We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft
  2. Microsoft 365 Tenant Setup
Microsoft 365 Tenant Setup

Creating a tenant takes an afternoon. Undoing a badly configured one takes years. Found yours properly the first time.

We build tenants for new American companies the way they ought to be built from the first day. Domains verified with all three authentication records published immediately, a genuine access policy baseline rather than the bare security defaults, emergency administrator accounts that exist and have been tested, licensing that actually fits the shape of the business, and SharePoint, Teams and device enrollment all designed before your first employee ever signs in.

Book a setup callWhat a proper foundation includes
Microsoft
Microsoft
365
Cloud Solution Partner
  • Day 1SPF, DKIM, DMARC
  • 2Break-glass accounts
  • DaysFoundation build
  • 100%You own the tenant
What a proper foundation includes

Nine decisions separating a tenant that was founded from one that merely appeared.

Anybody can click through the signup wizard in twenty minutes. That wizard never asks about emergency accounts, about enforcing your mail authentication, about what happens to Teams over five years, or about what occurs the day somebody deletes a mailbox. These are the nine areas configured deliberately and in writing before your first person signs in.

Verified domains and DNS done right

Your own domain verified and made primary, the default Microsoft address demoted to a fallback, and every DNS record placed properly: mail routing, discovery, the sender policy, the signing keys, and an authentication policy that begins in monitoring and moves to enforcement on a written schedule. Most tenants somebody set up themselves never publish the signing keys or the policy at all, which is precisely why their invoices keep landing in junk folders.

Email authentication from day one

The sender policy scoped to who genuinely sends on your behalf, signing enabled per domain, and the authentication policy reporting back so you can see who is impersonating you. All configured before the first external message ever leaves, so your domain builds its sending reputation from message one rather than repairing it eighteen months later.

Conditional Access baseline, not just security defaults

Security defaults are the seatbelt every new tenant arrives wearing. They are far better than nothing and they are the wrong shape for a business. We replace them with a proper access baseline: multifactor enforced for everybody, the legacy protocols closed, administrative sessions restricted, risk-based policy wherever the licensing permits it, and every exception named and documented rather than left as a silent gap.

Admin and break-glass structure

The top administrative role separated from the account somebody reads their email on, narrower roles for anybody who only needs mail or SharePoint rights, and two emergency accounts holding long random credentials stored offline and excluded from the access policies. When multifactor or federation breaks, those accounts are the difference between an unpleasant hour and a company locked entirely out of itself.

License plan fit, plan families only

The entry plans, the standard tier, Business Premium, the enterprise family and the frontline plans each suit a different shape of company. Roles get mapped to plan families so that nobody is paying enterprise rates for somebody who only needs a mailbox, and nobody is running a security program on a plan incapable of enforcing it. The pricing comes from whoever sells you the licenses. The analysis of what fits comes from us.

OneDrive and SharePoint architecture

A structure matching how the company genuinely operates. Sites per department, a coherent document architecture, sharing rules set per site rather than blanket across the tenant, and OneDrive treated as personal working space rather than as the company file server. All decided now, while moving a file costs nothing, rather than after three years of accumulation.

Teams governance before sprawl

Who is allowed to create a team, what happens to the ones everybody abandoned, how they get named, the rules on guests, and whether decisions live in channels or in private chats. A ten person company that skips this becomes a sixty person company carrying a hundred and forty dead teams and no idea where anything is. Governance costs an hour on the first day and a consulting engagement in the third year.

Backup and retention decisions

Your data is replicated. It is not backed up in the sense most business owners assume it is. Retention policies get set deliberately, what the built-in retention does and does not cover gets written down explicitly, and a separate backup is recommended wherever the gap genuinely matters. The first conversation about a deleted mailbox happens now, calmly, rather than during a crisis.

Device enrollment path

How the laptops and phones actually join the tenant. Company machines joined to the directory, enrolled into device management wherever the plan supports it, and app protection policies covering personal phones that read company mail. Even where full device management arrives later, the enrollment path is designed now so that every device lands in the right place from the very first purchase order.

Day-one hardening checklist

Everything switched on before your first person ever signs in.

This is the concrete list and every line of it can be verified. Each gets configured, tested and written into the handover. When somebody quotes you for a setup, ask them which of these they include. The answer separates a tenant that was founded from a signup wizard with an invoice attached.

