# Athencia — Full Site Content > Complete content from athencia.com for LLM reference. See https://athencia.com/llms.txt for a summary. ## Homepage Athencia is a managed IT services and cybersecurity company based in Lynnwood, Washington, serving small businesses with 5 to 75 employees across the Greater Seattle area. Founded by Jeremy Phillips, Athencia specializes in IT management for professional services firms including law offices, CPA firms, and financial advisors. One dashboard shows your IT health at a glance. Green means good. Yellow means check on it. Red means let's talk. No jargon. No guesswork. Two service tiers: Athencia One (visibility + on-demand support) and Athencia One Complete (fully managed IT). Professional Services available for project-based work. - https://athencia.com ## About Jeremy Phillips founded Athencia after 30+ years building and running IT systems. Started in the 90s with Exchange and network infrastructure. Ran operations at enterprise scale — environments with over 16 million mailboxes. Led teams, managed multi-million dollar P&Ls, ran technology strategy for growing organizations. Athencia is independent and locally owned. Not backed by private equity. Named after Athena, goddess of wisdom and strategy. - https://athencia.com/about ## Athencia One Visibility and on-demand support for small businesses. One dashboard shows IT health at a glance using green/yellow/red indicators. Escalate directly from the portal when something needs attention. We fix it and bill for the time. Includes: Microsoft 365 Business Premium, Huntress 24/7 SOC (EDR, ITDR, SAT, SIEM), Dropsuite M365 backup, managed patching via Level RMM, CIS Controls baseline alignment with ControlMap, and the Athencia One Portal. 1Password available as optional add-on (+$5/user/mo). Pricing: $45-55/user/month depending on team size. Support billed hourly when needed. Best for: Firms with 5-75 employees that have some internal IT resources or a technical partner and prefer paying for support as needed. - https://athencia.com/athencia-one ## Athencia One Complete Fully managed IT and cybersecurity. Everything in Athencia One plus: unlimited user support, 24/7 security monitoring, device management, user onboarding/offboarding, vendor coordination, quarterly business reviews, Virtual IT Manager, and 1Password Business included. Pricing: $159-199/user/month depending on team size. Flat monthly fee, unlimited support included. Founder direct line for business-critical emergencies. Best for: Firms with 5-75 employees that don't have internal IT resources and want someone to handle everything. - https://athencia.com/athencia-one-complete ## Professional Services Project-based IT consulting: Microsoft 365 migrations, security assessments, network redesigns, device fleet overhauls, vendor evaluations, and AI workshops. 30+ years of hands-on Microsoft experience. Pricing models: Hourly ($150-200/hr), fixed-fee (defined deliverables, quoted upfront), or retainer (reserved hours at preferred rate). Process: Discovery > Scope > Execute > Handoff. Documentation and knowledge transfer included. - https://athencia.com/professional-services ## Pricing Athencia One: $45-55/user/month (visibility + on-demand support, support billed hourly). Athencia One Complete: $159-199/user/month (fully managed, unlimited support included). Professional Services: Hourly, fixed-fee, or retainer. No long-term contracts required. Onboarding fee based on environment complexity. - https://athencia.com/pricing ## Technology Stack Athencia standardizes on a curated stack rather than supporting every possible tool: - Identity & Productivity: Microsoft 365 Business Premium — https://athencia.com/stack/microsoft-365-business-premium - Endpoint Security: Huntress Managed EDR + ITDR + SAT + SIEM — https://athencia.com/stack/huntress - Backup: Dropsuite for Microsoft 365 and Entra ID — https://athencia.com/stack/dropsuite - Device Management: Level RMM — https://athencia.com/stack/level-rmm - Password Management: 1Password Business — https://athencia.com/stack/1password - Compliance Mapping: ControlMap — https://athencia.com/stack/controlmap - Business Phone Systems: Quo VoIP or Microsoft Teams Phone — https://athencia.com/stack/phone-systems - https://athencia.com/stack ## Service Area Greater Seattle, Washington: Seattle, Bellevue, Redmond, Kirkland, Bothell, Everett, Lynnwood, Edmonds, Shoreline, Mountlake Terrace. Remote clients supported nationwide via cloud-native delivery. - https://athencia.com/areas-we-serve --- ## Blog ### What the FTC Safeguards Rule Actually Requires from Your Accounting Firm > The FTC Safeguards Rule applies to accounting firms of every size. Here is what it actually requires, where most small firms fall short, and what Microsoft 365 does and does not cover. Published: 2026-03-21 | Author: Jeremy Phillips | Category: Compliance URL: https://athencia.com/blog/ftc-safeguards-rule-accounting-firms If you run an accounting or tax practice, there is a good chance you have heard of the FTC Safeguards Rule. There is also a good chance you are not entirely sure what it requires, whether you are covered, or whether your current IT setup actually meets the bar. This post covers what the rule says, what it means in practice for a small professional services organization, and where most accounting practices fall short without realizing it. ## What is the FTC Safeguards Rule? The Safeguards Rule is a regulation from the Federal Trade Commission that requires financial institutions to protect customer information with a Written Information Security Program (WISP). It has existed in some form since 2003, but the FTC significantly updated the requirements in 2023 with more specific, prescriptive obligations. "Financial institution" under the Safeguards Rule is broader than most people expect. It includes banks and credit unions, but it also covers tax preparers, accountants, mortgage brokers, investment advisors, and any business that provides financial products or services to consumers. If your organization handles tax returns, financial statements, or client financial records, you are almost certainly covered. The rule was not written for large companies. It was explicitly designed to apply to businesses of all sizes, and the FTC has been clear that "small" is not an exemption. ## What the rule requires The 2023 updates moved the rule from vague principles to specific requirements. Here is what you actually need to have in place. **A Written Information Security Program (WISP)** This is the foundation of the rule. You need a documented security program that covers how your organization handles, protects, and manages customer information. "Documented" means written down, not just something you do informally. The program needs to be tailored to your organization's size and complexity. A 10-person CPA practice does not need the same WISP as a large financial institution, but the program still needs to exist and actually reflect how your organization operates. **A designated Qualified Individual** The rule requires you to designate someone to oversee your information security program. This does not have to be a full-time security professional. For most small organizations, it is the owner or a senior partner. But someone has to own this formally, and their name needs to be in writing. **A risk assessment** You need to conduct and document a risk assessment that identifies the risks to customer information at your organization. This includes things like who has access to client data, how it is transmitted and stored, what happens when an employee leaves, and what third-party vendors touch your data. The key word is "documented." Knowing in your head that your organization has some risks does not satisfy the rule. You need a written assessment. **Specific security controls** The 2023 update added a list of required controls. These include: - Encryption of customer information, both in transit and at rest - Multi-factor authentication for anyone accessing systems with customer data - Access controls that limit who can see what - Monitoring and testing of your safeguards - A patch management process for software updates - Secure disposal of customer information when it is no longer needed For most accounting firms, the honest question is not whether they have heard of these controls. It is whether they have actually implemented them across their environment. **A written incident response plan** If something goes wrong, you need a plan for how to respond. The rule requires a written incident response plan that addresses how you detect, contain, and recover from a security event. It also needs to cover how you notify affected customers when required. **Annual reporting to the board or senior management** Someone with oversight responsibility at the organization needs to receive a written report at least annually covering the status of your information security program. For a small organization, this might be a one-page summary reviewed by the managing partners. But it needs to happen and be documented. **Oversight of service providers** If you use vendors that access customer information (cloud software, payroll providers, document management systems, your IT provider), you need to have contracts in place that require them to implement appropriate security measures. You also need to periodically review their security practices. This is one area where a lot of small organizations have gaps. Many accounting practices use a handful of cloud tools and have never reviewed the security provisions in those vendor agreements. ## Where most small accounting firms fall short After working with professional services organizations for years, the gaps I see most often are not exotic. They are straightforward. **No written WISP.** Most small organizations have some informal security practices but nothing documented. The Safeguards Rule requires written documentation. "We do it this way" does not satisfy a regulator. **MFA is inconsistent.** Multi-factor authentication is specifically required under the rule. A lot of organizations have it turned on for some systems but not others. Your practice management software might have MFA enabled while your email, file storage, or client portal does not. **No formal risk assessment.** Knowing your organization handles sensitive data is not the same as having a documented risk assessment. The rule requires you to actually conduct and record one. **Employee offboarding gaps.** When someone leaves the organization, their access to client data needs to be terminated promptly. This sounds obvious, but it fails in practice regularly. Shared passwords, old email accounts, lingering access to cloud tools. These are compliance violations and security risks. **Vendor agreements without security provisions.** Most small organizations sign up for software tools without paying close attention to the data handling provisions in the agreement. The Safeguards Rule requires you to ensure your vendors are protecting customer data appropriately. ## What Microsoft 365 covers and what it does not Most accounting firms run on Microsoft 365. It is a good platform and it includes a lot of security capability. But M365 Business Premium does not automatically make you Safeguards Rule compliant. What M365 Business Premium gives you: MFA, encryption in transit, Conditional Access policies, Intune for device management, Defender for endpoint protection. These are real security controls that map to Safeguards Rule requirements when they are properly configured. What it does not give you automatically: a written WISP, a risk assessment, a documented incident response plan, vendor oversight records, or the governance layer the rule requires. Those have to be built on top of the technical controls. The platform is necessary but not sufficient. Compliance requires both the controls and the documentation. ## What enforcement actually looks like The FTC has authority to investigate and fine businesses that violate the Safeguards Rule, and they have used it. Fines can reach $50,120 per violation per day for knowing violations. Beyond federal enforcement, some states have their own data security laws with additional requirements and penalties. The more practical concern for most small accounting firms is not an FTC audit. It is a data breach. If your organization experiences a breach and it turns out you did not have the required security program in place, you are looking at regulatory exposure, potential civil liability, and the kind of reputational damage that is very hard to recover from in a business built on client trust. The Safeguards Rule is not just a compliance checkbox. It is a floor for reasonable security practice. Most of what it requires you would want to do anyway. ## Getting compliant without hiring a full-time security team A 15-person accounting firm does not need a CISO. But you do need someone who understands what the rule requires and can build the documentation and controls to meet it. That is what [Athencia Comply](/athencia-comply) is designed for. We help professional services organizations build the written WISP, implement the technical controls through [Athencia One Complete](/athencia-one-complete), document the risk assessment, and prepare you for the oversight and renewal obligations that come after the initial setup. The goal is not to bury you in paperwork. It is to build a security program that is real, documented, and maintainable by a small organization without a dedicated IT staff. If you are not sure where your organization stands against the Safeguards Rule requirements, the right first step is a gap assessment. Start there before worrying about anything else. --- Ready to find out where you actually stand? [See how Athencia Comply works](/athencia-comply) or [get in touch directly](/contact) for a straightforward conversation about what your organization needs. #### FAQs **Q: Does the FTC Safeguards Rule apply to small accounting firms?** A: Yes. The rule applies to any business that qualifies as a "financial institution" under the Gramm-Leach-Bliley Act, which includes tax preparers, accountants, and financial planners of any size. There is no small business exemption, though the rule does acknowledge that requirements should be "appropriate to the size and complexity" of your organization. **Q: What is the difference between the original Safeguards Rule and the 2023 updates?** A: The original rule required financial institutions to have a security program but was largely principles-based. The 2023 updates added specific required controls: encryption, MFA, access controls, patch management, incident response plans, and annual reporting obligations. The updated rule is significantly more prescriptive and harder to satisfy with vague general practices. **Q: Does Microsoft 365 Business Premium make my firm Safeguards Rule compliant?** A: Not by itself. M365 Business Premium includes many of the technical controls the rule requires (MFA, encryption, device management), but it does not provide the written documentation, risk assessment, incident response plan, or governance layer the rule also requires. You need both the technical controls and the program documentation. **Q: What happens if my firm has a data breach and is not compliant with the Safeguards Rule?** A: A breach while non-compliant creates significant exposure. The FTC can investigate and fine violators. Individual states may have additional data breach notification requirements and penalties. Beyond regulatory action, civil liability from affected clients is possible. Perhaps most importantly for a small professional services firm, a breach that reveals inadequate security practices can cause lasting reputational damage. **Q: How long does it take to become Safeguards Rule compliant?** A: For most small accounting firms starting from a reasonable security baseline (M365, basic controls in place), getting to documented compliance takes roughly 60 to 90 days. The documentation and governance layer takes time regardless of how strong the underlying technical controls are. If your technical environment needs significant work first, the timeline extends accordingly. ### What Does a Managed IT Company Actually Do? > A plain-English breakdown of what managed IT companies do, what's included in their services, and how to tell if you actually need one. Published: 2026-02-05 | Author: Jeremy Phillips | Category: IT Operations & Management URL: https://athencia.com/blog/what-does-a-managed-it-company-actually-do If you've ever searched for IT help for your business, you've probably come across the term "managed IT" or "MSP" (managed service provider). But what does that actually mean? And how is it different from just hiring someone to fix your computer when it breaks? This article breaks down what managed IT companies do, what you can expect from their services, and how to figure out if this model makes sense for your business. ## The basic idea behind managed IT A managed IT company takes responsibility for some or all of your technology infrastructure. Instead of waiting for something to break and then scrambling to fix it, they monitor your systems, apply updates, and address small issues before they become big problems. Think of it like the difference between waiting for your car to break down on the highway versus getting regular oil changes and inspections. The second approach costs more upfront, but it keeps you from being stranded. Most managed IT companies charge a flat monthly fee per user or per device. In exchange, you get ongoing monitoring, maintenance, and support. The specifics vary by provider, but the core concept is the same: predictable costs in exchange for proactive management. ## What's typically included Managed IT services usually cover several areas: **Monitoring and maintenance** Your provider watches your systems around the clock (or during business hours, depending on your plan). They track things like server health, disk space, backup status, and security alerts. When something looks wrong, they investigate before it affects your team. **Patching and updates** Software updates are tedious but important. They fix bugs and close security holes. A managed IT company handles this for your operating systems, applications, and security tools so you don't have to remember to do it yourself. **Help desk support** When your employees have IT problems, they contact your managed IT provider instead of trying to figure it out themselves or bothering a coworker who "knows computers." Good providers offer multiple contact methods: phone, email, chat, or a support portal. **Security tools and monitoring** Modern managed IT includes security. This might mean endpoint protection (antivirus and more), email filtering, security awareness training for employees, and monitoring for suspicious activity. Some providers include a security operations center (SOC) that watches for threats 24/7. **Backup and disaster recovery** Your data needs to be backed up, and those backups need to be tested. Managed IT providers typically handle this, ensuring your data is recoverable if something goes wrong. ## What's usually extra Some services cost additional fees on top of the base managed IT agreement: - Hardware purchases (computers, networking equipment) - Major projects like office moves or system migrations - Compliance management for regulated industries - On-site visits (many providers are remote-first) - After-hours emergency support (some include this, others charge extra) Ask any provider you're considering what's included and what costs extra. The answers vary significantly. ## How managed IT differs from other options **In-house IT staff** Hiring your own IT person gives you someone dedicated to your business. But one person can't be an expert in everything: security, networking, Microsoft 365, backups, and user support. They also take vacations and sick days. Managed IT gives you a team with diverse expertise and coverage beyond a single person's availability. **Break-fix support** Break-fix means you call someone when something breaks, they fix it, and you pay for that specific work. It's simple and feels cheaper in the short term. But it's reactive: you're always dealing with problems after they've disrupted your business. Managed IT flips this model to prevention. **Hiring a consultant** IT consultants are great for specific projects or strategic advice, but they're not designed for day-to-day operations. You might hire a consultant to plan a cloud migration and a managed IT provider to run your systems afterward. ## Signs you might need managed IT Not every business needs managed IT. But you might benefit from it if: - Your team wastes time dealing with IT issues instead of their actual jobs - You've been hit by a security incident or close call - You're growing and your informal IT setup isn't scaling - You handle sensitive data (client information, financial records, health data) - You can't afford downtime and need systems that just work - You want predictable IT costs instead of surprise bills ## Questions to ask a managed IT provider Before signing up, get clear answers to these questions: 1. What's included in the monthly fee versus billed separately? 2. What are your response time targets for different issue types? 3. What security tools and practices do you use? 4. How do you handle onboarding for new clients? 5. Can I see references from businesses like mine? 6. What happens if we need to part ways? The answers will tell you a lot about whether the provider is a good fit. ## The bottom line Managed IT companies exist to handle your technology so you can focus on your business. They monitor, maintain, and support your systems for a predictable monthly cost. The value comes from prevention: catching issues early, keeping systems updated, and having experts available when problems do occur. Whether this model makes sense for you depends on your business size, complexity, and tolerance for IT headaches. But if you're tired of technology problems interrupting your work, managed IT is worth investigating. #### FAQs **Q: What's the difference between break-fix IT and managed IT?** A: Break-fix IT means you call someone when something breaks and pay for repairs. Managed IT is proactive: you pay a monthly fee and the provider monitors, maintains, and fixes issues before they cause downtime. Managed IT typically costs more upfront but saves money by preventing problems rather than reacting to them. **Q: How much does managed IT cost for a small business?** A: Managed IT services typically cost between $50 and $200 per user per month, depending on the level of service. Basic plans include monitoring and patching. Comprehensive plans add unlimited support, security tools, compliance management, and vendor coordination. Most providers offer tiered pricing based on what you need. **Q: Can I keep my current software and systems with a managed IT provider?** A: Usually, yes. A good managed IT provider will assess your current setup and integrate with the tools you already use. They may recommend changes if something is outdated or creates security risks, but the goal is to improve your environment, not force you to start over. **Q: What should I look for when choosing a managed IT company?** A: Look for transparent pricing, clear response time commitments, security certifications or frameworks they follow (like CIS Controls), and references from businesses similar to yours. Ask about their onboarding process and how they handle emergencies. Avoid providers who won't explain what's included or push long-term contracts before you've worked together. ### Why 'Just Do a Weekly Offsite Backup' Is the Worst Advice Your Business Will Ever Get > A weekly offsite backup sounds reasonable until you lose a week of client data. Here is what a real backup and disaster recovery strategy looks like for SMBs in 2026. Published: 2026-02-19 | Author: Jeremy Phillips | Category: Cybersecurity URL: https://athencia.com/blog/why-weekly-offsite-backup-is-bad-advice I recently sat through a cybersecurity webinar aimed at small business owners. The presenter was a federal forensic analyst with impressive credentials. The first half covered the current cybercrime landscape, how threat actors operate, how ransomware-as-a-service has made attacks more accessible than ever. Solid stuff. Then the conversation shifted to what businesses should actually do about it. And when it came to backups, the recommendation was this: do a weekly offsite backup so that if you get hit with ransomware, you only lose a week of data. I nearly fell out of my chair. If you run a business with 10, 20, or 50 employees and someone tells you that a weekly offsite backup is a valid strategy against ransomware, they are giving you advice that could cost you your company. Let me explain why, and more importantly, what you should be doing instead. ## The problem with "Just Do a Weekly Offsite Backup" On the surface, the logic makes sense. You have a copy of your data, it lives somewhere other than your office, and if something bad happens, you can restore from it. But "only losing a week of data" is being treated like an acceptable outcome here, and it is not. Not even close. **A week of data loss can be fatal.** Think about what your business produces in a week. Emails sent, contracts drafted, invoices generated, client work delivered, accounting entries logged. For a 20-person law firm or accounting practice, a week of lost data is not an inconvenience. It is a crisis. Reconstructing a week of billable work, correspondence, and financial transactions is not just expensive. In many cases, it is impossible. **Weekly is not frequent enough.** If your last backup was six days ago and you get hit today, you are looking at nearly a full business week of lost work. For many small businesses, that amount of data loss means missed deadlines, broken client commitments, compliance violations, and real financial damage. The recovery point objective (how much data you can afford to lose) for most businesses should be measured in hours, not days. **Offsite backup alone does not get you back up and running.** Even if your weekly offsite backup is perfectly intact, restoring from it takes time. You need hardware to restore to. You need to rebuild the environment. You need to verify the data. For many businesses, this process takes days or even weeks. Every hour of downtime costs money, and a weekly offsite backup has no answer for the question, "How do we keep working while we recover?" **Ransomware does not wait for your backup schedule.** Many ransomware variants sit dormant for days or weeks before activating, quietly spreading across your environment. By the time the encryption kicks in, your last several weekly backups may already contain the compromised payload. Restoring from any of them just reinfects you. The bottom line: a weekly offsite backup is better than nothing, but it is nowhere near good enough. It is a 2008 strategy being recommended in 2026, and it gives business owners a dangerous false sense of security. ## What most small businesses get wrong about Microsoft 365 backups Here is something that surprises a lot of business owners: Microsoft does not back up your data for you. When you are paying for Microsoft 365, you are paying for the platform, the applications, and the infrastructure. You are not paying for data protection. Microsoft is very clear about this. Their Shared Responsibility Model puts the responsibility for protecting your data squarely on you. Their service agreement even recommends using third-party backup solutions. Most people never read that. They assume that because their email is "in the cloud," it is safe. It is not. Here is what can go wrong: - **Accidental deletion.** Someone deletes a critical email, a SharePoint folder, or a OneDrive file. Once it clears the recycle bin (which Microsoft only retains for up to 93 days in most cases), it is gone. Permanently. - **Ransomware and malware.** A compromised account can encrypt or delete files across Exchange, OneDrive, SharePoint, and Teams. Microsoft's native tools have limited recovery options for this. - **Departing employees.** When someone leaves and their license gets removed, their mailbox and OneDrive data have limited retention windows. If you do not act fast, you lose it. - **Compliance and legal holds.** If you are ever involved in litigation or need to produce historical records for a compliance audit, Microsoft's native retention is not built to be your archive. You need a real solution for that. The reality is that for most small businesses, their entire operation lives inside Microsoft 365. Email, files, calendars, contacts, shared documents, Teams conversations. If any of that disappears and you do not have an independent backup, you are in serious trouble. ## What a real Microsoft 365 backup strategy looks like A proper M365 backup solution runs automatically, multiple times per day, and stores your data independently from Microsoft's infrastructure. No USB drives. No human intervention. No hoping someone remembered to run the backup before they left for the weekend. At Athencia, we use Dropsuite for Microsoft 365 backup across our managed clients. Here is what that actually means for your business: **Automated, incremental backups.** Your Exchange mailboxes, OneDrive files, SharePoint sites, Teams data, calendars, and contacts are backed up automatically, multiple times daily. No one has to remember to do anything. It just happens. **Immutable storage.** Your backup data is stored in a separate cloud environment with immutable protection. That means even if an attacker compromises your Microsoft 365 tenant, they cannot reach your backups. This is the critical difference between a real backup solution and simply having a copy of your data sitting somewhere offsite. **Granular, point-in-time recovery.** Need to restore a single email from three weeks ago? A SharePoint folder from last Tuesday? A departed employee's entire mailbox? You can do all of that without restoring everything. You pick exactly what you need and recover it to the exact point in time you choose. **Unlimited storage.** No worrying about storage capacity limits or paying overage fees. Your backup grows with your data. **Built-in compliance and eDiscovery.** For professional services organizations that deal with client data, legal holds, or regulatory requirements, having a searchable archive of all email and file history is not a nice-to-have. It is a necessity. The difference between this approach and the weekly offsite recommendation is not incremental. It is the difference between being able to recover from an incident in minutes versus discovering, days later, that your last good backup was from last weekend and half your client files are gone. ## But what about on-premises servers? That is where BCDR comes in Cloud backup solves the Microsoft 365 problem, but many small businesses still have on-premises infrastructure. Maybe it is a file server, a line-of-business application, a database, or a domain controller. For these workloads, you need something more than backup. You need business continuity and disaster recovery, or BCDR. The difference between backup and BCDR is critical. A backup saves your data. BCDR saves your business. With a true BCDR solution, if your server goes down, whether from hardware failure, ransomware, fire, flood, or anything else, you can spin up a virtual copy of that server within minutes, either on the local appliance or in the cloud. Your team keeps working while you deal with the underlying problem. We deploy Slide BCDR appliances for our clients' on-premises workloads. Slide was founded by the same team that built Datto (one of the most widely deployed BCDR platforms in the MSP space) and designed from scratch with no legacy code. Here is what makes this approach different from a weekly offsite backup: **Frequent, image-level backups.** Instead of copying files once a week, a BCDR appliance takes full image snapshots of your servers multiple times per day. If you need to recover, you are restoring the entire system, not just files, to a point in time that is hours old, not days. **Local and cloud virtualization.** If a server fails, you can boot a virtual machine directly from the backup appliance. Your team can keep working while the primary server is repaired or replaced. If the entire office goes down, you can spin up in the cloud and operate remotely. **All-flash, high-performance hardware.** The Slide Z1 appliance uses NVMe solid-state storage, which means backups and restores happen fast. There are no spinning disks to fail, no mechanical parts to wear out. For a small office, the entry-level appliance is about the size of an Apple Mac Studio and can store up to 16TB of protected data. **End-to-end encryption.** Data is encrypted on the appliance, in transit, and in the cloud. This is built in, not an add-on. **Offsite replication to a private cloud.** Your backups are automatically replicated to a dedicated private cloud, not a shared public cloud environment. If the worst happens and your office is physically destroyed, your data and your ability to run your systems are still intact. This is what modern disaster recovery looks like. It is not a weekly backup job and a prayer. It is an automated, tested, always-on system that keeps your business running when everything else goes wrong. ## Putting it all together: the two-layer approach For most small businesses in 2026, the right backup and recovery strategy has two layers: **Layer 1: Cloud-to-cloud backup for Microsoft 365.** This covers your email, files, SharePoint, Teams, and everything else that lives in Microsoft's cloud. A solution like Dropsuite runs automatically, stores your data independently, and gives you granular recovery when you need it. **Layer 2: BCDR for on-premises workloads.** This covers your servers, applications, and anything that runs locally. A solution like Slide gives you frequent image-level backups, instant local or cloud virtualization, and offsite replication so you can survive anything from a hardware failure to a total office loss. Together, these two layers mean that no matter what happens, whether it is ransomware, accidental deletion, hardware failure, a disgruntled employee, a natural disaster, or just plain bad luck, your data is protected and your business can keep running. Compare that to a weekly offsite backup and hoping for the best. ## What to ask your IT provider If you are a business owner reading this and you are not sure where you stand, here are the questions you should be asking your IT provider or MSP today: - Do we have a third-party backup for our Microsoft 365 data, or are we relying on Microsoft's native retention? - How often are our backups running, and how much data would we lose in a worst-case scenario? - If our server goes down right now, how long until we are back up and running? Is the answer measured in minutes, hours, or days? - Are our backups stored somewhere completely separate from our production environment? - Has our backup and recovery process been tested recently? Can you show me a successful restore? - If our entire office is destroyed, can we still operate? If your IT provider cannot answer these questions clearly, or if the answers involve the words "weekly" and "offsite" and not much else, it is time to have a different conversation. ## Stop hoping. Start protecting. The cybersecurity webinar I sat through was well-intentioned. The presenter was trying to help small businesses understand the threats they face. But good intentions paired with outdated advice can do more harm than good, because it gives business owners a false sense of security. If you walk away from a webinar thinking your weekly offsite backup has you covered, you are more vulnerable than you were before you attended, because now you think the problem is solved. It is not. Real data protection in 2026 means automated cloud backup for your SaaS platforms and BCDR for your on-premises infrastructure. It means your backups run without human intervention, are stored independently from your production systems, and can be recovered quickly when you need them. It means you know your data is safe instead of hoping it is. --- **Athencia** helps small businesses nationwide stop guessing about their IT and start seeing what is actually happening. With a local presence in the Greater Seattle area and the ability to support clients anywhere in the country, our managed IT plans include automated M365 backup, BCDR for on-premises workloads, and a single dashboard where you can see the health of your entire environment at a glance. *Want to find out where your backup strategy actually stands?* **Let's talk.** Visit [athencia.com](https://www.athencia.com) or reach out directly to schedule a no-pressure conversation about what is protecting your business today and what should be. ### Your VMware Bill Just Doubled. Here's What to Do About It. > Broadcom's VMware repricing has turned renewals into an exit-planning problem for SMBs. Here's what to know before moving from VMware to Hyper-V. Published: 2026-03-24 | Author: Jeremy Phillips | Category: IT Operations & Management URL: https://athencia.com/blog/your-vmware-bill-just-doubled-heres-what-to-do-about-it I've quoted this project at least twice a month for the last several months, which tells me something. The VMware-to-Hyper-V conversation has moved from "worth exploring someday" to "we need a plan before the next renewal invoice." Broadcom made that decision for a lot of SMBs. This is not a technical migration problem. It's a renewal deadline problem. Here's what actually happens on these projects, and what you should know before starting one. ## What happened to VMware Broadcom acquired VMware in late 2023 and has been repricing it ever since. Perpetual licensing is gone. The familiar Standard and Enterprise Plus SKUs are gone for new contracts. If you only need the hypervisor, you're buying a bundle and paying for shelfware. The 72-core minimum purchase attempt in early 2025 was the clearest signal yet, even after Broadcom walked it back. If you run a 2- or 3-node cluster, you're not their target customer anymore. You're long-tail revenue they're willing to squeeze or lose. I've personally seen massive increases in renewal quotes, and the number varies widely by environment and contract history. For most SMB environments, the math no longer works. ## Why Hyper-V, and why Azure Arc seals it For the SMB clients I work with, law firms, accounting practices, financial services, consultancies running Microsoft 365 and Entra ID, Hyper-V is almost always the right answer. It's already included in Windows Server (assuming properly licensed Datacenter or appropriately licensed Standard cores for your VM density). The management story is Windows Admin Center, which is browser-based and clean. Azure Site Recovery handles DR. The operational surface is familiar to any Windows admin. If something breaks at 2am, finding someone who can troubleshoot it is not a problem. There are situations where other platforms make sense. An environment with strong Linux expertise in-house and no Azure footprint, for example, might have good reasons to look at other options. If you're heavily invested in VMware-specific tooling or NSX, this becomes a different conversation. But for Microsoft shops, those situations are the exception. And the real reason I keep recommending Hyper-V over the alternatives has nothing to do with familiarity. It's Azure Arc. ## Azure Arc changes the calculus Most people frame this as a hypervisor replacement decision. I think of it as an on-premises positioning decision, and that framing changes everything. Azure Arc lets you extend Azure's management plane to your on-premises Hyper-V infrastructure. Your on-prem VMs show up in the Azure portal. You can apply Azure Policy to them, manage them through Defender for Cloud, enforce governance at the same level as your cloud resources, and use the same tooling your team already knows. It turns your Hyper-V cluster into a first-class node in your broader Azure estate rather than an isolated island managed through a separate workflow. (Some feature differences apply compared to native Azure VMs, depending on workload and agent coverage, but for the governance and visibility use cases that matter most to SMBs, it delivers.) For the professional services organizations I work with, this shows up in three ways. **Workload placement becomes an intentional decision.** With Arc in the picture, you're not locked into on-prem or cloud as a binary. You can run sensitive client data workloads on your own hardware, where you control the physical location and can speak to that clearly from a compliance standpoint, while spinning up burst compute or dev environments in Azure when it makes more sense economically. The management experience is unified either way. **Security posture stays consistent.** Defender for Cloud covers Arc-enrolled machines the same way it covers Azure VMs. Your server security posture, patch compliance, and vulnerability findings are all visible in one place across both environments. For a 30-person law firm with a hybrid footprint, that's a meaningful operational improvement over running two separate monitoring and compliance stories. **It gives you an honest migration path.** If some workloads genuinely belong in the cloud, and some of them probably do, Arc gives you the tools to evaluate that clearly and move them on your timeline. You make deliberate decisions about where each workload lives instead of defaulting to wherever it already is. **Azure Backup rounds out the story.** When you enroll your Hyper-V hosts into Arc and use Microsoft Azure Backup Server (MABS) or newer Azure Backup approaches depending on environment design, you can vault backups offsite directly to an Azure Recovery Services vault. Short-term retention stays local for fast operational recovery; long-term retention lives in Azure without needing a separate backup cloud provider. For clients already invested in Azure, it's a clean fit. None of this is available to you if you leave VMware for a platform with no Azure integration. An alternative hypervisor might be a solid piece of software. It is not connected to Azure, and for an organization where the rest of the stack is Microsoft-shaped, that gap is real. If you're evaluating this, you're in one of three buckets: 1. Stay on VMware and absorb the cost 2. Migrate to another hypervisor (Hyper-V, Proxmox, others) 3. Exit on-prem entirely and move to Azure This post is about option 2, and why for Microsoft-centric SMBs, Hyper-V combined with Azure Arc is usually the cleanest path. ## What the migration actually looks like I'll be direct: this isn't a weekend project, and anyone who says otherwise hasn't done enough of them. Do not try to move everything in one sprint. That's how outages happen. **Start with inventory.** Every VM needs to be documented before anything moves: OS, RAM, vCPU, disk size, network config, application dependencies. Migrations go wrong when people skip this step and find out midway through that one of their VMs has an application that doesn't tolerate the new virtual hardware profile. **Assess the hardware.** Most servers running ESXi will run Hyper-V without issues. Confirm CPU virtualization is enabled in BIOS and review your storage configuration. If you're running vSAN, you'll need a plan for shared storage. Windows Storage Spaces Direct is Microsoft's native option for hyperconverged storage, but it requires careful design and isn't always the right fit for smaller environments. **Convert the VMs.** Microsoft's MVMC has been deprecated, which still catches people off guard. The current workflow depends on your situation. One important caveat first: if your VMs are running on vSAN, this step gets harder. vSAN's tight coupling between storage and compute means most standard conversion tools don't work against it directly. You'll typically need to storage vMotion the VMs off vSAN onto a traditional VMFS datastore first, then convert from there. Skipping this step is one of the most common reasons VMware-to-Hyper-V migrations stall. Plan for it before you start. - **StarWind V2V Converter** for VMDK-to-VHDX conversion, free, reliable, and the tool I reach for first - **Disk2vhd** for any physical-to-virtual scenarios that still exist in the environment - Manual export/import for anything application-sensitive that needs careful handling General sequence: clean shutdown of the source VM, convert the disk, create a Generation 2 VM in Hyper-V, attach the converted disk, ensure Integration Services are current, validate network and storage, test the application. In that order, every time. **On Integration Services.** For modern guest operating systems (Windows Server 2016 and later), Integration Services are built in and kept current via Windows Update. For legacy guests, you'll need to handle it manually. Either way, don't assume it's done. Verify it. VMs without current Integration Services will have degraded performance and inconsistent backup behavior, and it's the most common thing I find left undone on migrations that someone else touched. **Plan your networking.** VMware's port group and vSwitch model maps conceptually to Hyper-V's virtual switch model, but they don't translate directly. Plan your external, internal, and private switch topology before the first VM moves. ## BCDR: get this right before cutover, not after The first question to answer isn't which backup tool, it's where your environment is going. That determines everything else. If you're moving to Hyper-V and staying on-prem, Slide is our default BCDR recommendation. It's purpose-built for MSPs, runs on all-NVMe hardware, encrypts everything by default, and was founded by the team that built Datto. It protects physical and virtual workloads via its appliance regardless of the underlying hypervisor, so the migration to Hyper-V doesn't change your protection story. If you're building a true hybrid environment with Azure Arc in the picture, the calculus shifts. You want a solution that lives in the same management plane as the rest of your infrastructure. Azure Backup via MABS vaults directly to an Azure Recovery Services vault and sits inside the same operational home base as everything else Arc-connected, and for clients already invested in Azure, it removes a vendor from the stack entirely. Zerto is the right answer when you need continuous data protection and near-zero RPO; it's more operationally complex, but for environments where a few hours of data loss is genuinely unacceptable, certain financial services clients, for example, it delivers. It can also replicate VMware VMs to Hyper-V while both environments are live, which compresses the cutover window considerably on larger migrations. Veeam handles Hyper-V natively and integrates cleanly with Azure Local and Arc environments if you're already running it. The important thing regardless of which tool you land on: reconfigure your backup jobs as part of the migration plan, not after. Backup agents registered to VMware-aware jobs will break at cutover. ## What tends to go wrong A few things I see consistently. **Legacy VMware drivers.** Windows Server 2012 VMs converted from VMware sometimes have VMware-specific drivers baked in that cause problems on Hyper-V. Remove VMware Tools before conversion, or immediately after first boot on the new host. **Generation 1 vs. Generation 2.** Generation 2 is the right choice for modern workloads: UEFI, secure boot, better performance. VMs with older Windows Server versions or certain Linux kernels may need to stay on Gen 1. Know which is which before you build the target VMs. **Windows activation.** VMs activated under a VMware-based deployment may need reactivation against the new virtual hardware profile. Volume licensing via KMS handles this automatically most of the time. Retail or OEM activations sometimes need manual attention. **Backup agent confusion.** Already mentioned this, but worth repeating because it causes more post-migration headaches than anything else on this list. ## Realistic timeline For a small environment, 10 to 20 VMs on a 2-node ESXi cluster, expect 4 to 8 weeks from scoping to production cutover. That includes hardware prep, test conversions, a validation window, and the actual go-live. The temptation is always to compress this. Resist it. Larger environments, or anything with SQL Always On clusters, Exchange remnants, or tightly coupled application dependencies, will take longer. Not because the tools are hard, but because the testing needs to be thorough and you can't rush that part. ## Is it worth it? For most of the clients I'm quoting right now, yes. The migration cost is typically recovered within the first or second year of avoided VMware subscription fees. After that, you're running a hypervisor that's already inside your Windows Server licensing with no separate renewal clock. With Azure Arc, you're positioned to make deliberate decisions about your hybrid footprint going forward rather than just surviving the next Broadcom price increase. The one situation where I tell people to reconsider: if you have fewer than five VMs and the workloads could realistically move to Azure IaaS or M365-native services, virtualization infrastructure might not be the right answer at that scale anyway. For everyone else with a real on-prem VM estate and a VMware renewal coming up: if your renewal is within six months, you should already be modeling your exit. Get the quote. Run the numbers. The exit is well-understood at this point and we've done it enough times to do it cleanly. ## Want help planning one of these? If you're looking at a VMware renewal and want a second opinion before you sign anything, or you're ready to start scoping a migration, that's exactly the kind of project we handle. Take a look at [Athencia's Professional Services](https://athencia.com/professional-services), or if you just want to have a conversation first, a [free IT Health Check](https://athencia.com/free-it-health-check) is a good place to start. *Athencia is a Pacific Northwest-rooted boutique IT services firm serving small and mid-sized businesses nationwide.* --- ## Knowledge Base ### Cloud & Backups #### How to Create a Simple Disaster Recovery Plan for Your Small Business > Step-by-step guide to creating a practical disaster recovery plan that helps your small business resume operations after an IT outage, cyberattack, or physical disaster. URL: https://athencia.com/kb/cloud-and-backups/how-to-create-a-simple-disaster-recovery-plan-for-your-small-business A disaster recovery plan documents exactly what to do when something takes your IT systems down, whether that is a ransomware attack, a server failure, a natural disaster, or even an ISP outage. Without a written plan, people panic, forget steps, and waste critical time. With one, you respond with a clear process and get back to business faster. The good news is that a useful disaster recovery plan does not need to be 50 pages of corporate boilerplate. A practical, three-to-five page document that your team has actually read and tested is far more valuable than a binder collecting dust on a shelf. Set aside two to four hours, follow the steps below, and you will have a working plan by the end. ## What you will need before you start Gather these items before sitting down to write the plan. Having them in front of you will save time and make the document far more accurate. - **An inventory of your critical systems and data.** This includes email, phone systems, file storage, line-of-business applications, accounting software, and any client-facing systems. - **Documentation of your current backup setup.** Know where backups are stored, how often they run, and who manages them. If Athencia manages your IT, your backup stack already includes Dropsuite for Microsoft 365 data and Slide for on-premises backups, and both are monitored through the [Athencia One portal](/athencia-one). - **Contact information for your IT provider, ISP, and key vendors.** Collect names, phone numbers, email addresses, and account numbers in advance. - **A block of focused time.** Two to four hours is enough for the initial draft. The plan does not need to be perfect on the first pass; you will revise it after testing. ## Why you need a written plan During a crisis, even smart, experienced people forget steps and make mistakes under pressure. A written disaster recovery plan removes guesswork and assigns clear responsibilities so everyone knows what to do. Beyond the operational benefits, cyber insurance policies increasingly require a documented incident response or disaster recovery plan. If you file a claim without one, the insurer may deny coverage or reduce the payout. Having a written, tested plan strengthens your position. ## Step 1: Identify your critical systems Start by listing every system your business depends on to operate. Walk through a typical workday and note each tool, service, and data source your team touches. Common examples include: - Email and calendar (Microsoft 365, for most Athencia clients) - Phone and voicemail system - File storage (OneDrive for Business, SharePoint Online, or an on-premises file server) - Line-of-business applications (CRM, ERP, project management) - Accounting and payroll software - Client-facing systems (website, client portal, e-commerce platform) Once you have the list, rank each system by criticality. Ask yourself: if we could only restore one system first, which would it be? Then the second, and so on. This ranking drives the order of recovery when a real disaster hits. For each system, document three things: where it is hosted (cloud, on-premises, or SaaS), who manages it (your team, your MSP, or a third-party vendor), and how it is currently backed up. If a system has no backup, flag it immediately. That gap needs to be addressed before the plan is complete. ## Step 2: Define your recovery objectives Two numbers drive your entire disaster recovery strategy: your Recovery Time Objective (RTO) and your Recovery Point Objective (RPO). **RTO (Recovery Time Objective)** is how long each system can be down before the business impact becomes unacceptable. For example, you might decide that email can be down for four hours, but your accounting system can tolerate up to 24 hours. These numbers are business decisions, not technical ones. Think about revenue loss, employee productivity, and client impact. **RPO (Recovery Point Objective)** is how much data you can afford to lose. If your backups run once per day, you could lose up to 24 hours of work in a worst-case scenario. If that is unacceptable for certain systems, you need more frequent backups for those systems. These objectives reveal gaps. If your RTO for email is one hour but your current backup would take eight hours to restore, you have a gap that needs a solution. If you use Dropsuite for Microsoft 365 backup, point-in-time recovery of individual mailboxes, files, and SharePoint sites is typically fast enough to meet a four-hour RTO for most small businesses. For on-premises data backed up with Slide, recovery time depends on the volume of data and whether you are restoring to original hardware or replacement equipment. ## Step 3: Document recovery procedures for each scenario Write out step-by-step instructions for each type of disaster. Be specific enough that someone under stress can follow the steps without guessing. Here are the four most common scenarios for small businesses. ### Scenario 1: Ransomware or cyberattack 1. Isolate affected systems immediately. Disconnect infected computers from the network by unplugging the Ethernet cable and turning off Wi-Fi. The goal is to stop the infection from spreading. 2. Contact your MSP or IT provider right away. If Athencia manages your IT, call the emergency support line listed in your contact sheet. Do not attempt to fix ransomware yourself. 3. Do not pay the ransom. Paying does not guarantee you will get your data back, and it funds further attacks. 4. Assess the scope of the attack. Work with your IT provider to determine which systems and data are affected. 5. Restore from clean backups once the infection is fully contained. For Microsoft 365 data, Dropsuite stores backups independently from your Microsoft tenant, so a compromised tenant does not compromise your backup data. For on-premises data, Slide provides the local backup copy for faster restoration. 6. Report the incident to the FBI's Internet Crime Complaint Center (IC3), your cyber insurance carrier, and any regulatory bodies required by your industry. 7. Communicate with employees and clients as appropriate. Be transparent about what happened and what you are doing about it. ### Scenario 2: Hardware failure (server, computer, network equipment) 1. Identify the failed component. Is it a workstation, a server, a switch, or a firewall? 2. Activate spare equipment if available. A spare laptop, a backup router, or a standby switch can keep operations running while the failed device is replaced. 3. Contact your MSP or hardware vendor for replacement. Provide the model, serial number, and warranty information. 4. Restore data from backup to the replacement device. For workstations, Microsoft Intune (included with Microsoft 365 Business Premium) can push company policies, applications, and settings to a new device quickly, reducing setup time from hours to minutes. 5. Document the failure for insurance and warranty purposes. ### Scenario 3: Internet or ISP outage 1. Switch to a backup internet connection if available. This could be a secondary ISP, a cellular failover device, or a dedicated LTE/5G backup line. 2. If no backup connection is available, set up a mobile hotspot from a phone for critical tasks like email and essential cloud applications. 3. If the outage will be extended, send employees home to work remotely using their home internet connections. Because Microsoft 365 data lives in the cloud, employees can access email, files, and Teams from any internet connection. 4. Contact the ISP for an estimated restoration time and document the outage duration for your records. ### Scenario 4: Physical disaster (fire, flood, extended power outage) 1. Ensure employee safety first. People come before data, always. 2. Assess physical damage to equipment once it is safe to do so. 3. Activate remote work capabilities. If your team uses Microsoft 365 Business Premium, email, OneDrive, SharePoint, and Teams are all accessible from any device with an internet connection. Employees can work from home while the office is unusable. 4. Contact your insurance carrier to begin the claims process. 5. Begin the equipment replacement process with your IT provider. 