Microsoft 365 New Tenant Setup for Small Business
Microsoft 365 New Tenant Setup for Small Business is a fixed-price, three-day engagement that takes a small organization from nothing — or from a half-configured trial — to a working, sensibly secured Microsoft 365 tenant: tenant created and named, your custom domain verified with DNS done right, users, groups, and shared mailboxes provisioned, Exchange Online, Teams, SharePoint, and OneDrive configured with defaults that fit a small business, a security starter baseline applied (MFA for everyone, protected admin accounts, legacy sign-in methods off), and an admin handover document that tells whoever runs it next exactly what was set up and why. It is designed for organizations up to about 50 seats that are starting fresh; if you have existing email to move, that is a migration and we scope it alongside this setup.
What this engagement is
Setting up Microsoft 365 for a business looks simple — Microsoft's own wizard will happily walk you through it — and that is exactly how small companies end up with the problems we get called to fix a year later: the tenant registered under a personal email address, a misspelled or throwaway onmicrosoft.com name that can never be changed, DNS records half-published so mail intermittently bounces, everyone working out of one shared admin login, no MFA, and files scattered between personal OneDrives because nobody decided where company documents live. None of those are hard to avoid on day one. All of them are expensive to unwind later. This engagement is the day-one done right. We create the tenant (or take over the trial or auto-created tenant you already have), verify your custom domain, and publish the DNS records Microsoft 365 actually needs — MX, SPF, autodiscover, and DKIM signing for your domain, not just the minimum the wizard suggests. We provision your users, groups, distribution lists, and shared mailboxes with a naming convention you approve. We configure Exchange Online, Microsoft Teams, SharePoint Online, and OneDrive with small-business-appropriate defaults — including OneDrive Known Folder Move, so the Desktop and Documents folders on your PCs back themselves up to the cloud without anyone thinking about it. And we apply a security starter baseline: multi-factor authentication for every user, a separate protected emergency-access admin account, no day-to-day work in admin roles, legacy authentication protocols disabled, and auditing on. Licensing is your choice, transparently. As a Microsoft direct-bill Cloud Solution Provider we can provision your subscriptions and bill them at Microsoft's published list price — the same price as buying direct from Microsoft; our margin comes from Microsoft, not from a markup on you — and you can move that billing to another partner, or back to Microsoft, at any time under Microsoft's own transfer process. Or bring subscriptions you already purchased elsewhere; the setup work is identical. We will recommend the right plan for your size and needs and tell you honestly when the cheaper one is enough. Who this is for: startups, newly formed entities, and small businesses up to about 50 seats buying Microsoft 365 for the first time. If you are larger, run hybrid Active Directory, or carry regulatory requirements, the same discipline applies but the scope does not fit three days — start with the free discovery session and we will scope the right engagement instead. If you have existing email and files at Google Workspace, GoDaddy, an IMAP host, or another Microsoft 365 tenant, the move itself is separate migration work that we quote alongside this setup so the two land as one plan. Pricing is fixed: $950 per project, quoted in writing before work begins, and you pay after you approve delivery.
Success criteria
What you receive
How the work unfolds
Kickoff call to confirm the decisions that are hard to change later: tenant name, naming conventions, plan selection, and who owns what. Then tenant creation or takeover, custom domain verification, DNS records published, and licensing provisioned. DNS propagation starts today for a reason — it is the one step on the critical path we do not control.
Users, groups, distribution lists, and shared mailboxes created and licensed. Exchange Online, Teams, SharePoint, and OneDrive configured to the agreed structure, DKIM enabled and verified, and the security baseline applied: MFA rollout, admin account separation, legacy authentication off.
End-to-end verification: sign-in, mail flow in both directions, deliverability checks, Teams/SharePoint/OneDrive access as a test user, and Known Folder Move behavior confirmed. Handover document finalized and walked through with your admin contact, including the emergency-access procedure and the first-90-days checklist.
Prerequisites
Who does what
IT Partner
- Run the kickoff and capture the foundation decisions in writing before configuring anything.
- Create or take over the tenant and configure it to the documented baseline.
- Publish (or hand to your DNS person, ready to paste) every required DNS record, and verify each resolves before relying on it.
- Provision licensing at Microsoft's published list price through our CSP, or assign the licenses you provide.
- Create all agreed users, groups, distribution lists, and shared mailboxes to the approved naming convention.
- Apply and verify the security starter baseline, and document the emergency-access procedure.
- Configure Exchange, Teams, SharePoint, and OneDrive defaults, including Known Folder Move policy.
- Verify mail flow and sign-in end-to-end, deliver the handover document, and conduct the handover walkthrough.
Your team
- Make the Day 1 decisions: tenant name, domain, plan, naming conventions, and document structure.
- Provide DNS access or apply requested DNS changes same-day.
- Provide the completed user and group list, and confirm it before provisioning.
- Ensure users complete MFA registration during the rollout window.
- Store the emergency-access admin credentials securely as instructed — they are the keys to the tenant.
- Designate the admin contact and attend the handover walkthrough.
- Review deliverables and approve acceptance against the published success criteria.
- Own ongoing administration after handover, or engage ongoing help separately if you would rather not.
