Setting Up Microsoft 365 for Your Organization

A practical guide to configuring Microsoft 365 for small and mid-size organizations — from licensing through security hardening, with shared email best practices.

Start Learning

A practical guide to configuring Microsoft 365 for small and mid-size organizations — from licensing through security hardening, with shared email best practices.

Course Overview

Microsoft 365 is powerful, badly documented for small organizations, and easy to misconfigure in ways you won't notice until something goes wrong. Most small teams end up with the wrong licenses, weak security defaults, and email authentication that makes their domain look like a spam source.

This course is a practical setup guide for clinic owners, office managers, and anyone responsible for running Microsoft 365 in an organization with 2 to 50 users. It starts before you buy — because choosing the wrong license tier is the most common and most expensive mistake — and ends with a working, hardened environment you can actually manage day to day.

Every module is written around decisions, not just steps. You'll understand why each configuration matters, not just where to click. That matters because Microsoft's default settings are not secure defaults, and understanding the reasoning is what lets you maintain the configuration as the platform changes.

The course covers SPF, DKIM, and DMARC in plain language — the three email authentication standards that determine whether your email lands in the inbox or the spam folder. It covers Conditional Access, MFA enforcement, data loss prevention, and how to structure groups and shared resources so they don't become a security liability as your team grows.

What you'll walk away with:

  • The right license tier for your organization size and use case — before you commit
  • A correctly configured domain with working SPF, DKIM, and DMARC records
  • Anti-spam and anti-phishing policies that actually protect your users
  • MFA enforced across your organization with Conditional Access configured correctly
  • A compliance and data retention baseline appropriate for a healthcare or regulated business
  • A day-to-day admin workflow that keeps your environment clean as users come and go

1 Before You Buy — Microsoft 365 Licensing

Comparing Business Basic, Standard, Premium, and Enterprise E1/E3/E5 plans. Add-on strategy and what you actually need.

1.1 Microsoft 365 Plans — Cutting Through the Confusion

A no-BS comparison of Microsoft 365 Business and Enterprise plans, with clear guidance on which plan fits your organization.

1.2 What's Actually Included (And What's an Add-On)

Breakdown of what each Microsoft 365 plan includes versus common paid add-ons, with warnings about add-on creep and a comparison to Google's simpler pricing.

1.3 Annual vs Monthly Billing — And the Cancellation Trap

How Microsoft 365 annual commitment billing works, what early cancellation actually costs, the 300-user limit, and a practical strategy for new deployments.

1.4 Buy Directly from Microsoft

Why you should buy Microsoft 365 directly from Microsoft, how the CSP partner model works, and when a partner actually makes sense.

2 Domain Setup & Verification in Microsoft 365

Walking through the Microsoft 365 admin center domain wizard, DNS verification methods, and initial configuration.

2.1 Adding Your Domain to Microsoft 365

Step-by-step walkthrough of adding and verifying your domain in the Microsoft 365 admin center, with TXT vs MX verification options explained.

2.2 DNS Records Microsoft 365 Needs

Complete reference of all DNS records required for Microsoft 365 — MX, Autodiscover, SPF, DKIM, DMARC — with actual values and common mistakes to avoid.

2.3 Domain Considerations for Microsoft 365

Primary vs additional domains, the .onmicrosoft.com fallback domain, vanity domain best practices, and subdomain strategies in Microsoft 365.

2.4 Initial Configuration Checklist

Post-domain-verification checklist: security defaults vs Conditional Access, external sharing, Teams settings, admin accounts, and the configuration decisions that matter on day one.

3 Email Naming Conventions & Structure

Establishing professional, scalable email naming patterns from day one.

3.1 Use firstname.lastname@ Format

Why firstname.lastname@ is the professional, predictable, and scalable standard.

3.2 Never Create Generic Mailboxes

Why info@, sales@, and support@ as real mailboxes destroy accountability, audit trails, and security.

3.3 Use Distribution Groups as Shared Aliases

How Google Groups provide collaborative inbox, full audit trail, and easy member management without shared passwords.

3.4 Establishing a Naming Convention Document

Creating a naming convention document on day one to prevent inconsistency as your organization grows.

4 Email Authentication — SPF, DKIM & DMARC

Protect your domain from spoofing and ensure email deliverability with proper authentication records.

4.1 Why Email Authentication Matters

Spoofing prevention, deliverability impact, bulk sender requirements, and the foundation for BIMI brand indicators.

4.2 SPF — Sender Policy Framework

How to inventory your senders, build a DNS TXT record, navigate the 10-include limit, and choose between ~all and -all.

4.3 DKIM — DomainKeys Identified Mail

Generating 2048-bit keys in Admin Console, publishing DNS records, and testing signature verification.

4.4 DMARC — Domain-based Message Authentication

Progressive enforcement from none to quarantine to reject, plus report monitoring strategies.

4.5 Verification & Ongoing Monitoring

Using Google Admin Toolbox, MXToolbox, dmarcian, and email header checks for ongoing compliance.

5 Anti-Spam & Phishing — Exchange Online Protection

Exchange Online Protection, Microsoft Defender for Office 365, Safe Links, Safe Attachments, and quarantine management.

5.1 Exchange Online Protection — What You Get for Free
5.2 Microsoft Defender for Office 365 — When Free Isn't Enough
5.3 Configuring Anti-Spam Policies
5.4 User Training and Phishing Simulation

6 Compliance & Data Protection — Microsoft Purview

Retention policies, eDiscovery, sensitivity labels, information barriers, and data loss prevention.

6.1 Microsoft Purview — What It Is and Why It Matters
6.2 Retention Policies and Labels
6.3 Data Loss Prevention (DLP)
6.4 eDiscovery and Content Search

7 Security Hardening — Entra ID & Conditional Access

Multi-factor authentication, Conditional Access policies, Entra ID (formerly Azure AD), and security defaults.

7.1 Security Defaults — Your Starting Point
7.2 Multi-Factor Authentication Done Right
7.3 Conditional Access Policies
7.4 Admin Account Best Practices
7.5 Monitoring and Alerts — Entra ID Sign-In Logs

8 Groups & Shared Resources — M365 Groups & Teams

Microsoft 365 Groups, Shared Mailboxes, Teams, distribution lists, and resource management.

8.1 The Microsoft 365 Group Ecosystem — Making Sense of the Chaos
8.2 Shared Mailboxes — The Right Way to Handle info@ and support@
8.3 Microsoft Teams — Groups, Channels, and When to Use What
8.4 Shared Calendars, Room Booking, and Equipment
8.5 Group Naming Policies and Lifecycle Management

9 Day-to-Day Admin — Microsoft 365 Admin Center

Navigating the admin portals (M365, Entra, Exchange, Teams), audit logs, and service health monitoring.

9.1 Navigating the Admin Portals — Yes, There Are Multiple
9.2 User Lifecycle — Onboarding, Offboarding, and License Management
9.3 Service Health, Message Center, and Staying Informed
9.4 Audit Logs and Activity Reports

10 Migration & Onboarding — Moving to Microsoft 365

Migration paths from Google Workspace and on-premises Exchange, cutover vs staged migration, and user onboarding.

10.1 Migration Paths — Where Are You Coming From?
10.2 The Migration Checklist
10.3 User Onboarding and Training
Course Overview
  • 10 modules
  • 42 lessons

Solo Owner Friendly No Tech Background Needed Works Day One Compliance Risk
Purchase Access

365-day access


Student Login

Already purchased? Log in to access your course.


All Courses