Licence right-sizing
Reconciliation against your staff list, tier review against real usage, and a recommendation that often reduces the monthly bill.
Microsoft 365
Most businesses use a fraction of what their licences include and leave the security features switched off. We right-size the licensing, build a SharePoint and Teams structure people can actually use, and turn on the protection that came with the subscription.
Overview
Microsoft 365 licensing is genuinely confusing, and the result is predictable: businesses over-buy at one end, under-use at the other, and pay for seats belonging to people who left last year. A tenant review is one of the fastest ways to find money in a small business IT budget.
We start by reconciling assigned licences against your actual staff list, which almost always finds something. Then we look at fit. A Business Premium licence includes Intune device management, Entra ID Plan 1, Defender for Office 365 and conditional access, and a large share of businesses paying for it are using none of them. Meanwhile a warehouse team that only needs email and Teams on a phone may be sitting on full desktop licences they never install.
The most common Microsoft 365 failure is not technical. It is a SharePoint and Teams estate that grew by accident, where anyone could create a team, nobody agreed on naming, files live in four places and staff give up and email attachments to each other again.
We design the structure before rolling anything out: which content belongs in SharePoint sites versus Teams channels versus personal OneDrive, a naming convention, permission groups that map to how you actually work, and a governance rule about who can create new teams. Migrating a mapped network drive into SharePoint without that thinking produces a mess that is harder to use than the drive was. Our data management page covers the file structure side properly.
Almost every tenant we inherit has security features included in the licence and switched off. MFA not enforced on every account. Legacy authentication protocols still enabled, which lets an attacker bypass MFA entirely. No conditional access rules. Defender safe links and safe attachments unconfigured. Audit logging not reviewed. Global administrator rights handed to four people who each use that account for daily email.
None of that costs extra to fix. It costs attention. We work through a hardening baseline, enforce MFA, kill legacy authentication, separate administrative accounts from daily-driver accounts, build conditional access policies that fit how your staff actually work, and enable the alerting that tells you when something changes.
Intune covers the device side without needing a full mobile device management project. Basic compliance policies, disk encryption enforcement, a requirement that mailboxes only open on managed or compliant devices, and remote wipe for lost phones handle most small business requirements. Autopilot makes new machine deployment considerably faster, which matters if you hire regularly, see new computer setup.
Adoption is the last piece and the one that decides whether any of this pays off. We run short sessions for staff on the specific things that change their day, rather than a generic tour. There is more detail at microsoft365.orcait.io, and identity design is covered on our Active Directory and Entra ID page.
Most tenants we inherit are paying for security features that are switched off.Orca IT, Gilbert AZ
What We Do
Six areas of work, available together or individually.
Reconciliation against your staff list, tier review against real usage, and a recommendation that often reduces the monthly bill.
Domains, DNS, mail flow, sharing policy, retention and administrative structure built to a documented standard rather than defaults.
Site and channel structure, naming conventions, permission groups and governance so the estate does not sprawl within six months.
MFA enforcement, legacy authentication blocking, conditional access rules and separated administrative accounts.
Learn more →
Compliance policies, encryption enforcement, mailbox access restricted to managed devices and Autopilot for new machine deployment.
Third-party protection for Exchange Online, OneDrive, SharePoint and Teams, because native retention is not a backup.
Learn more →
How It Works
Licence reconciliation, security configuration against a hardening baseline, sharing settings, structure and identity posture.
MFA enforced, legacy authentication blocked, admin accounts separated, conditional access built, Defender policies configured.
SharePoint and Teams designed around how you work, permissions mapped to groups, retention applied and governance agreed.
Short, specific training for staff on what changes for them, plus documentation, then ongoing administration under your plan.
MFA, legacy authentication blocking and admin separation cost nothing but time and close the most common attack path.
It depends on the role. Business Basic suits staff who only need web and mobile access to email and Teams. Business Standard adds the desktop applications. Business Premium adds Intune, Entra ID Plan 1, Defender for Office 365 and conditional access, which is worth it for anyone handling sensitive data. Mixing tiers by role is normal and usually cheaper than standardising on one.
Often, yes. The common wins are removing licences for departed staff, moving low-need users to a lower tier, and dropping third-party products that duplicate something already included in the tier you own. We reconcile against your staff list and your actual usage rather than guessing.
Usually, but not by dragging the drive across. SharePoint works well when the structure is designed around how teams work, with permissions mapped to groups. A deep folder tree copied verbatim from a mapped drive tends to be harder to use than what it replaced, so we design first.
Not sufficiently. Security defaults help, but most tenants need MFA enforced properly, legacy authentication blocked, conditional access rules built, administrative accounts separated from daily use, and Defender policies configured. All of that is included in common licence tiers and frequently left off.
At the basic level it lets you require devices to be encrypted and compliant before they can open company mail, wipe a lost phone remotely, and deploy new computers with Autopilot so a machine configures itself when the user first signs in. You do not need a full device management project to get value from it.
Yes. Microsoft's responsibility is platform availability, not recovering data your own users or an attacker deleted. Native retention windows are limited and do not cover every scenario. A third-party backup for mail, OneDrive, SharePoint and Teams is inexpensive and we treat it as standard.
We block sign-in immediately, revoke active sessions and tokens, convert the mailbox to a shared mailbox so colleagues keep access without paying for a seat, transfer OneDrive content to the manager, and remove the licence. Doing this consistently is one of the most valuable habits a business can adopt.
Some, and short beats long. We run focused sessions on the specific things that change for them, such as where files now live and how sharing works, rather than a general tour of every application. Adoption is what determines whether the investment pays off.
Licences reconciled, security gaps listed, structure assessed. Usually saves money.
Talk to Your Pod
We will reconcile every licence against your staff list, check which security features you own but have not enabled, and show you what the same money could be doing.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.