6. Restore on-premises data from offsite or cloud backups. This is where the offsite copy in a 3-2-1 backup strategy proves its value. If your local Slide appliance was destroyed in the disaster, the cloud copy of your Microsoft 365 data in Dropsuite remains completely unaffected. ## Step 4: Document key contacts Create a contact sheet and include it in the plan. Print a copy and keep it somewhere accessible even if your computers and network are down. Include: - **IT provider/MSP:** Name, phone, email, emergency support line - **ISP:** Account number, support phone number - **Key software vendors:** Support contacts for each critical application - **Cyber insurance carrier:** Policy number, claims phone number, agent contact - **Company leadership:** Names and cell phone numbers for decision-makers - **Employee notification list:** Personal email addresses and cell phone numbers for all employees (you cannot use company email to notify people if company email is down) ## Step 5: Assign roles Even in a five-person company, define who does what during a disaster. When everyone assumes someone else is handling it, nothing gets handled. - **Incident commander:** The person who makes decisions during the disaster. This is usually the business owner or operations manager. They decide priorities, approve spending, and communicate with leadership. - **IT lead:** Your MSP or internal IT contact who handles the technical recovery work. They coordinate with vendors, execute restore procedures, and report progress to the incident commander. - **Communications lead:** The person who communicates with employees, clients, and vendors during the incident. They send status updates, manage expectations, and handle any public-facing communication. In a small business, one person may fill multiple roles. That is fine. The important thing is that the roles are defined in writing and everyone knows their responsibilities before a disaster happens. ## Step 6: Test the plan A plan you have never tested is just a document. You do not know if it works until you walk through it. **Run a tabletop exercise once per year.** Gather your team around a table and walk through a scenario verbally. For example: "It is Monday morning and we discover our email has been encrypted by ransomware. Walk me through what we do." Go step by step. You will find gaps, outdated contacts, and unclear procedures every time. **Test a backup restore once per quarter.** Pick a random file, email, or folder and actually restore it from backup. Verify the restored data is complete and usable. If your backups are managed through Athencia, you can verify backup health anytime through the Athencia One portal, but a hands-on restore test is still essential. **Update the plan after every test** with the lessons you learned. Also update it whenever systems, vendors, or personnel change. A disaster recovery plan is a living document, not a one-time project. ## Need help? Building a disaster recovery plan is easier with an experienced IT partner. If you want help creating or testing your plan, [reach out to Athencia](/contact) and we will walk through it with you. #### How to Migrate Your Office File Server to the Cloud > Practical guide for small businesses moving files from a local server to SharePoint and OneDrive, covering planning, migration, and user training. URL: https://athencia.com/kb/cloud-and-backups/how-to-migrate-your-office-file-server-to-the-cloud Migrating from a local file server to cloud storage eliminates the maintenance, backup burden, and single point of failure that comes with keeping an on-premises server running. Your team gets access to files from anywhere, automatic version history on every document, and real-time collaboration features that a traditional file server simply cannot provide. The migration itself is straightforward when planned well, but rushing it without cleanup and user training creates confusion and resistance. This guide walks you through the entire process, from auditing what you have today to shutting down the old server for good. ## What you will need - **Microsoft 365 Business Premium licenses for all users.** This is the license tier Athencia deploys, and it includes OneDrive for Business (1 TB per user), SharePoint Online, and Microsoft Intune for device management. If you are on a different license tier, confirm that OneDrive and SharePoint are included before starting. - **Admin access to the current file server and to Microsoft 365.** You will need to read file server permissions and create SharePoint sites in the Microsoft 365 admin center. - **An inventory of what is on the file server and who uses what.** This does not need to be a formal audit. A walk-through with department leads to identify active folders and stale data is enough. - **Time for data cleanup before the migration.** This step is the most important part of the entire project. ## Why move to the cloud A local file server is a piece of hardware that needs power, cooling, maintenance, and replacement every five to seven years. It is a single point of failure. If the hard drives crash and your backups are not current, you lose data. If the office floods, the server goes with it. Moving your files to SharePoint Online and OneDrive for Business eliminates those risks. Your data lives in Microsoft's data centers with built-in redundancy, and your team can access files from the office, from home, or from a mobile device without needing a VPN. Every file gets automatic version history, so the days of "Final_v3_REAL.docx" are over. And because SharePoint integrates directly with Microsoft Teams, your team can collaborate on documents in real time. ## Step 1: Audit and clean up your file server This is the most important step in the entire migration. Migrating junk to the cloud just creates cloud junk that is harder to find and costs time to manage. Start by identifying what is actually being used versus what has not been touched in years. Check last-modified dates on folders and files. Most file servers contain 30 to 50 percent data that does not need to be migrated at all. Work through the file server folder by folder with the people who use it. Delete duplicates, outdated drafts, and files that are no longer relevant. For old project files and historical data that you need to keep but nobody accesses regularly, create a separate archive location. You can set up a dedicated "Archive" library in SharePoint for this purpose, or simply keep a final backup of the file server after migration. This cleanup typically takes longer than the actual migration, but every hour you spend here saves confusion and frustration later. ## Step 2: Plan your cloud structure Do not replicate the file server's folder structure exactly. This migration is your chance to fix years of organic, messy folder growth. The general rule is straightforward. Shared files that multiple people need to access go in SharePoint document libraries. Personal files that belong to one person go in that person's OneDrive. Map your file server shares to SharePoint sites. Each department or major business function should get its own SharePoint site. For example: - The "S:\Clients" share becomes a SharePoint site called "Client Projects" under Operations - The "S:\Finance" share becomes a SharePoint site called "Finance" - The "S:\Marketing" share becomes a SharePoint site called "Marketing" - Individual "My Documents" folders become each user's OneDrive Keep the folder hierarchy shallow. Two to three levels deep is ideal. Deeply nested folders become difficult to navigate and impossible to sync reliably. Where you previously used deep folder structures to categorize files, consider using metadata columns in SharePoint instead. Document this mapping in a simple spreadsheet: old location on the left, new location on the right. You will use this document for the migration itself and as a reference guide for your team. ## Step 3: Set up SharePoint sites and libraries Log in to the Microsoft 365 admin center at admin.microsoft.com and navigate to **Active sites** under **Sites** in the SharePoint admin center. Create each SharePoint site based on the mapping you built in Step 2. For each site, configure permissions to match the access controls from the file server. Click on the site, then go to **Site permissions** to add the appropriate users or Microsoft 365 groups. Use Microsoft 365 groups rather than adding individual users whenever possible. This makes ongoing permission management much simpler. Create the folder structure within each document library. Keep it shallow and logical. Then test with a small batch of files before you start the full migration. Upload a handful of files, verify permissions work correctly, and confirm the structure makes sense in practice. ## Step 4: Migrate the data The migration method depends on how much data you are moving. **For smaller migrations (under 100 GB),** use the OneDrive sync client. Sync the target SharePoint libraries to File Explorer, then drag and drop files from the file server into the synced folders. This is the simplest approach and works well for small offices. **For medium migrations (100 GB to 1 TB),** use the SharePoint Migration Tool, which is free from Microsoft. Download it from Microsoft's website, point it at your file server, map the source folders to destination SharePoint libraries, and let it run. It handles large file counts more reliably than drag-and-drop and preserves file metadata. **For large or complex migrations,** use a third-party tool like ShareGate or AvePoint, or engage your IT provider to manage the migration. These tools handle permission mapping, scheduling, and reporting more gracefully at scale. Regardless of the method, run the migration outside business hours if possible. Uploading hundreds of gigabytes will saturate your internet connection and slow everything else down. Migration speed depends on your upload bandwidth and file count. Thousands of small files take significantly longer than the same total volume in fewer large files. After migration, verify the results. Compare file counts between the source and destination. Spot-check files by opening them and confirming the content is intact, not just that the file name exists. ## Step 5: Set up OneDrive sync for users Once data is in SharePoint, each user needs to sync the libraries they work with to their local File Explorer. This gives them the familiar folder experience they are used to from the file server. Have each user navigate to the relevant SharePoint library in their web browser, click the **Sync** button in the toolbar, and approve the prompt to open the OneDrive sync client. The library will appear in File Explorer under the company name. Enable **Files On-Demand** so that files do not fill up local storage. With Files On-Demand turned on, files show in File Explorer but only download to the device when someone opens them. This is especially important for laptops with smaller drives. If your devices are managed through Microsoft Intune (included with Microsoft 365 Business Premium), your IT provider can push the Files On-Demand setting to all company devices automatically rather than configuring it one computer at a time. ## Step 6: Train your team Training is where most migrations succeed or fail. If your team does not understand the new system, they will resist it, work around it, or create a mess of duplicate files. Schedule a 30-minute session with your team and cover the following: - **Where files live now.** Show them the File Explorer path and the SharePoint web interface. Walk through the mapping from old locations to new locations. - **How to share files.** Demonstrate sharing a file or folder with a colleague using the **Share** button. Show the difference between "Can Edit" and "Can View" permissions. For external sharing, show how to create a link with an expiration date. - **How to use version history.** Right-click a file in File Explorer, select **Version history**, and show how to view and restore previous versions. This feature alone eliminates a huge category of "I accidentally saved over my file" support requests. - **The cutoff date.** Set a clear date and communicate it: "After [date], the old file server is read-only. All new work goes to SharePoint and OneDrive." This prevents the migration from dragging on indefinitely. Provide a one-page quick reference guide with the old file locations mapped to the new ones. Post it in common areas and share it digitally. ## Step 7: Decommission the file server Keep the old file server running in read-only mode for 30 to 60 days after the migration. This provides a safety net in case files were missed or something was not migrated correctly. During this transition period, monitor for users who are still saving to the old server. If people are bypassing the new system, find out why and address it. It is usually a training gap or a permission issue. After the transition period, take a final backup of the file server and shut it down. Store that final backup for six to twelve months in case anything surfaces later. Then cancel any maintenance contracts on the old server hardware. If you had an on-premises backup solution like Slide protecting the file server, work with your IT provider to redirect that protection to any remaining on-premises systems or to decommission it if everything has moved to the cloud. ## Common mistakes to avoid - **Migrating without cleaning up first.** Moving ten years of accumulated junk to the cloud just makes it harder to find what you need. - **Replicating the exact folder structure.** Use this as an opportunity to simplify and reorganize. - **Skipping user training.** If your team does not know how to use the new system, they will not use it, or they will use it badly. - **No cutoff date.** Without a firm deadline, some employees will keep saving to the old server indefinitely. - **Forgetting to migrate permissions.** Users who suddenly cannot access files they need will lose trust in the new system. - **Not testing with a small batch first.** Always migrate one department or one folder set first and verify before doing the full migration. ## Need help? Migrating a file server to the cloud is a project where a little planning goes a long way. If you would like guidance or hands-on support for your migration, [contact Athencia](/contact) and we will help you plan and execute it. #### How to Set Up OneDrive for Business So Your Team Actually Uses It > Practical guide to rolling out OneDrive for Business in a small office, including folder structure, training tips, and common mistakes to avoid. URL: https://athencia.com/kb/cloud-and-backups/how-to-set-up-onedrive-for-business-so-your-team-actually-uses-it OneDrive for Business gives every Microsoft 365 user 1 TB of cloud storage that syncs files between their computer and the cloud. When set up correctly, it works quietly in the background. Your team saves files to familiar folders in File Explorer, and those files are automatically backed up and accessible from any device. When set up poorly, you end up with duplicate files, confused folder structures, and employees who refuse to use it because "it is too complicated." This guide walks you through how to set up OneDrive for Business the right way so your team actually adopts it. ## OneDrive vs. SharePoint: Which to use when Before you start, understand the difference between OneDrive and SharePoint. They work together, but they serve different purposes. **OneDrive** is for personal work files that belong to one person. Think of it as that person's "My Documents" folder in the cloud. Their drafts, notes, individual work, and personal reference files all belong here. **SharePoint** is for shared team files that multiple people need to access. Project folders, shared templates, company policies, and departmental resources all belong in SharePoint document libraries. The most common mistake is putting shared files in one person's OneDrive and sharing them out. This creates a serious problem: if that person leaves the company, access to those files breaks. Their OneDrive is deleted 30 days after their Microsoft 365 account is removed unless someone intervenes. As a rule of thumb, if more than one person needs regular access to a folder, it belongs in SharePoint, not OneDrive. ## Step 1: Verify OneDrive is provisioned for each user OneDrive for Business is included with Microsoft 365 Business Premium, which is the license tier Athencia deploys. It is also included with Business Basic and Business Standard licenses. To verify that OneDrive is active for a user, have them sign in to [onedrive.com](https://onedrive.com) with their work email address and password. If the OneDrive interface loads and they can see their files area, it is provisioned and ready. If OneDrive is not available, check the user's license assignment. Sign in to the Microsoft 365 admin center at admin.microsoft.com, navigate to **Users** then **Active users**, click on the user's name, and check their **Licenses and apps** section. Make sure a license that includes OneDrive is assigned and that the OneDrive toggle is turned on. For brand-new users, OneDrive may take up to 24 hours to provision after the license is assigned. If it has been longer than that, try navigating to the user's OneDrive URL directly from the admin center to trigger provisioning. ## Step 2: Set up the OneDrive sync client The OneDrive sync client is built into Windows 10 and Windows 11, so there is no separate installation needed. It runs in the background and keeps files synchronized between the computer and the cloud. To set it up on an employee's computer: 1. Look for the **OneDrive cloud icon** in the system tray (the area near the clock in the bottom-right corner of the screen). It may be a white cloud or a gray cloud. 2. Click the icon and select **Sign in**. If prompted, choose **Work or school account**. 3. Enter the employee's work email address and password. Complete any multi-factor authentication prompts. 4. OneDrive will ask which folders to sync. For most users, the default selection is fine to start with. 5. Once setup is complete, a new folder appears in File Explorer under the company name. This is where synced files live. For employees with laptops or devices that have limited local storage (128 GB or 256 GB drives), enable **Files On-Demand**. Click the OneDrive cloud icon in the system tray, click the **gear icon**, select **Settings**, go to the **Sync and backup** tab, and make sure **Files On-Demand** is turned on. With this setting enabled, files appear in File Explorer but only download to the device when someone opens them, saving significant disk space. If your company devices are managed through Microsoft Intune (included with Microsoft 365 Business Premium), your IT provider can push OneDrive sync settings, including Files On-Demand and silent sign-in, to all company devices at once. This eliminates the need to configure each computer individually. ## Step 3: Establish a folder structure A clear folder structure, communicated before rollout, prevents the chaos that develops when everyone creates their own system. Keep the top-level folders simple and consistent across users. A good starting point: - **Clients** or **Projects** for client-specific or project-specific work - **Templates** for frequently used document templates - **Reference** for personal reference materials - **Archive** for completed work that needs to be kept but is no longer active Avoid replicating a legacy file server's ten-level-deep folder hierarchy. Deep nesting makes files hard to find and causes sync issues. Two to three levels deep is the practical limit. Create a short document outlining the company standard for folder names and file names. Share this with your team before the rollout, not after. Clear expectations set upfront prevent months of cleanup later. No more "Final_v2_REAL_FINAL.docx" because version history handles that automatically. ## Step 4: Migrate existing files If your team is moving from a local file server, another cloud service, or files scattered across individual computers, plan the migration before dumping everything into OneDrive. **For small migrations (under 100 GB total):** Drag and drop files from the old location into the synced OneDrive or SharePoint folder in File Explorer. This is simple and works well for small teams. **For larger migrations:** Use the SharePoint Migration Tool (free from Microsoft) or a third-party migration tool for more reliable, faster transfers. These tools preserve file metadata and handle large file counts better than manual drag-and-drop. After migrating, spot-check files by opening them and verifying they are complete, not just by checking file names and counts. A file that transferred with zero bytes or became corrupted during the move will not show up in a file count check. Set a cutoff date and communicate it clearly: "After [date], the old file server is read-only. All new work goes in OneDrive and SharePoint." Without a firm deadline, the migration drags on indefinitely. ## Step 5: Train your team Rollout training does not need to be a formal class. A 20-to-30 minute walkthrough covering the essentials is enough for most teams. **Show employees how to find files in File Explorer.** Open File Explorer, navigate to the OneDrive folder under the company name, and show them that working with files here is identical to working with any other folder. They can save, open, rename, and move files exactly as they always have. **Demonstrate how to share files.** Right-click a file, select **Share**, and show how to send a sharing link to a colleague or external contact. Walk through the permission options: **Can edit** gives the recipient full editing access, while **Can view** gives read-only access. For external sharing, show how to set an expiration date on the link so it does not remain active indefinitely. **Explain version history.** Right-click a file, select **Version history**, and show how OneDrive keeps previous versions of every file. If someone accidentally overwrites a document or needs to see what a file looked like last week, they can restore a previous version with two clicks. This single feature eliminates one of the most common support requests. **Show how to recover deleted files.** If someone accidentally deletes a file, it goes to the OneDrive recycle bin, which retains deleted files for 93 days. Open OneDrive in the web browser, click **Recycle bin** in the left sidebar, select the file, and click **Restore**. The file goes back to its original location. It is also worth mentioning that OneDrive is not a substitute for a true backup solution. OneDrive syncs changes, including deletions, across all devices. A third-party backup service like Dropsuite, which Athencia includes in its managed IT stack, independently backs up OneDrive, email, and SharePoint data so that files can be recovered even outside of OneDrive's own 93-day recycle bin window. ## Common mistakes to avoid - **Syncing too many files on a device with limited storage.** If a laptop has a 256 GB drive, syncing 500 GB of files will fill it up and cause problems. Use Files On-Demand to solve this. - **Not disabling personal OneDrive on work computers.** Employees can sign into both a personal OneDrive account and a business OneDrive account on the same computer. If both are active, people accidentally save work files to their personal account. Disable the personal OneDrive sign-in on company-managed devices through Intune policies. - **Sharing files with "Anyone with the link" when "People in your organization" is more appropriate.** The "Anyone" option creates a link that works for anyone on the internet, with no authentication required. For internal documents, use the more restrictive option. - **Using one person's OneDrive as the team file server.** If multiple people need regular access to the same files, those files belong in a SharePoint library, not someone's personal OneDrive. - **No folder structure or naming conventions.** Without clear standards communicated at rollout, the file structure devolves into chaos within weeks. ## Need help? Setting up OneDrive the right way from the start saves hours of cleanup later. If you need help with the rollout or want to make sure your setup follows best practices, [get in touch with Athencia](/contact) and we will get your team set up properly. #### How to Verify Your Backups Are Actually Working: A Monthly Checklist > A practical monthly checklist for small businesses to verify that backups are completing, data is recoverable, and nothing is silently failing. URL: https://athencia.com/kb/cloud-and-backups/how-to-verify-your-backups-are-actually-working-a-monthly-checklist Backups fail silently more often than most business owners realize. A backup job that stopped running three weeks ago, a storage drive that quietly filled up, a corrupted backup file that looks fine on the surface but cannot actually be restored. None of these problems announce themselves. You only discover them when you desperately need to recover data and find out you cannot. This monthly checklist takes about 30 to 45 minutes to complete. It catches problems before they become disasters and gives you documented proof that your backups are working, which is increasingly important for cyber insurance audits and compliance reviews. ## Why monthly verification matters Setting up a backup system is only the first step. Without ongoing verification, that system can silently break in dozens of ways. Service account passwords expire. Storage fills up. Software updates change settings. A new employee joins and their data is never added to the backup. A server gets replaced and nobody updates the backup configuration. The worst time to discover your backup does not work is during a data loss event. By then, it is too late. Monthly verification turns backup from "something we set up once and forgot about" into "something we know works because we checked it this month." Cyber insurance providers are also paying closer attention to backup practices. Many now ask for evidence of regular backup testing as part of the policy application or renewal. Having a documented verification log strengthens your position and may even affect your premium. ## The monthly checklist ### Check 1: Verify backup jobs are completing Start by logging in to each backup service or appliance and reviewing the job history for the past 30 days. For **Dropsuite** (Microsoft 365 backup), sign in to the Dropsuite admin dashboard and check the backup status for each protected mailbox, OneDrive account, and SharePoint site. Look for green "Success" indicators across the board. Click into any job that shows a warning or failure to see the specific error. Common causes include a user whose license was changed, a mailbox that was put on litigation hold, or an authentication token that expired. For **Slide** (on-premises backup), check the appliance dashboard or log in to the management console. Review the past 30 days of backup jobs. Confirm every scheduled job completed with a "Success" status. If you see "Completed with warnings," investigate. A warning is not the same as success. It usually means some files were skipped, locked, or inaccessible during the backup. If your backups are monitored through the [Athencia One portal](/athencia-one), backup status is visible in real time. But this monthly check is still valuable because it forces you to look at the details, not just the top-level status indicator. For any backup job that failed, document the failure, the root cause, and the resolution. If a job has been failing for more than 48 hours without being resolved, treat it as urgent. ### Check 2: Verify data volume looks correct Pull up the total size of your most recent backup and compare it to the previous month. A sudden, significant decrease in backup size is a warning sign. It could mean that files, mailboxes, or entire data sources are no longer being backed up. For example, if last month's Microsoft 365 backup covered 25 mailboxes and this month it covers 22, three users may have fallen out of the backup scope due to a license change or account modification. A sudden significant increase can also indicate a problem, such as a backup loop, duplicate data being captured, or a new data source being added without anyone realizing it. For Microsoft 365 backups through Dropsuite, verify that the number of protected mailboxes and OneDrive accounts matches your current active user count. When employees join or leave the company, the backup scope needs to be updated. For on-premises backups through Slide, verify that the total backup size is consistent with the amount of data on the protected servers. If a new file share or application was added to a server, confirm it is included in the backup configuration. ### Check 3: Perform a test restore This is the most important check on the list. A backup that completes successfully but cannot actually be restored is worthless. Pick a random file, folder, or mailbox from the backup and restore it to a temporary location. Do not restore it to the original location; you do not want to overwrite current data with an older version. For a **Dropsuite** test restore: sign in to the Dropsuite dashboard, navigate to the user's mailbox or OneDrive backup, browse to a specific email or file, and click **Restore**. Choose to restore to a temporary folder or download the file directly. Open the restored item and verify it is complete and matches what you expected. For a **Slide** test restore: open the Slide management console, select a backup snapshot from a specific date, browse to a file or folder, and restore it to a test location on the network. Open the restored files and verify they are intact and usable. Rotate what you test each month to cover different parts of your backup over time. One month, test a file from OneDrive. The next month, test an email from Exchange. The following month, test a folder from an on-premises server. Document what you tested, the date, and whether the restore was successful. ### Check 4: Verify the offsite or cloud copy is current If you follow a 3-2-1 backup strategy (and you should), you have copies of your data in at least two separate locations. This check confirms that the offsite or cloud copy is up to date and not lagging behind. For Dropsuite, this is straightforward because the backups are cloud-based by nature. Verify the most recent backup timestamp for each data source and confirm it is within the expected window (usually within the last 24 hours). For Slide, if the appliance replicates to a cloud target or a secondary offsite location, log in and verify that replication is current. If there is a replication lag of more than 24 hours, investigate. Common causes include bandwidth limitations, network configuration changes, or a credential issue with the replication target. The offsite copy is your last line of defense. If ransomware encrypts your local backups or a physical disaster destroys your office, the offsite copy is what you will recover from. It must be current. ### Check 5: Review backup coverage This check catches the gaps that form naturally as your business changes. Ask yourself these questions: - Were any new computers, servers, or cloud services added this month? If so, are they included in the backup? - Did any employees join the company? Are their Microsoft 365 mailboxes and OneDrive accounts protected by Dropsuite? - Did any employees leave? Were their accounts properly handled, and is their data preserved if needed for compliance or reference? - Are there new applications or databases running that are not yet included in any backup? - Is anything still being backed up that no longer exists or no longer needs protection? Removing unnecessary backup targets frees up storage and simplifies management. ### Check 6: Verify retention policy Check how far back your backups go and confirm the retention period meets your business requirements. For most small businesses, a minimum retention of 30 days is necessary. Ninety days is recommended because many data loss scenarios, such as a departing employee who quietly deleted files, are not discovered immediately. Verify that old backups are being properly rotated and deleted when they pass the retention window. If old backups are not being cleaned up, storage will eventually fill up and cause new backups to fail. If your industry has specific compliance requirements (healthcare, legal, financial services), confirm that your retention settings meet those requirements. Your IT provider or compliance advisor can help determine the right retention period. ## Recording your results Keep a simple log of each monthly verification. A shared spreadsheet or document works fine. For each check, record: - The date the check was performed - What was checked (backup jobs, data volume, test restore, offsite copy, coverage, retention) - Pass or fail - Any issues found and the actions taken to resolve them - Who performed the check This log serves two purposes. First, it creates accountability and ensures the checks actually happen every month. Second, it provides documentation for cyber insurance audits and compliance reviews. When an auditor asks "How do you verify your backups?" you can hand them a log showing monthly verification going back months or years. Assign the checklist to a specific person and set a recurring calendar reminder. If it is "everyone's job," it is nobody's job. ## Red flags that need immediate attention Do not wait until next month's check if you encounter any of these issues: - **Any backup job that has failed for more than 48 hours** without being investigated and resolved. - **Backup storage over 80 percent capacity.** At this level, you are one or two backup cycles away from running out of space and having backups stop entirely. - **No successful test restore in the past 90 days.** If you have not verified that data can actually be restored in three months, you do not know if your backups are usable. - **New data sources not included in the backup.** A new server, a new application, or new employees whose data is not being backed up represent unprotected risk. - **Credentials or licenses expiring soon on the backup service.** An expired license or credential will stop backups silently. ## Need help? If you would rather have your backup verification handled by professionals, or if this checklist revealed issues you are not sure how to fix, [contact Athencia](/contact). We monitor backups continuously and can help you close any gaps. #### What Is a 3-2-1 Backup Strategy and Why Your Small Business Needs One > Plain-language explanation of the 3-2-1 backup rule and how small businesses can implement it affordably to protect against data loss. URL: https://athencia.com/kb/cloud-and-backups/what-is-a-3-2-1-backup-strategy-and-why-your-small-business-needs-one The 3-2-1 backup strategy is a simple rule that protects your business from data loss: keep three copies of your data, on two different types of storage, with one copy stored offsite. If you follow this rule, no single event, whether a hardware crash, a ransomware attack, a fire, or a theft, can destroy all your business data. This approach has been the standard in IT for decades because it works. It accounts for the reality that any single backup can fail, any single location can be compromised, and any single type of storage can have a systemic problem. The 3-2-1 rule builds in enough redundancy that you can survive any one of those failures. ## The 3-2-1 rule explained **3 copies of your data.** You keep the original production data plus two separate backups. If one backup turns out to be corrupted or incomplete, you still have another to fall back on. A single backup is a single point of failure, and single points of failure are exactly what a backup strategy is supposed to eliminate. **2 different types of storage media.** Do not keep all copies on the same kind of storage. If your production data is on a hard drive and your only backup is on another hard drive in the same location, a power surge, flood, or fire could take out both at the same time. By using two different types of storage, such as a local backup appliance and a cloud backup service, you protect against a failure mode that affects one storage type but not the other. **1 copy offsite.** At least one of your backups must be physically separate from your office. A backup on an external hard drive sitting on the desk next to the computer it backs up will not survive the same fire, flood, or theft. An offsite copy, whether in the cloud or at a different physical location, ensures that a disaster at your office does not take your backups with it. ## Why this matters for small businesses The statistics are sobering. A significant percentage of small businesses that lose their data permanently close their doors within months. The common causes of data loss, such as hardware failure, ransomware, accidental deletion, theft, fire, and water damage, are not exotic edge cases. They happen to real businesses every day. There is also a widespread misconception that cloud services like Microsoft 365 fully back up your data. They do not. Microsoft operates under a shared responsibility model: Microsoft is responsible for keeping the service running, but you are responsible for protecting your data from accidental deletion, malicious insiders, and retention gaps. Microsoft retains deleted items for a limited time (30 to 93 days depending on the service), not indefinitely. If you need to recover a file that was deleted four months ago and you do not have a separate backup, it is gone. ## Copy 1: Your live data (the original) This is the data your team works with every day. It lives on your employees' computers, your file servers, and your cloud services like Microsoft 365 Business Premium (which includes OneDrive for Business, SharePoint Online, and Exchange Online). This is not a backup. It is the primary copy that everything else is designed to protect. If this copy is compromised by ransomware, corrupted by a hardware failure, or deleted by accident or malice, you need to be able to recover from the other two copies. ## Copy 2: A local or near-line backup The second copy provides fast recovery for everyday issues like accidental file deletion, hardware failure, or a corrupted database. Because it is local (on your network or physically in your office), restoring data from it is fast. For on-premises data such as local servers, workstations, and network drives, Athencia deploys Slide as an on-premises backup appliance. Slide runs automated backups on a schedule, typically daily or more frequently for critical systems, and stores them locally for quick recovery. If an employee accidentally deletes an important folder or a server drive fails, restoration from Slide is fast because the data does not need to travel over the internet. For Microsoft 365 data, you need a third-party backup service because Microsoft's native retention policies are not a backup. A third-party backup service like Dropsuite, which Athencia includes in its managed IT stack, automatically backs up Microsoft 365 email, OneDrive, and SharePoint data independently from Microsoft's retention policies. This means you can recover data even after Microsoft's own retention windows have expired, whether that is an email from six months ago or a file that was deleted and purged from the recycle bin. ## Copy 3: An offsite or cloud backup The third copy protects against events that affect your entire office: fire, flood, theft, or ransomware that encrypts every device on your network including local backup drives. This copy must be physically separate from your office. Cloud backup services are the most practical option for most small businesses because they require no hardware at a second location and update automatically. For the cloud backup of Microsoft 365 data, Dropsuite stores backups in its own cloud infrastructure, completely separate from your Microsoft tenant. For on-premises data, Slide can replicate backups to an offsite cloud target, giving you a second copy of your local data in a different location. Together with the production data in Microsoft 365 itself, this satisfies all three requirements of the 3-2-1 strategy. This offsite copy should be immutable or air-gapped whenever possible. An immutable backup cannot be modified or deleted by ransomware, even if an attacker gains administrative access to your network. This is your last line of defense, and it needs to be bulletproof. ## Implementing 3-2-1 on a small business budget You do not need an enterprise budget to implement a proper 3-2-1 backup strategy. Here is what a practical setup looks like for a typical five-to-fifteen person office. **Start with Microsoft 365 backup.** If your business runs on Microsoft 365 (email, OneDrive, SharePoint), protecting that data should be your first priority. A service like Dropsuite typically costs a few dollars per user per month and covers email, OneDrive, and SharePoint backup with point-in-time recovery. This is the highest-impact, lowest-effort step you can take. **Add on-premises backup if you have local servers or data.** If your business still has data on local servers, workstations, or network drives, a backup appliance like Slide protects that data with automated local backups and optional offsite replication. The cost depends on the amount of data and the retention period, but it is affordable for most small businesses. **If you cannot do everything at once, prioritize.** Start with Microsoft 365 backup (Dropsuite) because that is where most of your critical business data lives. Add on-premises backup next. Then verify that the offsite/cloud replication is working for both. You can build toward a complete 3-2-1 strategy incrementally rather than trying to do it all at once. ## The part most businesses skip: Testing your backups A backup you have never restored is not a backup. It is a hope. Until you have actually recovered data from a backup and verified that it is complete and usable, you do not truly know if your backup works. **Test a restore at least once per quarter.** Pick a random file, email, or folder from your backup and restore it to a temporary location. Open it and verify it is intact. Rotate what you test each quarter so you cover different data sources over time. **Check backup reports weekly.** Log in to your backup dashboards (Dropsuite, Slide, or both) and verify that jobs are completing successfully. Look for failures, warnings, or missed schedules. If your backups are managed through Athencia, backup health is visible through the [Athencia One portal](/athencia-one), but a quick manual check still builds confidence. **Know your RTO and RPO.** Your Recovery Time Objective (RTO) is how long it would take to restore operations from backup. Your Recovery Point Objective (RPO) is how much data you can afford to lose. If you back up daily, your worst-case RPO is 24 hours of work. If that is unacceptable for certain systems, you need more frequent backups for those systems. These numbers should be documented and reviewed at least annually. ## Need help? Setting up a 3-2-1 backup strategy does not have to be complicated. If you want help designing a backup plan that fits your business and budget, [contact Athencia](/contact) and we will help you get it done right. #### Why Microsoft 365 Doesn't Back Up Your Data and What to Do About It > Explains Microsoft's shared responsibility model and why small businesses need a separate backup solution for email, OneDrive, SharePoint, and Teams data. URL: https://athencia.com/kb/cloud-and-backups/why-microsoft-365-doesnt-back-up-your-data-and-what-to-do-about-it Microsoft 365 does not provide comprehensive backup of your business data. This surprises many small business owners who assume that because their email and files are "in the cloud," they are automatically protected. They are not, at least not in the way most people think. Microsoft operates under what it calls a shared responsibility model. Microsoft is responsible for keeping the service running: the data centers, the hardware, the network infrastructure, and the geographic replication that protects against platform-level failures. But you are responsible for protecting your data from accidental deletion, malicious insiders, ransomware, retention policy gaps, and regulatory compliance requirements. Microsoft will keep the lights on. Protecting what is inside those lights is on you. Many small businesses discover this distinction the hard way, usually when they try to recover something and find out it is already gone. ## What Microsoft does and does not protect Understanding the line between Microsoft's responsibility and yours is critical. **Microsoft's responsibility** covers infrastructure uptime and hardware redundancy. If a hard drive fails in a Microsoft data center, your data is fine because it is replicated across multiple servers and geographic locations. If an entire data center goes offline, the service fails over to another location. Microsoft is very good at this. Their infrastructure uptime is excellent. **Your responsibility** covers everything that happens to the data itself. If a user accidentally deletes a critical file, that is on you. If a departing employee maliciously clears out their mailbox, that is on you. If ransomware encrypts your OneDrive files, that is on you. If you need to produce emails from two years ago for a legal matter and they have been purged because no retention policy was in place, that is on you. Here is the key distinction: Microsoft's replication is not backup. Replication protects against hardware failure on Microsoft's side. But it also replicates deletions. If a user deletes a file, that deletion replicates across all copies. Replication keeps your data available; it does not keep your data recoverable. ## The retention gaps that catch businesses off guard Microsoft does provide some built-in recovery windows, but they are shorter than most people realize and they vary by service. **Deleted mailbox items (Exchange Online).** When someone deletes an email, it goes to the Deleted Items folder. If they empty Deleted Items, the email moves to a hidden Recoverable Items folder where it stays for 14 days by default (configurable up to 30 days). After that, it is permanently gone. **Deleted OneDrive files.** Deleted files go to the OneDrive recycle bin, where they are recoverable for 93 days. After 93 days, the file is permanently deleted with no way to recover it through Microsoft. **Deleted SharePoint files.** Similar to OneDrive, deleted SharePoint files go to a site recycle bin and are recoverable for 93 days. After that, a site collection administrator can recover them from a second-stage recycle bin, but only within the same 93-day window. **Deleted user accounts.** When an employee leaves and their Microsoft 365 account is removed, their OneDrive data is deleted 30 days after the account is removed, unless another user was specifically granted access to the data beforehand. **Teams messages and channel data.** Retention depends on whether explicit retention policies have been configured. Without them, data can be lost when teams or channels are deleted. Many businesses have no Teams retention policies in place. These retention windows are short enough that problems often go unnoticed until it is too late. If a disgruntled employee deletes files and nobody notices for four months, that data is gone without a third-party backup. If someone needs an email from 18 months ago for a compliance audit, it may no longer exist in Microsoft's systems. ## Scenarios where Microsoft's built-in recovery falls short **Ransomware encrypts OneDrive files.** OneDrive does keep version history, which can help recover from ransomware by rolling files back to a pre-encryption version. However, if the attack persists long enough to age out previous versions (OneDrive keeps versions for 30 days by default, or 500 versions, whichever comes first), recovery becomes partial or impossible. A third-party backup that stores data independently from the Microsoft tenant is unaffected by ransomware that compromises your Microsoft 365 environment. **A departing employee deletes their mailbox contents and OneDrive files.** You have 30 to 93 days to notice, depending on the service. If the deletion happens gradually over their final weeks and nobody is watching, critical data can be permanently lost. With a third-party backup, you can restore that employee's mailbox and files to their exact state from any point in time covered by your backup retention. **An admin account is compromised.** An attacker with global admin access can delete data, disable retention policies, remove backup configurations, and cover their tracks. Because a third-party backup like Dropsuite stores data independently from your Microsoft 365 tenant, a tenant-level compromise does not affect your backup data. **A compliance investigation requires historical email.** If a legal matter requires email records from two years ago and no retention policy was configured to keep data that long, the email is gone. A third-party backup with long-term retention solves this problem by keeping data for as long as your retention policy specifies, independent of anything Microsoft does or does not retain. ## What a third-party backup solution provides A dedicated Microsoft 365 backup solution fills the gaps that Microsoft leaves open. **Automated daily backups** of Exchange mailboxes, OneDrive accounts, SharePoint sites, and Teams data. Once configured, backups run automatically without anyone needing to remember or trigger them. **Long-term retention** independent of Microsoft's retention policies. Keep backup data for months or years, depending on your business and compliance requirements. Your backup retention is completely separate from Microsoft's built-in retention windows, so data remains recoverable long after Microsoft would have purged it. **Point-in-time recovery.** Restore a mailbox, file, or SharePoint site to its exact state from a specific date. If you need to see what a file looked like last Tuesday, or recover an email that was deleted three months ago, you can do that with a few clicks. **Granular recovery.** Restore a single email, a single file, or a single folder without having to restore an entire mailbox or site. This is important for everyday recovery requests where someone just needs one deleted file, not a full restore. **Independent storage.** Backups are stored separately from Microsoft 365, so a compromise of your Microsoft tenant does not compromise your backups. This is critical for ransomware protection and for scenarios where an attacker gains administrative access to your Microsoft 365 environment. ## How Athencia handles Microsoft 365 backup Athencia includes Dropsuite as the Microsoft 365 backup solution in its [managed IT stack](/athencia-one). Dropsuite automatically backs up Exchange email, OneDrive, and SharePoint data for every protected user. Backups run daily, and backup health is monitored through the Athencia One portal so issues are caught and resolved before they become problems. If you need to recover data, whether it is a single email or an entire mailbox, the Athencia team can perform the restore through the Dropsuite dashboard. For a single email recovery, sign in to the Dropsuite admin console, navigate to the user's mailbox backup, search for the specific email by date, subject, or sender, and click **Restore**. For larger restores, such as an entire OneDrive or a SharePoint site, the process works the same way but covers a broader scope. This is different from relying on Microsoft's native retention. Microsoft's retention is a limited safety net with expiration dates. Dropsuite provides independent, point-in-time recovery that works regardless of what has happened inside your Microsoft 365 tenant. ## How to get started If you are not currently backing up your Microsoft 365 data, here is how to close that gap. 1. **Audit your current retention policies.** Sign in to the Microsoft 365 admin center at admin.microsoft.com. Navigate to **Compliance** (or **Purview**), then **Data lifecycle management**, then **Retention policies**. Review what policies are in place. If there are none, your data is only protected by Microsoft's default retention windows described above. 2. **Identify your most critical data.** Think about what data would cause the most damage if lost: client email correspondence, financial documents, project files, shared team resources. This helps prioritize what to protect first. 3. **Set up a third-party backup.** If Athencia manages your IT, Dropsuite is already included and configured. If you are managing IT yourself, choose a backup solution that covers Exchange, OneDrive, SharePoint, and Teams. 4. **Configure backup coverage for all users.** Make sure every active mailbox and OneDrive account is included. When new employees join, add them to the backup. When employees leave, preserve their data according to your retention requirements. 5. **Verify the first backup completes successfully.** Log in to the backup dashboard and confirm that the initial backup ran without errors. Check the data volume to make sure it looks reasonable for your organization. 6. **Test a restore within the first week.** Pick a random email or file and restore it to a temporary location. Open it and verify it is intact. This confirms that the backup is not just running but is actually producing usable, recoverable data. 7. **Schedule monthly verification.** Set a recurring calendar reminder to check backup status, test a restore, and review coverage. A backup system that nobody monitors will eventually fail silently. ## Need help? If you are unsure whether your Microsoft 365 data is properly backed up, or if you want to close the gap, [reach out to Athencia](/contact). We can audit your current setup and get backup protection in place quickly. ### Cybersecurity #### How to Create a Password Policy for Your Small Business > Practical guide to building a password policy that actually works for small businesses, including length requirements, password managers, and MFA. URL: https://athencia.com/kb/cybersecurity/how-to-create-a-password-policy-for-your-small-business A strong password policy protects your business accounts from unauthorized access. The most effective modern approach prioritizes longer passphrases and multi-factor authentication over complex character requirements that lead to sticky notes on monitors. ## Why your small business needs a written password policy Most data breaches start with compromised credentials. Without a clear, documented policy, employees tend to default to short, reused passwords across multiple services. That single habit creates a cascading risk: one breached service exposes the same password everywhere it was used. Beyond the practical security benefits, many compliance frameworks and cyber insurance policies require a documented password policy. If your business handles healthcare data (HIPAA), processes credit cards (PCI DSS), or carries cyber insurance, you likely need a written policy on file. Even if none of those apply today, having a clear policy saves you from scrambling to create one when an insurer or client asks for it. A good password policy does not need to be long. One to two pages that cover the basics is far more effective than a 20-page document nobody reads. ## Modern password guidelines (NIST recommendations) The National Institute of Standards and Technology (NIST) updated its password guidance in recent years, and the changes may surprise you. The old rules about requiring uppercase letters, numbers, and special characters are no longer recommended. Those complexity rules lead to predictable patterns like "Password1!" that technically satisfy the requirement but are trivially easy to guess. Here is what NIST recommends instead: - **Minimum 12 characters, with 16 or more as the ideal.** Length is the most important factor in password strength. - **Encourage passphrases over complex strings.** A passphrase like "correct-horse-battery-staple" is both stronger and easier to remember than "P@ssw0rd!" because length matters more than character variety. - **Do not require regular password rotation.** Forced rotation every 60 or 90 days leads to weaker passwords because people just increment a number at the end. Only require a change when a breach is suspected. - **Screen new passwords against known breached lists.** Services like Have I Been Pwned maintain databases of passwords exposed in data breaches. Your password manager or identity provider can check new passwords against these lists automatically. ## Require a password manager A password manager is non-negotiable for any business that wants its password policy to actually work. Without one, employees will reuse passwords because nobody can memorize 50 unique, 16-character passwords. A password manager generates strong, unique passwords for every account and stores them in an encrypted vault. Employees only need to memorize one master password to unlock the vault. Athencia recommends 1Password for small businesses, and includes it in the [Athencia One Complete](/athencia-one-complete) managed IT plan. 1Password combines strong security with a user-friendly interface that makes adoption easier for non-technical teams. It also supports shared vaults, which let teams securely share credentials for shared accounts without sending passwords over email or chat. Other solid options in the SMB space include Bitwarden (affordable and open-source) and Keeper (compliance-focused with detailed audit logging). When rolling out a password manager to your team, start by migrating your most critical accounts first: email, banking, and payroll. Then set a deadline for employees to move all business accounts into the manager. The master password is the one password employees must memorize, so make sure it is a strong passphrase that is not used anywhere else. ## Require multi-factor authentication (MFA) MFA is the single most effective account protection after a strong password. It requires a second form of verification, typically a code from an authenticator app, in addition to the password. Even if an attacker steals a password, they cannot access the account without the second factor. Where to enforce MFA: - **Microsoft 365 and email** (this is the most critical one) - **VPN and remote access** connections - **Banking and payroll** systems - **Any cloud application** that stores sensitive business data Authenticator apps like Microsoft Authenticator or Authy are preferred over SMS text message codes. SMS-based MFA is better than nothing, but it is vulnerable to SIM swapping attacks where an attacker convinces your phone carrier to transfer your number to their device. Authenticator apps do not have this vulnerability. If your business uses Microsoft 365 Business Premium, you can enforce MFA across your entire organization using Conditional Access policies in Entra ID. Conditional Access lets you create rules like "require MFA for all sign-ins from outside the office network" or "require MFA for any sign-in to admin portals." This is far more effective than relying on individual employees to enable MFA themselves. ## What your written policy should include Keep the document short and specific. Here is what it should cover: - **Minimum password length:** 12 characters minimum, 16 or more recommended. - **Password manager requirement:** All business accounts must use the company password manager. No exceptions. - **No password reuse:** Every account gets a unique password, enforced through the password manager. - **MFA requirement:** MFA must be enabled on all critical systems. List the specific systems. - **Compromise reporting procedure:** If an employee suspects a password has been compromised, they must report it to IT immediately, change the password, and not attempt to investigate on their own. - **No password sharing:** Employees should never share passwords via email, chat, or text. If a shared account is necessary, use the shared vault in your password manager. ## How to enforce the policy A policy that is not enforced is just a suggestion. Here are concrete ways to make it stick: **Use technical controls where possible.