
Microsoft 365 Implementation & Setup
Licences bought from a card checkout arrive as an empty tenant. Implementation is everything between that and a business actually running on it.
Tenant and domain, identity, a real security baseline, SharePoint and Teams structure that matches how you work, and documentation for whoever owns it afterwards — designed with you, built once, and handed over.
What a Microsoft 365 implementation covers:creating and configuring the tenant, verifying your domain and setting DNS records including SPF, DKIM and DMARC, building user accounts and groups, applying a security baseline, structuring SharePoint and Teams, enrolling devices where the plan supports it, migrating your existing mail and files, switching MX records at a planned cutover, and handing over documentation. Typically one to three weeks for a business of 10–50 users.
Eight things that get configured
Tenant and domain
Tenant created in the right region, your domain verified, and the DNS records that make it work — MX, SPF, DKIM and DMARC — configured rather than left at the registrar's defaults. Getting SPF and DKIM right at the start is the difference between your invoices arriving and your invoices going to junk.
Identity and accounts
User accounts, groups, and the naming convention you will live with for years. Shared and role mailboxes set up as shared mailboxes — which need no licence — rather than as paid user accounts, which is where a lot of quiet recurring spend comes from.
Security baseline
Multi-factor authentication enforced, admin roles separated from day-to-day accounts, legacy authentication blocked, and conditional access where the plan supports it. A tenant on defaults is not secure because you bought Premium.
SharePoint and OneDrive structure
Sites and document libraries that match how the business is actually organised, with sharing rules decided deliberately. This is the piece that is genuinely hard to change later, because by then everyone has bookmarks and links.
Teams structure
Teams and channels that map to real work rather than to the org chart, with guest access and external sharing set to what you actually want. Left to grow organically, Teams becomes unsearchable within a year.
Device enrolment
Where Business Premium is in play, company devices enrolled into Intune with compliance policies and the ability to wipe a lost laptop. Skipped where it is not needed rather than sold as mandatory.
Mail flow and coexistence
Routing configured so that mail keeps working during the transition, including any period where some people are on the old system and some are on the new one.
Documentation and handover
What was configured, why, and how to do the five things you will need to do yourself — add a user, remove a leaver, reset a password, add an alias, restore a deleted file.
Six stages, each with something you can see
Every stage produces an output you can review. That is deliberate — it is how you know where a project has got to without asking.
| Stage | What happens | What you get |
|---|---|---|
| 1. Discovery | User count and roles, what you run today, DNS and domain ownership, compliance requirements, and which devices are company-owned. Usually a single call plus access to your DNS. | A written scope and a plan recommendation |
| 2. Design | Naming conventions, group and site structure, sharing and security policy, licence allocation per person. Agreed with you before anything is built, because these are the decisions that are expensive to reverse. | A design document you sign off |
| 3. Build | Tenant configured, identity created, security baseline applied, SharePoint and Teams structure built, devices enrolled. Your existing email keeps running untouched throughout. | A working tenant, not yet live |
| 4. Migrate and verify | Mail, calendars, contacts and files copied across and checked against the source. Discrepancies are found here, while there is still time and the old system is still authoritative. | Verified data in the new tenant |
| 5. Cutover | MX records switched at a low-traffic window agreed with you. We watch mail flow through the change rather than switching it and going home. | Live on Microsoft 365 |
| 6. Handover and support | Short role-specific sessions for staff, admin documentation for whoever owns it internally, and a support window while the questions are still frequent. | Documentation and a named contact |
Six decisions that are expensive to reverse
These are the questions we bring to the design stage. None of them are technical, all of them are about how your business actually works, and every one of them is far cheaper to answer now than in eighteen months.
One domain or several
Businesses with multiple trading names often want separate domains on one tenant. Straightforward if planned, messy if retrofitted.
How shared addresses work
accounts@, info@, sales@ — as shared mailboxes, distribution lists, or Teams channels. They behave differently and the wrong choice is felt daily.
Who can share externally
Locked down, open, or per-site. The default is more permissive than most businesses realise once they look at it.
What happens when someone leaves
Mailbox converted to shared, OneDrive reassigned, licence reclaimed. Decide the process before you need it, not during a resignation.
Whether devices are managed
Intune is powerful and it is also a commitment. Worth it for company-owned laptops handling client data; overhead for a team on personal machines.
Where files actually live
OneDrive is personal, SharePoint is organisational. Teams that put everything in OneDrive lose it when the person leaves, which is the single most common structural mistake.
Six things we find on self-installed tenants
A fair share of our Microsoft 365 work is not new deployments but tidying up tenants that were set up quickly by somebody who had other things to do. These six come up constantly.
