How a tenant engagement runs
Most Microsoft 365 work starts with a tenant that already exists and grew without a plan: licenses bought one at a time, SharePoint sites created by whoever needed one, a handful of global admins nobody remembers granting, and security settings that were never turned on. The first step is an audit, not a proposal.
Audit. We pull the license inventory against actual usage, the admin roles, the sharing settings, the mail flow rules, the conditional access policies or the absence of them, and the SharePoint and Teams sprawl. You get a written report of what is configured, what is paid for and unused, and what is exposed.
Rebuild. We fix the tenant in place. Unused licenses come off. Admin roles get trimmed to the people who need them, with MFA enforced. Security tooling that Business Premium already includes gets turned on: Defender for Office 365 on mail, Defender for Business on endpoints, conditional access on sign-in. SharePoint gets restructured around how your team shares files, typically a small number of hub sites by department or client, with permissions that follow the structure rather than fighting it.
Document and maintain. Everything is written down, and then the tenant is maintained on an ongoing basis: policy adjustments as Microsoft changes things, new hires provisioned through Intune so a laptop arrives configured, and quarterly license reviews so spend tracks headcount.
License rightsizing, specifically
The two common mistakes are paying for E5 or E3 features that nobody uses, and paying full per-user prices for shared mailboxes that need no license at all. Our quarterly license review catches both. Most clients save 15 to 30 percent on Microsoft licensing in the first quarter, and after the July 2026 price increase the review matters more than it did. We are a Cloud Solution Provider partner, so licenses can come through us on one bill, but we will tell you when buying direct from Microsoft is the better deal for your situation.
Migrations
From Google Workspace. Mail, calendars, contacts, Drive, and shared drives move over two to four weeks depending on data volume. Staff keep working in Google until a cutover weekend, after which Outlook and OneDrive are live and the old environment stays readable for a defined window. We have run this for teams from 10 to 200 users.
From an older tenant or on-prem Exchange. Tenant-to-tenant moves after an acquisition, or the last Exchange server in a closet, follow the same shape: inventory, pilot group, staged cutover, decommission.
Migrations are quoted as flat project fees, not hourly, so a slow weekend is our problem rather than your invoice.
Intune and the new-hire laptop
With Intune configured, a new hire’s laptop ships from the vendor to their desk, they sign in with their work account, and policies, apps, Wi-Fi, and security settings arrive without anyone touching the machine. When they leave, the device is wiped remotely. Personal phones get the lighter version: only the work apps are managed, and only the work data is removed when someone leaves or loses the phone. Our guide on company devices versus personal phones explains the split in plain English. For a New York firm with staff split between the office, home, and client sites, this is the difference between managing devices and hoping about them.
Who this is for
Businesses with 10 to 150 users on Microsoft 365 Business Premium or above. We require Business Premium at minimum because it includes the security tooling that makes the rest of this work. We will not build a tenant on Business Basic and call it secured. Tenant work is included in every managed IT support tier, and it is also the most common thing internal IT leads hand us under co-managed IT. If you are on Google Workspace and plan to stay there, we support that too, and we will scope it on the discovery call.