** In Microsoft 365, you can set password length minimums through Entra ID. Enable Conditional Access policies to require MFA, so it is not optional. Block legacy authentication protocols (IMAP, POP3) that do not support MFA. **Audit password manager adoption quarterly.** Check that all employees are actively using the password manager. 1Password's admin dashboard shows you which team members have logged in recently and how many accounts they have stored. If someone has only two items in their vault, they are not using it for all their business accounts. **Include the password policy in onboarding.** New employees should set up their password manager account and enroll in MFA on their first day. Make it part of the onboarding checklist, not something they get around to later. **Lead by example.** If the owner or leadership team does not follow the policy, nobody else will either. Owners and managers should follow the same rules, no exceptions. ## Need help? Building a password policy is straightforward, but rolling it out and enforcing it across your team takes work. If you want help creating your policy or deploying a password manager and MFA to your organization, [reach out to Athencia](/contact). We do this for small businesses every day. #### How to Recognize a Phishing Email: A Guide for Small Business Employees > Learn the warning signs of phishing emails and how to protect your small business from email-based attacks with practical tips your whole team can follow. URL: https://athencia.com/kb/cybersecurity/how-to-recognize-a-phishing-email-a-guide-for-small-business-employees Phishing emails trick people into clicking malicious links, downloading malware, or handing over credentials by impersonating trusted senders. Recognizing the warning signs before clicking is the single most effective defense a small business has against email-based attacks. ## What is phishing and why small businesses are targeted Phishing is a type of social engineering attack where criminals send fraudulent emails designed to steal your login credentials, install malware on your computer, or trick you into sending money. The emails are crafted to look like they come from someone you trust: Microsoft, your bank, a vendor, or even your own CEO. Small businesses are prime targets for phishing because they typically have fewer security layers in place, less frequent employee training, and higher-trust environments where people are less likely to question an email from a colleague. Attackers know this, and they exploit it. The average cost of a successful phishing attack on a small business ranges from $25,000 to over $100,000 when you factor in downtime, recovery, and potential data breach notification costs. ## Red flag 1: Urgency and pressure tactics Phishing emails almost always try to create a sense of panic. You will see subject lines and body text like "Your account will be suspended in 24 hours," "Immediate action required," or "Respond within the hour to avoid service disruption." The goal is to bypass your critical thinking by making you feel like you need to act right now without stopping to verify. Legitimate companies rarely threaten immediate consequences via email. If Microsoft or your bank actually needed you to take urgent action, they would typically notify you through their app, your account dashboard, or by phone. An email demanding you click a link immediately is a red flag, every time. ## Red flag 2: Sender address does not match This is one of the easiest things to check, and one of the most commonly missed. The display name in your inbox might say "Microsoft Support," but if you look at the actual email address, it reads something like support@m1crosoft-alerts.com. That is not Microsoft. To check the actual sender address in Outlook, hover over or click the sender name to reveal the full email address. On a phone, tap the sender name to expand the details. Look closely for swapped letters (rn instead of m), extra characters, or domains that do not match the company's real website. If a vendor you work with has always emailed you from billing@acmecorp.com and suddenly sends from billing@acme-corp-invoices.com, that is suspicious. ## Red flag 3: Suspicious links Before clicking any link in an email, hover your mouse over it (without clicking) to see where it actually leads. The displayed text might say "Sign in to your account," but the underlying URL could point to a completely different domain. Look for misspelled domains, extra subdomains (like microsoft.login.suspicious-site.com), or unfamiliar URLs. Shortened URLs from services like bit.ly or tinyurl in business emails are almost always suspicious. Legitimate companies link to their own domains. If you are unsure about a link, open a new browser tab and navigate directly to the company's website instead of clicking the link in the email. ## Red flag 4: Unexpected attachments If you were not expecting a file from a particular sender, do not open it. Dangerous file types include .exe, .zip, .docm (macro-enabled Word documents), and .html files. Even PDFs and standard Word documents can contain malicious content. When in doubt, confirm with the sender through a separate channel. Call them, send a Teams message, or walk over to their desk. Do not reply to the suspicious email to ask if it is legitimate, because if the sender's account was compromised, the attacker will respond and tell you it is safe. ## Red flag 5: Requests for credentials or sensitive information No legitimate service will ever ask you for your password via email. Messages like "Please verify your password by clicking here" or "Update your payment information to avoid service interruption" are phishing attempts. Common targets include fake Microsoft 365 sign-in pages, bank portals, and payroll systems. If you receive an email asking you to log in to any service, do not use the link in the email. Open a new browser tab, go directly to the service's website, and log in from there. If there is a real issue with your account, you will see it after you sign in. ## Red flag 6: Generic greetings and poor formatting Phishing emails often use generic greetings like "Dear Customer" or "Dear User" instead of your actual name. They may also contain grammatical errors, odd phrasing, or inconsistent formatting like mixed fonts, misaligned logos, or low-resolution images. One important caveat: AI-generated phishing emails are getting significantly better at grammar and formatting. A well-written email is not proof that it is legitimate. Always check the other red flags on this list, even if the writing looks professional. ## What to do if you suspect a phishing email Follow these steps in order: 1. **Do not click any links or open any attachments** in the email. 2. **Do not reply** to the email. 3. **Report it to your IT team or managed service provider immediately.** A quick report lets them investigate and warn others before anyone else falls for the same email. 4. **Use the Report Message button in Outlook.** If your company uses Microsoft 365, the **Report Message** add-in lets you flag suspicious emails directly from your inbox. Click the **Report Message** button in the ribbon and select **Phishing**. This reports the message to Microsoft and your admin, and moves it out of your inbox. Microsoft Defender for Office 365 uses these reports to improve its filtering for your entire organization. 5. **If you already clicked a link or entered credentials,** report it to your IT team immediately and change your password from a known-safe device. Do not wait. ## Building a phishing-resistant team Technology helps, but people are the last line of defense against phishing. Building a team that can spot phishing consistently requires ongoing effort. **Run regular security awareness training.** At minimum, train employees quarterly on how to recognize phishing, social engineering, and BEC attacks. Huntress provides security awareness training (SAT) as part of its platform, combining phishing simulations with targeted training modules that adapt based on how employees perform. This approach measures actual behavior rather than just checking a compliance box. **Run simulated phishing tests.** Simulated phishing campaigns send fake phishing emails to your team and track who clicks. This is not about catching people doing something wrong. It is about identifying who needs more training and measuring improvement over time. When someone clicks a simulated phishing link, they should immediately see a brief training message explaining what they missed. **Create a no-blame culture for reporting.** If employees are afraid of getting in trouble for reporting a suspicious email (or even for clicking one), they will stay quiet. That silence is far more dangerous than the click itself. Make it clear that reporting a suspicious email is always the right thing to do, and that reporting a mistake quickly is valued, not punished. **Establish a clear reporting process.** Every employee should know exactly what to do when they see a suspicious email. Post the process somewhere visible: on the intranet, in the breakroom, or as a pinned message in your company's Teams channel. The simpler the process, the more likely people are to follow it. ## How technology helps block phishing Even with a well-trained team, some phishing emails are convincing enough to fool anyone. That is where email security technology comes in. Microsoft Defender for Office 365, included with Microsoft 365 Business Premium, provides Safe Attachments (scans email attachments in a sandbox before delivering them), Safe Links (rewrites URLs and checks them at click time), and anti-phishing policies that detect impersonation attempts. These features catch many phishing emails before they ever reach your team's inbox. Athencia layers Huntress on top of Microsoft Defender for Business on every managed endpoint, providing a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. If a phishing email does slip through and an employee downloads something malicious, Huntress catches the resulting suspicious behavior on the endpoint and responds before damage spreads. The combination of email filtering, endpoint protection, and trained employees creates multiple layers of defense. No single layer is perfect, but together they make a successful phishing attack far less likely. ## Need help? Phishing is the most common way small businesses get breached, and it only takes one click. If you want help setting up email security, running phishing simulations, or training your team, [contact Athencia](/contact). We will help you build a defense that works. #### How to Secure Remote and Hybrid Employees for a Small Business > Practical security guide for small businesses with remote or hybrid employees, covering VPN, device management, home network risks, and access controls. URL: https://athencia.com/kb/cybersecurity/how-to-secure-remote-and-hybrid-employees-for-a-small-business Remote and hybrid work expands your attack surface because employees access company data from home networks, coffee shops, and personal devices that you do not control. Securing remote workers does not require enterprise-grade complexity, but it does require deliberate steps beyond what most small businesses have in place. ## What you will need Before you start, make sure you have the following in place: - **Microsoft 365 Business Premium** (or equivalent) for Conditional Access, Intune device management, and Defender for Business. This is the license tier Athencia deploys for managed clients because it bundles identity, device, and email security into a single plan. - **A clear policy** on which devices can access company data and under what conditions. - **An understanding of how your employees currently work remotely,** including what devices they use, what networks they connect from, and what applications they access. ## Step 1: Require MFA for all remote access Multi-factor authentication is non-negotiable for any employee accessing company systems from outside the office. If an attacker steals an employee's password (through phishing, a data breach, or credential stuffing), MFA stops them from signing in. Enable MFA on Microsoft 365, your VPN, and any cloud applications your business uses. The most effective way to do this is through Conditional Access policies in Entra ID, which let you create rules like "require MFA for all sign-ins from outside the office network" or "require MFA when a sign-in is flagged as risky." This approach enforces MFA automatically rather than relying on employees to enable it themselves. Authenticator apps like Microsoft Authenticator are preferred over SMS text message codes for remote workers. SMS codes are vulnerable to SIM swapping attacks, and cell reception can be unreliable when working from different locations. ## Step 2: Use company-managed devices Employees should access company data from company-owned, managed devices whenever possible. An unmanaged personal computer may have outdated software, no antivirus, or malware already running on it. You have no way to know. Enroll company devices in Microsoft Intune, which is included with Microsoft 365 Business Premium. Intune lets you enforce security policies remotely: require BitLocker encryption on all laptops, require a device PIN, enforce Windows updates automatically, and remotely wipe a lost or stolen device. This is especially critical for remote workers whose laptops travel with them to coffee shops, airports, and co-working spaces. If employees must use personal devices (a BYOD scenario), Intune's Mobile Application Management (MAM) can protect company data within managed apps like Outlook and Teams without taking control of the entire personal device. This creates a separation between personal and business data. The employee keeps their personal apps and photos; you keep your business data secure and wipeable. ## Step 3: Secure the connection For businesses with on-premises resources like file servers or internal applications, employees need a VPN to access them securely from outside the office. If you use a VPN, make sure it requires MFA to connect. A VPN without MFA is a wide-open door if credentials are stolen. For cloud-only environments where everything runs in Microsoft 365 and SaaS applications, a VPN may not be necessary if you have Conditional Access configured properly. Conditional Access can enforce security requirements (MFA, device compliance, location) at the identity layer, which provides similar protection without the overhead of routing all traffic through a VPN. Regardless of your setup, advise employees to avoid public Wi-Fi for work tasks unless they are using a VPN. Open networks at coffee shops and hotels are easy targets for attackers to intercept traffic. If public Wi-Fi is unavoidable, a VPN encrypts the connection and prevents eavesdropping. ## Step 4: Protect endpoints Every remote device needs the same endpoint protection as office devices, if not more. Remote laptops face additional risks because they are not behind the office firewall and are more likely to be lost or stolen. Athencia deploys Microsoft Defender for Business as the endpoint protection foundation on every managed device, then layers Huntress on top to provide a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. Defender handles real-time protection and threat scanning; Huntress makes sure nothing slips through by monitoring for persistent footholds, suspicious processes, and identity-based attacks. Other endpoint protection options in the SMB space include SentinelOne and CrowdStrike. Beyond endpoint protection software, make sure the following settings are configured on all remote devices: - **Windows updates install automatically.** Remote devices are not on the office network where a patch management server pushes updates, so automatic updates are essential. - **Windows Firewall is enabled.** This should be on by default, but verify it has not been disabled. - **BitLocker is turned on.** Full-disk encryption means a stolen laptop does not expose your data. BitLocker is included with Windows Pro and can be enforced through Intune. - **Automatic screen lock is set to 5 minutes.** If an employee walks away from their laptop at a coffee shop, the screen should lock quickly. ## Step 5: Control data access Not every employee needs access to everything, and not every device should be trusted equally. Conditional Access policies in Entra ID let you build rules that control who can access what, from where, and on which devices. Practical examples of Conditional Access rules for remote workers: - **Block access from unmanaged devices** to sensitive data, or limit access to view-only in the browser so files cannot be downloaded to personal computers. - **Prevent syncing SharePoint or OneDrive** to unmanaged personal computers. This keeps company files from being copied to devices you do not control. - **Require device compliance** before allowing access. A device must meet your Intune compliance policy (updated, encrypted, protected) before it can access company resources. - **Use sensitivity labels** on confidential documents to prevent forwarding, printing, or copying, regardless of where the document is accessed from. These rules work automatically in the background. Employees on compliant, managed devices will not notice any friction. Employees trying to access data from unapproved devices will be prompted to use a compliant device instead. ## Step 6: Address home network risks Employees' home routers are rarely secured properly. Default passwords are unchanged, firmware is years out of date, and the same network connects work laptops alongside smart TVs, baby monitors, and gaming consoles. You cannot fully control a home network, but you can provide guidance and focus your security on the device and connection instead. Share these recommendations with remote employees: - **Change the default router admin password** to something unique. The default password is publicly known for every router model. - **Enable WPA3 or WPA2 encryption** on the Wi-Fi network. WPA and WEP are outdated and easily cracked. - **Update the router firmware.** Most routers have an update option in the admin panel, typically accessible at 192.168.1.1 or 192.168.0.1. - **Separate work devices from IoT devices** on different networks if the router supports guest networks or VLANs. This prevents a compromised smart device from being used as a stepping stone to the work laptop. Recognize that home network guidance is advisory. Your real protection comes from the device-level security (endpoint protection, encryption, Intune compliance) and the identity-level security (MFA, Conditional Access) that you control directly. ## Create a remote work security policy Document your remote work security expectations in a short, practical policy. A one-page document that everyone reads and follows is far more effective than a 10-page policy that sits in a shared drive untouched. Include the following: - Which devices are approved for remote work (company-managed only, or BYOD with MAM). - What applications can be accessed remotely and from where. - VPN requirements and when to use it. - How to handle a lost or stolen device (report to IT immediately). - Acceptable use guidelines for public Wi-Fi and shared workspaces. Review and update the policy annually, or whenever your remote work setup changes significantly. ## Need help? Securing remote and hybrid workers involves identity, devices, data, and network considerations that need to work together. If you want help setting up Intune, Conditional Access, and endpoint protection for your remote team, [get in touch with Athencia](/contact). We help small businesses build remote work security that actually holds up. #### How to Secure Your Business Email Against Spoofing with SPF, DKIM, and DMARC > Plain-language guide to setting up SPF, DKIM, and DMARC records to prevent attackers from spoofing your business email domain. URL: https://athencia.com/kb/cybersecurity/how-to-secure-your-business-email-against-spoofing-with-spf-dkim-and-dmarc SPF, DKIM, and DMARC are three DNS records that work together to prevent attackers from sending emails that appear to come from your business domain. Without them, anyone can send an email that looks like it came from you@yourcompany.com, and your clients, vendors, and employees have no way to tell the difference. ## Why email spoofing is a serious problem for small businesses Spoofing means someone sends email pretending to be you or one of your employees. It is surprisingly easy to do. Without proper email authentication records, an attacker can send an invoice that appears to come from your CEO to your bookkeeper, requesting an urgent wire transfer. Or they can send emails to your clients that look like they came from your domain, damaging your reputation and trust. Beyond the fraud risk, email deliverability is at stake. Google and Microsoft are increasingly blocking or flagging email from domains that lack proper SPF, DKIM, and DMARC records. If your domain does not have these records configured, your legitimate emails may end up in your clients' spam folders. Setting up all three records is free (they are just DNS entries) and protects your domain from being used in phishing attacks against the people who trust your business. ## Understanding the three records Before diving into setup, here is what each record does in plain language: **SPF (Sender Policy Framework)** tells receiving mail servers which servers are authorized to send email for your domain. Think of it as a guest list for your email. If an email claims to come from your domain but was sent from a server not on the list, the receiving server knows something is wrong. **DKIM (DomainKeys Identified Mail)** adds a digital signature to every outgoing email, proving that the message was not tampered with in transit and that it actually came from your domain. Think of it as a wax seal on a letter. If the seal is broken, the recipient knows the message was altered. **DMARC (Domain-based Message Authentication, Reporting, and Conformance)** ties SPF and DKIM together and tells receiving servers what to do when authentication checks fail. You choose the action: do nothing (monitor only), quarantine the message (send it to spam), or reject it outright (block it). DMARC also sends you reports about who is trying to send email as your domain. All three work together. SPF and DKIM verify the email is legitimate; DMARC tells the world what to do when it is not. ## Step 1: Check your current records Before making changes, check what you already have in place. Go to [MXToolbox.com](https://mxtoolbox.com) and run a lookup on your domain. Check for SPF, DKIM, and DMARC records separately. What you are likely to find: many small business domains have a partial or incorrect SPF record (often missing third-party senders), no DKIM signing enabled, and no DMARC record at all. If your results show all three configured correctly, you are ahead of most small businesses. If not, work through the steps below. Another useful tool is [dmarcian.com](https://dmarcian.com), which provides a more detailed analysis and ongoing monitoring. ## Step 2: Set up SPF SPF is a TXT record added to your domain's DNS settings. You access DNS through wherever your domain is registered (GoDaddy, Namecheap, Cloudflare, etc.) or through your DNS hosting provider. For businesses using Microsoft 365, the SPF record should be: ``` v=spf1 include:spf.protection.outlook.com -all ``` This tells receiving servers that Microsoft's mail servers are authorized to send email for your domain, and that all other servers should be rejected (`-all`). If you use other services that send email on your behalf, such as Mailchimp for newsletters, QuickBooks for invoices, or a CRM that sends from your domain, you need to add their SPF includes to the same record. For example: ``` v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net -all ``` Important: you can only have one SPF record per domain. If you create a second one, both will break. Combine all authorized senders into a single record. The difference between `~all` (soft fail) and `-all` (hard fail): soft fail means "treat unauthorized senders as suspicious," while hard fail means "reject unauthorized senders." Start with `-all` if you are confident you have listed all legitimate senders. Use `~all` temporarily if you are still identifying all services that send email as your domain. ## Step 3: Set up DKIM DKIM requires generating signing keys and publishing them in your DNS. For Microsoft 365, this is done through the Microsoft Defender portal. 1. Go to [security.microsoft.com](https://security.microsoft.com). 2. Navigate to **Policies & rules** > **Threat policies** > **Email authentication settings**. 3. Select the **DKIM** tab. 4. Select your domain from the list. 5. Click **Enable** to turn on DKIM signing. 6. Microsoft will display two CNAME records that you need to add to your domain's DNS. Copy those CNAME records and add them at your DNS provider. The records will look something like: ``` selector1._domainkey.yourcompany.com -> selector1-yourcompany-com._domainkey.yourcompany.onmicrosoft.com selector2._domainkey.yourcompany.com -> selector2-yourcompany-com._domainkey.yourcompany.onmicrosoft.com ``` After adding the DNS records, wait for DNS propagation (this can take up to 48 hours, though it often completes much faster). Then return to the Defender portal and click **Enable** again to activate DKIM signing. If the DNS records have propagated, DKIM will turn on successfully. A common mistake is adding the DNS records but forgetting to go back and enable DKIM signing in the portal. Both steps are required. ## Step 4: Set up DMARC DMARC is another TXT record added to your DNS. Start with a monitoring-only policy so you can see what is happening before you start blocking anything. Add this TXT record to your DNS at `_dmarc.yourcompany.com`: ``` v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com ``` Here is what each part means: - `v=DMARC1` identifies this as a DMARC record. - `p=none` is the policy. "None" means do not take action on failed messages; just report them. - `rua=mailto:dmarc-reports@yourcompany.com` is where aggregate reports will be sent. The `p=none` policy does not block anything, but it starts sending you reports about who is sending email as your domain. This is the discovery phase, and it is essential. Skipping straight to a blocking policy risks blocking legitimate email from services you forgot about. After monitoring for 2 to 4 weeks and reviewing your reports, move to `p=quarantine`. This sends suspicious emails (those failing SPF and DKIM checks) to the recipient's spam folder instead of their inbox. Once you are confident that all legitimate senders are properly authenticated, move to `p=reject`. This is the final goal. With a reject policy, spoofed emails claiming to come from your domain are blocked entirely and never delivered. ## Step 5: Monitor DMARC reports DMARC sends XML report files to the email address specified in your `rua=` tag. These reports are dense and difficult to read in raw format. Use a free tool like [dmarcian](https://dmarcian.com), Valimail, or DMARC Analyzer to parse and visualize them. What to look for in your reports: - **Legitimate services failing authentication.** If your CRM or invoicing software is sending email as your domain but is not included in your SPF record, it will show up as a failure. Add it to your SPF record. - **Unknown senders spoofing your domain.** If you see emails being sent from your domain by servers you do not recognize, someone is spoofing you. This is exactly what DMARC is designed to catch. - **The overall pass rate.** As you add legitimate senders to SPF and enable DKIM, your pass rate should climb toward 100%. Review reports weekly during the first month, then monthly once your configuration is stable. Microsoft Defender for Office 365, included with Microsoft 365 Business Premium, also provides email authentication insights in the Defender portal that complement your DMARC reports. ## Common mistakes These are the issues we see most often when small businesses set up email authentication: - **Multiple SPF records.** Only one SPF TXT record is allowed per domain. If you add a second one, both fail. Combine all authorized senders into a single record. - **Jumping to DMARC p=reject before monitoring.** This blocks legitimate email from services you forgot to authorize. Always start with `p=none`, review reports, then move to `p=quarantine`, and finally `p=reject`. - **Forgetting third-party senders.** Your CRM, invoicing software, marketing platform, and ticketing system may all send email as your domain. Each one needs to be included in your SPF record. - **Adding DKIM DNS records but not enabling signing.** The CNAME records in DNS are only half the setup. You must also enable DKIM signing in the Microsoft Defender portal. ## Need help? Email authentication involves DNS changes that can affect your email deliverability if done incorrectly. If you are not comfortable making DNS changes yourself, or if you want someone to handle the full SPF, DKIM, and DMARC setup and monitoring, [contact Athencia](/contact). We configure email authentication for small businesses regularly and can have it done correctly in a single session. #### What Is Business Email Compromise and How to Protect Your Company > Explains how business email compromise (BEC) attacks work, why they target small businesses, and practical steps to prevent wire fraud and data theft. URL: https://athencia.com/kb/cybersecurity/what-is-business-email-compromise-and-how-to-protect-your-company Business email compromise (BEC) is a type of attack where a criminal impersonates a trusted person, typically a CEO, vendor, or attorney, to trick an employee into sending money or sensitive information. BEC attacks cause more financial damage than any other type of cybercrime, with the FBI reporting over $2.9 billion in losses in a single year. Unlike ransomware, which is loud and obvious, BEC is quiet. There is no malware, no locked screens, and often no sign anything happened until the money is gone. ## How BEC attacks work A BEC attack starts with research. The attacker learns about your company by browsing your website, LinkedIn profiles, and social media. They identify who the CEO is, who handles finances, who your vendors are, and how your company communicates internally. Next, the attacker either compromises a real email account (through phishing, credential theft, or password spraying) or creates a lookalike email address that is almost identical to a real one. For example, they might register "athencla.com" instead of "athencia.com," a difference most people would not notice in a busy inbox. Then comes the request. The attacker sends a convincing email asking for an urgent wire transfer, payment to a new bank account, or sensitive data like W-2 forms or employee records. The email appears to come from someone the employee trusts and expects to receive instructions from. The urgency and authority built into the request pressure the employee into acting quickly without verifying through a separate channel. The entire attack relies on social engineering, not technology. That is what makes it so effective and so difficult for traditional security tools to catch. ## Common BEC scenarios **CEO fraud.** An email appearing to come from the CEO or owner asks the bookkeeper or office manager to wire funds for a "confidential acquisition" or "urgent vendor payment." The email often includes language like "handle this quietly" or "I'm in a meeting, can you take care of this before end of day?" **Vendor invoice manipulation.** An email appearing to come from a real vendor says "our bank account has changed, please send future payments to this new account number." The email may include a convincing invoice with the correct logo, formatting, and amounts, but with different banking details. **Attorney impersonation.** A fake attorney contacts an employee about a "confidential legal matter" requiring immediate payment. These often target finance staff and use legal urgency to discourage questions. **Payroll diversion.** An email appearing to come from an employee asks HR to update their direct deposit information to a new bank account. The employee's real paycheck then goes to the attacker. **Data theft.** A request for W-2s, employee lists, Social Security numbers, or client data, sent to HR or the office manager from what appears to be the CEO. This information is then used for identity theft or sold on the dark web. ## Why small businesses are especially vulnerable Small businesses are the ideal target for BEC because they often have fewer approval layers for financial transactions. One person may handle all payments, and a request from the owner is rarely questioned. There is often no formal verification process for changing vendor payment details or processing wire transfers. Smaller teams also mean fewer people to notice something is off. In a larger company, a suspicious wire transfer request might pass through multiple approvals and raise questions. In a 15-person company, the person who handles the books may simply process the request because the email looks like it came from the boss. The amounts requested in BEC attacks are often deliberately calibrated. Attackers request amounts large enough to be profitable but small enough to avoid triggering bank fraud alerts or unusual payment scrutiny. A $28,000 wire transfer feels urgent but not outlandish, which is exactly the point. ## Protection step 1: Implement verification procedures The most effective defense against BEC is a simple human process: verify before you act. Require verbal (phone call) confirmation for any wire transfer, payment change, or new vendor setup. Call the person using a phone number you already have on file, not a number provided in the email. If the CEO sends an email requesting a wire transfer, call the CEO on their known cell phone number and confirm it. Require dual authorization for wire transfers and payments above a set threshold. No single person should be able to initiate and approve a large payment on their own. Never change vendor payment details based solely on an email request. Always verify new banking information through a known contact at the vendor company, using a phone number from your records. These verification steps may feel like extra work, but they are far cheaper than losing $50,000 to a fraudulent wire transfer. ## Protection step 2: Secure your email accounts If an attacker cannot compromise your actual email accounts, they are limited to spoofing or lookalike domains, which are easier to detect. Locking down your email is critical. **Enable MFA on all email accounts.** This is the single most effective technical protection against account compromise. If an attacker phishes an employee's password, MFA stops them from signing in. Use Conditional Access policies in Entra ID to enforce MFA across your entire Microsoft 365 tenant, not just for users who remember to turn it on. **Configure anti-phishing policies in Microsoft Defender for Office 365.** Defender for Office 365, included with Microsoft 365 Business Premium, provides impersonation protection that flags emails where the sender's name matches a known internal user but the email address does not. This catches many BEC attempts before they reach the inbox. **Enable mailbox auditing** to detect unauthorized access to email accounts. Microsoft 365 has mailbox auditing enabled by default, but verify it is active for all users. **Set up alerts for mail forwarding rule changes.** One of the first things an attacker does after compromising an account is set up a forwarding rule to intercept replies. Configure alerts in the Security & Compliance center to notify admins when new forwarding rules are created. Huntress provides identity threat detection and response (ITDR) that monitors for suspicious sign-in activity, credential attacks, and account takeover attempts across your Microsoft 365 environment. This adds a layer of 24/7 human monitoring that catches identity-based threats that automated tools may miss. ## Protection step 3: Protect against domain spoofing Configure SPF, DKIM, and DMARC on your email domain to prevent attackers from sending email that appears to come from your exact domain. With DMARC set to a "reject" policy, spoofed emails are blocked by the receiving server and never delivered. This does not prevent lookalike domains (athencla.com vs. athencia.com), but it stops exact-domain spoofing. For a detailed setup guide, see our article on [how to secure your business email against spoofing with SPF, DKIM, and DMARC](/kb/cybersecurity/how-to-secure-your-business-email-against-spoofing-with-spf-dkim-and-dmarc). ## Protection step 4: Train your team Make BEC a specific topic in your security awareness training, separate from general phishing awareness. BEC attacks are different because they often contain no malicious links or attachments. They rely entirely on social engineering, which means technical email filters may not catch them. Use real-world examples relevant to your industry. A law firm should hear about fake settlement wire requests; a construction company should hear about fraudulent subcontractor invoices. The scenarios need to feel real to your team. Emphasize that urgency and authority are the primary manipulation tools in BEC. Any request that is both urgent and involves money or sensitive data should trigger a verification call, every time. Create a culture where questioning a financial request is expected, not disrespectful. The bookkeeper should feel comfortable calling the CEO to verify a wire transfer, even if the email says "don't call me, I'm in a meeting." That is exactly when they should call. Huntress provides security awareness training as part of its platform, including targeted BEC scenarios and phishing simulations that help employees practice identifying these attacks in a safe environment. ## What to do if you suspect a BEC attack Act fast. Every hour matters, especially if money has already been sent. 1. **Do not send the requested payment or information.** If you have not acted on the request yet, stop. 2. **Verify the request** through a separate communication channel. Call the supposed sender using a known phone number. 3. **If money was already sent, contact your bank immediately.** Wire recalls have a narrow window (often 24 to 48 hours). The sooner you call, the better your chances of recovering the funds. 4. **Report to the FBI's IC3** at [ic3.gov](https://www.ic3.gov/) and your local FBI field office. BEC is a federal crime and the IC3 has a Recovery Asset Team that works with banks to freeze fraudulent transfers. 5. **If an email account was compromised,** reset the password, revoke all active sessions, check for forwarding rules and inbox rules, and review recent sent items to see what the attacker sent from the account. 6. **Notify your cyber insurance carrier.** Most policies have specific timelines for breach notification, and delayed reporting can affect your claim. ## Need help? BEC is the costliest form of cybercrime for small businesses, and prevention starts with the right combination of training, verification procedures, and email security. If you want help hardening your email environment or responding to a suspected compromise, [contact Athencia](/contact). We handle BEC prevention and incident response for small businesses across the country. #### What Is Ransomware and How Can Small Businesses Protect Against It > Plain-language explanation of ransomware, how it targets small businesses, and the practical steps you can take to prevent and recover from an attack. URL: https://athencia.com/kb/cybersecurity/what-is-ransomware-and-how-can-small-businesses-protect-against-it Ransomware is malicious software that encrypts your business files and demands payment (a ransom) to unlock them. Small businesses are the most common target because they often lack the security layers that larger companies have, and they are more likely to pay to get their data back quickly. ## How ransomware works Ransomware typically enters your network through a phishing email, a compromised website, or an unpatched vulnerability in your software. Once inside, the malware spreads across the infected computer and any connected network drives, encrypting files as it goes. Documents, spreadsheets, databases, images, and backups (if they are accessible on the network) all get locked. A ransom note then appears on screen demanding payment, usually in cryptocurrency like Bitcoin, in exchange for the decryption key. There is typically a deadline, and the attacker threatens to increase the ransom or permanently delete the key if you do not pay in time. Modern ransomware attacks frequently use a tactic called double extortion. The attacker steals a copy of your data before encrypting it, then demands two payments: one to decrypt your files and another to prevent them from leaking your data publicly. This means that even if you have good backups and can restore your files without paying, you still face the threat of sensitive data being published. Typical ransom demands for small businesses range from $10,000 to $250,000 or more, depending on the attacker's assessment of what you can afford. ## Why small businesses are prime targets Attackers have figured out the sweet spot: small businesses are big enough to pay meaningful ransoms but small enough to have significant security gaps. Most small businesses do not have dedicated IT security staff or advanced endpoint protection. Systems are often running outdated software with unpatched vulnerabilities. Backup and recovery plans exist on paper but have never been tested. And when a ransomware attack hits, the pressure to pay is enormous because extended downtime can threaten the survival of the business. Attackers know all of this. They specifically target small businesses because the return on effort is high. A single phishing email can lead to a six-figure payout. ## How ransomware gets in (common entry points) Understanding how ransomware enters your network is the first step to blocking it: - **Phishing emails** with malicious attachments or links are the most common entry point. An employee opens a file or clicks a link, and the malware installs silently in the background. - **Remote Desktop Protocol (RDP)** exposed to the internet with weak or default credentials. Attackers scan the internet for open RDP ports and brute-force their way in. - **Unpatched vulnerabilities** in software, firewalls, or VPN appliances. Known vulnerabilities in widely used products are exploited within days of being disclosed. - **Compromised credentials** purchased on the dark web from previous data breaches. If an employee reused a password that was exposed in a breach, attackers buy it and try it against your systems. - **Infected USB drives or personal devices** connected to the business network without proper security controls. ## Protection step 1: Implement strong email security Since phishing is the most common delivery method for ransomware, email security is your first line of defense. Microsoft Defender for Office 365, included with Microsoft 365 Business Premium, provides Safe Attachments and Safe Links. Safe Attachments opens email attachments in a secure sandbox environment before delivering them to the recipient. If the attachment is malicious, it is blocked before it ever reaches the inbox. Safe Links rewrites URLs in emails and checks them at the moment the user clicks, blocking access to known malicious sites even if the URL was safe when the email was originally sent. Configure anti-phishing policies in Defender to detect impersonation attempts and flag suspicious emails. These policies catch many ransomware delivery emails before employees ever see them. Complement your email security with employee training. Even the best filters will miss some phishing emails, so your team needs to know how to recognize them. See our guide on [how to recognize a phishing email](/kb/cybersecurity/how-to-recognize-a-phishing-email-a-guide-for-small-business-employees) for practical tips you can share with your staff. Implement SPF, DKIM, and DMARC on your email domain to prevent attackers from spoofing your domain in phishing campaigns. ## Protection step 2: Keep everything patched and updated Unpatched software is one of the easiest ways for ransomware to enter your network. Every patch you skip is a known vulnerability that attackers can exploit. Enable automatic Windows updates on all business PCs. For remote workers who are not on the office network, this is especially important since they may miss updates that a local patch management server would push. Keep third-party software updated as well. Browsers (Chrome, Edge, Firefox), Adobe Reader, Java, and Zoom all receive regular security patches. Outdated versions of these applications are common entry points. Patch network equipment firmware including routers, firewalls, and wireless access points. These devices sit at the edge of your network and are often forgotten in patching routines. Replace end-of-life software and hardware that no longer receives security updates. Running Windows 10 after its end-of-life date, for example, means known vulnerabilities will never be patched, leaving your systems permanently exposed. If your business uses Microsoft 365 Business Premium, Microsoft Intune can enforce update policies across all enrolled devices, ensuring that patches install automatically even on remote laptops. ## Protection step 3: Use endpoint protection (not just antivirus) Traditional antivirus works by scanning files against a database of known malware signatures. Modern ransomware is specifically designed to evade signature-based detection. It changes its code with every attack, encrypts itself to avoid detection, and uses legitimate system tools to carry out malicious actions. Endpoint Detection and Response (EDR) takes a fundamentally different approach. Instead of just checking files against a list, EDR monitors the behavior of processes running on your computer. If a process starts encrypting files rapidly, disabling backups, or communicating with known command-and-control servers, EDR detects and stops it. Athencia deploys Microsoft Defender for Business as the endpoint protection foundation on every managed device, then layers Huntress on top to provide a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. Defender handles real-time protection and automated responses; Huntress adds persistent foothold detection, SIEM log analysis, and human-led investigations that catch threats automated tools miss. Other EDR options in the SMB space include SentinelOne and CrowdStrike. The key point: you need both automated detection and human monitoring. Automated tools catch the obvious threats; human analysts catch the sophisticated ones that know how to blend in. ## Protection step 4: Maintain tested backups Backups are your last line of defense against ransomware. If everything else fails, a clean, recent backup means you can restore your data without paying the ransom. Follow the 3-2-1 backup rule: maintain 3 copies of your data, on 2 different types of media, with 1 copy stored offsite or in the cloud. At least one backup must be air-gapped or immutable. An air-gapped backup is physically disconnected from your network, so ransomware cannot reach it. An immutable backup cannot be modified or deleted once written, even by an administrator. This is critical because modern ransomware specifically targets and encrypts backup files that are accessible on the network. Dropsuite provides cloud backup for Microsoft 365 email, OneDrive, and SharePoint, giving you an independent copy of your data that lives outside your Microsoft 365 environment. If ransomware compromises your tenant or an attacker deletes data, Dropsuite lets you restore from a clean backup. Test your backup restoration regularly. A backup you have never tested is not a backup. At least quarterly, restore a sample of files from your backup to verify that the process works, the data is intact, and you know how long recovery actually takes. Knowing your recovery time objective (RTO) before a crisis hits is far better than discovering it during one. ## Protection step 5: Limit access and privileges Ransomware spreads faster and does more damage when the infected account has broad access to files and systems. Limiting privileges reduces the blast radius of an attack. **Remove local admin rights** from everyday user accounts. Employees do not need admin privileges for their daily work, and removing those privileges prevents ransomware from making system-level changes on the infected computer. **Apply the principle of least privilege** for file share and application access. Users should only have access to the files and systems they need for their job, nothing more. **Segment your network** so that an infection on one computer cannot spread to every shared drive and system on your network. At minimum, separate guest Wi-Fi from your business network and isolate critical systems like accounting and HR databases. **Disable Remote Desktop Protocol (RDP)** unless it is absolutely necessary. If RDP must be used, protect it with a VPN and require MFA to connect. Exposed RDP is one of the most exploited entry points for ransomware. ## What to do if you are hit by ransomware If ransomware hits your business, speed and containment are critical. Here is what to do: 1. **Disconnect infected computers from the network immediately.** Unplug the Ethernet cable and disable Wi-Fi. The goal is to stop the ransomware from spreading to other devices and network drives. 2. **Do not pay the ransom.** Payment does not guarantee you will get your data back. It funds future attacks and marks your business as willing to pay, making you a target for repeat attacks. 3. **Contact your IT provider or MSP immediately.** Ransomware response requires expertise in containment, forensics, and recovery. Do not try to handle it alone. 4. **Report the incident** to the FBI's IC3 at [ic3.gov](https://www.ic3.gov/) and your cyber insurance carrier. Most insurance policies have specific timelines for reporting incidents. 5. **Begin recovery from clean backups** once the infection vector has been identified and contained. Restoring before you know how the ransomware got in risks reinfection. The best time to prepare for a ransomware attack is before it happens. Having endpoint protection, tested backups, and a basic incident response plan in place turns a potential disaster into a recoverable event. ## Need help? Ransomware protection requires layers: email security, endpoint protection, backups, patching, and access controls all working together. If you want help assessing your current defenses or building a protection plan for your business, [contact Athencia](/contact). We help small businesses put the right layers in place before an attack happens. #### What to Do If You Think Your Business Email Has Been Compromised > An incident response checklist for business email compromise (BEC). Steps to contain the threat, assess damage, and prevent it from happening again. URL: https://athencia.com/kb/cybersecurity/what-to-do-if-you-think-your-business-email-has-been-compromised ## Recognizing the signs Business email compromise (BEC) is one of the most financially damaging cyberattacks affecting small and mid-size businesses. The FBI's Internet Crime Complaint Center reports BEC losses exceeding $2.9 billion annually in the US alone. You may be dealing with a compromised email account if you notice any of the following: - **Sent items you did not write**, especially messages to vendors, clients, or finance contacts - **Inbox rules you did not create**, such as rules that auto-delete or forward messages - **Password reset notifications** you did not request - **Colleagues or clients reporting suspicious messages** from your address - **Unfamiliar sign-in activity** in your account's sign-in logs - **Missing emails** that should be in your inbox If any of these apply, treat the account as compromised and act immediately. Speed matters. ## Step 1: Contain the account (do this first) The goal is to stop the attacker from continuing to use the account. ### Reset the password 1. Have an administrator reset the user's password from the [Microsoft Entra admin center](https://entra.microsoft.com) 2. Use a strong, unique password (16+ characters) 3. Do not let the user reset their own password from the compromised account ### Revoke active sessions 1. In the Entra admin center, go to **Users** > select the user > **Sign-in sessions** 2. Click **Revoke all sessions** 3. This forces the attacker out of any active sessions immediately ### Disable the account temporarily (if needed) If you cannot confirm containment, disable the account entirely until the investigation is complete. In the Entra admin center, go to **Users** > select the user > **Properties** > **Account status** and toggle sign-in to **Block sign in**. This is the safest option when financial fraud may be in progress. ## Step 2: Check for persistence mechanisms Attackers often set up ways to maintain access even after a password change. Check all of the following. ### Inbox rules 1. Go to **Exchange admin center** > **Recipients** > **Mailboxes** > select user 2. Click **Manage mailbox delegation** or use PowerShell: `Get-InboxRule -Mailbox user@domain.com` 3. Look for rules that forward, redirect, or delete emails 4. Delete any rules you did not create ### Mail forwarding 1. In Exchange admin center, check the user's mailbox properties for **Email forwarding** 2. Verify no external forwarding address has been added 3. PowerShell: `Get-Mailbox user@domain.com | Select ForwardingAddress,ForwardingSmtpAddress` ### OAuth app consents 1. In Entra admin center, go to **Users** > select user > **Applications** 2. Review consented applications 3. Revoke any unfamiliar third-party app permissions ### Registered devices and MFA methods 1. Check **Authentication methods** for the user 2. Remove any MFA methods you do not recognize (unfamiliar phone numbers, authenticator apps) 3. Check **Devices** and remove any unrecognized registered devices ## Step 3: Assess the damage Before you can notify the right people, you need to understand what the attacker did. ### Review sign-in logs 1. Entra admin center > **Sign-in logs** 2. Filter by the affected user 3. Look for sign-ins from unusual locations, IP addresses, or devices 4. Note the earliest suspicious sign-in to establish a timeline If your environment is monitored by Huntress, check the Huntress dashboard as well. Huntress provides identity threat detection and response (ITDR) and SIEM capabilities that correlate sign-in anomalies with other suspicious activity across your environment, giving you a more complete picture of the compromise timeline. ### Review audit logs 1. Check **Unified audit log** in the Microsoft Purview compliance portal 2. Filter by the user and time range 3. Look for mail access, file downloads, sharing changes, and admin actions ### Check for data exfiltration - Were sensitive files accessed or downloaded from SharePoint or OneDrive? - Were emails forwarded to external addresses? - Were contact lists or client data exported? If your organization uses Dropsuite for Microsoft 365 backup, you can compare current mailbox and OneDrive contents against the backup to identify exactly what was deleted, modified, or exported during the compromise window. Document everything you find. You will need this for notifications and potential legal obligations. ## Step 4: Notify stakeholders ### Internal notification - Inform your leadership team and legal counsel - Alert your finance team if the attacker sent payment-related messages - Notify any employees who received suspicious messages from the compromised account ### External notification - Contact any clients or vendors who received fraudulent messages - If financial transactions were redirected, contact your bank immediately (wire recalls have a narrow window) - If personal data was exposed, you may have breach notification obligations under state law (e.g., CCPA) or industry regulations (e.g., HIPAA) ### Law enforcement - File a report with the [FBI's IC3](https://www.ic3.gov/) if financial fraud occurred - File a local police report if required by your cyber insurance policy ## Step 5: Harden the account and environment After containment and investigation, take these steps to prevent recurrence. ### For the affected account - Enable MFA if not already active (see our [MFA setup guide](/kb/microsoft-365/how-to-set-up-multi-factor-authentication-in-microsoft-365)) - Require a fresh MFA registration - Review and re-consent only necessary OAuth applications ### For the entire organization - **Enable Conditional Access policies in Entra ID** to require MFA for all users, block legacy authentication protocols, and restrict sign-ins from non-compliant devices. Conditional Access, included with Microsoft 365 Business Premium, is significantly more flexible than Security Defaults and should be the standard for any organization that has experienced a compromise. - **Disable legacy authentication** (IMAP, POP3, SMTP basic auth) tenant-wide. These protocols do not support MFA and are a common entry point for credential-based attacks. - **Deploy anti-phishing policies** in Microsoft Defender for Office 365 to detect impersonation attempts and block malicious attachments and links before they reach inboxes. - **Deploy Huntress across all endpoints and identities.