Identity and access

  • MFA enforced for every user via Conditional Access
    Not the old per-person multifactor, and not left sitting on security defaults
  • Legacy authentication blocked tenant-wide
    The legacy mail protocols are the front door password spraying walks through
  • Two break-glass accounts created and tested
    Excluded from Conditional Access, credentials stored offline
  • Global Admin count minimized and separated from daily accounts
    Admins get a second account for admin work
  • Self-service password reset configured
    So a forgotten password is not a support ticket

Email and domain

  • Custom domain verified and set as primary
    onmicrosoft.com demoted to fallback only
  • SPF record scoped to actual senders
    Including any invoicing or marketing platforms you already use
  • DKIM signing enabled for every sending domain
  • DMARC published with reporting
    Enforcement schedule agreed and documented
  • Anti-phishing, anti-spoofing, and safe attachment policies tuned
    Beyond the shipped defaults, matched to your plan family
  • Mail flow tested end to end
    Mail in, mail out, and the authentication headers all verified from a mailbox outside your tenant

Data and collaboration

  • SharePoint site structure created per the agreed architecture
  • External sharing set per site, not tenant-wide open
    Anonymous links disabled where they should be
  • Teams creation and guest access rules applied
  • Retention policies applied and documented
    With a written note setting out exactly what the built-in retention does not cover
  • Deleted item and mailbox recovery windows recorded
    So nobody discovers the limits during an incident

Devices and audit

  • Device join and enrollment path configured
    Devices joined to the directory, enrolled into management where licensed, with app protection covering personal phones
  • Unified audit logging confirmed active
    The history needs to already exist on the day you first need it
  • Admin consent workflow for third-party apps enabled
    Users request, admins approve, nothing self-installs silently
  • Tenant handover document issued
    Every setting above, written down alongside the reason somebody chose it
Why found the tenant with GR

Four reasons new companies hand us the empty tenant.

We run tenants, not just create them

Setting a tenant up is a week of work for us. Operating tenants is what we do every day. The baseline installed here is the identical one we run for managed clients, which means it has been tested against real incidents, real audits and the way real staff actually behave, rather than assembled from an article somebody read.

Everything is documented and handed over

You get a written handover covering every administrative account, every DNS record, every policy alongside the reason it exists, the procedure for the emergency credentials, and how the licensing is assigned. Any competent provider can pick it up, and so can whoever you eventually hire internally. Nothing is held hostage.

Built with US compliance in mind

We know which settings matter for SOC 2 readiness, HIPAA-covered practices, FTC Safeguards obligations, and the vendor security questionnaires enterprise customers send, and we build them in rather than bolting them on. The handover document doubles as the start of your evidence pack.

You own the tenant, always

The tenant, the domain, the licensing and the top administrative rights are yours from the first day. We work through delegated access that you can revoke. Leave us next year and you revoke it and lose absolutely nothing. That is how this relationship ought to be structured, and it is surprising how often it is not.

Who needs a founded tenant

Four situations where day-one setup pays for itself.

Startups and new companies

A company just formed and about to hire its first people. You end up with company email, files, Teams and a security baseline nobody will have to tear up once there are twenty of you. Starting with three people is entirely fine, because the foundation is identical to the one that carries a business to three hundred.

US subsidiaries of foreign companies

A parent company somewhere else entirely and a new American entity opening here. We stand up the American tenant, or the American presence within your existing one, line it up with whatever group security policy already exists, and handle everything local: the domain, how the licensing is structured, the questions about where data physically resides, and the coordination back to head office IT.

Spin-offs and carve-outs

A division becoming a company in its own right needs a tenant of its own, and everybody in it needs their mail, their files and their Teams history extracted cleanly from the parent. We build the new foundation first and run the migration afterward, so that the first day of the new company does not begin with several hundred empty mailboxes.

Companies leaving shared or agency tenants

Your email currently lives inside a web agency tenant, or a group company tenant, or something a freelancer set up on their own account, and you hold no administrative rights over your own data whatsoever. We stand up a tenant you actually own, migrate the mail and files across, repoint the domain, and end the arrangement without losing a single message of history.

New companies and funded startups

Get the tenant right before employee number one.

