# Athencia — Full Site Content > Complete content from athencia.com for LLM reference. See https://athencia.com/llms.txt for a summary. ## Homepage Athencia is a managed IT services and cybersecurity company based in Lynnwood, Washington, serving small businesses with 5 to 75 employees across the Greater Seattle area. Founded by Jeremy Phillips, Athencia specializes in IT management for professional services firms including law offices, CPA firms, and financial advisors. One dashboard shows your IT health at a glance. Green means good. Yellow means check on it. Red means let's talk. No jargon. No guesswork. Two service tiers: Athencia One (visibility + on-demand support) and Athencia One Complete (fully managed IT). Professional Services available for project-based work. - https://athencia.com ## About Jeremy Phillips founded Athencia after 30+ years building and running IT systems. Started in the 90s with Exchange and network infrastructure. Ran operations at enterprise scale — environments with over 16 million mailboxes. Led teams, managed multi-million dollar P&Ls, ran technology strategy for growing organizations. Athencia is independent and locally owned. Not backed by private equity. Named after Athena, goddess of wisdom and strategy. - https://athencia.com/about ## Athencia One Visibility and on-demand support for small businesses. One dashboard shows IT health at a glance using green/yellow/red indicators. Escalate directly from the portal when something needs attention. We fix it and bill for the time. Includes: Microsoft 365 Business Premium, Huntress 24/7 SOC (EDR, ITDR, SAT, SIEM), Dropsuite M365 backup, managed patching via Level RMM, CIS Controls baseline alignment with ControlMap, and the Athencia One Portal. 1Password available as optional add-on (+$5/user/mo). Pricing: $45-55/user/month depending on team size. Support billed hourly when needed. Best for: Firms with 5-75 employees that have some internal IT resources or a technical partner and prefer paying for support as needed. - https://athencia.com/athencia-one ## Athencia One Complete Fully managed IT and cybersecurity. Everything in Athencia One plus: unlimited user support, 24/7 security monitoring, device management, user onboarding/offboarding, vendor coordination, quarterly business reviews, Virtual IT Manager, and 1Password Business included. Pricing: $159-199/user/month depending on team size. Flat monthly fee, unlimited support included. Founder direct line for business-critical emergencies. Best for: Firms with 5-75 employees that don't have internal IT resources and want someone to handle everything. - https://athencia.com/athencia-one-complete ## Professional Services Project-based IT consulting: Microsoft 365 migrations, security assessments, network redesigns, device fleet overhauls, vendor evaluations, and AI workshops. 30+ years of hands-on Microsoft experience. Pricing models: Hourly ($150-200/hr), fixed-fee (defined deliverables, quoted upfront), or retainer (reserved hours at preferred rate). Process: Discovery > Scope > Execute > Handoff. Documentation and knowledge transfer included. - https://athencia.com/professional-services ## Pricing Athencia One: $45-55/user/month (visibility + on-demand support, support billed hourly). Athencia One Complete: $159-199/user/month (fully managed, unlimited support included). Professional Services: Hourly, fixed-fee, or retainer. No long-term contracts required. Onboarding fee based on environment complexity. - https://athencia.com/pricing ## Technology Stack Athencia standardizes on a curated stack rather than supporting every possible tool: - Identity & Productivity: Microsoft 365 Business Premium — https://athencia.com/stack/microsoft-365-business-premium - Endpoint Security: Huntress Managed EDR + ITDR + SAT + SIEM — https://athencia.com/stack/huntress - Backup: Dropsuite for Microsoft 365 and Entra ID — https://athencia.com/stack/dropsuite - Device Management: Level RMM — https://athencia.com/stack/level-rmm - Password Management: 1Password Business — https://athencia.com/stack/1password - Compliance Mapping: ControlMap — https://athencia.com/stack/controlmap - Business Phone Systems: Quo VoIP or Microsoft Teams Phone — https://athencia.com/stack/phone-systems - https://athencia.com/stack ## Service Area Greater Seattle, Washington: Seattle, Bellevue, Redmond, Kirkland, Bothell, Everett, Lynnwood, Edmonds, Shoreline, Mountlake Terrace. Remote clients supported nationwide via cloud-native delivery. - https://athencia.com/areas-we-serve --- ## Blog ### What the FTC Safeguards Rule Actually Requires from Your Accounting Firm > The FTC Safeguards Rule applies to accounting firms of every size. Here is what it actually requires, where most small firms fall short, and what Microsoft 365 does and does not cover. Published: 2026-03-21 | Author: Jeremy Phillips | Category: Compliance URL: https://athencia.com/blog/ftc-safeguards-rule-accounting-firms If you run an accounting or tax practice, there is a good chance you have heard of the FTC Safeguards Rule. There is also a good chance you are not entirely sure what it requires, whether you are covered, or whether your current IT setup actually meets the bar. This post covers what the rule says, what it means in practice for a small professional services organization, and where most accounting practices fall short without realizing it. ## What is the FTC Safeguards Rule? The Safeguards Rule is a regulation from the Federal Trade Commission that requires financial institutions to protect customer information with a Written Information Security Program (WISP). It has existed in some form since 2003, but the FTC significantly updated the requirements in 2023 with more specific, prescriptive obligations. "Financial institution" under the Safeguards Rule is broader than most people expect. It includes banks and credit unions, but it also covers tax preparers, accountants, mortgage brokers, investment advisors, and any business that provides financial products or services to consumers. If your organization handles tax returns, financial statements, or client financial records, you are almost certainly covered. The rule was not written for large companies. It was explicitly designed to apply to businesses of all sizes, and the FTC has been clear that "small" is not an exemption. ## What the rule requires The 2023 updates moved the rule from vague principles to specific requirements. Here is what you actually need to have in place. **A Written Information Security Program (WISP)** This is the foundation of the rule. You need a documented security program that covers how your organization handles, protects, and manages customer information. "Documented" means written down, not just something you do informally. The program needs to be tailored to your organization's size and complexity. A 10-person CPA practice does not need the same WISP as a large financial institution, but the program still needs to exist and actually reflect how your organization operates. **A designated Qualified Individual** The rule requires you to designate someone to oversee your information security program. This does not have to be a full-time security professional. For most small organizations, it is the owner or a senior partner. But someone has to own this formally, and their name needs to be in writing. **A risk assessment** You need to conduct and document a risk assessment that identifies the risks to customer information at your organization. This includes things like who has access to client data, how it is transmitted and stored, what happens when an employee leaves, and what third-party vendors touch your data. The key word is "documented." Knowing in your head that your organization has some risks does not satisfy the rule. You need a written assessment. **Specific security controls** The 2023 update added a list of required controls. These include: - Encryption of customer information, both in transit and at rest - Multi-factor authentication for anyone accessing systems with customer data - Access controls that limit who can see what - Monitoring and testing of your safeguards - A patch management process for software updates - Secure disposal of customer information when it is no longer needed For most accounting firms, the honest question is not whether they have heard of these controls. It is whether they have actually implemented them across their environment. **A written incident response plan** If something goes wrong, you need a plan for how to respond. The rule requires a written incident response plan that addresses how you detect, contain, and recover from a security event. It also needs to cover how you notify affected customers when required. **Annual reporting to the board or senior management** Someone with oversight responsibility at the organization needs to receive a written report at least annually covering the status of your information security program. For a small organization, this might be a one-page summary reviewed by the managing partners. But it needs to happen and be documented. **Oversight of service providers** If you use vendors that access customer information (cloud software, payroll providers, document management systems, your IT provider), you need to have contracts in place that require them to implement appropriate security measures. You also need to periodically review their security practices. This is one area where a lot of small organizations have gaps. Many accounting practices use a handful of cloud tools and have never reviewed the security provisions in those vendor agreements. ## Where most small accounting firms fall short After working with professional services organizations for years, the gaps I see most often are not exotic. They are straightforward. **No written WISP.** Most small organizations have some informal security practices but nothing documented. The Safeguards Rule requires written documentation. "We do it this way" does not satisfy a regulator. **MFA is inconsistent.** Multi-factor authentication is specifically required under the rule. A lot of organizations have it turned on for some systems but not others. Your practice management software might have MFA enabled while your email, file storage, or client portal does not. **No formal risk assessment.** Knowing your organization handles sensitive data is not the same as having a documented risk assessment. The rule requires you to actually conduct and record one. **Employee offboarding gaps.** When someone leaves the organization, their access to client data needs to be terminated promptly. This sounds obvious, but it fails in practice regularly. Shared passwords, old email accounts, lingering access to cloud tools. These are compliance violations and security risks. **Vendor agreements without security provisions.** Most small organizations sign up for software tools without paying close attention to the data handling provisions in the agreement. The Safeguards Rule requires you to ensure your vendors are protecting customer data appropriately. ## What Microsoft 365 covers and what it does not Most accounting firms run on Microsoft 365. It is a good platform and it includes a lot of security capability. But M365 Business Premium does not automatically make you Safeguards Rule compliant. What M365 Business Premium gives you: MFA, encryption in transit, Conditional Access policies, Intune for device management, Defender for endpoint protection. These are real security controls that map to Safeguards Rule requirements when they are properly configured. What it does not give you automatically: a written WISP, a risk assessment, a documented incident response plan, vendor oversight records, or the governance layer the rule requires. Those have to be built on top of the technical controls. The platform is necessary but not sufficient. Compliance requires both the controls and the documentation. ## What enforcement actually looks like The FTC has authority to investigate and fine businesses that violate the Safeguards Rule, and they have used it. Fines can reach $50,120 per violation per day for knowing violations. Beyond federal enforcement, some states have their own data security laws with additional requirements and penalties. The more practical concern for most small accounting firms is not an FTC audit. It is a data breach. If your organization experiences a breach and it turns out you did not have the required security program in place, you are looking at regulatory exposure, potential civil liability, and the kind of reputational damage that is very hard to recover from in a business built on client trust. The Safeguards Rule is not just a compliance checkbox. It is a floor for reasonable security practice. Most of what it requires you would want to do anyway. ## Getting compliant without hiring a full-time security team A 15-person accounting firm does not need a CISO. But you do need someone who understands what the rule requires and can build the documentation and controls to meet it. That is what [Athencia Comply](/athencia-comply) is designed for. We help professional services organizations build the written WISP, implement the technical controls through [Athencia One Complete](/athencia-one-complete), document the risk assessment, and prepare you for the oversight and renewal obligations that come after the initial setup. The goal is not to bury you in paperwork. It is to build a security program that is real, documented, and maintainable by a small organization without a dedicated IT staff. If you are not sure where your organization stands against the Safeguards Rule requirements, the right first step is a gap assessment. Start there before worrying about anything else. --- Ready to find out where you actually stand? [See how Athencia Comply works](/athencia-comply) or [get in touch directly](/contact) for a straightforward conversation about what your organization needs. #### FAQs **Q: Does the FTC Safeguards Rule apply to small accounting firms?** A: Yes. The rule applies to any business that qualifies as a "financial institution" under the Gramm-Leach-Bliley Act, which includes tax preparers, accountants, and financial planners of any size. There is no small business exemption, though the rule does acknowledge that requirements should be "appropriate to the size and complexity" of your organization. **Q: What is the difference between the original Safeguards Rule and the 2023 updates?** A: The original rule required financial institutions to have a security program but was largely principles-based. The 2023 updates added specific required controls: encryption, MFA, access controls, patch management, incident response plans, and annual reporting obligations. The updated rule is significantly more prescriptive and harder to satisfy with vague general practices. **Q: Does Microsoft 365 Business Premium make my firm Safeguards Rule compliant?** A: Not by itself. M365 Business Premium includes many of the technical controls the rule requires (MFA, encryption, device management), but it does not provide the written documentation, risk assessment, incident response plan, or governance layer the rule also requires. You need both the technical controls and the program documentation. **Q: What happens if my firm has a data breach and is not compliant with the Safeguards Rule?** A: A breach while non-compliant creates significant exposure. The FTC can investigate and fine violators. Individual states may have additional data breach notification requirements and penalties. Beyond regulatory action, civil liability from affected clients is possible. Perhaps most importantly for a small professional services firm, a breach that reveals inadequate security practices can cause lasting reputational damage. **Q: How long does it take to become Safeguards Rule compliant?** A: For most small accounting firms starting from a reasonable security baseline (M365, basic controls in place), getting to documented compliance takes roughly 60 to 90 days. The documentation and governance layer takes time regardless of how strong the underlying technical controls are. If your technical environment needs significant work first, the timeline extends accordingly. ### What Does a Managed IT Company Actually Do? > A plain-English breakdown of what managed IT companies do, what's included in their services, and how to tell if you actually need one. Published: 2026-02-05 | Author: Jeremy Phillips | Category: IT Operations & Management URL: https://athencia.com/blog/what-does-a-managed-it-company-actually-do If you've ever searched for IT help for your business, you've probably come across the term "managed IT" or "MSP" (managed service provider). But what does that actually mean? And how is it different from just hiring someone to fix your computer when it breaks? This article breaks down what managed IT companies do, what you can expect from their services, and how to figure out if this model makes sense for your business. ## The basic idea behind managed IT A managed IT company takes responsibility for some or all of your technology infrastructure. Instead of waiting for something to break and then scrambling to fix it, they monitor your systems, apply updates, and address small issues before they become big problems. Think of it like the difference between waiting for your car to break down on the highway versus getting regular oil changes and inspections. The second approach costs more upfront, but it keeps you from being stranded. Most managed IT companies charge a flat monthly fee per user or per device. In exchange, you get ongoing monitoring, maintenance, and support. The specifics vary by provider, but the core concept is the same: predictable costs in exchange for proactive management. ## What's typically included Managed IT services usually cover several areas: **Monitoring and maintenance** Your provider watches your systems around the clock (or during business hours, depending on your plan). They track things like server health, disk space, backup status, and security alerts. When something looks wrong, they investigate before it affects your team. **Patching and updates** Software updates are tedious but important. They fix bugs and close security holes. A managed IT company handles this for your operating systems, applications, and security tools so you don't have to remember to do it yourself. **Help desk support** When your employees have IT problems, they contact your managed IT provider instead of trying to figure it out themselves or bothering a coworker who "knows computers." Good providers offer multiple contact methods: phone, email, chat, or a support portal. **Security tools and monitoring** Modern managed IT includes security. This might mean endpoint protection (antivirus and more), email filtering, security awareness training for employees, and monitoring for suspicious activity. Some providers include a security operations center (SOC) that watches for threats 24/7. **Backup and disaster recovery** Your data needs to be backed up, and those backups need to be tested. Managed IT providers typically handle this, ensuring your data is recoverable if something goes wrong. ## What's usually extra Some services cost additional fees on top of the base managed IT agreement: - Hardware purchases (computers, networking equipment) - Major projects like office moves or system migrations - Compliance management for regulated industries - On-site visits (many providers are remote-first) - After-hours emergency support (some include this, others charge extra) Ask any provider you're considering what's included and what costs extra. The answers vary significantly. ## How managed IT differs from other options **In-house IT staff** Hiring your own IT person gives you someone dedicated to your business. But one person can't be an expert in everything: security, networking, Microsoft 365, backups, and user support. They also take vacations and sick days. Managed IT gives you a team with diverse expertise and coverage beyond a single person's availability. **Break-fix support** Break-fix means you call someone when something breaks, they fix it, and you pay for that specific work. It's simple and feels cheaper in the short term. But it's reactive: you're always dealing with problems after they've disrupted your business. Managed IT flips this model to prevention. **Hiring a consultant** IT consultants are great for specific projects or strategic advice, but they're not designed for day-to-day operations. You might hire a consultant to plan a cloud migration and a managed IT provider to run your systems afterward. ## Signs you might need managed IT Not every business needs managed IT. But you might benefit from it if: - Your team wastes time dealing with IT issues instead of their actual jobs - You've been hit by a security incident or close call - You're growing and your informal IT setup isn't scaling - You handle sensitive data (client information, financial records, health data) - You can't afford downtime and need systems that just work - You want predictable IT costs instead of surprise bills ## Questions to ask a managed IT provider Before signing up, get clear answers to these questions: 1. What's included in the monthly fee versus billed separately? 