First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Rapid Start: Remote Work
AssessmentImplementation

Rapid Start: Remote Work — Microsoft 365 Setup in 2 Weeks

Rapid Start: Remote Work gets a small or mid-sized organization working from anywhere on the Microsoft 365 licenses it already owns — Teams meetings, Outlook mail and calendar on phones, OneDrive file sync and coauthoring, a shared SharePoint site, and a multi-factor authentication baseline — configured, validated with a pilot group, and handed off in 2 weeks for a fixed $1,750. IT Partner reviews your tenant, makes the settings decisions with you, configures the collaboration and security baseline your plan supports, and leaves your administrators a rollout guide for everyone else.

Timeline 2 weeksService owner Mike MackeyOffice 365microsoft 365

What this engagement is

Most organizations that struggle with remote work already own the tools that fix it. A Microsoft 365 subscription includes Exchange Online for mail and calendar, Microsoft Teams for meetings and chat, OneDrive for personal files, SharePoint Online for shared documents, and Office apps on Windows, macOS, iOS and Android — but out of the box the tenant is tuned for nobody in particular, files still live on a server or a laptop, and phones connect with a password alone. Rapid Start: Remote Work closes that gap in a bounded, fixed-price engagement. Over 2 weeks IT Partner reviews your tenant and licensing, agrees the handful of decisions that shape remote work (personal-device stance, external sharing level, how MFA is enforced), and configures a collaboration baseline: organization-wide Teams meeting settings with the Outlook meeting add-in confirmed, Outlook mobile access to mail and calendar, OneDrive sync on the pilot devices (with Known Folder Move where your licensing lets us push it), and one Teams team or SharePoint site as the shared home for documents with sharing set to the approved level. On the security side we turn on the baseline your plan supports: multi-factor authentication for every user through Microsoft Entra security defaults, or — where your plan includes Microsoft Entra ID P1, as Microsoft 365 Business Premium does — a baseline Conditional Access policy that requires MFA and blocks legacy authentication, plus Intune app protection policies for Outlook, Teams and OneDrive on personal iOS and Android phones. A pilot group you nominate then proves the whole path — join a meeting, read mail on a phone, sync and coauthor a file, open the shared site — before we hand your administrators the as-configured notes and a one-page quick-start for the rest of the company. Who this is for: organizations on a single Microsoft 365 tenant with mail already in Exchange Online, that need people productive off-site quickly and want the configuration done by someone who has done it many times. Who it is not for: organizations that still need to migrate mail or files into Microsoft 365 (see Cutover Exchange Online Migration and Company Document Migration to SharePoint Online or Teams), that want full device management (see Microsoft Intune Initial Setup for Windows Device Management), or that need a complete Conditional Access design (see Microsoft Entra ID, Conditional Access Policy Implementation). Each of those extends this rapid start as separately quoted work. IT Partner has itself run as a fully virtual company since COVID, with a team distributed across the US and Europe — the setup we configure for you is the one we work in every day.

Success criteria

01Every pilot user schedules a Teams meeting from Outlook or Teams and joins it with audio, video and screen sharing from their primary device.
02Every pilot user reads mail and calendar in Outlook on a phone, signed in with multi-factor authentication.
03Every pilot user has OneDrive sync running on their computer, and two pilot users coauthor the same Word, Excel or PowerPoint file from the shared library at the same time.
04The shared Teams team or SharePoint site exists with the agreed membership and permissions, and external sharing is set to the level approved in the decision record.
05Multi-factor authentication enforcement is on for the tenant — Microsoft Entra security defaults, or the baseline Conditional Access policy where Microsoft Entra ID P1 is licensed — and every pilot user has completed MFA registration.
06Where Intune is licensed, the app protection policy is applied to Outlook, Teams and OneDrive on the pilot iOS and Android phones and verified: app PIN prompt, and cut/copy/paste into unmanaged apps blocked as configured.
07Your administrators hold the as-configured notes, the decision record and the end-user quick-start guide, the handoff session is complete, and you approve delivery.

