First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 New Tenant Setup for Small Business
Implementation

Microsoft 365 New Tenant Setup for Small Business

Microsoft 365 New Tenant Setup for Small Business is a fixed-price, three-day engagement that takes a small organization from nothing — or from a half-configured trial — to a working, sensibly secured Microsoft 365 tenant: tenant created and named, your custom domain verified with DNS done right, users, groups, and shared mailboxes provisioned, Exchange Online, Teams, SharePoint, and OneDrive configured with defaults that fit a small business, a security starter baseline applied (MFA for everyone, protected admin accounts, legacy sign-in methods off), and an admin handover document that tells whoever runs it next exactly what was set up and why. It is designed for organizations up to about 50 seats that are starting fresh; if you have existing email to move, that is a migration and we scope it alongside this setup.

Timeline 3 daysService owner Roman SotnikMicrosoft 365Exchange OnlineMicrosoft Entra ID

What this engagement is

Setting up Microsoft 365 for a business looks simple — Microsoft's own wizard will happily walk you through it — and that is exactly how small companies end up with the problems we get called to fix a year later: the tenant registered under a personal email address, a misspelled or throwaway onmicrosoft.com name that can never be changed, DNS records half-published so mail intermittently bounces, everyone working out of one shared admin login, no MFA, and files scattered between personal OneDrives because nobody decided where company documents live. None of those are hard to avoid on day one. All of them are expensive to unwind later. This engagement is the day-one done right. We create the tenant (or take over the trial or auto-created tenant you already have), verify your custom domain, and publish the DNS records Microsoft 365 actually needs — MX, SPF, autodiscover, and DKIM signing for your domain, not just the minimum the wizard suggests. We provision your users, groups, distribution lists, and shared mailboxes with a naming convention you approve. We configure Exchange Online, Microsoft Teams, SharePoint Online, and OneDrive with small-business-appropriate defaults — including OneDrive Known Folder Move, so the Desktop and Documents folders on your PCs back themselves up to the cloud without anyone thinking about it. And we apply a security starter baseline: multi-factor authentication for every user, a separate protected emergency-access admin account, no day-to-day work in admin roles, legacy authentication protocols disabled, and auditing on. Licensing is your choice, transparently. As a Microsoft direct-bill Cloud Solution Provider we can provision your subscriptions and bill them at Microsoft's published list price — the same price as buying direct from Microsoft; our margin comes from Microsoft, not from a markup on you — and you can move that billing to another partner, or back to Microsoft, at any time under Microsoft's own transfer process. Or bring subscriptions you already purchased elsewhere; the setup work is identical. We will recommend the right plan for your size and needs and tell you honestly when the cheaper one is enough. Who this is for: startups, newly formed entities, and small businesses up to about 50 seats buying Microsoft 365 for the first time. If you are larger, run hybrid Active Directory, or carry regulatory requirements, the same discipline applies but the scope does not fit three days — start with the free discovery session and we will scope the right engagement instead. If you have existing email and files at Google Workspace, GoDaddy, an IMAP host, or another Microsoft 365 tenant, the move itself is separate migration work that we quote alongside this setup so the two land as one plan. Pricing is fixed: $950 per project, quoted in writing before work begins, and you pay after you approve delivery.

Success criteria

01The Microsoft 365 tenant exists with an agreed, correctly spelled tenant name and onmicrosoft.com domain, registered to a company-controlled identity — not an employee's personal mailbox.
02Your custom domain is verified, set as the default domain, and all required DNS records (MX, SPF, autodiscover CNAME, and DKIM) are published and verified as resolving correctly.
03Every agreed user account is created with the approved naming convention, licensed, and able to sign in; agreed groups, distribution lists, and shared mailboxes exist and receive mail.
04Mail flow is verified in both directions: messages to and from external addresses (including Gmail and a second external system) deliver without going to junk, and DKIM signing passes for your domain.
05Multi-factor authentication is enforced for every user and admin, a separate emergency-access admin account exists with credentials handed to the owner, and no user account holds standing Global Administrator rights for daily work.
06Legacy authentication protocols are disabled, and mailbox and tenant auditing are confirmed on.
07Teams, SharePoint, and OneDrive open and work for a test user, the agreed company document library exists, and OneDrive Known Folder Move is configured for rollout to your PCs.
08The admin handover document is delivered and walked through with your designated contact: every setting we changed, the credentials that matter, and the first-90-days checklist.