** Huntress provides 24/7 SOC monitoring with human threat hunters, identity threat detection (ITDR), and SIEM. This ensures that if credentials are compromised again, the suspicious sign-in activity is caught and responded to by a human analyst before the attacker can act. - **Train employees** on recognizing phishing and BEC tactics. Huntress also provides security awareness training with phishing simulations to measure and improve your team's ability to spot these attacks. - **Implement email authentication** (SPF, DKIM, DMARC) to prevent domain spoofing ## Timeline summary | Time Frame | Action | |------------|--------| | First 15 minutes | Reset password, revoke sessions, disable account if needed | | First hour | Check inbox rules, forwarding, OAuth consents, MFA methods | | First 4 hours | Review sign-in and audit logs, assess data exposure | | First 24 hours | Notify internal stakeholders, affected clients, and vendors | | First 48 hours | Contact bank for wire recalls, file IC3 report if needed | | First week | Harden environment, enable MFA, deploy anti-phishing policies | | Ongoing | Employee training, regular access reviews, phishing simulations | ## When to call for help If your organization does not have in-house security expertise, do not try to handle a BEC incident alone. The financial and legal risks are significant. Athencia provides incident response support for business email compromise. We handle containment, investigation, remediation, and hardening so you can focus on running your business. [Reach out to us](/contact) if you need assistance. #### What Your Cyber Insurance Policy Expects from Your IT Security > Guide to the most common IT security requirements in cyber insurance policies and how small businesses can meet them to avoid denied claims. URL: https://athencia.com/kb/cybersecurity/what-your-cyber-insurance-policy-expects-from-your-it-security Cyber insurance policies increasingly require specific IT security controls as a condition of coverage. If you experience a breach and cannot demonstrate that these controls were in place, your claim may be denied. Understanding and meeting these requirements protects both your coverage and your business. ## Why cyber insurance requirements have gotten stricter Ransomware payouts skyrocketed between 2020 and 2024, costing insurers billions and forcing them to tighten underwriting standards dramatically. Many policies now include detailed security questionnaires during the application and renewal process, asking specific questions about MFA, endpoint protection, backup practices, and employee training. Insurers are also actively denying claims when businesses misrepresented their security posture on the application. If you said MFA was enabled on all accounts but it was only enabled on two out of twenty, that discrepancy can void your coverage when you need it most. The good news is that meeting these requirements is not just about keeping your insurer happy. Every control on this list genuinely reduces your risk of a breach. The insurers require them because they work. ## Requirement 1: Multi-factor authentication (MFA) Nearly every cyber insurance policy now requires MFA, and it is the single most common reason for claim denials. The insurer asks "Is MFA enabled on all email accounts and remote access?" on the application, the business checks "yes," and then a breach investigation reveals that MFA was only enabled on some accounts, or was configured but not actually enforced. Where MFA must be enabled: - **Email** (Microsoft 365 or Google Workspace) for all users, not just admins - **VPN and remote access** connections - **Admin accounts** for all systems, including firewalls, servers, and cloud platforms - **Cloud applications** that store sensitive data (accounting, payroll, CRM) Authenticator apps or hardware security keys are preferred. Some policies explicitly state that SMS-based MFA does not satisfy the requirement because it is vulnerable to SIM swapping attacks. The most reliable way to enforce MFA across your organization is through Conditional Access policies in Entra ID, included with Microsoft 365 Business Premium. Conditional Access lets you create rules that require MFA for every sign-in, or for specific conditions like sign-ins from outside your office network or from non-compliant devices. This is enforcement at the platform level, meaning individual users cannot bypass it. ## Requirement 2: Endpoint detection and response (EDR) Traditional antivirus is no longer sufficient for most cyber insurance policies. Insurers now expect some form of EDR or next-generation endpoint protection that actively monitors for threats rather than just scanning for known malware signatures. The specific language varies by insurer. Some policies say "EDR," others say "next-generation antivirus" or "managed detection and response." Read the exact language in your policy and make sure your solution meets the stated requirement. Athencia deploys Microsoft Defender for Business as the endpoint protection foundation on every managed device, then layers Huntress on top to provide a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. This combination satisfies the EDR requirement and the managed detection and response (MDR) requirement that many policies now include. Defender handles real-time protection; Huntress provides the human monitoring, SIEM, and incident response that insurers want to see. Other EDR options in the SMB space include SentinelOne and CrowdStrike. If your policy requires MDR or 24/7 monitoring, make sure you can demonstrate that capability. Having EDR software installed but nobody watching the alerts is a gap that insurers will identify. ## Requirement 3: Regular data backups Policies typically require regular backups with offsite or cloud copies. The bar has been raised beyond simply running a backup job. Insurers now want to see: - **Regular backup frequency.** Daily for most data, more frequently for critical systems like databases and financial records. - **Offsite or cloud storage.** At least one copy of your backup must be stored outside your primary environment. If ransomware encrypts your local server, your backup needs to be somewhere it cannot reach. - **Immutable or air-gapped backups.** Increasingly, policies require that at least one backup copy cannot be modified or deleted, even by an administrator. This prevents ransomware from encrypting your backups along with your production data. - **Documented backup testing.** It is not enough to say backups are running. You need to demonstrate that you have tested restoration and that the data is recoverable. Keep logs of backup test results, including the date, what was restored, and whether it was successful. Dropsuite provides cloud backup for Microsoft 365 email, OneDrive, and SharePoint. This gives you an independent, cloud-based copy of your Microsoft 365 data that lives outside your tenant. If your environment is compromised, Dropsuite lets you restore clean copies of email, files, and sites. Having a third-party backup solution like Dropsuite also demonstrates to your insurer that your backups are genuinely independent from your production environment. ## Requirement 4: Patch management Unpatched systems are one of the most commonly exploited entry points for attackers, and insurers know it. Most policies require a documented patch management process, and many specify a timeframe for applying critical patches, typically within 14 to 30 days of release. This requirement applies to everything: operating systems, applications (browsers, Adobe, Java), network devices (routers, firewalls, VPN appliances), and firmware. End-of-life software that no longer receives security patches is a red flag for insurers and may be grounds for increased premiums or denied coverage. If your business uses Microsoft 365 Business Premium, Microsoft Intune can enforce Windows update policies across all enrolled devices, ensuring patches install automatically on both office and remote computers. For third-party application patching, your MSP or IT provider can implement tools that automate updates for common business software. A documented patch management process does not need to be complicated. A simple written procedure that states "critical patches are applied within 14 days; all other patches within 30 days; end-of-life software is replaced before support ends" gives you a defensible position. ## Requirement 5: Employee security awareness training Most cyber insurance policies require documented security awareness training for all employees. Phishing remains the most common entry point for attacks, and insurers expect you to be actively training your team to recognize and report it. Training should cover: - **Phishing recognition** (email, SMS, and voice phishing) - **Password hygiene** and the use of password managers - **Social engineering tactics** including business email compromise - **Data handling** and what constitutes sensitive information Frequency matters. Annual training is the minimum most policies require, but quarterly training demonstrates a stronger commitment to security. Many policies also expect simulated phishing tests, where fake phishing emails are sent to employees to measure who clicks and who reports. Huntress provides security awareness training (SAT) as part of its platform, combining phishing simulations with targeted training modules. Employees who click on simulated phishing links receive immediate, relevant training. This approach measures actual behavior, not just attendance at a training session, which is exactly what insurers want to see. Keep records of who completed training and when. During a claim, you may be asked to produce training completion reports for all employees. ## Requirement 6: Access controls and privileged account management Insurers expect you to follow the principle of least privilege: users should only have access to the systems and data they need for their job, nothing more. Specific expectations include: - **Separate admin accounts.** Administrators should have a separate account for admin tasks, distinct from their daily email and productivity account. If their daily account is phished, the attacker does not gain admin access. - **Prompt offboarding.** When an employee leaves, their access must be revoked promptly. Document your offboarding process and show that it includes disabling accounts, revoking MFA, and removing access to shared resources. - **Password policies that meet minimum standards.** Minimum length requirements (12+ characters), no password reuse, and the use of a password manager. Athencia recommends 1Password for small businesses because of its balance of security and usability. - **Regular access reviews.** Periodically review who has access to what and remove unnecessary permissions. This does not need to be a formal audit; a quarterly check by your IT provider is sufficient. Entra ID and Conditional Access make it straightforward to enforce these controls across your Microsoft 365 environment. Conditional Access can require compliant devices, block risky sign-ins, and enforce MFA on all admin accounts automatically. ## Other common requirements Beyond the six core requirements above, your policy may also expect: - **Incident response plan.** A documented plan for what to do during a breach. Even a simple one-page plan that covers who to call, how to contain the threat, and how to notify stakeholders satisfies most policies. - **Email security.** SPF, DKIM, and DMARC configured on your domain to prevent spoofing. Microsoft Defender for Office 365, included with Business Premium, provides additional email security through Safe Attachments, Safe Links, and anti-phishing policies. - **Full-disk encryption.** BitLocker on Windows laptops, FileVault on Macs. Both are included with the operating system and can be enforced through Intune. - **Network segmentation.** Guest Wi-Fi separated from your business network. Critical systems isolated from general user traffic. - **Vulnerability scanning.** Regular scanning of internet-facing systems for known vulnerabilities. Your MSP should be doing this as part of their management service. ## How to prepare for your cyber insurance application or renewal Do not wait until the application lands on your desk. Prepare in advance so you can answer every question honestly and completely. 1. **Get a copy of the insurer's security questionnaire** before renewal. Your broker can usually provide this in advance. 2. **Audit your current security posture** against each requirement. Be honest. Misrepresentation can void your coverage entirely. 3. **Fix gaps before submitting the application.** If MFA is not enabled everywhere, enable it now. If backups are not tested, test them. Fixing the gaps before you apply is always better than hoping the insurer does not ask. 4. **Document everything.** Policies, training records, backup test results, patch reports, access reviews. Create a simple folder (physical or digital) where all compliance evidence lives. 5. **Work with your MSP or IT provider** to compile evidence of compliance. An [Athencia One](/athencia-one) managed IT plan includes the security controls that most cyber insurance policies require, and we can help you document them for your insurer. Athencia also provides CIS Controls baseline assessments that map your current security posture against the CIS Controls framework, giving you a clear picture of where you stand and what needs to improve. ## Need help? Cyber insurance requirements can feel overwhelming, but most of them boil down to the same security fundamentals: MFA, endpoint protection, backups, patching, and training. If you need help meeting your policy requirements or preparing for a renewal, [contact Athencia](/contact). We work with small businesses to close security gaps and document compliance so your coverage holds up when you need it. ### General IT #### How to Build an IT Budget for a Small Business > Practical guide to creating an IT budget for a small business, covering hardware, software, security, support, and common budgeting mistakes. URL: https://athencia.com/kb/general-it/how-to-build-an-it-budget-for-a-small-business An IT budget prevents the cycle of emergency spending and deferred maintenance that plagues most small businesses. Without one, you spend money when something breaks rather than when it makes strategic sense. Planning ahead for hardware replacements, software renewals, security tools, and support costs means fewer surprises and better decisions about where your IT dollars go. This guide walks through each spending category, gives you real numbers to work with, and shows you how to put it all together. ## Why small businesses need an IT budget Most small business owners treat IT spending as a series of one-off expenses. A laptop dies, so you buy a new one. A software renewal comes in, so you pay it. A security incident happens, so you scramble to add protections after the fact. This reactive approach almost always costs more than planning ahead. An IT budget forces you to take stock of what you have, what you're spending, and what's coming due in the next 12 months. It turns unpredictable expenses into a manageable monthly or annual plan. It also gives you the data you need to evaluate whether your current IT spending is reasonable. If you're paying $200 per user per month for managed IT but not getting security monitoring or strategic guidance, your budget will make that gap obvious. Budgets also matter when you apply for cyber insurance. Underwriters want to see that you're investing in security, not just hoping for the best. A documented IT budget that includes line items for endpoint protection, backup, and security training shows that you take risk seriously. ## Industry benchmarks: How much should you spend A common guideline is 3 to 7 percent of revenue for total IT costs. Businesses with simple IT needs, such as email and basic cloud apps with no compliance requirements, tend to fall at the lower end around 3 to 4 percent. Businesses with compliance obligations, heavy cloud usage, or complex technology environments typically land in the 5 to 7 percent range. Another way to benchmark is per employee. Total IT costs (hardware, software, support, and security combined) typically run $3,000 to $7,000 per employee per year. A 20-person company should expect to spend somewhere between $60,000 and $140,000 annually on IT, depending on the complexity of its environment and the level of security required. These are benchmarks, not rules. Your actual budget depends on your specific needs, your industry, and your risk tolerance. A law firm handling sensitive client data needs to spend more on security than a landscaping company with five employees. ## Category 1: Hardware Hardware is the most visible IT expense and the one most likely to catch you off guard if you don't plan for it. **Computers.** Plan for laptop replacement every 4 years and desktop replacement every 5 years. Budget $800 to $1,200 per laptop and $600 to $1,000 per desktop. A 20-person office with 4-year laptop cycles replaces about 5 machines per year, which means setting aside $4,000 to $6,000 annually just for computer replacements. **Networking equipment.** Routers, switches, and wireless access points typically last 5 to 7 years. Budget $500 to $2,000 depending on office size. If your wireless network struggles with video calls or drops connections, this line item deserves attention sooner rather than later. **Peripherals.** Monitors, keyboards, mice, headsets, and docking stations wear out or need replacing when new employees join. Budget $200 to $500 per employee per year for replacements and new hires. **Printers.** Replace every 5 to 7 years. Budget for the printer itself plus ongoing toner and ink costs, which can add up to several hundred dollars per year for a busy office printer. **Spare equipment.** Keep one or two configured spare laptops ready for emergency swaps. If someone's laptop fails on a Monday morning, having a spare means they're back to work in minutes instead of days. Budget for these separately from your replacement cycle. ## Category 2: Software and licensing Software costs are recurring, which makes them easier to budget for once you know what you're paying. **Microsoft 365.** Athencia deploys Microsoft 365 Business Premium for its managed IT clients, which runs $22 per user per month. This license tier includes everything most small businesses need: Outlook, Teams, Word, Excel, plus Intune for device management, Defender for Business for endpoint security, and Entra ID with Conditional Access for identity protection. If you're currently on a lower-tier plan like Business Basic ($6 per user per month) or Business Standard ($12.50 per user per month), you may be paying separately for security tools that Business Premium already includes. **Line-of-business applications.** CRM, accounting, practice management, and project management tools vary widely. List every tool your team uses, what it costs per user or per month, and when the renewal date is. Tracking renewal dates in one place prevents surprise charges and gives you a chance to evaluate whether you still need each tool. **Security software.** Endpoint protection, email security, and a password manager typically add $5 to $15 per user per month on top of your Microsoft 365 license. Tools like Huntress Managed EDR (which layers 24/7 human threat hunting on top of Microsoft Defender) and 1Password for credential management are common additions for businesses that take security seriously. **Backup services.** Microsoft 365 does not fully back up your email, OneDrive, or SharePoint data. A dedicated backup solution like Dropsuite runs $2 to $5 per user per month and protects you against accidental deletion, ransomware, and data loss. **Domain and website.** Hosting, domain renewal, and SSL certificates typically run $500 to $2,000 per year. ## Category 3: Managed IT services and support This is where your budget either becomes predictable or stays chaotic. **Managed services (MSP).** A managed IT provider charges a fixed monthly fee per user that covers monitoring, patching, security management, help desk support, and strategic guidance. For context, [Athencia One](/athencia-one) runs $45 to $55 per user per month for IT visibility and baseline security, while [Athencia One Complete](/athencia-one-complete) runs $159 to $199 per user per month for fully managed IT including advanced security, a password manager, and Microsoft 365 licensing. Most MSPs in the market charge between $100 and $250 per user per month for fully managed services. **Break-fix support (if you don't use an MSP).** On-demand IT support typically runs $150 to $250 per hour, and the total is unpredictable. You pay more when things go wrong, which is exactly when you can least afford it. A single server outage that takes 8 hours to resolve can cost $1,200 to $2,000 in labor alone, not counting the productivity your team lost. **Project work.** Migrations, new office setup, and major infrastructure upgrades are one-time costs that should be budgeted separately from your recurring monthly spend. Get scoping estimates for any projects you anticipate in the next 12 months. ## Category 4: Security and compliance Security is not optional, and it has real, recurring costs. **Cyber insurance.** Premiums range from $1,000 to $5,000 or more per year, depending on your coverage limits and industry. Many insurers now require specific security controls (MFA, endpoint protection, backup, security training) as conditions of coverage. Your IT budget should reflect the cost of meeting those requirements. **Security awareness training.** Training your employees to recognize phishing and social engineering attacks costs $2 to $5 per user per month. Some providers, like Huntress, bundle security awareness training with their endpoint detection and response platform. **Compliance audits or assessments.** If your industry requires compliance with HIPAA, PCI, or similar frameworks, budget $2,000 to $10,000 per year for formal assessments. Even if you're not in a regulated industry, a baseline security assessment against the CIS Controls framework identifies your biggest gaps and helps you prioritize spending. **Penetration testing or vulnerability scanning.** Formal penetration testing for a small business typically costs $2,000 to $5,000 annually. This is often a cyber insurance requirement. ## Category 5: Internet and communications **Business internet.** Budget $100 to $300 per month depending on speed and provider. If your team relies heavily on video conferencing and cloud applications, investing in faster, more reliable internet pays for itself in productivity. **Phone system (VoIP).** A cloud phone system runs $20 to $40 per user per month. If you're on Microsoft 365, Teams Phone can replace a standalone phone system, consolidating one more cost into a platform you already pay for. **Backup internet connection.** If your business can't function without internet, a secondary connection from a different provider ($50 to $150 per month) provides failover when your primary connection goes down. ## Building the budget: Practical steps Start by taking a complete inventory of your current IT spending. Pull credit card statements, invoices, and subscription records for the past 12 months. Sort everything into the categories above. Most business owners are surprised by how much they're actually spending once it's all in one place. Next, list known upcoming costs for the next 12 months. Which computers are due for replacement? Which software renewals are coming up? Are there any planned projects like an office move or a system migration? Add up your recurring monthly costs: MSP fees, software licenses, internet, phone, and security tools. Multiply by 12 to get your annual recurring baseline. Finally, add a contingency fund. Set aside 10 to 15 percent of your total IT budget for unexpected needs. A failed switch, a sudden new hire, or a security incident that requires an unplanned investment will happen. The contingency fund keeps these events from blowing up your budget. Review the budget quarterly, not just annually. Technology needs change, prices shift, and new tools come on the market. A quarterly review keeps your budget aligned with reality and gives you a chance to reallocate funds before they're spent. ## Common budgeting mistakes **Not budgeting for hardware replacement.** Computers don't last forever. If your budget doesn't account for a regular replacement cycle, you'll end up scrambling when machines start failing. **Ignoring security costs until forced.** Many business owners don't think about security spending until a cyber insurance application or a compliance audit forces the conversation. By then, you're behind and spending reactively. **Not accounting for growth.** Every new hire needs a computer, a Microsoft 365 license, access to your business applications, and onboarding time from your IT provider. If you're planning to hire 5 people this year, your IT budget needs to reflect that. **Cutting IT to save money short-term.** Deferring hardware replacements, dropping security tools, or canceling your MSP to save money creates a debt that comes due with interest. Downtime, data loss, and security incidents are far more expensive than the monthly costs they prevent. **Not separating recurring costs from one-time projects.** Your monthly IT spend and your project spend are different animals. Mixing them together makes it impossible to track whether your baseline costs are growing and whether your project investments are delivering value. ## Need help? Building an IT budget from scratch takes time, but it pays for itself in predictability and smarter spending. If you want help assessing your current IT costs or building a budget that fits your business, [reach out to Athencia](/contact). We'll walk through it with you. #### How to Choose a Managed IT Provider for Your Small Business > Practical guide for small business owners evaluating managed IT providers (MSPs), covering what to look for, questions to ask, and red flags to avoid. URL: https://athencia.com/kb/general-it/how-to-choose-a-managed-it-provider-for-your-small-business Choosing the right managed IT provider (MSP) is one of the most important infrastructure decisions a small business makes. A good MSP keeps your systems running, your data secure, and your team productive. A bad one creates more problems than it solves. This guide covers when you actually need an MSP, what a good one should provide, the right questions to ask during evaluation, and the red flags that should send you looking elsewhere. ## When does a small business need an MSP Not every business needs managed IT services, but most reach a point where going without one becomes a liability. Here are the common signals. You have 5 or more employees using computers and email daily, and IT issues are eating into time you should be spending on revenue-generating work. You don't have a full-time IT person on staff, and you don't need one yet, but you need consistent, reliable support when something breaks or a new employee starts. You have compliance requirements. If your industry requires HIPAA, PCI, or cyber insurance compliance, you need documented security controls, regular assessments, and someone who can prove your IT environment meets the standard. A friend who "knows computers" cannot provide that. You've experienced a security incident or data loss and want to make sure it doesn't happen again. Or your current IT support, whether it's a part-time contractor, a nephew, or the office manager who happens to be tech-savvy, can't keep up with the growing demands of your business. If any of these sound familiar, it's time to evaluate MSPs seriously. ## What a good MSP should provide When you're evaluating providers, look for these core capabilities. Any MSP worth considering should include all of these in their base offering. **Proactive monitoring.** Your MSP should monitor all of your computers, servers, and network equipment 24/7 for problems before they cause downtime. This means automated alerts when a hard drive starts failing, when a computer stops checking in, or when a security policy isn't applied correctly. You should not be the one discovering problems. **Patch management.** Operating system and application updates need to happen regularly and reliably. A good MSP automates this process so your machines stay current with security patches without disrupting your workday. Ask how they handle patch deployment and what happens when a patch causes an issue. **Endpoint protection.** Every device in your environment needs managed antivirus and endpoint detection and response (EDR). The best MSPs layer additional protection on top of the baseline. For example, Huntress Managed EDR adds 24/7 human threat hunters and a security operations center on top of Microsoft Defender for Business, catching threats that automated tools miss. **Backup management.** Your MSP should configure, monitor, and regularly test your backups. This includes cloud data. Microsoft 365 has limited built-in retention, so a separate backup solution like Dropsuite for your email, OneDrive, and SharePoint data is important. If your business has on-premises servers or data, local backup with a tool like Slide should also be part of the conversation. **Help desk.** A responsive support team for day-to-day IT issues. Ask about average response times and get specific numbers: 15 minutes for critical issues, 1 hour for standard requests, same-day for low-priority items. Vague promises like "we respond quickly" tell you nothing. **Security management.** This goes beyond antivirus. Your MSP should enforce multi-factor authentication across all accounts, manage email security, configure access controls using tools like Conditional Access in Microsoft Entra ID, and provide security awareness training so your employees know how to spot phishing attempts. **Strategic guidance.** Your MSP should function as a technology advisor, not just a help desk. This means regular Technology Business Reviews where they assess your environment, identify risks, and recommend improvements prioritized by business impact. This strategic layer is often called a vCIO (virtual Chief Information Officer) function. **Vendor management.** A good MSP coordinates with your internet provider, phone system vendor, and software vendors on your behalf. When your internet goes down, you shouldn't be the one on hold with the ISP. ## Questions to ask during evaluation These questions separate serious providers from those who are just selling a contract. **How many clients do you support, and what's the typical company size?** You want an MSP experienced with businesses your size. An MSP that primarily manages 500-person enterprises may not be attentive to a 15-person company. **What is your average response time for support requests?** Get specific numbers. If they can't answer this, they aren't tracking it, which is a problem. **What does your onboarding process look like?** A good MSP audits your entire environment before taking over: network, devices, security posture, software, and licenses. They document everything and build a remediation plan before they start managing. An MSP that just installs their tools and calls it done is setting you up for surprises. **What security tools and practices are included in your base offering?** You want to hear specifics: endpoint protection, MFA enforcement, email security, backup, security awareness training, and access controls. If security is an "add-on," that tells you it's not a priority. **How do you handle after-hours and emergency support?** Know what happens when something critical breaks at 7 PM on a Friday. Is there an after-hours team, or does it wait until Monday? **What does your reporting look like?** You should receive regular reports on your IT health, including device status, security posture, open issues, and completed work. A dashboard like the [Athencia One Portal](/athencia-one) gives you real-time visibility into your environment rather than waiting for a monthly PDF. **Can you provide references from clients in my industry or of a similar size?** References are table stakes. If they can't provide them, that's a concern. **What happens if we want to leave?** Understand data portability, transition support, and contract terms before you sign. You should always own your Microsoft 365 tenant, your domain, and your admin credentials. The MSP should have delegated access, not ownership. **What is NOT included in your monthly fee?** This is where hidden costs live. Project work, after-hours support, hardware procurement, software licensing, and onboarding fees can add up quickly if they're not included. ## Pricing: What to expect Most MSPs charge per user per month. Some charge per device, but per-user pricing is more common and generally simpler to budget for. The typical range for fully managed IT services for a small business is $100 to $250 per user per month. What's included at each price point varies significantly. Look for providers who publish their pricing. Athencia, for example, charges $45 to $55 per user per month for Athencia One (IT visibility, monitoring, and baseline security) and $159 to $199 per user per month for [Athencia One Complete](/athencia-one-complete) (fully managed IT with advanced security, 1Password, and Microsoft 365 Business Premium licensing included). Transparent pricing lets you budget accurately and compare providers on equal terms. Watch out for hidden costs. Some providers quote a low per-user fee but charge extra for everything: project work, after-hours support, hardware markup, even software licensing that should be included. The cheapest option is rarely the best. You get what you pay for in managed IT, and the cost of a security incident or extended downtime dwarfs the monthly savings from choosing a bargain provider. ## Red flags to watch for **No onboarding process.** An MSP that doesn't audit your environment before starting can't protect what they don't understand. If they skip the assessment, they're guessing. **Reactive only, not proactive.** If they only fix things when they break, you're paying for a help desk, not managed services. Proactive monitoring, patching, and security management are what separate an MSP from a break-fix shop. **No documentation.** A good MSP documents your network, accounts, licenses, and configurations. If they don't, you're locked in. When you try to leave, you won't know what you have. **Long-term contracts with no exit clause.** Avoid 3 to 5 year contracts with steep early termination fees. A 1-year agreement with 30 to 60 day notice is reasonable. An MSP that needs a long contract to keep clients has a retention problem. **No security focus.** If they don't mention MFA, endpoint protection, backup, or security awareness training as part of their standard offering, they're behind. Security is not an add-on; it's foundational. **Slow response times.** If it takes hours to get a response during business hours while you're evaluating them, it won't get better after you sign. **They own your domain or admin accounts.** You should always own and control your domain registration, your Microsoft 365 tenant, and your admin credentials. The MSP should have delegated admin access. If they insist on owning your accounts, walk away. This creates a dependency that makes it extremely difficult and expensive to switch providers. ## What to expect during onboarding Once you've chosen an MSP, the onboarding process typically takes 2 to 4 weeks for a small business. Here's what a thorough onboarding looks like. First, the MSP conducts a full audit of your current IT environment: network layout, device inventory, security posture, software licensing, and user accounts. They document everything, including network diagrams, device serial numbers, account credentials stored in a secure password manager like 1Password, and a list of every tool and license you're paying for. Next, they install their monitoring and management agents on all devices. If your business uses Microsoft 365 Business Premium with Intune, device management policies, security configurations, and compliance baselines can be deployed across your entire fleet from a central console. They configure backup, security tools, and automated patching. They migrate you from your previous provider if applicable, and they introduce your team to the help desk and support process so everyone knows how to get help. Finally, they deliver a roadmap of recommended improvements prioritized by risk and impact. This is your first look at the strategic value your MSP should be providing on an ongoing basis. ## Need help? Choosing the right MSP is a big decision, and it's worth getting right the first time. If you're evaluating providers and want a straightforward conversation about what your business needs, [contact Athencia](/contact). No pressure, no pitch, just practical advice. #### How to Decide When to Replace vs. Repair an Office Computer > Practical framework for small businesses to decide whether to repair a struggling office computer or replace it, based on age, cost, and business impact. URL: https://athencia.com/kb/general-it/how-to-decide-when-to-replace-vs-repair-an-office-computer Every small business owner eventually faces the question: is it worth fixing this computer, or should we just buy a new one? The answer comes down to three factors: the age of the machine, the cost of the repair relative to a replacement, and how much the downtime and performance issues are costing your business in lost productivity. This guide gives you a clear framework for making that call so you stop guessing and start making decisions based on numbers. ## The age rule of thumb Age is the single most reliable indicator of whether a repair makes financial sense. Here's a straightforward breakdown. **0 to 3 years old.** A computer in this range is almost always worth repairing unless the damage is catastrophic, like liquid damage that shorted the motherboard or a severe drop that cracked the chassis and display at the same time. A screen replacement, a new battery, or a keyboard swap on a 2-year-old laptop is a smart investment. The machine has years of useful life left, and the repair cost is a fraction of a replacement. **3 to 4 years old.** This is the gray zone. Repair the machine if the cost is under 50 percent of what a comparable new computer would cost. A $300 repair on a 3-year-old laptop that would cost $1,000 to replace makes sense. A $600 repair on that same machine doesn't, because you're paying more than half the price of a brand-new computer and still walking away with aging hardware. **4 to 5 years old.** Strongly consider replacement, especially if the computer is already showing signs of slowing down: long boot times, laggy applications, frequent freezes. At this age, even a successful repair doesn't buy you much runway. You're likely to face another issue within 6 to 12 months. **5+ years old.** Replace it. The repair cost, the lost productivity during the repair, and the security risk of running aging hardware almost always exceed the cost of a new machine. Computers older than 5 years often can't run the latest operating system or security software, which creates real vulnerability in your environment. ## The cost comparison Before deciding, get an actual repair estimate. Don't guess. Then compare the repair cost to the price of a comparable new computer, not the original purchase price you paid years ago. A decent business laptop costs $800 to $1,200 today. A business desktop runs $600 to $1,000. These are the numbers you're comparing against. If the repair is more than 50 percent of the replacement cost on a machine over 3 years old, replace it. If the repair is under 50 percent on a machine under 3 years old, repair it. Don't forget to factor in the labor cost of the repair (your IT provider's time to diagnose, order parts, and complete the work) and the employee's downtime during the process. If a repair takes 3 days and the employee is working from a loaner or not working at all, that lost productivity has a real dollar value. A planned replacement with a pre-configured machine can have the employee back to full speed in under an hour. ## Hidden costs of keeping old computers The sticker price of a repair isn't the full picture. Old computers carry hidden costs that add up quietly. **Productivity loss.** A slow computer costs you employee time every single day. Even 15 minutes of daily waiting, for applications to load, for files to save, for the machine to wake from sleep, adds up to over 60 hours per year per employee. At a $30/hour fully loaded employee cost, that's $1,800 per year in wasted time from a single slow machine. **Security risk.** Computers that can't run the latest operating system or security software are vulnerable to attacks that modern systems handle automatically. Windows 10 reached end of support in October 2025, meaning machines stuck on it no longer receive security patches from Microsoft. If your endpoint protection requires a current OS to function properly, an outdated machine becomes a gap in your security perimeter. **Compatibility issues.** Older hardware may not support new software versions, current video conferencing requirements (Teams and Zoom are resource-hungry), or newer peripherals like USB-C docking stations. Your team ends up working around limitations instead of working productively. **Increasing failure rate.** Hardware failure rates climb significantly after year 4. The cost of an unplanned failure, including emergency replacement, potential data recovery, and extended employee downtime, is much higher than a planned replacement where the new machine is configured and ready before the old one is retired. **Support costs.** Older machines generate more help desk tickets. More crashes, more driver issues, more "it's running slow" calls. Each ticket costs your IT provider time and costs your employee productivity. ## Signs it's time to replace (regardless of age) Sometimes a computer tells you it's done before the calendar does. Replace the machine if any of the following are true. The computer takes more than 2 minutes to boot and be ready to work. Applications freeze or crash regularly during normal use. The computer can't run required software updates or the current operating system. The hard drive is failing, evidenced by clicking sounds, frequent errors, or painfully slow file access, and the machine still runs a spinning hard drive instead of an SSD. The laptop battery holds less than 2 hours of charge, and a battery replacement costs more than a third of the machine's current value. The computer can't handle current video conferencing requirements. If Teams or Zoom calls consistently cause the machine to lag, overheat, or drop audio, the hardware is not meeting the basic demands of modern work. The machine has needed multiple repairs in the past 12 months, which signals that failures are cascading and more are coming. ## When repair makes sense Repair is the right call in several specific situations. The computer is under 3 years old and the repair is straightforward. Screen replacements, battery swaps, and keyboard replacements on newer machines are cost-effective and give you years of additional use. Upgrading to an SSD can extend the useful life of a 2 to 4 year old machine significantly. If the computer has a traditional spinning hard drive, swapping it for an SSD is often the single best upgrade you can make. Boot times drop from minutes to seconds, applications open faster, and the machine feels new again, all for $100 to $200 in parts plus labor. Adding RAM is cheap and effective if the machine is currently under-provisioned. If a computer shipped with 8 GB of RAM and regularly hits 90 percent memory usage, adding another 8 GB can resolve slowness for under $100. The repair is covered under warranty or an extended service plan. If you're not paying for the repair, there's no reason not to take advantage of it. ## Planning for computer replacements The best way to avoid the repair-or-replace dilemma is to plan for replacements before they become urgent. Set a standard lifecycle: 4 years for laptops, 5 years for desktops. Track the purchase date and warranty expiration for every machine in your environment. A 20-person office with 4-year laptop cycles replaces about 5 machines per year, which is a predictable, budgetable expense. Stagger your replacements so you're not buying all new hardware in the same year. If you bought 20 laptops at once when you started the business, you'll face a painful $16,000 to $24,000 replacement bill in year 4 unless you start rotating a few machines each year before then. Keep one or two spare machines configured and ready for emergency swaps. If your business uses Microsoft 365 Business Premium with Intune and Autopilot, provisioning a spare is straightforward. Register the laptop's hardware ID with your Microsoft tenant, and when an employee powers it on and signs in with their credentials, all company policies, apps, and security settings deploy automatically. There's no need for an IT technician to manually configure each machine. This is how [Athencia provisions devices](/athencia-one) for its managed IT clients. ## What to do with old computers Once you've replaced a machine, don't just toss it in a closet or, worse, the trash. Wipe the hard drive securely before disposing of or donating the computer. A factory reset is not enough; it leaves recoverable data on the drive. Use DBAN or a similar tool for traditional hard drives, and use the manufacturer's secure erase utility for SSDs. If the machine was managed through Intune, you can initiate a remote wipe from the admin console before decommissioning it. Remove any asset tags and update your inventory records. Donate the machine to a local nonprofit if it still has useful life, or recycle it through a certified e-waste recycler. Never throw computers in the regular trash. It's both an environmental hazard and a data security risk. ## Need help? If you're trying to figure out whether to repair or replace a machine and want a professional opinion, [get in touch with Athencia](/contact). We'll assess the situation and give you a straight answer. #### How to Write an Acceptable Use Policy for Your Small Business > Template and guide for creating a simple, effective IT acceptable use policy that protects your business and sets clear expectations for employees. URL: https://athencia.com/kb/general-it/how-to-write-an-acceptable-use-policy-for-your-small-business An acceptable use policy (AUP) defines how employees can and cannot use company technology, including computers, email, internet access, and software. It sounds like a formality, but having a written policy protects your business legally, supports your cyber insurance, and sets clear expectations so employees know the rules before they break them. This guide walks you through what to include, how to write it in plain language, and how to make sure it actually gets followed. ## Why you need one The most common reason small businesses finally write an AUP is because a cyber insurance application asks for one. Underwriters want to see that you have documented IT policies. Not having one can mean higher premiums or, worse, a denied claim after an incident because you couldn't demonstrate that employees were trained on acceptable use. Beyond insurance, a written policy gives you a basis for addressing misuse of company technology. Without one, it's difficult to take action when someone installs unauthorized software, stores client data on a personal Dropbox account, or clicks a phishing link they should have recognized. You can't enforce rules that don't exist in writing. Compliance frameworks like HIPAA, PCI, and the CIS Controls all require documented acceptable use policies. Even if your industry isn't formally regulated, following these frameworks strengthens your security posture and demonstrates due diligence. A clear policy also prevents misunderstandings. When everyone knows the expectations, there are fewer awkward conversations and fewer gray areas. New hires read it during onboarding, sign an acknowledgment, and start day one with a clear understanding of what's expected. ## What to include ### Scope Start by defining who the policy applies to and what it covers. The policy should apply to all employees, contractors, interns, and anyone else who uses company technology. It should cover company-owned computers, phones, email accounts, internet access, software, cloud accounts, and network resources. If your business allows employees to use personal devices for work (a BYOD arrangement), the policy should explicitly address that. State what rules apply to personal devices when they're used to access company email, files, or applications. For example, personal devices used for work should have a screen lock enabled, be running a current operating system, and not store company data locally. ### Acceptable use State clearly that company technology is provided for business purposes. Reasonable personal use is fine, such as checking personal email during a break or browsing the web at lunch, as long as it does not interfere with work, violate any other part of the policy, or create security risks. Employees are responsible for the security of their accounts and devices. That means locking their computer when they step away (Windows key + L is the fastest way), not leaving their laptop unattended in a coffee shop, and reporting anything suspicious to IT immediately. Software should only be installed with IT approval. This prevents malware infections from sketchy downloads and avoids software licensing violations that could expose your business to legal liability. If your business manages devices through Microsoft Intune, you can enforce this technically by restricting which applications users can install, but the policy should state the rule in writing regardless. ### Prohibited use Be specific about what's not allowed. Employees should not use company systems for illegal activity, access or distribute inappropriate or discriminatory content, install unauthorized software or browser extensions, or share passwords with anyone, including coworkers. Connecting unauthorized personal devices to the business network is prohibited. This includes personal laptops, USB drives, and IoT devices. Each unauthorized device is a potential entry point for malware or data exfiltration. Storing company data on personal cloud accounts (personal Google Drive, Dropbox, iCloud) is not allowed. Company data belongs on company-approved systems like OneDrive, SharePoint, or your line-of-business applications. This isn't about being controlling; it's about knowing where your data lives so you can protect it and recover it if something goes wrong. Employees should not circumvent security controls. That means no disabling antivirus, no using unauthorized VPN services, and no attempting to bypass Conditional Access policies or web filtering. These controls exist to protect the entire organization, and one person bypassing them creates risk for everyone. Using company email for personal business ventures or side projects is prohibited. ### Email and communication Business email is for business communication. State this plainly and then address the practical details. Employees should not open suspicious attachments or click links in emails they weren't expecting. Security awareness training, which tools like Huntress include alongside their managed EDR platform, teaches employees to recognize phishing attempts, but the policy should still state the expectation clearly. Confidential information should not be sent via personal email accounts. If a client sends sensitive information, it stays in the company email system. Company email may be monitored for security purposes. State this directly so there are no surprises. Email signatures should follow the company standard template. ### Internet use Internet access is provided for business purposes, and reasonable personal use is acceptable. Keep this section practical rather than heavy-handed. Employees should not access illegal, inappropriate, or high-risk websites on company devices. They should not download files from untrusted sources. Streaming services like Netflix or Spotify are fine during breaks, but they should not be used in a way that degrades network performance for others, particularly during business hours when video calls and cloud applications need bandwidth. ### Data and confidentiality Company data must be stored on company-approved systems. For most businesses using Microsoft 365, that means OneDrive for personal work files and SharePoint for shared team files. Be specific about where data should and should not live. Employees should not transfer company data to personal devices or accounts. Confidential client information must be handled according to applicable regulations. If your business handles protected health information, financial data, or legal records, reference the specific requirements here or point to a separate data handling policy. Require employees to report any suspected data breach or loss immediately. The faster you know about a potential incident, the faster you can contain it. ### Security responsibilities This section covers the day-to-day security habits you expect from every employee. Lock your computer when stepping away from your desk. Use the company password manager, such as 1Password, for all business accounts. Never reuse passwords across accounts, and never store passwords in a browser, a spreadsheet, or a sticky note. 1Password generates strong, unique passwords for every account and stores them securely, so employees don't need to memorize anything. Enable multi-factor authentication on all accounts that support it. Report suspicious emails, messages, or activity to IT immediately. Do not share credentials with anyone for any reason, including coworkers and managers. Complete security awareness training as assigned. ### Consequences of policy violation State clearly that violations may result in disciplinary action, up to and including termination. Severe violations, such as data theft or illegal activity, may result in legal action. The company reserves the right to monitor and audit the use of company technology. Keep this section straightforward and factual. The goal is not to threaten employees but to make clear that the policy has teeth and that compliance is not optional. ## Keeping the policy effective A 20-page policy that nobody reads is worse than useless. It creates a false sense of security while providing no actual protection. Keep your AUP to 2 to 4 pages maximum. Write in plain language, not legalese. If an employee needs a lawyer to understand the policy, it's too complicated. Use short sentences, clear prohibitions, and concrete examples. Have every employee sign an acknowledgment during onboarding. Store the signed acknowledgments in your HR files. This is the proof that the employee read and understood the policy, and it's the documentation your cyber insurer will want to see if you ever file a claim. Review and update the policy annually, or whenever major changes occur. New remote work arrangements, new compliance requirements, a shift from in-office to hybrid work, these all warrant a policy update. When you update it, have employees re-sign the acknowledgment. Make the policy accessible. Store it somewhere employees can find it without asking, such as a SharePoint site or the company handbook. If people can't find the policy, they can't follow it. ## Need help? Writing an acceptable use policy doesn't have to be complicated, but it does need to be done right. If you want help drafting or reviewing your AUP, [contact Athencia](/contact). We help small businesses put practical IT policies in place. #### IT Offboarding Checklist: How to Securely Remove Access When Someone Leaves > Step-by-step IT offboarding checklist for small businesses to revoke access, preserve data, and recover devices when an employee departs. URL: https://athencia.com/kb/general-it/it-offboarding-checklist-how-to-securely-remove-access-when-someone-leaves When an employee leaves your business, whether they resign or are terminated, every account they had access to becomes a security risk until it's locked down. IT offboarding is the process of revoking all access, preserving important data, and recovering company devices. Doing this quickly and completely prevents ex-employees from accessing company systems and ensures no business data walks out the door. This guide gives you a step-by-step process to follow every time someone departs. ## Timing is critical The single most important factor in offboarding is speed. Every hour a departed employee has active credentials is an hour your business is exposed. For voluntary departures (resignations), complete most steps on the employee's last day. You typically have advance notice, so use it. Coordinate with HR to confirm the departure date and plan the IT steps ahead of time. Have everything ready so that when the employee walks out, their access is revoked within minutes. For involuntary departures (terminations), complete access revocation immediately, ideally before or during the termination meeting. This is not optional. A terminated employee who still has active credentials and remote access to your systems is a significant risk. If your business uses Microsoft 365 Business Premium with Entra ID, you can block sign-in and revoke all active sessions from the admin console in under two minutes. Have IT standing by during any termination meeting so access can be cut the moment the conversation ends. Coordination between HR and IT is essential. IT should never learn about a departure after the fact. Build a process where HR notifies IT as soon as a departure is confirmed, with the expected last day and whether it's voluntary or involuntary. ## Immediate actions (day of departure) ### Revoke sign-in access Start with the employee's Microsoft 365 account, which is usually the gateway to email, files, Teams, and most cloud applications. Reset the employee's Microsoft 365 password to a long, random value. Then block sign-in on the account in the Microsoft 365 admin center (Admin > Users > Active users > Select user > Block sign-in). This prevents the former employee from authenticating even if they know the old password. Revoke all active sessions. This is a step many businesses miss. Blocking sign-in prevents new logins, but it doesn't terminate sessions that are already active on the employee's phone, home computer, or tablet. In Entra ID, navigate to the user's account and select "Revoke sessions" to force sign-out on every device immediately. Disable or reset credentials for VPN access, remote desktop, and any other systems that have their own authentication separate from Microsoft 365. ### Disable accounts in business applications Go through every application the employee used and disable or deactivate their account. This includes your CRM, accounting software, project management tools, practice management system, and any other line-of-business application. Revoke access to third-party cloud services: Slack, Zoom, Dropbox, Canva, and anything else the employee signed up for or was given access to. Check your records or ask the employee's manager for a complete list. Remove the employee from all shared vaults in your password manager. If your business uses 1Password, go to the admin console and remove the user from every vault they had access to. This is critically important. Shared vaults often contain credentials for systems, vendor portals, and social media accounts that the former employee should no longer be able to reach. If any passwords in those shared vaults were known to the departing employee, rotate them. Check for OAuth app consents in Entra ID and revoke them. Employees sometimes grant third-party apps access to their Microsoft 365 account (for example, a scheduling tool that reads their calendar). These consents persist even after the password is changed, so they need to be explicitly revoked. ## Data preservation (same day or within 48 hours) ### Email Convert the employee's mailbox to a shared mailbox in the Microsoft 365 admin center. This preserves all email without consuming a paid license. Once converted, grant access to the shared mailbox to the employee's manager or their replacement so they can review and respond to messages. If the manager needs to receive new messages sent to the former employee's address, set up email forwarding on the shared mailbox. This is common when a salesperson or account manager leaves and clients continue emailing their old address. Set an auto-reply on the mailbox informing senders that the employee is no longer with the company and providing the new point of contact. Keep this professional and brief. ### Files and documents Transfer the employee's OneDrive files to their manager or replacement. In the Microsoft 365 admin center, go to Users, select the departing user, and use the OneDrive tab to grant a delegate access. The delegate has 30 days to access and move files before OneDrive is automatically deleted, so don't wait. Before wiping the employee's computer, check for files stored locally that may not have synced to OneDrive. Desktop files, Downloads folder contents, and documents saved outside the OneDrive sync folder are easy to lose if you wipe the machine first. Transfer ownership of any shared folders, SharePoint sites, or Teams channels the employee owned. If they were the sole owner of a Teams channel, that channel becomes unmanageable until a new owner is assigned. ### Other data Transfer ownership of CRM records, deals, and client relationships. Open tickets and tasks should be reassigned to another team member. Export or transfer any data from tools the employee used that won't transfer automatically when their account is disabled. ## Group memberships and permissions Remove the employee from all Microsoft 365 groups, Teams channels, and distribution lists. Remove their permissions from SharePoint sites they had access to. If they had access to other shared mailboxes (like info@ or support@), remove that access as well. Transfer ownership of any Microsoft 365 groups or Teams the employee created or owned. If they were the only owner, assign a new owner before disabling the account. Don't forget physical access. Remove the employee from building access systems, change alarm codes they knew, and collect keys or security badges. Physical security is just as important as digital security. ## Device recovery Collect the laptop, phone, monitor, headset, docking station, and any other company hardware. Collect access cards, keys, and security tokens. Have a checklist of what was issued to the employee so you can confirm everything is returned. If the device can't be collected immediately, for example if the employee is remote and needs to ship the equipment back, initiate a remote wipe through Intune. This erases all company data and policies from the device regardless of where it is physically. For [Athencia's managed IT clients](/athencia-one), this is a standard part of the offboarding process and can be triggered within minutes. Once the device is returned or wiped, remove it from Entra ID and Intune. Reset it to factory settings so it's ready to be reissued to the next employee. Update your asset inventory to reflect the device's current status. ## Post-departure verification Trust but verify. After completing all of the steps above, test the results. Try to sign in to Microsoft 365 with the former employee's credentials. The login should fail. Verify that access to business applications is disabled by checking each one. Confirm that email forwarding or the shared mailbox is working correctly by sending a test message to the old address. Verify that OneDrive files were transferred successfully and that no critical data was lost. Check audit logs in Microsoft 365 and Entra ID for any suspicious activity in the days leading up to the departure. Look for large file downloads, forwarding rules set up on the mailbox, or data exports from business applications. This is particularly important for involuntary departures, but it's good practice for all offboarding. Remove the employee from your IT documentation, phone lists, emergency contacts, and any internal directories. ## Delete the account (after data is secured) Once you've confirmed that all data is preserved and all access is revoked, delete the Microsoft 365 user account. This frees up the license for reassignment. Microsoft retains the deleted account for 30 days, so if you realize you missed something, you can restore it during that window. After 30 days, the deletion is permanent. ## Offboarding checklist summary Use this as a quick reference each time an employee departs. - Password reset and sign-in blocked on Microsoft 365 - All active sessions revoked in Entra ID - Business application accounts disabled - Password manager access removed and shared passwords rotated - Mailbox converted to shared mailbox with forwarding set up - OneDrive files transferred to manager or replacement - Group memberships and ownership transferred - Devices collected and wiped (remotely via Intune if needed) - Physical access revoked (keys, badges, alarm codes) - Post-departure access verified as fully revoked - Audit logs reviewed for suspicious pre-departure activity - Account deleted and license reclaimed ## Need help? Offboarding done poorly creates security gaps that can haunt your business for months. If you want help building a repeatable offboarding process or need to offboard someone quickly, [contact Athencia](/contact). We'll make sure nothing gets missed. #### IT Onboarding Checklist: Everything to Prepare Before a New Employee Starts > Complete IT onboarding checklist for small businesses covering accounts, devices, access, and training to have ready before a new hire's first day. URL: https://athencia.com/kb/general-it/it-onboarding-checklist-everything-to-prepare-before-a-new-employee-starts A complete IT onboarding process ensures new employees have everything they need on day one: a working device, active accounts, proper access to the tools they'll use, and clear instructions for getting help. Scrambling to set things up after they arrive wastes their time, frustrates their manager, and makes your business look disorganized. This guide walks through every step, from two weeks before the start date through the day-one handoff, so nothing falls through the cracks. ## When to start: Timeline IT onboarding doesn't begin on the new hire's first day. It starts the moment HR confirms the hire. **1 to 2 weeks before the start date.