~/projects/m365-tenant-rollout
Microsoft 365 Tenant Rollout
- Microsoft 365
- Exchange
- Intune
- Security
The brief
An on-prem Exchange 2013 server well past end-of-life, no MFA, and staff laptops that had never seen a management policy. The firm's insurer was starting to ask pointed questions.
What I did
- Planned a staged hybrid migration and moved 120 mailboxes in batches, nights and weekends, with no mail loss and no NDR storms.
- Enforced MFA and conditional access for all users; blocked legacy authentication.
- Enrolled all laptops into Intune with compliance policies, BitLocker and automated app deployment.
- Configured SPF, DKIM and DMARC properly — their mail finally stopped landing in customers' spam folders.
- Ran short training sessions and wrote one-page guides staff actually kept.
Outcome
- Exchange server decommissioned, licensing consolidated
- 100% MFA adoption within three weeks
- Lost/stolen laptops are now a remote-wipe, not an incident report
- Passed the insurer's cyber questionnaire on the next renewal