top of page

Microsoft 365 Security for Small Business: What Actually Needs to Be Configured

  • Writer: Shay
    Shay
  • Apr 14
  • 21 min read

Updated: Aug 21

Microsoft 365 security for small business - what actually needs to be configured

Updated August 2026: Microsoft 365 has continued to evolve since I originally published this article. I've updated it to reflect the way I currently approach Microsoft 365 security for small businesses, including device management, Microsoft 365 Business Premium, identity and access controls, SharePoint, third-party applications, backup and recovery, and the growing importance of preparing the Microsoft environment for AI.


If your small business already uses Microsoft 365, you may assume Microsoft is taking care of most of the security for you. After all, your email works, employees can open Word and Excel, files are syncing to OneDrive, someone may have created a SharePoint site, and multifactor authentication may already be enabled.

From the owner's perspective, Microsoft 365 is working.


When I review a Microsoft 365 environment, though, I'm looking at a different question: Is it actually configured and managed for the business using it today?

I want to know who has administrator access, how employees authenticate, what computers are accessing company information, whether those computers are centrally managed, who can share files outside the company, which vendors or guests still have access, what third-party applications are connected to the tenant, how email is protected, what happens when an employee leaves, how company information is backed up, and whether the security capabilities the business is already paying for have actually been implemented.


I've reviewed Microsoft 365 environments that had been working for years and still found things the business owner didn't know were there. That doesn't necessarily mean someone originally set the environment up incorrectly. Small-business technology tends to grow with the company. Employees are added, vendors change, new applications are connected, SharePoint sites are created, computers are replaced, and Microsoft continues adding and changing features.

The better question is not simply whether Microsoft 365 works.

Does the Microsoft 365 environment you have today still match the business you have today?

We're a Small Business. Why Would Anyone Target Us?

I hear versions of this question from small-business owners, and I understand why. If you have 10, 20, 30 or 50 employees, it can be difficult to imagine that an attacker would be interested in your company when there are much larger organizations available to target.

An attacker doesn't necessarily need your company to be large. They need an opportunity.


A 20-person construction company, law firm, accounting firm, landscaping company or other professional-services business can still have significant amounts of money and valuable information moving through it. Employees receive invoices by email, communicate with vendors, share documents, handle customer information and make financial decisions.

Small businesses also tend to operate on trust. The employee paying an invoice may personally know the owner who supposedly requested it. A vendor may have worked with the company for years. An unusual request can feel legitimate because it appears to come from someone the employee recognizes.


That trust is one of the things that makes a small business work, but attackers can exploit it.

Business Email Compromise, commonly called BEC, is a good example. An attacker may impersonate an owner, employee or vendor. In other cases, the attacker may gain access to a legitimate email account and monitor conversations until they understand enough about the business to make a fraudulent request believable. That could involve changing payment instructions, redirecting an invoice payment or convincing an employee to release sensitive information.


This is why I don't think the number of employees should determine whether a business needs to take Microsoft 365 security seriously. The more important question is what the business has to lose.


Technology is only part of the answer, too. If a vendor suddenly emails new banking information or an owner appears to request an unusual financial transaction, the business should have a process for verifying that request through another trusted method. Microsoft 365 security can help prevent, detect and limit many of the techniques attackers use, but technology shouldn't replace good business processes.


Why Microsoft 365 Security for Small Business Is More Than Email Security

Microsoft 365 may have originally entered a small business as a way to get professional email and Office applications. For many companies today, it has become a much larger part of the IT environment.


The same Microsoft environment may now contain the company's user identities, email, Teams, OneDrive, SharePoint, authentication controls, endpoint security, device-management policies, external collaboration and connections to third-party applications.

Increasingly, Microsoft 365 is also becoming part of the company's AI environment.

This is especially important for cloud-first businesses that no longer have a traditional server sitting in the office. I sometimes hear variations of, “We don't have servers anymore. Everything is in the cloud.”


The business still has an IT environment. More of that environment has simply moved into the cloud.


An employee can be sitting at home using a laptop to sign into Microsoft 365, access a SharePoint site, download company information, communicate with a vendor and connect to another cloud application without ever touching the company's physical office network.