** Order hardware if you don't have a spare available. Create the employee's Microsoft 365 account and email address. Request access to business applications. If you're working with a managed IT provider, notify them of the incoming hire with the employee's name, role, start date, and the applications they'll need. **2 to 3 days before.** Configure the device. Install software. Test everything. Verify that email works, that the employee can access the files and applications they need, and that printers and peripherals function correctly. This testing step is the difference between a smooth first day and an embarrassing one. **Day before.** Final verification. Confirm credentials are ready. Prepare any welcome materials or documentation the employee will receive. Set temporary passwords that will require a change on first login. **Day of.** Hand off the device. Walk through key systems. Introduce the IT support contact. Verify everything works in the employee's hands, not just on the IT bench. ## Hardware and devices Start with the physical equipment the employee will use every day. Order or allocate a laptop or desktop that meets the requirements for the role. Standard office work (email, documents, web browsing, video calls) requires a machine with at least 16 GB of RAM, an SSD, and a current-generation processor. Roles involving design, data analysis, or video editing may need higher specs. Confirm with the hiring manager before ordering. Order a monitor, keyboard, mouse, and headset if the employee will work from an office. For remote employees, decide whether you're providing these items or offering a stipend. Consistency matters here; every employee should have the equipment they need to do their job without making do. If the role requires a desk phone, order it and coordinate with your phone system provider to assign an extension or number. For businesses using Microsoft Teams Phone, this is configured in the Teams admin center and doesn't require separate hardware unless the employee prefers a physical handset. Asset tag every piece of equipment and record serial numbers in your inventory. This takes five minutes per device and saves hours of confusion when it's time to track down equipment during offboarding. ## Accounts and licenses Create the employee's Microsoft 365 account with the appropriate license. If your business runs Microsoft 365 Business Premium (which includes Intune, Defender for Business, and Entra ID with Conditional Access), assign that license so the employee gets the full security stack from day one. Set up their email address following your company's naming convention, typically firstname.lastname@company.com. Create accounts in every business application the employee will use: CRM, accounting software, project management tools, practice management system, and anything else relevant to their role. Don't wait until they ask; have these ready before they arrive. Set up a 1Password account for the employee and add them to the appropriate shared vaults. Shared vaults give new hires immediate access to the credentials they need, such as shared service logins and vendor portals, without anyone having to send passwords over email or chat. If your business uses [Athencia One Complete](/athencia-one-complete), 1Password is included in your per-user fee. Create VPN credentials if the employee needs remote access to on-premises resources. Set temporary passwords for all accounts that require the employee to change their password on first login. Never email passwords in plain text. Use your password manager's secure sharing feature or provide them verbally during the day-one walkthrough. ## Access and permissions Add the employee to the correct Microsoft 365 groups and distribution lists based on their role. Grant access to relevant SharePoint sites and shared drives. Add them to the Teams channels they'll participate in. Set up shared mailbox access if they need it (for example, if they'll be monitoring info@ or support@). Grant access to printers and networked devices. Add them to the company directory and phone system. Apply the principle of least privilege: grant only the access needed for the employee's role, nothing more. It's much easier to add permissions later when a need arises than to audit and remove excessive access after the fact. If your business uses Entra ID with Conditional Access policies, new employees automatically inherit the access controls that apply to their group memberships, including MFA requirements, device compliance checks, and location-based restrictions. ## Device configuration This is the most time-consuming step, and it's also the one that benefits most from automation. If your business uses Microsoft 365 Business Premium with Intune and Autopilot, most of this setup happens automatically. Register the new laptop's hardware ID with your Microsoft tenant, and when the employee powers it on and signs in with their new Microsoft 365 credentials, all company policies, apps (including 1Password and Microsoft Teams), and security settings deploy without anyone touching the machine. The employee gets a fully configured, secured laptop by simply signing in. This is how Athencia provisions devices for its managed IT clients. If you're configuring manually, here's the full checklist. Complete Windows setup and join the device to Entra ID (or your identity system). Install all pending Windows updates. Enable BitLocker drive encryption to protect data if the laptop is lost or stolen. Install endpoint protection; if you're using Microsoft 365 Business Premium, Defender for Business is included and should be configured via Intune policies. Install Microsoft 365 apps: Outlook, Teams, Word, Excel, PowerPoint, and OneNote. Install any business applications specific to the employee's role. Install and configure 1Password or your password manager. Install the VPN client if needed. Connect printers. Configure OneDrive sync so the employee's files are automatically backed up to the cloud. Set security policies including screen lock timeout (5 minutes is a reasonable default) and automatic update settings. ## Email and communication Configure Outlook with the employee's mailbox and verify that sending and receiving works. Set up their email signature following the company template. Add them to relevant distribution lists so they receive team and company-wide communications. Set up Microsoft Teams and verify that audio and video work correctly. A quick test call catches hardware or driver issues before the employee's first meeting with a client. Add the employee to the company phone system. If you use Teams Phone, assign a phone number in the Teams admin center. Share the IT support contact information and explain how to submit help requests, whether that's an email address, a support portal, or a phone number. ## Security Security setup is not optional and should not be deferred to "sometime during the first week." Enable multi-factor authentication on the employee's Microsoft 365 account before they sign in for the first time. Walk them through the MFA setup process during the day-one handoff, which involves installing the Microsoft Authenticator app on their phone and registering it with their account. This takes about three minutes and is the single most effective thing you can do to prevent account compromise. Provide the initial password securely. Do not email it, do not write it on a sticky note, and do not put it in a Teams message. Use 1Password's secure sharing feature or provide it verbally during the in-person handoff. Schedule security awareness training. Whether you use an internal program or a platform like Huntress (which bundles security awareness training with its managed EDR), new employees should complete their first training module within their first two weeks. Phishing attacks target new hires because they're less familiar with company communication patterns. Review the company password policy and acceptable use policy with the employee. Have them sign an acknowledgment that they've read and understood both documents. ## Documentation to provide Give the new employee a simple reference document (one page is plenty) that covers the essentials. Include IT support contact information: who to call, how to submit a ticket, and the process for emergency support. Provide a quick start guide covering how to access email, files, Teams, VPN, and printers. Include password policy instructions and a brief guide to using 1Password. Attach or link to the acceptable use policy. Provide Wi-Fi credentials for the business and guest networks. Store this documentation somewhere the employee can find it later, like a SharePoint page or an internal wiki. First-day information overload is real; they'll need to reference it again. ## Day-one walkthrough The final step is a hands-on walkthrough with the employee. Hand over the device and verify they can sign in. Walk through email, Teams, and file access. Verify printer access works. Show them where to find IT help and how to contact support. Verify that MFA is set up and working on their phone. Walk through the password manager and make sure they can access the shared vaults assigned to them. Answer their questions and confirm everything works. This walkthrough typically takes 20 to 30 minutes and prevents a flood of "how do I..." tickets in the first week. ## Onboarding checklist summary Use this as a quick reference for every new hire. - Hardware ordered, configured, and tested - Microsoft 365 account created with correct license (Business Premium) - Business application accounts created - 1Password account set up with appropriate shared vault access - Appropriate group memberships and permissions assigned - Device fully configured with security settings, software, and policies - Email, Teams, and phone configured and tested - MFA enabled and verified - Security awareness training scheduled - IT documentation and policies provided - Day-one walkthrough completed ## Need help? Getting onboarding right sets the tone for a new employee's experience and protects your business from day one. If you need help building a repeatable onboarding process or want to streamline device provisioning with Autopilot, [contact Athencia](/contact). We do this every day. #### What Is a Technology Business Review and Why Your Small Business Needs One > Explains what a Technology Business Review (TBR) is, what it covers, and how it helps small businesses align IT investments with business goals. URL: https://athencia.com/kb/general-it/what-is-a-technology-business-review-and-why-your-small-business-needs-one A Technology Business Review (TBR) is a structured meeting between your business leadership and your IT provider to evaluate the health of your technology environment, identify risks, and plan investments that align with your business goals. It's the IT equivalent of an annual physical: it catches problems before they become emergencies and gives you a clear picture of where you stand. Having one at least annually prevents your IT from falling behind while you're focused on running the business. ## What a TBR covers A good TBR is not a vague conversation about "how things are going." It's a data-driven review with specific deliverables. Here's what each section should include. **Current state assessment.** This is a clear, honest picture of your IT environment today. It covers your hardware inventory (how many computers, their age, their condition), your software licenses (what you're paying for, what's in use, what's expiring), your security posture (MFA adoption, endpoint protection coverage, backup status), and your network health (internet speed, wireless performance, equipment age). If your IT provider uses a real-time dashboard like the [Athencia One Portal](/athencia-one), much of this data is already collected and can be presented without a manual audit. If they have to scramble to pull this information together before the meeting, that tells you something about their monitoring practices. **Risk identification.** Every IT environment has risks. The question is whether you know what they are. A TBR should identify aging hardware approaching end of life, software nearing end of support (such as applications that won't run on the latest operating system), security gaps (employees without MFA, devices without endpoint protection), compliance issues relevant to your industry, and single points of failure (one server with no redundancy, one person who knows all the passwords). Each risk should be rated by severity and likelihood so you can prioritize the ones that matter most. **Performance review.** This section looks at how well IT is serving your business day to day. Your IT provider should present data on support ticket trends (are tickets increasing or decreasing?), average response and resolution times, system uptime, recurring issues that haven't been permanently resolved, and user satisfaction. If the same printer problem generates a ticket every week, that's not an IT support success story. It's a sign that someone needs to fix the root cause. **Budget review.** A TBR should include a clear summary of what you're currently spending on IT across all categories: hardware, software, managed services, security, internet, and phone. It should highlight areas where costs could be optimized (unused licenses, redundant tools, overprovisioned services) and areas where additional investment is needed (aging hardware, security gaps, compliance requirements). This section turns IT from a mystery expense into a transparent, manageable budget item. **Roadmap and priorities.** The most valuable part of a TBR is the forward-looking plan. Your IT provider should present a roadmap for the next 6 to 12 months, with specific projects ranked by business impact and risk. For example: "Replace the 5 laptops that are over 4 years old (high impact, medium cost), upgrade from Microsoft 365 Business Standard to Business Premium to get Intune and Defender (high impact, moderate cost), implement a formal backup for your Microsoft 365 data using Dropsuite (high impact, low cost)." Each recommendation should include an estimated cost and a clear rationale. ## Why small businesses skip TBRs (and why they shouldn't) The most common excuse is "we're too small for that." But even a 10-person company benefits from a yearly IT checkup. In fact, smaller businesses often benefit more because they have less margin for error. A single security incident or prolonged outage can have an outsized impact on a business with 15 employees. Many small businesses lack internal IT leadership. The owner makes IT decisions on the fly, reacting to problems rather than planning ahead. A TBR gives you an hour or two of structured strategic thinking about technology, guided by someone who does this professionally. It's the closest thing to having a CIO without hiring one. Reactive IT culture is another barrier. When technology only gets attention after something breaks, risks accumulate silently. That 6-year-old server nobody thinks about, the two employees who never set up MFA, the backup that stopped running three months ago but nobody noticed. Without regular reviews, these issues don't surface until they cause an expensive emergency: a server failure, a security breach, or a failed compliance audit. ## What a good TBR should produce Walk out of a TBR with tangible deliverables, not just a handshake and a verbal summary. **Written report.** A document summarizing findings, risks, and recommendations. This is your reference between reviews and your evidence for cyber insurance applications, compliance audits, or board discussions. **Risk register.** A prioritized list of risks with severity, likelihood, and recommended actions. This becomes your "fix it" list, ordered by what matters most. **Hardware lifecycle plan.** A clear picture of which devices need replacement in the next 12 months and the estimated cost. No surprises when a laptop dies if you already knew it was due for replacement. **Security scorecard.** Where your security stands against a recognized framework. A CIS Controls baseline assessment, for example, measures your environment against the Center for Internet Security's recommended controls and identifies specific gaps with actionable recommendations. This gives you an objective measure of your security posture, not just your IT provider's opinion. **Budget projection.** Estimated IT costs for the next 12 months, including recurring costs and planned projects. This feeds directly into your annual business budget. **Priority roadmap.** The top 3 to 5 projects recommended for the next quarter, with rationale, estimated cost, and expected business impact. ## How often to have a TBR **Annually at minimum.** A comprehensive review covering all of the categories above. This is the baseline. Any business working with an MSP should expect at least one thorough TBR per year. **Quarterly is better.** Shorter check-ins (30 to 60 minutes) to review progress on the roadmap, address new issues, and adjust priorities. Quarterly reviews keep the roadmap from becoming a document nobody looks at after the annual meeting. They also catch emerging risks, like a new employee who was onboarded without MFA, before they become problems. **Triggered reviews.** Schedule an additional TBR after a security incident, a major business change (acquisition, rapid hiring, new office location), or a compliance audit. These events change your IT landscape enough to warrant a fresh assessment. For [Athencia's managed IT clients](/athencia-one), triggered reviews are part of the service relationship and can be scheduled on short notice. Most managed IT providers include quarterly or annual TBRs as part of their service agreement. If yours doesn't, ask why. ## What to prepare for your TBR Come to the meeting ready to discuss the business side. Your IT provider brings the technical data; you bring the business context. Share your business goals for the next 12 months. Are you planning to hire? Open a new location? Launch a new service? These plans directly affect your IT needs, and your provider needs to know about them to plan effectively. Bring up any IT frustrations or recurring issues your team is experiencing. Slow computers, unreliable Wi-Fi, confusing software, difficulty accessing files remotely. These issues often get normalized ("that's just how it is"), but they shouldn't be. A TBR is the right time to raise them. Mention upcoming compliance requirements or audits. If your industry requires HIPAA compliance and you have an audit in six months, your IT provider needs to factor that into the roadmap. Be transparent about budget constraints. A good IT provider will work within your budget and help you prioritize spending where it has the most impact. Hiding budget limitations leads to recommendations you can't act on, which wastes everyone's time. Finally, bring questions. If you've heard about a new tool, a new threat, or a technology trend that might affect your business, the TBR is the right place to discuss it. ## Red flags: When your IT provider doesn't offer TBRs An MSP or IT provider that never reviews your environment strategically is operating as a help desk, not a partner. They're solving today's problems without thinking about tomorrow's risks. That distinction matters. Without TBRs, issues like aging hardware, expiring software licenses, and security gaps go unaddressed until they cause a crisis. You end up in a constant cycle of emergency spending, which is both more expensive and more stressful than planned investment. A good IT provider proactively schedules TBRs and comes prepared with data, analysis, and recommendations. They don't wait for you to ask. If your current provider doesn't offer regular TBRs, ask them to start. If they're unwilling or unable, consider it a significant factor in evaluating alternatives. ## Need help? A Technology Business Review is one of the most valuable things an IT provider can offer, and it's one of the easiest to overlook. If you haven't had one in the past year, or if you've never had one at all, [reach out to Athencia](/contact). We'll assess your environment, identify your risks, and give you a clear plan for the next 12 months. ### Microsoft 365 #### How to Add a New Employee to Microsoft 365 and Set Up Their Email > Step-by-step guide for adding a new user account in Microsoft 365, assigning a license, and configuring their business email. URL: https://athencia.com/kb/microsoft-365/how-to-add-a-new-employee-to-microsoft-365-and-set-up-their-email Adding a new employee to Microsoft 365 involves creating a user account in the admin center, assigning a license, and configuring their email. The whole process takes about 10 minutes and does not require any technical background. This guide walks through every step with the exact screens and buttons you will encounter. ## What you need - **Global Administrator** or **User Administrator** access to your Microsoft 365 tenant - An available Microsoft 365 license to assign - The new employee's full name and desired email address - Their job title and department (for the company directory) ## Step 1: Sign in to the Microsoft 365 admin center Go to [admin.microsoft.com](https://admin.microsoft.com) and sign in with your admin credentials. You will land on the admin center home page, which shows a dashboard of your tenant's health and usage. If you are not sure who your admin is, any existing user can check by going to **Settings** > **Org settings** in Microsoft 365 and looking for the admin contact. If your company uses a managed IT provider like [Athencia](/athencia-one), your provider handles user provisioning for you and you can simply send them the new hire's details. ## Step 2: Create the new user account 1. In the left sidebar, click **Users** > **Active users** 2. Click **+ Add a user** at the top of the page 3. Fill in the following fields: - **First name** and **Last name** - **Display name** (auto-populates from the name fields) - **Username**: This becomes the employee's email address. Enter the part before the @ sign and select your company domain from the dropdown (e.g., jsmith@yourcompany.com) 4. Under **Password settings**, choose one of two options: - **Auto-generate a password**: Microsoft creates a random password for you. This is the easiest option. - **Let me create the password**: You type in a temporary password manually. 5. Check the box for **Require this user to change their password when they first sign in**. Always leave this enabled so the employee sets their own password on day one. 6. Click **Next** ## Step 3: Assign a license On the next screen, you will assign a product license. This determines which Microsoft 365 apps and services the employee can use. 1. Check the box next to the license you want to assign 2. If you have multiple license types, choose the one appropriate for the employee's role Here is a quick comparison of the most common license tiers: | Feature | Business Basic | Business Standard | Business Premium | |---------|---------------|------------------|-----------------| | Exchange email | Yes | Yes | Yes | | Web and mobile Office apps | Yes | Yes | Yes | | Desktop Office apps | No | Yes | Yes | | Microsoft Teams | Yes | Yes | Yes | | OneDrive (1 TB) | Yes | Yes | Yes | | Intune device management | No | No | Yes | | Defender for Office 365 | No | No | Yes | | Entra ID Conditional Access | No | No | Yes | Athencia deploys Microsoft 365 Business Premium for all managed clients because it includes Intune, Defender for Office 365, and Conditional Access at no extra cost. These security features are not available in Business Basic or Business Standard, which means organizations on those tiers lack device management, advanced email threat protection, and the ability to enforce sign-in policies. If you have no available licenses, click the link to **Purchase licenses** directly from this screen. The new license is added to your subscription immediately. 3. Click **Next** ## Step 4: Configure optional settings This screen lets you set additional details for the user's profile and permissions. **Admin roles**: Leave this set to **User (no admin center access)** unless the employee specifically needs admin privileges. Follow the principle of least privilege: only assign admin roles to people who need them, and use the most limited role that covers their responsibilities. **Profile information**: Fill in the employee's **Job title**, **Department**, **Office**, and **Phone number**. This information populates the company directory and is used by Exchange transport rules (for email signatures), org charts, and the Teams people card. Filling it in now saves you from having to update it later. Click **Next**, then review the summary and click **Finish adding** to create the account. ## Step 5: Add the user to groups and shared mailboxes After the account is created, add the employee to the correct distribution groups, Microsoft 365 groups, and shared mailboxes. 1. Go to **Users** > **Active users** and click on the new user's name 2. Click the **Groups** tab 3. Click **Manage groups** and add them to any relevant groups (e.g., allstaff@, marketing-team@) 4. For shared mailbox access, go to **Teams & groups** > **Shared mailboxes**, click the shared mailbox, and add the new user as a member If your company uses Microsoft Teams for collaboration, the employee will automatically gain access to any Teams channels associated with the Microsoft 365 groups you added them to. ## Step 6: Share login credentials securely Never send a password in a plain-text email. If that email is intercepted or the recipient's inbox is compromised, the attacker has the credentials. Instead, share the temporary password using one of these methods: - **In person or by phone**: The most secure option for employees working on-site. - **Password manager**: If your company uses 1Password, create a secure share link with the temporary credentials. Athencia includes 1Password in its [Athencia One Complete](/athencia-one-complete) package and offers it as an add-on for Athencia One clients. A password manager eliminates the problem of securely transmitting credentials entirely. - **Separate channels**: Send the username by email and the temporary password by text message, so both are never in the same place. Let the employee know what to expect on their first sign-in: they will be prompted to change their password, and if your organization has MFA enabled, they will also be walked through setting up the Microsoft Authenticator app. ## Step 7: Verify the account is working Before considering the setup complete, confirm everything is functioning: 1. **Send a test email** to the new address from another account and verify it arrives 2. **Have the employee sign in** at [outlook.office.com](https://outlook.office.com) and confirm they can access Outlook, Teams, and OneDrive 3. **Check the license** by going to **Users** > **Active users** > clicking their name > **Licenses and apps** to confirm the correct license and services are assigned If your organization uses Microsoft Intune for device management (included with Business Premium), the employee's device enrollment will happen automatically when they sign in to their work account on a company-managed device. For personal devices in a BYOD setup, Intune app protection policies can secure company data on the device without managing the entire phone. ## Device and security setup Once the account is active, the new employee's device needs to be properly secured. On a Business Premium tenant, this includes: - **Microsoft Intune** enrollment, which pushes your company's security policies (encryption, password requirements, screen lock) to the device automatically - **Microsoft Defender for Business**, which provides endpoint protection on the device - **Huntress Managed EDR**, which Athencia layers on top of Defender for 24/7 monitoring by human threat hunters. Defender handles baseline protection; Huntress adds a managed Security Operations Center that catches threats Defender misses. This happens behind the scenes for managed clients. If you are handling IT internally, you will need to configure Intune device enrollment and compliance policies separately. ## Common issues | Issue | Cause | Fix | |-------|-------|-----| | "This username is already taken" | Another account (active or deleted) uses that address | Check the deleted users list under **Users** > **Deleted users**. If found, either restore it or permanently delete it to free the address. | | License assignment fails | No available licenses | Purchase additional licenses from **Billing** > **Purchase services** | | Email not in global address list | Directory sync takes time | Allow up to 24 hours for the new user to appear in the global address list and Outlook autocomplete | | Employee cannot sign in | Account may be blocked or password issue | Verify sign-in is not blocked under the user's account settings and try resetting the password | ## Need help? Adding users is straightforward, but getting the full onboarding right, from license selection to device enrollment to security configuration, takes more planning. If you want help setting up new employees or building a repeatable onboarding process, [contact Athencia](/contact). We handle user provisioning as part of every client onboarding. #### How to Offboard an Employee in Microsoft 365 Without Losing Their Data > Step-by-step guide for securely removing a departing employee from Microsoft 365 while preserving their email, files, and data for your business. URL: https://athencia.com/kb/microsoft-365/how-to-offboard-an-employee-in-microsoft-365-without-losing-their-data Offboarding an employee from Microsoft 365 requires revoking their access immediately while preserving their email, files, and data for business continuity. Doing this in the wrong order can result in permanent data loss or a security gap where the departing employee retains access to company systems. This guide walks through every step in the correct sequence. ## What you need - **Global Administrator** access to Microsoft 365 - Knowledge of which files, emails, and data the departing employee owns - A plan for who should receive access to the employee's mailbox and files (typically their manager or replacement) ## Why order matters The single most common mistake is deleting the user account before preserving their data. Once the account is deleted, you have 30 days to restore it before everything is permanently gone. The correct sequence is: block access first, preserve data second, delete the account last. ## Step 1: Reset the password and block sign-in This should happen immediately, ideally on or before the employee's last day. Every minute the account remains accessible after the employee has left is a security risk. 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Users** > **Active users** 2. Click on the departing employee's name 3. Click **Reset password** at the top of their account page 4. Select **Auto-generate password** and uncheck **Require this user to change their password when they first sign in** (it does not matter since they will not be signing in again) 5. Click **Reset password** 6. Next, click **Block sign-in** on the same user's account page 7. Check the box for **Block this user from signing in** and click **Save changes** Blocking sign-in revokes all active sessions across all devices, including Outlook desktop, Teams, mobile apps, and any browser sessions. The user will be signed out everywhere within about 60 minutes. If you need immediate session revocation, go to the user's account page, click the **Account** tab, and click **Revoke sessions**. If your organization uses Huntress Managed ITDR alongside Microsoft Entra ID, any suspicious sign-in attempts from the former employee's credentials after this point will be flagged and investigated by Huntress's 24/7 SOC team automatically. ## Step 2: Convert the mailbox to a shared mailbox Converting the departing employee's mailbox to a shared mailbox is the best way to preserve their email. A shared mailbox does not require a license, so you stop paying for it immediately, and all email history is retained indefinitely. 1. Go to the [Exchange admin center](https://admin.exchange.microsoft.com) 2. Click **Recipients** > **Mailboxes** 3. Click on the departing employee's mailbox 4. Click **Convert to shared mailbox** (under the Others section at the bottom) 5. Confirm the conversion After converting, add the employee's manager or replacement as a member of the shared mailbox: 1. Go back to [admin.microsoft.com](https://admin.microsoft.com) > **Teams & groups** > **Shared mailboxes** 2. Click on the newly converted shared mailbox 3. Under **Members**, click **Edit** and add the appropriate people The alternative is setting up email forwarding to another user. However, forwarding only captures new incoming mail. It does not preserve the departing employee's email history, sent items, or folder structure. Converting to a shared mailbox preserves everything. If your company needs to retain email data for compliance or legal reasons beyond what the shared mailbox provides, Dropsuite provides independent backup of Microsoft 365 mailboxes, OneDrive, and SharePoint. Athencia includes Dropsuite in its managed stack, which means you can restore email data from any point in time, even if something goes wrong during offboarding. ## Step 3: Transfer OneDrive files The departing employee's OneDrive contains their personal work files. You need to transfer these before deleting the account. 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Users** > **Active users** 2. Click on the departing employee's name 3. Click the **OneDrive** tab 4. Under **Get access to files**, click **Create link to files** 5. This generates a link that opens the employee's OneDrive. Share this link with their manager or replacement. The delegate has 30 days from the date the account is deleted to access and move files. After 30 days, the OneDrive data is permanently deleted. To move the files permanently: 1. Open the link to the employee's OneDrive 2. Select all relevant files and folders 3. Click **Move to** and choose a location in a SharePoint document library or another user's OneDrive 4. Verify the files transferred successfully If you need to extend the 30-day window, go to the SharePoint admin center ([admin.microsoft.com](https://admin.microsoft.com) > **Admin centers** > **SharePoint**) > **Settings** > **OneDrive retention** and increase the retention period (up to 3,650 days). ## Step 4: Remove from groups and transfer ownership The departing employee may be a member or owner of Microsoft 365 groups, Teams channels, distribution lists, and shared mailboxes. You need to handle each: 1. Go to **Users** > **Active users** > click the employee's name > **Groups** tab 2. Review every group they belong to 3. For groups where they are the **sole owner**, add a new owner before proceeding. If the only owner is removed, no one can manage the group. 4. Remove the employee from all groups For Microsoft Teams specifically: 1. Open the Teams admin center at [admin.teams.microsoft.com](https://admin.teams.microsoft.com) 2. Go to **Teams** > **Manage teams** and check each team the employee belonged to 3. If they owned any teams, transfer ownership to another user 4. Remove them from all teams ## Step 5: Revoke access to third-party apps Departing employees often have access to third-party applications through their Microsoft 365 account. These need to be revoked. 1. Go to the [Entra admin center](https://entra.microsoft.com) > **Identity** > **Users** > select the departing user 2. Click **Applications** to see which enterprise applications they accessed 3. Revoke any app-specific permissions 4. Under **Consents and permissions**, review and remove any OAuth consents the user granted to third-party apps This step is frequently overlooked. OAuth consents can persist even after the user's password is reset, allowing third-party apps to continue accessing company data through tokens the user previously authorized. ## Step 6: Review sign-in logs Before deleting the account, check the sign-in logs for any suspicious activity during the employee's final days. 1. In the [Entra admin center](https://entra.microsoft.com), go to **Identity** > **Monitoring & health** > **Sign-in logs** 2. Filter by the departing user's name 3. Look for sign-ins from unusual locations, bulk file downloads, or access to sensitive applications This requires Entra ID P1 licensing, which is included with Microsoft 365 Business Premium. Business Basic and Business Standard do not include sign-in log retention or the ability to filter by user. ## Step 7: Delete the user account Only delete the account after you have confirmed that the mailbox is converted, files are transferred, and group ownership is reassigned. 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Users** > **Active users** 2. Select the departing employee 3. Click **Delete user** 4. Confirm the deletion After deletion: - The account moves to **Users** > **Deleted users** and stays there for 30 days. During this window, you can restore the account if needed. - After 30 days, deletion is permanent and the account cannot be recovered. - The license assigned to the deleted user becomes available for reassignment immediately. ## Offboarding checklist Use this checklist to make sure nothing is missed: - [ ] Password reset and sign-in blocked - [ ] Active sessions revoked - [ ] Mailbox converted to shared mailbox - [ ] Manager or replacement added to shared mailbox - [ ] OneDrive files transferred or access granted - [ ] Group memberships reviewed and employee removed - [ ] Group and Teams ownership transferred where needed - [ ] Third-party app access and OAuth consents revoked - [ ] Sign-in logs reviewed for suspicious activity - [ ] User account deleted - [ ] License reclaimed and available for reassignment ## Need help? Employee offboarding involves security, compliance, and data preservation decisions that are easy to get wrong. If you want to make sure nothing falls through the cracks, [contact Athencia](/contact). We handle offboarding for managed clients and can audit your current process for gaps. #### How to Organize Your Company Files in SharePoint for a Small Team > Practical guide to setting up a SharePoint document library that keeps your small team's files organized, accessible, and properly secured. URL: https://athencia.com/kb/microsoft-365/how-to-organize-your-company-files-in-sharepoint-for-a-small-team SharePoint document libraries are the right place for shared company files that multiple people need to access. Setting up a clean structure from the start prevents the tangled mess of duplicated folders, broken permissions, and files nobody can find that plagues most small businesses. This guide covers planning, structure, permissions, and syncing, with specific steps you can follow today. ## What you need - Microsoft 365 admin or SharePoint admin access - A plan for which teams or departments need shared file spaces - A list of who needs access to what Every Microsoft 365 plan that includes Teams also includes SharePoint. The document libraries behind every Teams channel are SharePoint libraries, even if your team never opens SharePoint directly. ## SharePoint sites vs. document libraries vs. folders Before building anything, understand the three layers of SharePoint file organization: - **SharePoint site**: A container for a team or department. Every Microsoft Teams team automatically gets a SharePoint site behind it. Think of a site as a top-level workspace. - **Document library**: A file storage area within a SharePoint site. Each site can have multiple libraries. Think of a library like a filing cabinet. - **Folders**: Subdivisions within a document library. Use these sparingly. SharePoint works best with a flat or shallow folder structure combined with metadata columns for filtering. The key recommendation is one SharePoint site per department or major function, with document libraries and metadata replacing deeply nested folders. If you are coming from a traditional file server with 10 levels of nested folders, this is a significant shift in thinking, but it pays off quickly in usability. ## Step 1: Plan your site structure Keep it simple. For a company with 10 to 30 people, you likely need only two to four SharePoint sites. Here is a practical starting structure: | Site Name | Purpose | Who Needs Access | |-----------|---------|-----------------| | Company-Wide | Policies, templates, shared resources | Everyone | | Operations | Projects, client work, delivery | Operations team | | Finance | Invoices, reports, budgets | Finance team + leadership | | HR | Onboarding docs, policies, personnel files | HR + leadership | Before creating any new sites, check what already exists. Each Teams team creates a SharePoint site automatically. If your marketing team already has a Teams channel, they already have a SharePoint site. Creating a separate SharePoint site for marketing would just create confusion and file duplication. To see existing sites, go to the SharePoint admin center at [admin.microsoft.com](https://admin.microsoft.com) > **Admin centers** > **SharePoint** > **Sites** > **Active sites**. ## Step 2: Create document libraries Within each SharePoint site, create document libraries for major file categories. Each library should represent a distinct type of work or content. 1. Open the SharePoint site 2. Click **+ New** in the top bar > **Document library** 3. Enter a name for the library (keep it short, use hyphens instead of spaces) 4. Click **Create** For example, an Operations site might have these libraries: - **Client-Projects**: All client deliverables and working files - **Templates**: Proposal templates, SOW templates, project plans - **Contracts**: Signed contracts and agreements - **Proposals**: Active and archived proposals Keep library names short and descriptive. Avoid spaces in library names because they get replaced with "%20" in URLs, which looks messy and can cause issues with some integrations. To customize the default view, click the column headers and select **Column settings** > **Show/hide columns**. The most useful default view includes: Name, Modified, Modified By, and any custom metadata columns you create in the next step. ## Step 3: Use metadata instead of deep folders This is the step that separates a well-organized SharePoint from one that looks like a cluttered file server. Instead of creating nested folders like Clients > Smith > 2026 > Invoices, create a flat library with metadata columns that let users filter and sort. To add a custom column: 1. Open the document library 2. Click **+ Add column** in the header row 3. Choose the column type: - **Choice**: For categories like Client Name, Document Type, or Status - **Date**: For deadlines or effective dates - **Person**: For assigning an owner or reviewer - **Number**: For invoice amounts, project numbers, etc. 4. Enter the column name and options 5. Click **Save** For a Client-Projects library, useful columns might be: | Column | Type | Options | |--------|------|---------| | Client Name | Choice | List of your clients | | Project Phase | Choice | Discovery, Active, Complete, Archived | | Document Type | Choice | Contract, Proposal, Deliverable, Invoice | | Owner | Person | (pulls from your directory) | Once columns are set up, users can click any column header to sort, or use the **Filter** pane on the right to show only files matching specific criteria. This is dramatically faster than navigating five levels of folders. When folders still make sense: if you need to apply different permissions to different sections of a library (for example, restricting access to certain client files), folders with broken permission inheritance are the way to do it. Otherwise, prefer metadata. ## Step 4: Set permissions SharePoint permissions inherit from the site by default. Everyone who has access to the site can see every library and file within it. For most libraries, this is fine. For sensitive content like HR records or financial data, you need to restrict access. To set permissions on a library: 1. Open the document library 2. Click the gear icon in the top right > **Library settings** > **Permissions for this document library** 3. Click **Stop Inheriting Permissions** to break the inheritance from the site 4. Remove groups that should not have access 5. Add the specific users or groups that need access, selecting the appropriate permission level: - **Full Control**: Can do everything, including managing permissions (use sparingly) - **Edit**: Can add, edit, and delete files - **Read**: Can view files but not modify them Follow the principle of least privilege. Give people the minimum access they need. Not everyone in the company needs to see financial reports or personnel files. Audit permissions quarterly, especially after employee departures. Former employees who were removed from Microsoft 365 lose access automatically, but contractors or external guests with direct permissions may not. ## Step 5: Sync libraries to File Explorer with OneDrive Many employees are more comfortable working with files in File Explorer (Windows) or Finder (Mac) than in a browser. SharePoint libraries can be synced to the desktop so they appear alongside local files. To set up sync: 1. Open the SharePoint document library in a browser 2. Click **Sync** in the toolbar at the top 3. Your browser will prompt you to open OneDrive. Click **Open** 4. OneDrive will begin syncing the library. Files appear under your company's name in File Explorer or Finder. Enable **Files On-Demand** so that synced files do not fill up the employee's hard drive. With Files On-Demand, files appear in the folder tree but are only downloaded when opened. To enable this: 1. Click the OneDrive icon in the system tray 2. Click the gear icon > **Settings** 3. Under the **Sync and backup** tab, check **Save space and download files as you use them** If your organization uses Microsoft Intune for device management (included with Microsoft 365 Business Premium), you can push OneDrive sync settings to all company devices through Intune policies. This ensures every employee's device is configured to sync the correct libraries with Files On-Demand enabled, without any manual setup on their part. ## Step 6: Back up your SharePoint data SharePoint has built-in version history and a recycle bin, but these are not the same as a true backup. If a user accidentally deletes an entire library, or if ransomware encrypts your files, version history alone may not save you. Dropsuite provides independent backup for SharePoint, OneDrive, and Exchange mailboxes. Athencia includes Dropsuite in its managed stack for all clients. With Dropsuite, your SharePoint data is backed up daily to a separate location, and you can restore individual files, folders, or entire libraries to any point in time. Without a third-party backup, you are relying solely on Microsoft's recycle bin (93 days for SharePoint) and version history. That is better than nothing, but it leaves gaps for bulk deletions, ransomware, and retention policy mistakes. ## Common mistakes - **Creating too many SharePoint sites.** More sites means more places to check and more permissions to manage. Start with the minimum and add sites only when there is a clear need. - **Deeply nested folder structures.** If you are recreating your old file server's folder tree in SharePoint, stop. Use metadata columns for filtering instead. - **Not setting permissions on sensitive libraries.** By default, everyone on the site sees everything. Break inheritance on HR, finance, and legal libraries. - **Not syncing libraries to File Explorer.** If employees have to open a browser and navigate to SharePoint every time they need a file, they will store files locally instead. Sync makes SharePoint feel like a local drive. - **No naming conventions.** Establish and enforce naming rules from day one. Files named "FINAL_v3_REAL_USE THIS ONE.docx" are a sign that no one agreed on a naming convention. - **Ignoring version history.** SharePoint keeps version history by default. Make sure it is enabled and set to a reasonable number of versions (50 is a good default). This lets you recover previous versions of any file. ## Need help? Setting up SharePoint well from the start saves hours of cleanup later. If you need help planning your site structure, configuring permissions, or migrating files from a file server or other cloud storage, [contact Athencia](/contact). We set up SharePoint as part of every Microsoft 365 deployment. #### How to Recover Deleted Emails in Outlook for Microsoft 365 > Guide to recovering deleted emails in Outlook, including items purged from the Deleted Items folder, using the Recoverable Items feature. URL: https://athencia.com/kb/microsoft-365/how-to-recover-deleted-emails-in-outlook-for-microsoft-365 Deleted emails in Outlook for Microsoft 365 can usually be recovered, even after being removed from the Deleted Items folder. Microsoft retains purged items for 14 days by default (up to 30 days if your admin has configured it), giving you a recovery window. This guide covers every recovery method available, from the simplest self-service options to admin-level tools for situations where the standard methods do not work. ## Understanding where deleted emails go Emails in Microsoft 365 do not disappear the moment you delete them. They pass through a series of stages, and each stage gives you a chance to recover them. **Stage 1: Deleted Items folder.** When you delete an email (pressing Delete or dragging it to Deleted Items), it moves to the Deleted Items folder. It stays there until you empty the folder or until your organization's retention policy clears it automatically. Recovering from here is as simple as dragging the email back to your Inbox. **Stage 2: Recoverable Items folder.** When you empty your Deleted Items folder, or delete an email from within Deleted Items, the email moves to a hidden folder called Recoverable Items. You will not see this folder in your normal folder list, but it is accessible through a special recovery option in Outlook. Items stay in Recoverable Items for 14 days by default. Your admin can extend this to up to 30 days. **Stage 3: Permanently deleted.** After the retention period in Recoverable Items expires, the email is permanently gone from the mailbox. At this point, only a third-party backup solution or a compliance search (if one was configured before deletion) can recover it. Understanding these stages helps you pick the right recovery method below. ## Option 1: Recover from the deleted items folder This is the simplest recovery. If the email is still in your Deleted Items folder, you can restore it in seconds. ### In Outlook on the web 1. Go to [outlook.office.com](https://outlook.office.com) and sign in 2. Click the **Deleted Items** folder in the left sidebar 3. Find the email you need. If you have a lot of deleted items, use the **Search** bar at the top of the folder and enter the sender's name, subject line, or a keyword from the email. 