What you receive

Remote-work readiness snapshot: which capabilities your assigned licenses already include (Teams, Exchange Online, OneDrive, SharePoint, Microsoft Entra ID tier, Intune), the current state of the relevant tenant settings, and the gaps this engagement closes.
Decision record — personal-device stance, external sharing level, MFA enforcement method, pilot group, and the shared document location — approved by you before configuration starts.
Configured Teams collaboration baseline: organization-wide meeting settings (lobby, anonymous join, recording and transcription defaults agreed with you), external access and guest access set to the approved level, and the Outlook meeting add-in confirmed for pilot users.
Exchange Online remote access confirmed for the pilot: Outlook on the web, and Outlook mobile signed in on the pilot phones with the mobile access controls your plan includes.
OneDrive configured on the pilot computers: sync client signed in, Known Folder Move (Desktop, Documents, Pictures) enabled by policy where Intune or Group Policy is available, otherwise applied and documented for guided rollout.
One Teams team or SharePoint site set up as the shared document home, with membership, permissions and sharing settings applied and a starter folder structure agreed with you.
Configured security baseline matched to your license tier: MFA enforcement for all users (security defaults, or a baseline Conditional Access policy requiring MFA and blocking legacy authentication where Microsoft Entra ID P1 is licensed), SharePoint and OneDrive sharing defaults, and — where Intune is licensed — one app protection policy each for iOS and Android covering Outlook, Teams and OneDrive.
Pilot validation record: each pilot user's results against the success criteria, issues found, and how each was resolved or documented for follow-up.
Administrator handoff pack: as-configured settings, open items, recommended next steps, and a one-page end-user quick-start guide (joining meetings, Outlook on a phone, OneDrive sync, coauthoring, finding the shared site) — delivered in a handoff session with your administrators.

How the work unfolds

Week 1, days 1–2 — Kickoff and readiness

Kickoff call to confirm goals, the pilot group and its device mix, and the people who approve decisions. IT Partner reviews assigned licenses and the current Teams, Exchange Online, SharePoint, OneDrive, Microsoft Entra and Intune settings, then delivers the readiness snapshot and the decision record for your approval.

Week 1, days 3–5 — Collaboration baseline

Configure organization-wide Teams meeting, external and guest settings; confirm Outlook mobile access; set up the shared Teams team or SharePoint site with its permissions and sharing level; configure OneDrive sync and Known Folder Move on the pilot computers.

Week 2, days 6–8 — Security baseline

Turn on MFA enforcement (security defaults, or the baseline Conditional Access policy where Microsoft Entra ID P1 is licensed), set SharePoint and OneDrive sharing defaults, and — where Intune is licensed — create and assign the iOS and Android app protection policies. Register the pilot users for MFA and confirm the policies apply to them.

Week 2, days 8–9 — Pilot validation and fixes

Walk each pilot user through the success-criteria checks on their own devices, resolve configuration issues found, and document anything outside the fixed scope for follow-up.

Week 2, day 10 — Handoff

Deliver the as-configured notes, decision record and end-user quick-start guide, hold the administrator handoff session, and close the project on your approval.

Prerequisites

An active Microsoft 365 tenant with licenses assigned to the users in scope that include Exchange Online, Microsoft Teams, OneDrive, SharePoint Online and the Office apps you expect people to use — for example Microsoft 365 Business Standard or Microsoft 365 Business Premium with Teams, or Microsoft 365 E3/E5 with Teams licensed alongside where your plan sells it separately.
Mail already hosted in Exchange Online with your custom domain verified and DNS pointing at Microsoft 365. Mailbox or file migration into Microsoft 365 is a separate service and must finish before this one starts.
Administrator access for IT Partner: Global Administrator, or delegated roles covering Teams, Exchange, SharePoint, Microsoft Entra Conditional Access and Intune as applicable — granted before kickoff and removable by you at the end.
A healthy identity setup: cloud-only accounts, or Microsoft Entra Connect synchronization that is working and not scheduled for repair. Identity remediation is out of scope.
A nominated pilot group representative of your device mix — we suggest one or two users per platform (Windows, macOS, iOS, Android) — whose members are available for testing in week 2.
Pilot devices running a version of Windows, macOS, iOS or Android that Microsoft 365 apps and the Intune app protection SDK currently support, with working internet access.
The security controls this service can turn on depend on your Microsoft Entra ID tier: security defaults are available to every tenant; Conditional Access and app protection policies require Microsoft Entra ID P1 and an Intune license, included in Microsoft 365 Business Premium and Microsoft 365 E3/E5 but not in Business Basic or Business Standard.
If per-user MFA, an existing Conditional Access policy or a third-party MFA product is already in use, its configuration disclosed at kickoff so enforcement can be reconciled rather than duplicated.
A point of contact who can make the decision-record choices at kickoff, communicate the MFA change to staff, and approve delivery within the 2-week schedule.