- error_outline
Everyone on one plan, because it was simpler to buy that way than to ask who needs what
- error_outline
Shared addresses created as licensed user accounts, quietly costing a seat each every month
- error_outline
SPF and DKIM never configured, so the domain is spoofable and invoices land in junk
- error_outline
Files left in personal OneDrive rather than SharePoint, so access leaves with the employee
- error_outline
Multi-factor authentication left optional because it seemed like it would cause complaints
- error_outline
No documented offboarding, so departed staff keep access and keep consuming licences
If any of these describe your tenant, a licence and configuration review is usually a shorter and cheaper piece of work than a full implementation.

You should not need us to add a user
A good handover means the routine things are yours. We document how to add a user, offboard a leaver, reset a password, add an alias and restore a deleted file — with the specifics of your tenant, not links to generic Microsoft articles.
What stays with us is the work that genuinely needs someone who does it often: policy changes, anything touching mail flow or DNS, licence right-sizing at renewal, and the problems that are not in any documentation. Where you have internal IT, the handover is written for them and they take the lot.
See the full range of Microsoft 365 services →Implementation — common questions
helpHow long does a Microsoft 365 implementation take?
expand_more
For a straightforward business of 10 to 50 users moving from webmail or Google Workspace, typically one to three weeks from discovery to cutover — most of which is waiting on data copying and on your availability for decisions, not on hands-on work. Larger organisations, on-premise Exchange, or complex SharePoint structures take longer. We give you a timeline in the scope rather than an estimate over the phone.
helpWill our email go down during the setup?
expand_more
No. The new tenant is built and populated while your existing email keeps running, so nothing depends on a single switchover moment. The only genuinely time-sensitive step is the MX record change, which we schedule for a low-traffic window — typically a Friday evening or a weekend — and watch through. Mail arriving mid-change is delivered once DNS propagates.
helpDo you configure security, or just set up the accounts?
expand_more
Security is part of the implementation, not an upsell. Multi-factor authentication, admin role separation, blocking legacy authentication, and SPF, DKIM and DMARC on your domain are all in scope by default. Conditional access and device compliance policies apply where your plan includes them — that is a Business Premium capability, and we will tell you plainly if the plan you have does not support what you are asking for.
helpWhat do we need to do ourselves?
expand_more
Three things, realistically. Give us access to your DNS or be available to make record changes. Make the structural decisions — how shared addresses work, who can share externally, how the file structure maps to the business. And tell your staff what is changing and when. Everything else is ours.
helpCan you work with our existing IT team?
expand_more
Yes, and it is usually the better arrangement where one exists. A common split is that we do the design and the build, your team owns day-to-day administration afterwards, and the handover documentation is written for them specifically. We are equally happy to retain administration where there is no internal IT.
helpWhat does implementation cost?
expand_more
It is quoted as fixed scope after the discovery call, based on user count, what you are migrating from, and how much structural work SharePoint and Teams need. We do not quote implementation hourly, because an open-ended hourly rate on a project like this is a bad deal for the client and an argument waiting to happen.
helpDo you set up Microsoft 365 for businesses outside Kerala?
expand_more
Yes. Tech Geum is based in Kerala and works with businesses across India. Implementation, migration and administration are all done remotely, so physical proximity is not a requirement — though working the same hours does make the cutover and the week afterwards considerably easier than a global support queue.
Related pages
Microsoft 365 Migration
The data side: what moves, what does not, and how the cutover is planned.
Microsoft 365 Licensing Explained
Which plan covers what, decided before the tenant is built.
Microsoft 365 Pricing in India
List prices in INR, GST, and what drives your real cost.
Microsoft 365 Services
Licensing, implementation, migration, security and support in one place.
Google Workspace Implementation
The same work on the Google side, if that turns out to be the fit.
Google Workspace vs Microsoft 365
Worth reading before you commit to either one.
Business Email Services
Our wider email practice across the three major suites.
Scope your implementation
A discovery call and a fixed-scope quote, at no charge.
Scope your Microsoft 365 implementation
Tell us your user count, what you run today and whether devices are company-owned. We will come back with a scope, a timeline and a fixed-scope quote before any work starts.
- check_circle
No charge for the discovery call
- check_circle
Fixed-scope quote, not an open-ended hourly rate
- check_circle
Cutover scheduled around your trading hours
If you already run a Windows domain and a file server, the order that matters — identity first, the old server last — is set out on our page for Microsoft 365 partner in Ernakulam.
Prefer to talk first? Call +91 99467 89916 or email admin@techgeum.com.
