. In this environment they provide an additional recovery option for certain file problems. That distinction has mattered because restoring a previous version locally can get the office working again much faster than pulling a large QuickBooks company file back across a slow Internet connection.


Their Shared Company Files Belonged to an Employee Who Had Left Years Earlier

Microsoft 365 became another major part of the work I eventually did for this client. When I inherited the environment, their computers were a mixture of local Windows accounts and devices already connected to what Microsoft called Azure AD at the time, which is now Microsoft Entra ID. Their shared company files presented an even bigger problem.

The company was using the OneDrive account of an employee who had left several years earlier as a shared file location. They had kept that former employee's Microsoft 365 license active, and someone still had access to the employee's mailbox and OneDrive so they could continue sharing files with new employees.


OneDrive itself was not the problem. The problem was using one former employee's individual account as the long term home for information the business depended on.

I sat down with the owner and office manager and went through the existing folders with them. We figured out what information they had, how it should be structured and who actually needed access to each area. Once we had that mapped out, I moved the shared business information into a SharePoint library, created security groups and assigned access based on what each user needed.


That moved the company's shared information away from a former employee's identity and into a location designed around the business. Microsoft also provides specific administrative processes for preserving and moving a former employee's OneDrive information, which is one of the reasons employee offboarding needs to include more than simply disabling an email account.


I have written separately about what can happen to Microsoft 365 OneDrive data when an employee leaves, including why businesses need to decide where company information should live before removing accounts and licenses.


Microsoft 365 Business Premium Was Only the Beginning

As I continued rebuilding their Microsoft environment, I upgraded the company's licensing to Microsoft 365 Business Premium and started putting the management and security controls underneath it in place. I configured Conditional Access policies along with Intune configurations and device policies so the computers could be managed more consistently.

Some of the computers were already connected to Microsoft Entra ID, but being connected to Entra ID did not automatically mean those computers were enrolled in Intune and receiving the policies I had configured. I had to work with the existing machines and enroll them into management. For a computer that was still using a local Windows account, I used a profile migration tool to move the existing profile into the Microsoft Entra environment so the computer could become part of the centrally managed setup without simply abandoning the user's existing Windows profile.


We also replaced some older computers that were still running Windows 10 with newer Windows 11 machines. This was not simply a licensing project. The goal was to move toward an environment where identities, computers, access and security policies could be managed more consistently instead of having a collection of machines that happened to have Microsoft accounts attached to them.


That distinction is one I talk about frequently with small business owners. Owning Microsoft 365 licensing and properly configuring Microsoft 365 are two different things. Business Premium gives a company access to a substantial set of identity, device management and security capabilities, but someone still has to determine how those capabilities should be configured for the business.


That is one of the reasons I offer a Microsoft 365 Audit. I am less interested in simply seeing which Microsoft license appears on an invoice than understanding what is actually configured inside the tenant and how the business is using it.


One of Their Longstanding Problems Had a Pretty Simple Fix

Not every improvement in this environment required a firewall, server or complicated Microsoft security policy. Scheduling had been a pain point for the company for a long time. The office manager and employees working in the field needed an easier way to see where appointments were scheduled and where everyone was expected to be throughout the day.


I created a shared calendar that the appropriate employees could access. For members of the field crew, I configured Outlook on their phones and added the shared calendar so they could see the day's appointments while they were away from the office. That also made things easier for the office manager because the information did not have to stay trapped inside the office.


like that part of this project because it is easy for IT conversations to become focused entirely on cybersecurity and infrastructure. Those things matter, but technology should also make it easier for employees to do their jobs. In this case, something the company had struggled with for a long time had a relatively simple solution using technology they already had available.


An Account Compromise Changed What We Did With Email Security

The company's Microsoft 365 security also evolved over time. After they experienced an account compromise, I strengthened the protections around their email environment rather than treating the Microsoft 365 configuration as something we had finished once and would never revisit.


I configured Microsoft Defender for Office 365 protections, including Safe Links and Safe Attachments, along with user and domain impersonation protections. Safe Links adds checks around potentially malicious URLs, while Safe Attachments provides another layer of analysis for email attachments. I also configured protections intended to help identify attempts to impersonate users and domains the company trusts. These controls reduce certain types of email risk, but I would never describe them as making phishing or account compromise impossible.


I also addressed email authentication for the company's domain. I enabled DKIM in the Microsoft 365 tenant and added the required DNS records. I configured DMARC with a policy of p=reject, which the domain did not previously have. Microsoft currently recommends configuring SPF, DKIM and DMARC for custom Microsoft 365 domains as part of email authentication, but those controls still need to be configured correctly for the actual services sending mail for a business.


This is another example of why I do not consider a Microsoft 365 environment finished simply because the licenses are active. The way a business uses email changes, threats change, Microsoft changes its products and controls, and sometimes an incident exposes an area that deserves another look.


This Client Is Not on a Managed IT Contract With Me

One of the things I want to be clear about in this case study is that this company is not on a traditional Managed IT contract with SNL-Tech Services. I think that matters because there is a tendency to talk about small business IT as though every company needs exactly the same support model.


This client owns its firewall, managed switch, wireless access point and backup solution. I also set up an RMM solution that the business owns so I can remotely access its computers when someone needs troubleshooting or support. I still perform the scheduled monthly server updates and maintain firmware on the network equipment, while other troubleshooting, upgrades and projects are handled as needed.


That arrangement works for this particular business. Another company may need broader ongoing management and support under a Managed IT agreement. Another may only need help with a specific project. Some businesses fall somewhere in between. I wrote a separate guide about what kind of IT support a small business actually needs, including Managed IT, hourly T&M, project based work and shared responsibility because I do not think the answer should automatically be the same for every business.


