Creating a tenant takes an afternoon. Undoing a badly configured one takes years. Found yours properly the first time.
We build tenants for new American companies the way they ought to be built from the first day. Domains verified with all three authentication records published immediately, a genuine access policy baseline rather than the bare security defaults, emergency administrator accounts that exist and have been tested, licensing that actually fits the shape of the business, and SharePoint, Teams and device enrollment all designed before your first employee ever signs in.
- Day 1SPF, DKIM, DMARC
- 2Break-glass accounts
- DaysFoundation build
- 100%You own the tenant
Nine decisions separating a tenant that was founded from one that merely appeared.
Verified domains and DNS done right
Your own domain verified and made primary, the default Microsoft address demoted to a fallback, and every DNS record placed properly: mail routing, discovery, the sender policy, the signing keys, and an authentication policy that begins in monitoring and moves to enforcement on a written schedule. Most tenants somebody set up themselves never publish the signing keys or the policy at all, which is precisely why their invoices keep landing in junk folders.
Email authentication from day one
The sender policy scoped to who genuinely sends on your behalf, signing enabled per domain, and the authentication policy reporting back so you can see who is impersonating you. All configured before the first external message ever leaves, so your domain builds its sending reputation from message one rather than repairing it eighteen months later.
Conditional Access baseline, not just security defaults
Security defaults are the seatbelt every new tenant arrives wearing. They are far better than nothing and they are the wrong shape for a business. We replace them with a proper access baseline: multifactor enforced for everybody, the legacy protocols closed, administrative sessions restricted, risk-based policy wherever the licensing permits it, and every exception named and documented rather than left as a silent gap.
Admin and break-glass structure
The top administrative role separated from the account somebody reads their email on, narrower roles for anybody who only needs mail or SharePoint rights, and two emergency accounts holding long random credentials stored offline and excluded from the access policies. When multifactor or federation breaks, those accounts are the difference between an unpleasant hour and a company locked entirely out of itself.
License plan fit, plan families only
The entry plans, the standard tier, Business Premium, the enterprise family and the frontline plans each suit a different shape of company. Roles get mapped to plan families so that nobody is paying enterprise rates for somebody who only needs a mailbox, and nobody is running a security program on a plan incapable of enforcing it. The pricing comes from whoever sells you the licenses. The analysis of what fits comes from us.
OneDrive and SharePoint architecture
A structure matching how the company genuinely operates. Sites per department, a coherent document architecture, sharing rules set per site rather than blanket across the tenant, and OneDrive treated as personal working space rather than as the company file server. All decided now, while moving a file costs nothing, rather than after three years of accumulation.
Teams governance before sprawl
Who is allowed to create a team, what happens to the ones everybody abandoned, how they get named, the rules on guests, and whether decisions live in channels or in private chats. A ten person company that skips this becomes a sixty person company carrying a hundred and forty dead teams and no idea where anything is. Governance costs an hour on the first day and a consulting engagement in the third year.
Backup and retention decisions
Your data is replicated. It is not backed up in the sense most business owners assume it is. Retention policies get set deliberately, what the built-in retention does and does not cover gets written down explicitly, and a separate backup is recommended wherever the gap genuinely matters. The first conversation about a deleted mailbox happens now, calmly, rather than during a crisis.
Device enrollment path
How the laptops and phones actually join the tenant. Company machines joined to the directory, enrolled into device management wherever the plan supports it, and app protection policies covering personal phones that read company mail. Even where full device management arrives later, the enrollment path is designed now so that every device lands in the right place from the very first purchase order.
Everything switched on before your first person ever signs in.