The right week to found a tenant is the week the company legally exists, before anybody has been hired. What actually happens is the opposite: a founder creates one on a personal card to get an email address for the bank and the state filing, and that Tuesday afternoon decision quietly becomes the company infrastructure. We work with newly formed companies, funded startups and new American subsidiaries to stand up the tenant, the domain and the security baseline as part of forming the business, so that the first person hired receives a proper company account on a hardened tenant rather than an invitation into whatever the founder improvised. For anybody planning to sell into large enterprises, this is also the cheapest SOC 2 preparation available anywhere: the access controls, the multifactor enforcement, the offboarding process and the audit logging that your first security questionnaire asks about are simply how the tenant was built in the first place.

  • The tenant, the domain and the email all live before your first hire, ready for the bank, the investors and every vendor
  • The security baseline configured while there is nobody at all to disrupt, which is the cheapest hardening you will ever buy
  • License plan family chosen for the company you are becoming, not the two people you are today
  • The evidence trail your first SOC 2 or customer security review asks for exists from day one
Book a setup call
Setup now vs remediation later

The identical tenant, founded properly or repaired afterward.

Everything below costs almost nothing on an empty tenant and a great deal to retrofit onto a live one. This is the straight comparison between paying once for the setup and paying later for the remediation, with a default self-service setup shown alongside for reference.
SPF, DKIM, DMARC live before first email
Founded on day one
Default self-setupSPF only, usually
Remediated laterAfter deliverability pain
Conditional Access baseline
Founded on day one
Default self-setupSecurity defaults
Remediated laterDisruptive rollout to live users
Break-glass accounts
Founded on day one
Default self-setup
Remediated laterOften only after a lockout
License plan matched to roles
Founded on day one
Default self-setupOne plan for everyone
Remediated laterTrue-up after overspend
SharePoint architecture
Founded on day oneDesigned empty
Default self-setupDefault sites
Remediated laterRestructure with live data
Teams governance
Founded on day oneRules before sprawl
Default self-setupAnyone creates anything
Remediated laterCleanup project
Retention understood and set
Founded on day one
Default self-setupDefaults, unread
Remediated laterDiscovered during an incident
User disruption
Founded on day oneNone, no users yet
Default self-setupNone, until it breaks
Remediated laterEvery change touches staff
Documentation
Founded on day oneHandover included
Default self-setupNone
Remediated laterReverse-engineered
Feature
Founded on day one
Default self-setup
Remediated later
SPF, DKIM, DMARC live before first email
SPF only, usuallyAfter deliverability pain
Conditional Access baseline
Security defaultsDisruptive rollout to live users
Break-glass accounts
Often only after a lockout
License plan matched to roles
One plan for everyoneTrue-up after overspend
SharePoint architecture
Designed emptyDefault sitesRestructure with live data
Teams governance
Rules before sprawlAnyone creates anythingCleanup project
Retention understood and set
Defaults, unreadDiscovered during an incident
User disruption
None, no users yetNone, until it breaksEvery change touches staff
Documentation
Handover includedNoneReverse-engineered
License plan fit

The plan families side by side, so the conversation about fit can be an honest one.

No prices on this page, and that is deliberate. The mistake a new company makes is never overpaying by a handful of seats. It is choosing a plan family incapable of enforcing the security posture they need, and then finding that out eight months later. What follows is the capability picture we walk through on the discovery call. Whoever sells you the licenses quotes the numbers.

Business email and Teams

Business Basic
Yes
Business Standard
Yes
Business Premium
Yes
Enterprise E plans
Yes
F plans (frontline)
Yes

Desktop Office apps

Business Basic
Web and mobile only
Business Standard
Yes
Business Premium
Yes
Enterprise E plans
Yes
F plans (frontline)
Web and mobile only

Intune device management

Business Basic
No
Business Standard
No
Business Premium
Yes
Enterprise E plans
Plan dependent
F plans (frontline)
Limited

Advanced identity protection

Business Basic
Baseline only
Business Standard
Baseline only
Business Premium
Yes
Enterprise E plans
Strongest on E5
F plans (frontline)
Baseline only

Advanced threat protection for email

Business Basic
Add-on
Business Standard
Add-on
Business Premium
Included
Enterprise E plans
Included, deepest on E5
F plans (frontline)
Add-on

Typical fit

Business Basic
Mailbox-and-browser roles
Business Standard
Standard knowledge workers
Business Premium
Most US SMBs, our default recommendation
Enterprise E plans
Larger or regulated organizations
F plans (frontline)
Retail, site, and field staff
Business BasicBusiness StandardBusiness PremiumEnterprise E plansF plans (frontline)
Business email and TeamsYesYesYesYesYes
Desktop Office appsWeb and mobile onlyYesYesYesWeb and mobile only
Intune device managementNoNoYesPlan dependentLimited
Advanced identity protectionBaseline onlyBaseline onlyYesStrongest on E5Baseline only
Advanced threat protection for emailAdd-onAdd-onIncludedIncluded, deepest on E5Add-on
Typical fitMailbox-and-browser rolesStandard knowledge workersMost US SMBs, our default recommendationLarger or regulated organizationsRetail, site, and field staff
How setup works

From the first call to a documented handover in roughly a week.