What matters to me in this client's environment is that the business understands what it owns, what I am responsible for and what still needs to be maintained. The technology belongs to their business. My job is to help them configure it correctly, maintain it and use it effectively.


What Changed for This Landscaping Company?

There have been a lot of individual changes over the years, so this is one place where I think it helps to step back and look at the larger picture.

Where We Started

What Changed

Three year equipment lease totaling approximately $6,300

Client purchased and owns its network equipment

Leased firewall and wireless access point

Purchased firewall and newer wireless access point

Employees experiencing WiFi connection problems

Wireless access point relocated to improve office coverage

QuickBooks server failed after a bad power supply

Power supply replaced and server restored

UPS battery was dead

More robust battery backup purchased

Server approximately six months behind on updates despite paid maintenance

Server brought current and now receives monthly updates

Backup service tied to previous arrangement

Client purchased its own backup solution

QuickBooks recovery depended heavily on backup over slow Internet

Shadow Copies added as an additional local recovery option

Shared files stored in a former employee's OneDrive

Business files reviewed, reorganized and moved into SharePoint

Mixed local and Microsoft connected Windows accounts

Environment moved toward Entra ID and Intune management

Older Windows 10 computers

Older systems replaced with Windows 11 machines

Longstanding scheduling problem

Shared calendar made available to office and field employees

Microsoft 365 email security needed improvement

Defender protections, DKIM and DMARC configured

Flatter network design

Managed switch and VLAN segmentation introduced

Remote troubleshooting needed

Client owned RMM solution configured

Network originally focused mainly on the office

Proposed future expansion includes cameras and wireless backhaul to other buildings

The point of that table is not that every landscaping company should copy this exact environment. The decisions were made around this particular business, its employees, its existing technology and the problems we encountered over time.


How Can a Small Business Know Whether Its IT Is Actually Being Managed?

This case raises a question I think more small business owners should ask. It is easy to look at an invoice and assume that because something says “maintenance,” “backup,” “security” or “managed,” someone is checking it. That assumption did not work particularly well for this client. They had a UPS, but its battery was dead. They were paying for server maintenance, but the server was approximately six months behind on updates. They had shared cloud storage, but it was tied to an employee who had left years earlier.

A business owner does not need to know how to configure Intune, build a VLAN or recover a QuickBooks company file. The owner should, however, be able to get clear answers to questions like these:

  • What hardware and software does my business actually own?

  • What equipment am I leasing, and what happens to it when the agreement ends?

  • When were my server and network devices last updated?

  • Is someone checking whether the UPS batteries protecting important equipment still work?

  • Has our backup actually been reviewed, and what would recovery look like?

  • Where do our shared company files live?

  • Are any important files dependent on a former employee's account?

  • Are our computers actually managed, or are they simply signed into Microsoft 365?

  • How are field employees accessing the information they need?

  • Who has access to company information, and why?

  • Who owns the remote management tools used by the IT provider?

  • What happens to our administrative access, equipment and management tools if we change IT providers?

Those questions do not tell you that every environment needs to be configured the same way. They help establish whether the business actually understands the technology it depends on and who is responsible for it.


Taking Back Control of IT Did Not Happen in One Day

When I look at this client's environment today, the biggest change is not one firewall, one Microsoft license or one server repair. It is that the business has much more control over the technology it depends on and a clearer path for changing that technology as the company evolves.


We started with a failed QuickBooks server, a dead UPS battery, an expensive equipment lease, server maintenance that was not being performed, unreliable WiFi, a mixture of local and Microsoft connected computers and shared business information living inside the OneDrive account of an employee who had left years earlier. Over time, the company purchased its own infrastructure, improved the network, brought the server maintenance under control, added practical recovery options, rebuilt how shared files were handled, moved toward centrally managed Windows devices, strengthened Microsoft 365 security and gave its field employees a better way to access scheduling information.


The work is still evolving. Today we are discussing cameras, another VLAN and wireless backhaul connectivity to additional buildings. A few years from now, the environment may look different again.


That is what I think taking control of IT actually looks like for a small business. It is not about buying the most expensive equipment or signing the biggest support contract. It is about understanding what the business has, knowing what it owns, verifying that the work being paid for is actually happening, and making deliberate technology decisions based on how the business operates.


If you are paying for IT services but are not sure what is being maintained, what equipment belongs to your business or whether your Microsoft 365 and network environment still fit the way your company works today, it may be time to take a closer look.


ADDITIONAL RESOURCES

Microsoft Learn: Microsoft Defender for Office 365

Current Microsoft documentation covering Defender for Office 365, including Safe Links, Safe Attachments and email protection features.https://learn.microsoft.com/en-us/defender-office-365/


Microsoft Learn: Email Authentication in Microsoft 365

Microsoft guidance covering SPF, DKIM and DMARC for custom Microsoft 365 domains.https://learn.microsoft.com/en-us/defender-office-365/email-authentication-about


Microsoft Learn: Set Up OneDrive File Storage and Sharing

Microsoft guidance covering OneDrive, SharePoint team sites and shared business files.https://learn.microsoft.com/en-us/microsoft-365/admin/setup/set-up-file-storage-and-sharing


Microsoft Learn: Remove a Former Employee from Microsoft 365

Microsoft guidance covering access to and preservation of a former employee's OneDrive and Outlook information.https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/remove-former-employee


CISA: Cybersecurity Performance Goals

Cybersecurity guidance covering areas such as patching, backups and network segmentation.https://www.cisa.gov/cyber-guidance/cybersecurity-performance-goals


Comments


bottom of page