Microsoft 365 and Cloud Setup, Explained for Business Owners
By Luis Pambid, Founder of YenkoDev
In a lot of small businesses, Microsoft 365 was set up once, in a hurry, by whoever was available. Email worked, files synced, and nobody looked at it again. The same goes for the cloud account the website or the app runs on. Years later the business has grown, people have joined and left, and the setup is still the one somebody clicked through on day one.
This post explains, in plain words, what a proper setup covers, how a move between systems should be planned, and what you should own at the end. We do this work (Cloud & Microsoft 365 is one of our services), so read it as an explanation from an interested party.
What "set up properly" means
Microsoft 365 and the big cloud platforms work out of the box. That is the problem: out of the box is built to work for everyone, not to protect you. A proper setup is the same tools with the settings chosen on purpose. Four areas matter most.
Who can sign in, and how. Every person should have their own account, protected by a second step at sign-in (a code or an app on their phone), not just a password. Shared logins should go. Accounts for people who have left should be closed the day they leave, not when someone remembers. Microsoft's sign-in system, Entra ID, handles all of this. It can also give staff one sign-in for the other tools you use, which is called single sign-on.
Who can reach what. Over time, access spreads. Someone was given admin rights for one task and kept them. A folder was shared with an outside contact for a project that ended two years ago. A proper setup gives each person what their job needs and nothing more, and makes it easy to see who has what.
Email protection. Email is one of the most common ways attacks start. A proper setup turns on the protections you already pay for, like filtering and warnings on outside senders. It also sets up your domain's email records, so other mail servers can tell your real email from a fake one sent in your name.
Backup. Many owners assume Microsoft keeps a copy of everything forever. It doesn't, at least not in the way most people mean. Deleted items are kept only for a limited time, and a mistake or an attack can wipe files across every synced computer at once. A separate backup, tested by actually restoring something from it, is the only kind that counts.
The cloud your software runs on
If your business runs a website, an app or internal tools, they live on a cloud platform: Microsoft Azure, Amazon Web Services (AWS), Google Cloud, or a simpler hosting service. The same questions about sign-in, access and backup apply there, plus one more: what is it costing you, and why?
Cloud bills tend to creep up. A test server nobody turned off. Storage that only ever grows. A server size picked "to be safe" that is twice what's needed. None of it is dramatic on its own, but together it is money spent every month on nothing. A cost review looks at what is actually used, removes what isn't, sizes the rest to fit, and sets alerts so you hear about the next rise before the invoice arrives.
Moving between systems
Moving email, files or software from one place to another is where setups go wrong in public. A move done well is boring, and that takes planning:
- A written plan first. What moves, in what order, on what date, and who is affected at each step.
- A way back. Before anything moves, there is a tested way to undo it if something goes wrong. A move with no way back is a bet.
- Nothing moves until you say go. You should know the date, and what your staff will notice, in advance.
- Check, then switch off the old one. The old system stays on until the new one has been checked, so nothing is lost in between.
One honest point: not every change pays for itself. If a move or a new setup ends up costing more than it saves, the right call is to say so and roll it back, not to leave you paying for it.
What you should own at the end
This is the part that matters most a few years from now.
Every account, every subscription and every admin login should be in your business's name, not in the name of the person or company who set it up. Every important setting should be written down in plain words, with the reason it was chosen. Any scripts that do routine jobs, like creating accounts for new staff, closing them for leavers or cleaning up old files, should be saved and explained.
The test is simple. If the person who set it up disappeared tomorrow, could someone new take over in a day? If the answer is no, the setup isn't finished, however well it works today.
That is why we treat this as a project with a finish line. It gets set up or moved, made safe, written down and handed back to you, so your own team, or whoever you choose next, can run it without us.
Where to start this week
You can check the basics yourself in an afternoon, with whoever holds the admin login:
- List every admin account in Microsoft 365 and in your cloud platforms. Is each one a real, current person who needs it?
- Check that every account uses a second sign-in step.
- Find the accounts of people who have left. Are they closed?
- Ask where your backup is, and when someone last restored a file from it.
- Look at your last three cloud bills. Can anyone explain every line?
If all five come back clean, you're in good shape. If they don't, you now have a short, honest list of what to fix first, whether you fix it yourselves or bring someone in.
Set up once and never checked?
A few lines is enough: what it should do, who will use it, and any date you're working to. Every brief is read by a senior engineer, the same person who would do the work.