Microsoft 365 is not hard to set up. It is easy to set up badly, and the damage shows up months later when email is split across two systems, files live on somebody's personal drive, and the person who left still owns the domain. The order below prevents all of that.
1. Sort the domain out first
Your business email should be yourname@yourbusiness.com, and that means proving to Microsoft that you control the domain by adding DNS records at whoever you bought it from. Do this before creating a single user account. If you set people up on the temporary onmicrosoft.com address first, you will migrate everyone twice.
While you are in there, write down where the domain is registered, which account owns it, and when it renews. An expired domain takes down email and website together, and it happens to somebody every week.
2. Pick the plan by what you actually need
The real fork is whether people need the installed Word, Excel and Outlook programs on their computers, or whether the browser versions will do. The other fork is whether you need device management and advanced security controls, which most very small teams do not on day one. You can move a user up a tier later without rebuilding anything, so start honest rather than aspirational.
One cost trap worth knowing: a shared mailbox — info@, sales@, support@ — does not need its own paid licence. Neither does a former employee's mailbox you are only keeping for the record. Businesses routinely pay for both for years.
3. Move the old email carefully
If you are coming from Gmail, an old hosting mailbox or another provider, do the migration before you switch the MX record that points mail at Microsoft — otherwise new mail lands in one place while the history sits in another. Migrate the mailboxes, verify a few of them, then flip the record. Expect a short window where mail arrives in both, which is normal and harmless.
Do not forget calendars, contacts, and any address that forwards somewhere else. Forwarding rules are the classic thing nobody documents and everybody misses.
4. Turn on multi-factor authentication on day one
Business email compromise almost always starts with one stolen password, and the target is usually the person who approves payments. Requiring a phone approval to sign in stops nearly all of it. Enable it while the team is small and the habit is cheap to establish — retrofitting it onto twenty annoyed people is a much harder conversation.
Enable it for the admin account first. And create a second admin account kept in reserve, so a lost phone does not lock you out of your own tenant.
5. Decide where files live before anyone saves anything
OneDrive is a person's own work. SharePoint or a Teams site is the company's work. The distinction matters enormously the day somebody leaves, because their OneDrive leaves with their account and shared files should not. Set up the team sites first, tell people where things go, and you will never have to run the "where is the contract" search.
6. Write down who owns the keys
The admin account, the domain registrar login, the billing card, the recovery phone number. Keep it somewhere the business owns — not one person's inbox. This single page is what separates a smooth staff change from two weeks of support tickets.
Would rather this went right the first time?
Post the job and a verified technician will handle the domain, the migration and the security setup — remotely, in a scheduled window, with nothing paid until it works.
Get Microsoft 365 set up