That changes what I have to protect. Identity, authentication, devices, permissions, applications and data all become part of the security conversation.


We're Only 10, 20, 30 or 50 Employees. Do We Really Need Microsoft 365 Business Premium?

Microsoft 365 Business Premium can sound like something intended for a much larger organization with an internal IT department. I often look at it from the opposite direction.

A company with 20 employees may have 20 or more computers, 20 Microsoft identities, phones and tablets, several SharePoint sites, remote employees, outside vendors, third-party applications and thousands of files containing company, customer or financial information.


Twenty employees doesn't mean there are only twenty things to manage.

A small business also usually doesn't have an internal IT department checking every computer individually. That's one of the reasons centralized management can make so much sense in a smaller environment.


Microsoft 365 Business Premium gives me access to tools such as Microsoft Intune, Microsoft Defender for Business, Defender for Office 365 and Microsoft Entra ID P1 with Conditional Access.


Those product names are important technically, but what matters to a business owner is what they allow me to do.


I can establish consistent security policies across company devices. I can manage supported devices centrally. I can strengthen how employees authenticate. I can create rules around access to company resources. I can improve endpoint and email protection, and I have better tools for connecting the identity of the employee with the device that person is using.


I don't recommend Business Premium simply because a company reaches a certain number of employees. I recommend it when the business needs the security and centralized management capabilities it provides.

A 15-person business can have just as much need to protect its identities, computers, email and company information as a company with hundreds of employees.


How Do I Know All of Our Computers Are Actually Protected?

This is where centralized management becomes much easier to understand.

Imagine a business with 30 laptops. I don't want security to depend on someone manually checking 30 different computers and hoping each one was configured the same way.

I want to be able to determine whether company devices are receiving the policies I've established and whether they meet the security requirements I've defined for the business.

Depending on the environment, those requirements may include BitLocker drive encryption, Microsoft Defender, firewall settings, Secure Boot, current security intelligence and other device compliance requirements.


I also want a consistent process when computer number 31 gets added.

Instead of configuring that computer based on what someone remembers doing six months earlier, I can bring it into the same managed environment and apply the policies I've established for the company.


For some clients, I also use an RMM, or Remote Monitoring and Management solution. An RMM can give me additional capabilities for remote support, hardware and software inventory, monitoring, third-party application management and other day-to-day IT functions.


The important part isn't expecting the business owner to understand the difference between Intune and an RMM. The important part is that I have visibility and management across the environment instead of treating every computer as a separate island.


What About Windows and Software Updates?

Updates are part of this conversation too.

Most business owners understand that computers need updates, but knowing that updates are important and knowing whether every company computer is actually receiving them are two different things.


Centralized management gives me better control and visibility over Windows update policies across supported managed devices. An RMM can complement that by helping me monitor systems and manage third-party applications that also need attention.

Browsers, PDF applications, remote-access software and other third-party programs can all have security vulnerabilities. Keeping Windows current while ignoring the other software employees use every day doesn't give me the complete picture I want.


For a small business without an internal IT department, this is one of the advantages of having the environment actively managed. I don't want to discover six months later that one employee's laptop stopped receiving something important simply because the computer continued to turn on every morning.


We Already Have MFA. Isn't That Enough?

Multifactor authentication, or MFA, is one of the most important security controls I want enabled, but I don't consider “MFA is turned on” to be the end of the identity-security conversation.


I also want to know what authentication methods employees are using, whether older methods are still allowed, which users have administrative privileges, and what should happen when a sign-in doesn't look normal.


Depending on the client's environment, I may implement stronger authentication methods such as passkeys and use Conditional Access to establish additional requirements around access.


Conditional Access is available through Microsoft Entra ID P1, which is included with Business Premium. In business-owner terms, Conditional Access allows me to look beyond whether someone simply knows the password and completed an MFA prompt.

Depending on the requirements of the business, I can consider factors such as the user's authentication, location and the device being used when determining whether access should be allowed.


I've implemented location-based sign-in controls for clients when they made sense for the business. If a company operates entirely within the United States and an employee's account suddenly attempts to authenticate from another country, I want the environment designed to respond according to the policies we've established.

