It looks as though anybody could administer it, and that is the problem
Microsoft 365 has a well-made admin centre: clear, translated, with the buttons in the right place. The consequence is that in a great many companies it ends up run by whoever has time rather than whoever knows how — the owner, the person in accounts who is good with computers, sometimes the business software vendor as a sideline.
It works while there are few people. Then the company grows, staff come and go, shared folders are added, and the configuration layers up exactly the way physical infrastructure does. With one difference: here the layering is invisible, because everything carries on working.
The three things we find in almost every review
Licences paid for people who are no longer there. Disabling an account and removing its licence are two distinct operations, and the second gets forgotten. In a company of thirty people we regularly find between three and six — a recurring cost cut in an afternoon.
Permissions grown by accretion. Somebody asks for access to a folder for a project, it is granted, the project ends and nobody takes it away. Repeated over years, the result is that everyone sees everything. It is not a decision: it is the absence of a review.
Nobody who can say where the files are. Between personal storage, group folders, team spaces and shares created on the fly, the same information exists in three places and the good version cannot be identified. It is also why document assistants and internal search work badly: they are searching a mess.
What we manage
- Accounts and licences — creation, decommissioning, assigning the right licence type to the role, and periodic verification of what is being paid for;
- People joining and leaving — the mailbox ready on day one with the right permissions, and properly closed on the last day, mail rules and devices included;
- Permissions and file structure — designed by role rather than granted on request;
- Migrations — from local mail or another provider, in groups and without stopping work;
- User support — the day-to-day requests, which are most of the volume: a share that will not work, a signature to fix, a new device to set up;
- Environment security — handled separately because it deserves its own space, on the Microsoft 365 security page.
Migrations: the hard part is not the mail
Moving mailboxes is the predictable, well-documented part. What makes migrations fail is everything attached to the mail that nobody puts on the list.
Company signatures, which have to be rebuilt. The sorting rules each person has built up over the years. Shared calendars and the delegations between an assistant and a director. Group mailboxes — info, accounts, orders — which are often the most important and the least documented. Everyone’s mobile devices, which have to be reconfigured one by one. And the applications that send mail in the company’s name: business systems, invoicing, booking systems, which stop working if nobody updates them.
The method we use is by groups, with the two environments coexisting during the transition and an agreed window for the final move. It is slower than moving everything at once, and it does not produce the Monday morning where the company cannot work.
The rest
See also Microsoft 365 security, workstation management of which this is the cloud part, and support contracts for the arrangements and response times.
The first step
A review of the environment: how many licences are genuinely needed, which accounts should be closed, how the permissions stand. The saving on licences alone often pays for the work. Free and without obligation.