2. What are your response time targets for different issue types? 3. What security tools and practices do you use? 4. How do you handle onboarding for new clients? 5. Can I see references from businesses like mine? 6. What happens if we need to part ways? The answers will tell you a lot about whether the provider is a good fit. ## The bottom line Managed IT companies exist to handle your technology so you can focus on your business. They monitor, maintain, and support your systems for a predictable monthly cost. The value comes from prevention: catching issues early, keeping systems updated, and having experts available when problems do occur. Whether this model makes sense for you depends on your business size, complexity, and tolerance for IT headaches. But if you're tired of technology problems interrupting your work, managed IT is worth investigating. #### FAQs **Q: What's the difference between break-fix IT and managed IT?** A: Break-fix IT means you call someone when something breaks and pay for repairs. Managed IT is proactive: you pay a monthly fee and the provider monitors, maintains, and fixes issues before they cause downtime. Managed IT typically costs more upfront but saves money by preventing problems rather than reacting to them. **Q: How much does managed IT cost for a small business?** A: Managed IT services typically cost between $50 and $200 per user per month, depending on the level of service. Basic plans include monitoring and patching. Comprehensive plans add unlimited support, security tools, compliance management, and vendor coordination. Most providers offer tiered pricing based on what you need. **Q: Can I keep my current software and systems with a managed IT provider?** A: Usually, yes. A good managed IT provider will assess your current setup and integrate with the tools you already use. They may recommend changes if something is outdated or creates security risks, but the goal is to improve your environment, not force you to start over. **Q: What should I look for when choosing a managed IT company?** A: Look for transparent pricing, clear response time commitments, security certifications or frameworks they follow (like CIS Controls), and references from businesses similar to yours. Ask about their onboarding process and how they handle emergencies. Avoid providers who won't explain what's included or push long-term contracts before you've worked together. ### Why 'Just Do a Weekly Offsite Backup' Is the Worst Advice Your Business Will Ever Get > A weekly offsite backup sounds reasonable until you lose a week of client data. Here is what a real backup and disaster recovery strategy looks like for SMBs in 2026. Published: 2026-02-19 | Author: Jeremy Phillips | Category: Cybersecurity URL: https://athencia.com/blog/why-weekly-offsite-backup-is-bad-advice I recently sat through a cybersecurity webinar aimed at small business owners. The presenter was a federal forensic analyst with impressive credentials. The first half covered the current cybercrime landscape, how threat actors operate, how ransomware-as-a-service has made attacks more accessible than ever. Solid stuff. Then the conversation shifted to what businesses should actually do about it. And when it came to backups, the recommendation was this: do a weekly offsite backup so that if you get hit with ransomware, you only lose a week of data. I nearly fell out of my chair. If you run a business with 10, 20, or 50 employees and someone tells you that a weekly offsite backup is a valid strategy against ransomware, they are giving you advice that could cost you your company. Let me explain why, and more importantly, what you should be doing instead. ## The problem with "Just Do a Weekly Offsite Backup" On the surface, the logic makes sense. You have a copy of your data, it lives somewhere other than your office, and if something bad happens, you can restore from it. But "only losing a week of data" is being treated like an acceptable outcome here, and it is not. Not even close. **A week of data loss can be fatal.** Think about what your business produces in a week. Emails sent, contracts drafted, invoices generated, client work delivered, accounting entries logged. For a 20-person law firm or accounting practice, a week of lost data is not an inconvenience. It is a crisis. Reconstructing a week of billable work, correspondence, and financial transactions is not just expensive. In many cases, it is impossible. **Weekly is not frequent enough.** If your last backup was six days ago and you get hit today, you are looking at nearly a full business week of lost work. For many small businesses, that amount of data loss means missed deadlines, broken client commitments, compliance violations, and real financial damage. The recovery point objective (how much data you can afford to lose) for most businesses should be measured in hours, not days. **Offsite backup alone does not get you back up and running.** Even if your weekly offsite backup is perfectly intact, restoring from it takes time. You need hardware to restore to. You need to rebuild the environment. You need to verify the data. For many businesses, this process takes days or even weeks. Every hour of downtime costs money, and a weekly offsite backup has no answer for the question, "How do we keep working while we recover?" **Ransomware does not wait for your backup schedule.** Many ransomware variants sit dormant for days or weeks before activating, quietly spreading across your environment. By the time the encryption kicks in, your last several weekly backups may already contain the compromised payload. Restoring from any of them just reinfects you. The bottom line: a weekly offsite backup is better than nothing, but it is nowhere near good enough. It is a 2008 strategy being recommended in 2026, and it gives business owners a dangerous false sense of security. ## What most small businesses get wrong about Microsoft 365 backups Here is something that surprises a lot of business owners: Microsoft does not back up your data for you. When you are paying for Microsoft 365, you are paying for the platform, the applications, and the infrastructure. You are not paying for data protection. Microsoft is very clear about this. Their Shared Responsibility Model puts the responsibility for protecting your data squarely on you. Their service agreement even recommends using third-party backup solutions. Most people never read that. They assume that because their email is "in the cloud," it is safe. It is not. Here is what can go wrong: - **Accidental deletion.** Someone deletes a critical email, a SharePoint folder, or a OneDrive file. Once it clears the recycle bin (which Microsoft only retains for up to 93 days in most cases), it is gone. Permanently. - **Ransomware and malware.** A compromised account can encrypt or delete files across Exchange, OneDrive, SharePoint, and Teams. Microsoft's native tools have limited recovery options for this. - **Departing employees.** When someone leaves and their license gets removed, their mailbox and OneDrive data have limited retention windows. If you do not act fast, you lose it. - **Compliance and legal holds.** If you are ever involved in litigation or need to produce historical records for a compliance audit, Microsoft's native retention is not built to be your archive. You need a real solution for that. The reality is that for most small businesses, their entire operation lives inside Microsoft 365. Email, files, calendars, contacts, shared documents, Teams conversations. If any of that disappears and you do not have an independent backup, you are in serious trouble. ## What a real Microsoft 365 backup strategy looks like A proper M365 backup solution runs automatically, multiple times per day, and stores your data independently from Microsoft's infrastructure. No USB drives. No human intervention. No hoping someone remembered to run the backup before they left for the weekend. At Athencia, we use Dropsuite for Microsoft 365 backup across our managed clients. Here is what that actually means for your business: **Automated, incremental backups.** Your Exchange mailboxes, OneDrive files, SharePoint sites, Teams data, calendars, and contacts are backed up automatically, multiple times daily. No one has to remember to do anything. It just happens. **Immutable storage.** Your backup data is stored in a separate cloud environment with immutable protection. That means even if an attacker compromises your Microsoft 365 tenant, they cannot reach your backups. This is the critical difference between a real backup solution and simply having a copy of your data sitting somewhere offsite. **Granular, point-in-time recovery.** Need to restore a single email from three weeks ago? A SharePoint folder from last Tuesday? A departed employee's entire mailbox? You can do all of that without restoring everything. You pick exactly what you need and recover it to the exact point in time you choose. **Unlimited storage.** No worrying about storage capacity limits or paying overage fees. Your backup grows with your data. **Built-in compliance and eDiscovery.** For professional services organizations that deal with client data, legal holds, or regulatory requirements, having a searchable archive of all email and file history is not a nice-to-have. It is a necessity. The difference between this approach and the weekly offsite recommendation is not incremental. It is the difference between being able to recover from an incident in minutes versus discovering, days later, that your last good backup was from last weekend and half your client files are gone. ## But what about on-premises servers? That is where BCDR comes in Cloud backup solves the Microsoft 365 problem, but many small businesses still have on-premises infrastructure. Maybe it is a file server, a line-of-business application, a database, or a domain controller. For these workloads, you need something more than backup. You need business continuity and disaster recovery, or BCDR. The difference between backup and BCDR is critical. A backup saves your data. BCDR saves your business. With a true BCDR solution, if your server goes down, whether from hardware failure, ransomware, fire, flood, or anything else, you can spin up a virtual copy of that server within minutes, either on the local appliance or in the cloud. Your team keeps working while you deal with the underlying problem. We deploy Slide BCDR appliances for our clients' on-premises workloads. Slide was founded by the same team that built Datto (one of the most widely deployed BCDR platforms in the MSP space) and designed from scratch with no legacy code. Here is what makes this approach different from a weekly offsite backup: **Frequent, image-level backups.** Instead of copying files once a week, a BCDR appliance takes full image snapshots of your servers multiple times per day. If you need to recover, you are restoring the entire system, not just files, to a point in time that is hours old, not days. **Local and cloud virtualization.** If a server fails, you can boot a virtual machine directly from the backup appliance. Your team can keep working while the primary server is repaired or replaced. If the entire office goes down, you can spin up in the cloud and operate remotely. **All-flash, high-performance hardware.** The Slide Z1 appliance uses NVMe solid-state storage, which means backups and restores happen fast. There are no spinning disks to fail, no mechanical parts to wear out. For a small office, the entry-level appliance is about the size of an Apple Mac Studio and can store up to 16TB of protected data. **End-to-end encryption.** Data is encrypted on the appliance, in transit, and in the cloud. This is built in, not an add-on. **Offsite replication to a private cloud.** Your backups are automatically replicated to a dedicated private cloud, not a shared public cloud environment. If the worst happens and your office is physically destroyed, your data and your ability to run your systems are still intact. This is what modern disaster recovery looks like. It is not a weekly backup job and a prayer. It is an automated, tested, always-on system that keeps your business running when everything else goes wrong. ## Putting it all together: the two-layer approach For most small businesses in 2026, the right backup and recovery strategy has two layers: **Layer 1: Cloud-to-cloud backup for Microsoft 365.** This covers your email, files, SharePoint, Teams, and everything else that lives in Microsoft's cloud. A solution like Dropsuite runs automatically, stores your data independently, and gives you granular recovery when you need it. **Layer 2: BCDR for on-premises workloads.** This covers your servers, applications, and anything that runs locally. A solution like Slide gives you frequent image-level backups, instant local or cloud virtualization, and offsite replication so you can survive anything from a hardware failure to a total office loss. Together, these two layers mean that no matter what happens, whether it is ransomware, accidental deletion, hardware failure, a disgruntled employee, a natural disaster, or just plain bad luck, your data is protected and your business can keep running. Compare that to a weekly offsite backup and hoping for the best. ## What to ask your IT provider If you are a business owner reading this and you are not sure where you stand, here are the questions you should be asking your IT provider or MSP today: - Do we have a third-party backup for our Microsoft 365 data, or are we relying on Microsoft's native retention? - How often are our backups running, and how much data would we lose in a worst-case scenario? - If our server goes down right now, how long until we are back up and running? Is the answer measured in minutes, hours, or days? - Are our backups stored somewhere completely separate from our production environment? - Has our backup and recovery process been tested recently? Can you show me a successful restore? - If our entire office is destroyed, can we still operate? If your IT provider cannot answer these questions clearly, or if the answers involve the words "weekly" and "offsite" and not much else, it is time to have a different conversation. ## Stop hoping. Start protecting. The cybersecurity webinar I sat through was well-intentioned. The presenter was trying to help small businesses understand the threats they face. But good intentions paired with outdated advice can do more harm than good, because it gives business owners a false sense of security. If you walk away from a webinar thinking your weekly offsite backup has you covered, you are more vulnerable than you were before you attended, because now you think the problem is solved. It is not. Real data protection in 2026 means automated cloud backup for your SaaS platforms and BCDR for your on-premises infrastructure. It means your backups run without human intervention, are stored independently from your production systems, and can be recovered quickly when you need them. It means you know your data is safe instead of hoping it is. --- **Athencia** helps small businesses nationwide stop guessing about their IT and start seeing what is actually happening. With a local presence in the Greater Seattle area and the ability to support clients anywhere in the country, our managed IT plans include automated M365 backup, BCDR for on-premises workloads, and a single dashboard where you can see the health of your entire environment at a glance. *Want to find out where your backup strategy actually stands?* **Let's talk.