Vai al contenuto

Microsoft 365 support for companies

Licences, mailboxes, permissions and migrations handled by somebody who answers - rather than by whoever has time to try.

In breve

Microsoft 365 looks as though anybody could administer it, and that is exactly why in many companies it ends up run by whoever has time rather than whoever knows how. The typical result is licences paid for people who have left, permissions grown by accretion, and nobody who can say where the files are. Xion handles accounts, licences, permissions, migrations and user support inside a contract with written response times.

Licences get paid for whether or not they are used

In almost every review we find active licences belonging to people who left months ago. That is a cost cut in an afternoon.

Permissions have to be designed

Grown by accretion, they end up giving everyone access to everything. Putting them back in order is the least visible and most useful work.

Somebody who answers

Not a generic support portal: a contract with written response times.

It looks as though anybody could administer it, and that is the problem

Microsoft 365 has a well-made admin centre: clear, translated, with the buttons in the right place. The consequence is that in a great many companies it ends up run by whoever has time rather than whoever knows how — the owner, the person in accounts who is good with computers, sometimes the business software vendor as a sideline.

It works while there are few people. Then the company grows, staff come and go, shared folders are added, and the configuration layers up exactly the way physical infrastructure does. With one difference: here the layering is invisible, because everything carries on working.

The three things we find in almost every review

Licences paid for people who are no longer there. Disabling an account and removing its licence are two distinct operations, and the second gets forgotten. In a company of thirty people we regularly find between three and six — a recurring cost cut in an afternoon.

Permissions grown by accretion. Somebody asks for access to a folder for a project, it is granted, the project ends and nobody takes it away. Repeated over years, the result is that everyone sees everything. It is not a decision: it is the absence of a review.

Nobody who can say where the files are. Between personal storage, group folders, team spaces and shares created on the fly, the same information exists in three places and the good version cannot be identified. It is also why document assistants and internal search work badly: they are searching a mess.

What we manage

Migrations: the hard part is not the mail

Moving mailboxes is the predictable, well-documented part. What makes migrations fail is everything attached to the mail that nobody puts on the list.

Company signatures, which have to be rebuilt. The sorting rules each person has built up over the years. Shared calendars and the delegations between an assistant and a director. Group mailboxes — info, accounts, orders — which are often the most important and the least documented. Everyone’s mobile devices, which have to be reconfigured one by one. And the applications that send mail in the company’s name: business systems, invoicing, booking systems, which stop working if nobody updates them.

The method we use is by groups, with the two environments coexisting during the transition and an agreed window for the final move. It is slower than moving everything at once, and it does not produce the Monday morning where the company cannot work.

The rest

See also Microsoft 365 security, workstation management of which this is the cloud part, and support contracts for the arrangements and response times.

The first step

A review of the environment: how many licences are genuinely needed, which accounts should be closed, how the permissions stand. The saving on licences alone often pays for the work. Free and without obligation.

Frequently asked questions

How many Microsoft 365 licences are we actually paying for?

It is the first thing we check and it almost always produces a surprise. Licences stay assigned to people who have left the company because disabling an account and removing its licence are two different operations, and the second gets forgotten. In a company of thirty people we regularly find between three and six licences being paid for inactive mailboxes.

What happens to the mailbox of someone who leaves?

It has to be handled explicitly, and the options differ depending on what is needed. If the mail has to stay consultable it can be converted to a shared mailbox, which consumes no licence; if it only has to be retained for obligations it can be archived. What should not happen is leaving it active and licensed, which is the most common situation and the worst on both cost and security.

Can we migrate mail without stopping the company?

Yes, and that is how we work. Migrations are done in groups, with old and new mail coexisting during the transition and an agreed window for the final move. The part that needs most attention is not the mail itself but everything attached to it - signatures, rules, shared calendars, group mailboxes, mobile devices.

Who manages permissions on shared files?

In most companies nobody, which is why over time everyone ends up seeing everything. Permissions have to be designed by role and reviewed periodically, otherwise they grow by accretion - somebody asks for access to a folder, it is granted, and nobody ever takes it away.

Do we need a contract or can we call when we need to?

Both are possible. The practical difference is that with a contract there are written response times and somebody looking at the environment even when you are not calling - licences, dormant accounts, security notices. On a call-out basis, problems get fixed; under contract, they get caught first.

Is your Microsoft 365 configured properly?

Almost every tenant starts with default settings that leave open what nobody uses. Let us look at how yours is set up.