Identity and access
- MFA enforced for every user via Conditional AccessNot the old per-person multifactor, and not left sitting on security defaults
- Legacy authentication blocked tenant-wideThe legacy mail protocols are the front door password spraying walks through
- Two break-glass accounts created and testedExcluded from Conditional Access, credentials stored offline
- Global Admin count minimized and separated from daily accountsAdmins get a second account for admin work
- Self-service password reset configuredSo a forgotten password is not a support ticket
Email and domain
- Custom domain verified and set as primaryonmicrosoft.com demoted to fallback only
- SPF record scoped to actual sendersIncluding any invoicing or marketing platforms you already use
- DKIM signing enabled for every sending domain
- DMARC published with reportingEnforcement schedule agreed and documented
- Anti-phishing, anti-spoofing, and safe attachment policies tunedBeyond the shipped defaults, matched to your plan family
- Mail flow tested end to endMail in, mail out, and the authentication headers all verified from a mailbox outside your tenant
Data and collaboration
- SharePoint site structure created per the agreed architecture
- External sharing set per site, not tenant-wide openAnonymous links disabled where they should be
- Teams creation and guest access rules applied
- Retention policies applied and documentedWith a written note setting out exactly what the built-in retention does not cover
- Deleted item and mailbox recovery windows recordedSo nobody discovers the limits during an incident
Devices and audit
- Device join and enrollment path configuredDevices joined to the directory, enrolled into management where licensed, with app protection covering personal phones
- Unified audit logging confirmed activeThe history needs to already exist on the day you first need it
- Admin consent workflow for third-party apps enabledUsers request, admins approve, nothing self-installs silently
- Tenant handover document issuedEvery setting above, written down alongside the reason somebody chose it
Four reasons new companies hand us the empty tenant.
We run tenants, not just create them
Setting a tenant up is a week of work for us. Operating tenants is what we do every day. The baseline installed here is the identical one we run for managed clients, which means it has been tested against real incidents, real audits and the way real staff actually behave, rather than assembled from an article somebody read.
Everything is documented and handed over
You get a written handover covering every administrative account, every DNS record, every policy alongside the reason it exists, the procedure for the emergency credentials, and how the licensing is assigned. Any competent provider can pick it up, and so can whoever you eventually hire internally. Nothing is held hostage.
Built with US compliance in mind
We know which settings matter for SOC 2 readiness, HIPAA-covered practices, FTC Safeguards obligations, and the vendor security questionnaires enterprise customers send, and we build them in rather than bolting them on. The handover document doubles as the start of your evidence pack.
You own the tenant, always
The tenant, the domain, the licensing and the top administrative rights are yours from the first day. We work through delegated access that you can revoke. Leave us next year and you revoke it and lose absolutely nothing. That is how this relationship ought to be structured, and it is surprising how often it is not.
Four situations where day-one setup pays for itself.
Startups and new companies
A company just formed and about to hire its first people. You end up with company email, files, Teams and a security baseline nobody will have to tear up once there are twenty of you. Starting with three people is entirely fine, because the foundation is identical to the one that carries a business to three hundred.
US subsidiaries of foreign companies
A parent company somewhere else entirely and a new American entity opening here. We stand up the American tenant, or the American presence within your existing one, line it up with whatever group security policy already exists, and handle everything local: the domain, how the licensing is structured, the questions about where data physically resides, and the coordination back to head office IT.
Spin-offs and carve-outs
A division becoming a company in its own right needs a tenant of its own, and everybody in it needs their mail, their files and their Teams history extracted cleanly from the parent. We build the new foundation first and run the migration afterward, so that the first day of the new company does not begin with several hundred empty mailboxes.
Companies leaving shared or agency tenants
Your email currently lives inside a web agency tenant, or a group company tenant, or something a freelancer set up on their own account, and you hold no administrative rights over your own data whatsoever. We stand up a tenant you actually own, migrate the mail and files across, repoint the domain, and end the arrangement without losing a single message of history.
Get the tenant right before employee number one.
The right week to found a tenant is the week the company legally exists, before anybody has been hired. What actually happens is the opposite: a founder creates one on a personal card to get an email address for the bank and the state filing, and that Tuesday afternoon decision quietly becomes the company infrastructure. We work with newly formed companies, funded startups and new American subsidiaries to stand up the tenant, the domain and the security baseline as part of forming the business, so that the first person hired receives a proper company account on a hardened tenant rather than an invitation into whatever the founder improvised. For anybody planning to sell into large enterprises, this is also the cheapest SOC 2 preparation available anywhere: the access controls, the multifactor enforcement, the offboarding process and the audit logging that your first security questionnaire asks about are simply how the tenant was built in the first place.