** Visit [athencia.com](https://www.athencia.com) or reach out directly to schedule a no-pressure conversation about what is protecting your business today and what should be. ### Your VMware Bill Just Doubled. Here's What to Do About It. > Broadcom's VMware repricing has turned renewals into an exit-planning problem for SMBs. Here's what to know before moving from VMware to Hyper-V. Published: 2026-03-24 | Author: Jeremy Phillips | Category: IT Operations & Management URL: https://athencia.com/blog/your-vmware-bill-just-doubled-heres-what-to-do-about-it I've quoted this project at least twice a month for the last several months, which tells me something. The VMware-to-Hyper-V conversation has moved from "worth exploring someday" to "we need a plan before the next renewal invoice." Broadcom made that decision for a lot of SMBs. This is not a technical migration problem. It's a renewal deadline problem. Here's what actually happens on these projects, and what you should know before starting one. ## What happened to VMware Broadcom acquired VMware in late 2023 and has been repricing it ever since. Perpetual licensing is gone. The familiar Standard and Enterprise Plus SKUs are gone for new contracts. If you only need the hypervisor, you're buying a bundle and paying for shelfware. The 72-core minimum purchase attempt in early 2025 was the clearest signal yet, even after Broadcom walked it back. If you run a 2- or 3-node cluster, you're not their target customer anymore. You're long-tail revenue they're willing to squeeze or lose. I've personally seen massive increases in renewal quotes, and the number varies widely by environment and contract history. For most SMB environments, the math no longer works. ## Why Hyper-V, and why Azure Arc seals it For the SMB clients I work with, law firms, accounting practices, financial services, consultancies running Microsoft 365 and Entra ID, Hyper-V is almost always the right answer. It's already included in Windows Server (assuming properly licensed Datacenter or appropriately licensed Standard cores for your VM density). The management story is Windows Admin Center, which is browser-based and clean. Azure Site Recovery handles DR. The operational surface is familiar to any Windows admin. If something breaks at 2am, finding someone who can troubleshoot it is not a problem. There are situations where other platforms make sense. An environment with strong Linux expertise in-house and no Azure footprint, for example, might have good reasons to look at other options. If you're heavily invested in VMware-specific tooling or NSX, this becomes a different conversation. But for Microsoft shops, those situations are the exception. And the real reason I keep recommending Hyper-V over the alternatives has nothing to do with familiarity. It's Azure Arc. ## Azure Arc changes the calculus Most people frame this as a hypervisor replacement decision. I think of it as an on-premises positioning decision, and that framing changes everything. Azure Arc lets you extend Azure's management plane to your on-premises Hyper-V infrastructure. Your on-prem VMs show up in the Azure portal. You can apply Azure Policy to them, manage them through Defender for Cloud, enforce governance at the same level as your cloud resources, and use the same tooling your team already knows. It turns your Hyper-V cluster into a first-class node in your broader Azure estate rather than an isolated island managed through a separate workflow. (Some feature differences apply compared to native Azure VMs, depending on workload and agent coverage, but for the governance and visibility use cases that matter most to SMBs, it delivers.) For the professional services organizations I work with, this shows up in three ways. **Workload placement becomes an intentional decision.** With Arc in the picture, you're not locked into on-prem or cloud as a binary. You can run sensitive client data workloads on your own hardware, where you control the physical location and can speak to that clearly from a compliance standpoint, while spinning up burst compute or dev environments in Azure when it makes more sense economically. The management experience is unified either way. **Security posture stays consistent.** Defender for Cloud covers Arc-enrolled machines the same way it covers Azure VMs. Your server security posture, patch compliance, and vulnerability findings are all visible in one place across both environments. For a 30-person law firm with a hybrid footprint, that's a meaningful operational improvement over running two separate monitoring and compliance stories. **It gives you an honest migration path.** If some workloads genuinely belong in the cloud, and some of them probably do, Arc gives you the tools to evaluate that clearly and move them on your timeline. You make deliberate decisions about where each workload lives instead of defaulting to wherever it already is. **Azure Backup rounds out the story.** When you enroll your Hyper-V hosts into Arc and use Microsoft Azure Backup Server (MABS) or newer Azure Backup approaches depending on environment design, you can vault backups offsite directly to an Azure Recovery Services vault. Short-term retention stays local for fast operational recovery; long-term retention lives in Azure without needing a separate backup cloud provider. For clients already invested in Azure, it's a clean fit. None of this is available to you if you leave VMware for a platform with no Azure integration. An alternative hypervisor might be a solid piece of software. It is not connected to Azure, and for an organization where the rest of the stack is Microsoft-shaped, that gap is real. If you're evaluating this, you're in one of three buckets: 1. Stay on VMware and absorb the cost 2. Migrate to another hypervisor (Hyper-V, Proxmox, others) 3. Exit on-prem entirely and move to Azure This post is about option 2, and why for Microsoft-centric SMBs, Hyper-V combined with Azure Arc is usually the cleanest path. ## What the migration actually looks like I'll be direct: this isn't a weekend project, and anyone who says otherwise hasn't done enough of them. Do not try to move everything in one sprint. That's how outages happen. **Start with inventory.** Every VM needs to be documented before anything moves: OS, RAM, vCPU, disk size, network config, application dependencies. Migrations go wrong when people skip this step and find out midway through that one of their VMs has an application that doesn't tolerate the new virtual hardware profile. **Assess the hardware.** Most servers running ESXi will run Hyper-V without issues. Confirm CPU virtualization is enabled in BIOS and review your storage configuration. If you're running vSAN, you'll need a plan for shared storage. Windows Storage Spaces Direct is Microsoft's native option for hyperconverged storage, but it requires careful design and isn't always the right fit for smaller environments. **Convert the VMs.** Microsoft's MVMC has been deprecated, which still catches people off guard. The current workflow depends on your situation. One important caveat first: if your VMs are running on vSAN, this step gets harder. vSAN's tight coupling between storage and compute means most standard conversion tools don't work against it directly. You'll typically need to storage vMotion the VMs off vSAN onto a traditional VMFS datastore first, then convert from there. Skipping this step is one of the most common reasons VMware-to-Hyper-V migrations stall. Plan for it before you start. - **StarWind V2V Converter** for VMDK-to-VHDX conversion, free, reliable, and the tool I reach for first - **Disk2vhd** for any physical-to-virtual scenarios that still exist in the environment - Manual export/import for anything application-sensitive that needs careful handling General sequence: clean shutdown of the source VM, convert the disk, create a Generation 2 VM in Hyper-V, attach the converted disk, ensure Integration Services are current, validate network and storage, test the application. In that order, every time. **On Integration Services.** For modern guest operating systems (Windows Server 2016 and later), Integration Services are built in and kept current via Windows Update. For legacy guests, you'll need to handle it manually. Either way, don't assume it's done. Verify it. VMs without current Integration Services will have degraded performance and inconsistent backup behavior, and it's the most common thing I find left undone on migrations that someone else touched. **Plan your networking.** VMware's port group and vSwitch model maps conceptually to Hyper-V's virtual switch model, but they don't translate directly. Plan your external, internal, and private switch topology before the first VM moves. ## BCDR: get this right before cutover, not after The first question to answer isn't which backup tool, it's where your environment is going. That determines everything else. If you're moving to Hyper-V and staying on-prem, Slide is our default BCDR recommendation. It's purpose-built for MSPs, runs on all-NVMe hardware, encrypts everything by default, and was founded by the team that built Datto. It protects physical and virtual workloads via its appliance regardless of the underlying hypervisor, so the migration to Hyper-V doesn't change your protection story. If you're building a true hybrid environment with Azure Arc in the picture, the calculus shifts. You want a solution that lives in the same management plane as the rest of your infrastructure. Azure Backup via MABS vaults directly to an Azure Recovery Services vault and sits inside the same operational home base as everything else Arc-connected, and for clients already invested in Azure, it removes a vendor from the stack entirely. Zerto is the right answer when you need continuous data protection and near-zero RPO; it's more operationally complex, but for environments where a few hours of data loss is genuinely unacceptable, certain financial services clients, for example, it delivers. It can also replicate VMware VMs to Hyper-V while both environments are live, which compresses the cutover window considerably on larger migrations. Veeam handles Hyper-V natively and integrates cleanly with Azure Local and Arc environments if you're already running it. The important thing regardless of which tool you land on: reconfigure your backup jobs as part of the migration plan, not after. Backup agents registered to VMware-aware jobs will break at cutover. ## What tends to go wrong A few things I see consistently. **Legacy VMware drivers.** Windows Server 2012 VMs converted from VMware sometimes have VMware-specific drivers baked in that cause problems on Hyper-V. Remove VMware Tools before conversion, or immediately after first boot on the new host. **Generation 1 vs. Generation 2.** Generation 2 is the right choice for modern workloads: UEFI, secure boot, better performance. VMs with older Windows Server versions or certain Linux kernels may need to stay on Gen 1. Know which is which before you build the target VMs. **Windows activation.** VMs activated under a VMware-based deployment may need reactivation against the new virtual hardware profile. Volume licensing via KMS handles this automatically most of the time. Retail or OEM activations sometimes need manual attention. **Backup agent confusion.** Already mentioned this, but worth repeating because it causes more post-migration headaches than anything else on this list. ## Realistic timeline For a small environment, 10 to 20 VMs on a 2-node ESXi cluster, expect 4 to 8 weeks from scoping to production cutover. That includes hardware prep, test conversions, a validation window, and the actual go-live. The temptation is always to compress this. Resist it. Larger environments, or anything with SQL Always On clusters, Exchange remnants, or tightly coupled application dependencies, will take longer. Not because the tools are hard, but because the testing needs to be thorough and you can't rush that part. ## Is it worth it? For most of the clients I'm quoting right now, yes. The migration cost is typically recovered within the first or second year of avoided VMware subscription fees. After that, you're running a hypervisor that's already inside your Windows Server licensing with no separate renewal clock. With Azure Arc, you're positioned to make deliberate decisions about your hybrid footprint going forward rather than just surviving the next Broadcom price increase. The one situation where I tell people to reconsider: if you have fewer than five VMs and the workloads could realistically move to Azure IaaS or M365-native services, virtualization infrastructure might not be the right answer at that scale anyway. For everyone else with a real on-prem VM estate and a VMware renewal coming up: if your renewal is within six months, you should already be modeling your exit. Get the quote. Run the numbers. The exit is well-understood at this point and we've done it enough times to do it cleanly. ## Want help planning one of these? If you're looking at a VMware renewal and want a second opinion before you sign anything, or you're ready to start scoping a migration, that's exactly the kind of project we handle. Take a look at [Athencia's Professional Services](https://athencia.com/professional-services), or if you just want to have a conversation first, a [free IT Health Check](https://athencia.com/free-it-health-check) is a good place to start. *Athencia is a Pacific Northwest-rooted boutique IT services firm serving small and mid-sized businesses nationwide.* --- ## Knowledge Base ### Cloud & Backups #### How to Create a Simple Disaster Recovery Plan for Your Small Business > Step-by-step guide to creating a practical disaster recovery plan that helps your small business resume operations after an IT outage, cyberattack, or physical disaster. URL: https://athencia.com/kb/cloud-and-backups/how-to-create-a-simple-disaster-recovery-plan-for-your-small-business A disaster recovery plan documents exactly what to do when something takes your IT systems down, whether that is a ransomware attack, a server failure, a natural disaster, or even an ISP outage. Without a written plan, people panic, forget steps, and waste critical time. With one, you respond with a clear process and get back to business faster. The good news is that a useful disaster recovery plan does not need to be 50 pages of corporate boilerplate. A practical, three-to-five page document that your team has actually read and tested is far more valuable than a binder collecting dust on a shelf. Set aside two to four hours, follow the steps below, and you will have a working plan by the end. ## What you will need before you start Gather these items before sitting down to write the plan. Having them in front of you will save time and make the document far more accurate. - **An inventory of your critical systems and data.** This includes email, phone systems, file storage, line-of-business applications, accounting software, and any client-facing systems. - **Documentation of your current backup setup.** Know where backups are stored, how often they run, and who manages them. If Athencia manages your IT, your backup stack already includes Dropsuite for Microsoft 365 data and Slide for on-premises backups, and both are monitored through the [Athencia One portal](/athencia-one). - **Contact information for your IT provider, ISP, and key vendors.** Collect names, phone numbers, email addresses, and account numbers in advance. - **A block of focused time.** Two to four hours is enough for the initial draft. The plan does not need to be perfect on the first pass; you will revise it after testing. ## Why you need a written plan During a crisis, even smart, experienced people forget steps and make mistakes under pressure. A written disaster recovery plan removes guesswork and assigns clear responsibilities so everyone knows what to do. Beyond the operational benefits, cyber insurance policies increasingly require a documented incident response or disaster recovery plan. If you file a claim without one, the insurer may deny coverage or reduce the payout. Having a written, tested plan strengthens your position. ## Step 1: Identify your critical systems Start by listing every system your business depends on to operate. Walk through a typical workday and note each tool, service, and data source your team touches. Common examples include: - Email and calendar (Microsoft 365, for most Athencia clients) - Phone and voicemail system - File storage (OneDrive for Business, SharePoint Online, or an on-premises file server) - Line-of-business applications (CRM, ERP, project management) - Accounting and payroll software - Client-facing systems (website, client portal, e-commerce platform) Once you have the list, rank each system by criticality. Ask yourself: if we could only restore one system first, which would it be? Then the second, and so on. This ranking drives the order of recovery when a real disaster hits. For each system, document three things: where it is hosted (cloud, on-premises, or SaaS), who manages it (your team, your MSP, or a third-party vendor), and how it is currently backed up. If a system has no backup, flag it immediately. That gap needs to be addressed before the plan is complete. ## Step 2: Define your recovery objectives Two numbers drive your entire disaster recovery strategy: your Recovery Time Objective (RTO) and your Recovery Point Objective (RPO). **RTO (Recovery Time Objective)** is how long each system can be down before the business impact becomes unacceptable. For example, you might decide that email can be down for four hours, but your accounting system can tolerate up to 24 hours. These numbers are business decisions, not technical ones. Think about revenue loss, employee productivity, and client impact. **RPO (Recovery Point Objective)** is how much data you can afford to lose. If your backups run once per day, you could lose up to 24 hours of work in a worst-case scenario. If that is unacceptable for certain systems, you need more frequent backups for those systems. These objectives reveal gaps. If your RTO for email is one hour but your current backup would take eight hours to restore, you have a gap that needs a solution. If you use Dropsuite for Microsoft 365 backup, point-in-time recovery of individual mailboxes, files, and SharePoint sites is typically fast enough to meet a four-hour RTO for most small businesses. For on-premises data backed up with Slide, recovery time depends on the volume of data and whether you are restoring to original hardware or replacement equipment. ## Step 3: Document recovery procedures for each scenario Write out step-by-step instructions for each type of disaster. Be specific enough that someone under stress can follow the steps without guessing. Here are the four most common scenarios for small businesses. ### Scenario 1: Ransomware or cyberattack 1. Isolate affected systems immediately. Disconnect infected computers from the network by unplugging the Ethernet cable and turning off Wi-Fi. The goal is to stop the infection from spreading. 2. Contact your MSP or IT provider right away. If Athencia manages your IT, call the emergency support line listed in your contact sheet. Do not attempt to fix ransomware yourself. 3. Do not pay the ransom. Paying does not guarantee you will get your data back, and it funds further attacks. 4. Assess the scope of the attack. Work with your IT provider to determine which systems and data are affected. 5. Restore from clean backups once the infection is fully contained. For Microsoft 365 data, Dropsuite stores backups independently from your Microsoft tenant, so a compromised tenant does not compromise your backup data. For on-premises data, Slide provides the local backup copy for faster restoration. 6. Report the incident to the FBI's Internet Crime Complaint Center (IC3), your cyber insurance carrier, and any regulatory bodies required by your industry. 