4. Right-click the email and select **Move** > **Inbox** (or choose another folder) 5. The email is restored to the folder you selected ### In Outlook desktop 1. Click the **Deleted Items** folder in the left sidebar 2. Find the email you need 3. Right-click the email and select **Move** > **Other Folder** 4. Choose **Inbox** or the original folder and click **OK** To recover multiple items at once, hold **Ctrl** (Windows) or **Cmd** (Mac) while clicking each email to select them, then right-click and move them all at the same time. ## Option 2: Recover purged items in Outlook on the web If you have already emptied your Deleted Items folder, the email may still be in the Recoverable Items folder. You can access this directly from Outlook on the web. 1. Go to [outlook.office.com](https://outlook.office.com) and sign in 2. Click the **Deleted Items** folder in the left sidebar 3. At the top of the message list, click **Recover items deleted from this folder** 4. A new window opens showing all recoverable items. Use the search bar to find specific emails by sender, subject, or date. 5. Select the emails you need by checking the box next to each one 6. Click **Restore** at the top of the list Restored items go back to the **Deleted Items** folder, not directly to your Inbox. After restoring, go to Deleted Items and move the emails to your Inbox or the folder where they belong. The items in this recovery window are only available for 14 days (or up to 30 days if your admin has extended the retention period). After that, they are permanently removed and cannot be recovered through this method. ## Option 3: Recover purged items in Outlook desktop The desktop version of Outlook also has access to the Recoverable Items folder, but the menu location varies depending on whether you are using classic Outlook or the new Outlook. ### Classic Outlook (Windows) 1. Click the **Deleted Items** folder in the left sidebar 2. Go to the **Folder** tab in the ribbon 3. Click **Recover Deleted Items** 4. A dialog box opens showing all recoverable items with their subject, sender, and deletion date 5. Select the items you need (hold Ctrl to select multiple) 6. Click **Restore Selected Items** (the envelope icon with the arrow) 7. Items are restored to the Deleted Items folder. Move them to your Inbox afterward. ### New Outlook (Windows and Mac) 1. Click the **Deleted Items** folder 2. At the top of the message list, click **Recover items deleted from this folder** (same as the web version) 3. Select items and click **Restore** If you do not see the **Recover Deleted Items** option in classic Outlook, make sure you have the Deleted Items folder selected. The option only appears when that specific folder is active. If it still does not show, your admin may not have enabled recoverable items for your mailbox. ## Option 4: Admin recovery If the user cannot find the email through any of the self-service options above, an admin can attempt recovery through the Exchange admin center or PowerShell. ### Exchange admin center 1. Sign in to the [Exchange admin center](https://admin.exchange.microsoft.com) 2. Go to **Recipients** > **Mailboxes** 3. Click on the user's mailbox 4. Under **Others**, click **Recover deleted items** 5. Search for the items by date range, subject, or sender 6. Select the items and click **Recover** ### PowerShell (for bulk recovery or advanced scenarios) Admins can use the Exchange Online PowerShell module to recover items that do not appear in the admin center interface. This is useful for bulk recovery or for items that are close to the end of their retention window. The command `Get-RecoverableItems` and `Restore-RecoverableItems` allow filtering by subject, sender, date range, and item type. This requires the Exchange Online PowerShell module and the appropriate admin role. ### Compliance search (last resort) If the email has passed the recoverable items retention window, and your organization has a retention policy or litigation hold in place, the email may still exist in the compliance store. 1. Go to [compliance.microsoft.com](https://compliance.microsoft.com) > **Content search** 2. Create a new search and specify the mailbox, date range, and keywords 3. Run the search and review the results 4. Export the results to recover the email Compliance Search only works if a retention policy, litigation hold, or in-place hold was active at the time the email was deleted. If none of these were configured, the email is gone once it passes the recoverable items window. ## How to prevent this in the future ### Extend the recoverable items retention period By default, Microsoft 365 keeps purged items for 14 days. Your admin can extend this to 30 days, which is the maximum for Exchange Online. To change this, an admin can run the following PowerShell command: ``` Set-Mailbox -Identity user@yourcompany.com -RetainDeletedItemsFor 30 ``` To apply this to all mailboxes at once, your admin can set it as a tenant-wide default. ### Train employees to archive instead of delete Most accidental deletions happen because employees use the Delete key as an organization tool. Encourage your team to use the **Archive** button instead. Archived emails move to the Archive folder, where they remain searchable and accessible without cluttering the Inbox. ### Set up retention policies Retention policies keep email for a defined period regardless of whether the user deletes it. Go to [compliance.microsoft.com](https://compliance.microsoft.com) > **Data lifecycle management** > **Retention policies** to create policies that retain email for one year, three years, or whatever your business or compliance requirements dictate. ### Use a third-party backup solution Microsoft's built-in retention has limits. The recoverable items window maxes out at 30 days, and compliance features require specific licensing. Dropsuite provides independent backup of Microsoft 365 mailboxes, backing up every email daily to a separate location. Athencia includes Dropsuite in its managed stack, which means any deleted email can be restored from backup at any point, regardless of Microsoft's retention windows. This is the most reliable safety net for accidental deletions, ransomware, and compliance requirements. ## Need help? If you have tried the steps above and still cannot find the email you need, or if you want to set up retention policies and backup to prevent this from happening again, [contact Athencia](/contact). We can help recover lost data and put safeguards in place for the future. #### How to Set Up a Consistent Email Signature for Your Whole Team in Microsoft 365 > Guide to creating and deploying a professional, consistent email signature across all employees in Microsoft 365 using transport rules or third-party tools. URL: https://athencia.com/kb/microsoft-365/how-to-set-up-a-consistent-email-signature-for-your-whole-team-in-microsoft-365 A consistent email signature across your entire team makes your business look professional and ensures every outgoing email includes your correct contact information, branding, and any required legal disclaimers. Without a centralized approach, you end up with employees using different fonts, outdated phone numbers, or no signature at all. Microsoft 365 offers several ways to manage signatures, from individual manual setup to fully centralized deployment. ## What you need - A finalized signature design (logo, contact format, colors, any legal disclaimers) - Microsoft 365 admin access for centralized deployment options - Employee names, titles, phone numbers, and other dynamic fields - Your company logo hosted at a public URL (for HTML signatures) ## Option 1: Manual setup in Outlook (simplest, least control) Each employee creates their own signature in Outlook using a template you provide. This works for very small teams where you trust everyone to follow the format. ### Outlook desktop (Windows) 1. Open Outlook and click **File** > **Options** 2. In the Options window, click **Mail** on the left sidebar 3. Click **Signatures** 4. Click **New**, give the signature a name (e.g., "Company Signature") 5. In the editor, paste the signature template you prepared. You can paste formatted HTML directly from a browser or design tool. 6. Under **Choose default signature**, set the signature for both **New messages** and **Replies/forwards** 7. Click **OK** to save ### Outlook on the web 1. Go to [outlook.office.com](https://outlook.office.com) and sign in 2. Click the **Settings** gear icon in the top right 3. Click **Mail** > **Compose and reply** 4. Under **Email signature**, paste your template into the editor 5. Check **Automatically include my signature on new messages I compose** and **Automatically include my signature on messages I forward or reply to** 6. Click **Save** ### Limitations of manual setup - Relies on each employee to set it up correctly and keep it updated - Does not apply to emails sent from mobile devices unless configured separately in the Outlook mobile app - If an employee reinstalls Outlook or gets a new device, the signature is lost and needs to be recreated - No centralized way to push updates (logo change, phone number change) to everyone at once This approach works for offices under five people. Beyond that, the maintenance overhead outweighs the simplicity. ## Option 2: Exchange transport rules (built-in, centralized) Exchange mail flow rules (also called transport rules) let you apply a signature to all outgoing email server-side. This means every external email gets the signature automatically, regardless of which device or app the sender uses. ### Setting up the transport rule 1. Go to the [Exchange admin center](https://admin.exchange.microsoft.com) 2. In the left sidebar, click **Mail flow** > **Rules** 3. Click **+ Add a rule** > **Apply disclaimers** 4. Name the rule (e.g., "Company Email Signature") 5. Under **Apply this rule if**, select **The sender is located** > **Inside the organization** 6. Under **Do the following**, select **Append the disclaimer** > **Enter text** 7. Paste your signature HTML into the text box 8. Under **Fallback action**, choose **Wrap** (this adds the signature even if Outlook cannot insert it inline) 9. Click **Next** through the remaining settings and **Save** ### Using dynamic variables Transport rules support variables that pull data from each user's Entra ID directory profile. This means you can create one template that automatically inserts each person's name, title, and phone number. Common variables: | Variable | Inserts | |----------|---------| | `%%DisplayName%%` | Full name | | `%%Title%%` | Job title | | `%%Department%%` | Department | | `%%PhoneNumber%%` | Office phone | | `%%MobilePhone%%` | Mobile phone | | `%%Email%%` | Email address | Your HTML template might look like this: ```html

%%DisplayName%%
%%Title%% | Your Company
%%PhoneNumber%% | %%Email%%
yourcompany.com

``` ### Limitations of transport rules - The signature is appended to every external email, including replies. This can look repetitive in long email threads. There is no built-in way to add the signature only to the first message in a conversation. - The signature does not appear in the sender's compose window. They will not see it while writing the email; it is added after they click Send. This can confuse employees who expect to see the signature in their draft. - If an employee's directory profile is incomplete (missing title or phone number), those fields will appear blank in the signature. Transport rules work well for offices of 5 to 25 people that want consistency without paying for third-party tools. The trade-off is the lack of reply-only control and the fact that employees cannot preview the signature while composing. ## Option 3: Third-party signature management tools For larger teams or businesses that need more control, third-party signature management tools provide the best experience. Popular options include Exclaimer, CodeTwo, and Opensense. These tools offer: - **Visual signature editor**: Design signatures in a drag-and-drop editor without writing HTML - **Automatic directory sync**: Pull employee details from Entra ID automatically and keep them in sync - **Cross-platform consistency**: Apply signatures across desktop, web, and mobile with no gaps - **Reply intelligence**: Add the full signature to the first email in a conversation and a shorter version on replies - **Campaign banners**: Add promotional banners, event announcements, or legal notices to signatures across the entire company with a single change - **Signature preview**: Employees see their correct signature in the compose window The cost is typically $1 to $3 per user per month. For businesses over 15 people, businesses with compliance requirements, or businesses that want campaign banners, the investment is worth it. ## Designing an effective email signature Regardless of which deployment method you choose, the signature itself should follow these guidelines: **Keep it concise.** Include name, title, company name, phone number, email address, and website. That is it. Every additional element (social media icons, inspirational quotes, multiple logos) adds visual clutter and increases the chance of rendering problems across email clients. **Size your logo appropriately.** Keep the logo file under 10 KB and size it to no more than 150 pixels wide. Large images cause emails to load slowly and may trigger spam filters. Host the logo at a public URL rather than embedding it as an attachment, which adds to email size and can display inconsistently. **Use web-safe fonts.** Stick to Arial, Verdana, Georgia, or other web-safe fonts. Custom fonts will not render in most email clients and will fall back to defaults, breaking your carefully designed layout. **Include required disclaimers.** If your industry requires confidentiality notices, regulatory disclosures, or legal disclaimers, add them below the signature in a smaller font. Check with your legal or compliance team for the exact language. **Skip the extras.** Animated GIFs, multiple social media icons, large banner images, and inspirational quotes all detract from the professional appearance of your email and increase the likelihood of deliverability issues. ## Ensuring directory profiles are complete Both transport rules and third-party tools pull employee data from Entra ID (formerly Azure AD) directory profiles. If a profile is missing a phone number or job title, the signature will have blank fields or broken formatting. Before deploying a centralized signature, audit every user's profile: 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Users** > **Active users** 2. Click on each user's name 3. Click the **Account** tab and verify the following fields are filled in: - **Display name** - **Job title** - **Department** - **Office phone** - **Mobile phone** (if used in the signature) 4. Click **Save changes** after updating For a team of 20 or more, updating profiles one by one is tedious. Admins can use PowerShell or a CSV import through the admin center to bulk-update user profiles. Go to **Users** > **Active users** > **Export users** to download a CSV, make your edits, and re-import. ## Need help? Getting email signatures right across your whole team takes more coordination than most businesses expect. If you want help designing, building, and deploying a consistent signature for your organization, [contact Athencia](/contact). We handle signature deployment as part of our Microsoft 365 setup process. #### How to Set Up a Shared Mailbox in Microsoft 365 for Your Team > Guide to creating and configuring a shared mailbox in Microsoft 365 so multiple team members can send and receive email from a common address. URL: https://athencia.com/kb/microsoft-365/how-to-set-up-a-shared-mailbox-in-microsoft-365-for-your-team A shared mailbox lets multiple people read and send email from a common address like info@yourcompany.com or support@yourcompany.com without needing an extra license. Creating one takes about five minutes in the Microsoft 365 admin center. ## What you need - **Global Administrator** or **Exchange Administrator** access to Microsoft 365 - The email address you want for the shared mailbox (e.g., info@, support@, sales@) - A list of users who need access ## Shared mailbox vs. distribution group These solve different problems. Pick the wrong one and you will end up reconfiguring later. | | Shared Mailbox | Distribution Group | |---|---|---| | **Use when** | Multiple people need to send and reply *from* the same address | You need to forward incoming email to a group of people | | **Shared inbox** | Yes: everyone sees the same inbox and sent items | No: each person receives a copy in their own inbox | | **Reply behavior** | Replies come from the shared address (e.g., support@) | Each person replies from their own address | | **License required** | No (up to 50 GB) | No | | **Common examples** | info@, support@, billing@, hr@ | allstaff@, marketing-team@, leadership@ | If you need a shared inbox where the team collaborates on replies, use a shared mailbox. If you just need to broadcast messages to a group, use a distribution group. ## Step 1: Create the shared mailbox 1. Sign in to the [Microsoft 365 admin center](https://admin.microsoft.com) 2. In the left sidebar, go to **Teams & groups** > **Shared mailboxes** 3. Click **+ Add a shared mailbox** 4. Enter a **Display name** (e.g., "Athencia Support") 5. Enter the **Email address** (e.g., support@yourcompany.com) 6. Click **Save changes** The mailbox is created immediately. No license is needed. Shared mailboxes are free and include 50 GB of storage. If you need more than 50 GB, you can assign an Exchange Online license to the shared mailbox later. ## Step 2: Add members Members are the users who can read and send email from the shared mailbox. 1. After creating the mailbox, you will see it listed on the Shared mailboxes page 2. Click the shared mailbox name to open its settings 3. Under **Members**, click **Edit** 4. Click **+ Add members** 5. Select the users who need access and click **Save** ### Understanding permission types When you add a member through the admin center, they get **Full Access** and **Send As** permissions by default. Here is what each means: - **Full Access**: The user can open the shared mailbox and read, delete, and organize messages inside it. The mailbox appears in their Outlook automatically. - **Send As**: The user can compose new messages that appear to come *from* the shared mailbox address. The recipient sees "support@yourcompany.com" as the sender with no indication it came from an individual. - **Send on Behalf** (not granted by default): The message shows "User Name on behalf of support@yourcompany.com." This is useful when you want recipients to know which individual sent the message. To grant this, use the Exchange admin center or PowerShell. For most teams, the default Full Access + Send As permissions are what you want. ## Step 3: Access the shared mailbox in Outlook ### Outlook desktop (Windows/Mac) The shared mailbox should appear automatically in the left folder pane within 15–60 minutes of being added as a member. If it does not appear: 1. Close and reopen Outlook 2. If it still does not appear, add it manually: - Click **File** > **Account Settings** > **Account Settings** - Select your email account and click **Change** - Click **More Settings** > **Advanced** tab - Click **Add** and enter the shared mailbox email address - Click **OK** through the dialogs and restart Outlook ### Outlook on the web 1. Sign in to [outlook.office.com](https://outlook.office.com) with your own account 2. Right-click **Folders** in the left sidebar 3. Select **Add shared folder** 4. Type the shared mailbox email address and click **Add** The shared mailbox will appear as a separate mailbox in your folder list. ### Outlook mobile (iOS/Android) The Outlook mobile app does not display shared mailboxes as a separate folder the way desktop Outlook does. To access it on mobile: 1. Open the Outlook app 2. Tap your profile icon in the top left 3. Tap the **+** (add account) icon 4. Select **Add a Shared Mailbox** 5. Enter the shared mailbox email address This adds the shared mailbox as a separate account you can switch to. You will not see it merged into your primary inbox. ## Step 4: Configure sent items By default, when a user sends a message from a shared mailbox, the sent message is saved in the *user's* personal Sent Items folder, not the shared mailbox's Sent Items. This means other team members cannot see what has been sent, which defeats the purpose of a shared mailbox. To fix this: 1. Sign in to the [Exchange admin center](https://admin.exchange.microsoft.com) 2. Go to **Recipients** > **Mailboxes** 3. Click the shared mailbox name 4. Click **Delegation** 5. Under **Sent Items**, enable both: - **Copy sent items to the shared mailbox's Sent Items folder for Send As** - **Copy sent items to the shared mailbox's Sent Items folder for Send on Behalf** 6. Click **Save** After enabling this, sent messages will appear in both the user's personal Sent Items and the shared mailbox's Sent Items. This gives the entire team visibility into what has been sent. ## Step 5: Set up auto-replies (optional) If the shared mailbox receives inquiries from customers or vendors, you may want an auto-reply to confirm receipt. 1. In the Exchange admin center, go to **Recipients** > **Mailboxes** 2. Click the shared mailbox 3. Click **Mail flow settings** 4. Under **Automatic replies**, click **Manage** 5. Toggle on **Send automatic replies** 6. Enter your message (e.g., "Thank you for reaching out. Our team will respond within one business day.") 7. Set date ranges if you only want auto-replies during specific periods 8. Click **Save** ## Common issues | Issue | Cause | Fix | |-------|-------|-----| | Shared mailbox not showing in Outlook | Auto-mapping can take up to 60 minutes | Restart Outlook, or add it manually (see Step 3) | | "You don't have permission to send from this address" | User has Full Access but not Send As permission | Grant Send As permission in the Exchange admin center under the mailbox's Delegation settings | | Sent messages not visible to the team | Sent Items saving to user's personal folder | Enable sent item copying in Exchange admin center (see Step 4) | | Mailbox full (50 GB limit) | Shared mailbox hit the free storage cap | Either clean up old mail, or assign an Exchange Online Plan 2 license to increase storage to 100 GB | | Cannot log in directly to the shared mailbox | Shared mailboxes do not support direct sign-in by design | Access it through a member's Outlook (see Step 3). Do not try to sign in with the shared mailbox credentials | ## Need help? If you run into issues setting up or managing shared mailboxes, [contact Athencia](/contact). We handle Microsoft 365 configuration as part of every onboarding. #### How to Set Up Multi-Factor Authentication in Microsoft 365 > A step-by-step guide to enabling multi-factor authentication (MFA) across your Microsoft 365 tenant to protect against unauthorized access. URL: https://athencia.com/kb/microsoft-365/how-to-set-up-multi-factor-authentication-in-microsoft-365 ## Why MFA matters Multi-factor authentication (MFA) is the single most effective control you can deploy to prevent unauthorized account access. Microsoft reports that MFA blocks over 99.9% of automated account compromise attacks. If your organization uses Microsoft 365 without MFA, you are leaving the front door open. MFA works by requiring a second form of verification beyond a password. Even if an attacker obtains a user's password through phishing or a data breach, they cannot access the account without the second factor. ## Before you start You need the following to complete this setup: - **Global Administrator** or **Authentication Administrator** role in Microsoft Entra ID (formerly Azure AD) - Access to the [Microsoft Entra admin center](https://entra.microsoft.com) - A plan for communicating the change to your users before enforcement ## Option 1: Security defaults (recommended for most small businesses) Security Defaults is Microsoft's built-in baseline that enforces MFA for all users. It is the fastest way to enable MFA across your entire tenant. ### Steps 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) 2. Navigate to **Identity** > **Overview** > **Properties** 3. Select **Manage security defaults** 4. Set the toggle to **Enabled** 5. Click **Save** ### What security defaults enforce - MFA registration for all users within 14 days - MFA challenge on every sign-in from a new device or location - Blocking of legacy authentication protocols (IMAP, POP3, SMTP basic auth) - Requiring MFA for all administrative actions ### Limitations Security Defaults do not allow you to exclude specific users, configure trusted locations, or use Conditional Access policies. If you need that level of control, use Option 2. ## Option 2: Conditional access policies (for more control) Conditional Access gives you granular control over when and how MFA is required. This requires Microsoft Entra ID P1 licensing, which is included with Microsoft 365 Business Premium. Athencia deploys Business Premium for all managed clients specifically because it includes Conditional Access, Intune, and Defender for Office 365. Business Basic and Business Standard do not include Conditional Access, so organizations on those tiers are limited to Security Defaults. ### Steps 1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) 2. Navigate to **Protection** > **Conditional Access** > **Policies** 3. Click **+ New policy** 4. Name the policy (e.g., "Require MFA for all users") 5. Under **Assignments** > **Users**, select **All users** 6. Under **Assignments** > **Target resources**, select **All cloud apps** 7. Under **Grant**, select **Require multifactor authentication** 8. Set **Enable policy** to **On** 9. Click **Create** ### Recommended additions - **Exclude a break-glass admin account** from the policy so you are never locked out - **Add a trusted location** for your office network to reduce MFA prompts for on-site work - **Require compliant devices** in addition to MFA for sensitive applications ## Helping your users through the transition Rolling out MFA without communication causes frustration and support tickets. Here is a practical rollout approach: 1. **Notify users 1 week before enforcement.** Explain what is changing and why. 2. **Send setup instructions** with screenshots of the Microsoft Authenticator app installation process. 3. **Allow a registration window.** Security Defaults give users 14 days to register. 4. **Designate an internal point of contact** for questions during the first week. ### Recommended authenticator apps - **Microsoft Authenticator** (preferred for Microsoft 365 environments) - Google Authenticator - Authy Hardware security keys (FIDO2) are the strongest option for high-value accounts. YubiKey is the most common choice. For password management alongside MFA, 1Password pairs well with any authenticator setup. It stores passwords securely and can generate strong, unique passwords for every service. Athencia includes 1Password in its [Athencia One Complete](/athencia-one-complete) package and offers it as an add-on for Athencia One clients. ## Verifying MFA is active After enabling MFA, verify it is working: 1. Go to the [Entra admin center](https://entra.microsoft.com) > **Users** > **All users** 2. Select a user and go to **Authentication methods** 3. Confirm the user has registered at least one MFA method You can also run the **MFA registration report** under **Protection** > **Authentication methods** > **Activity** to see registration status across all users. ## Common issues | Issue | Cause | Fix | |-------|-------|-----| | User cannot register for MFA | Legacy browser or blocked pop-ups | Use Edge or Chrome, allow pop-ups for microsoft.com | | MFA prompt on every sign-in | No trusted device or location configured | Add office IP as trusted location in Conditional Access | | App passwords not working | Legacy apps using basic auth | Migrate to modern authentication or create app-specific passwords | | Locked out after phone loss | No backup method registered | Use break-glass account to reset; require backup methods during registration | ## Summary Enabling MFA is the highest-impact security action you can take for your Microsoft 365 environment. Security Defaults work well for most small businesses. Organizations needing granular control should use Conditional Access policies. Either way, communicate the change to your users before enforcing it. MFA protects against password-based attacks, but it is one layer in a broader security stack. Athencia pairs MFA with Huntress Managed ITDR, which monitors identity-based threats across your Microsoft Entra ID environment around the clock. If an attacker bypasses MFA through token theft, session hijacking, or social engineering, Huntress's 24/7 SOC team detects and responds to the threat in real time. If you need help configuring MFA or rolling it out across your organization, [contact Athencia](/contact). We handle this as part of every onboarding. #### How to Share Files Securely with Clients Using Microsoft Teams > Guide to sharing files and collaborating with external clients in Microsoft Teams without exposing your internal data or creating security risks. URL: https://athencia.com/kb/microsoft-365/how-to-share-files-securely-with-clients-using-microsoft-teams Microsoft Teams lets you share files and collaborate with people outside your organization without giving them access to your internal systems. Setting up external sharing correctly ensures clients get what they need while your internal data stays protected. This guide walks through each method, the admin settings that control it, and the security practices that keep your business safe. ## What you need - Microsoft 365 admin access to configure external sharing policies - Understanding of your organization's current external access settings - A clear picture of what you need to share and with whom ## Understanding external access vs. guest access Microsoft Teams has two separate mechanisms for working with people outside your organization. Picking the right one avoids confusion and security mistakes. **External access** allows chat and calls with people in other Microsoft 365 organizations. They stay in their own tenant and use their own Teams app. They cannot see your channels, files, or internal conversations. Use this for quick one-on-one communication where you do not need to share files or collaborate on documents. **Guest access** invites an external person into a specific Team or channel within your tenant. They can see the files, conversations, and shared resources within that specific channel. They cannot see other channels or Teams unless you explicitly add them. Use this for ongoing project collaboration where you need to share files, track conversations, and work together in a shared space. Neither option gives external users access to your entire tenant. Both are scoped to what you explicitly grant. ## Step 1: Check your tenant's external sharing settings Before inviting any external users, verify that your admin settings allow the type of sharing you need. There are two admin centers to check. ### Teams admin center 1. Go to [admin.teams.microsoft.com](https://admin.teams.microsoft.com) 2. In the left sidebar, click **Users** > **External access** 3. Review the settings. The default allows communication with all external Microsoft 365 organizations. You can restrict this to specific domains if you only work with known partners. 4. Next, click **Users** > **Guest access** 5. Verify that **Allow guest access in Teams** is set to **On** 6. Review the individual permissions for guests: calling, meeting, and messaging capabilities ### SharePoint admin center File sharing through Teams relies on SharePoint's external sharing settings. If SharePoint sharing is restricted, Teams file sharing will be blocked too. 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Admin centers** > **SharePoint** 2. Click **Policies** > **Sharing** 3. Set the SharePoint external sharing level. For most businesses, **New and existing guests** provides the right balance of accessibility and control. Avoid **Anyone** (anonymous links) for business files. 4. Under **More external sharing settings**, enable **Guests must sign in using the same account to which sharing invitations are sent** for added security ## Step 2: Create a dedicated channel for client collaboration The safest way to share files with a client is to create a channel specifically for that collaboration. This keeps client-facing work isolated from your internal conversations and files. 1. Open Microsoft Teams and go to the Team that handles client work (e.g., "Operations" or "Client Projects") 2. Click the three dots next to the Team name and select **Add channel** 3. Name the channel clearly (e.g., "Client - Smith Law Firm" or "Project - Website Redesign") 4. Set the privacy to **Standard** (visible to all Team members) or **Private** (visible only to selected members) 5. Click **Add** ### Adding the client as a guest 1. Click the three dots next to the Team name and select **Add member** 2. Enter the client's email address 3. Teams will recognize it as an external address and label them as a **Guest** 4. Click **Add** The client will receive an email invitation. Once they accept and sign in, they can see only the channels you have added them to. They cannot see your other channels, other Teams, or any internal conversations. ### Sharing files in the channel 1. Go to the channel's **Files** tab 2. Click **Upload** to add files, or drag and drop files directly into the tab 3. Both your team and the client can now access, view, and edit the files in this channel 4. All activity is logged, so you have an audit trail of who uploaded, edited, or downloaded each file This is better than emailing files back and forth for several reasons: everyone works on the same version, you have a complete conversation history alongside the files, and you can revoke access at any time by removing the guest from the Team. ## Step 3: Use SharePoint sharing links for one-off files When you need to share a single file without adding someone as a guest to your entire Team, SharePoint sharing links give you precise control. 1. In Teams, navigate to the file you want to share 2. Right-click the file and select **Share** or click the **Share** button 3. Click **People you specify** (do not use "Anyone with the link" for business files) 4. Enter the client's email address 5. Set permissions: **Can edit** or **Can view** 6. Optionally, set an **expiration date** on the link. This is recommended for sensitive files so the link stops working after the project is complete. 7. Optionally, set a **password** on the link for an additional layer of protection 8. Click **Send** The client receives an email with the link. They sign in with their email address to access the file. If they do not have a Microsoft account, they will be prompted to verify their identity through a one-time passcode sent to their email. Avoid using "Anyone with the link" sharing for business files. These links can be forwarded to anyone and are impossible to audit. "People you specify" ensures only the intended recipient can access the file. ## Step 4: Apply sensitivity labels to control what recipients can do If your organization uses Microsoft 365 Business Premium, you have access to sensitivity labels that control what recipients can do with your files after you share them. This is important for legal documents, financial data, or confidential project materials. Sensitivity labels can: - Prevent recipients from downloading or printing the file (view-only in the browser) - Prevent forwarding or copying content - Add watermarks to documents - Encrypt the file so only authorized recipients can open it - Automatically expire access after a set period To apply a sensitivity label: 1. Open the file in Word, Excel, PowerPoint, or the Teams Files tab 2. Click **Sensitivity** in the toolbar (or the shield icon) 3. Select the appropriate label (e.g., "Confidential - External Sharing Allowed" or "Highly Confidential - View Only") 4. Save the file Your admin configures the available sensitivity labels in the Microsoft Purview compliance portal. Athencia deploys Microsoft 365 Business Premium for all managed clients, which includes the licensing for sensitivity labels. Business Basic and Business Standard do not include this capability. ## Step 5: Set up guest access policies with conditional access For organizations on Microsoft 365 Business Premium, Conditional Access policies in Entra ID can enforce security requirements for guest users, not just your internal team. Useful policies for guest access include: - **Require MFA for all guest sign-ins**: Guests must verify their identity with a second factor every time they access your resources. This prevents a compromised client email account from accessing your files. - **Block guest access from specific countries**: If your clients are all domestic, block guest sign-ins from countries where you have no business relationships. - **Require terms of use acceptance**: Present guests with a terms-of-use agreement before they can access shared resources. To create a guest-specific Conditional Access policy: 1. Go to [entra.microsoft.com](https://entra.microsoft.com) > **Protection** > **Conditional Access** > **Policies** 2. Click **+ New policy** 3. Under **Users**, select **Guest or external users** 4. Under **Target resources**, select **All cloud apps** 5. Under **Grant**, select **Require multifactor authentication** 6. Set the policy to **Report-only** first to test, then switch to **On** after reviewing the results 7. Click **Create** ## Security best practices for external sharing **Review guest access quarterly.** Go to [entra.microsoft.com](https://entra.microsoft.com) > **Identity** > **Users** > **All users** and filter by user type "Guest." Remove any guests who no longer need access. Stale guest accounts are a common security blind spot. **Set expiration policies for guest accounts.** Configure automatic expiration so guests lose access after 90 days of inactivity. Go to **Identity** > **External Identities** > **External collaboration settings** to configure this. **Disable guest access for internal-only Teams.** If a Team contains purely internal information, go to the Team settings and disable guest permissions for that specific Team. **Never share files through personal OneDrive or consumer cloud services.** Files shared outside the company should go through SharePoint or Teams, where your organization retains control, visibility, and audit trails. **Monitor external sharing activity.** The SharePoint admin center includes an external sharing report under **Reports** > **Sharing**. Review this monthly to catch unexpected sharing or overly broad permissions. ## Common issues | Issue | Cause | Fix | |-------|-------|-----| | "External sharing is disabled" error | SharePoint or Teams admin settings block external sharing | Check both the Teams admin center and SharePoint admin center sharing settings (see Step 1) | | Client cannot access shared files | They have not accepted the guest invitation email | Ask the client to check their inbox (including spam folder) for the invitation and accept it | | Client sees too many channels | They were added to the Team, not a specific channel | Remove them and re-add them to only the channels they need access to | | Shared links expire unexpectedly | Organization-wide link expiration policy is set | Check the SharePoint admin center under **Policies** > **Sharing** > **File and folder links** for the default expiration | | Guest cannot edit files | Sharing link was set to "Can view" | Re-share the file with "Can edit" permissions, or update the existing link | ## Need help? Setting up secure external sharing involves coordinating settings across Teams, SharePoint, and Entra ID. If you want help configuring external sharing policies or reviewing your current setup for security gaps, [contact Athencia](/contact). We configure these settings as part of every Microsoft 365 deployment. #### What Is Conditional Access in Microsoft 365 and Why Your Business Needs It > Plain-language explanation of Conditional Access policies in Microsoft 365 and how they protect small businesses by controlling who can access what, from where. URL: https://athencia.com/kb/microsoft-365/what-is-conditional-access-in-microsoft-365-and-why-your-business-needs-it Conditional Access policies in Microsoft 365 automatically enforce security rules based on conditions like who is signing in, where they are signing in from, and what device they are using. Instead of treating every login the same, Conditional Access lets you require extra verification for risky situations while keeping low-risk access smooth for your team. It is one of the most important security features available to small businesses, and most are not using it. ## What you need - **Microsoft 365 Business Premium**, E3, or E5. Conditional Access requires Entra ID P1 licensing, which is included with Business Premium but not with Business Basic or Business Standard. - **Entra ID admin access** (Global Administrator or Conditional Access Administrator role) - An understanding of how your team accesses company resources: from the office, remotely, on mobile devices, or a mix Athencia deploys Microsoft 365 Business Premium for all managed clients specifically because it includes Conditional Access, Microsoft Intune, and Defender for Office 365 at no extra cost. Organizations on Business Basic or Business Standard cannot use Conditional Access and are limited to Security Defaults, which offer far less control. ## How conditional access works Every time someone signs in to Microsoft 365, the sign-in request is evaluated against your Conditional Access policies before access is granted. The policy checks several conditions: - **Who is the user?** An admin, a regular employee, a guest? - **What device are they on?** A company-managed device, a personal phone, an unknown computer? - **Where are they?** Your office network, their home, a coffee shop, another country? - **What app are they accessing?** Outlook, SharePoint, a third-party app connected through single sign-on? - **What is the risk level?** Is this a normal sign-in pattern, or does it look suspicious? Based on those conditions, the policy does one of three things: grants access normally, requires additional verification (like MFA or a compliant device), or blocks access entirely. Think of it as a smart security checkpoint. An employee signing in from a company laptop at the office gets through quickly. That same employee signing in from an unknown device in another country gets asked for extra proof, or gets blocked outright. ## Why business basic and standard are not enough Security Defaults, which are available on all Microsoft 365 plans, enforce MFA for all users and block legacy authentication. That is a solid baseline. But Security Defaults are all-or-nothing. You cannot customize them. With Conditional Access, you can: - Require MFA only when signing in from outside the office - Block access entirely from countries where you have no employees - Require a company-managed device for accessing sensitive applications - Allow mobile access only through protected apps like Outlook and Teams - Apply different rules to admins, regular users, and guests - Enforce device compliance standards through Microsoft Intune None of these are possible with Security Defaults alone. If your business has any remote workers, uses personal devices, or needs to comply with industry regulations, Conditional Access is not optional. ## Common policies for small businesses You do not need dozens of policies. Most small businesses are well served by five or six policies that cover the most important scenarios. ### 1. Require MFA for all users This is the most basic and most important policy. Every sign-in requires a second factor of verification. - **Users**: All users (exclude one break-glass admin account) - **Target resources**: All cloud apps - **Grant**: Require multifactor authentication ### 2. Block sign-ins from untrusted countries If your team only operates in the United States, there is no reason to allow sign-ins from other countries. Blocking foreign sign-ins eliminates a large percentage of automated attacks. - **Users**: All users - **Conditions**: Locations > Include all locations, Exclude your trusted countries - **Grant**: Block access To set up named locations, go to [entra.microsoft.com](https://entra.microsoft.com) > **Protection** > **Conditional Access** > **Named locations** > **+ Countries location**. Select the countries where your employees and clients are located and save. ### 3. Require compliant devices This policy ensures that only devices meeting your organization's security standards can access company data. A compliant device is one enrolled in Microsoft Intune that passes your compliance checks: encryption enabled, operating system up to date, screen lock active, and endpoint protection running. - **Users**: All users - **Target resources**: All cloud apps (or specific sensitive apps) - **Grant**: Require device to be marked as compliant This policy works hand-in-hand with Intune. When you deploy Microsoft 365 Business Premium, Intune is included for device management. Athencia configures Intune compliance policies as part of every [Athencia One](/athencia-one) onboarding, setting the baseline requirements that devices must meet before they are granted access. For endpoint protection, Athencia layers Huntress Managed EDR on top of Microsoft Defender for Business. Defender provides the baseline antivirus and endpoint detection included with Business Premium. Huntress adds a 24/7 Security Operations Center staffed by human threat hunters who investigate and respond to threats that automated tools miss. Together, they ensure that compliant devices are not just configured correctly but actively monitored for threats. ### 4. Block legacy authentication Legacy authentication protocols like POP3, IMAP, and SMTP basic auth do not support MFA. Attackers exploit these protocols to bypass MFA entirely. Blocking them closes one of the most common attack vectors. - **Users**: All users - **Conditions**: Client apps > Select **Exchange ActiveSync clients** and **Other clients** - **Grant**: Block access Before enabling this, verify that no employees are using legacy email clients or apps that rely on basic authentication. Most modern apps (Outlook desktop, Outlook mobile, Thunderbird with OAuth) use modern authentication and will not be affected. ### 5. Require app protection on mobile devices For employees who access company email and files on personal phones, this policy restricts access to managed apps like Outlook and Teams. Company data stays within those protected apps and cannot be copied to personal apps or saved to unmanaged storage. - **Users**: All users - **Conditions**: Device platforms > iOS, Android - **Target resources**: Office 365 - **Grant**: Require approved client app or require app protection policy This uses Intune App Protection Policies, which protect company data on the device without requiring full device enrollment. The employee's personal photos, messages, and apps are untouched. Only company data within managed apps is controlled. ### 6. Require MFA for guest users External guests who access your Teams channels, SharePoint sites, or shared files should be held to the same MFA standard as your internal team. A compromised client email account should not be able to walk into your environment unchallenged. - **Users**: Guest or external users - **Target resources**: All cloud apps - **Grant**: Require multifactor authentication ## Setting up your first conditional access policy Here is the step-by-step process for creating a policy in the Entra admin center. 1. Sign in to [entra.microsoft.com](https://entra.microsoft.com) 2. In the left sidebar, navigate to **Protection** > **Conditional Access** > **Policies** 3. Click **+ New policy** 4. Enter a clear, descriptive name (e.g., "Require MFA - All Users" or "Block Legacy Auth") 5. Under **Assignments** > **Users**, select the users or groups the policy applies to. Start with a test group of a few users, not your entire organization. 6. Under **Assignments** > **Target resources**, select **All cloud apps** or specific apps 7. Under **Conditions**, set any conditions (locations, device platforms, client apps) 8. Under **Access controls** > **Grant**, choose the action: Require MFA, Require compliant device, Block access, etc. 9. Set **Enable policy** to **Report-only** 10. Click **Create** Report-only mode is critical. It lets you see exactly which sign-ins would be affected by the policy without actually blocking anyone. Leave it in report-only mode for at least one week before switching to On. ## Why report-only mode matters Turning on a Conditional Access policy without testing it first can lock out your entire team. Report-only mode prevents this by simulating the policy without enforcing it. While a policy is in report-only mode: - Every sign-in is evaluated against the policy - The sign-in logs show whether the policy would have been applied (and what the result would have been) - No users are actually blocked or prompted for additional verification To review report-only results: 1. Go to [entra.microsoft.com](https://entra.microsoft.com) > **Identity** > **Monitoring & health** > **Sign-in logs** 2. Click on any sign-in event 3. Under the **Conditional Access** tab, you will see each policy and whether it would have applied Look for unexpected impacts: service accounts that would be blocked, shared devices that cannot satisfy compliance requirements, conference room accounts, or third-party integrations that use basic authentication. Fix these before switching the policy to On. ## The break-glass account Every organization using Conditional Access must have at least one emergency access account (commonly called a break-glass account). This is a Global Administrator account that is excluded from all Conditional Access policies. Why? If a policy misconfiguration locks out every admin, you need a way to sign in and fix it. Without a break-glass account, you would need to contact Microsoft support, which can take hours or days. Break-glass account best practices: - Use a strong, random password stored securely (1Password is a good option for this; Athencia includes 1Password in its [Athencia One Complete](/athencia-one-complete) package) - Do not assign it to a real person - Exclude it from all Conditional Access policies - Enable alerts for when this account signs in (any sign-in on this account should be investigated) - Do not enable MFA on this account (that defeats its purpose as a fallback) ## Common mistakes **Locking yourself out.** Always exclude a break-glass account from every Conditional Access policy. Test in report-only mode first. **Not testing in report-only mode.** Enforcing an untested policy can block your entire team, including all admins. Always run in report-only for at least a week. **Being too restrictive too fast.** Start with MFA for all users. Once that is stable, add device compliance. Then add location restrictions. Layering policies incrementally gives you time to identify and fix problems. **Forgetting service accounts.** Automated processes, scheduling tools, and service accounts may fail if they cannot satisfy MFA or device compliance requirements. Identify these accounts and either exclude them from specific policies or configure them to use managed identities. **Not blocking legacy authentication.** This is one of the most exploited gaps in Microsoft 365 security. Even with MFA enforced, attackers can authenticate through POP3 or IMAP, which do not support MFA. Block legacy auth early. **Ignoring identity threats after deployment.** Conditional Access sets the rules, but it does not actively hunt for identity-based attacks. Huntress Managed ITDR layers on top of Entra ID to monitor for credential theft, token replay attacks, and other identity threats around the clock. Conditional Access controls the front door; Huntress watches for intruders who find a way around it. ## Need help? Conditional Access is powerful, but getting the policies right requires understanding your team's access patterns, device landscape, and compliance needs. If you want help designing and deploying Conditional Access policies for your business, [contact Athencia](/contact). We configure Conditional Access as part of every managed client onboarding. ### Networking #### How to Choose the Right Internet Plan for Your Small Office > Guide to selecting a business internet plan based on employee count, usage patterns, and reliability needs, with bandwidth calculations for common scenarios. URL: https://athencia.com/kb/networking/how-to-choose-the-right-internet-plan-for-your-small-office Choosing the right internet plan for your office means matching your bandwidth to your actual usage without overpaying for speed you don't need or underpaying for a connection that slows everyone down. Most small offices need more bandwidth than they think, especially once you factor in video conferencing, cloud file storage, and SaaS applications that everyone uses at the same time. This guide walks you through how to calculate your real bandwidth needs, compare connection types, and decide whether you need a backup connection. ## What you'll need to know before shopping Before you call an ISP or compare plans online, gather these four pieces of information: **Number of simultaneous users.** Count the employees who are actively online at the same time during your busiest hour. If you have 20 employees but only 15 are typically at their desks using the internet at once, plan for 15. **Primary usage patterns.** Think about what your team actually does online throughout the day. Email and basic web browsing use very little bandwidth. Video conferencing on Microsoft Teams or Zoom uses significantly more, especially when multiple people are in meetings at the same time. Cloud-based applications like Microsoft 365, accounting software, and CRM platforms fall somewhere in between. Large file transfers, such as uploading design files or syncing shared folders, can spike your bandwidth usage unpredictably. **Upload speed requirements.** If your team does a lot of video conferencing or uploads large files to cloud storage, upload speed matters just as much as download speed. Many cable internet plans advertise fast download speeds but offer upload speeds that are a fraction of the download rate. A plan advertising 500 Mbps download may only include 20 Mbps upload, which becomes a bottleneck quickly. **Tolerance for downtime.** Consider what happens to your business when the internet goes down. If your phone system runs over the internet (VoIP), your cloud applications are inaccessible, and your team cannot work, even an hour of downtime costs real money. That changes the kind of plan and backup strategy you should invest in. ## How much bandwidth do you actually need Here is a simple framework for estimating your bandwidth needs based on what your team does: **Basic office work** such as email, web browsing, and light cloud app usage requires about 5 to 10 Mbps per employee. **Regular video conferencing** on platforms like Microsoft Teams or Zoom pushes that to 10 to 15 Mbps per employee. **Heavy cloud usage**, including large file uploads, cloud-based design tools, or constant streaming, requires 15 to 25 Mbps per employee. To calculate your target plan, multiply the per-employee number by your simultaneous user count, then add 20 to 30 percent headroom for spikes. For example, an office with 15 employees who regularly use video conferencing would calculate: 15 employees times 12 Mbps equals 180 Mbps. Adding 30 percent headroom brings the target to roughly 250 Mbps. That means a 250 or 300 Mbps business plan would be appropriate. One detail people often overlook: if your business uses Microsoft 365 Business Premium and your team is actively collaborating in SharePoint, OneDrive, and Teams throughout the day, all of that traffic adds up. Plan for the higher end of the range if cloud collaboration is central to your workflow. ## Business internet vs. residential internet Business internet plans typically cost $20 to $50 more per month than residential plans at the same speed tier. That premium buys you several things that matter for a business: **Service Level Agreement (SLA).** Business plans include a contractual guarantee for uptime, usually 99.9 percent, and a committed repair response time. If your internet goes down on a residential plan, you go into the same support queue as everyone else. On a business plan, you get priority response. **Higher upload speeds.** Business plans, especially fiber, often offer symmetric speeds, meaning your upload speed matches your download speed. This is critical for video conferencing and cloud file uploads. **Static IP address.** A static IP is important if you run a VPN for remote access, host anything on-premises, or need consistent connectivity for security cameras or other IP-based systems. **No data caps.** Many residential plans have data caps that you might not notice at home but can easily exceed in an office with 10 or more people. **Priority support.** When something goes wrong, you speak to a business support team rather than waiting in a general consumer queue. The price difference is small relative to the cost of a slow or unreliable connection affecting your entire team's productivity. ## Connection types compared **Fiber** is the best option if it is available at your location. Fiber provides symmetric speeds (same upload and download), the lowest latency, and the highest reliability. Plans range from 100 Mbps to 10 Gbps. If fiber is available, choose it. **Cable** is widely available and offers good download speeds, but upload speeds are typically one-tenth of the download speed. Cable bandwidth is shared with other users in your area, which means you may experience slowdowns during peak hours. Cable works well for small offices, but the upload limitation can be a problem for teams that rely heavily on video conferencing. **DSL** is legacy technology. Speeds degrade with distance from the provider's equipment, and maximum speeds are generally too low for offices with more than five people. Avoid DSL unless there is truly no other option. **Fixed wireless and 5G** are good alternatives in areas without fiber or cable. Latency can be higher than wired connections, and some plans have data caps, so check the fine print. Performance continues to improve as carriers expand 5G coverage. **Satellite** is a last resort. The high latency makes video conferencing unreliable and VPN connections sluggish. Satellite is only appropriate for very rural locations with no other options. The priority order is straightforward: fiber first, cable second, fixed wireless or 5G third. ## Do you need a backup internet connection Ask yourself this question: if your internet goes down for four hours, what happens to your business? If the answer is that your team sits idle, your phones stop working, and you lose access to every application, a backup connection is worth the investment. There are a few practical options for backup connectivity. The simplest is a cellular failover device, which is a small piece of hardware that automatically switches your office to a cellular data connection when the primary internet goes down. These typically cost $30 to $60 per month for a data plan and provide enough bandwidth to keep email, cloud apps, and VoIP running during an outage. A more resilient approach is a secondary ISP on a different technology. For example, if your primary connection is fiber, use cable as your backup. Many business-grade firewalls support automatic failover between two internet connections, so the switch happens without anyone needing to do anything. At minimum, have a documented plan for what your team does when the internet goes down. If your team uses Microsoft 365 Business Premium and devices managed through Intune, employees can switch to working from home or mobile hotspots while the office connection is restored, since their access to cloud resources is tied to their identity rather than the office network. ## Questions to ask your ISP When comparing plans or negotiating with an ISP, ask these specific questions: 1. Is there a data cap, and what happens if you exceed it? Some ISPs charge overage fees; others throttle your speed. 