This is a short engagement with a fixed scope. Most of the calendar time is DNS propagating and the mail authentication being observed rather than anybody working, and your team can start using the tenant the moment the foundation has been verified.
  1. 1

    Discovery call

    1 hour

    The shape of the company, how many people you expect over the next eighteen months, which regulations apply, whatever email exists today, who owns the domain, and what you intend to do about devices. What comes out is a written plan carrying a recommendation on which plan family fits, alongside every single decision we would be making on your behalf, listed for you to approve.

  2. 2

    Foundation build

    2-4 days

    The tenant created or taken over, the domain verified, the DNS records placed, the access baseline applied, the administrative and emergency account structure built, the SharePoint and Teams architecture stood up, retention configured, and the device enrollment path established. Where mail is coming across from Google Workspace or another tenant, the migration runs inside this same window.

  3. 3

    Verification and hardening check

    1 day

    Every item on the hardening checklist tested and evidenced rather than assumed. Mail authentication verified from a mailbox outside your tenant, multifactor and the legacy protocol block both confirmed, somebody actually signing in with an emergency account, and the sharing rules probed from outside. Nothing gets declared finished on the strength of a screenshot of a settings page.

  4. 4

    Handover with documentation

    1 session

    A walkthrough with whoever owns or runs the business, plus the written handover covering the accounts, the DNS, every policy alongside its reason, the emergency account procedure, how licensing is assigned, and the short list of decisions deliberately left for later. From that point you can run it yourself, hire somebody to run it, or move onto our management service. All three are fine.

Tenant setup FAQ

What founders and managers ask before we start.

The actual effort runs to days rather than weeks: two to four days of building plus a day verifying it, wrapped around a one hour discovery call at the start and a handover session at the end. Calendar time comes out around a week, because DNS propagating and mail authentication being observed both involve waiting rather than working. Where mail is also coming across from Google Workspace or an older tenant, add time in proportion to how many mailboxes there are, agreed in the plan before anybody starts.

Yes, and that is precisely why doing the setup properly matters. The foundation for five people is identical to the foundation for five hundred: a verified domain, mail authentication, access policy, an administrative structure, a SharePoint architecture and rules about governance. What scales is the number of licenses, never the design. A tenant founded correctly at five people grows by adding people. A default tenant grows by accumulating problems that all surface simultaneously somewhere between thirty and fifty staff.

A written handover covering every administrative account and what it is for, the emergency account procedure, every DNS record placed and the reason for it, every access policy along with its intent and its exceptions, the SharePoint and Teams architecture, the retention settings and where they stop, licensing assigned person by person, and a short list of decisions worth revisiting as the company grows. Plus a live walkthrough, so that somebody understands it rather than simply filing it.

You own all of it. The tenant, the domain, the licensing and the top administrative rights. Our access is delegated and you can revoke it at any moment. We insist on that arrangement despite it making us considerably easier to dismiss, because the alternative, a provider holding your administrative rights or your domain registration, is the single most common trap we pull companies out of.

Yes. That is remediation rather than setup, and it applies the same checklist to a live environment. We audit what exists, keep whatever is already right, and fix the remainder in an order that does not interrupt anybody trying to work. It takes more effort than building on day one, because every change now touches real people and real data, which is exactly why we tell new companies to do this before they hire anybody. Where a tenant is genuinely beyond saving, or sits under somebody else control entirely, we build a fresh one and migrate you across.

Yes, and it is the most common migration we run inside a setup engagement. Mail, calendars, contacts and files all move across, the domain repoints, and everybody cuts over inside a planned window, usually across a weekend. The foundation work happens first, so you land on a hardened tenant rather than an empty one. Coexistence gets planned properly so that nothing bounces while the switch is happening.

