Microsoft 365
Microsoft 365 for small business: a plain-English setup checklist
Microsoft 365 is the quiet backbone of most small businesses - email, files, Teams, the lot - and most setups are only half-configured. That's where the trouble starts: mailboxes with no backup, sign-ins with no multi-factor, files scattered across personal OneDrives no one can find when someone leaves. This guide is a plain setup checklist for a small business standing up Microsoft 365 properly, whether you're moving off Gmail, tidying an inherited tenant, or starting fresh. We cover choosing the right licence tier without overpaying, migrating email without losing a message, turning on multi-factor authentication the painless way, organising SharePoint and OneDrive so files have one home, and the backup gap Microsoft doesn't fill for you. Work through it top to bottom and you'll have a setup that's secure, tidy and easy to hand over. Prefer it done for you? That's a job we do most weeks across the Northern Rivers.
Which licence tier you actually need
Microsoft's plan names are deliberately confusing, so start with what you actually use. Business Basic gives you business email, the web and mobile versions of Word, Excel and Outlook, Teams and cloud storage - but no installed desktop apps. Business Standard adds the full desktop Office apps you install on a laptop, which is what most offices want. Business Premium is Standard plus the security and device-management layer - Microsoft Defender, Intune device control and conditional access - that turns a basic setup into a properly protected one.
The honest rule of thumb: if your team lives in installed Word and Outlook, you need Standard as a floor. If you hold client data, handle money, or simply want to sleep at night, Premium is a small step up in price for a large step up in protection, and it is the tier we recommend for most businesses that care about security. Don't reach for the big Enterprise (E3/E5) plans unless you have a specific reason - they are built for large organisations and the Business plans cap out at 300 users, which almost no small business troubles. You can also mix tiers per person: Premium for the owner and finance, Basic for a casual who only needs webmail. Registered charities and schools get heavily discounted or donated licences, so check your eligibility before you pay full price.
Migrating email without losing a message
Email is the part everyone is nervous about, and rightly so - it is the one system a business cannot be without for even an afternoon. The secret is that a clean migration is almost entirely planning. Start by writing down what you actually have: every mailbox, every alias, shared mailboxes like accounts@ or info@, distribution lists, and any calendars people share. That inventory is your checklist for "did everything come across?"
Next, add and verify your domain inside Microsoft 365 (a DNS record proves you own it), then create the users and mailboxes ready and waiting. A day or two before the switch, lower the TTL on your DNS records so the change propagates quickly. Do the actual cutover outside business hours - a Friday evening is ideal - by pointing your domain's MX record at Microsoft only once the new mailboxes exist. For a move from Gmail or another IMAP system, an IMAP migration copies the old mail across; from an existing Exchange server, a cutover migration does the same job. Leave the old system running read-only for a couple of weeks as a safety net, and confirm nothing bounced before you decommission it.
The step that quietly makes or breaks a migration is mail authentication. Set up SPF, DKIM and DMARC records for your domain so the rest of the world trusts mail from you - get these wrong and your invoices start landing in customers' spam folders. If email is genuinely business-critical, this is the one part worth handing to someone who has done it many times.
Turn on MFA the painless way
Multi-factor authentication - a second check beyond your password - blocks the overwhelming majority of account takeovers, and it is the single most valuable thing you can switch on. The reason people avoid it is a fear of constant, annoying prompts. Done well, that fear is unfounded.
Use the free Microsoft Authenticator app with number-matching rather than SMS codes, which can be intercepted or SIM-swapped. Roll it out to everyone in one short session - twenty minutes with the team beats chasing people for a fortnight. New Microsoft 365 tenants can switch on "security defaults", which turns MFA on for everyone at no cost; on Business Premium you get conditional access for finer control, such as trusting the office network so staff aren't prompted every single time. Turn on self-service password reset at the same time so a forgotten password doesn't always land on you, and make sure legacy sign-in protocols are switched off, because they are the back door that lets attackers skip MFA entirely.
SharePoint vs OneDrive
This is the distinction that saves businesses the most grief. OneDrive is personal - it is one person's work drive. SharePoint is shared - it is the business's files, organised into team sites. The classic, costly mistake is letting shared business files live inside an individual's OneDrive, because when that person leaves, their OneDrive is scheduled for deletion and the company's files can vanish or lock up with them.
The rule is simple: if more than one person needs a file, it belongs in SharePoint, not OneDrive. Set up a small number of clearly named SharePoint sites that match how you work - one for Finance, one for Operations, one for a big client - rather than a sprawl no one can navigate. Staff reach those files straight from Teams or a synced folder on their laptop, and "files on-demand" keeps copies in the cloud so laptops don't fill up. Keep OneDrive for genuine personal drafts, and before anyone leaves, make sure their real work has been moved into the shared library where it belongs.
Teams without the chaos
Teams is brilliant and it sprawls fast. Left to grow on its own you end up with forty half-dead "teams", duplicate channels, and notifications everyone has learned to ignore - which defeats the point. A little deliberate structure at the start keeps it useful for years.
Create a small set of Teams that map to how the business actually works - by department or by major project - not one per passing conversation. Agree a simple naming convention so people can find things, and restrict who is allowed to create new teams so the list stays tidy. Let each team's files live in its own SharePoint library rather than being re-uploaded into chats. Then tame the noise: encourage people to set quiet hours, mute channels they only skim, and agree a norm for what belongs in a quick chat versus a channel post. When a project ends, archive its team rather than leaving it to clutter the list. External partners can be added as guests with controlled access when you genuinely need them in the room.
The backup gap Microsoft does NOT cover
Here is the assumption that catches almost everyone: people believe that because their email and files live in Microsoft's cloud, Microsoft is backing them up. It is not, and it does not claim to. Microsoft runs on a shared-responsibility model - they keep the service online and protect their own infrastructure, but recovering your data after an accidental deletion, a ransomware infection, or a departing employee who wipes a folder is squarely your responsibility.
The recycle bin and retention windows are limited - typically weeks, not years - and they are not a backup. Once that window passes, a deleted mailbox or SharePoint library is genuinely gone. The fix is a third-party backup that takes independent, historical copies of your Exchange email, OneDrive, SharePoint and Teams data, with point-in-time restore so you can roll back to how things were before the problem. It is inexpensive, it runs quietly in the background, and it is the single most-missed piece of a Microsoft 365 setup. If you take one action from this whole guide, make it this one.
A one-page handover
Finish by writing down the keys to the kingdom on a single page, because the worst time to go looking for them is the day a key person leaves or something breaks. The essentials: your tenant name, who holds the admin accounts, the login for your domain registrar, the list of licences you pay for, which SharePoint sites hold what, your backup provider and how a restore is actually done, the process for resetting someone's MFA, and an emergency contact.
Store that page somewhere genuinely secure - a password manager or a locked vault - not a Word file on a desktop called "passwords". This one document is what lets you hand the whole setup to a new staff member or a new I.T. partner without a stressful archaeology dig, and it is the mark of a setup that is truly under control rather than merely working for now.