Who does what

IT Partner

  • Run the kickoff, review licensing and current tenant settings, and produce the readiness snapshot and decision record.
  • Configure the Teams, Exchange Online, SharePoint and OneDrive collaboration baseline described above, including the shared team or site.
  • Configure the security baseline your license tier supports — MFA enforcement, sharing defaults and, where licensed, the baseline Conditional Access policy and iOS/Android app protection policies.
  • Set up OneDrive sync and Known Folder Move on the pilot computers and Outlook mobile on the pilot phones, remotely with the user present.
  • Register the pilot users for MFA, run the pilot validation against the success criteria, and fix configuration issues within the fixed scope.
  • Document open items and dependencies that need separate remediation, with a recommended path for each.
  • Deliver the administrator handoff pack and the end-user quick-start guide, and hold the handoff session.

Your team

  • Grant the administrator access and disclose existing MFA, Conditional Access, device management and sharing configuration before kickoff.
  • Make the decision-record choices — personal-device stance, external sharing level, MFA method, pilot group, shared document location — at or within two business days of kickoff.
  • Nominate pilot users and make them and their devices available for the week-2 validation sessions.
  • Tell staff about the MFA change and the registration prompt they will see, using the wording IT Partner provides.
  • Own rollout to users beyond the pilot after handoff — OneDrive sign-in, Outlook mobile setup and MFA registration for everyone else — using the quick-start guide, unless separately contracted.
  • Provide or procure the Microsoft licenses, devices, headsets and internet connectivity the setup depends on.
  • Review the deliverables and approve delivery, or report defects, within the 2-week schedule.

What's not included

Migrations — mailboxes from another mail system, file shares, home folders, or content from Google Workspace, Dropbox or Box. See Cutover Exchange Online Migration, Company Document Migration to SharePoint Online or Teams and Box, Dropbox & Google Drive to OneDrive Document Migration.
Device management — Intune device enrollment, compliance and configuration policies, Windows Autopilot, and Defender for Business or Defender for Endpoint onboarding. These build on this rapid start through Microsoft Intune Initial Setup for Windows Device Management and Microsoft Intune Initial Setup for iPhone & iPad Management.
Identity and security programs beyond the baseline — a full Conditional Access policy set, named-location or risk-based policies, passwordless rollout, Secure Score-driven hardening, DLP, sensitivity labels, retention, eDiscovery, SIEM or incident response. See Microsoft Entra ID, Conditional Access Policy Implementation and Microsoft 365 Security 30 Days Service.
Voice — Teams Phone, calling plans, number porting, Direct Routing, Operator Connect, auto attendants and call queues. See Microsoft Teams Phone System Setup.
SharePoint intranet design, custom site branding, Power Platform automation, custom Teams apps and line-of-business integration. See SharePoint Online Intranet Design and Deployment.
Rollout beyond the pilot — hands-on setup of every user's computer and phone, organization-wide MFA registration campaigns, and instructor-led training. Company-wide MFA rollout with user communications is offered as Enable MFA for All Users; structured Teams adoption as Microsoft Teams Adoption Training & Pilot.
Ongoing administration and end-user support after handoff — available separately through the Remote Support Help Desk Service. Microsoft licenses, devices, headsets, home internet and telecom charges are billed by their vendors, not by IT Partner.