I wouldn't configure that same policy for a company whose employees routinely travel internationally. Security still has to fit the way the business operates.


How Could an Email Account Still Be Compromised If We Have MFA?

This is another reason I don't stop at checking a box that says MFA is enabled.

Attackers have changed their techniques. Phishing can involve fake Microsoft login pages, stolen sessions, convincing MFA prompts and other methods designed to get around the protections users have been taught to expect.

I've worked with businesses after an email account was compromised, and an incident like that can expose weaknesses that weren't obvious while everything appeared to be working normally.


In one environment, an email compromise originating from another country became the reason to look much more broadly at the Microsoft 365 configuration. I strengthened email protections, removed older authentication methods, added domain and user impersonation protections, implemented location-based sign-in controls, introduced passkeys and reviewed the other security controls surrounding the account.

Changing a password after an incident is important. What interests me just as much is what I can change in the environment to make the next attempt more difficult.


Could Someone Pretend to Be Me, an Employee or One of My Vendors?

Email security becomes easier to understand when I explain it in those terms.

I don't expect a business owner to memorize SPF, DKIM and DMARC. Those technical controls matter, and I configure and review them, but the business question behind them is more important.

How difficult are we making it for someone to impersonate this company?


I review SPF, DKIM and DMARC as part of domain and email protection. I also look at anti-phishing controls, user impersonation, domain impersonation and the additional email-security capabilities available through Microsoft Defender for Office 365.

For a business that regularly sends invoices, receives payment instructions or communicates with vendors through email, those controls aren't abstract cybersecurity features. They're part of protecting the way the company conducts business every day.


Can Microsoft Defender Replace the Antivirus We're Already Paying For?

In some environments, yes.

Microsoft 365 Business Premium includes Microsoft Defender for Business for endpoint security. I've moved clients away from separate antivirus products and standardized them on Microsoft Defender when their licensing, security requirements and overall environment made that the better solution.


I don't remove an existing security product simply because Defender appears in the Microsoft license, though. First, I want to make sure the devices are properly onboarded, the appropriate Defender policies are configured, the devices are reporting correctly and the resulting protection meets the client's requirements.


This is also why licensing should be reviewed periodically. If a business is paying Microsoft for security capabilities it isn't using while paying another vendor for overlapping services, I want to understand why.

Sometimes the third-party product should stay. Sometimes consolidation makes sense. The decision should be intentional.


Where Should Our Company Files Live: OneDrive, SharePoint or a Local Server?

There isn't one answer that fits every small business.

I generally think of OneDrive as an individual's working area. Information that belongs to a team or to the business and needs to remain available regardless of whether one particular employee stays or leaves often belongs in an appropriately structured SharePoint environment.


That doesn't mean every traditional file server should automatically be moved to SharePoint.

I work with businesses where SharePoint makes excellent sense for collaboration and company documents. I also work with environments where local servers, virtual machines, databases, QuickBooks or other line-of-business applications still make sense locally.

The question isn't simply whether the cloud is better than a server. I want to understand how the business uses the information and choose the architecture that supports that workflow.


For information that does live in SharePoint, I want the sites, document libraries, security groups and permissions structured intentionally. I don't want years of individual sharing decisions to become the company's long-term security model.


Who Outside Our Company Has Access to Our Files?

This is a question every business using SharePoint should be able to answer.

External sharing isn't automatically a problem. Small businesses legitimately need to collaborate with clients, vendors, accountants, attorneys, subcontractors and other outside organizations.

The important question is whether that access is intentional and still necessary.

When I'm reviewing an environment, I may want to know:

  • Which SharePoint sites allow external sharing.

  • Which vendors, guests and outside users currently have access.

  • Whether they still have a business reason for that access.

  • Whether employees are creating anonymous sharing links.

  • Whether someone has access to an entire site when they only need specific information.

  • Whether sensitive information is stored somewhere external sharing should be more restricted.

  • What happens to vendor access when a project or business relationship ends.

I don't want to disable collaboration simply to make the environment look more secure. I want to make sure the collaboration reflects how the business actually intends to share its information.


