Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Microsoft 365

Microsoft 365 for SMBs in Quebec: migration, security, Teams, SharePoint and Intune

Microsoft 365 puts your email, your files, your meetings and your identities in one place. It has also become the main target of attacks against small businesses. OKTO Solutions deploys, migrates, secures and manages your Microsoft 365 environment so your teams work without friction and without an open door.

Managed Microsoft 365 covers migrating email and files, right-sizing licences workstation by workstation, securing identities with multifactor authentication and conditional access, setting up Teams and SharePoint, then administering the accounts day to day. Without a named owner, a Microsoft 365 tenant drifts toward licences paid for nothing and shares left wide open.

In short

What is managed Microsoft 365 for an SMB?

A managed Microsoft 365 environment means someone takes full charge of the licences, the identities, the mailboxes, the SharePoint and OneDrive files, Teams and the devices enrolled in Intune, and keeps all of it secure. It is meant for Quebec SMBs that already use Microsoft 365 without anyone really owning it, and for those leaving a local mail server or a file share behind. The result shows up in three places: the licences finally match real use, access is under control, and employees stop working around tools that were badly set up.

Microsoft 365 is not a product you install once. It is an environment that keeps moving. Microsoft changes settings, your employees come and go, your shares multiply and your devices get replaced. So our engagement covers the daily administration as much as the initial setup.

  • Licences adjusted as people leave, so you stop paying for dormant subscriptions
  • Accounts created and removed at the pace of your hires and departures
A workstation set up properly on day one means an employee who never has to call to find their files.
  • Security policies kept current, without waiting for an incident to force the issue
  • Monitoring of the signals that give away a compromised account
  • A dedicated backup of your Microsoft 365 data, with restore tests

What the service includes

What OKTO covers in managing Microsoft 365

Six areas, one engagement, because they all rest on the same identities.

Email and domain

Mailboxes, shared mailboxes, distribution lists, aliases, and protection against domain spoofing with SPF, DKIM and DMARC.

Accounts and departures

Accounts created on hiring, blocked the same day someone leaves, sessions revoked, mailbox and OneDrive handed over to the manager.

SharePoint and OneDrive

Site structure, libraries, permissions by group rather than by person, and a clean-up of sharing links open to the whole world.

Teams

Teams, channels, meetings, telephony, retention policies and clear rules about who is allowed to create what.

Identities and devices

Multifactor authentication, conditional access, separate admin accounts, workstations and phones enrolled in Intune.

Data backup

A dedicated backup of Exchange, SharePoint, OneDrive and Teams, with restore tests on the calendar.

The copy runs in the background while your teams keep working.

The migration

How does a Microsoft 365 migration actually go?

A successful migration is judged on the Monday morning after. People open Outlook and everything is there. You get there by preparing, not by improvising: a full inventory before anything is touched, data copied while the old system stays live, a cutover at an agreed hour, then the security work. The old server is decommissioned only after everything checks out, never before.

  1. Inventory and plan

    Mailboxes and their size, distribution lists, shared mailboxes, files to move, software that sends mail, devices in use. We also check the domain name and its records. The plan sets the order, the groups of employees and the cutover window.

  2. Preparation and copy

    We prepare the Microsoft 365 tenant, the licences, the security policies and the file structure. Email and documents get copied in the background. Nothing is cut off at this stage.

  3. Cutover and support

    Mail switches over at an agreed time, often in the evening, followed by a final pass on recent items. We configure the workstations and the phones, and we stay available the first few days to explain what actually changes.

  4. Security and handover

    Multifactor authentication, conditional access, shares closed back up, admin accounts separated from everyday accounts, backup turned on and tested. The environment then moves into our managed IT services.

The audit

A Microsoft 365 audit: what we find almost every time

When we take over a Microsoft 365 environment that has never been managed, the same findings come back. None of them needs an expensive tool to fix. All that was missing was someone whose job it was.

  • Licences billed every month for employees who left, or subscription tiers higher than the workstations need
  • Accounts of former employees still active, sometimes with their mail forwarded to a personal address
  • No multifactor authentication on the admin accounts, which is precisely where it matters most
  • SharePoint sites and folders shared with the entire organization, or through a link anyone who has it can open
  • Auto-forwarding rules left behind by an old compromise, quietly copying mail to the outside
  • No backup of the Microsoft 365 data at all, on the belief that Microsoft handles it
  • Devices reaching company email without being enrolled in Intune or subject to any policy
  • A domain with no DMARC record, so anyone can write in your company’s name

The audit produces a prioritized list of those gaps, with the effort each fix takes. You then decide what you correct yourself and what you hand to us.

Licensing

Which Microsoft 365 plan for which job?

The question that comes up most often in an SMB is whether everyone needs the same subscription. The answer is almost always no. A warehouse employee who reads three emails a week does not have the same needs as a controller handling financial data on a laptop that leaves the building. Here are the common plans for a small business, sorted by how the job actually uses them. The choice is made one workstation at a time, then revisited when someone changes role or leaves.

Plan Which job it suits Installed applications What it gives you
Exchange Online Plan 1 A plant, warehouse or field worker who only needs an email address No Mailbox, calendar and contacts. Nothing else.
Microsoft 365 Apps for business A workstation that needs Word, Excel and Outlook installed, with no hosted email service Yes The installed applications and OneDrive. No mailbox.
Microsoft 365 Business Basic An office worker who does perfectly well in the browser No Email, Teams, SharePoint, OneDrive, web versions of the applications.
Microsoft 365 Business Standard A classic desk job that handles documents all day long Yes Everything in Basic, plus the installed applications and webinars.
Microsoft 365 Business Premium Management, accounting, human resources, admin accounts and laptops Yes Everything in Standard, plus Intune, conditional access, advanced email protection and information encryption.
Worth remembering: an assistant like Copilot is a licence that sits on top of one of these plans, never a replacement for it. And a dormant licence costs exactly as much as one somebody uses. Costs are presented on request, once the workstations have been inventoried.