7. Communicate with employees and clients as appropriate. Be transparent about what happened and what you are doing about it. ### Scenario 2: Hardware failure (server, computer, network equipment) 1. Identify the failed component. Is it a workstation, a server, a switch, or a firewall? 2. Activate spare equipment if available. A spare laptop, a backup router, or a standby switch can keep operations running while the failed device is replaced. 3. Contact your MSP or hardware vendor for replacement. Provide the model, serial number, and warranty information. 4. Restore data from backup to the replacement device. For workstations, Microsoft Intune (included with Microsoft 365 Business Premium) can push company policies, applications, and settings to a new device quickly, reducing setup time from hours to minutes. 5. Document the failure for insurance and warranty purposes. ### Scenario 3: Internet or ISP outage 1. Switch to a backup internet connection if available. This could be a secondary ISP, a cellular failover device, or a dedicated LTE/5G backup line. 2. If no backup connection is available, set up a mobile hotspot from a phone for critical tasks like email and essential cloud applications. 3. If the outage will be extended, send employees home to work remotely using their home internet connections. Because Microsoft 365 data lives in the cloud, employees can access email, files, and Teams from any internet connection. 4. Contact the ISP for an estimated restoration time and document the outage duration for your records. ### Scenario 4: Physical disaster (fire, flood, extended power outage) 1. Ensure employee safety first. People come before data, always. 2. Assess physical damage to equipment once it is safe to do so. 3. Activate remote work capabilities. If your team uses Microsoft 365 Business Premium, email, OneDrive, SharePoint, and Teams are all accessible from any device with an internet connection. Employees can work from home while the office is unusable. 4. Contact your insurance carrier to begin the claims process. 5. Begin the equipment replacement process with your IT provider. 6. Restore on-premises data from offsite or cloud backups. This is where the offsite copy in a 3-2-1 backup strategy proves its value. If your local Slide appliance was destroyed in the disaster, the cloud copy of your Microsoft 365 data in Dropsuite remains completely unaffected. ## Step 4: Document key contacts Create a contact sheet and include it in the plan. Print a copy and keep it somewhere accessible even if your computers and network are down. Include: - **IT provider/MSP:** Name, phone, email, emergency support line - **ISP:** Account number, support phone number - **Key software vendors:** Support contacts for each critical application - **Cyber insurance carrier:** Policy number, claims phone number, agent contact - **Company leadership:** Names and cell phone numbers for decision-makers - **Employee notification list:** Personal email addresses and cell phone numbers for all employees (you cannot use company email to notify people if company email is down) ## Step 5: Assign roles Even in a five-person company, define who does what during a disaster. When everyone assumes someone else is handling it, nothing gets handled. - **Incident commander:** The person who makes decisions during the disaster. This is usually the business owner or operations manager. They decide priorities, approve spending, and communicate with leadership. - **IT lead:** Your MSP or internal IT contact who handles the technical recovery work. They coordinate with vendors, execute restore procedures, and report progress to the incident commander. - **Communications lead:** The person who communicates with employees, clients, and vendors during the incident. They send status updates, manage expectations, and handle any public-facing communication. In a small business, one person may fill multiple roles. That is fine. The important thing is that the roles are defined in writing and everyone knows their responsibilities before a disaster happens. ## Step 6: Test the plan A plan you have never tested is just a document. You do not know if it works until you walk through it. **Run a tabletop exercise once per year.** Gather your team around a table and walk through a scenario verbally. For example: "It is Monday morning and we discover our email has been encrypted by ransomware. Walk me through what we do." Go step by step. You will find gaps, outdated contacts, and unclear procedures every time. **Test a backup restore once per quarter.** Pick a random file, email, or folder and actually restore it from backup. Verify the restored data is complete and usable. If your backups are managed through Athencia, you can verify backup health anytime through the Athencia One portal, but a hands-on restore test is still essential. **Update the plan after every test** with the lessons you learned. Also update it whenever systems, vendors, or personnel change. A disaster recovery plan is a living document, not a one-time project. ## Need help? Building a disaster recovery plan is easier with an experienced IT partner. If you want help creating or testing your plan, [reach out to Athencia](/contact) and we will walk through it with you. #### How to Migrate Your Office File Server to the Cloud > Practical guide for small businesses moving files from a local server to SharePoint and OneDrive, covering planning, migration, and user training. URL: https://athencia.com/kb/cloud-and-backups/how-to-migrate-your-office-file-server-to-the-cloud Migrating from a local file server to cloud storage eliminates the maintenance, backup burden, and single point of failure that comes with keeping an on-premises server running. Your team gets access to files from anywhere, automatic version history on every document, and real-time collaboration features that a traditional file server simply cannot provide. The migration itself is straightforward when planned well, but rushing it without cleanup and user training creates confusion and resistance. This guide walks you through the entire process, from auditing what you have today to shutting down the old server for good. ## What you will need - **Microsoft 365 Business Premium licenses for all users.** This is the license tier Athencia deploys, and it includes OneDrive for Business (1 TB per user), SharePoint Online, and Microsoft Intune for device management. If you are on a different license tier, confirm that OneDrive and SharePoint are included before starting. - **Admin access to the current file server and to Microsoft 365.** You will need to read file server permissions and create SharePoint sites in the Microsoft 365 admin center. - **An inventory of what is on the file server and who uses what.** This does not need to be a formal audit. A walk-through with department leads to identify active folders and stale data is enough. - **Time for data cleanup before the migration.** This step is the most important part of the entire project. ## Why move to the cloud A local file server is a piece of hardware that needs power, cooling, maintenance, and replacement every five to seven years. It is a single point of failure. If the hard drives crash and your backups are not current, you lose data. If the office floods, the server goes with it. Moving your files to SharePoint Online and OneDrive for Business eliminates those risks. Your data lives in Microsoft's data centers with built-in redundancy, and your team can access files from the office, from home, or from a mobile device without needing a VPN. Every file gets automatic version history, so the days of "Final_v3_REAL.docx" are over. And because SharePoint integrates directly with Microsoft Teams, your team can collaborate on documents in real time. ## Step 1: Audit and clean up your file server This is the most important step in the entire migration. Migrating junk to the cloud just creates cloud junk that is harder to find and costs time to manage. Start by identifying what is actually being used versus what has not been touched in years. Check last-modified dates on folders and files. Most file servers contain 30 to 50 percent data that does not need to be migrated at all. Work through the file server folder by folder with the people who use it. Delete duplicates, outdated drafts, and files that are no longer relevant. For old project files and historical data that you need to keep but nobody accesses regularly, create a separate archive location. You can set up a dedicated "Archive" library in SharePoint for this purpose, or simply keep a final backup of the file server after migration. This cleanup typically takes longer than the actual migration, but every hour you spend here saves confusion and frustration later. ## Step 2: Plan your cloud structure Do not replicate the file server's folder structure exactly. This migration is your chance to fix years of organic, messy folder growth. The general rule is straightforward. Shared files that multiple people need to access go in SharePoint document libraries. Personal files that belong to one person go in that person's OneDrive. Map your file server shares to SharePoint sites. Each department or major business function should get its own SharePoint site. For example: - The "S:\Clients" share becomes a SharePoint site called "Client Projects" under Operations - The "S:\Finance" share becomes a SharePoint site called "Finance" - The "S:\Marketing" share becomes a SharePoint site called "Marketing" - Individual "My Documents" folders become each user's OneDrive Keep the folder hierarchy shallow. Two to three levels deep is ideal. Deeply nested folders become difficult to navigate and impossible to sync reliably. Where you previously used deep folder structures to categorize files, consider using metadata columns in SharePoint instead. Document this mapping in a simple spreadsheet: old location on the left, new location on the right. You will use this document for the migration itself and as a reference guide for your team. ## Step 3: Set up SharePoint sites and libraries Log in to the Microsoft 365 admin center at admin.microsoft.com and navigate to **Active sites** under **Sites** in the SharePoint admin center. Create each SharePoint site based on the mapping you built in Step 2. For each site, configure permissions to match the access controls from the file server. Click on the site, then go to **Site permissions** to add the appropriate users or Microsoft 365 groups. Use Microsoft 365 groups rather than adding individual users whenever possible. This makes ongoing permission management much simpler. Create the folder structure within each document library. Keep it shallow and logical. Then test with a small batch of files before you start the full migration. Upload a handful of files, verify permissions work correctly, and confirm the structure makes sense in practice. ## Step 4: Migrate the data The migration method depends on how much data you are moving. **For smaller migrations (under 100 GB),** use the OneDrive sync client. Sync the target SharePoint libraries to File Explorer, then drag and drop files from the file server into the synced folders. This is the simplest approach and works well for small offices. **For medium migrations (100 GB to 1 TB),** use the SharePoint Migration Tool, which is free from Microsoft. Download it from Microsoft's website, point it at your file server, map the source folders to destination SharePoint libraries, and let it run. It handles large file counts more reliably than drag-and-drop and preserves file metadata. **For large or complex migrations,** use a third-party tool like ShareGate or AvePoint, or engage your IT provider to manage the migration. These tools handle permission mapping, scheduling, and reporting more gracefully at scale. Regardless of the method, run the migration outside business hours if possible. Uploading hundreds of gigabytes will saturate your internet connection and slow everything else down. Migration speed depends on your upload bandwidth and file count. Thousands of small files take significantly longer than the same total volume in fewer large files. After migration, verify the results. Compare file counts between the source and destination. Spot-check files by opening them and confirming the content is intact, not just that the file name exists. ## Step 5: Set up OneDrive sync for users Once data is in SharePoint, each user needs to sync the libraries they work with to their local File Explorer. This gives them the familiar folder experience they are used to from the file server. Have each user navigate to the relevant SharePoint library in their web browser, click the **Sync** button in the toolbar, and approve the prompt to open the OneDrive sync client. The library will appear in File Explorer under the company name. Enable **Files On-Demand** so that files do not fill up local storage. With Files On-Demand turned on, files show in File Explorer but only download to the device when someone opens them. This is especially important for laptops with smaller drives. If your devices are managed through Microsoft Intune (included with Microsoft 365 Business Premium), your IT provider can push the Files On-Demand setting to all company devices automatically rather than configuring it one computer at a time. ## Step 6: Train your team Training is where most migrations succeed or fail. If your team does not understand the new system, they will resist it, work around it, or create a mess of duplicate files. Schedule a 30-minute session with your team and cover the following: - **Where files live now.** Show them the File Explorer path and the SharePoint web interface. Walk through the mapping from old locations to new locations. - **How to share files.** Demonstrate sharing a file or folder with a colleague using the **Share** button. Show the difference between "Can Edit" and "Can View" permissions. For external sharing, show how to create a link with an expiration date. - **How to use version history.** Right-click a file in File Explorer, select **Version history**, and show how to view and restore previous versions. This feature alone eliminates a huge category of "I accidentally saved over my file" support requests. - **The cutoff date.** Set a clear date and communicate it: "After [date], the old file server is read-only. All new work goes to SharePoint and OneDrive." This prevents the migration from dragging on indefinitely. Provide a one-page quick reference guide with the old file locations mapped to the new ones. Post it in common areas and share it digitally. ## Step 7: Decommission the file server Keep the old file server running in read-only mode for 30 to 60 days after the migration. This provides a safety net in case files were missed or something was not migrated correctly. During this transition period, monitor for users who are still saving to the old server. If people are bypassing the new system, find out why and address it. It is usually a training gap or a permission issue. After the transition period, take a final backup of the file server and shut it down. Store that final backup for six to twelve months in case anything surfaces later. Then cancel any maintenance contracts on the old server hardware. If you had an on-premises backup solution like Slide protecting the file server, work with your IT provider to redirect that protection to any remaining on-premises systems or to decommission it if everything has moved to the cloud. ## Common mistakes to avoid - **Migrating without cleaning up first.** Moving ten years of accumulated junk to the cloud just makes it harder to find what you need. - **Replicating the exact folder structure.** Use this as an opportunity to simplify and reorganize. - **Skipping user training.** If your team does not know how to use the new system, they will not use it, or they will use it badly. - **No cutoff date.** Without a firm deadline, some employees will keep saving to the old server indefinitely. - **Forgetting to migrate permissions.** Users who suddenly cannot access files they need will lose trust in the new system. - **Not testing with a small batch first.** Always migrate one department or one folder set first and verify before doing the full migration. ## Need help? Migrating a file server to the cloud is a project where a little planning goes a long way. If you would like guidance or hands-on support for your migration, [contact Athencia](/contact) and we will help you plan and execute it. #### How to Set Up OneDrive for Business So Your Team Actually Uses It > Practical guide to rolling out OneDrive for Business in a small office, including folder structure, training tips, and common mistakes to avoid. URL: https://athencia.com/kb/cloud-and-backups/how-to-set-up-onedrive-for-business-so-your-team-actually-uses-it OneDrive for Business gives every Microsoft 365 user 1 TB of cloud storage that syncs files between their computer and the cloud. When set up correctly, it works quietly in the background. Your team saves files to familiar folders in File Explorer, and those files are automatically backed up and accessible from any device. When set up poorly, you end up with duplicate files, confused folder structures, and employees who refuse to use it because "it is too complicated." This guide walks you through how to set up OneDrive for Business the right way so your team actually adopts it. ## OneDrive vs. SharePoint: Which to use when Before you start, understand the difference between OneDrive and SharePoint. They work together, but they serve different purposes. **OneDrive** is for personal work files that belong to one person. Think of it as that person's "My Documents" folder in the cloud. Their drafts, notes, individual work, and personal reference files all belong here. **SharePoint** is for shared team files that multiple people need to access. Project folders, shared templates, company policies, and departmental resources all belong in SharePoint document libraries. The most common mistake is putting shared files in one person's OneDrive and sharing them out. This creates a serious problem: if that person leaves the company, access to those files breaks. Their OneDrive is deleted 30 days after their Microsoft 365 account is removed unless someone intervenes. As a rule of thumb, if more than one person needs regular access to a folder, it belongs in SharePoint, not OneDrive. ## Step 1: Verify OneDrive is provisioned for each user OneDrive for Business is included with Microsoft 365 Business Premium, which is the license tier Athencia deploys. It is also included with Business Basic and Business Standard licenses. To verify that OneDrive is active for a user, have them sign in to [onedrive.com](https://onedrive.com) with their work email address and password. If the OneDrive interface loads and they can see their files area, it is provisioned and ready. If OneDrive is not available, check the user's license assignment. Sign in to the Microsoft 365 admin center at admin.microsoft.com, navigate to **Users** then **Active users**, click on the user's name, and check their **Licenses and apps** section. Make sure a license that includes OneDrive is assigned and that the OneDrive toggle is turned on. For brand-new users, OneDrive may take up to 24 hours to provision after the license is assigned. If it has been longer than that, try navigating to the user's OneDrive URL directly from the admin center to trigger provisioning. ## Step 2: Set up the OneDrive sync client The OneDrive sync client is built into Windows 10 and Windows 11, so there is no separate installation needed. It runs in the background and keeps files synchronized between the computer and the cloud. To set it up on an employee's computer: 1. Look for the **OneDrive cloud icon** in the system tray (the area near the clock in the bottom-right corner of the screen). It may be a white cloud or a gray cloud. 