Limitations & technical notes

!The security baseline is bounded by your Microsoft Entra ID tier. On Business Basic, Business Standard or any plan without Microsoft Entra ID P1, MFA is enforced through security defaults — a tenant-wide, all-or-nothing switch with no exceptions, no legacy-authentication blocking policy of your own, and no app protection policies for personal phones. Conditional Access and Intune app protection require Microsoft Entra ID P1 and Intune licensing (both included in Microsoft 365 Business Premium and Microsoft 365 E3/E5).
!MFA enforcement is tenant-wide, not pilot-only. Once it is on, every user must complete MFA registration at their next sign-in — Microsoft removed the former 14-day skip window from security defaults in 2025, so there is no grace period to lean on. IT Partner registers the pilot users; communicating the change to everyone else before enforcement day is yours, with the wording we provide.
!Security defaults cannot coexist with Conditional Access policies, and legacy per-user MFA settings interact with both. Where any of these already exist, kickoff decides one enforcement path; untangling a partly deployed third-party MFA product is separate work.
!App protection policies manage Microsoft 365 app data on personal phones — a PIN, encryption, and controls on copy, save and share — but not the device itself. There is no device-level control, remote wipe of the whole phone, or protection for apps that do not support the Intune SDK. Device management is a separate service.
!Known Folder Move can be pushed silently only where Intune or Group Policy applies to the pilot computers; on unmanaged computers it is enabled per device with the user and documented for your rollout. Files kept on a file server or in a non-Microsoft cloud are not moved.
!Coauthoring and always-current documents depend on files living in OneDrive, SharePoint or Teams. This service sets up the shared location and the sync; populating it with your existing content is a migration and is quoted separately.
!Meeting quality and sync speed depend on each user's home internet, device health and Microsoft service availability, none of which this engagement controls.
!The 2-week schedule assumes the decision record is approved within two business days of kickoff, administrator access is ready at kickoff, and pilot users are available in week 2. Client-side delays move the completion date, not the scope. The fixed price covers one Microsoft 365 tenant and the baseline described on this page; additional tenants, platforms or remediation are quoted in writing before any work starts.
!A security baseline reduces risk; it does not eliminate it. No configuration can guarantee that every account, device or file is protected against every threat.
!Technical content reviewed September 2026.

Frequently asked questions

What exactly does Rapid Start: Remote Work include?

A readiness review of your tenant and licenses; a decision record you approve; a collaboration baseline across Teams meeting settings, Outlook mobile access, OneDrive sync with Known Folder Move, and one shared Teams team or SharePoint site; a security baseline matched to your license tier (MFA for all users, sharing defaults, and where licensed a baseline Conditional Access policy and iOS/Android app protection policies); a pilot validation with users you nominate; and an administrator handoff pack with a one-page end-user quick-start guide. All of it within 2 weeks for the fixed price on this page.

How much does it cost, and what does the fixed price cover?

$1,750, fixed, for one Microsoft 365 tenant and the baseline described on this page. The price is quoted in writing before work begins and you pay after you approve delivery. Microsoft licenses, devices and connectivity are billed by their vendors. Anything outside the baseline — migrations, device management, a full Conditional Access design, rollout to every user — is quoted separately in writing, and no out-of-scope work happens without your approval.

How long does it take?

2 weeks: readiness and the collaboration baseline in week 1, the security baseline, pilot validation and handoff in week 2. That assumes the decision record is approved within two business days of kickoff, our administrator access is ready on day 1, and pilot users are available for their validation sessions. Client-side delays move the completion date rather than the scope.

Which Microsoft 365 licenses do we need?

Any plan that gives the users in scope Exchange Online, Microsoft Teams, OneDrive, SharePoint Online and the Office apps — Microsoft 365 Business Basic, Business Standard or Business Premium with Teams, or Microsoft 365 E3/E5 with Teams. The collaboration baseline works on all of them. The security baseline depends on your Microsoft Entra ID tier: security defaults on any plan; Conditional Access and app protection policies only where Microsoft Entra ID P1 and Intune are included, as in Business Premium and E3/E5. We do not require you to upgrade — we configure what your current licenses support and tell you what an upgrade would add.

