Email lived in Google Workspace. Documents lived wherever each person had put them - mostly personal OneDrive accounts tied to individuals, not to the business. That meant no central ownership of company data, no consistent security, no device management, and a real risk that a departing employee walked out with the files. For a business whose engineers are out on site, it also meant nobody could reliably reach the right document from the right device.
The commercial pressure made it urgent. The business had grown its reputation on major infrastructure work, including for Transport for London, and the next step was bidding directly for supermarket contracts rather than through intermediaries. Large customers now vet suppliers’ IT security as part of procurement: multi-factor authentication, managed and encrypted devices, endpoint protection, controlled company data. On the existing setup, those questions had no good answers - and a failed security questionnaire ends a tender before price is even discussed.
The brief was clear: bring everything under one properly managed, properly secured Microsoft 365 estate that would satisfy a corporate procurement review - without upheaval for a small team who needed to keep working throughout.
Email migration
- Full Gmail to Exchange Online migration - all mailboxes and history
- Domain and DNS moved to Microsoft: MX, DKIM and device-management records
- Cut over with no lost mail and no downtime for the team
Microsoft 365 Business Premium
- Business Premium licensing for the full security feature set, not the cut-down version
- Company data brought into SharePoint and business-owned OneDrive - out of personal accounts
- Exchange Online protection: anti-phishing, Safe Links, Safe Attachments, external sender tagging
Device management with Intune
- Every machine enrolled in Microsoft Intune and brought under central management
- Security baseline applied: encryption, firewall, hardening and attack surface reduction
- Devices provisioned and retired from one console - no more ad-hoc laptops
Defender and Conditional Access
- Microsoft Defender rolled out across every device, with EDR onboarding
- Conditional Access built and enabled: MFA for everyone, legacy authentication blocked, only managed devices allowed in
- Every Business Premium security feature switched on and configured, not left at defaults
90% Secure Score
Microsoft Secure Score taken from an unmanaged baseline to 90% - well above the typical SME.
Email on Microsoft
Gmail fully migrated to Exchange Online with all history intact and no downtime.
Company-owned data
Files moved out of personal OneDrives into business-owned SharePoint - the business now owns its data.
Every device managed
100% of machines enrolled in Intune, encrypted, hardened and protected by Defender.
Access under control
Conditional Access live: MFA enforced, legacy sign-ins blocked, unmanaged devices kept out.
Tender-ready
Supplier security questionnaires now answered with evidence - MFA, managed encrypted devices, Defender and controlled data - clearing the way to bid direct.
