Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment?
- Shay

- 2 days ago
- 9 min read

I talk to small business owners who tell me their Microsoft 365 is already taken care of because someone set it up years ago. Email works, employees have the Microsoft applications they need, OneDrive is syncing and everyone gets an MFA prompt when they sign in, so there hasn't been much reason to question what is happening behind the scenes. From the owner's perspective, Microsoft 365 is doing exactly what they are paying for it to do.
What I usually want to know is who has actually been managing that Microsoft 365 environment since it was originally set up, because having Microsoft 365 and actively managing it are two very different things. Maybe an IT company configured everything five years ago, another company worked on it later, an employee was given administrative access somewhere along the way and different licenses or applications were added as the business needed them. Nobody necessarily did anything wrong, and there may not be anything obviously broken, but that doesn't tell us whether the Microsoft 365 environment the company has today is still the environment everyone thinks they have.
Microsoft 365 isn't a set-it-and-forget-it service. Microsoft continues to change the platform, and at the same time the businesses using it continue to change too. That combination is why I think it's worth asking a different question than whether your email is working.
Is someone actually managing your Microsoft 365 environment today?
Why Does Microsoft 365 Management for a Small Business Matter?
This can be difficult to see as a business owner because most of what happens inside Microsoft 365 isn't visible during a normal workday. You open Outlook and your email is there. Employees can get to the files they need, Teams works and nobody is calling because they can't sign in. Those are all good things, but they really only tell us that the services employees are using are working.
They don't tell us who has administrative access to the environment, whether former employees still have access somewhere, which applications have been connected to Microsoft 365 over the years, how employees are authenticating or what security policies are actually in place. They also don't tell us whether the computers accessing company information are being managed or whether old SharePoint and OneDrive permissions still match what employees need today.
A business owner shouldn't need to understand Microsoft Entra, Conditional Access, Intune or all of the administrative roles inside Microsoft 365 just to know whether their technology is being taken care of. What I would expect is that the person or company responsible for managing the environment can answer those questions, explain what is in place and tell the owner why it is configured that way.
That is an important part of how SNL-Tech Services approaches Microsoft 365 management for small business. I'm not only interested in whether email is flowing and employees can sign in. I want to know what is happening behind those services and whether the environment still makes sense for the business using it.
Microsoft Keeps Changing, but Has Your Microsoft 365 Kept Up?
One of the reasons Microsoft 365 needs ongoing attention is simply that Microsoft keeps changing it. New security capabilities are introduced, existing features change, licensing changes, older technologies are retired and Microsoft's recommendations for how businesses should protect accounts and information continue to evolve.
Authentication is a good current example. Microsoft is moving Entra ID users away from Microsoft-provided SMS and voice authentication and toward stronger, phishing-resistant methods such as passkeys. Beginning September 1, 2026, Microsoft says users who are enabled for SMS or voice authentication will also be enabled for passkeys and may be prompted to register one. Microsoft-provided SMS and voice authentication is scheduled to retire on February 1, 2027.
If your employees currently receive text messages as part of their Microsoft 365 sign-in process, this is a change that needs to be planned for. It doesn't mean using SMS for MFA in the past was a mistake. The technology is changing, and whoever is responsible for the company's Microsoft 365 should understand how employees are authenticating today and have a plan for moving them forward.
Licensing changes too. A company may have started with Business Standard and then added other Microsoft licenses, security products or add-ons as different needs came up. Those decisions may all have made sense at the time, but several years later it is worth understanding what the business is paying for, what capabilities it already owns and whether the same combination still makes sense.
Your Business Has Changed. Has Your Microsoft 365 Changed With It?
Microsoft isn't the only thing that changes. Since Microsoft 365 was originally configured, employees may have joined or left, people may have changed roles, computers have been replaced, remote work may have become more common and considerably more company information may now live in OneDrive, SharePoint and Teams.
Those changes can leave things behind. Someone may still have access to a SharePoint site from an old project. An employee who changed roles may have permissions they no longer need. A previous IT provider or outside consultant may still have an administrative account that was completely appropriate when it was created. In IT, we sometimes call this configuration drift, but the terminology isn't particularly important. What matters is whether the Microsoft 365 environment the business has today still matches the business using it.
The same applies to the computers employees use. Some businesses are comfortable allowing employees to access company information from personal computers, while others only allow access from company-managed devices. That should be an intentional decision, particularly for businesses that have regulatory compliance requirements, handle sensitive information or have contractual or client requirements around how information is protected. Microsoft 365 gives us tools that can help enforce those decisions, but someone needs to know what the business has decided and whether the environment is actually configured that way.
Why SNL-Tech Services Maintains a Microsoft 365 Runbook
This is also why SNL-Tech Services creates and maintains a runbook for the Microsoft 365 environments I manage. I don't want important information about a client's tenant living in someone's memory or buried in an old email.
The runbook provides an overview of the environment and documents what is in place. Depending on the environment, that can include things such as:
Conditional Access policies and notes about how they are being used
Security groups that have been created and their purpose
Screenshots of important configurations
Emergency or break-glass accounts, including how they are protected and who has custody of the associated FIDO security keys
Significant configuration changes, including when they were made and why
I also maintain dates and version history as the runbook changes. If I adjust a security policy today, I don't want to look at the tenant a year from now and wonder when it changed or why it was configured that way. I want something I can reference that gives me the history and context behind the environment, particularly when troubleshooting a problem, reviewing the tenant later or deciding whether an existing configuration should be changed.