What's not included
Limitations & technical notes
Frequently asked questions
Can't we just do this ourselves with Microsoft's setup wizard?
You can, and the wizard has gotten genuinely good at the happy path. What it does not do is make the judgment calls: a tenant name you will not regret (it is permanent), an admin structure that is not one shared login, MFA actually enforced rather than suggested, DKIM enabled for your domain, sharing defaults that fit how a small company works, and a decision about where company files live before people invent their own answer. The $950 is not for clicking through the wizard — it is for the hundred small decisions being made by someone who has cleaned up the wrong versions of them for years.
Do we have to buy our Microsoft licenses through you?
No. If we provision them, you pay Microsoft's published list price — the same price as buying direct, because our margin comes from Microsoft, not from a markup on you — and billing through us gets you a partner who can see and fix subscription problems. But the setup work is identical if you bring licenses bought from Microsoft or anywhere else. And there is no lock-in in either direction: Microsoft's own CSP transfer process lets you move your subscriptions to another partner, or back to Microsoft, at any time, and we do not and cannot block it.
Which Microsoft 365 plan should we pick?
For most small businesses the honest shortlist is Microsoft 365 Business Basic (web apps and email), Business Standard (adds desktop Office apps), and Business Premium (adds the security and device-management features we would rather you had). Business plans cap at 300 users, which is not a constraint at your size. Part of Day 1 is a plain-language recommendation against what you actually do — and we will tell you when the cheaper plan is enough: nobody at IT Partner earns a commission, so no one's pay goes up when your license bill does.
We already have email at Google Workspace / GoDaddy / an old provider. Does this service move it?
No — moving existing mail, contacts, calendars, and files is migration work with its own scope and price, and pretending it fits inside a $950 setup would shortchange both jobs. What we do instead: quote the right migration alongside this setup so you approve one coherent plan — new tenant built properly, then your data moved into it, in the right order. If your Microsoft 365 lives inside GoDaddy's reseller wrapper, there is a dedicated defederation and takeover service for that specific situation.
Someone here already started a trial tenant. Is that a problem?
Usually not, and it is common — someone signs up to test, or a vendor auto-creates a tenant while provisioning another product. Give us the credentials and Day 1 includes assessing it: if the tenant name is acceptable, we clean it up and build on it; if the name is wrong (misspelled, personal, or a placeholder), we will tell you before anything is built on it, because the onmicrosoft.com name is the one thing that can never be changed. What we want to avoid is the two-accidental-tenants situation, which is genuinely painful to merge later.
What exactly is in the 'security starter baseline' — and what isn't?
In: MFA enforced for every user and admin, a separate documented emergency-access admin account, no daily work in Global Administrator roles, legacy authentication protocols disabled, DKIM signing for your domain, auditing on, and external-sharing defaults set deliberately rather than left wide open. Not in: Conditional Access policy design, Defender for Office 365 tuning, data loss prevention, backup, or compliance work — those are real engagements of their own, and the security baseline service is the natural next step when you are ready. We draw this line clearly because 'secure' claims without a scope are how vendors overpromise.
How fast will our email actually work?
Sign-in and internal mail work as soon as accounts exist — Day 1 or 2. External mail depends on DNS: records usually propagate within hours, occasionally up to a day or two depending on your registrar and old record TTLs. The three-day plan sequences DNS first for exactly that reason, and we verify both directions of mail flow — including deliverability checks so your first invoice does not land in a customer's junk folder — before we call it done.
What is Known Folder Move and why do you include it?
It points each PC's Desktop, Documents, and Pictures folders at OneDrive, so the files people inevitably save there are synced to the cloud automatically. For a small business without a server it is the single cheapest insurance against a dead laptop taking the only copy of something important. We configure the policy tenant-side and verify the behavior; it then applies as your users sign in to OneDrive on their machines.
Who runs the tenant after you hand it over?
You do — and the handover is designed to make that realistic for a non-specialist: a document listing every setting we changed and why, the emergency-access procedure, and a first-90-days checklist, walked through live with your designated contact. When you would rather not own it, Microsoft 365 Administrator On Demand provides ongoing admin help without a full-time hire, and it starts from the same handover document, so nothing is lost in translation.
Can you also set up our laptops and phones?
Not inside this engagement — device management done properly means Intune: enrollment, compliance policies, app deployment, and (for Windows) Autopilot so new laptops configure themselves. That is the separate Microsoft Intune Initial Setup family, and Business Premium licensing (which we may well have recommended on Day 1) already includes the Intune licenses it needs. This setup gets the tenant right so that device management has something solid to attach to.
We're bigger than 50 seats — or we have an on-premises Active Directory. Is this still the right service?
Probably not this exact package, and we would rather tell you now than discover it on Day 2. Above roughly 50 seats, or with hybrid AD, directory synchronization, or compliance requirements in scope, setup stops being a three-day fixed project. Book the free discovery session and we will scope what your situation actually needs — the same day-one discipline, sized honestly.
How do we order, and is any of this handled by AI?
You start with the free discovery call or a quote request, and the quote arrives in writing with the fixed price and pay-after-approval terms. Our AI tools may prepare a quote — clearly labeled as such — but no order is executed by an AI: every order is confirmed and closed by a human, and the work is delivered by our engineers. You pay after you approve delivery.