What Applications Have Access to Our Microsoft 365 Environment?

This is one of the questions I think small-business owners are least likely to know they should ask.


When an employee signs into a third-party application using a Microsoft business account, that application may request permission to interact with Microsoft 365. Depending on the application and the permissions granted, that can include access to company information.

Microsoft refers to many of these connected applications within Entra as Enterprise Applications.

I've seen why reviewing them matters.

During an actual tenant cleanup, I found an old WordPress-related application authorization even though the business hadn't used WordPress in years. I also found an old QuickBooks authorization after the company had moved away from QuickBooks roughly a year and a half earlier.

The business had moved on. The Microsoft tenant hadn't.


That doesn't automatically mean an old application is malicious. It means I want to understand why it's still there, what permissions it has and whether it still needs access.

I also want to look at how employees are allowed to approve new applications. Cleaning up yesterday's unused applications doesn't solve much if new applications can continually be added without anyone understanding what access they're requesting.


What Happens When an Employee Leaves?

Disabling someone's email account isn't a complete offboarding process.

I want to understand what happens to the employee's identity, email, OneDrive files, company computer, group memberships, SharePoint access and third-party applications. I also want to know whether that employee had administrative privileges, owned important company information or was responsible for sharing information with vendors and clients.

Small businesses often develop informal processes because everyone knows everyone. That can work for a long time, until one important step gets missed.


A defined onboarding and offboarding process gives me a repeatable way to add people correctly when they join and remove their access while preserving company information when they leave.


Does Microsoft Back Up Microsoft 365?

This question deserves more than a simple yes or no.

Microsoft provides native recovery, retention, versioning and recycle-bin capabilities within Microsoft 365. Microsoft also offers Microsoft 365 Backup as a separate service for supported workloads.


The business still needs to decide what its actual recovery requirements are.

How far back might we need to recover information? What happens if something is accidentally deleted? What if an account is compromised? What information needs to be retained? How quickly do we need to recover it? Who is verifying that the backup process is actually working?


For clients using the managed Microsoft 365 backup solution I provide, I monitor the protected backups daily, provide a monthly backup report and perform quarterly tested restores with a report documenting the recovery test.

The restore testing matters to me.

A successful backup job tells me that the backup process ran. A tested restore helps demonstrate that I can actually recover the protected information when it matters.


We Don't Have Servers. Why Do We Need Someone Managing Microsoft 365?

For cloud-first small businesses, this question is becoming increasingly important.

Not having an on-premises server doesn't mean the business no longer has an IT environment. It means more of that environment may now live in Microsoft 365 and other cloud services.


Years ago, it was easier for an owner to visualize the security boundary. There was a server in the office, computers connected to the network and a firewall between the business and the internet.


Today, an employee might be working from home, a hotel or a client's office. The employee signs into Microsoft 365, opens a SharePoint document, sends email, connects to a cloud application and accesses company information without ever touching the physical office network. The boundary changed. Identity, device, data and access have become part of that boundary.


That's why I care about Entra identities, authentication, Conditional Access, Intune, Defender, BitLocker, SharePoint permissions, external sharing and Enterprise Applications.

Those aren't disconnected Microsoft products I'm turning on because they're available. Together, they give me a way to manage a business whose people, devices and information may no longer sit behind one physical firewall.


We Want to Start Using AI. Is Our Microsoft 365 Environment Ready?

This is becoming one of the most important reasons I think businesses should understand their Microsoft 365 environment before introducing more technology into it.

If a company is considering Microsoft 365 Copilot, I don't think the first step should be buying Copilot licenses.


I want to understand what Copilot will be working with.

Are SharePoint permissions correct? Are employees members of groups they no longer need? Are there old sites nobody manages? Is sensitive information overshared? Do former vendors still have access? Are old applications connected to the tenant? Is company information organized in a way that reflects who should actually be able to find and use it?

Copilot and other AI tools can make it easier for employees to find, summarize and work with information they already have permission to access. That makes the quality of the underlying permissions and data governance even more important.

AI doesn't automatically fix permissions that were already too broad.

