How to Set Up Microsoft 365 for a New Small Business: Step-by-Step
Share
Microsoft 365 is the default productivity platform for Australian small business, and setting it up badly is remarkably easy. The sign-up takes fifteen minutes; doing it properly takes a bit longer and saves you years of irritation. This guide walks through a clean setup in the order that avoids rework.
Before you start: decisions to make
Which plan
The Business tier plans cover almost every small business under 300 users. The practical differences:
- Business Basic — cloud services only. Web and mobile Office apps, email, Teams, OneDrive, SharePoint. No desktop Office applications.
- Business Standard — everything in Basic, plus the desktop Office apps installed on your computers. This is what most businesses want.
- Business Premium — everything in Standard, plus device management and the security tooling: conditional access, threat protection, device compliance policies. If you handle sensitive data or have compliance obligations, this is the one.
You can mix plans across your team. Frontline or casual staff who only need email on a phone do not need the same licence as your office manager.
Your domain name
You need a domain you control — yourbusiness.com.au, not a free email address. Make sure the domain is registered in your business's name with login details you hold. This causes more grief than any other single item when a business changes providers or web designers.
Your naming convention
Decide now: firstname@, firstname.lastname@, or initials. Changing it later means changing business cards, signage, vehicle wraps and every supplier record you have. Also decide your shared addresses — info@, accounts@, support@ — and make them shared mailboxes rather than user licences, because shared mailboxes are free.
Step 1: Create the tenant
Sign up for the plan you chose. During sign-up you will create an initial admin account on an onmicrosoft.com address. Keep this account — it becomes your emergency access.
Critical: the tenant must be created under your business's identity, with billing details and recovery contacts you control. If a consultant creates it under their own account, you are renting your own email.
Step 2: Add and verify your domain
In the Microsoft 365 admin centre, add your custom domain. Microsoft gives you a TXT record to add at your domain registrar to prove ownership, then a set of records to route mail and services.
The records you will end up with:
- MX — directs incoming mail to Microsoft
- CNAME records — for autodiscover and various services
- SPF (a TXT record) — declares which servers may send mail as your domain
If you are migrating from an existing email provider, do not change the MX record until your mailboxes are ready. Changing it early means mail arrives at an empty destination.
Step 3: Set up email authentication properly
This step is skipped constantly and it is the difference between your invoices arriving and your invoices landing in spam — or worse, someone spoofing your domain to defraud your customers.
- SPF — lists authorised senders. Include Microsoft, plus any other service that sends mail as you: your accounting software, your CRM, your marketing platform, your website contact form. A common failure is having several of these and exceeding the lookup limit.
- DKIM — cryptographically signs your outgoing mail. Enable it in the Microsoft security portal and publish the two CNAME records it gives you.
- DMARC — tells receiving servers what to do with mail that fails the other two checks. Start in monitoring mode (p=none) with a reporting address, review what you learn for a few weeks, then tighten to quarantine and eventually reject.
Getting all three right is one of the highest-value hours anyone will ever spend on your email.
Step 4: Create users and assign licences
Add your people. For each user, set the display name properly — it appears on every email they send — and assign the appropriate licence.
Set up shared mailboxes for the generic addresses and grant access to the relevant staff rather than sharing a password. Distribution lists work well for addresses that just need to forward to several people.
Step 5: Turn on security before anyone logs in
Do this now, not later. Later never comes.
- Multi-factor authentication for everyone, including admins. This is the single most effective control available to you. Modern tenants have security defaults enabled that enforce this; if you have disabled them, use conditional access policies instead.
- Block legacy authentication. Old protocols bypass MFA entirely and are the main vector for account compromise.
- Create a separate admin account. Your day-to-day account should not have global admin rights. Compromising a normal user is bad; compromising an admin is catastrophic.
- Set up an emergency access account with a long stored password, excluded from conditional access, so a misconfigured policy cannot lock you out of your own tenant.
- Enable audit logging. It costs nothing and you will want it if something ever goes wrong.
- Restrict mailbox auto-forwarding to external addresses. Attackers use forwarding rules to quietly read a compromised mailbox for months.
Step 6: Sort out where files live
This decision shapes daily working life more than anything else in the setup.
- OneDrive is for an individual's own work. It leaves with them.
- SharePoint is for the business's files. It stays.
- Teams sits on top of SharePoint — a Team's Files tab is a SharePoint library.
Business documents belong in SharePoint or Teams, not in someone's personal OneDrive. When that person leaves, personal OneDrive content becomes an administrative problem. Set up a small number of clear libraries with sensible permissions rather than a sprawl of Teams created ad hoc.
Turn on Known Folder Move so Desktop, Documents and Pictures sync automatically to OneDrive. This alone prevents most "my laptop died and the file was on the desktop" disasters.
Step 7: Migrate existing mail and files
If you are moving from another provider, migrate mailbox content before cutting over the MX record. For small numbers of mailboxes, a straightforward import works. For larger or messier migrations, a purpose-built migration tool preserves folder structure, calendars and contacts far better than manual methods.
Plan the cutover for a Friday evening or a quiet period, and expect a short window where mail delivery is in transit.
Step 8: Understand what Microsoft does and does not back up
A widespread and dangerous misconception: Microsoft 365 is not a backup. Microsoft protects the platform's availability. It does not protect you from a user deleting a folder, a departing employee wiping their mailbox, or ransomware encrypting a synced library.
Retention and recycle bins give you a limited window — typically weeks, not years. If your data matters, use a third-party backup service for Microsoft 365 that covers Exchange, OneDrive, SharePoint and Teams.
Step 9: Deploy to devices and document it
Install the Office apps, sign users in, configure Outlook, and confirm OneDrive is syncing. If you are on Business Premium, use Intune to enrol devices so you can enforce encryption, screen locks and remote wipe.
Then write down: the tenant name, who holds admin access, where the domain is registered, which third-party services send mail as you, and where backups go. Store it somewhere that is not only in one person's head.
The common mistakes, summarised
- Tenant created under a consultant's or employee's personal identity
- MFA "to be turned on later"
- No DKIM or DMARC, then confusion about mail going to spam
- Everyone a global admin
- Business files in personal OneDrive
- Assuming Microsoft backs up your data
- No record of who has access to what
Real IT Consulting sets up Microsoft 365 for businesses across the Gold Coast, Brisbane, Logan, Pimpama and Sydney — including migrations, security configuration, and third-party backup. Remote setup is $99 per hour with no hidden fees. Call 0489 940 359.