Skip to content

Microsoft 365 and Azure as the office you already live in

Written by AERVIO, a Montreal studio. Human-reviewed before publish. Contact: hello@aervio.io · +1 438-498-3913.

Microsoft 365 and Azure as the office you already live in

“Cloud services” as a poster usually means a tour of Azure icons. Your people already live in mail, files, chat, and a login screen. That workplace is the product. AERVIO keeps it patched and boring so nobody is the accidental global admin.

We are not allergic to Azure. We are allergic to a subscription full of forgotten virtual machines, a SharePoint site named “Documents (1),” and fourteen people with God rights because onboarding copied last year’s user.

Identity first, always

Joiners get a standard: licence, groups, MFA, device, mailbox. Leavers lose it in a written order the same day — not “when someone remembers.” Shared mailboxes do not use a shared password. Admin roles are few and named.

If MFA is “recommended” and not required for admins, you do not have a workplace. You have a hope. The companion piece is MFA, logging, and restores.

Mail and files without a second file server in spirit

Moving to Microsoft 365 and then syncing a chaotic on-prem file server forever is how you pay twice. We pick a structure (libraries people can find), archive what is dead, and stop mapping S: from 2009 unless there is a line-of-business reason.

Retention is a legal conversation (including Law 25). We implement what counsel and you decide. We do not invent a seven-year rule because it sounded corporate.

Azure bits that deserve to exist

A VM for a vendor app that only runs on Windows Server: fine, with backups and a named owner. A VM because someone clicked “quickstart” in 2021: off.

App registrations, storage accounts, and DNS in Azure live on an inventory. If it is not on the inventory, it is next month’s surprise invoice.

Official docs we actually use with customers live on Microsoft Learn — not on a partner one-pager.

How this connects to the studio work

The website and CRM often use the same identity. SSO that works is worth more than a custom login we have to babysit. DNS for the Next.js or WordPress site and DNS for mail like to break together; one workplace owner beats two vendors pointing at each other.

Hands-off customers get this as part of the desk. In-house teams get it as bench projects. Same technical standard, different who-owns-the-tenant.

A 30-day dullness program

  1. Inventory licences, admins, domains, Azure resources
  2. Enforce MFA on privileged roles; schedule the rest
  3. Kill stale guest accounts
  4. Restore a mailbox and a SharePoint library to prove it
  5. Write the joiner/leaver page your manager can follow

Dull is the goal. Excitement in a tenant is an incident.

If your invoice has SKUs nobody can explain, send the PDF (redact amounts if you want) to hello@aervio.io. We will mark what is unused before we talk about “cloud strategy.”

SharePoint as a junk drawer

If everything is in “General” with 8,000 files named `final_v7`, 365 is not a workplace. It is a guilt pile. We pick libraries by team, archive with a date, and stop syncing the entire tenant to every laptop. Syncing everything is how laptops die and how Law 25 gets interesting (data on a café Mac).

Guest links

A link that “anyone with the link can edit” from 2022 is still live. We search for those. We kill them or expiry them. This takes an afternoon and prevents a class of incident that never looks like hacking in the movies.

Conditional access without a science fair

Start with: admins cannot sign in from a random country at 03:00 without MFA. Then: unmanaged devices cannot open the finance library. Stop before you lock the warehouse scanner out of existence. Each policy needs a named exception process. Otherwise your helpdesk *is* the exception process, at midnight.

Unused SKUs on a PDF remain the fastest brief.

Questions

Are you a Microsoft partner tier we should brag about?

We implement the workplace you already pay for. Partner badges are not the offer. Named admins, MFA, and a restore you have seen are the offer.

Must everything live in Azure?

No. If a VM does not earn its keep, we turn it off. 365 without a zoo of virtual machines is a normal, healthy outcome.

Can you work with Google Workspace instead?

Yes, as identity and mail. The same rules apply: you keep the tenant, we document leavers, we test restore.

Let's write the next step.

AERVIO web development illustration — Montreal studio AERVIO growth illustration — the next URL after launch