This is why one of the principles I use when discussing AI with businesses is:

“Responsible AI adoption doesn't start with choosing an AI product. It starts with understanding the business, securing the environment underneath it and then deciding how AI fits into it.” — Shay, SNL Tech Services

For a cloud-first small business, Microsoft 365 may be a significant part of that environment underneath AI. The conversation isn't limited to Microsoft Copilot, either.


Employees may already be using ChatGPT, Claude, Gemini, AI meeting assistants, browser extensions and AI features built into other business applications. Some applications may be connected to company identities or request permission to access company information.


I want the owner to know what AI the company has officially approved, what employees are actually using, what information is being provided to those tools and whether any applications have been connected to the Microsoft environment.

The company's official AI strategy and what employees are actually doing aren't always the same thing.


Why Does Microsoft 365 Need to Be Reviewed Again After It's Configured?

Because neither Microsoft nor the business stands still.

Employees join and leave. Someone changes roles. New computers are purchased. Vendors come and go. SharePoint sites are created. Applications are connected. Security policies are adjusted. AI tools are introduced.


Microsoft changes too. The July 2026 Microsoft 365 licensing changes are a good example. Microsoft changed pricing across parts of its commercial Microsoft 365 lineup and also expanded capabilities included with certain plans. Those kinds of changes can alter the value a business is receiving from the licenses it already owns.

That doesn't mean every company should immediately change plans whenever Microsoft announces something new.


It means licensing should be reviewed instead of treated as a decision that was made once and never needs to be revisited.


I want to know what the business is paying for, what capabilities those licenses include today, what the company is actually using, whether the company is paying separately for overlapping products, and whether the current licensing still makes sense.

The environment changes in smaller ways too. Someone receives temporary permissions that never get removed. A vendor is added to a SharePoint site. An employee connects a new application. A security setting gets changed while troubleshooting. An old account remains active longer than intended.


Over time, those individual changes can create configuration drift, where the environment gradually moves away from the security and management structure that was originally intended. A Microsoft 365 environment that was configured correctly two years ago isn't automatically configured correctly today.


What Should I Be Asking Whoever Manages Our Microsoft 365?

A business owner doesn't need to understand every Microsoft security setting. I do think an owner should be able to get clear answers to some basic questions:

  • Who currently has administrator access to our Microsoft environment?

  • How are employees authenticating?

  • Are our company computers centrally managed, encrypted, protected and receiving updates?

  • What happens when someone tries to access company information from an unexpected location or device?

  • Who outside the company currently has access to our SharePoint information?

  • What third-party applications are connected to our Microsoft 365 environment?

  • What happens to access and company information when an employee or vendor leaves?

  • How is our Microsoft 365 data protected and backed up, and when was the last tested restore?

  • Are we actually using the security capabilities included in the Microsoft licenses we're paying for?

  • If we're considering AI, have we reviewed our data, permissions and connected applications first?


If nobody can answer those questions without spending several days figuring them out, that's useful information by itself.


How Do I Know Whether Our Microsoft 365 Environment Is Configured Correctly?

This is where my Microsoft 365 Audit comes in.

I have a separate article that goes deeper into my Microsoft 365 Tenant Security Review and why I believe periodically reviewing the tenant is important.


The audit gives me a point-in-time view of how the tenant is actually configured today. I'm not looking for ways to turn on every Microsoft feature simply because it exists. I want to understand the business first and then determine whether the technology supports and protects the way that business actually operates.


Depending on the environment, my review may include licensing, identities, administrative privileges, authentication methods, Conditional Access, devices, Intune, Defender, email security, SharePoint and OneDrive, internal permissions, external sharing, guests and vendors, Enterprise Applications, application consent, retention, backup and recovery, onboarding and offboarding, sensitive information, logging and AI readiness.

At the end of the review, I want to be able to explain three things clearly to the owner:

What do you have today?

What concerns me?

What should we change?

If the business wants to move forward, I can also perform the technical remediation necessary to implement the recommendations.

The audit identifies the issues. The remediation is where I fix them.


What If We Don't Even Know What Technology We Have?

