Microsoft 365 is not hard to set up. It is easy to set up badly, and the damage shows up months later — email split across two systems, files on somebody's personal drive, the domain owned by a person who left in March. None of it announces itself on day one.
The order below prevents all of it. Most of the steps take minutes; the expensive part is doing them in the wrong sequence.
Sort the domain out first
Your business email should be yourname@yourbusiness.com, and that means proving to Microsoft that you control the domain by adding a DNS record at whoever you bought it from. Do this before creating a single user account. If you set people up on the temporary onmicrosoft.com address first, you will migrate everyone twice.
While you are in there, write down where the domain is registered, which account owns it, and when it renews. An expired domain takes down email and website together, and it happens to somebody every week. If yours has already lapsed, start with the domain rescue steps — nothing else here matters until it is back.
Pick the plan by what you actually need
Microsoft's published prices, as of September 2026, are $7 per user per month for Business Basic, $14 for Business Standard and $22 for Business Premium — each on an annual commitment, with month-to-month billing running about 20% higher. Prices rose in July 2026, so ignore any article still quoting last year's numbers, and check Microsoft's current page before you commit.
The real fork is whether people need the installed Word, Excel and Outlook programs on their computers, or whether the browser versions will do. Basic is browser-only; Standard adds the desktop apps. Premium adds device management and stronger security controls — worth it once you handle client data or staff work from personal machines, overkill for a three-person shop on day one. You can move a user up a tier later without rebuilding anything, so start honest rather than aspirational.
One cost trap worth knowing: a shared mailbox — info@, sales@, support@ — does not need its own paid licence. Neither does a former employee's mailbox you are only keeping for the record. Businesses routinely pay for both for years.
If you are still weighing Microsoft against Google, the honest answer is that the comparable tiers cost almost exactly the same as of September 2026, so the decision is really about which apps your people already know. The full comparison is here.
Add the DNS records that make mail deliver
Verifying the domain gets you an account. Four more DNS records decide whether your mail actually arrives:
- MX tells the internet to deliver your mail to Microsoft. Change it last, after the migration below.
- SPF lists which servers may send as your domain, so a scammer in someone else's basement cannot.
- DKIM puts a cryptographic signature on every message, proving it left your tenant unaltered.
- DMARC tells receiving servers what to do with mail that fails those checks — and the big mailbox providers increasingly expect to see it.
Microsoft's setup wizard writes the MX and SPF records for you at most registrars. DKIM you switch on yourself in the security portal, and DMARC you add by hand — skipping those two is the classic reason a brand-new tenant's invoices land in spam. If that is already happening, the deliverability guide walks through each record in owner's English.
Move the old email before you flip the switch
If you are coming from Gmail, an old hosting mailbox or another provider, do the migration before you change the MX record that points mail at Microsoft — otherwise new mail lands in one place while the history sits in another. Migrate the mailboxes, verify a few of them, then flip the record. Expect a short window where mail arrives in both places, which is normal and harmless.
Do not forget calendars, contacts, and any address that quietly forwards somewhere else. Forwarding rules are the classic thing nobody documents and everybody misses. The moving parts, and the ways cutovers actually go wrong, are covered in the migration guide — and a tech on Koadi can run the whole switchover in a scheduled evening window so nobody works through it on a Tuesday.
Shared mailbox or distribution group — pick the right one for info@
Everyone wants an info@ address. Few businesses pick the right mechanism behind it.
- A shared mailbox is one mailbox several people open. It keeps its own history, everyone can see what has already been answered, and replies go out from the info@ name. Use it for anything customers write to.
- A distribution group simply forwards a copy of each message to every member. Nothing is stored centrally, nobody can tell whether a colleague has replied, and answers come from personal addresses. Use it for one-way announcements — all-staff@, not support@.
Put customer mail on a distribution group and you will eventually have two people answering the same message and a third answering nobody.
Turn on MFA before you invite the team
Business email compromise almost always starts with one stolen password, and the target is usually the person who approves payments. Requiring a phone approval at sign-in stops nearly all of it. New tenants come with Microsoft's security defaults switched on, which push every user to register for multi-factor authentication — leave them on, and if you outgrow them later, replace them with proper Conditional Access rules rather than switching them off.
Set it up on the admin account first, and create a second admin account kept in reserve so a lost phone does not lock you out of your own tenant. Do all of this while the team is small and the habit is cheap to establish — retrofitting it onto twenty annoyed people is a much harder conversation. If anyone needs convincing, the two-factor guide makes the case in twenty minutes.
Decide where files live before anyone saves anything
OneDrive is a person's own work. SharePoint — usually reached through Teams — is the company's work. The distinction matters enormously the day somebody leaves, because their OneDrive leaves with their account and shared files should not.
Structure beats enthusiasm here. Create a handful of sites that mirror how the business actually runs — Operations, Finance, Clients — and set permissions at the site level, not file by file. Resist the urge to spin up a new Team for every passing project; each one is another place for the contract to hide. Then state the rule on day one: if a colleague might ever need it, it goes in SharePoint. Do that and you will never have to run the "where is the contract" search.
Write down who owns the keys
The admin account, the reserve admin password, the domain registrar login, the billing card, the recovery phone number. Keep the list somewhere the business owns — not one person's inbox, and not the memory of whoever did the setup. This single page is what separates a smooth staff change from two weeks of support tickets.
When you'd rather run the business than the tenant
Koadi sets up Microsoft 365 for small businesses end to end — domain, DNS, migration, mailboxes, MFA — and supports it afterwards. Post the job free in plain words, set a fixed price you are happy with or take bids from vetted, identity-verified technicians, and watch the work happen over a screen-share. Payment sits in escrow and is released only when you confirm mail is flowing and everyone can sign in. Remote setup works from anywhere in the US, evenings and weekends included, and if you want someone at the desks on switchover day, local on-site technicians are available too.