Home / Services / Microsoft 365 & Office suite
Microsoft 365 & Office suite

You already own most of what you need. Let’s configure it.

Word, Excel, Outlook, Teams, SharePoint and OneDrive are in almost every agency. The gap is rarely the software. It is how it is set up, secured and used.

What we do

The whole Office suite, configured for a regulated agency

Licensing review

Right-size what you pay for. Many agencies pay for the wrong plan: missing the security features they need, or paying for features nobody uses.

Setup and migration

A new tenant, or a move from Google Workspace, an old mail host or file shares into Exchange Online, SharePoint and OneDrive, without losing mail or breaking anyone’s week.

Identity and access

Multi-factor sign-in, conditional access, groups built around who needs what, and guest access you can explain. Field staff on personal email are the usual challenge.

Email security

Anti-phishing, SPF, DKIM and DMARC, shared mailboxes for orders and invoices, and mail that stays inside your own domain when it should.

Teams and SharePoint

A site structure for each audience, document libraries your office can find things in, Teams calling and phone menus, and a resource site for care staff.

Compliance controls

Retention, labels, data loss prevention and audit logging in Microsoft Purview, so the tenant itself helps protect PHI.

Power Platform

Power Automate flows, Lists, Planner and forms that replace the spreadsheet-and-email routines: intake, approvals, reminders, voicemail-to-task.

Word and Excel that work for you

Templates, fillable forms and Excel workbooks that reconcile and report, built so a successor can understand them. No fragile macros.

Tenant health check

Fifteen things we look at in an afternoon

A health check is the fastest way to learn where a Microsoft 365 tenant stands. You get a ranked list, written for a non-technical owner, with the fixes we recommend first.

  • Multi-factor sign-in coverage, including admins
  • Legacy sign-in methods blocked
  • Number of administrators, and whether they are all needed
  • A protected emergency (break-glass) account
  • Guest accounts and external sharing settings
  • Automatic mail forwarding rules, a common sign of compromise
  • Shared mailboxes that allow direct sign-in
  • SPF, DKIM and DMARC for each of your domains
  • Mailbox and admin audit logging switched on
  • Retention and data loss prevention policies
  • Device compliance and encryption
  • Anti-phishing and safe-attachment settings
  • Secure Score, read in context
  • Backup of Microsoft 365 data (Microsoft retention is not a backup)
  • Which services are covered by your Microsoft agreement for HIPAA

On Microsoft and HIPAA

Microsoft offers a Business Associate Agreement for covered Microsoft 365 services through its standard licensing terms. A BAA is necessary, not sufficient: what protects PHI is how the services are configured and used. We check that each service you use is covered by the agreement, and then configure it properly.

Copilot and AI features need the same scrutiny as any other service: what data they can see, and where they run. We configure them the way we configure our own: closed-book, with web access off. See AI & automation.

Day-to-day Office help

  • Templates for letters, SOPs and policies in your house format
  • Excel workbooks that reconcile two lists and report the differences
  • Outlook rules and shared calendars that match how the office really works
  • Training for the people who use all of it, one-to-one if they prefer. See training

Tell us the one workflow that costs you the most time.

A working session is free of obligation: we look at one process, tell you plainly whether AI belongs in it, and what keeping it inside HIPAA would take.

Book a working session