Sometimes a Microsoft 365 Audit isn't the right place to start.

If I walk into a business where there isn't a reliable inventory of the computers, network equipment, security products, backups, Microsoft licensing or how those systems fit together, I may recommend starting with my Baseline IT Assessment.


The Baseline IT Assessment gives me a broader view of the technology environment. From there, I can determine whether a deeper Microsoft 365 Audit is needed and how Microsoft 365 fits with the company's computers, network, applications, backup and business workflows.


That distinction matters because Microsoft 365 doesn't operate in isolation. The devices, network, applications, users and processes around it all affect how I ultimately secure and manage the tenant.


Why Would We Continue Having Microsoft 365 Managed After the Audit?

An audit tells us what the environment looks like today. Remediation allows me to correct the issues we identify.


Ongoing management is what helps prevent the environment from slowly becoming another collection of forgotten accounts, old vendor access, unused applications, inconsistent computers and permissions nobody remembers granting.


When I'm managing an environment, I also maintain a run book for the client. That documentation helps me keep track of how the environment is designed, what security controls are in place, why certain decisions were made, how systems and applications are configured, and what needs to be considered before something changes.

The run book gives me a documented baseline to work from. If a policy changes, an application is added, a device is replaced or a workflow changes, I have context for that change instead of treating every request as an isolated IT task.


When Microsoft changes something, I can evaluate how it affects the client. When an employee leaves, I can make the technical changes and document them. When a new computer arrives, I can bring it into the managed environment. When a vendor needs SharePoint access, I can help structure that access appropriately. When a new application needs access to Microsoft 365, I can evaluate what it's requesting. When the company wants to introduce AI, I already understand the environment the AI will be entering.

That's very different from waiting until something goes wrong and then trying to reconstruct years of technology decisions.


Small Business Doesn't Mean Small Risk

A ten-person business doesn't need every security product or enterprise feature available.

It does need a technology environment appropriate for the information, money and operations the business depends on.


That's the distinction I want small-business owners to understand.


I don't recommend Microsoft 365 Business Premium simply because a company has reached a certain number of employees. I recommend it when the business needs the security and centralized management capabilities it provides.

For some companies, the right starting point is a Microsoft 365 Audit. For others, I need to step back and look at the entire technology environment through a Baseline IT Assessment first. Either way, I want to understand what the business has before I start recommending what it should buy.


Microsoft 365 may have started as the place your business gets email and Office applications. For many small businesses today, it has become part of the company's identity system, security platform, device management, file storage, collaboration and increasingly its AI environment.

It should be managed accordingly.


Frequently Asked Questions


Is Microsoft 365 Business Premium overkill for a 10- or 20-person company?

Not necessarily. I look at what the business needs to manage and protect rather than employee count alone. A small company may still need centralized device management, Conditional Access, endpoint protection, stronger email security and better visibility across its environment.

In fact, centralized management can be particularly valuable when the business doesn't have its own internal IT department.


Do All of Our Employees Need Microsoft 365 Business Premium?

Not every Microsoft 365 environment has to use identical licensing for every person. I look at what users do, what information they access, what devices they use and which security and management controls the business needs.

I often prefer standardization where it makes operational and security sense, but licensing should be designed around the business rather than upgraded simply because a higher-tier plan exists.


Is MFA Enough to Protect Microsoft 365?

MFA is extremely important, but I don't treat it as the entire identity-security strategy. Authentication methods, administrative privileges, Conditional Access, devices, email protection and other controls also affect how well the environment is protected.


Can Microsoft Defender Replace Our Current Antivirus?

It can in some environments. Business Premium includes Defender for Business, but I first make sure the client's requirements can be met and that Defender is properly configured, deployed and reporting before removing an existing endpoint-security product.


Do We Need Intune If We're a Small Company?

The answer depends on the environment, but employee count isn't the only consideration.

If a business has company computers accessing company information, centralized device management can give me a consistent way to apply policies, monitor compliance and manage those devices without treating each computer as an independent system.


Should All of Our Files Be Moved Into SharePoint?

Not automatically.

SharePoint works very well for many collaboration and business-document workloads, but some applications and workloads may still make more sense on a local server or another platform. I look at how the business actually works before deciding where the information belongs.