Good documentation isn't just a record of what Microsoft 365 looks like today; it helps explain how it got there.
Thinking About Microsoft Copilot? This Is a Good Time to Look at Microsoft 365 First
More small businesses are looking at Microsoft Copilot because it fits naturally into an environment employees are already using. They are working in Outlook, Word, Excel, Teams, OneDrive and SharePoint, so adding AI capabilities within those applications can be an attractive next step.
Before a broader Copilot rollout, however, I want to understand the permissions that already exist. Microsoft 365 Copilot operates within the access a user already has. If someone changed departments three years ago but still has access to an old SharePoint site, Copilot didn't create that permission. If a site was shared more broadly than necessary and nobody cleaned it up, that also existed before Copilot.
What Copilot changes is how easily employees can find, summarize and work with information they are already permitted to access. That's why SNL-Tech Services recommends reviewing the Microsoft 365 environment before a broader Copilot rollout. I would rather identify old permissions and oversharing first than discover them after adding a tool designed to make company information easier to find and use.
If you're getting ready to build something new on top of Microsoft 365, it's worth knowing what you're building it on.
What If Nobody Knows What's Actually in Your Microsoft 365?
This is where a lot of small businesses find themselves. They know Microsoft 365 works, but once we get beyond the applications employees use every day, nobody is completely sure what is actually configured. The owner may know MFA is enabled but not how it is being enforced, know they are paying Microsoft every month but not why every license is there, or know that an IT provider set everything up years ago without knowing whether anyone has reviewed the overall environment since.
That doesn't automatically tell me there is a security problem, and I don't think the answer is to scare a business owner into assuming there must be one. What it tells me is that we don't have a current baseline.
That is what the SNL-Tech Services Microsoft 365 Audit is designed to establish.
Depending on the environment, the Audit can include reviewing:
User accounts and administrative access
MFA and authentication methods
Microsoft 365 licensing
Security policies and configurations
Devices and how they are allowed to access company information
SharePoint, OneDrive and other permissions
Connected applications
Existing security groups and access controls
I'm not looking for things to change simply for the sake of changing them. I want to understand what's there, identify anything that deserves attention and give the business a much clearer picture of the Microsoft 365 environment it relies on every day.
Sometimes an audit uncovers something that needs attention quickly. Other times I find permissions that no longer fit the business, licensing that deserves another look or capabilities the company is already paying for but isn't using. There are also times when the review confirms that much of the environment is in good shape, and that's useful information too.
If your Microsoft 365 was configured several years ago and you're not completely sure who has been managing it since then, you don't need to know which Microsoft policies to ask about or which settings should be enabled before having that conversation.
That's what the audit is there to figure out. If you're not sure what is currently in place, we can start there.
Frequently Asked Questions About Microsoft 365 for Small Businesses
Is Microsoft Authenticator going away?
No. Microsoft Authenticator is not going away. Microsoft is retiring Microsoft-provided SMS and voice authentication and moving toward stronger authentication methods, including passkeys and other phishing-resistant options. Microsoft says its transition begins September 1, 2026, with Microsoft-provided SMS and voice authentication scheduled to retire February 1, 2027.
Is Microsoft 365 Business Premium worth it for a small business?
It can be, particularly for businesses that need additional identity, security and device-management capabilities, but I don't think every company should automatically upgrade because a more expensive license has more features. I prefer to understand what the business already owns, what it is paying for separately and what it actually needs before making that recommendation.
Can employees access Microsoft 365 from their personal computers?
They can if the environment is configured to allow it, but whether they should is a business and security decision. The type of information the company handles, client requirements, cyber insurance requirements and regulatory or contractual obligations can all affect whether allowing access from unmanaged personal devices makes sense.
Should Microsoft 365 be reviewed before deploying Copilot?
I recommend it. Copilot works within users' existing Microsoft 365 permissions, which means old access and oversharing that already exist can become more important once employees have a much easier way to discover and work with information.
Can SNL-Tech Services Audit Microsoft 365 If Another IT Company Set It Up?
Yes. A Microsoft 365 Audit doesn't have to begin with replacing the company that originally configured the environment. Sometimes a business simply wants an independent look at what it has today, whether its security and access controls still make sense and whether Microsoft 365 matches what the business believes is in place.
The first step is understanding the existing environment. I'm not going to change something simply because another IT provider configured it differently than I would have. I want to understand why it is there, document what is currently in place and then identify anything that deserves attention.
Can a Microsoft 365 Audit Help With Cyber Insurance?
It can help a business be better prepared for a cyber insurance application or renewal. Insurers may ask about controls such as MFA, administrative account protection, endpoint security, encryption, backups, email security and remote access. The problem is that a business owner may believe those protections are in place without having current documentation showing how they are actually configured.
A cyber insurance application isn't the time to discover that the security control you thought was configured actually isn't.
A Microsoft 365 Audit can help establish what is actually in place, while a current runbook gives the business something to reference as the environment changes. That doesn't guarantee a lower premium, because pricing and coverage depend on the insurer and many other factors. What it can do is help the business and its insurance broker answer underwriting questions accurately and demonstrate the controls that are actually in place, which can put the business in a stronger position when seeking or renewing coverage.
Sources and Further Reading
This article provides general information about Microsoft 365 management, cybersecurity, cyber insurance and regulatory considerations. Microsoft licensing, product capabilities, service features, insurance requirements and regulatory requirements can change over time, and the requirements that apply to an individual business depend on its circumstances.




Comments