2. What is the upload speed, not just the download speed? Get the exact number, not a vague "up to" figure. 3. Is the IP address static or dynamic? If you need a static IP, confirm it is included or ask about the additional cost. 4. What is the SLA for uptime and what is the guaranteed repair response time? 5. Is the quoted price a promotional rate? If so, what does it increase to after the promotional period, and when does that happen? 6. What is the installation timeline and cost? Some business fiber installations take weeks and may involve construction fees. 7. Are there early termination fees if you need to cancel or switch providers? Getting clear answers to these questions before you sign a contract will save you from surprises later. ## Need help? Choosing the right internet plan can feel overwhelming, especially when ISPs make it hard to compare apples to apples. If you want a second opinion on your options or need help evaluating your current setup, [contact Athencia](/contact). We help small businesses get the right connectivity without overpaying. #### How to Set Up a Separate Guest Wi-Fi Network for Your Office > Guide to creating a guest Wi-Fi network that keeps visitors online while protecting your business network and devices from unauthorized access. URL: https://athencia.com/kb/networking/how-to-set-up-a-separate-guest-wifi-network-for-your-office A separate guest Wi-Fi network gives visitors internet access without exposing your business computers, file shares, printers, and internal systems. Without one, every device that connects to your office Wi-Fi can potentially see and communicate with every other device on the same network. That means a client's laptop, a vendor's phone, or a job candidate's tablet could be sitting on the same network as your accounting software and shared files. Setting up a guest network is straightforward on most business-grade routers and access points. This guide walks you through the process step by step. ## Why a separate guest network matters The core issue is simple: any device on your main Wi-Fi network can potentially discover and communicate with other devices on that same network. That includes your file servers, printers, point-of-sale systems, and every employee's computer. A guest who connects to your main network with an infected laptop could spread malware to your business machines without anyone realizing it. Even without malicious intent, a visitor running a network scanner or file-sharing software could accidentally expose your internal resources. A properly configured guest network uses network isolation to ensure that visitor devices can reach the internet but cannot see or communicate with anything on your business network. This is not just a best practice; many compliance frameworks, including PCI-DSS and HIPAA, require network segmentation as a baseline security control. ## What you'll need Before you start, confirm you have the following: **A business-grade router or access point that supports VLANs or guest network isolation.** Most business-grade equipment from brands like Ubiquiti, Meraki, FortiGate, and SonicWall supports this. Consumer routers from Best Buy or Amazon often lack proper guest isolation, which is one of several reasons they are not suitable for business use. **Access to your router's admin interface.** You will need the IP address of the router (commonly 192.168.1.1 or 192.168.0.1) and the admin login credentials. If you do not know these, check the label on the device or contact your IT provider. **A plan for the guest network name and password.** Choose a network name (SSID) that is clearly identifiable as a guest network, such as "YourCompany-Guest." Pick a password that is easy to share with visitors but completely different from your main network password. ## Step 1: Access your router's admin interface Open a web browser on a computer connected to your office network and type your router's IP address into the address bar. Log in with your admin credentials. If you are using a cloud-managed platform like Ubiquiti's UniFi or Cisco Meraki, log in to the cloud dashboard instead. For UniFi, navigate to **unifi.ui.com** and sign in. For Meraki, go to **dashboard.meraki.com**. Once logged in, look for a section labeled **Wireless**, **Wi-Fi**, **Networks**, or **SSIDs** depending on your hardware. This is where you will create the guest network. ## Step 2: Create the guest SSID Create a new wireless network with a name like "YourCompany-Guest." In most router interfaces, you will find a button labeled **Add Network**, **Create SSID**, or **Add Wireless Network**. Set the security type to **WPA3** if your equipment supports it, or **WPA2** as a minimum. Never leave a guest network open and unsecured, even though it might seem more convenient for visitors. An open network allows anyone within range to connect without a password, which is a security and liability risk. Choose a password that is simple enough to share verbally or print on a card, but not something obvious like "guest123" or your company name. Something like "Welcome2Office" is easy to communicate and reasonably secure for a guest network. ## Step 3: Enable network isolation This is the most important step. Creating a separate SSID alone does not isolate the guest network from your business network. You need to enable isolation settings so guest devices cannot communicate with your internal resources. Look for settings labeled **Client Isolation**, **AP Isolation**, **Guest Policies**, or **VLAN Assignment** in your router's configuration. Enable these options: **Client isolation** prevents guest devices from communicating with each other. This stops a compromised device from scanning or attacking other guest devices. **Network isolation** (sometimes called VLAN isolation or guest network isolation) prevents the guest network from routing traffic to your internal business network. The guest network should only have a path to the internet. On many business-grade systems, the proper way to do this is to assign the guest SSID to a separate VLAN with its own subnet. For example, your business network might be on VLAN 1 (192.168.1.x) and your guest network on VLAN 10 (192.168.10.x), with firewall rules blocking traffic between the two. **How to verify it works:** Connect a phone to the guest network and try to access a device on your main network, such as a shared printer or file server. If the isolation is working correctly, you should not be able to reach it. ## Step 4: Set bandwidth limits Without bandwidth limits, a single visitor streaming video or downloading large files on your guest network could consume a significant portion of your internet capacity, slowing things down for your entire team. Most business-grade routers allow you to set bandwidth limits on a per-SSID or per-device basis. A reasonable limit for a guest network is 10 to 25 Mbps download per device, depending on your total available bandwidth. If your office has a 250 Mbps internet connection, capping guest devices at 10 to 15 Mbps each ensures visitors can browse the web and check email comfortably without impacting your business traffic. Look for settings labeled **Bandwidth Control**, **Rate Limiting**, **Traffic Shaping**, or **QoS** (Quality of Service) in your router's wireless or network settings. ## Step 5: Post the credentials for visitors Make the guest Wi-Fi information easy for visitors to find without requiring your team to share it individually every time someone visits. Print a small, clean sign for your lobby, conference room, or reception area with the guest network name and password. If your office has multiple meeting rooms, consider placing a card in each one. Change the guest password on a regular schedule. Quarterly is a good baseline for most offices. If your office has high visitor traffic, such as a medical practice or coworking space, monthly is better. When you change the password, update all the printed signs at the same time. Some business routers support a **captive portal**, which displays a terms-of-use page that visitors must accept before gaining internet access. This is a nice-to-have for liability purposes but is not required for most small businesses. ## What about employee personal devices Personal employee phones, tablets, and smartwatches should also connect to the guest network, not your main business network. Only company-managed devices belong on the primary network. If your business uses Microsoft Intune for device management (included with Microsoft 365 Business Premium), Intune can enforce this distinction automatically. Devices enrolled in Intune and marked as compliant can be granted access to the business network, while unenrolled personal devices are directed to the guest network. This keeps the boundary clear without relying on employees to make the right choice. A written BYOD (bring your own device) policy should spell this out: personal devices connect to the guest Wi-Fi, company-managed devices connect to the business Wi-Fi. Keep it simple so there is no ambiguity. ## Common mistakes to avoid **Creating a separate SSID without enabling isolation.** A second Wi-Fi name without VLAN separation or isolation settings gives the appearance of security without actually providing it. Guest devices can still reach your internal network. **Using the same password for guest and business networks.** If they share a password, changing one means changing both, and visitors who know the guest password effectively know the business password. **Forgetting to test isolation after setup.** Always verify by connecting a device to the guest network and confirming it cannot ping or access internal resources. **Skipping bandwidth limits.** A guest network without bandwidth controls is an open invitation for your internet to slow down when multiple visitors are connected. ## Need help? Setting up a properly isolated guest network involves more than just creating a new Wi-Fi name. If you want to make sure your guest network is truly segmented from your business systems, [contact Athencia](/contact) and we will get it configured correctly. #### How to Set Up a VPN for Secure Remote Access to Your Office Network > Guide to setting up a business VPN so employees can securely access office resources like file servers, printers, and internal applications from home. URL: https://athencia.com/kb/networking/how-to-set-up-a-vpn-for-secure-remote-access-to-your-office-network A VPN (Virtual Private Network) creates an encrypted tunnel between a remote employee's device and your office network, allowing them to access internal resources like file servers, printers, and on-premises applications as if they were sitting in the office. Setting up a proper business VPN requires a capable firewall or router, a clear plan for who needs access to what, and the right authentication to keep unauthorized users out. Before diving into the setup steps, it is worth asking whether your business actually needs a traditional VPN at all. Many small businesses have moved entirely to cloud-based tools, which changes the equation significantly. ## Do you actually need a VPN? A VPN is necessary when employees need to reach resources that are physically located in your office: file servers, on-premises line-of-business applications, network printers, or IP-based security camera systems. If people need to access something that lives on your office network, a VPN is the way to get there securely. However, if all of your business applications are cloud-based, you may not need a VPN at all. For businesses running on Microsoft 365 Business Premium, Conditional Access policies through Entra ID can secure access to cloud applications without routing traffic through your office. Instead of tunneling all traffic through a VPN, Conditional Access verifies the user's identity, device compliance (through Intune), and location before granting access to cloud resources like SharePoint, Teams, OneDrive, and email. This approach is simpler to manage and often more secure than a traditional VPN because it does not rely on a single point of entry that an attacker could target. The honest answer for many small businesses is a hybrid: use Conditional Access for cloud applications and a VPN only for the few on-premises resources that still require it. This reduces the load on your VPN, simplifies the employee experience, and keeps your attack surface smaller. ## What you'll need If you do need a VPN, gather the following before you start: **A business-grade firewall or router that supports VPN.** Consumer routers do not have the processing power or security features for business VPN use. Look for hardware from FortiGate, SonicWall, Ubiquiti, or Cisco Meraki. These include built-in VPN server capabilities and the management tools to configure them properly. **A static public IP address from your ISP.** Your VPN clients need a consistent address to connect to. If your ISP only provides a dynamic IP, you can use a dynamic DNS (DDNS) service as an alternative, though a static IP is more reliable. **An identity provider that supports multi-factor authentication (MFA).** If your business uses Microsoft 365, you already have Entra ID, which can serve as your identity provider for VPN authentication. This means employees use their Microsoft 365 credentials and MFA to connect, rather than managing a separate set of VPN passwords. **A list of employees who need remote access and what they need to reach.** Not everyone needs VPN access, and not everyone who needs VPN access needs to reach everything on the network. Define this upfront. ## VPN types for small businesses There are a few different VPN configurations. Understanding the differences will help you choose the right one for your situation. **Client-to-site VPN** is the most common setup for small businesses. Each employee installs a VPN client application on their device (laptop, desktop, or phone), and that client connects them to the office network over an encrypted tunnel. When the employee is done working, they disconnect. **Site-to-site VPN** connects two office networks together permanently. For example, if your company has a main office and a satellite location, a site-to-site VPN links them so devices on either network can communicate as if they were in the same building. This runs continuously and does not require individual employees to connect or disconnect. **SSL VPN** uses standard HTTPS encryption, the same technology that secures online banking. SSL VPN works through virtually any firewall and does not require special network configuration on the employee's side, which makes it the preferred option for most small businesses. Employees can connect from home, coffee shops, or hotels without running into blocked ports. **IPsec VPN** provides strong encryption and is well-suited for site-to-site connections, but it can be more complex to set up for individual users. Some public networks (hotels, airports, conference Wi-Fi) block IPsec traffic, which can prevent employees from connecting. For client-to-site VPN, SSL is usually the better choice. ## Step 1: Configure VPN on your firewall Log in to your firewall's admin interface. The exact navigation varies by manufacturer, but here is the general process: Navigate to the **VPN** section of the firewall's settings. On a FortiGate, this is under **VPN > SSL-VPN Settings**. On a SonicWall, look under **VPN > SSL VPN > Server Settings**. On Ubiquiti, navigate to **Settings > VPN**. Enable the VPN server feature and select your VPN type (SSL VPN is recommended for client-to-site access). Configure the listening interface to use your firewall's public IP address or your dynamic DNS hostname. Set the VPN address pool, which is the range of IP addresses assigned to VPN clients when they connect. This should be a different subnet from your office network. For example, if your office network is 192.168.1.0/24, assign VPN clients to 10.10.10.0/24. Configure split tunneling vs. full tunneling. **Split tunneling** only routes office-bound traffic through the VPN; everything else (web browsing, streaming) goes directly through the employee's home internet. This is faster for the user and reduces load on your office internet connection. **Full tunneling** routes all traffic through the VPN, which gives you more visibility and control but uses more of your office bandwidth. For most small businesses, split tunneling is the practical choice. Require multi-factor authentication for VPN connections. Integrate your VPN with Entra ID or a RADIUS server so employees authenticate with their Microsoft 365 credentials and MFA. A password alone is not sufficient for VPN access; compromised credentials are one of the most common ways attackers gain access to business networks. ## Step 2: Create user accounts and access policies Rather than giving every VPN user full access to the entire office network, define access policies based on the principle of least privilege: each user should only be able to reach the resources they need. If your firewall supports integration with Entra ID or Active Directory, connect it so that user accounts and group memberships are managed in one place. Create user groups based on access needs. For example, an "Accounting" group might have VPN access to the accounting server and file share, while a "General Staff" group might only access shared file storage. Block VPN access to sensitive systems like domain controllers, backup servers, and management interfaces unless specifically required. Define these rules in the firewall's VPN access policy before any users connect. ## Step 3: Deploy the VPN client to employees Each employee who needs VPN access will need the VPN client software installed on their device. The client software is specific to your firewall brand: - FortiGate uses **FortiClient VPN** - SonicWall uses **SonicWall Mobile Connect** or **NetExtender** - Cisco Meraki uses **Cisco AnyConnect** - Ubiquiti uses the built-in VPN client in the operating system (L2TP/IPsec or WireGuard) Download the client from your firewall vendor's website and install it on each employee's device. Configure the connection with your firewall's public IP address (or DDNS hostname), the authentication method, and MFA settings. If your devices are managed through Microsoft Intune, you can push the VPN client and its configuration to devices automatically. This means employees do not need to configure anything manually; the VPN profile appears on their device ready to use. Intune can also enforce that only compliant devices (up-to-date, encrypted, with active endpoint protection) are allowed to connect. Test each employee's connection before considering the deployment complete. Have them connect from outside the office network and verify they can reach the specific internal resources they need. ## Step 4: Secure the VPN A VPN that is not properly secured can become an entry point for attackers. Follow these steps to lock it down: **Require MFA for every connection.** This is non-negotiable. If an employee's password is compromised through phishing or a data breach, MFA is the layer that prevents the attacker from connecting to your network. **Set session timeouts.** Configure idle VPN connections to disconnect automatically after a period of inactivity, such as 30 minutes. This prevents sessions from staying open indefinitely when an employee walks away from their computer. **Enable logging.** Turn on VPN connection logging so you have a record of who connected, when, from where, and for how long. This is important for both troubleshooting and security investigations. **Keep firmware updated.** VPN vulnerabilities in firewalls are a common attack vector. When your firewall vendor releases a firmware update, apply it promptly. Subscribe to your vendor's security advisories so you are aware of critical patches. **Disable unused VPN protocols.** If you are using SSL VPN, disable IPsec VPN (and vice versa) to reduce your attack surface. Every enabled service is a potential target. **Monitor for unusual activity.** Watch for VPN connections from unexpected locations, connections at unusual hours, repeated failed authentication attempts, or a single account connecting from multiple locations simultaneously. These are signs of compromised credentials. If your business uses Huntress Managed EDR, their 24/7 SOC can help identify suspicious activity that correlates with VPN access patterns. ## Common issues and fixes **"VPN connects but I can't access anything."** The VPN tunnel is up, but traffic is not routing correctly. Check the VPN access policy and firewall rules. Verify that the VPN address pool has routes to the internal subnets the user needs to reach. **Slow VPN performance.** VPN encryption is processor-intensive. Check your firewall's CPU usage during peak VPN hours. If it is consistently above 80 percent, your firewall may not have enough processing power for the number of concurrent VPN users. Switching to split tunneling can also significantly reduce VPN load by keeping non-office traffic off the tunnel. **VPN won't connect from a hotel or public network.** Some networks block VPN protocols, especially IPsec. If this is a recurring problem, switch to SSL VPN, which uses port 443 (the same port as regular HTTPS web traffic) and is almost never blocked. **Employee forgot their VPN password.** If your VPN is integrated with Entra ID, the VPN password is the employee's Microsoft 365 password. They can reset it at **aka.ms/sspr** without IT involvement. If VPN authentication is managed separately on the firewall, an admin will need to reset the password in the firewall's user management. ## Need help? Setting up a secure VPN involves coordinating your firewall, identity provider, and device management. If you want help getting it right the first time, or if you are wondering whether Conditional Access could replace your VPN entirely, [contact Athencia](/contact). We will evaluate your setup and recommend the right approach. #### How to Troubleshoot Slow Internet in a Small Office > Systematic guide to diagnosing and fixing slow internet in a small office, from ISP issues to network congestion to hardware problems. URL: https://athencia.com/kb/networking/how-to-troubleshoot-slow-internet-in-a-small-office Slow office internet is usually caused by one of five things: an ISP issue, overloaded network hardware, Wi-Fi interference, bandwidth hogs, or DNS problems. The mistake most people make is guessing at the cause and throwing money at a faster plan when the real problem might be a $200 router that needs replacing or a backup job running during business hours. This guide walks through each potential cause in order, starting with the quickest checks and working toward the less obvious culprits. Follow the steps in sequence; each one either eliminates a cause or points you to the fix. ## Step 1: Test your actual speed Before you can troubleshoot, you need a baseline. Run a speed test from a computer that is connected directly to your router with an Ethernet cable, not over Wi-Fi. This is important because Wi-Fi adds its own variables, and you need to isolate whether the problem is your internet connection or your wireless network. Open a browser and go to **speedtest.net** or **fast.com**. Run the test and write down three numbers: download speed, upload speed, and ping (latency). Run the test two or three times to get a consistent reading. Now compare those numbers to what your ISP plan promises. If your plan is 250 Mbps download and your wired test shows 240 Mbps, your internet connection is fine and the problem is almost certainly on your internal network (Wi-Fi, router, or congestion). If your wired test shows 80 Mbps on a 250 Mbps plan, the problem is either your ISP, your modem, or the cable between your modem and router. Write down the results. You will need them if you call your ISP or if you want to compare before and after making changes. ## Step 2: Check for ISP issues If your wired speed test came back significantly below what your plan promises, the problem may be on your ISP's side. Start by visiting your ISP's status page. Most ISPs have an outage map or service status page you can check online. Search for "[your ISP name] outage map" to find it. If there is a known outage or congestion in your area, you may just need to wait. If there is no reported outage, restart your modem. Unplug the power cable from the modem (not the router, the modem specifically), wait 30 seconds, and plug it back in. Wait two to three minutes for the modem to fully reconnect to your ISP. If your modem and router are the same device (a combo unit from your ISP), this restart resets both. After the modem restarts, run the wired speed test again. If speeds are still well below your plan, check the modem's indicator lights. A solid green or blue light on the "online" or "internet" indicator usually means the connection is healthy. A flashing or red light on those indicators often signals a problem. The exact meaning varies by model, so check your modem's manual or search for the model number online. If wired speeds remain low after a modem restart and there is no reported outage, call your ISP. Tell them you have tested on a wired connection, restarted the modem, and are getting X Mbps on a plan that should deliver Y Mbps. Giving them these specifics will help them diagnose the issue faster and prevents them from running you through basic troubleshooting you have already done. ## Step 3: Check your router and network hardware If your wired speed test matched your ISP plan but the office still feels slow, the problem is likely your router or internal network equipment. Ask yourself a few questions about your router. How old is it? Consumer routers older than three to four years often cannot handle the demands of a modern office. Is it a consumer model from a retail store? Consumer routers are designed for a household with five to ten devices; an office with 15 to 30 devices (computers, phones, printers, smart devices) can overwhelm one quickly. Restart the router by unplugging its power, waiting 30 seconds, and plugging it back in. Wait two minutes for it to fully boot. If your router is separate from your modem, you only need to restart the router at this step. Check for firmware updates on your router. Log in to the admin interface (typically at 192.168.1.1 or 192.168.0.1 in your browser), navigate to the **System**, **Administration**, or **Firmware** section, and check for available updates. Outdated firmware can cause performance issues and security vulnerabilities. Look at how many devices are connected. Most router admin interfaces show a list of connected devices. If you see 25 devices connected to a consumer router rated for 15, that is your bottleneck. Signs that your router is the problem include periodic connection drops, slowdowns that happen at the same time every day (when everyone is online), and devices failing to connect to Wi-Fi even though the network appears available. If your router is a consumer model and you have more than ten employees, replacing it with a business-grade router or firewall is the most impactful upgrade you can make. Business-grade hardware from Ubiquiti, Meraki, FortiGate, or SonicWall is designed to handle dozens of concurrent devices without degradation. ## Step 4: Diagnose Wi-Fi specific issues Wi-Fi is almost always slower than a wired Ethernet connection, and some speed reduction is normal. The question is how much speed you are losing over Wi-Fi compared to wired. Run a speed test over Wi-Fi from the same location where you tested wired. If your wired test showed 250 Mbps but Wi-Fi shows 40 Mbps, you have a significant Wi-Fi problem. If Wi-Fi shows 180 Mbps, that is a normal and acceptable reduction. The most common causes of poor Wi-Fi performance are distance from the access point, physical obstructions (walls, metal filing cabinets, concrete), and interference from other wireless networks nearby. Download a free Wi-Fi analyzer app on your phone (Wi-Fi Analyzer on Android, or use the built-in wireless diagnostics on Mac). These tools show you which Wi-Fi channels are congested in your area. If your router is on the same channel as five other nearby networks, switching to a less crowded channel can improve performance noticeably. Your router broadcasts on two frequency bands: 2.4 GHz and 5 GHz. The 5 GHz band is faster but has a shorter range and does not penetrate walls as well. The 2.4 GHz band reaches farther but is slower and more susceptible to interference. For desks close to the router, connect to 5 GHz. For areas farther away, 2.4 GHz may be the only option, but performance will be lower. If your office is larger than about 1,500 square feet, a single access point probably cannot cover the entire space adequately. Consider adding additional access points or switching to a mesh Wi-Fi system designed for business use. Placing a second access point in the area with the weakest signal can make a dramatic difference. ## Step 5: Identify bandwidth hogs Sometimes the internet connection and network hardware are both fine, but a specific device or application is consuming most of the available bandwidth. Common culprits include cloud backup services running during business hours, Windows updates downloading simultaneously on every computer in the office, employees streaming music or video, and large file transfers to or from cloud storage. To identify the offender, log in to your router's admin interface and look for a section labeled **Traffic Monitor**, **Bandwidth Usage**, **Connected Devices**, or **Statistics**. Most business-grade routers show per-device bandwidth consumption in real time. If you see a single device using 50 percent of your bandwidth, you have found the problem. The fixes are straightforward. Schedule large backups and updates to run after business hours. Configure Windows Update policies to download updates overnight rather than during the workday. If your devices are managed through Microsoft Intune, you can set delivery optimization policies that control when and how updates are downloaded, preventing every machine from pulling the same update simultaneously and flooding your connection. Set up Quality of Service (QoS) rules on your router to prioritize business-critical traffic. QoS tells the router to give priority to applications like Microsoft Teams, VoIP phone calls, and cloud business applications over less critical traffic like software updates and streaming. Look for QoS settings in your router's admin interface under **Traffic Management**, **QoS**, or **Bandwidth Management**. For ongoing visibility into what is consuming your network resources, a monitoring dashboard makes a real difference. The [Athencia One Portal](/athencia-one) provides real-time visibility into network health and device status, so you can spot bandwidth problems before your team starts complaining about slow internet. ## Step 6: Check DNS settings If websites feel slow to load even though speed tests look normal, your DNS server may be the problem. DNS is the system that translates website names (like athencia.com) into IP addresses. A slow or unreliable DNS server adds a delay to every website you visit, every cloud application you open, and every link you click. By default, your network uses your ISP's DNS servers, which are not always fast. Switching to a faster public DNS service can make web browsing feel noticeably snappier. To change your DNS settings at the router level (so all devices on the network benefit), log in to your router's admin interface and look for DNS settings under **WAN**, **Internet**, or **Network** settings. Replace your ISP's DNS addresses with one of these options: - **Cloudflare:** 1.1.1.1 and 1.0.0.1 (fast and privacy-focused) - **Google:** 8.8.8.8 and 8.8.4.4 (reliable, widely used) - **Quad9:** 9.9.9.9 and 149.112.112.112 (includes built-in malware blocking) Save the settings and restart your router. Every device on the network will now use the new DNS servers automatically. If you want DNS-level security that also blocks malicious and phishing websites, consider Cloudflare's malware-blocking DNS (1.1.1.2) or a dedicated DNS filtering service. See our guide on DNS filtering for more on that approach. ## When to upgrade your internet plan If you have worked through all the steps above and your connection is legitimately maxed out, it may be time for a faster plan. Here are the signs: Your wired speed tests consistently match your ISP plan, which means you are getting what you are paying for, but it is not enough. Your plan is under 100 Mbps and you have more than ten employees. Video calls are choppy even on wired connections. Multiple people report slowdowns at the same time during normal business activity. As a general rule, plan for 10 to 25 Mbps per employee for typical office work that includes video conferencing, and consider a plan upgrade before you hit that ceiling rather than after. ## Need help? If you have worked through these steps and your office internet is still slow, there may be a deeper issue with your network configuration or hardware. [Contact Athencia](/contact) for a thorough network assessment. We will pinpoint the problem and get your team back to full speed. #### What Is DNS Filtering and How It Protects Your Small Business Network > Explains how DNS filtering blocks malicious websites and inappropriate content at the network level, and how small businesses can set it up affordably. URL: https://athencia.com/kb/networking/what-is-dns-filtering-and-how-it-protects-your-small-business-network DNS filtering blocks access to malicious, phishing, and inappropriate websites at the network level before they ever load in a browser. It is one of the simplest and most cost-effective security layers you can add to your office network, and it works across every device on the network without installing anything on individual computers. This guide explains how DNS filtering works in plain terms, what it protects against, how to set it up, and where it fits alongside your other security tools. ## How DNS works (the 30-second version) Every time you type a website address into your browser or click a link, your computer needs to translate that human-readable name (like athencia.com) into a numerical IP address that the internet actually uses to route traffic. Your computer does this by sending a request to a DNS (Domain Name System) server, which acts like a phone book for the internet. By default, your computer uses whatever DNS server your ISP provides. That DNS server translates every request without any filtering. It does not know or care whether the website you are trying to reach is legitimate or a phishing page designed to steal your password. DNS filtering replaces your ISP's DNS with a filtering service that checks every request against a constantly updated database of known malicious, phishing, and unwanted domains. If the website you are trying to reach is on the block list, the request is stopped before the site ever loads. Instead of seeing the malicious page, the user sees a block notification explaining that the site was flagged as unsafe. The key benefit is that this happens before any content is downloaded. The malicious page never loads, the phishing form never appears, and the malware never gets a chance to execute. It is a preventive control, not a reactive one. ## What DNS filtering protects against DNS filtering is effective against several categories of threats that small businesses commonly encounter: **Known malware domains.** Security researchers and threat intelligence services maintain databases of websites that distribute malware, ransomware, and spyware. DNS filtering blocks access to these sites, preventing employees from accidentally downloading malicious software by clicking a bad link in an email or search result. **Phishing sites.** Phishing attacks often direct victims to fake login pages that look identical to Microsoft 365, banking portals, or other services. DNS filtering can block access to these fake sites before the employee ever sees the login form, reducing the risk of stolen credentials. **Command and control servers.** If a device on your network is already compromised (by malware that slipped through other defenses), that malware typically needs to communicate with a command and control server to receive instructions or exfiltrate data. DNS filtering blocks these communications, effectively neutralizing the infection even if the malware itself is still present on the device. This is an important layer because it limits the damage even when other protections fail. **Newly registered domains.** Attackers frequently register brand-new domains just days before using them in an attack. Some DNS filtering services can block access to domains that are less than 30 days old, which catches a large percentage of attack infrastructure before it can be used against your team. **Inappropriate content.** Beyond security, DNS filtering can optionally block access to categories of websites that are not appropriate for the workplace, such as adult content, gambling, or social media during business hours. This is configurable, so you can decide which categories to block based on your workplace policies. ## How DNS filtering fits with your other security tools DNS filtering is one layer in a multi-layered security approach. It does not replace your other tools, but it complements them in an important way. Think of it this way: your endpoint protection (like Microsoft Defender for Business, which is included with Microsoft 365 Business Premium) catches threats that reach the device. DNS filtering prevents many of those threats from reaching the device in the first place. If your business also uses Huntress Managed EDR for 24/7 threat monitoring, DNS filtering reduces the volume of threats that Huntress needs to investigate by blocking the low-hanging fruit at the network level. The combination of DNS filtering (blocking malicious sites before they load), endpoint protection (catching threats that make it to the device), and managed EDR (human threat hunters investigating suspicious activity) creates overlapping protection where each layer catches what the others might miss. ## DNS filtering options for small businesses There are several DNS filtering services that work well for small businesses, ranging from free to affordable paid options: **Cloudflare Gateway (Zero Trust).** Cloudflare offers a free tier for small teams that is easy to configure and uses one of the fastest DNS networks in the world. The paid tiers add more granular controls and logging. **Cisco Umbrella (formerly OpenDNS).** An established product with strong threat intelligence. Cisco Umbrella is available through managed service providers and offers detailed reporting. This is a paid service with per-user pricing. **DNSFilter.** A cloud-based service with affordable per-user pricing and AI-powered threat detection. Good reporting and easy to manage. **NextDNS.** A privacy-focused option with a generous free tier and highly customizable filtering rules. Good for businesses that want granular control over what is blocked. **Built-in firewall DNS filtering.** Many business-grade firewalls, including FortiGate and SonicWall, include DNS or web filtering as a built-in feature. If you already have one of these firewalls, check whether DNS filtering is included in your license before purchasing a separate service. **Free baseline option.** For the simplest possible protection, you can configure Cloudflare's malware-blocking DNS (1.1.1.2 and 1.0.0.2) or Quad9 (9.9.9.9) on your router at no cost. These block known malicious domains but do not offer the reporting, customization, or category-based filtering that paid services provide. ## How to set it up: Protecting the whole office (router level) The fastest way to deploy DNS filtering for your entire office is to change the DNS settings on your router. This ensures that every device connected to your office network uses the filtering DNS automatically, without touching any individual devices. Log in to your router's admin interface. This is typically at **192.168.1.1** or **192.168.0.1** in your browser. Enter your admin credentials. Navigate to the DNS settings. Depending on your router, these may be under **WAN**, **Internet**, **Network Settings**, or **DHCP Settings**. Look for fields labeled "Primary DNS" and "Secondary DNS" or "DNS Server 1" and "DNS Server 2." Replace the existing DNS server addresses with the addresses from your chosen DNS filtering provider. For example, if you are using Cloudflare's malware-blocking DNS, enter **1.1.1.2** as the primary and **1.0.0.2** as the secondary. If you are using a paid service like Cisco Umbrella or DNSFilter, they will provide you with custom DNS addresses tied to your account. Click **Save** or **Apply** to commit the changes. Some routers require a restart for DNS changes to take effect. After the change, all devices on the network will use the new DNS servers the next time they renew their network settings (usually within a few minutes, or immediately after reconnecting to Wi-Fi). To verify it is working, try visiting a known test page. Most DNS filtering providers offer a test URL that should display a block page if filtering is active. For example, Cloudflare provides a test at **malware.testcategory.com** that should be blocked when using their malware-filtering DNS. ## How to set it up: Protecting roaming laptops (per-device) Router-level DNS filtering only protects devices while they are connected to your office network. Laptops that employees take home, to client sites, or to coffee shops are not protected once they leave the office. To extend DNS filtering to roaming devices, most filtering services offer a lightweight agent that installs on each device and redirects DNS queries to the filtering service regardless of which network the device is on. **Cloudflare WARP** is the agent for Cloudflare Gateway. **Cisco Umbrella Roaming Client** extends Umbrella protection to off-network devices. **DNSFilter Agent** does the same for DNSFilter. These agents run quietly in the background and do not noticeably affect device performance. If your devices are managed through Microsoft Intune (included with Microsoft 365 Business Premium), you can deploy the DNS filtering agent to all managed devices automatically. In the Intune admin center, navigate to **Apps > All apps > Add**, select the agent installer for your chosen DNS filtering provider, and assign it to the device groups that need protection. The agent will install silently the next time each device checks in. This approach ensures that every company-managed device is protected by DNS filtering whether it is in the office, at home, or on public Wi-Fi. ## What DNS filtering does not do DNS filtering is a valuable security layer, but it is important to understand its limits so you do not rely on it for things it was not designed to handle. **DNS filtering is not a firewall.** It only blocks based on domain names. It does not inspect all network traffic, block port scans, or prevent unauthorized access to your network. **DNS filtering does not inspect page content.** It either allows or blocks an entire domain. If a legitimate website is compromised and serves malware on a single page, DNS filtering will not catch it unless the domain itself is flagged. **DNS filtering does not replace endpoint protection.** You still need antivirus or EDR software on each device to catch threats that arrive through means other than web browsing, such as USB drives or email attachments. **DNS filtering can be bypassed.** A tech-savvy user could manually change their device's DNS settings to bypass the filter. The per-device agent approach prevents this, which is one reason it is recommended for managed devices. On unmanaged devices, router-level filtering can be bypassed by anyone who knows how to change their DNS settings. **DNS filtering does not protect against email-based threats.** Phishing emails with malicious attachments or links to newly created domains that have not yet been categorized may still get through. Email security and user awareness training are separate, necessary layers. ## Need help? DNS filtering is one of the highest-impact, lowest-effort security improvements you can make for your office network. If you want help choosing the right provider, configuring it on your network, or deploying agents to your devices, [contact Athencia](/contact). We will get it set up and make sure it is working correctly across your entire environment. #### Why Your Office Should Not Use Consumer-Grade Routers > Explains the risks and limitations of using home routers in a business environment and what to look for in a business-grade alternative. URL: https://athencia.com/kb/networking/why-your-office-should-not-use-consumer-grade-routers Consumer-grade routers from retail stores are designed for households with a handful of personal devices, not offices running 10 to 50 or more devices with business-critical applications and real security requirements. Using one in a business environment creates security gaps, reliability issues, and performance bottlenecks that cost more in lost productivity and risk than the price difference between consumer and business hardware. This guide explains exactly what goes wrong with consumer routers in an office, what business-grade alternatives offer instead, and when it is time to make the switch. ## The problem with consumer routers in an office Consumer routers are built to handle a household where a few people browse the web, stream video, and check email. They are optimized for low cost and simple setup, not for the demands of a business environment. Here is where they fall short. **Device capacity.** A typical consumer router is designed for 5 to 15 personal devices. An office with even 10 employees easily reaches 20 to 30 connected devices once you count computers, smartphones, tablets, printers, VoIP phones, security cameras, and IoT devices. When a consumer router is handling more devices than it was designed for, performance degrades. Connections drop, Wi-Fi becomes unreliable, and the router may need to be rebooted regularly just to keep working. **Processing power.** Consumer routers have limited CPUs and memory. Features that business networks rely on, such as VPN encryption, firewall inspection, content filtering, and managing multiple VLANs, are either unavailable or so resource-intensive that they cripple the router's performance. A consumer router trying to handle VPN connections for remote employees while also serving the office network will slow to a crawl. **Firmware and security updates.** Consumer router manufacturers typically stop releasing firmware updates one to two years after a product ships. After that, any newly discovered security vulnerabilities remain unpatched permanently. This is a serious risk because consumer routers are frequent targets for known exploits. Attackers scan the internet for routers running outdated firmware with known vulnerabilities, and consumer models are the easiest targets. **No VLAN support.** VLANs (Virtual Local Area Networks) allow you to segment your network so that different types of devices are isolated from each other. Without VLANs, you cannot properly separate your guest Wi-Fi from your business network, your IoT devices from your workstations, or your payment processing systems from general office traffic. Consumer routers do not support VLANs, which means everything sits on one flat network where any device can see and potentially communicate with every other device. **No centralized management.** Every configuration change on a consumer router requires logging into the device's local web interface. There is no cloud dashboard, no remote management, and no way to manage multiple access points from a single pane of glass. For an IT provider managing your network, this means slower response times and more manual work for every change. ## Security gaps that put your business at risk Beyond performance limitations, consumer routers have fundamental security shortcomings that create real risk for a business. **No intrusion detection or prevention.** Business-grade firewalls include IDS/IPS (Intrusion Detection and Prevention Systems) that monitor network traffic for signs of attacks and automatically block suspicious activity. Consumer routers do not offer this capability. An attack against your network would proceed undetected. **No DNS security or content filtering.** Consumer routers use whatever DNS servers your ISP provides, with no ability to filter out malicious or phishing domains at the network level. Business-grade equipment either includes DNS filtering or integrates easily with third-party filtering services. **No VPN server (or a very limited one).** If employees need secure remote access to office resources, they need a VPN. Consumer routers either lack VPN server functionality entirely or offer a rudimentary implementation that is slow, insecure, or both. **No logging or alerting.** When something suspicious happens on your network, you want to know about it. Business-grade firewalls log network activity and can alert you (or your IT provider) to unusual behavior. Consumer routers keep minimal logs, if any, and have no alerting capability. **Insecure default settings.** Consumer routers frequently ship with default admin passwords, outdated encryption protocols enabled, and remote management features turned on. Many users never change these defaults, leaving the router wide open. A CIS Controls baseline assessment, which evaluates your security posture against industry best practices, will flag a consumer router as a significant gap in almost every category related to network security. ## Reliability issues that affect your team daily Even if security is not your primary concern, consumer routers create day-to-day reliability problems that affect productivity. **Overheating and instability.** Consumer routers are not designed for continuous, heavy use. Under constant business load, they overheat, slow down, and eventually need rebooting. If your team has gotten used to "restart the router" as a regular fix, the router is the problem. **No redundancy.** When a consumer router fails, every person in the office loses internet, Wi-Fi, and access to cloud applications. There is no failover, no backup path, and no way to keep working until the device is replaced or restarted. **No Quality of Service (QoS).** QoS allows you to prioritize certain types of traffic. In a business environment, you want voice calls and video conferencing to take priority over file downloads and software updates. Without QoS, a large Windows update downloading on one machine can make everyone's Teams calls choppy. Consumer routers either lack QoS entirely or offer a basic version that does not work well under load. **Limited Wi-Fi coverage.** A consumer router provides a single access point, which is rarely enough for an office larger than a few rooms. Adding more access points to a consumer setup is not straightforward because consumer hardware does not support managed AP configurations. The result is dead zones, weak signals, and frustrated employees. ## What business-grade routers and firewalls offer Business-grade network equipment is designed for exactly the environment consumer routers cannot handle. Here is what you get with a proper business setup. **VLAN support** lets you properly segment your network. You can put business devices on one network, guest Wi-Fi on another, and IoT devices (printers, cameras, smart displays) on a third. Each segment is isolated from the others, so a compromised device on the guest network cannot reach your file server. **Enterprise-grade firewall** with stateful packet inspection, IDS/IPS, and the ability to create granular rules about what traffic is allowed between network segments and to the internet. **Built-in VPN** for secure remote access. Employees can connect from home with encryption and multi-factor authentication, integrated with Entra ID so they use their existing Microsoft 365 credentials. **Centralized management** through cloud-based dashboards. Platforms like Ubiquiti's UniFi, Cisco Meraki, and FortiCloud let your IT provider monitor, configure, and troubleshoot your network remotely. Changes can be made in minutes without needing to be on-site. **Regular firmware updates** with long support lifecycles. Business-grade manufacturers actively patch security vulnerabilities for years, not months. Subscribing to vendor security advisories ensures critical patches are applied promptly. **Higher device capacity.** Business-grade equipment is built to handle dozens or hundreds of concurrent devices without degradation. The hardware has the processing power, memory, and cooling to run reliably under continuous load. **Quality of Service** to prioritize business-critical traffic like Microsoft Teams calls and cloud applications over background traffic like updates and personal browsing. If your devices are managed through Microsoft Intune, a business-grade network setup also enables better device management. Intune can enforce compliance policies that check whether a device is connected to a trusted network before granting access to sensitive resources, but this only works reliably when your network infrastructure supports proper segmentation and identification. ## Recommended business-grade options for small businesses You do not need enterprise-scale equipment for a small office. Here are practical options organized by office size. **For offices under 15 people,** an entry-level business firewall and one or two managed access points is usually sufficient. Ubiquiti's UniFi line (a UniFi Gateway and one or two UniFi access points) is a popular and cost-effective choice. FortiGate entry-level models (FortiGate 40F or 60F) are another solid option with more advanced security features. **For offices of 15 to 50 people,** you will want a more capable firewall with higher throughput and additional access points for full Wi-Fi coverage. Cisco Meraki, FortiGate mid-range models, and SonicWall TZ series are common choices in this range. Cloud-managed platforms like Meraki simplify ongoing management significantly. **In terms of cost,** expect to spend $300 to $1,500 on the hardware depending on your office size and the features you need. Some platforms (like Meraki) also require an annual license for cloud management. Compare this to the total cost of ownership for consumer routers: a $100 consumer router that needs replacing every 18 months costs nearly as much over five years as a $500 business router that runs reliably for the full period, and the consumer option gives you none of the security, segmentation, or management benefits. ## When to make the switch If any of the following apply to your office, it is time to replace the consumer router with business-grade equipment: You have more than 5 to 10 employees. You are experiencing dropped connections, slow speeds, or the need to reboot the router regularly. You need guest Wi-Fi that is properly isolated from your business network. You have compliance requirements such as HIPAA, PCI-DSS, or cyber insurance that mandate network security controls. You need VPN access for employees working from home. You have been told by a security assessment or your cyber insurance provider that your network does not meet baseline security requirements. The switch does not have to be complicated. A qualified IT provider can replace a consumer router with a properly configured business firewall and access points in a few hours, with minimal disruption to your team. ## Need help? If you are not sure whether your current network equipment is up to the task, or if you are ready to upgrade, [contact Athencia](/contact). We will assess your current setup, recommend the right hardware for your office size and needs, and handle the migration so your team stays productive throughout the transition. ### Windows #### How to Enable BitLocker Drive Encryption on Business Laptops > Step-by-step guide to enabling BitLocker on Windows laptops so business data stays protected if a device is lost or stolen. URL: https://athencia.com/kb/windows/how-to-enable-bitlocker-drive-encryption-on-business-laptops BitLocker encrypts the entire hard drive on a Windows laptop so that if the device is lost or stolen, nobody can read the data without the correct credentials. For any business laptop that leaves the office, enabling BitLocker is one of the most important security steps you can take. Most cyber insurance policies now require full disk encryption, and compliance frameworks like HIPAA and PCI DSS expect it as a baseline control. The good news is that BitLocker is built into Windows Pro and Enterprise at no additional cost, and on modern hardware with an SSD, you will not notice any performance impact. ## What you will need Before you begin, confirm you have the following: - **Windows 10 or 11 Pro or Enterprise.** BitLocker is not available on Windows Home. If you are unsure which edition you have, go to **Settings > System > About** and look for the "Edition" line. - **A TPM (Trusted Platform Module) chip, version 1.2 or later.** Virtually all business laptops manufactured after 2016 include one. You will verify this in Step 1 below. - **Administrator access** to the device. - **A plan for storing BitLocker recovery keys securely.