Can Vendors Safely Access SharePoint?

Yes, when external access is intentionally configured and managed.

The important questions are who has access, what they can access, why they need it and how that access will be removed when the business relationship or project ends.


Can Employees Connect Third-Party Applications to Our Microsoft 365 Accounts?

Depending on how application consent is configured, users may be able to authorize applications to access certain Microsoft resources.

This is why I review Enterprise Applications, permissions and application-consent settings as part of the Microsoft environment.


Does Microsoft Back Up Microsoft 365?

Microsoft provides native recovery, retention, versioning and recycle-bin capabilities, and Microsoft also offers a separate Microsoft 365 Backup service.

The more important question is whether the business has a defined recovery strategy that meets its needs and whether anyone is actually testing that recovery process.


Should We Review Microsoft 365 Before Deploying Copilot or Other AI Tools?

I recommend it.

Before introducing AI, I want to understand the data, SharePoint and OneDrive permissions, external sharing, sensitive information, connected applications and other access controls in the environment.

AI can make existing information easier to find and use. That makes getting the underlying permissions and governance right even more important.


Why Do We Need Managed IT If Everything Is in the Cloud?

Cloud services still require identities, devices, permissions, applications, security policies, backups and access to be managed.

Moving away from an on-premises server changes the IT environment. It doesn't eliminate the need to manage one.


What's the Difference Between a Microsoft 365 Audit and a Baseline IT Assessment?

My Microsoft 365 Audit takes a deeper look at the Microsoft tenant itself, including identity, security, devices, email, SharePoint, OneDrive, permissions, external access, applications, backup and other Microsoft 365 controls.


My Baseline IT Assessment looks at the broader technology environment. If a business doesn't have a clear picture of its computers, network, security, backups, applications and Microsoft 365 environment, the Baseline IT Assessment may be the better place to start.


Additional Information & Resources

Microsoft — Microsoft 365 Business Premium SecurityMicrosoft's overview of the security and management capabilities included with Microsoft 365 Business Premium.Microsoft 365 Business Premium Security Overview


Microsoft — Microsoft IntuneInformation about Microsoft's cloud-based endpoint and device-management platform and how it can be used to centrally manage business devices.What Is Microsoft Intune?


Microsoft — Microsoft Entra Conditional AccessMicrosoft's guidance on Conditional Access and using identity, device, location and other signals to control access to company resources.Microsoft Entra Conditional Access Overview


Microsoft — Microsoft Defender for BusinessInformation about Microsoft's endpoint-security platform designed for small and medium-sized businesses.Microsoft Defender for Business Overview


Microsoft — Microsoft Defender for Office 365Information about Microsoft's email and collaboration security capabilities, including protection against phishing and other email-based threats.Microsoft Defender for Office 365 Overview


Microsoft — SharePoint and OneDrive External SharingMicrosoft guidance covering external sharing, guests and collaboration with people outside the organization.SharePoint and OneDrive External Sharing Overview


Microsoft — Enterprise Applications and Application ConsentMicrosoft guidance explaining how users and administrators can grant applications access to Microsoft 365 resources and why application consent should be managed.Application Consent in Microsoft Entra ID


Microsoft — Microsoft 365 BackupMicrosoft's information about Microsoft 365 Backup, supported workloads and recovery capabilities.Microsoft 365 Backup Overview


Microsoft — Preparing SharePoint for Microsoft 365 CopilotMicrosoft guidance covering SharePoint permissions, oversharing, site ownership and preparing organizational information for Microsoft 365 Copilot.Prepare SharePoint for Microsoft 365 Copilot


Microsoft — 2026 Microsoft 365 Pricing and Packaging UpdatesMicrosoft's announcement covering the Microsoft 365 commercial pricing and packaging changes that took effect in July 2026.Microsoft 365 2026 Pricing and Packaging Updates


FBI Internet Crime Complaint Center — Business Email CompromiseInformation about Business Email Compromise, how these scams work and steps businesses can take to reduce their risk.FBI — Business Email Compromise


Comments


bottom of page