What you receive

Tenant provisioning or takeover: creation of the tenant (or assessment and cleanup of an existing trial/auto-created tenant), tenant naming, organization profile, and technical contact details set to company-controlled identities.
Custom domain verification and full DNS configuration for Microsoft 365: MX, SPF, autodiscover, and DKIM records published at your DNS host, with a record of every entry and why it is there.
Licensing recommendation and provisioning: a plain-language comparison of the plans that fit your size, subscriptions provisioned through our direct-bill CSP at Microsoft's published list price or assignment of licenses you bought elsewhere.
User and group provisioning: up to 50 user accounts with an agreed naming convention, plus agreed security groups, distribution lists, aliases, and shared mailboxes.
Exchange Online configuration: mailbox defaults, shared mailbox access and send-as rights, anti-spam and anti-phishing policy review, and mail flow verification in both directions.
Security starter baseline: MFA enforced for all users and admins (via security defaults or Conditional Access, matching your licensing), a documented emergency-access admin account, admin role separation, legacy authentication disabled, and auditing verified on.
Teams, SharePoint, and OneDrive initial configuration: team and site structure agreed and created for company documents, sensible external-sharing defaults, and OneDrive Known Folder Move policy configured.
Admin handover document: every configured setting with its reasoning, license and billing summary, emergency-access procedure, and a first-90-days checklist — plus a one-hour handover walkthrough with your designated admin or owner.

How the work unfolds

Day 1 — Foundation: tenant, domain, licensing

Kickoff call to confirm the decisions that are hard to change later: tenant name, naming conventions, plan selection, and who owns what. Then tenant creation or takeover, custom domain verification, DNS records published, and licensing provisioned. DNS propagation starts today for a reason — it is the one step on the critical path we do not control.

Day 2 — People and workloads

Users, groups, distribution lists, and shared mailboxes created and licensed. Exchange Online, Teams, SharePoint, and OneDrive configured to the agreed structure, DKIM enabled and verified, and the security baseline applied: MFA rollout, admin account separation, legacy authentication off.

Day 3 — Verification and handover

End-to-end verification: sign-in, mail flow in both directions, deliverability checks, Teams/SharePoint/OneDrive access as a test user, and Known Folder Move behavior confirmed. Handover document finalized and walked through with your admin contact, including the emergency-access procedure and the first-90-days checklist.

Prerequisites

A decision-maker available for the Day 1 kickoff — tenant name, domain, plan choice, and naming conventions need answers from an owner, not from us guessing.
Access to your domain's DNS management (registrar or DNS host credentials, or a person who can apply our changes same-day); DNS turnaround is what keeps the three-day schedule honest.
Ownership of the domain you want to use for email. If you have not registered one yet, do that first — we can advise on the choice but domain purchase is yours.
The user list: names, desired email addresses, and roles, plus which shared mailboxes and groups you want (we provide a simple template to fill in).
A payment method for Microsoft subscriptions — through our CSP billing or your own Microsoft billing profile if you bought direct.
If a trial or auto-created tenant already exists (someone signed up to test, or a vendor created one), the credentials for it — takeover and cleanup is in scope; running two accidental tenants is how identity problems start.
Each user available for about ten minutes during rollout to complete MFA registration on their phone.
A designated admin contact — the person who will own the tenant day-to-day, even part-time — to receive the handover.

Who does what

IT Partner

  • Run the kickoff and capture the foundation decisions in writing before configuring anything.
  • Create or take over the tenant and configure it to the documented baseline.
  • Publish (or hand to your DNS person, ready to paste) every required DNS record, and verify each resolves before relying on it.
  • Provision licensing at Microsoft's published list price through our CSP, or assign the licenses you provide.
  • Create all agreed users, groups, distribution lists, and shared mailboxes to the approved naming convention.
  • Apply and verify the security starter baseline, and document the emergency-access procedure.
  • Configure Exchange, Teams, SharePoint, and OneDrive defaults, including Known Folder Move policy.
  • Verify mail flow and sign-in end-to-end, deliver the handover document, and conduct the handover walkthrough.

