Microsoft 365

Microsoft 365, run by someone who answers

Most small businesses buy Microsoft 365 and then never touch the admin centre again. That is fine until somebody leaves, a mailbox fills up, or you need to prove who has access to what.

Microsoft 365 administration is the work of running the tenant: who has an account, what each person can reach, which licences you are paying for, and whether the security settings match how your business actually works. It covers the initial setup, the day to day changes, and the awkward jobs like taking ownership of a tenant somebody else built.

It is not the same as business email migration, which is the one-time job of moving mailboxes between providers, though the two often happen in the same project. If you are choosing between platforms rather than running one, Google Workspace setup covers the other side of that decision.

What usually goes wrong

The problems we get called about are remarkably consistent, and almost none of them are exotic.

Nobody owns the admin account

The tenant was set up years ago by a contractor, a nephew, or an employee who has since left. The password is unknown, the recovery email points at a dead address, and the business cannot make a change to its own email without a support case. This is the most common and the most expensive to unpick.

Licences drift out of sync with the payroll

People join and leave. Licences get bought and never released. It is normal to find a business paying for accounts belonging to people who left over a year ago, and equally normal to find a former employee whose mailbox still receives customer enquiries because nobody converted it properly.

Everything is set up as a person

Enquiries land in one owner's personal mailbox rather than a shared address, so when they are on holiday the business cannot see its own leads. Shared mailboxes and aliases exist for exactly this and cost nothing extra on most plans.

Security settings were never revisited

Multi-factor authentication was skipped at setup because it was one more thing, and never came back. That single gap is behind a large share of the small business account compromises we get called about, and it is free to turn on.

What running a tenant properly involves

None of this is complicated. It is just work that nobody owns until it is urgent, which is the worst time to do it.

  • Ownership that belongs to the business. A real admin account the business controls, with recovery details recorded somewhere reachable that is not one person's phone.
  • Accounts that match reality. Joiners set up, leavers handled properly, and mailboxes converted rather than deleted when someone goes.
  • Licences you are actually using. A periodic look at what is assigned against who works there. This one frequently pays for the review.
  • Shared addresses for shared jobs. Enquiries, accounts and info should not be a person. They should be an address several people can reach.
  • Multi-factor authentication on, everywhere. Especially on admin accounts. This is the highest-value hour anyone can spend on a small business tenant.
  • Mail authentication that passes. SPF, DKIM and DMARC aligned to the domain, so your mail arrives. See the DNS glossary if those are unfamiliar.
  • A written record. What exists, who has access, and where the recovery details live. Boring, and the thing that saves you when someone leaves.

How we pick this up

  1. Find out what actually exists

    Which tenant, which plan, which accounts, who holds admin, and what is attached to the domain. Often the first genuine inventory the business has ever had.

  2. Establish proper ownership

    Get administrative control back into an account the business owns. If that has been lost entirely, this step involves a recovery process with Microsoft and is worth starting early because it is not instant.

  3. Fix what is urgent

    Usually multi-factor authentication, any leaver whose access is still live, and mail authentication if messages have been going astray.

  4. Tidy the rest

    Licences against actual staff, shared mailboxes where they belong, groups that reflect how the business works rather than how it worked three years ago.

  5. Write it down and hand it over

    You get the record. If you would rather we kept running it, that is what care plans cover, but you own the documentation either way.

Who this is for

  • Businesses on Microsoft 365 with nobody in-house who administers it
  • Owners who cannot say for certain who has access to their email
  • Anyone who inherited a tenant from a previous provider or a departed employee
  • Businesses paying for licences they suspect they no longer need
  • Teams that need shared mailboxes set up so enquiries do not sit in one inbox

When this is not the right fit

  • Large organisations needing full-time internal IT. We are not a substitute for that and would say so.
  • Businesses wanting a bespoke line-of-business application built on the Microsoft stack. That is a different kind of project.
  • Anyone looking for a Microsoft reseller relationship or licensing partner discounts. We administer tenants, we do not resell licences.
  • Businesses perfectly happy on Google Workspace. Switching for its own sake is cost without benefit.

What SolvenceHQ can help with

Setup, takeover, or ongoing administration. Most businesses come to us for one specific problem and stay for the ongoing part, because the tenant is one of those things that only gets attention when it breaks.

  • Initial setup for a business moving onto Microsoft 365
  • Taking ownership of a tenant nobody currently controls
  • User accounts, joiners and leavers handled properly
  • Shared mailboxes, aliases and distribution groups
  • Licence review against who actually works there
  • Multi-factor authentication and the security settings that matter
  • Mailbox migration when you are moving in from another provider
  • Mail authentication so messages are not landing in spam
  • The DNS side, which is where most mail problems actually live

Common questions

What is the difference between Microsoft 365 and Office 365?

Mostly the name. Microsoft renamed most of the Office 365 business plans to Microsoft 365 in 2020, and the branding has been inconsistent ever since. If someone quotes you for "Office 365" today they almost certainly mean the same product.

The part that actually matters is which plan you are on, because that decides whether you get the desktop apps, how much mail storage each person has, and which security controls are even available to you. That is worth checking before you buy anything else.

Do I need Microsoft 365, or is Google Workspace fine?

Both are good. The honest answer is that the better choice is usually the one your business already leans toward. If everyone lives in Excel and your accountant sends desktop spreadsheets, Microsoft 365 removes friction. If your team is browser-first and already on Gmail, Google Workspace is simpler to run.

What we would not do is move you from one to the other because the other is fashionable. A migration costs real time and carries real risk to your mail. There has to be a reason beyond preference.

Can you take over a tenant somebody else set up?

Yes, and it is a common request. The usual situation is that a previous provider, a former employee, or the owner's personal account holds the admin rights, and nobody is certain what the setup actually looks like.

The first job is establishing proper ownership: a real global admin account that belongs to the business rather than a person, with the recovery details recorded somewhere the business controls. Working out what exists and who holds it is technical cleanup, and the two jobs usually run together.

Will moving email cause downtime?

A migration done properly should not lose mail, and the cutover window is normally short. But anyone who tells you a mail migration is risk-free is overselling it. Mail is the thing a business notices within minutes.

The way to keep it boring is preparation: know every mailbox and alias before starting, get the migration sequence right, lower DNS record timings ahead of the switch, and verify authentication after. That last step is what stops the new mail landing in spam.

Who should hold the admin account?

The business. Not us, and not one employee's personal login. We will happily hold administrative access to do the work, but ownership of the tenant should sit with the owner of the business, with recovery details you can reach without going through anybody else.

This is the single most common problem we find. When the person who set it up leaves on bad terms, or a provider relationship ends, the business discovers it cannot get into its own email. It is entirely avoidable and expensive to fix afterwards.

Get a Quote

Not sure what is in your tenant

Most owners are not, and that is the normal starting point rather than an embarrassing one. Tell us what you think you have and we will tell you what is actually there.

Call now Request a quote