Security

How do you secure Microsoft 365 in a small business?

Securing Microsoft 365 comes down to a handful of moves that in most cases cost nothing in extra licensing, but that have to be made and then verified. Multifactor authentication first, on every account and above all on the admin accounts. Conditional access next, to refuse a sign-in coming from a country where you have no employees. Then the auto-forwarding rules to the outside, which are the first reflex of an attacker who has just taken over a mailbox.

  • Multifactor authentication enforced by policy, not left to individual goodwill
  • Conditional access: allowed countries, known devices, legacy applications blocked
One forwarding rule left in place can copy your mail to the outside for months without anyone noticing.
  • External forwarding rules blocked, with an alert when someone creates one
  • Named admin accounts, kept separate from everyday working accounts
  • SPF, DKIM and DMARC configured so nobody writes in your domain’s name
  • Workstations and phones enrolled in Intune, with remote wipe if one goes missing

Governance and Copilot

Do you have to clean house before turning on Copilot?

Yes, and that is the only honest answer. Copilot reads whatever the user is already allowed to see. If an assistant has been given access to the payroll folder or to management’s files by mistake, a tool that searches and summarizes on their behalf will make that access far more visible, far faster. So data governance comes before activation: SharePoint permissions rebuilt by group, open sharing links closed, sensitive documents labelled and sorted. That work pays off even if you then decide not to deploy an assistant at all.

After that, start small. A limited group, specific and repetitive tasks: meeting summaries, searching internal documents, first drafts of written work. Look at what genuinely got used before going wider. Plenty of the requests that reach us under that banner are really tasks to automate rather than to assist, and our page on business automation and intelligent tools explains the difference.

Cleaning up permissions is not a technical prerequisite for Copilot. It is the only way to find out what your company is already exposing, assistant or no assistant.

Antonio Pazzi, founder of OKTO Solutions

Comparing the models

Managed service, licence reseller, or running it in house

Three ways to live with Microsoft 365 in a small business. They do not cost the same, and above all they do not cover the same risks.

Managed by OKTO

Someone owns the environment day to day: licences adjusted, accounts removed on time, policies kept current, backup verified, users supported. Changes are documented, and you stay the owner of the tenant, the domain and the data.

Through a licence reseller

You get the subscriptions and an invoice. Nobody looks at your configuration: the shares stay open, the accounts of people who left stay active, the dormant licences keep getting billed. The day something is compromised, there is neither monitoring nor history.

Running it all in house

An organization with a solid IT person can administer Microsoft 365 itself. The hard part is consistency. Settings change, departures have to be handled the same day and the backup has to be tested. This is a good case for co-managed IT.

Our office is in Trois-Rivières and the service is offered across Quebec, remotely and on site when the job calls for it. See our IT services in Trois-Rivières or our IT services and Microsoft 365 migrations in Montreal. Microsoft 365 covers the office side; for your servers and your applications, see our cloud and Azure work.

Questions and answers

Frequently asked questions about Microsoft 365 for SMBs

How long does a Microsoft 365 migration take for an SMB?
Up to 25 mailboxes, we see 2 to 4 weeks. From 25 to 100 mailboxes, 4 to 8 weeks. Beyond that, it depends on the starting point. Those are ranges observed on our own projects, not a commitment: the length also depends on the volume of email and files to move, and on the in-house software that sends mail. The copy runs in the background while your teams keep working, and only the final cutover needs an agreed window, usually outside business hours.
Will we lose email or files during the migration?
No. The data is copied, not moved: the old system stays intact and working until everything has been verified. A final pass picks up whatever arrived during the cutover, and the old server is only decommissioned once you say so.
Does Microsoft back up our data in Microsoft 365?
Microsoft guarantees the availability of its platform and keeps deleted items for a limited period. That is not a backup: a file erased several months ago, a mailbox emptied by an employee on the way out, or data encrypted by ransomware will not come back that way. We add a dedicated backup and we test the restore.
Which Microsoft 365 licences does an SMB need?
It depends on what your employees actually do: email only, installed desktop applications, device management, advanced security features. We start from real use, workstation by workstation, rather than applying the same subscription to everyone, and we drop the licences that no longer serve anyone. Costs are presented on request.
Can we keep our domain name and our email addresses?
Yes. Your domain name and your addresses stay the same. We adjust the domain records at cutover, and we take the opportunity to put the anti-spoofing protections for your domain in place.
Should we turn on Copilot in our company?
Not before the permissions have been cleaned up. Copilot works from whatever the user is already allowed to open: if the sharing is too broad, the assistant will make that problem very obvious. We recommend fixing the access first, then starting with a small group and specific tasks before going wider.
What happens when an employee leaves the company?
The account is blocked the same day, the session is revoked on every device, the mail is forwarded or turned into a shared mailbox depending on what you want, the OneDrive files go to the manager and the licence is released. It is a documented procedure, not something improvised on a Friday afternoon.

Ask for an audit of your Microsoft 365

We review your tenant, then hand you the list of what is misconfigured, what is being paid for nothing and what is exposing you. You decide what comes next, with no obligation.