2. Click the icon and select **Sign in**. If prompted, choose **Work or school account**. 3. Enter the employee's work email address and password. Complete any multi-factor authentication prompts. 4. OneDrive will ask which folders to sync. For most users, the default selection is fine to start with. 5. Once setup is complete, a new folder appears in File Explorer under the company name. This is where synced files live. For employees with laptops or devices that have limited local storage (128 GB or 256 GB drives), enable **Files On-Demand**. Click the OneDrive cloud icon in the system tray, click the **gear icon**, select **Settings**, go to the **Sync and backup** tab, and make sure **Files On-Demand** is turned on. With this setting enabled, files appear in File Explorer but only download to the device when someone opens them, saving significant disk space. If your company devices are managed through Microsoft Intune (included with Microsoft 365 Business Premium), your IT provider can push OneDrive sync settings, including Files On-Demand and silent sign-in, to all company devices at once. This eliminates the need to configure each computer individually. ## Step 3: Establish a folder structure A clear folder structure, communicated before rollout, prevents the chaos that develops when everyone creates their own system. Keep the top-level folders simple and consistent across users. A good starting point: - **Clients** or **Projects** for client-specific or project-specific work - **Templates** for frequently used document templates - **Reference** for personal reference materials - **Archive** for completed work that needs to be kept but is no longer active Avoid replicating a legacy file server's ten-level-deep folder hierarchy. Deep nesting makes files hard to find and causes sync issues. Two to three levels deep is the practical limit. Create a short document outlining the company standard for folder names and file names. Share this with your team before the rollout, not after. Clear expectations set upfront prevent months of cleanup later. No more "Final_v2_REAL_FINAL.docx" because version history handles that automatically. ## Step 4: Migrate existing files If your team is moving from a local file server, another cloud service, or files scattered across individual computers, plan the migration before dumping everything into OneDrive. **For small migrations (under 100 GB total):** Drag and drop files from the old location into the synced OneDrive or SharePoint folder in File Explorer. This is simple and works well for small teams. **For larger migrations:** Use the SharePoint Migration Tool (free from Microsoft) or a third-party migration tool for more reliable, faster transfers. These tools preserve file metadata and handle large file counts better than manual drag-and-drop. After migrating, spot-check files by opening them and verifying they are complete, not just by checking file names and counts. A file that transferred with zero bytes or became corrupted during the move will not show up in a file count check. Set a cutoff date and communicate it clearly: "After [date], the old file server is read-only. All new work goes in OneDrive and SharePoint." Without a firm deadline, the migration drags on indefinitely. ## Step 5: Train your team Rollout training does not need to be a formal class. A 20-to-30 minute walkthrough covering the essentials is enough for most teams. **Show employees how to find files in File Explorer.** Open File Explorer, navigate to the OneDrive folder under the company name, and show them that working with files here is identical to working with any other folder. They can save, open, rename, and move files exactly as they always have. **Demonstrate how to share files.** Right-click a file, select **Share**, and show how to send a sharing link to a colleague or external contact. Walk through the permission options: **Can edit** gives the recipient full editing access, while **Can view** gives read-only access. For external sharing, show how to set an expiration date on the link so it does not remain active indefinitely. **Explain version history.** Right-click a file, select **Version history**, and show how OneDrive keeps previous versions of every file. If someone accidentally overwrites a document or needs to see what a file looked like last week, they can restore a previous version with two clicks. This single feature eliminates one of the most common support requests. **Show how to recover deleted files.** If someone accidentally deletes a file, it goes to the OneDrive recycle bin, which retains deleted files for 93 days. Open OneDrive in the web browser, click **Recycle bin** in the left sidebar, select the file, and click **Restore**. The file goes back to its original location. It is also worth mentioning that OneDrive is not a substitute for a true backup solution. OneDrive syncs changes, including deletions, across all devices. A third-party backup service like Dropsuite, which Athencia includes in its managed IT stack, independently backs up OneDrive, email, and SharePoint data so that files can be recovered even outside of OneDrive's own 93-day recycle bin window. ## Common mistakes to avoid - **Syncing too many files on a device with limited storage.** If a laptop has a 256 GB drive, syncing 500 GB of files will fill it up and cause problems. Use Files On-Demand to solve this. - **Not disabling personal OneDrive on work computers.** Employees can sign into both a personal OneDrive account and a business OneDrive account on the same computer. If both are active, people accidentally save work files to their personal account. Disable the personal OneDrive sign-in on company-managed devices through Intune policies. - **Sharing files with "Anyone with the link" when "People in your organization" is more appropriate.** The "Anyone" option creates a link that works for anyone on the internet, with no authentication required. For internal documents, use the more restrictive option. - **Using one person's OneDrive as the team file server.** If multiple people need regular access to the same files, those files belong in a SharePoint library, not someone's personal OneDrive. - **No folder structure or naming conventions.** Without clear standards communicated at rollout, the file structure devolves into chaos within weeks. ## Need help? Setting up OneDrive the right way from the start saves hours of cleanup later. If you need help with the rollout or want to make sure your setup follows best practices, [get in touch with Athencia](/contact) and we will get your team set up properly. #### How to Verify Your Backups Are Actually Working: A Monthly Checklist > A practical monthly checklist for small businesses to verify that backups are completing, data is recoverable, and nothing is silently failing. URL: https://athencia.com/kb/cloud-and-backups/how-to-verify-your-backups-are-actually-working-a-monthly-checklist Backups fail silently more often than most business owners realize. A backup job that stopped running three weeks ago, a storage drive that quietly filled up, a corrupted backup file that looks fine on the surface but cannot actually be restored. None of these problems announce themselves. You only discover them when you desperately need to recover data and find out you cannot. This monthly checklist takes about 30 to 45 minutes to complete. It catches problems before they become disasters and gives you documented proof that your backups are working, which is increasingly important for cyber insurance audits and compliance reviews. ## Why monthly verification matters Setting up a backup system is only the first step. Without ongoing verification, that system can silently break in dozens of ways. Service account passwords expire. Storage fills up. Software updates change settings. A new employee joins and their data is never added to the backup. A server gets replaced and nobody updates the backup configuration. The worst time to discover your backup does not work is during a data loss event. By then, it is too late. Monthly verification turns backup from "something we set up once and forgot about" into "something we know works because we checked it this month." Cyber insurance providers are also paying closer attention to backup practices. Many now ask for evidence of regular backup testing as part of the policy application or renewal. Having a documented verification log strengthens your position and may even affect your premium. ## The monthly checklist ### Check 1: Verify backup jobs are completing Start by logging in to each backup service or appliance and reviewing the job history for the past 30 days. For **Dropsuite** (Microsoft 365 backup), sign in to the Dropsuite admin dashboard and check the backup status for each protected mailbox, OneDrive account, and SharePoint site. Look for green "Success" indicators across the board. Click into any job that shows a warning or failure to see the specific error. Common causes include a user whose license was changed, a mailbox that was put on litigation hold, or an authentication token that expired. For **Slide** (on-premises backup), check the appliance dashboard or log in to the management console. Review the past 30 days of backup jobs. Confirm every scheduled job completed with a "Success" status. If you see "Completed with warnings," investigate. A warning is not the same as success. It usually means some files were skipped, locked, or inaccessible during the backup. If your backups are monitored through the [Athencia One portal](/athencia-one), backup status is visible in real time. But this monthly check is still valuable because it forces you to look at the details, not just the top-level status indicator. For any backup job that failed, document the failure, the root cause, and the resolution. If a job has been failing for more than 48 hours without being resolved, treat it as urgent. ### Check 2: Verify data volume looks correct Pull up the total size of your most recent backup and compare it to the previous month. A sudden, significant decrease in backup size is a warning sign. It could mean that files, mailboxes, or entire data sources are no longer being backed up. For example, if last month's Microsoft 365 backup covered 25 mailboxes and this month it covers 22, three users may have fallen out of the backup scope due to a license change or account modification. A sudden significant increase can also indicate a problem, such as a backup loop, duplicate data being captured, or a new data source being added without anyone realizing it. For Microsoft 365 backups through Dropsuite, verify that the number of protected mailboxes and OneDrive accounts matches your current active user count. When employees join or leave the company, the backup scope needs to be updated. For on-premises backups through Slide, verify that the total backup size is consistent with the amount of data on the protected servers. If a new file share or application was added to a server, confirm it is included in the backup configuration. ### Check 3: Perform a test restore This is the most important check on the list. A backup that completes successfully but cannot actually be restored is worthless. Pick a random file, folder, or mailbox from the backup and restore it to a temporary location. Do not restore it to the original location; you do not want to overwrite current data with an older version. For a **Dropsuite** test restore: sign in to the Dropsuite dashboard, navigate to the user's mailbox or OneDrive backup, browse to a specific email or file, and click **Restore**. Choose to restore to a temporary folder or download the file directly. Open the restored item and verify it is complete and matches what you expected. For a **Slide** test restore: open the Slide management console, select a backup snapshot from a specific date, browse to a file or folder, and restore it to a test location on the network. Open the restored files and verify they are intact and usable. Rotate what you test each month to cover different parts of your backup over time. One month, test a file from OneDrive. The next month, test an email from Exchange. The following month, test a folder from an on-premises server. Document what you tested, the date, and whether the restore was successful. ### Check 4: Verify the offsite or cloud copy is current If you follow a 3-2-1 backup strategy (and you should), you have copies of your data in at least two separate locations. This check confirms that the offsite or cloud copy is up to date and not lagging behind. For Dropsuite, this is straightforward because the backups are cloud-based by nature. Verify the most recent backup timestamp for each data source and confirm it is within the expected window (usually within the last 24 hours). For Slide, if the appliance replicates to a cloud target or a secondary offsite location, log in and verify that replication is current. If there is a replication lag of more than 24 hours, investigate. Common causes include bandwidth limitations, network configuration changes, or a credential issue with the replication target. The offsite copy is your last line of defense. If ransomware encrypts your local backups or a physical disaster destroys your office, the offsite copy is what you will recover from. It must be current. ### Check 5: Review backup coverage This check catches the gaps that form naturally as your business changes. Ask yourself these questions: - Were any new computers, servers, or cloud services added this month? If so, are they included in the backup? - Did any employees join the company? Are their Microsoft 365 mailboxes and OneDrive accounts protected by Dropsuite? - Did any employees leave? Were their accounts properly handled, and is their data preserved if needed for compliance or reference? - Are there new applications or databases running that are not yet included in any backup? - Is anything still being backed up that no longer exists or no longer needs protection? Removing unnecessary backup targets frees up storage and simplifies management. ### Check 6: Verify retention policy Check how far back your backups go and confirm the retention period meets your business requirements. For most small businesses, a minimum retention of 30 days is necessary. Ninety days is recommended because many data loss scenarios, such as a departing employee who quietly deleted files, are not discovered immediately. Verify that old backups are being properly rotated and deleted when they pass the retention window. If old backups are not being cleaned up, storage will eventually fill up and cause new backups to fail. If your industry has specific compliance requirements (healthcare, legal, financial services), confirm that your retention settings meet those requirements. Your IT provider or compliance advisor can help determine the right retention period. ## Recording your results Keep a simple log of each monthly verification. A shared spreadsheet or document works fine. For each check, record: - The date the check was performed - What was checked (backup jobs, data volume, test restore, offsite copy, coverage, retention) - Pass or fail - Any issues found and the actions taken to resolve them - Who performed the check This log serves two purposes. First, it creates accountability and ensures the checks actually happen every month. Second, it provides documentation for cyber insurance audits and compliance reviews. When an auditor asks "How do you verify your backups?" you can hand them a log showing monthly verification going back months or years. Assign the checklist to a specific person and set a recurring calendar reminder. If it is "everyone's job," it is nobody's job. ## Red flags that need immediate attention Do not wait until next month's check if you encounter any of these issues: - **Any backup job that has failed for more than 48 hours** without being investigated and resolved. - **Backup storage over 80 percent capacity.** At this level, you are one or two backup cycles away from running out of space and having backups stop entirely. - **No successful test restore in the past 90 days.** If you have not verified that data can actually be restored in three months, you do not know if your backups are usable. - **New data sources not included in the backup.** A new server, a new application, or new employees whose data is not being backed up represent unprotected risk. - **Credentials or licenses expiring soon on the backup service.** An expired license or credential will stop backups silently. ## Need help? If you would rather have your backup verification handled by professionals, or if this checklist revealed issues you are not sure how to fix, [contact Athencia](/contact). We monitor backups continuously and can help you close any gaps. #### What Is a 3-2-1 Backup Strategy and Why Your Small Business Needs One > Plain-language explanation of the 3-2-1 backup rule and how small businesses can implement it affordably to protect against data loss. URL: https://athencia.com/kb/cloud-and-backups/what-is-a-3-2-1-backup-strategy-and-why-your-small-business-needs-one The 3-2-1 backup strategy is a simple rule that protects your business from data loss: keep three copies of your data, on two different types of storage, with one copy stored offsite. If you follow this rule, no single event, whether a hardware crash, a ransomware attack, a fire, or a theft, can destroy all your business data. This approach has been the standard in IT for decades because it works. It accounts for the reality that any single backup can fail, any single location can be compromised, and any single type of storage can have a systemic problem. The 3-2-1 rule builds in enough redundancy that you can survive any one of those failures. ## The 3-2-1 rule explained **3 copies of your data.** You keep the original production data plus two separate backups. If one backup turns out to be corrupted or incomplete, you still have another to fall back on. A single backup is a single point of failure, and single points of failure are exactly what a backup strategy is supposed to eliminate. **2 different types of storage media.