Microsoft 365

Admin & Management

We take full ownership of your Microsoft 365 environment - keeping it secure, compliant, and running exactly the way your business needs it.

Best for: SMEs that want expert-level M365 administration without the overhead of an in-house IT team.

How We Manage Your Tenant

A structured process that keeps your environment stable, auditable, and aligned with how your business actually operates.

01

Tenant Discovery and Baseline

We begin with a full audit of your existing Microsoft 365 environment - identifying configuration gaps, unused licences, legacy settings, and security risks. This gives us a clear baseline and surfaces quick wins before ongoing management begins.

02

Security Hardening and Baseline Policies

We apply or review your tenant's security baseline - conditional access policies, MFA enforcement, admin role separation, and Defender for Business settings. Everything is documented so you know exactly what is in place and why.

03

Ongoing Administration and Change Requests

Your team submits change requests through your normal support channel - new starters, leavers, licence changes, policy updates, new Teams setups. We action them within SLA, apply the change safely, and document everything we do in your environment.

04

Proactive Monitoring and Alerts

We monitor your tenant health, service alerts, and Microsoft Secure Score continuously. If Microsoft rolls out a breaking change or a threat is detected in your environment, we respond before your team notices a problem - not after.

05

Regular Reporting and Reviews

You receive a monthly summary of activity in your tenant - changes made, licences in use, security posture, and any recommendations. Quarterly reviews align your M365 configuration with where your business is heading.

What We Manage For You

From day-to-day user administration to security policy enforcement, we handle every layer of your M365 tenant so your team can stay focused on the work that matters.

User Administration

  • New user onboarding and account setup
  • Licence assignment and optimisation
  • Offboarding with data retention handling
  • Group and distribution list management
  • Role-based access control (RBAC)

Security & Compliance

  • Conditional access policy management
  • Multi-factor authentication enforcement
  • Microsoft Secure Score monitoring
  • Defender for Business configuration
  • Data Loss Prevention (DLP) policies

Exchange & Email

  • Mailbox configuration and quota management
  • Anti-spam and anti-phishing policy tuning
  • Shared mailbox and alias setup
  • Email routing and connector management
  • Litigation hold and eDiscovery support

SharePoint & OneDrive

  • Site collection creation and governance
  • External sharing policy configuration
  • Storage quota management
  • Permission auditing and cleanup
  • Document library structure support

Teams & Collaboration

  • Team and channel creation and governance
  • Guest access policy management
  • Teams Phone and calling plan setup
  • Meeting policy configuration
  • App permission management

Change Requests

  • Any admin change actioned within agreed SLA
  • Licence add, remove, and swap requests
  • Policy updates as business needs evolve
  • App integration and connector enablement
  • Tenant-wide setting changes with review
Change Request Response Times

All M365 admin tasks are handled within defined SLAs. Urgent requests - such as offboarding a leaver immediately or responding to a security incident - are treated as priority regardless of request type.

Request Type Examples Priority Response Completion
Security Incident Compromised account, MFA bypass, data leak alert Critical 15 min 1 hour
User Offboarding Disable account, revoke sessions, redirect mailbox High 30 min 2 hours
New User Onboarding Account creation, licence assign, group membership Medium 2 hours 4 hours
Policy or Config Change Conditional access update, sharing settings, DLP rule Medium 4 hours Next business day
Licence Change Upgrade, downgrade, add or remove a licence Low 4 hours Next business day
General Admin Task New Teams channel, shared mailbox, alias, group Low 8 hours 2 business days
Why Managed M365 With On IT

Security-First Administration

Every change we make is assessed for security impact before it is applied. We follow the principle of least privilege as standard and document every action in your tenant for full auditability.

Full Change Documentation

Every admin action is logged against a ticket, giving you a complete record for internal governance, insurance requirements, or compliance audits. You always know what changed and when.

Licence Optimisation

Most businesses overspend on Microsoft licences. We review your assignments quarterly, identify unused or duplicated licences, and make recommendations that reduce your M365 spend without losing capability.

Fast Turnaround on Requests

No waiting until someone has a free moment. Requests go into a managed queue and are actioned to SLA by engineers who work in M365 environments every day - not generalists figuring it out as they go.

Stays Current with Microsoft

We track the Microsoft 365 roadmap and message centre on your behalf, alerting you to changes that affect your business and applying tenant updates before they cause disruption.

Visibility Without the Noise

Monthly reports give you a clear picture of your tenant's health, user activity, and security posture - without requiring you to dig through the admin centre yourself. We surface what matters.

Common Questions

Do we need to give On IT full Global Admin access?

No. We work with you to establish a delegated admin relationship through Microsoft's Partner Centre where appropriate, or assign the minimum roles needed to perform administration safely. We never ask for broader access than the work requires, and all access is documented.

How do we submit change requests?

Through your existing On IT support channel - email, portal, or Teams depending on your setup. You do not need to learn a separate system. Everything flows through the same ticketing process as your other IT support.

What if we already have someone internally who handles some M365 tasks?

We work alongside your team, not over them. We can take full ownership or act as the escalation point and specialist resource for more complex or sensitive changes. We agree the split of responsibilities clearly at the start of the engagement.

Is Microsoft 365 Admin included in my Managed IT package?

M365 administration is included in qualifying Managed IT packages. The scope - number of users, change request volume, reporting cadence - is defined in your service agreement. Speak to us if you want to confirm what is included or discuss upgrading.

Do you manage Microsoft licences and billing?

We can procure and manage your Microsoft 365 licences directly through our partner programme, which often means simplified billing and access to advisor support. Alternatively, if you prefer to retain direct Microsoft billing, we manage the admin side only. We discuss the options that make most sense for your business.

What happens when Microsoft makes changes that affect our environment?

We monitor the Microsoft 365 message centre and roadmap as part of your managed service. If an incoming change affects your configuration, user experience, or security posture, we will notify you in plain language and - where action is required - handle it before the change takes effect. You should not have to read Microsoft's technical release notes yourself.

Take M365 Off Your Plate

Whether you need full M365 administration or want to fill gaps alongside your existing team, we can scope a service that fits. Get in touch and we will walk through your environment and what managed admin would look like for you.