** This is critical. If you lose the recovery key and the user gets locked out, the data on the drive is permanently inaccessible. ## Why BitLocker matters for your business A lost or stolen laptop without encryption is an open book. Anyone with basic tools and a few minutes can remove the hard drive, plug it into another computer, and read every file on it. Client records, financial data, saved passwords, email archives, all of it. With BitLocker enabled, the drive is unreadable without the correct Windows login or recovery key. That means if a laptop goes missing, you can report it to your insurance carrier and your clients with confidence that the data is protected. Beyond the security benefit, BitLocker is required by most cyber insurance policies and by compliance frameworks including HIPAA, PCI DSS, and CIS Controls. If you are ever audited or need to file a claim, having encryption enabled on every device is something you will need to demonstrate. On modern hardware with solid-state drives, BitLocker runs with no noticeable performance impact. Your employees will not feel a difference. ## Step 1: Verify that TPM is available and enabled Press **Windows + R** on your keyboard to open the Run dialog. Type `tpm.msc` and press **Enter**. This opens the TPM Management window. If the TPM is working correctly, you will see a status message that reads "The TPM is ready for use." You should also see the TPM version listed (2.0 is ideal, and 1.2 will work). If the window says TPM is not found, the chip may be disabled in the BIOS. Restart the computer and enter the BIOS setup (usually by pressing F2, F12, or Delete during startup, depending on the manufacturer). Navigate to the **Security** section and look for a TPM setting. Enable it, save your changes, and boot back into Windows. Then run `tpm.msc` again to confirm. If the device genuinely has no TPM, which is rare on any business laptop from the last decade, BitLocker can still work using a USB startup key. However, this is not recommended for most businesses because the employee would need to insert the USB key every time the laptop starts, and if the USB key is lost alongside the laptop, the encryption is compromised. ## Step 2: Enable BitLocker There are two paths depending on your Windows version. **On Windows 11:** Go to **Settings > Privacy & security > Device encryption**. If the device meets the requirements, you will see a toggle to turn on device encryption. Toggle it on. **On Windows 10 or 11 (full BitLocker settings):** Open **Control Panel > System and Security > BitLocker Drive Encryption**. Click **Turn on BitLocker** next to your C: drive. Windows will walk you through a short setup wizard. When prompted for the encryption method, select **XTS-AES 256-bit**. This is the most secure option and is the standard for business use. Next, you will be asked what to encrypt. Choose **"Encrypt entire drive"** if the laptop has been in use and contains existing data. Choose **"Encrypt used disk space only"** if the laptop is brand new and has not been used yet; this option is faster because it only encrypts the portions of the drive that contain data (new data will be encrypted automatically going forward). Once you confirm, encryption begins in the background. The laptop can be used normally while this runs. Encryption time depends on the drive size and type. A 256 GB SSD typically takes 30 to 60 minutes. A larger or slower drive may take longer. ## Step 3: Back up the recovery key (this is critical) During the BitLocker setup wizard, Windows will prompt you to back up your recovery key. The recovery key is a 48-digit numerical code that can unlock the drive if normal login fails. Do not skip this step. **Best option: Save to Entra ID.** If the device is joined to your company's Entra ID (formerly Azure AD) tenant, select the option to save the recovery key to your Azure AD account. The key is then stored securely in the Entra admin center, where any authorized IT administrator can retrieve it. This is the recommended approach because recovery keys are centrally managed and cannot be lost by individual employees. **Alternative: Save to a USB drive.** Save the key file to a USB drive and store that USB drive in a secure location, not with the laptop itself. **Alternative: Print it.** Print the recovery key and store the printed copy in a locked cabinet or safe. There are two things you should never do with recovery keys. First, do not save the recovery key only on the encrypted drive itself. If you are locked out of the drive, you will not be able to access the key. Second, do not email recovery keys in plain text. If the email account is compromised, the attacker would have the key to decrypt the drive. If a recovery key is lost and the user gets locked out, the data on the drive is permanently inaccessible. There is no backdoor. ## Step 4: Verify that encryption is active After encryption completes, verify the status. Go to **Control Panel > BitLocker Drive Encryption**. The status should show **"BitLocker on"** next to your C: drive, along with a note that the drive is encrypted. For a more detailed check, open **PowerShell as administrator** (right-click the Start button, select **Terminal (Admin)** or **Windows PowerShell (Admin)**) and run: ``` manage-bde -status C: ``` Look for two lines in the output: **"Protection Status: Protection On"** and **"Encryption Method: XTS-AES 256."** If both are present, BitLocker is fully active and using the strongest encryption method. ## Managing BitLocker across multiple devices If your office has more than a handful of laptops, enabling BitLocker one machine at a time is not practical. This is where Microsoft Intune becomes valuable. If your business uses Microsoft 365 Business Premium, Intune is included at no extra cost. With Intune, you can create a device configuration policy that enforces BitLocker automatically on every enrolled device. When a new laptop is enrolled, Intune pushes the BitLocker policy and encryption begins without anyone needing to touch the machine manually. Recovery keys are automatically stored in Entra ID, so your IT team can retrieve them from a central console whenever needed. Intune also provides compliance policies that flag any device where BitLocker is not active. You can pull reports showing encryption status across your entire fleet, which is exactly what auditors and insurance carriers ask for. This is how Athencia manages BitLocker for its clients: encryption is enforced by policy, recovery keys are centrally stored, and compliance is continuously monitored through the [Athencia One Portal](/athencia-one). ## When the recovery key is needed There are several situations where BitLocker will ask for the recovery key instead of allowing a normal login: - **After a BIOS or firmware update.** Changes to the system firmware can trigger BitLocker's tamper detection. - **If the TPM detects a change to the boot configuration.** This is a security feature; if something in the startup process has changed unexpectedly, BitLocker wants to verify the user is authorized. - **If the hard drive is moved to a different computer.** BitLocker ties the encryption to the specific TPM chip in the original device. - **After certain Windows updates.** This is rare, but some major updates can trigger a recovery key prompt. - **If the user forgets their Windows password and the device locks out.** In all of these cases, having recovery keys stored centrally in Entra ID means your IT team (or Athencia's support team) can retrieve the key and get the user back into their laptop within minutes rather than hours. ## Need help? Enabling BitLocker on a single laptop is straightforward, but managing encryption across an entire office requires the right policies and tools. If you need help enforcing BitLocker across your devices or setting up centralized recovery key management, [reach out to Athencia](/contact). We will get your fleet encrypted and compliant. #### How to Fix Common Printer Issues in a Windows Office Environment > Troubleshooting guide for the most common office printer problems on Windows, including offline printers, print queue jams, and driver issues. URL: https://athencia.com/kb/windows/how-to-fix-common-printer-issues-in-a-windows-office-environment Most office printer problems fall into a handful of categories: the printer shows as offline, print jobs are stuck in the queue, the driver is missing or corrupted, or the network connection dropped. Before you call for help, there is a good chance one of the fixes below will get you printing again in a few minutes. ## Problem 1: Printer shows as "offline" This is the most common printer complaint in any office. The printer is powered on and looks fine, but Windows insists it is offline. Start with the physical basics. Walk over to the printer and confirm it is powered on. Check for any error lights or messages on the printer's display panel. Make sure it has paper in the tray and that no paper jam indicators are lit. Next, check the network connection. If the printer is connected via Ethernet, verify the cable is plugged in and the link light on the port is active. If it is a Wi-Fi printer, check that it is connected to the correct wireless network. You can usually print a network configuration page from the printer's built-in menu, which will show its current IP address and connection status. Try typing that IP address into a web browser on your computer. If the printer's web interface loads, the printer is reachable on the network and the problem is on the Windows side. On your computer, go to **Settings > Bluetooth & devices > Printers & scanners** and select the printer that shows as offline. Click **Open print queue**. In the print queue window, click the **Printer** menu at the top and look for an option labeled **"Use Printer Offline."** If it is checked, uncheck it. This is a setting that Windows sometimes enables on its own, and unchecking it often resolves the issue immediately. If the printer still shows as offline after unchecking that option, restart the Print Spooler service (covered in Problem 2 below). This clears out the Windows print system and forces it to re-detect available printers. ## Problem 2: Print jobs stuck in the queue When print jobs pile up in the queue and refuse to print or cancel, the Print Spooler service is usually the culprit. The spooler is the Windows service responsible for managing all print jobs, and it can get jammed. First, try clearing the queue manually. Go to **Settings > Bluetooth & devices > Printers & scanners**, select the affected printer, and click **Open print queue**. In the queue window, click the **Printer** menu and select **Cancel All Documents**. Confirm the prompt. Wait 30 seconds and try printing again. If the jobs refuse to cancel, or if new jobs immediately get stuck, you need to restart the Print Spooler service. Click the **Start** button and search for **"Services."** Open the Services application. Scroll down to **Print Spooler**, right-click it, and select **Restart**. After the service restarts, try printing again. If even restarting the spooler does not clear the jam, there is a more thorough fix. Open Services, right-click **Print Spooler**, and select **Stop**. Then open File Explorer and navigate to `C:\Windows\System32\spool\PRINTERS`. Delete all files in this folder (these are the stuck print job files). Go back to Services, right-click **Print Spooler**, and select **Start**. The queue should now be empty and the printer should accept new jobs. ## Problem 3: Printer not found or not installed If a printer does not appear in your list of available printers, you need to add it manually. Go to **Settings > Bluetooth & devices > Printers & scanners** and click **Add device**. Windows will scan for available printers. If the printer appears in the list, click it and follow the prompts to install it. If the printer does not appear, click **"The printer that I want isn't listed"** (or **"Add manually"** on some Windows 11 versions). For network printers, the most reliable option is to add it by IP address. Select **"Add a printer using a TCP/IP address or hostname,"** click **Next**, and enter the printer's IP address. To find the printer's IP address, check the printer's display panel (most modern printers can show their IP in a network status screen), print a network configuration page from the printer's built-in menu, or check your router's DHCP client list to see what IP was assigned. If Windows does not have the correct driver built in, you will need to download it from the manufacturer's website (HP, Brother, Canon, etc.). Go to the manufacturer's support page, search for your exact printer model, download the driver for your version of Windows, and run the installer. After the driver is installed, try adding the printer again. For businesses that manage multiple computers, Microsoft Intune can deploy printer configurations to all enrolled devices from a central console. This eliminates the need to manually install printers on each workstation. You configure the printer connection once in Intune, and it pushes to every managed device automatically. ## Problem 4: Prints are garbled, faded, or misaligned If the printer is working but the output looks wrong, the issue is usually the toner/ink or the driver. Start by running the printer's built-in cleaning and alignment functions. These are usually accessible from the printer's own control panel or touch screen. Look for a **Maintenance** or **Tools** menu on the printer itself. Check toner or ink levels. For laser printers, if the toner is low, try removing the toner cartridge, gently rocking it side to side a few times to redistribute the remaining toner, and reinserting it. This can extend the life of a cartridge by a few hundred pages. Try printing a test page from Windows to isolate whether the problem is with a specific application or with the printer itself. Go to **Settings > Bluetooth & devices > Printers & scanners**, select the printer, and click **Print test page**. If the test page looks fine, the issue is likely in the application you were printing from (check print settings, margins, or page scaling). If the test page is also garbled or distorted, the issue is with the driver or the printer hardware. To fix a driver issue, uninstall the printer from **Settings > Printers & scanners** (select it and click **Remove**), then reinstall it using the steps in Problem 3. Download a fresh driver from the manufacturer's website to make sure you have the latest version. ## Problem 5: Printing is extremely slow Slow printing usually comes down to print quality settings or the network connection. First, check the print quality setting. When you print a document, look at the print dialog for a quality or resolution option. If it is set to **"Best"** or **"High Quality,"** change it to **"Normal"** or **"Draft"** for everyday documents. High-quality mode sends much more data to the printer and takes significantly longer, especially for documents with images. For network printers, the connection type matters. Wi-Fi printers are often noticeably slower than Ethernet-connected printers, especially if the Wi-Fi signal is weak or the network is congested. If slow printing is a recurring problem, consider connecting the printer via Ethernet cable instead. Large documents with many images take longer regardless of settings. For draft copies, try printing in black and white to speed things up. If one specific computer is slow but other computers print to the same printer at normal speed, the issue is likely the print driver on that computer. Uninstall and reinstall the printer driver on the slow machine. ## Problem 6: Printer works for some users but not others When the printer works for some people in the office but not others, the issue is usually configuration or permissions. First, verify that the printer is actually installed on the affected user's computer. Go to **Settings > Bluetooth & devices > Printers & scanners** on their machine and check if the printer appears in the list. If it does not, install it using the steps in Problem 3. Next, check that the user is sending print jobs to the correct printer. They may have a different default printer selected. Go to **Settings > Bluetooth & devices > Printers & scanners** and look at which printer is set as the default. If you are using a print server or a shared printer hosted on another computer, verify that the affected user has permission to access the shared printer. On the computer hosting the shared printer, right-click the printer, select **Printer properties > Security tab**, and confirm the user or their security group has the **Print** permission. Finally, check that the affected user's driver version matches what other working users have. Mismatched driver versions between the print server and the client can cause silent failures. ## When to call for help Some printer problems go beyond basic troubleshooting: - **Error codes on the printer's display** that you cannot resolve after checking the manufacturer's documentation or support website. - **Hardware issues** like paper jams that will not clear, grinding or clicking sounds, or persistent error lights after following all troubleshooting steps. - **Driver issues that persist** after uninstalling and reinstalling. - **Network printers that consistently drop off the network.** This usually indicates a deeper network infrastructure issue (DHCP lease problems, Wi-Fi coverage gaps, or network switch problems) that requires someone to look at the network, not just the printer. ## Need help? Printer problems are frustrating, but most have simple fixes once you know where to look. If you have worked through these steps and the issue persists, or if you are dealing with recurring printer problems across your office, [get in touch with Athencia](/contact). We can diagnose the issue remotely and get your team printing again. #### How to Fix Microsoft Teams Audio and Video Problems on Windows > Troubleshooting guide for the most common Teams audio and video issues on Windows, including microphone problems, camera not working, and echo during calls. URL: https://athencia.com/kb/windows/how-to-fix-microsoft-teams-audio-and-video-problems-on-windows Microsoft Teams audio and video issues are one of the most common help desk requests in any small office. The good news is that most problems come down to one of three things: Teams has selected the wrong audio or video device, Windows is blocking microphone or camera access, or a driver needs to be updated. This guide walks through each scenario with specific steps so you can get back into your meeting quickly. ## Quick fix: Check the basics first Before diving into detailed troubleshooting, run through these quick checks. They resolve the majority of Teams audio and video problems in under a minute. **Is the microphone or headset connected?** If you are using a USB headset, confirm it is plugged in. If it is Bluetooth, verify it is paired and connected by clicking the Bluetooth icon in the Windows taskbar. Bluetooth devices sometimes silently disconnect. **Is the microphone muted in Teams?** Look at the meeting controls bar at the bottom of the Teams window. If the microphone icon has a line through it, click it to unmute. This is the single most common cause of "nobody can hear me." **Is the system volume turned up?** Click the speaker icon in the Windows taskbar and check the volume slider. Also check that the output is not set to a disconnected device. **Restart Teams completely.** Closing the Teams window does not fully shut it down; it keeps running in the background. Right-click the Teams icon in the system tray (bottom-right corner of the taskbar) and select **Quit**. Then reopen Teams from the Start menu. **Restart the computer.** If a Teams restart does not help, a full reboot clears out audio driver issues and releases hardware locks that other applications may have on your microphone or camera. This fixes a surprising number of audio and video problems. ## Problem: Others cannot hear you (microphone not working) If you are in a Teams meeting and other participants cannot hear you, work through these steps in order. **Check Teams device settings.** While in a meeting, click the three dots **(...)** in the meeting controls bar and select **Device settings**. A panel will open on the right side of the screen showing your selected Speaker, Microphone, and Camera. Verify that the correct microphone is selected. If you have multiple audio devices connected (laptop built-in mic, USB headset, webcam mic), Teams may have picked the wrong one. Select the device you are actually using and speak. The audio level indicator next to the microphone selection should move when you talk. **Check Windows microphone permissions.** Go to **Settings > Privacy & security > Microphone**. Make sure the toggle for **"Microphone access"** is turned on. Scroll down the list of apps and confirm that Microsoft Teams is allowed to access the microphone. If it is toggled off, turn it on. You may need to restart Teams after changing this setting. **Check Windows sound settings.** Go to **Settings > System > Sound > Input**. Verify that the correct microphone is selected as the input device and that the input volume is not set to zero. Speak into the microphone and watch the input level meter on this screen. If the meter does not move at all, Windows is not receiving audio from the microphone, which points to a hardware issue, a connection problem, or a driver issue. **Run the Teams test call.** In Teams, click your profile picture in the top right, then go to **Settings > Devices**. Click **Make a test call**. Teams will call you, play a prompt, record a short clip of your voice, and play it back. If you can hear your own voice in the playback, the microphone is working correctly in Teams and the issue may be meeting-specific (check your mute status again or ask the other participants if the issue is on their end). ## Problem: You cannot hear others (speaker or audio output not working) If you have joined a Teams meeting but cannot hear anyone speaking, the issue is on the output side. **Check Teams device settings.** In the meeting, click **(...)** > **Device settings** and verify the correct speaker or headset is selected for audio output. Click the **Test** button (if available) to play a test tone through the selected device. **Check Windows sound settings.** Go to **Settings > System > Sound > Output**. Verify the correct output device is selected and the volume is not at zero or muted. **Check physical volume controls.** If you are using a headset with an inline volume control, make sure it is turned up. If you are using external speakers, confirm they are powered on and the volume knob is not turned down. **Test with another application.** Play a video on YouTube or any other website, or play a system sound. If you can hear audio from other applications but not Teams, the problem is specific to Teams (most likely the wrong device selected in Teams device settings). If you cannot hear audio from anything, the issue is with Windows sound settings, the output device itself, or the audio driver. ## Problem: Camera not working If your video is not showing in Teams meetings, work through these steps. **Check Teams device settings.** In the meeting, click **(...)** > **Device settings** and verify the correct camera is selected. If you see a preview image in the device settings panel, the camera is working. If the preview is black or blank, continue troubleshooting. **Check Windows camera permissions.** Go to **Settings > Privacy & security > Camera**. Make sure **"Camera access"** is turned on and that Microsoft Teams is listed and allowed. If Teams is not in the list, try reinstalling Teams. **Check if another application is using the camera.** Only one application can use the camera at a time on most Windows devices. If you have Zoom, Webex, or another video application open, close it completely (including from the system tray) and try Teams again. **Check for a physical camera shutter or switch.** Many business laptops, especially Lenovo ThinkPads and HP EliteBooks, have a physical privacy shutter that slides over the camera lens. Look for a small slider near the camera at the top of the screen. Slide it open. **Update the camera driver.** Right-click the **Start** button and select **Device Manager**. Expand the **Cameras** section, right-click your camera device, and select **Update driver**. Choose **"Search automatically for drivers."** If Windows finds an update, install it and restart Teams. ## Problem: Echo or feedback during calls Echo is caused by audio from your speakers being picked up by your microphone and sent back to other participants. This creates a loop that everyone hears as echo or feedback. **Use a headset.** The most reliable fix for echo is to use a headset instead of the laptop's built-in speakers and microphone. When audio plays through a headset's earpieces, it does not leak into the microphone. **Multiple devices in the same room.** If two or more people in the same physical room are each joined to the same Teams meeting on their own laptops, you will get echo. One person should mute their microphone and speakers entirely, or one person should disconnect from audio and let the other person's device handle it. In conference rooms, use a single shared speakerphone device (like a Jabra Speak or Poly Sync) instead of multiple individual laptops. **Disable "Listen to this device."** Go to **Settings > System > Sound**, click your input device, and look for a **"Listen"** option. If **"Listen to this device"** is checked, uncheck it. This setting plays your microphone input through your speakers in real time, which creates a feedback loop in calls. **Keep your microphone muted when you are not speaking.** In meetings with many participants, muting when you are not talking reduces the chance of background noise and echo being picked up. ## Problem: Video is choppy or freezing Choppy video in Teams is almost always a bandwidth or network issue, not a camera problem. **Check your internet speed.** Run a speed test at speedtest.net or fast.com. Teams video calls need at least 1.5 Mbps upload and 1.5 Mbps download for acceptable quality, and 4 Mbps or higher in both directions for HD video. If your speeds are below these thresholds, video quality will suffer. **Close bandwidth-heavy applications.** Pause any cloud backup services, large file downloads or uploads, and streaming video on other devices. In a small office sharing a single internet connection, one person running a large backup can degrade video quality for everyone. **Turn off your camera.** If bandwidth is limited and audio quality is more important than seeing faces, turning off your video can dramatically improve the stability of the call. Click the camera icon in the Teams meeting controls to toggle it off. **Use a wired Ethernet connection.** Plug your laptop into an Ethernet cable instead of relying on Wi-Fi. Wired connections are more stable and have lower latency, both of which matter for real-time video calls. If your laptop does not have an Ethernet port, a USB-to-Ethernet adapter costs around $15 and is well worth it for anyone who takes frequent video calls. **Lower video quality in Teams settings.** In Teams, go to **Settings > General** or **Settings > Appearance and accessibility** and look for video quality or bandwidth options. Reducing the resolution setting can help on slower connections. For businesses where Teams is a critical daily tool, having a reliable network makes all the difference. If your team regularly experiences choppy video or dropped calls, the root cause is often the office network itself rather than individual computers. A network assessment can identify bottlenecks and recommend improvements. ## Need help? If you have worked through these steps and your Teams audio or video is still not cooperating, [contact Athencia](/contact). We can troubleshoot remotely, check your device settings, and make sure your team's meeting experience is reliable. #### How to Keep Windows Computers Updated Without Disrupting Your Team > Guide to managing Windows updates in a small office so computers stay secure without surprise reboots during the workday. URL: https://athencia.com/kb/windows/how-to-keep-windows-computers-updated-without-disrupting-your-team Windows updates are essential for security, but unmanaged updates are a constant source of frustration. Surprise reboots in the middle of the workday, slow mornings while a laptop finishes installing patches, lost work when a restart closes unsaved documents. The goal is straightforward: keep every computer patched and secure while controlling exactly when updates install and restart, so your team is never disrupted during business hours. ## Why you cannot just ignore updates It is tempting to click "remind me later" indefinitely, but skipping updates creates real risk for your business. Security patches fix known vulnerabilities that attackers are actively exploiting. When Microsoft publishes a patch, it publicly describes the vulnerability it fixes, which gives attackers a roadmap to target any computer that has not installed the patch yet. Unpatched computers are the most common entry point for ransomware and malware. Microsoft releases security patches on the second Tuesday of every month, known as "Patch Tuesday." These monthly updates address critical and high-severity vulnerabilities. Delaying these patches for more than two weeks after release significantly increases your exposure. Cyber insurance policies increasingly require evidence of regular, timely patching. If you file a claim and your insurer finds that the breached computer was months behind on updates, they may deny coverage. Compliance frameworks like HIPAA, PCI DSS, and CIS Controls also require that systems run supported, patched software. ## Option 1: Configure active hours (no extra tools required) If you have a very small office with fewer than five computers and no IT management tools, configuring Active Hours on each machine is the simplest way to prevent daytime reboots. Go to **Settings > Windows Update > Advanced options > Active hours**. Set the active hours window to match your business hours. For example, set it from 7:00 AM to 6:00 PM. Windows will only restart for updates outside of these hours, so restarts happen overnight or early morning when nobody is working. This approach has limitations. Employees can change their own active hours settings, there is no central control, and it does not guarantee that updates install in a timely way. It simply prevents restarts during the hours you specify. For a solo practitioner or a two-person office, this is usually sufficient. For anything larger, you need more control. ## Option 2: Use Windows update for business with Microsoft Intune For offices with 5 to 50 computers, Microsoft Intune provides centralized control over when and how updates are installed across every device. If your business uses Microsoft 365 Business Premium, Intune is included at no extra cost. Intune lets you create update policies that apply to all enrolled devices from a single console. Here is what you can control: **Deferral periods.** You can defer quality and security updates by a set number of days after Microsoft releases them. A recommended approach is to defer security updates by 7 days (which lets any early issues with a patch surface before it hits your fleet) and defer feature updates by 30 days (feature updates are larger and more disruptive, so a longer testing window is appropriate). **Maintenance windows.** Configure updates to download and install during a specific time window, such as 10:00 PM to 5:00 AM. This ensures that restarts happen overnight when employees are not working. **Restart behavior.** Set policies that prevent automatic restarts during business hours. You can require user confirmation before a restart, or configure the device to restart only outside of active hours. **Compliance reporting.** Intune shows you which devices have installed the latest patches and which are behind, so you always know where your fleet stands. This is the same data auditors and insurance carriers ask for. This is how Athencia manages patching for its clients. Update policies are configured in Intune, maintenance windows are set to overnight hours, and compliance is tracked through the [Athencia One Portal](/athencia-one). If a device falls behind on patches, it gets flagged automatically. ## Option 3: Managed patching service For businesses that want patching handled completely, a managed patching service takes the entire process off your plate. With Athencia's managed patching, both OS patches (Windows updates) and third-party application updates (browsers, PDF readers, Zoom, and other common business software) are deployed automatically on a schedule. Compliance reports show exactly which machines are up to date and which need attention. Your team does not need to click anything or think about updates at all. This is particularly important because Windows updates alone do not cover all the software on a computer. Third-party applications like web browsers, Java, and Adobe products are frequent attack targets, and they need their own updates. A managed patching service handles all of it. ## Practical update schedule for a small office If you are managing updates yourself, here is a week-by-week schedule that balances security with stability: **Monday after Patch Tuesday:** Review what Microsoft released. Check the Microsoft Security Response Center website for a summary of the month's patches and any known issues. **Wednesday:** Approve and deploy security updates to a small test group. Pick 3 to 5 computers (ideally ones used by tech-savvy employees who will notice if something breaks) and push the updates to them first. Let these machines run for a day or two to catch any compatibility problems. **Friday:** Deploy security updates to all remaining computers, scheduled for overnight installation. Make sure the policy is set to restart outside of business hours. **Following Monday:** Verify that all computers updated successfully. Check for any machines that did not restart or where the update failed. Follow up on any machines that are still pending. **Monthly:** Review and deploy any deferred feature updates (the larger Windows version updates) following the same test-then-deploy approach. ## Tips for reducing update disruption **Tell employees to leave computers on overnight on update nights.** If a computer is shut down, it cannot install updates. Send a quick reminder on update days asking people to leave their laptops open, plugged in, and connected to the network when they leave for the day. **For laptops that go home with employees,** schedule updates for a time when the laptop is likely to be on and connected to power, such as late evening. Updates will not install if the laptop is closed and sleeping. **Enable Delivery Optimization.** This Windows feature lets computers on the same local network share update files with each other, so only one computer needs to download the update from Microsoft, and the rest get it from that machine. This reduces internet bandwidth usage significantly in offices with many computers. Go to **Settings > Windows Update > Advanced options > Delivery Optimization** and turn on **"Allow downloads from other PCs."** **Set downloads on metered connections if needed.** If some employees use mobile hotspots or limited internet connections, go to **Settings > Windows Update > Advanced options** and enable **"Download updates over metered connections"** to ensure they still receive critical patches. ## What to do when an update causes problems Occasionally, a Windows update introduces a new bug or breaks compatibility with a specific application. Here is how to handle it. First, check Microsoft's known issues page for the specific update (search for the KB number on the Microsoft support website). If the issue is known, Microsoft often provides a workaround or a timeline for a fix. If you need to remove the update, go to **Settings > Windows Update > Update history**, scroll to the bottom, and click **Uninstall updates**. Find the problematic update, select it, and click **Uninstall**. The computer will restart and revert the change. After uninstalling, pause updates on the affected machine for 7 days to prevent the same update from reinstalling immediately. Go to **Settings > Windows Update** and click **Pause updates**. Report the issue to your IT provider so they can evaluate whether the update should be paused across all machines in the office, or whether the problem is specific to one device or application. ## Need help? Keeping every computer in your office patched and secure without disrupting your team takes planning and the right tools. If you want to stop worrying about updates entirely, [talk to Athencia](/contact). We handle patching, monitoring, and compliance reporting so you can focus on running your business. #### How to Plan Your Office Migration from Windows 10 to Windows 11 > Practical migration guide for small businesses moving from Windows 10 to Windows 11 before end of support, covering hardware requirements, timeline, and rollout strategy. URL: https://athencia.com/kb/windows/how-to-plan-your-office-migration-from-windows-10-to-windows-11 Windows 10 reached end of support in October 2025. That means Microsoft no longer releases free security patches for it. Every Windows 10 computer still running in your office is a growing security liability, and with each passing month, new vulnerabilities are discovered and left unpatched on those machines. Migrating to Windows 11 requires checking hardware compatibility, planning a rollout that minimizes disruption, and replacing machines that cannot make the upgrade. If you have not started this migration yet, now is the time. Here is how to plan and execute it. ## Why this is urgent End of support is not just a label. It means your Windows 10 computers no longer receive the monthly security updates that protect against newly discovered vulnerabilities. Every Patch Tuesday, new fixes are released for Windows 11, and attackers know that those same vulnerabilities exist on Windows 10 but will never be patched there. Cyber insurance policies may not cover breaches that occur on unsupported operating systems. If your insurer investigates a claim and finds that the compromised machine was running Windows 10 after end of support, they have grounds to deny coverage. Compliance frameworks including HIPAA, PCI DSS, and CIS Controls require that systems run supported software. Microsoft does offer paid Extended Security Updates (ESU) for Windows 10 at $61 per device for the first year, with the cost increasing each subsequent year. ESU is a temporary bridge for machines you cannot replace immediately, but it is not a long-term solution. The goal should be to get every machine onto Windows 11. ## Step 1: Inventory your current hardware Before you upgrade anything, you need a clear picture of what you have. List every Windows computer in your office: desktops, laptops, shared workstations, and any machines in conference rooms or reception areas. For each device, record the manufacturer, model, approximate age, current Windows version, and the primary user. If your devices are enrolled in Microsoft Intune (included with Microsoft 365 Business Premium), you can pull this inventory from the Intune admin center. Go to **Devices > All devices** and export the list. Intune shows the device model, OS version, last check-in date, and compliance status for every enrolled device, which saves you from walking to each desk. If you are doing this manually, you can check each machine by going to **Settings > System > About**. This screen shows the Windows edition, version, processor, and installed RAM. ## Windows 11 hardware requirements Windows 11 has stricter hardware requirements than Windows 10. The most common blocker is the processor requirement. - **Processor:** 1 GHz or faster with 2 or more cores on a compatible 64-bit processor. In practice, this means Intel 8th generation (Coffee Lake, released 2017-2018) or newer, or AMD Ryzen 2000 series or newer. - **RAM:** 4 GB minimum. For business use, 8 GB or more is strongly recommended. - **Storage:** 64 GB minimum. For practical use, 256 GB or more is recommended. - **TPM:** Version 2.0 is required. Most business PCs manufactured from 2018 onward have TPM 2.0 built in. - **UEFI firmware with Secure Boot** is required. The quickest way to check a specific machine is to download and run the **Microsoft PC Health Check** app. It gives you a simple pass or fail result and tells you exactly which requirements are not met. The biggest blocker for most offices is the processor requirement. Machines older than 2018 typically have CPUs that are not on Microsoft's supported list, and there is no workaround for this. ## Step 2: Categorize your machines After checking each device, sort them into three categories: **Can upgrade in place.** The machine meets all Windows 11 hardware requirements. Windows 11 can be installed on top of Windows 10 without wiping the machine, preserving all files, applications, and settings. This is the simplest path. **Needs replacement.** The machine does not meet hardware requirements, usually because of the processor or TPM. These machines must be replaced with new hardware. **Borderline.** The machine meets the requirements but is old enough (four or more years) that you should consider whether it makes sense to upgrade it or replace it. Upgrading a five-year-old laptop to Windows 11 is technically possible, but you may only get another year or two of useful life from that hardware before it needs replacement anyway. In many cases, replacing these machines now saves you from doing it again in 18 months. ## Step 3: Plan the rollout Do not upgrade all machines at once. A phased rollout lets you catch problems early before they affect your entire office. **Phase 1: Pilot group.** Upgrade 3 to 5 machines first. Choose a mix of roles (someone in accounting, someone in operations, etc.) so you can test how different applications and workflows perform on Windows 11. Run the pilot for at least one week and ask the pilot users to report any issues with their applications, printers, or other peripherals. **Phase 2: Main deployment.** After the pilot confirms no major issues, upgrade the remaining compatible machines in batches of 5 to 10 per week. Schedule upgrades for evenings or weekends so the machines are ready to use the next business morning. The in-place upgrade takes 1 to 3 hours per machine depending on hardware speed and the amount of data on the drive. **Phase 3: Hardware replacements.** Replace incompatible machines as budget allows. Prioritize users who work with sensitive data (client records, financial information, healthcare data) because those machines carry the highest risk while running an unsupported operating system. For businesses with devices enrolled in Microsoft Intune, you can manage the Windows 11 upgrade centrally. Intune lets you create a Windows feature update deployment policy that targets specific groups of devices, so you can roll out the upgrade in phases without touching each machine individually. ## Step 4: Check application compatibility Most modern business applications work on Windows 11 without issues. Microsoft Office, Microsoft 365 apps, major web browsers, and most cloud-based applications are fully compatible. Test your critical applications during the pilot phase. This means any line-of-business applications, accounting software (QuickBooks, Sage), practice management tools, EHR systems, or industry-specific software. Open them, run through typical workflows, and confirm everything behaves as expected. Check with your software vendors for Windows 11 compatibility statements. Most vendors publish these on their support websites. If you use any software that specifically requires Internet Explorer or a 32-bit-only environment, it may have issues on Windows 11. These situations are rare but worth checking. Also verify that your printers and peripherals have Windows 11 drivers available. Check the manufacturer's website for driver downloads for your specific models. ## Step 5: Perform the upgrade Before upgrading any machine, back up the user's data. Even though an in-place upgrade preserves files and settings, having a backup ensures you can recover if something goes wrong. If the user's files are already syncing to OneDrive or SharePoint, verify the sync is current before starting. Run the upgrade through **Settings > Windows Update**. If the Windows 11 upgrade is available for the device, it will appear as an optional update. Click **Download and install** and follow the prompts. Alternatively, download the **Windows 11 Installation Assistant** from Microsoft's website and run it directly. After the upgrade completes, verify the following: all applications open and work correctly, printers are connected and printing, the user can access email and calendar in Outlook, Teams calls and meetings work (test microphone and camera), and shared files on OneDrive, SharePoint, or network drives are accessible. Run **Windows Update** again to pick up any post-upgrade patches. ## Budgeting for replacements For machines that need replacement, plan for approximately $800 to $1,200 per laptop and $600 to $1,000 per desktop for business-grade hardware. Business-class machines from Dell (Latitude), HP (EliteBook), and Lenovo (ThinkPad) are built for durability and manageability and are the recommended options. A typical 20-person office may need to replace 5 to 10 machines that do not meet Windows 11 requirements. If budget is tight, stagger purchases across 2 to 3 months, prioritizing the highest-risk machines first. Consider refurbished business-class machines as a cost-effective option. A refurbished Dell Latitude or Lenovo ThinkPad that is 2 to 3 years old will meet Windows 11 requirements and cost significantly less than a new machine. Factor in setup time for new machines: 2 to 4 hours per device for configuration, application installation, and data migration. For businesses with more than a handful of new machines to deploy, Microsoft Autopilot (included with Microsoft 365 Business Premium) eliminates most of this manual work. With Autopilot, you register the new device's hardware ID with your tenant, and when the employee powers on the laptop and signs in with their work credentials, all policies, applications, and settings deploy automatically. Athencia configures Autopilot as part of its [managed IT stack](/athencia-one), so new laptops can be shipped directly to employees and set themselves up. ## What about machines you cannot replace yet If you have machines that cannot run Windows 11 and cannot be replaced immediately, here is how to reduce the risk. Purchase Extended Security Updates (ESU) from Microsoft. This provides continued security patches for Windows 10 at $61 per device for the first year. The cost increases each subsequent year, so this is a short-term measure. Isolate Windows 10 machines on the network as much as possible. If your office network supports VLANs, place these machines on a separate network segment with restricted access to sensitive resources. Make sure endpoint protection is current and actively monitored on these machines. Microsoft Defender for Business provides baseline protection, and layering Huntress Managed EDR on top adds 24/7 human threat monitoring. If a Windows 10 machine is compromised, you want to know about it immediately. Do not use Windows 10 machines for processing sensitive data. Move users who handle client records, financial data, or healthcare information to Windows 11 machines first. Plan to replace these machines within 12 to 18 months. ESU buys you time, but it is not a permanent solution. ## Need help? Migrating an entire office from Windows 10 to Windows 11 involves hardware decisions, compatibility testing, and careful scheduling. If you want help planning the rollout, budgeting for replacements, or setting up new machines with Autopilot, [contact Athencia](/contact). We will build a migration plan that fits your timeline and budget. #### How to Set Up a New Windows Laptop for a Small Business Employee > Checklist and guide for configuring a new Windows laptop for business use, covering security settings, Microsoft 365, and company policies. URL: https://athencia.com/kb/windows/how-to-set-up-a-new-windows-laptop-for-a-small-business-employee Setting up a new Windows laptop for a business employee involves joining it to your company's identity system, installing required software, configuring security settings, and verifying everything works before handing it over. Following a consistent process every time ensures that every device in your office meets the same security and configuration baseline, which is important for both protection and compliance. This guide walks through the full setup process step by step. If you are setting up more than a few machines, see the section at the end on automating this with Microsoft Autopilot. ## What you will need before starting Gather the following before you begin: - **The laptop,** powered on and connected to the internet. A wired Ethernet connection is preferred for faster downloads during setup, but Wi-Fi works fine. - **The employee's Microsoft 365 credentials** (email address and temporary password). If the account has not been created yet, set it up in the Microsoft 365 admin center first. - **A list of business applications** the employee needs for their role (line-of-business software, CRM, accounting tools, etc.). - **Admin credentials** for the device or your management platform. - **Your company's Wi-Fi network name and password.** ## Step 1: Complete Windows out-of-box setup (OOBE) When you power on a brand-new laptop for the first time, Windows walks you through the Out-of-Box Experience. Select your region, keyboard layout, and connect to the internet. **If your company uses Entra ID (formerly Azure AD):** When Windows asks how you want to set up the device, select **"Set up for work or school."** Enter the employee's work email address and password. This joins the laptop to your company's Entra ID tenant, which connects it to your organization's identity system, security policies, and management tools. This is the recommended path for any business using Microsoft 365 Business Premium. **If you are not using Entra ID:** Select **"Set up for personal use"** and create a local administrator account with a strong temporary password. After setup is complete, create a separate standard (non-admin) user account for the employee's daily use. Employees should not use an administrator account for everyday work. Administrator accounts can install software and change system settings, which means malware running under an admin account has full access to the machine. A standard account limits the damage that malware or accidental changes can cause. ## Step 2: Run all Windows updates Immediately after the initial setup, go to **Settings > Windows Update** and click **Check for updates**. Install all available updates. When prompted to restart, do so, then go back to Windows Update and check again. Some updates are sequential, meaning the second batch only appears after the first batch is installed and the machine has restarted. Continue this cycle until the Windows Update screen shows **"You're up to date"** with no pending restarts. On a brand-new laptop, this process can take 30 to 60 minutes. Factor this time into your setup schedule. It is tempting to skip this step and hand the laptop over, but an unpatched machine is vulnerable from the moment it connects to the network. ## Step 3: Configure security settings With the laptop updated, configure the core security settings. **Verify Windows Security (Defender) is active.** Go to **Settings > Privacy & security > Windows Security** and click **Open Windows Security**. Check that Virus & threat protection shows a green checkmark and that definitions are up to date. Microsoft Defender for Business, included with Microsoft 365 Business Premium, provides stronger protection than the basic consumer version of Defender, including attack surface reduction rules, web filtering, and centralized alerting. Athencia layers Huntress Managed EDR on top of Defender for Business for all client devices. Huntress provides 24/7 monitoring by a human security operations center (SOC) that investigates suspicious activity, confirms real threats, and initiates response actions. If your company uses Huntress, install the Huntress agent now. Your IT provider will supply the installer and the organization key needed during installation. **Enable BitLocker drive encryption.** Go to **Settings > Privacy & security > Device encryption** and turn it on. If the full BitLocker settings are available (on Pro or Enterprise editions), open **Control Panel > System and Security > BitLocker Drive Encryption** and click **Turn on BitLocker**. Select **XTS-AES 256-bit** encryption. When prompted to back up the recovery key, save it to Entra ID if the device is joined to your tenant. This stores the recovery key centrally where administrators can access it. If the device is not joined to Entra ID, save the recovery key to a USB drive and store it in a secure location separate from the laptop. **Verify Windows Firewall is on.** Go to **Windows Security > Firewall & network protection**. All three network profiles (Domain, Private, and Public) should show the firewall as on. This is enabled by default, but it is worth confirming. ## Step 4: Install Microsoft 365 apps Open a web browser and navigate to **office.com**. Sign in with the employee's Microsoft 365 credentials. Click **Install Office** (or **Install apps** in the top right corner) to download the Microsoft 365 desktop application installer. Run the installer. This installs Word, Excel, PowerPoint, Outlook, Teams, and OneNote. After installation completes, open **Outlook** and sign in with the employee's work email. Outlook will automatically configure the email account. Verify that email sends and receives by sending a test message. Open **Teams** and sign in. Verify the employee can see their team channels and contacts. Open **OneDrive** from the system tray (bottom-right corner of the taskbar, look for the cloud icon) and sign in with the employee's work credentials. OneDrive will begin syncing any shared folders or libraries that are configured for the employee. If your company stores files in SharePoint document libraries, set up the sync for those libraries as well by navigating to the SharePoint site in a browser, clicking **Sync**, and confirming in the OneDrive app. ## Step 5: Install business applications Install the company-specific applications the employee needs for their role. This varies by business but typically includes: - **Line-of-business applications:** CRM, practice management, accounting software (QuickBooks, Sage), EHR systems, or industry-specific tools. - **1Password:** If your company uses 1Password as its password manager, install it now. Download it from 1password.com, install the desktop app and the browser extension, and have the employee sign in to the company vault. Setting up the password manager early in the onboarding process means the employee has secure access to all their account credentials from day one. - **VPN client:** If the employee needs remote access to on-premises resources, install the VPN client and configure the connection. - **Printers:** Connect to networked printers. Go to **Settings > Bluetooth & devices > Printers & scanners > Add device** and add the office printers by name or IP address. If your devices are managed with Microsoft Intune, many of these applications can be deployed automatically. Intune supports pushing Microsoft 365 apps, line-of-business applications, and Win32 apps to enrolled devices without manual installation. Check your Intune app deployment policies to see which applications are already configured for automatic deployment. ## Step 6: Apply company policies If the device is enrolled in Microsoft Intune, company policies apply automatically after enrollment. Intune pushes configuration profiles that control security settings, update policies, compliance requirements, and more. You can verify that policies are applying by going to **Settings > Accounts > Access work or school**, clicking on the connected account, and selecting **Info**. This shows the sync status and any policies applied to the device. If you are managing devices manually without Intune, configure the following settings by hand: - **Screen lock timeout:** Go to **Settings > System > Power > Screen and sleep**. Set the screen to turn off after 5 to 10 minutes of inactivity. Also require a password on wake by going to **Settings > Accounts > Sign-in options** and setting **"Require sign-in"** to **"When PC wakes from sleep."** - **Disable USB autorun:** Search for **"AutoPlay"** in Settings and turn off **"Use AutoPlay for all media and devices."** This prevents malware from executing automatically when a USB drive is inserted. - **Configure Windows Update:** Go to **Settings > Windows Update > Advanced options** and set active hours to match business hours so restarts only happen outside of work time. - **Set the default browser** if your company has a standard (Edge is the default on Windows 11 and integrates well with Microsoft 365). - **Configure power settings** appropriate for the employee's role. For desk workers, set the laptop to **"Best performance."** For employees who travel frequently, **"Balanced"** preserves battery life. ## Step 7: Verify and hand off Before handing the laptop to the employee, do a final verification pass. Restart the laptop one more time. After it boots, sign in with the employee's account and confirm the following: - **Email:** Open Outlook, send a test email, and verify it is received. - **Teams:** Start a test call. Verify the microphone picks up audio and the camera shows video. - **Files:** Open OneDrive and verify shared files and folders are visible and syncing. - **Printers:** Print a test page to each printer the employee needs. - **Applications:** Open each business application and confirm it launches and connects to any required servers or databases. - **Security:** Open Windows Security and confirm Defender and any additional endpoint protection (Huntress) show green/active status. Verify BitLocker is on. Walk the employee through the basics: how to lock the screen (Windows + L), where to find their key applications, how to connect to Wi-Fi at home or on the road, and who to contact for IT help. ## Automating setup with Microsoft Autopilot If your office is setting up more than a few laptops, doing this process manually for each one is time-consuming. Microsoft Autopilot, included with Microsoft 365 Business Premium, eliminates most of the manual work. With Autopilot, you register the new laptop's hardware ID with your Microsoft 365 tenant before the employee ever touches it. When the employee powers on the laptop for the first time and signs in with their work email, Autopilot takes over. It joins the device to Entra ID, enrolls it in Intune, applies all company policies, installs assigned applications, and configures security settings, all automatically. The employee ends up with a fully configured, compliant device without anyone from IT needing to touch the machine. This means new laptops can be shipped directly from the vendor or retailer to the employee's home or desk. The employee opens the box, powers it on, signs in, and everything configures itself. Athencia sets up Autopilot as part of its [managed IT stack](/athencia-one) so that every new device deployment is consistent and secure. ## Setup checklist summary - Windows OOBE complete and joined to Entra ID (or local account created) - All Windows updates installed - BitLocker enabled and recovery key backed up to Entra ID - Endpoint protection installed and active (Defender for Business + Huntress) - Microsoft 365 apps installed and configured (Outlook, Teams, OneDrive) - Business applications installed - 1Password installed and signed in - Printers connected - Company policies applied (via Intune or manually) - All functionality verified - Employee walked through basics ## Need help? Setting up laptops consistently is one of the most important things you can do for your business's security posture. If you want to streamline the process with Autopilot, or if you need help configuring Intune policies for your devices, [contact Athencia](/contact). We will make sure every device that enters your organization is set up right from the start.