- The tenant, the domain and the email all live before your first hire, ready for the bank, the investors and every vendor
- The security baseline configured while there is nobody at all to disrupt, which is the cheapest hardening you will ever buy
- License plan family chosen for the company you are becoming, not the two people you are today
- The evidence trail your first SOC 2 or customer security review asks for exists from day one
The identical tenant, founded properly or repaired afterward.
| Feature | Founded on day one | Default self-setup | Remediated later |
|---|---|---|---|
SPF, DKIM, DMARC live before first email | SPF only, usually | After deliverability pain | |
Conditional Access baseline | Security defaults | Disruptive rollout to live users | |
Break-glass accounts | Often only after a lockout | ||
License plan matched to roles | One plan for everyone | True-up after overspend | |
SharePoint architecture | Designed empty | Default sites | Restructure with live data |
Teams governance | Rules before sprawl | Anyone creates anything | Cleanup project |
Retention understood and set | Defaults, unread | Discovered during an incident | |
User disruption | None, no users yet | None, until it breaks | Every change touches staff |
Documentation | Handover included | None | Reverse-engineered |
The plan families side by side, so the conversation about fit can be an honest one.
Business email and Teams
- Business Basic
- Yes
- Business Standard
- Yes
- Business Premium
- Yes
- Enterprise E plans
- Yes
- F plans (frontline)
- Yes
Desktop Office apps
- Business Basic
- Web and mobile only
- Business Standard
- Yes
- Business Premium
- Yes
- Enterprise E plans
- Yes
- F plans (frontline)
- Web and mobile only
Intune device management
- Business Basic
- No
- Business Standard
- No
- Business Premium
- Yes
- Enterprise E plans
- Plan dependent
- F plans (frontline)
- Limited
Advanced identity protection
- Business Basic
- Baseline only
- Business Standard
- Baseline only
- Business Premium
- Yes
- Enterprise E plans
- Strongest on E5
- F plans (frontline)
- Baseline only
Advanced threat protection for email
- Business Basic
- Add-on
- Business Standard
- Add-on
- Business Premium
- Included
- Enterprise E plans
- Included, deepest on E5
- F plans (frontline)
- Add-on
Typical fit
- Business Basic
- Mailbox-and-browser roles
- Business Standard
- Standard knowledge workers
- Business Premium
- Most US SMBs, our default recommendation
- Enterprise E plans
- Larger or regulated organizations
- F plans (frontline)
- Retail, site, and field staff
From the first call to a documented handover in roughly a week.
- 1
Discovery call
1 hour
The shape of the company, how many people you expect over the next eighteen months, which regulations apply, whatever email exists today, who owns the domain, and what you intend to do about devices. What comes out is a written plan carrying a recommendation on which plan family fits, alongside every single decision we would be making on your behalf, listed for you to approve.
- 2
Foundation build
2-4 days
The tenant created or taken over, the domain verified, the DNS records placed, the access baseline applied, the administrative and emergency account structure built, the SharePoint and Teams architecture stood up, retention configured, and the device enrollment path established. Where mail is coming across from Google Workspace or another tenant, the migration runs inside this same window.
- 3
Verification and hardening check
1 day
Every item on the hardening checklist tested and evidenced rather than assumed. Mail authentication verified from a mailbox outside your tenant, multifactor and the legacy protocol block both confirmed, somebody actually signing in with an emergency account, and the sharing rules probed from outside. Nothing gets declared finished on the strength of a screenshot of a settings page.
- 4
Handover with documentation
1 session
A walkthrough with whoever owns or runs the business, plus the written handover covering the accounts, the DNS, every policy alongside its reason, the emergency account procedure, how licensing is assigned, and the short list of decisions deliberately left for later. From that point you can run it yourself, hire somebody to run it, or move onto our management service. All three are fine.
What founders and managers ask before we start.
Where a founded tenant goes next.
Microsoft 365 Tenant Management
Ongoing administration of the tenant we founded: users, licenses, policies, and monitoring as a service.
Tenant Security Baseline
The full hardening standard behind our day-one checklist, applied to new and inherited tenants.
Startup IT Business Kit
The wider first-hire IT stack for new companies: devices, identity, security, and support from day one.
Get the tenant right once, before your first hire logs in.
A one-hour discovery call produces a written setup plan: the license plan family that fits, the decisions we will make, and the day-one hardening checklist you will receive evidence against. If your tenant already exists and needs rescuing, the same call scopes the remediation honestly.
Related Services
Explore more solutions that work great with this service
M365 Tenant Management
Your tenant run properly, end to end
Learn moreTenant Security Baseline
Documented controls mapped to CIS
Learn moreM365 Administration
Expert Microsoft 365 tenant management
Learn moreMicrosoft Entra
Identity and access management solutions
Learn moreMicrosoft Intune
Device management and endpoint security
Learn more