Your team

  • Make the Day 1 decisions: tenant name, domain, plan, naming conventions, and document structure.
  • Provide DNS access or apply requested DNS changes same-day.
  • Provide the completed user and group list, and confirm it before provisioning.
  • Ensure users complete MFA registration during the rollout window.
  • Store the emergency-access admin credentials securely as instructed — they are the keys to the tenant.
  • Designate the admin contact and attend the handover walkthrough.
  • Review deliverables and approve acceptance against the published success criteria.
  • Own ongoing administration after handover, or engage ongoing help separately if you would rather not.

What's not included

Email, file, or data migration from any existing system — Google Workspace, GoDaddy, IMAP hosts, POP mailboxes, another Microsoft 365 tenant, or PST files. That is the migration family, quoted alongside this setup whenever you have existing data.
Device management and enrollment — configuring Intune, Windows Autopilot, or company policies on laptops and phones is Microsoft Intune Initial Setup; we install nothing on end-user devices in this engagement beyond verifying Known Folder Move behavior.
Ongoing administration after handover — user changes, support requests, and month-two questions belong to Microsoft 365 Administrator On Demand, which picks up exactly where the handover document ends.
Security hardening beyond the starter baseline — Conditional Access design, Defender for Office 365 tuning, DLP, and Secure Score remediation are the separate Microsoft 365 Security Baseline and Secure Score Remediation engagement; this setup makes you sensibly secure, not compliance-ready.
Microsoft subscription costs — licenses are billed at Microsoft's published list price and are separate from the $950 service fee.
Domain registration and website or web-hosting changes — we publish the Microsoft 365 records at your DNS host and leave your website records untouched.
Custom email signatures, workflow automation, phone systems, and line-of-business app integrations — all available as separate engagements once the foundation exists.

Limitations & technical notes

!The onmicrosoft.com tenant name is permanent — Microsoft provides no way to rename it after creation. It is the first decision we confirm in writing at kickoff, because it is the only one that can never be revisited.
!The three-day schedule assumes same-day DNS changes and your user list confirmed by Day 1. DNS propagation and registrar delays are the usual stretch factors, which is why DNS access is a listed prerequisite.
!The engagement covers up to 50 users. It is not a hard technical limit — it is where honest scoping ends: above that size, or with hybrid Active Directory or regulatory requirements in play, a three-day fixed package would be underscoping your setup, and we will say so at the discovery call rather than after.
!MFA enforcement uses security defaults or Conditional Access depending on the licensing you choose; we implement the strongest option your plan supports and document which one you got and why.
!The security starter baseline is a floor, not a ceiling: it makes a new tenant sensibly secure for a small business. It is not a compliance framework, an audit, or a substitute for the deeper hardening some industries need — the handover document flags what a next step would look like if you need one.
!New tenants and licensing offers change on Microsoft's schedule, not ours; plan recommendations reflect Microsoft's lineup at engagement time. Technical content reviewed August 2026.

Frequently asked questions

Can't we just do this ourselves with Microsoft's setup wizard?

You can, and the wizard has gotten genuinely good at the happy path. What it does not do is make the judgment calls: a tenant name you will not regret (it is permanent), an admin structure that is not one shared login, MFA actually enforced rather than suggested, DKIM enabled for your domain, sharing defaults that fit how a small company works, and a decision about where company files live before people invent their own answer. The $950 is not for clicking through the wizard — it is for the hundred small decisions being made by someone who has cleaned up the wrong versions of them for years.

Do we have to buy our Microsoft licenses through you?

No. If we provision them, you pay Microsoft's published list price — the same price as buying direct, because our margin comes from Microsoft, not from a markup on you — and billing through us gets you a partner who can see and fix subscription problems. But the setup work is identical if you bring licenses bought from Microsoft or anywhere else. And there is no lock-in in either direction: Microsoft's own CSP transfer process lets you move your subscriptions to another partner, or back to Microsoft, at any time, and we do not and cannot block it.

Which Microsoft 365 plan should we pick?