It turns on the mix of roles rather than the headcount. The entry plan suits anybody living in a mailbox and the browser. The standard tier adds the desktop applications. Business Premium adds the security and device management most American small businesses genuinely ought to be running. The enterprise plans fit larger or regulated companies, and the frontline plans fit staff who need mail and Teams without a full desktop. On the discovery call your roles get mapped to plan families. The pricing itself comes from whoever sells you the licenses.

The built-in defaults enforce multifactor and close the legacy protocols, and for somebody personal tenant they are entirely adequate. A business needs policy it can shape: an exception for the meeting room account, stricter rules covering administrators, control over where a sign-in may originate, and the ability to add device conditions later on. The defaults are all or nothing and they quietly limit what you can do next. We start you on a proper access baseline so that security can grow alongside the company rather than being switched off in frustration the first week it inconveniences somebody.

They are emergency administrative accounts held outside the access policies, carrying long random passwords stored securely offline, and used only when normal administrative access has failed. A multifactor outage, a policy somebody misconfigured that locked everybody out, or an administrator account being contained after a compromise. Two exist so that one of them failing, expiring or simply being unreachable does not leave you with none. Every serious tenant has them. Almost no tenant somebody set up themselves does, and that gap gets discovered halfway through a lockout.

Microsoft keeps your service running and replicates data for resilience, and retention policies can preserve content, but none of that is a backup in the sense of point-in-time restore after ransomware, malicious deletion, or a departed admin's cleanup. During setup we configure retention deliberately, document its limits in plain language, and recommend a third-party Microsoft 365 backup where the risk justifies it. The decision is yours; our job is to make sure it is an informed decision made on day one, not a discovery made during an incident.

Substantially. SOC 2 readiness and HIPAA security assessments both ask tenant-level questions: is MFA enforced, how is admin access controlled, how are leavers offboarded, is audit logging on, what does retention do. A founded tenant answers each from the handover document, because the controls went in before the first user and the evidence has existed since day one. For HIPAA-covered organizations, Microsoft offers a Business Associate Agreement for Microsoft 365; the tenant still has to be configured so your side of it is real, which is exactly what the setup delivers. We build controls and evidence; your compliance advisors own the interpretation.

Yes, and it is worth doing carefully. The clean path is a cooperative handover: the provider transfers Global Admin to accounts you own, we audit what they built against our baseline, and delegated access is re-established on your terms. When the relationship is not cooperative, leverage usually sits with whoever controls the domain registration and the tenant, so we start by establishing exactly what you control today, then either recover admin rights through Microsoft's processes or build a fresh tenant you own and migrate into it. Either way, the end state is the same: your tenant, your domain, your admin rights, documented.

The tenant work is cloud configuration, so the entire engagement runs remotely: discovery call, build, verification, and the handover walkthrough all happen over video sessions on your schedule. That also means time zones are not a constraint; founders setting up a US entity from abroad can run the whole engagement before relocating. Device provisioning that pairs with the setup is designed remotely too, using Autopilot so laptops enroll themselves out of the box wherever they ship.

No. Setup is a fixed engagement and the handover is designed so you can run the tenant yourself or give it to any provider. That said, most clients keep some relationship: our Microsoft 365 tenant management service takes the day-to-day administration, joiner-mover-leaver changes, and security monitoring off your plate, and the engineers who built your foundation already know it. Both paths are legitimate; the documentation makes either work.
After the foundation

Where a founded tenant goes next.

Microsoft 365 Tenant Management

Ongoing administration of the tenant we founded: users, licenses, policies, and monitoring as a service.

Learn more

Tenant Security Baseline

The full hardening standard behind our day-one checklist, applied to new and inherited tenants.

Learn more

Startup IT Business Kit

The wider first-hire IT stack for new companies: devices, identity, security, and support from day one.

Learn more
Founding a company?

Get the tenant right once, before your first hire logs in.

A one-hour discovery call produces a written setup plan: the license plan family that fits, the decisions we will make, and the day-one hardening checklist you will receive evidence against. If your tenant already exists and needs rescuing, the same call scopes the remediation honestly.

Book a setup callSee Microsoft 365 services

Related Services

Explore more solutions that work great with this service

M365 Tenant Management

Your tenant run properly, end to end

Learn more

Tenant Security Baseline

Documented controls mapped to CIS

Learn more

M365 Administration

Expert Microsoft 365 tenant management

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Microsoft Intune

Device management and endpoint security

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA