Modern Workplace

Microsoft 365 Support for Sussex SMEs: Who Owns Your Tenant

Who really owns your Microsoft 365 tenant? Sussex SMEs need governance, not just break/fix. Five checks to verify your setup. Book a Security Triage Call.

Modern Workplace

Microsoft 365 Support for Sussex SMEs: Who Owns Your Tenant

Who really owns your Microsoft 365 tenant? Sussex SMEs need governance, not just break/fix. Five checks to verify your setup. Book a Security Triage Call.

Published:

Most Sussex businesses that use Microsoft 365 treat it like a software licence. They pay the monthly fee, their staff log in, and when something breaks someone — usually the most tech-literate person on the payroll — digs around and fixes it.

That arrangement works until it does not. A former employee still has admin access. SharePoint has drifted into a permission mess. MFA is enabled for some users and not others. No one can point to the person who owns those decisions.

At that point the question stops being about software and starts being about governance: who actually owns your Microsoft 365 tenant, and how do you know they are maintaining it to a standard that keeps your business secure?

This article explains what proper Microsoft 365 support means for a 10–25 seat Sussex business, what should already be covered by your licence, how that maps to the IT Security Baseline, and why native retention features are not a backup strategy. If you want to understand your current position, the next step is a Security Triage Call.

What a Managed M365 Service Actually Covers

Microsoft 365 is not a product you simply buy and set. It is a platform with hundreds of configurable controls — identity policies, device management, data loss prevention rules, retention settings, and more. A managed service that truly covers your M365 estate handles all of that, not just the break/fix layer.

A proper managed M365 service should cover:

  • Identity and access governance — MFA enforcement across all users, admin account separation, conditional access policies, guest access reviews, and joiner/leaver automation.

  • Device management — every device enrolled in Microsoft Intune, encryption enforced, patch compliance monitored, and standardised builds applied via Autopilot.

  • Security configuration — Defender for Office 365 policies, anti-phishing rules, spam filtering, safe attachments, and data loss prevention (DLP) policies configured to match your business needs.

  • SharePoint and OneDrive governance — site permissions audited, sharing policies set organisation-wide, external sharing restricted to approved domains.

  • Backup management — third-party backup deployed and tested independently of the Microsoft 365 tenant, with documented retention and restore testing cadence.

  • Ongoing monitoring and compliance — real-time alerting on security events, monthly access reviews, and evidence that controls are maintained, not just configured once.

That last point matters. A lot of providers configure something and move on. A managed service that owns your tenant maintains it — regularly reviewing access, patching configuration drift, and ensuring controls stay aligned to your security baseline.

If you are curious about the most common weaknesses Sussex SMEs have in their Microsoft 365 environments, our article on common Microsoft 365 security weaknesses in SMEs covers what we regularly find.

What Is Already in Your Licence — and What Costs Extra

A lot of confusion around M365 support comes from not knowing what Microsoft provides natively versus what requires additional licensing or external management.

Microsoft 365 Business Standard and Business Premium include:

  • Core productivity applications (Word, Excel, Outlook, Teams, SharePoint, OneDrive)

  • Exchange Online email with spam filtering (basic)

  • Microsoft Defender for Office 365 — threat protection for email, links, and attachments (included with Business Premium and most Enterprise plans)

  • Azure Active Directory (now Entra ID) — identity management with basic MFA

  • Microsoft Intune — device management for enrolled devices

  • Basic data loss prevention policies

What typically requires additional licensing or external support:

  • Advanced DLP policies beyond the built-in templates

  • Conditional Access policies configured to organisation-specific rules (technically possible with Entra ID P1, included in Business Premium and E3/E5)

  • Third-party Microsoft 365 backup (Microsoft does not provide a backup product)

  • Managed security monitoring and configuration reviews

  • Joiner/leaver automation beyond basic deactivation workflows

  • Security Baseline alignment and evidence gathering

The key takeaway: your licence covers the tools. It does not cover someone continuously managing and governing those tools on your behalf. That is where a managed service comes in.

How M365 Support Maps to the IT Security Baseline

The IT Security Baseline is a structured set of controls mapped to the Cyber Essentials framework, covering identity, devices, patching, malware protection, backup, access control, and cloud services. Microsoft 365 is the platform through which most of these controls are enforced for a typical SME.

Here is how proper M365 governance maps to the Baseline:

Baseline Domain

How It Appears in M365

Identity & Access

MFA enforced, admin accounts separated, Conditional Access policies, guest access reviewed, joiner/leaver automation

Devices

All devices enrolled in Intune, BitLocker/FileVault enforced, patch compliance monitored, standardised builds

Patching

Microsoft automatically patches M365 apps and services; operating system patching is managed via Intune compliance policies

Malware Protection

Defender for Office 365 (email/attachments), SentinelOne or equivalent on endpoints, phishing simulation and reporting

Backup

Third-party backup of Exchange, SharePoint, OneDrive, and Teams data — outside the tenant, with restore testing

Access Control

Role-based admin assignments, privileged access review cadence, session timeout policies

Cloud Services

SharePoint sharing restricted, external access controlled, API permissions audited

If you do not have someone reviewing these controls regularly, they drift. Microsoft does not default to a security-hardened configuration — it defaults to a feature-enabled one. That is why ownership matters.

For Sussex businesses looking for a provider that manages this across the full estate, our managed IT services in Sussex page covers the operating model.

Why Native Retention Is Not a Backup Strategy

Microsoft 365 includes data retention features — you can recover deleted items from the recycle bin, restore from version history, and in some cases retrieve content from the recoverable items store. Microsoft also offers Microsoft 365 Backup as a native add-on.

But none of this is equivalent to an independent backup strategy, and here is why.

A backup that lives inside the same Microsoft 365 tenant, controlled by the same credentials and subject to the same ransomware propagation path, offers limited protection against a tenant-wide compromise. If an attacker gains admin access and encrypts or deletes data across your organisation, the same credentials can reach into Microsoft's retention systems.

The real question is not whether Microsoft can restore from their own copy — it is whether your backup copy is reachable by the same ransomware event that encrypted your primary data. A genuinely independent backup, held outside the tenant with separate credentials and storage, answers that question.

Our article on ransomware-resistant backups for SMEs covers this in detail. The short version: if your backup and your primary data share the same attack surface, you do not have a backup — you have a secondary copy on the same compromised system.

What Should Already Be in Your Licence? A Quick Checklist

If you are reviewing your Microsoft 365 estate, here is a practical checklist of what should already be covered by your licence and what you should expect your provider to manage:

  • MFA enforced across all user accounts (no exceptions)

  • At least two global administrators identified, with day-to-day admin separated from privileged access

  • Conditional Access policies applied (block legacy authentication, require MFA for cloud apps)

  • All devices enrolled in Intune with encryption and compliance policies

  • Defender for Office 365 configured (anti-phishing, safe attachments, URL filtering)

  • SharePoint external sharing restricted to approved domains or disabled

  • Third-party backup deployed and tested (outside the tenant)

  • Joiner/leaver automation in place (not manual deactivation)

If you can tick all of these confidently, you are ahead of most SMEs we encounter. If not, that is exactly what a Security Triage Call is for — a high-level view of where you stand without any obligation.

How This Compares to the Kent Approach

We published a similar article for Kent businesses last month covering the same governance question from a local perspective. The mechanics are identical — whether you are in Sussex or Kent, the issue of tenant ownership and governance does not change. You can read that article here: Microsoft 365 for Kent SMEs.

Both pages own their local county query, and both point to the same underlying principle: your Microsoft 365 tenant needs an owner who maintains it, not just someone who fixes things when they break.

FAQ

Is Microsoft 365 secure by default?

No. Microsoft 365 ships with features enabled, not security controls hardened. MFA is available but not enforced by default. Admin accounts exist without separation. SharePoint sharing defaults to a permissive stance. Conditional Access policies require explicit configuration. Microsoft provides the tools; someone needs to configure and maintain them to a standard that matches your business risk profile.

Can a local provider take over my tenant without downtime?

Yes, but the process depends on what is already in place. If your current provider has admin access and documentation, the handover is straightforward — we take over admin rights, audit the configuration, and begin maintaining the baseline. If there is no documentation or previous provider access, we start with an audit of what exists and work from there. In both cases, there is no downtime for your users — the handover happens on the admin side.

What should already be in my Microsoft 365 licence?

Core productivity apps, Exchange Online email, basic spam filtering, Entra ID identity management with MFA, Intune device management, and Defender for Office 365 (on Business Premium and above) are included in standard licences. What is not included: third-party backup, advanced DLP beyond templates, custom Conditional Access policies configured to your rules, security monitoring, and ongoing governance reviews. Those require either additional licensing or external management. The Modern Workplace hub covers how these layers integrate into a coherent governance approach for your Microsoft 365 estate.

Do you support Google Workspace?

No. Infinite Cloud IT works exclusively with Microsoft 365 as the core identity and collaboration platform for SMEs. We do not support Google Workspace. If your business uses Microsoft 365, we can help you understand and govern it properly.

Next Steps

If you are a Sussex business owner who wants to know who actually owns your Microsoft 365 tenant — and whether that ownership is being maintained to a standard that keeps your business secure — the starting point is a conversation.

A Book a Security Triage Call gives you a high-level view of your current setup, the controls that matter, and whether there is a fit for a structured, baseline-led approach. It takes 20–30 minutes and carries no obligation.

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.