For most small businesses the honest shortlist is Microsoft 365 Business Basic (web apps and email), Business Standard (adds desktop Office apps), and Business Premium (adds the security and device-management features we would rather you had). Business plans cap at 300 users, which is not a constraint at your size. Part of Day 1 is a plain-language recommendation against what you actually do — and we will tell you when the cheaper plan is enough: nobody at IT Partner earns a commission, so no one's pay goes up when your license bill does.

We already have email at Google Workspace / GoDaddy / an old provider. Does this service move it?

No — moving existing mail, contacts, calendars, and files is migration work with its own scope and price, and pretending it fits inside a $950 setup would shortchange both jobs. What we do instead: quote the right migration alongside this setup so you approve one coherent plan — new tenant built properly, then your data moved into it, in the right order. If your Microsoft 365 lives inside GoDaddy's reseller wrapper, there is a dedicated defederation and takeover service for that specific situation.

Someone here already started a trial tenant. Is that a problem?

Usually not, and it is common — someone signs up to test, or a vendor auto-creates a tenant while provisioning another product. Give us the credentials and Day 1 includes assessing it: if the tenant name is acceptable, we clean it up and build on it; if the name is wrong (misspelled, personal, or a placeholder), we will tell you before anything is built on it, because the onmicrosoft.com name is the one thing that can never be changed. What we want to avoid is the two-accidental-tenants situation, which is genuinely painful to merge later.

What exactly is in the 'security starter baseline' — and what isn't?

In: MFA enforced for every user and admin, a separate documented emergency-access admin account, no daily work in Global Administrator roles, legacy authentication protocols disabled, DKIM signing for your domain, auditing on, and external-sharing defaults set deliberately rather than left wide open. Not in: Conditional Access policy design, Defender for Office 365 tuning, data loss prevention, backup, or compliance work — those are real engagements of their own, and the security baseline service is the natural next step when you are ready. We draw this line clearly because 'secure' claims without a scope are how vendors overpromise.

How fast will our email actually work?

Sign-in and internal mail work as soon as accounts exist — Day 1 or 2. External mail depends on DNS: records usually propagate within hours, occasionally up to a day or two depending on your registrar and old record TTLs. The three-day plan sequences DNS first for exactly that reason, and we verify both directions of mail flow — including deliverability checks so your first invoice does not land in a customer's junk folder — before we call it done.

What is Known Folder Move and why do you include it?

It points each PC's Desktop, Documents, and Pictures folders at OneDrive, so the files people inevitably save there are synced to the cloud automatically. For a small business without a server it is the single cheapest insurance against a dead laptop taking the only copy of something important. We configure the policy tenant-side and verify the behavior; it then applies as your users sign in to OneDrive on their machines.

Who runs the tenant after you hand it over?

You do — and the handover is designed to make that realistic for a non-specialist: a document listing every setting we changed and why, the emergency-access procedure, and a first-90-days checklist, walked through live with your designated contact. When you would rather not own it, Microsoft 365 Administrator On Demand provides ongoing admin help without a full-time hire, and it starts from the same handover document, so nothing is lost in translation.

Can you also set up our laptops and phones?

Not inside this engagement — device management done properly means Intune: enrollment, compliance policies, app deployment, and (for Windows) Autopilot so new laptops configure themselves. That is the separate Microsoft Intune Initial Setup family, and Business Premium licensing (which we may well have recommended on Day 1) already includes the Intune licenses it needs. This setup gets the tenant right so that device management has something solid to attach to.

We're bigger than 50 seats — or we have an on-premises Active Directory. Is this still the right service?

Probably not this exact package, and we would rather tell you now than discover it on Day 2. Above roughly 50 seats, or with hybrid AD, directory synchronization, or compliance requirements in scope, setup stops being a three-day fixed project. Book the free discovery session and we will scope what your situation actually needs — the same day-one discipline, sized honestly.

How do we order, and is any of this handled by AI?

You start with the free discovery call or a quote request, and the quote arrives in writing with the fixed price and pay-after-approval terms. Our AI tools may prepare a quote — clearly labeled as such — but no order is executed by an AI: every order is confirmed and closed by a human, and the work is delivered by our engineers. You pay after you approve delivery.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$950 per project
3 days
Book a free discovery call