Will you turn on MFA for everyone, and what will staff notice?

Yes — enforcement is tenant-wide, because a remote workforce signing in with passwords alone is the risk this service most needs to close. On plans without Microsoft Entra ID P1 we enable security defaults; every user is then required to register for MFA at their next sign-in — Microsoft removed the former 14-day skip window from security defaults in 2025, which is why we give you the announcement wording before enforcement day. On plans with P1 we create a baseline Conditional Access policy that requires MFA and blocks legacy authentication. We register the pilot users ourselves; a company-wide registration campaign with per-user follow-up is the separate Enable MFA for All Users service.

Can employees use their personal phones and laptops?

Yes, and the decision record fixes how. On Business Premium or E3/E5 we apply Intune app protection policies to Outlook, Teams and OneDrive on personal iPhones and Android phones: a PIN on the work apps, encrypted data, and blocks on copying or saving work data into personal apps — without enrolling or controlling the device. On plans without Intune, personal phones get Outlook mobile with MFA and the mobile access controls Exchange Online includes, and we document what an upgrade would add. Personal computers get OneDrive sync and the Office apps; full device management, for company-owned or personal devices, is a separate Intune service.

Our email and files are not in Microsoft 365 yet. Can this still work?

Not on its own. This rapid start configures a tenant whose mail already lives in Exchange Online; it sets up the shared document location and OneDrive sync but does not move existing content. Migrate first — Cutover Exchange Online Migration for mail, Company Document Migration to SharePoint Online or Teams, or Box, Dropbox & Google Drive to OneDrive Document Migration for files — and run Rapid Start: Remote Work immediately after. We can sequence both in one plan.

Does it include phone calls in Teams?

No. Teams meetings, chat and internal calling between Teams users are included; calling to and from regular phone numbers needs Teams Phone licensing, numbers and call routing, which is the separate Microsoft Teams Phone System Setup service. The two combine well — many organizations run them back to back.

Who is this service for — and who should choose something else?

It fits organizations on a single Microsoft 365 tenant with mail already in Exchange Online, that need people productive from home or on the road quickly and want the configuration done right the first time. Choose something else if you need a full device management foundation (Microsoft Intune Initial Setup), a complete Conditional Access design (Conditional Access Policy Implementation), Secure Score-driven hardening (Microsoft 365 Security 30 Days Service), or a structured Teams adoption program with training (Microsoft Teams Adoption Training & Pilot). Each of those builds on what this rapid start leaves in place.

How is this different from Microsoft Intune Initial Setup or Microsoft 365 Security 30 Days Service?

Scope and depth. Rapid Start: Remote Work is a 2-week, fixed-price baseline that touches every workload a remote employee uses and turns on the security controls your licenses already include — no device enrollment, no policy library. Microsoft Intune Initial Setup is an 8-week foundation that enrolls and governs company-owned Windows devices with a full security baseline. Microsoft 365 Security 30 Days Service is a 30-day tenant hardening engagement driven by Secure Score. Start here if the immediate problem is people who cannot work from home well; move to those when the problem becomes managing the estate.

What do we receive at the end, and what happens next?

The readiness snapshot, the approved decision record, the pilot validation record, the administrator handoff pack (as-configured settings, open items, next steps) and the one-page end-user quick-start guide, delivered in a handoff session — and you approve delivery before invoicing. Your administrators then roll the quick-start out to the rest of the company. Natural next steps, each quoted separately: Enable MFA for All Users for a managed registration campaign, an Intune device-management foundation, a complete Conditional Access design, or the Remote Support Help Desk Service if you would rather we handle user questions.

Who owns this service at IT Partner?

Mike Mackey, IT Partner's founder, is the service owner. IT Partner has been a Microsoft partner since 2006 and has itself operated as a fully virtual company since COVID, with the team distributed across the US and Europe — the working setup described on this page is the one we use.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,750 per project
2 weeks
Book a remote-work scoping call