** Do not keep all copies on the same kind of storage. If your production data is on a hard drive and your only backup is on another hard drive in the same location, a power surge, flood, or fire could take out both at the same time. By using two different types of storage, such as a local backup appliance and a cloud backup service, you protect against a failure mode that affects one storage type but not the other. **1 copy offsite.** At least one of your backups must be physically separate from your office. A backup on an external hard drive sitting on the desk next to the computer it backs up will not survive the same fire, flood, or theft. An offsite copy, whether in the cloud or at a different physical location, ensures that a disaster at your office does not take your backups with it. ## Why this matters for small businesses The statistics are sobering. A significant percentage of small businesses that lose their data permanently close their doors within months. The common causes of data loss, such as hardware failure, ransomware, accidental deletion, theft, fire, and water damage, are not exotic edge cases. They happen to real businesses every day. There is also a widespread misconception that cloud services like Microsoft 365 fully back up your data. They do not. Microsoft operates under a shared responsibility model: Microsoft is responsible for keeping the service running, but you are responsible for protecting your data from accidental deletion, malicious insiders, and retention gaps. Microsoft retains deleted items for a limited time (30 to 93 days depending on the service), not indefinitely. If you need to recover a file that was deleted four months ago and you do not have a separate backup, it is gone. ## Copy 1: Your live data (the original) This is the data your team works with every day. It lives on your employees' computers, your file servers, and your cloud services like Microsoft 365 Business Premium (which includes OneDrive for Business, SharePoint Online, and Exchange Online). This is not a backup. It is the primary copy that everything else is designed to protect. If this copy is compromised by ransomware, corrupted by a hardware failure, or deleted by accident or malice, you need to be able to recover from the other two copies. ## Copy 2: A local or near-line backup The second copy provides fast recovery for everyday issues like accidental file deletion, hardware failure, or a corrupted database. Because it is local (on your network or physically in your office), restoring data from it is fast. For on-premises data such as local servers, workstations, and network drives, Athencia deploys Slide as an on-premises backup appliance. Slide runs automated backups on a schedule, typically daily or more frequently for critical systems, and stores them locally for quick recovery. If an employee accidentally deletes an important folder or a server drive fails, restoration from Slide is fast because the data does not need to travel over the internet. For Microsoft 365 data, you need a third-party backup service because Microsoft's native retention policies are not a backup. A third-party backup service like Dropsuite, which Athencia includes in its managed IT stack, automatically backs up Microsoft 365 email, OneDrive, and SharePoint data independently from Microsoft's retention policies. This means you can recover data even after Microsoft's own retention windows have expired, whether that is an email from six months ago or a file that was deleted and purged from the recycle bin. ## Copy 3: An offsite or cloud backup The third copy protects against events that affect your entire office: fire, flood, theft, or ransomware that encrypts every device on your network including local backup drives. This copy must be physically separate from your office. Cloud backup services are the most practical option for most small businesses because they require no hardware at a second location and update automatically. For the cloud backup of Microsoft 365 data, Dropsuite stores backups in its own cloud infrastructure, completely separate from your Microsoft tenant. For on-premises data, Slide can replicate backups to an offsite cloud target, giving you a second copy of your local data in a different location. Together with the production data in Microsoft 365 itself, this satisfies all three requirements of the 3-2-1 strategy. This offsite copy should be immutable or air-gapped whenever possible. An immutable backup cannot be modified or deleted by ransomware, even if an attacker gains administrative access to your network. This is your last line of defense, and it needs to be bulletproof. ## Implementing 3-2-1 on a small business budget You do not need an enterprise budget to implement a proper 3-2-1 backup strategy. Here is what a practical setup looks like for a typical five-to-fifteen person office. **Start with Microsoft 365 backup.** If your business runs on Microsoft 365 (email, OneDrive, SharePoint), protecting that data should be your first priority. A service like Dropsuite typically costs a few dollars per user per month and covers email, OneDrive, and SharePoint backup with point-in-time recovery. This is the highest-impact, lowest-effort step you can take. **Add on-premises backup if you have local servers or data.** If your business still has data on local servers, workstations, or network drives, a backup appliance like Slide protects that data with automated local backups and optional offsite replication. The cost depends on the amount of data and the retention period, but it is affordable for most small businesses. **If you cannot do everything at once, prioritize.** Start with Microsoft 365 backup (Dropsuite) because that is where most of your critical business data lives. Add on-premises backup next. Then verify that the offsite/cloud replication is working for both. You can build toward a complete 3-2-1 strategy incrementally rather than trying to do it all at once. ## The part most businesses skip: Testing your backups A backup you have never restored is not a backup. It is a hope. Until you have actually recovered data from a backup and verified that it is complete and usable, you do not truly know if your backup works. **Test a restore at least once per quarter.** Pick a random file, email, or folder from your backup and restore it to a temporary location. Open it and verify it is intact. Rotate what you test each quarter so you cover different data sources over time. **Check backup reports weekly.** Log in to your backup dashboards (Dropsuite, Slide, or both) and verify that jobs are completing successfully. Look for failures, warnings, or missed schedules. If your backups are managed through Athencia, backup health is visible through the [Athencia One portal](/athencia-one), but a quick manual check still builds confidence. **Know your RTO and RPO.** Your Recovery Time Objective (RTO) is how long it would take to restore operations from backup. Your Recovery Point Objective (RPO) is how much data you can afford to lose. If you back up daily, your worst-case RPO is 24 hours of work. If that is unacceptable for certain systems, you need more frequent backups for those systems. These numbers should be documented and reviewed at least annually. ## Need help? Setting up a 3-2-1 backup strategy does not have to be complicated. If you want help designing a backup plan that fits your business and budget, [contact Athencia](/contact) and we will help you get it done right. #### Why Microsoft 365 Doesn't Back Up Your Data and What to Do About It > Explains Microsoft's shared responsibility model and why small businesses need a separate backup solution for email, OneDrive, SharePoint, and Teams data. URL: https://athencia.com/kb/cloud-and-backups/why-microsoft-365-doesnt-back-up-your-data-and-what-to-do-about-it Microsoft 365 does not provide comprehensive backup of your business data. This surprises many small business owners who assume that because their email and files are "in the cloud," they are automatically protected. They are not, at least not in the way most people think. Microsoft operates under what it calls a shared responsibility model. Microsoft is responsible for keeping the service running: the data centers, the hardware, the network infrastructure, and the geographic replication that protects against platform-level failures. But you are responsible for protecting your data from accidental deletion, malicious insiders, ransomware, retention policy gaps, and regulatory compliance requirements. Microsoft will keep the lights on. Protecting what is inside those lights is on you. Many small businesses discover this distinction the hard way, usually when they try to recover something and find out it is already gone. ## What Microsoft does and does not protect Understanding the line between Microsoft's responsibility and yours is critical. **Microsoft's responsibility** covers infrastructure uptime and hardware redundancy. If a hard drive fails in a Microsoft data center, your data is fine because it is replicated across multiple servers and geographic locations. If an entire data center goes offline, the service fails over to another location. Microsoft is very good at this. Their infrastructure uptime is excellent. **Your responsibility** covers everything that happens to the data itself. If a user accidentally deletes a critical file, that is on you. If a departing employee maliciously clears out their mailbox, that is on you. If ransomware encrypts your OneDrive files, that is on you. If you need to produce emails from two years ago for a legal matter and they have been purged because no retention policy was in place, that is on you. Here is the key distinction: Microsoft's replication is not backup. Replication protects against hardware failure on Microsoft's side. But it also replicates deletions. If a user deletes a file, that deletion replicates across all copies. Replication keeps your data available; it does not keep your data recoverable. ## The retention gaps that catch businesses off guard Microsoft does provide some built-in recovery windows, but they are shorter than most people realize and they vary by service. **Deleted mailbox items (Exchange Online).** When someone deletes an email, it goes to the Deleted Items folder. If they empty Deleted Items, the email moves to a hidden Recoverable Items folder where it stays for 14 days by default (configurable up to 30 days). After that, it is permanently gone. **Deleted OneDrive files.** Deleted files go to the OneDrive recycle bin, where they are recoverable for 93 days. After 93 days, the file is permanently deleted with no way to recover it through Microsoft. **Deleted SharePoint files.** Similar to OneDrive, deleted SharePoint files go to a site recycle bin and are recoverable for 93 days. After that, a site collection administrator can recover them from a second-stage recycle bin, but only within the same 93-day window. **Deleted user accounts.** When an employee leaves and their Microsoft 365 account is removed, their OneDrive data is deleted 30 days after the account is removed, unless another user was specifically granted access to the data beforehand. **Teams messages and channel data.** Retention depends on whether explicit retention policies have been configured. Without them, data can be lost when teams or channels are deleted. Many businesses have no Teams retention policies in place. These retention windows are short enough that problems often go unnoticed until it is too late. If a disgruntled employee deletes files and nobody notices for four months, that data is gone without a third-party backup. If someone needs an email from 18 months ago for a compliance audit, it may no longer exist in Microsoft's systems. ## Scenarios where Microsoft's built-in recovery falls short **Ransomware encrypts OneDrive files.** OneDrive does keep version history, which can help recover from ransomware by rolling files back to a pre-encryption version. However, if the attack persists long enough to age out previous versions (OneDrive keeps versions for 30 days by default, or 500 versions, whichever comes first), recovery becomes partial or impossible. A third-party backup that stores data independently from the Microsoft tenant is unaffected by ransomware that compromises your Microsoft 365 environment. **A departing employee deletes their mailbox contents and OneDrive files.** You have 30 to 93 days to notice, depending on the service. If the deletion happens gradually over their final weeks and nobody is watching, critical data can be permanently lost. With a third-party backup, you can restore that employee's mailbox and files to their exact state from any point in time covered by your backup retention. **An admin account is compromised.** An attacker with global admin access can delete data, disable retention policies, remove backup configurations, and cover their tracks. Because a third-party backup like Dropsuite stores data independently from your Microsoft 365 tenant, a tenant-level compromise does not affect your backup data. **A compliance investigation requires historical email.** If a legal matter requires email records from two years ago and no retention policy was configured to keep data that long, the email is gone. A third-party backup with long-term retention solves this problem by keeping data for as long as your retention policy specifies, independent of anything Microsoft does or does not retain. ## What a third-party backup solution provides A dedicated Microsoft 365 backup solution fills the gaps that Microsoft leaves open. **Automated daily backups** of Exchange mailboxes, OneDrive accounts, SharePoint sites, and Teams data. Once configured, backups run automatically without anyone needing to remember or trigger them. **Long-term retention** independent of Microsoft's retention policies. Keep backup data for months or years, depending on your business and compliance requirements. Your backup retention is completely separate from Microsoft's built-in retention windows, so data remains recoverable long after Microsoft would have purged it. **Point-in-time recovery.** Restore a mailbox, file, or SharePoint site to its exact state from a specific date. If you need to see what a file looked like last Tuesday, or recover an email that was deleted three months ago, you can do that with a few clicks. **Granular recovery.** Restore a single email, a single file, or a single folder without having to restore an entire mailbox or site. This is important for everyday recovery requests where someone just needs one deleted file, not a full restore. **Independent storage.** Backups are stored separately from Microsoft 365, so a compromise of your Microsoft tenant does not compromise your backups. This is critical for ransomware protection and for scenarios where an attacker gains administrative access to your Microsoft 365 environment. ## How Athencia handles Microsoft 365 backup Athencia includes Dropsuite as the Microsoft 365 backup solution in its [managed IT stack](/athencia-one). Dropsuite automatically backs up Exchange email, OneDrive, and SharePoint data for every protected user. Backups run daily, and backup health is monitored through the Athencia One portal so issues are caught and resolved before they become problems. If you need to recover data, whether it is a single email or an entire mailbox, the Athencia team can perform the restore through the Dropsuite dashboard. For a single email recovery, sign in to the Dropsuite admin console, navigate to the user's mailbox backup, search for the specific email by date, subject, or sender, and click **Restore**. For larger restores, such as an entire OneDrive or a SharePoint site, the process works the same way but covers a broader scope. This is different from relying on Microsoft's native retention. Microsoft's retention is a limited safety net with expiration dates. Dropsuite provides independent, point-in-time recovery that works regardless of what has happened inside your Microsoft 365 tenant. ## How to get started If you are not currently backing up your Microsoft 365 data, here is how to close that gap. 1. **Audit your current retention policies.** Sign in to the Microsoft 365 admin center at admin.microsoft.com. Navigate to **Compliance** (or **Purview**), then **Data lifecycle management**, then **Retention policies**. Review what policies are in place. If there are none, your data is only protected by Microsoft's default retention windows described above. 2. **Identify your most critical data.** Think about what data would cause the most damage if lost: client email correspondence, financial documents, project files, shared team resources. This helps prioritize what to protect first. 3. **Set up a third-party backup.** If Athencia manages your IT, Dropsuite is already included and configured. If you are managing IT yourself, choose a backup solution that covers Exchange, OneDrive, SharePoint, and Teams. 4. **Configure backup coverage for all users.** Make sure every active mailbox and OneDrive account is included. When new employees join, add them to the backup. When employees leave, preserve their data according to your retention requirements. 5. **Verify the first backup completes successfully.** Log in to the backup dashboard and confirm that the initial backup ran without errors. Check the data volume to make sure it looks reasonable for your organization. 6. **Test a restore within the first week.** Pick a random email or file and restore it to a temporary location. Open it and verify it is intact. This confirms that the backup is not just running but is actually producing usable, recoverable data. 7. **Schedule monthly verification.** Set a recurring calendar reminder to check backup status, test a restore, and review coverage. A backup system that nobody monitors will eventually fail silently. ## Need help? If you are unsure whether your Microsoft 365 data is properly backed up, or if you want to close the gap, [reach out to Athencia](/contact). We can audit your current setup and get backup protection in place quickly. ### Cybersecurity #### How to Create a Password Policy for Your Small Business > Practical guide to building a password policy that actually works for small businesses, including length requirements, password managers, and MFA. URL: https://athencia.com/kb/cybersecurity/how-to-create-a-password-policy-for-your-small-business A strong password policy protects your business accounts from unauthorized access. The most effective modern approach prioritizes longer passphrases and multi-factor authentication over complex character requirements that lead to sticky notes on monitors. ## Why your small business needs a written password policy Most data breaches start with compromised credentials. Without a clear, documented policy, employees tend to default to short, reused passwords across multiple services. That single habit creates a cascading risk: one breached service exposes the same password everywhere it was used. Beyond the practical security benefits, many compliance frameworks and cyber insurance policies require a documented password policy. If your business handles healthcare data (HIPAA), processes credit cards (PCI DSS), or carries cyber insurance, you likely need a written policy on file. Even if none of those apply today, having a clear policy saves you from scrambling to create one when an insurer or client asks for it. A good password policy does not need to be long. One to two pages that cover the basics is far more effective than a 20-page document nobody reads. ## Modern password guidelines (NIST recommendations) The National Institute of Standards and Technology (NIST) updated its password guidance in recent years, and the changes may surprise you. The old rules about requiring uppercase letters, numbers, and special characters are no longer recommended. Those complexity rules lead to predictable patterns like "Password1!" that technically satisfy the requirement but are trivially easy to guess. Here is what NIST recommends instead: - **Minimum 12 characters, with 16 or more as the ideal.** Length is the most important factor in password strength. - **Encourage passphrases over complex strings.** A passphrase like "correct-horse-battery-staple" is both stronger and easier to remember than "P@ssw0rd!" because length matters more than character variety. - **Do not require regular password rotation.** Forced rotation every 60 or 90 days leads to weaker passwords because people just increment a number at the end. Only require a change when a breach is suspected. - **Screen new passwords against known breached lists.** Services like Have I Been Pwned maintain databases of passwords exposed in data breaches. Your password manager or identity provider can check new passwords against these lists automatically. ## Require a password manager A password manager is non-negotiable for any business that wants its password policy to actually work. Without one, employees will reuse passwords because nobody can memorize 50 unique, 16-character passwords. A password manager generates strong, unique passwords for every account and stores them in an encrypted vault. Employees only need to memorize one master password to unlock the vault. Athencia recommends 1Password for small businesses, and includes it in the [Athencia One Complete](/athencia-one-complete) managed IT plan. 1Password combines strong security with a user-friendly interface that makes adoption easier for non-technical teams. It also supports shared vaults, which let teams securely share credentials for shared accounts without sending passwords over email or chat. Other solid options in the SMB space include Bitwarden (affordable and open-source) and Keeper (compliance-focused with detailed audit logging). When rolling out a password manager to your team, start by migrating your most critical accounts first: email, banking, and payroll. Then set a deadline for employees to move all business accounts into the manager. The master password is the one password employees must memorize, so make sure it is a strong passphrase that is not used anywhere else. ## Require multi-factor authentication (MFA) MFA is the single most effective account protection after a strong password. It requires a second form of verification, typically a code from an authenticator app, in addition to the password. Even if an attacker steals a password, they cannot access the account without the second factor. Where to enforce MFA: - **Microsoft 365 and email** (this is the most critical one) - **VPN and remote access** connections - **Banking and payroll** systems - **Any cloud application** that stores sensitive business data Authenticator apps like Microsoft Authenticator or Authy are preferred over SMS text message codes. SMS-based MFA is better than nothing, but it is vulnerable to SIM swapping attacks where an attacker convinces your phone carrier to transfer your number to their device. Authenticator apps do not have this vulnerability. If your business uses Microsoft 365 Business Premium, you can enforce MFA across your entire organization using Conditional Access policies in Entra ID. Conditional Access lets you create rules like "require MFA for all sign-ins from outside the office network" or "require MFA for any sign-in to admin portals." This is far more effective than relying on individual employees to enable MFA themselves. ## What your written policy should include Keep the document short and specific. Here is what it should cover: - **Minimum password length:** 12 characters minimum, 16 or more recommended. - **Password manager requirement:** All business accounts must use the company password manager. No exceptions. - **No password reuse:** Every account gets a unique password, enforced through the password manager. - **MFA requirement:** MFA must be enabled on all critical systems. List the specific systems. - **Compromise reporting procedure:** If an employee suspects a password has been compromised, they must report it to IT immediately, change the password, and not attempt to investigate on their own. - **No password sharing:** Employees should never share passwords via email, chat, or text. If a shared account is necessary, use the shared vault in your password manager. ## How to enforce the policy A policy that is not enforced is just a suggestion. Here are concrete ways to make it stick: **Use technical controls where possible.** In Microsoft 365, you can set password length minimums through Entra ID. Enable Conditional Access policies to require MFA, so it is not optional. Block legacy authentication protocols (IMAP, POP3) that do not support MFA. **Audit password manager adoption quarterly.** Check that all employees are actively using the password manager. 1Password's admin dashboard shows you which team members have logged in recently and how many accounts they have stored. If someone has only two items in their vault, they are not using it for all their business accounts. **Include the password policy in onboarding.** New employees should set up their password manager account and enroll in MFA on their first day. Make it part of the onboarding checklist, not something they get around to later. **Lead by example.** If the owner or leadership team does not follow the policy, nobody else will either. Owners and managers should follow the same rules, no exceptions. ## Need help? Building a password policy is straightforward, but rolling it out and enforcing it across your team takes work. If you want help creating your policy or deploying a password manager and MFA to your organization, [reach out to Athencia](/contact). We do this for small businesses every day. #### How to Recognize a Phishing Email: A Guide for Small Business Employees > Learn the warning signs of phishing emails and how to protect your small business from email-based attacks with practical tips your whole team can follow. URL: https://athencia.com/kb/cybersecurity/how-to-recognize-a-phishing-email-a-guide-for-small-business-employees Phishing emails trick people into clicking malicious links, downloading malware, or handing over credentials by impersonating trusted senders. Recognizing the warning signs before clicking is the single most effective defense a small business has against email-based attacks. ## What is phishing and why small businesses are targeted Phishing is a type of social engineering attack where criminals send fraudulent emails designed to steal your login credentials, install malware on your computer, or trick you into sending money. The emails are crafted to look like they come from someone you trust: Microsoft, your bank, a vendor, or even your own CEO. Small businesses are prime targets for phishing because they typically have fewer security layers in place, less frequent employee training, and higher-trust environments where people are less likely to question an email from a colleague. Attackers know this, and they exploit it. The average cost of a successful phishing attack on a small business ranges from $25,000 to over $100,000 when you factor in downtime, recovery, and potential data breach notification costs. ## Red flag 1: Urgency and pressure tactics Phishing emails almost always try to create a sense of panic. You will see subject lines and body text like "Your account will be suspended in 24 hours," "Immediate action required," or "Respond within the hour to avoid service disruption." The goal is to bypass your critical thinking by making you feel like you need to act right now without stopping to verify. Legitimate companies rarely threaten immediate consequences via email. If Microsoft or your bank actually needed you to take urgent action, they would typically notify you through their app, your account dashboard, or by phone. An email demanding you click a link immediately is a red flag, every time. ## Red flag 2: Sender address does not match This is one of the easiest things to check, and one of the most commonly missed. The display name in your inbox might say "Microsoft Support," but if you look at the actual email address, it reads something like support@m1crosoft-alerts.com. That is not Microsoft. To check the actual sender address in Outlook, hover over or click the sender name to reveal the full email address. On a phone, tap the sender name to expand the details. Look closely for swapped letters (rn instead of m), extra characters, or domains that do not match the company's real website. If a vendor you work with has always emailed you from billing@acmecorp.com and suddenly sends from billing@acme-corp-invoices.com, that is suspicious. ## Red flag 3: Suspicious links Before clicking any link in an email, hover your mouse over it (without clicking) to see where it actually leads. The displayed text might say "Sign in to your account," but the underlying URL could point to a completely different domain. Look for misspelled domains, extra subdomains (like microsoft.login.suspicious-site.com), or unfamiliar URLs. Shortened URLs from services like bit.ly or tinyurl in business emails are almost always suspicious. Legitimate companies link to their own domains. If you are unsure about a link, open a new browser tab and navigate directly to the company's website instead of clicking the link in the email. ## Red flag 4: Unexpected attachments If you were not expecting a file from a particular sender, do not open it. Dangerous file types include .exe, .zip, .docm (macro-enabled Word documents), and .html files. Even PDFs and standard Word documents can contain malicious content. When in doubt, confirm with the sender through a separate channel. Call them, send a Teams message, or walk over to their desk. Do not reply to the suspicious email to ask if it is legitimate, because if the sender's account was compromised, the attacker will respond and tell you it is safe. ## Red flag 5: Requests for credentials or sensitive information No legitimate service will ever ask you for your password via email. Messages like "Please verify your password by clicking here" or "Update your payment information to avoid service interruption" are phishing attempts. Common targets include fake Microsoft 365 sign-in pages, bank portals, and payroll systems. If you receive an email asking you to log in to any service, do not use the link in the email. Open a new browser tab, go directly to the service's website, and log in from there. If there is a real issue with your account, you will see it after you sign in. ## Red flag 6: Generic greetings and poor formatting Phishing emails often use generic greetings like "Dear Customer" or "Dear User" instead of your actual name. They may also contain grammatical errors, odd phrasing, or inconsistent formatting like mixed fonts, misaligned logos, or low-resolution images. One important caveat: AI-generated phishing emails are getting significantly better at grammar and formatting. A well-written email is not proof that it is legitimate. Always check the other red flags on this list, even if the writing looks professional. ## What to do if you suspect a phishing email Follow these steps in order: 1. **Do not click any links or open any attachments** in the email. 2. **Do not reply** to the email. 3. **Report it to your IT team or managed service provider immediately.** A quick report lets them investigate and warn others before anyone else falls for the same email. 4. **Use the Report Message button in Outlook.** If your company uses Microsoft 365, the **Report Message** add-in lets you flag suspicious emails directly from your inbox. Click the **Report Message** button in the ribbon and select **Phishing**. This reports the message to Microsoft and your admin, and moves it out of your inbox. Microsoft Defender for Office 365 uses these reports to improve its filtering for your entire organization. 5. **If you already clicked a link or entered credentials,** report it to your IT team immediately and change your password from a known-safe device. Do not wait. ## Building a phishing-resistant team Technology helps, but people are the last line of defense against phishing. Building a team that can spot phishing consistently requires ongoing effort. **Run regular security awareness training.** At minimum, train employees quarterly on how to recognize phishing, social engineering, and BEC attacks. Huntress provides security awareness training (SAT) as part of its platform, combining phishing simulations with targeted training modules that adapt based on how employees perform. This approach measures actual behavior rather than just checking a compliance box. **Run simulated phishing tests.** Simulated phishing campaigns send fake phishing emails to your team and track who clicks. This is not about catching people doing something wrong. It is about identifying who needs more training and measuring improvement over time. When someone clicks a simulated phishing link, they should immediately see a brief training message explaining what they missed. **Create a no-blame culture for reporting.** If employees are afraid of getting in trouble for reporting a suspicious email (or even for clicking one), they will stay quiet. That silence is far more dangerous than the click itself. Make it clear that reporting a suspicious email is always the right thing to do, and that reporting a mistake quickly is valued, not punished. **Establish a clear reporting process.** Every employee should know exactly what to do when they see a suspicious email. Post the process somewhere visible: on the intranet, in the breakroom, or as a pinned message in your company's Teams channel. The simpler the process, the more likely people are to follow it. ## How technology helps block phishing Even with a well-trained team, some phishing emails are convincing enough to fool anyone. That is where email security technology comes in. Microsoft Defender for Office 365, included with Microsoft 365 Business Premium, provides Safe Attachments (scans email attachments in a sandbox before delivering them), Safe Links (rewrites URLs and checks them at click time), and anti-phishing policies that detect impersonation attempts. These features catch many phishing emails before they ever reach your team's inbox. Athencia layers Huntress on top of Microsoft Defender for Business on every managed endpoint, providing a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. If a phishing email does slip through and an employee downloads something malicious, Huntress catches the resulting suspicious behavior on the endpoint and responds before damage spreads. The combination of email filtering, endpoint protection, and trained employees creates multiple layers of defense. No single layer is perfect, but together they make a successful phishing attack far less likely. ## Need help? Phishing is the most common way small businesses get breached, and it only takes one click. If you want help setting up email security, running phishing simulations, or training your team, [contact Athencia](/contact). We will help you build a defense that works. #### How to Secure Remote and Hybrid Employees for a Small Business > Practical security guide for small businesses with remote or hybrid employees, covering VPN, device management, home network risks, and access controls. URL: https://athencia.com/kb/cybersecurity/how-to-secure-remote-and-hybrid-employees-for-a-small-business Remote and hybrid work expands your attack surface because employees access company data from home networks, coffee shops, and personal devices that you do not control. Securing remote workers does not require enterprise-grade complexity, but it does require deliberate steps beyond what most small businesses have in place. ## What you will need Before you start, make sure you have the following in place: - **Microsoft 365 Business Premium** (or equivalent) for Conditional Access, Intune device management, and Defender for Business. This is the license tier Athencia deploys for managed clients because it bundles identity, device, and email security into a single plan. - **A clear policy** on which devices can access company data and under what conditions. - **An understanding of how your employees currently work remotely,** including what devices they use, what networks they connect from, and what applications they access. ## Step 1: Require MFA for all remote access Multi-factor authentication is non-negotiable for any employee accessing company systems from outside the office. If an attacker steals an employee's password (through phishing, a data breach, or credential stuffing), MFA stops them from signing in. Enable MFA on Microsoft 365, your VPN, and any cloud applications your business uses. The most effective way to do this is through Conditional Access policies in Entra ID, which let you create rules like "require MFA for all sign-ins from outside the office network" or "require MFA when a sign-in is flagged as risky." This approach enforces MFA automatically rather than relying on employees to enable it themselves. Authenticator apps like Microsoft Authenticator are preferred over SMS text message codes for remote workers. SMS codes are vulnerable to SIM swapping attacks, and cell reception can be unreliable when working from different locations. ## Step 2: Use company-managed devices Employees should access company data from company-owned, managed devices whenever possible. An unmanaged personal computer may have outdated software, no antivirus, or malware already running on it. You have no way to know. Enroll company devices in Microsoft Intune, which is included with Microsoft 365 Business Premium. Intune lets you enforce security policies remotely: require BitLocker encryption on all laptops, require a device PIN, enforce Windows updates automatically, and remotely wipe a lost or stolen device. This is especially critical for remote workers whose laptops travel with them to coffee shops, airports, and co-working spaces. If employees must use personal devices (a BYOD scenario), Intune's Mobile Application Management (MAM) can protect company data within managed apps like Outlook and Teams without taking control of the entire personal device. This creates a separation between personal and business data. The employee keeps their personal apps and photos; you keep your business data secure and wipeable. ## Step 3: Secure the connection For businesses with on-premises resources like file servers or internal applications, employees need a VPN to access them securely from outside the office. If you use a VPN, make sure it requires MFA to connect. A VPN without MFA is a wide-open door if credentials are stolen. For cloud-only environments where everything runs in Microsoft 365 and SaaS applications, a VPN may not be necessary if you have Conditional Access configured properly. Conditional Access can enforce security requirements (MFA, device compliance, location) at the identity layer, which provides similar protection without the overhead of routing all traffic through a VPN. Regardless of your setup, advise employees to avoid public Wi-Fi for work tasks unless they are using a VPN. Open networks at coffee shops and hotels are easy targets for attackers to intercept traffic. If public Wi-Fi is unavoidable, a VPN encrypts the connection and prevents eavesdropping. ## Step 4: Protect endpoints Every remote device needs the same endpoint protection as office devices, if not more. Remote laptops face additional risks because they are not behind the office firewall and are more likely to be lost or stolen. Athencia deploys Microsoft Defender for Business as the endpoint protection foundation on every managed device, then layers Huntress on top to provide a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. Defender handles real-time protection and threat scanning; Huntress makes sure nothing slips through by monitoring for persistent footholds, suspicious processes, and identity-based attacks. Other endpoint protection options in the SMB space include SentinelOne and CrowdStrike. Beyond endpoint protection software, make sure the following settings are configured on all remote devices: - **Windows updates install automatically.** Remote devices are not on the office network where a patch management server pushes updates, so automatic updates are essential. - **Windows Firewall is enabled.** This should be on by default, but verify it has not been disabled. - **BitLocker is turned on.** Full-disk encryption means a stolen laptop does not expose your data. BitLocker is included with Windows Pro and can be enforced through Intune. - **Automatic screen lock is set to 5 minutes.** If an employee walks away from their laptop at a coffee shop, the screen should lock quickly. ## Step 5: Control data access Not every employee needs access to everything, and not every device should be trusted equally. Conditional Access policies in Entra ID let you build rules that control who can access what, from where, and on which devices. Practical examples of Conditional Access rules for remote workers: - **Block access from unmanaged devices** to sensitive data, or limit access to view-only in the browser so files cannot be downloaded to personal computers. - **Prevent syncing SharePoint or OneDrive** to unmanaged personal computers. This keeps company files from being copied to devices you do not control. - **Require device compliance** before allowing access. A device must meet your Intune compliance policy (updated, encrypted, protected) before it can access company resources. - **Use sensitivity labels** on confidential documents to prevent forwarding, printing, or copying, regardless of where the document is accessed from. These rules work automatically in the background. Employees on compliant, managed devices will not notice any friction. Employees trying to access data from unapproved devices will be prompted to use a compliant device instead. ## Step 6: Address home network risks Employees' home routers are rarely secured properly. Default passwords are unchanged, firmware is years out of date, and the same network connects work laptops alongside smart TVs, baby monitors, and gaming consoles. You cannot fully control a home network, but you can provide guidance and focus your security on the device and connection instead. Share these recommendations with remote employees: - **Change the default router admin password** to something unique. The default password is publicly known for every router model. - **Enable WPA3 or WPA2 encryption** on the Wi-Fi network. WPA and WEP are outdated and easily cracked. - **Update the router firmware.** Most routers have an update option in the admin panel, typically accessible at 192.168.1.1 or 192.168.0.1. - **Separate work devices from IoT devices** on different networks if the router supports guest networks or VLANs. This prevents a compromised smart device from being used as a stepping stone to the work laptop. Recognize that home network guidance is advisory. Your real protection comes from the device-level security (endpoint protection, encryption, Intune compliance) and the identity-level security (MFA, Conditional Access) that you control directly. ## Create a remote work security policy Document your remote work security expectations in a short, practical policy. A one-page document that everyone reads and follows is far more effective than a 10-page policy that sits in a shared drive untouched. Include the following: - Which devices are approved for remote work (company-managed only, or BYOD with MAM). - What applications can be accessed remotely and from where. - VPN requirements and when to use it. - How to handle a lost or stolen device (report to IT immediately). - Acceptable use guidelines for public Wi-Fi and shared workspaces. Review and update the policy annually, or whenever your remote work setup changes significantly. ## Need help? Securing remote and hybrid workers involves identity, devices, data, and network considerations that need to work together. If you want help setting up Intune, Conditional Access, and endpoint protection for your remote team, [get in touch with Athencia](/contact). We help small businesses build remote work security that actually holds up. #### How to Secure Your Business Email Against Spoofing with SPF, DKIM, and DMARC > Plain-language guide to setting up SPF, DKIM, and DMARC records to prevent attackers from spoofing your business email domain. URL: https://athencia.com/kb/cybersecurity/how-to-secure-your-business-email-against-spoofing-with-spf-dkim-and-dmarc SPF, DKIM, and DMARC are three DNS records that work together to prevent attackers from sending emails that appear to come from your business domain. Without them, anyone can send an email that looks like it came from you@yourcompany.com, and your clients, vendors, and employees have no way to tell the difference. ## Why email spoofing is a serious problem for small businesses Spoofing means someone sends email pretending to be you or one of your employees. It is surprisingly easy to do. Without proper email authentication records, an attacker can send an invoice that appears to come from your CEO to your bookkeeper, requesting an urgent wire transfer. Or they can send emails to your clients that look like they came from your domain, damaging your reputation and trust. Beyond the fraud risk, email deliverability is at stake. Google and Microsoft are increasingly blocking or flagging email from domains that lack proper SPF, DKIM, and DMARC records. If your domain does not have these records configured, your legitimate emails may end up in your clients' spam folders. Setting up all three records is free (they are just DNS entries) and protects your domain from being used in phishing attacks against the people who trust your business. ## Understanding the three records Before diving into setup, here is what each record does in plain language: **SPF (Sender Policy Framework)** tells receiving mail servers which servers are authorized to send email for your domain. Think of it as a guest list for your email. If an email claims to come from your domain but was sent from a server not on the list, the receiving server knows something is wrong. **DKIM (DomainKeys Identified Mail)** adds a digital signature to every outgoing email, proving that the message was not tampered with in transit and that it actually came from your domain. Think of it as a wax seal on a letter. If the seal is broken, the recipient knows the message was altered. **DMARC (Domain-based Message Authentication, Reporting, and Conformance)** ties SPF and DKIM together and tells receiving servers what to do when authentication checks fail. You choose the action: do nothing (monitor only), quarantine the message (send it to spam), or reject it outright (block it). DMARC also sends you reports about who is trying to send email as your domain. All three work together. SPF and DKIM verify the email is legitimate; DMARC tells the world what to do when it is not. ## Step 1: Check your current records Before making changes, check what you already have in place. Go to [MXToolbox.com](https://mxtoolbox.com) and run a lookup on your domain. Check for SPF, DKIM, and DMARC records separately. What you are likely to find: many small business domains have a partial or incorrect SPF record (often missing third-party senders), no DKIM signing enabled, and no DMARC record at all. If your results show all three configured correctly, you are ahead of most small businesses. If not, work through the steps below. Another useful tool is [dmarcian.com](https://dmarcian.com), which provides a more detailed analysis and ongoing monitoring. ## Step 2: Set up SPF SPF is a TXT record added to your domain's DNS settings. You access DNS through wherever your domain is registered (GoDaddy, Namecheap, Cloudflare, etc.) or through your DNS hosting provider. For businesses using Microsoft 365, the SPF record should be: ``` v=spf1 include:spf.protection.outlook.com -all ``` This tells receiving servers that Microsoft's mail servers are authorized to send email for your domain, and that all other servers should be rejected (`-all`). If you use other services that send email on your behalf, such as Mailchimp for newsletters, QuickBooks for invoices, or a CRM that sends from your domain, you need to add their SPF includes to the same record. For example: ``` v=spf1 include:spf.protection.outlook.com include:servers.mcsv.net -all ``` Important: you can only have one SPF record per domain. If you create a second one, both will break. Combine all authorized senders into a single record. The difference between `~all` (soft fail) and `-all` (hard fail): soft fail means "treat unauthorized senders as suspicious," while hard fail means "reject unauthorized senders." Start with `-all` if you are confident you have listed all legitimate senders. Use `~all` temporarily if you are still identifying all services that send email as your domain. ## Step 3: Set up DKIM DKIM requires generating signing keys and publishing them in your DNS. For Microsoft 365, this is done through the Microsoft Defender portal. 1. Go to [security.microsoft.com](https://security.microsoft.com). 2. Navigate to **Policies & rules** > **Threat policies** > **Email authentication settings**. 3. Select the **DKIM** tab. 4. Select your domain from the list. 5. Click **Enable** to turn on DKIM signing. 6. Microsoft will display two CNAME records that you need to add to your domain's DNS. Copy those CNAME records and add them at your DNS provider. The records will look something like: ``` selector1._domainkey.yourcompany.com -> selector1-yourcompany-com._domainkey.yourcompany.onmicrosoft.com selector2._domainkey.yourcompany.com -> selector2-yourcompany-com._domainkey.yourcompany.onmicrosoft.com ``` After adding the DNS records, wait for DNS propagation (this can take up to 48 hours, though it often completes much faster). Then return to the Defender portal and click **Enable** again to activate DKIM signing. If the DNS records have propagated, DKIM will turn on successfully. A common mistake is adding the DNS records but forgetting to go back and enable DKIM signing in the portal. Both steps are required. ## Step 4: Set up DMARC DMARC is another TXT record added to your DNS. Start with a monitoring-only policy so you can see what is happening before you start blocking anything. Add this TXT record to your DNS at `_dmarc.yourcompany.com`: ``` v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com ``` Here is what each part means: - `v=DMARC1` identifies this as a DMARC record. - `p=none` is the policy. "None" means do not take action on failed messages; just report them. - `rua=mailto:dmarc-reports@yourcompany.com` is where aggregate reports will be sent. The `p=none` policy does not block anything, but it starts sending you reports about who is sending email as your domain. This is the discovery phase, and it is essential. Skipping straight to a blocking policy risks blocking legitimate email from services you forgot about. After monitoring for 2 to 4 weeks and reviewing your reports, move to `p=quarantine`. This sends suspicious emails (those failing SPF and DKIM checks) to the recipient's spam folder instead of their inbox. Once you are confident that all legitimate senders are properly authenticated, move to `p=reject`. This is the final goal. With a reject policy, spoofed emails claiming to come from your domain are blocked entirely and never delivered. ## Step 5: Monitor DMARC reports DMARC sends XML report files to the email address specified in your `rua=` tag. These reports are dense and difficult to read in raw format. Use a free tool like [dmarcian](https://dmarcian.com), Valimail, or DMARC Analyzer to parse and visualize them. What to look for in your reports: - **Legitimate services failing authentication.** If your CRM or invoicing software is sending email as your domain but is not included in your SPF record, it will show up as a failure. Add it to your SPF record. - **Unknown senders spoofing your domain.** If you see emails being sent from your domain by servers you do not recognize, someone is spoofing you. This is exactly what DMARC is designed to catch. - **The overall pass rate.** As you add legitimate senders to SPF and enable DKIM, your pass rate should climb toward 100%. Review reports weekly during the first month, then monthly once your configuration is stable. Microsoft Defender for Office 365, included with Microsoft 365 Business Premium, also provides email authentication insights in the Defender portal that complement your DMARC reports. ## Common mistakes These are the issues we see most often when small businesses set up email authentication: - **Multiple SPF records.** Only one SPF TXT record is allowed per domain. If you add a second one, both fail. Combine all authorized senders into a single record. - **Jumping to DMARC p=reject before monitoring.** This blocks legitimate email from services you forgot to authorize. Always start with `p=none`, review reports, then move to `p=quarantine`, and finally `p=reject`. - **Forgetting third-party senders.** Your CRM, invoicing software, marketing platform, and ticketing system may all send email as your domain. Each one needs to be included in your SPF record. - **Adding DKIM DNS records but not enabling signing.** The CNAME records in DNS are only half the setup. You must also enable DKIM signing in the Microsoft Defender portal. ## Need help? Email authentication involves DNS changes that can affect your email deliverability if done incorrectly. If you are not comfortable making DNS changes yourself, or if you want someone to handle the full SPF, DKIM, and DMARC setup and monitoring, [contact Athencia](/contact). We configure email authentication for small businesses regularly and can have it done correctly in a single session. #### What Is Business Email Compromise and How to Protect Your Company > Explains how business email compromise (BEC) attacks work, why they target small businesses, and practical steps to prevent wire fraud and data theft. URL: https://athencia.com/kb/cybersecurity/what-is-business-email-compromise-and-how-to-protect-your-company Business email compromise (BEC) is a type of attack where a criminal impersonates a trusted person, typically a CEO, vendor, or attorney, to trick an employee into sending money or sensitive information. BEC attacks cause more financial damage than any other type of cybercrime, with the FBI reporting over $2.9 billion in losses in a single year. Unlike ransomware, which is loud and obvious, BEC is quiet. There is no malware, no locked screens, and often no sign anything happened until the money is gone. ## How BEC attacks work A BEC attack starts with research. The attacker learns about your company by browsing your website, LinkedIn profiles, and social media. They identify who the CEO is, who handles finances, who your vendors are, and how your company communicates internally. Next, the attacker either compromises a real email account (through phishing, credential theft, or password spraying) or creates a lookalike email address that is almost identical to a real one. For example, they might register "athencla.com" instead of "athencia.com," a difference most people would not notice in a busy inbox. Then comes the request. The attacker sends a convincing email asking for an urgent wire transfer, payment to a new bank account, or sensitive data like W-2 forms or employee records. The email appears to come from someone the employee trusts and expects to receive instructions from. The urgency and authority built into the request pressure the employee into acting quickly without verifying through a separate channel. The entire attack relies on social engineering, not technology. That is what makes it so effective and so difficult for traditional security tools to catch. ## Common BEC scenarios **CEO fraud.** An email appearing to come from the CEO or owner asks the bookkeeper or office manager to wire funds for a "confidential acquisition" or "urgent vendor payment." The email often includes language like "handle this quietly" or "I'm in a meeting, can you take care of this before end of day?" **Vendor invoice manipulation.** An email appearing to come from a real vendor says "our bank account has changed, please send future payments to this new account number." The email may include a convincing invoice with the correct logo, formatting, and amounts, but with different banking details. **Attorney impersonation.** A fake attorney contacts an employee about a "confidential legal matter" requiring immediate payment. These often target finance staff and use legal urgency to discourage questions. **Payroll diversion.** An email appearing to come from an employee asks HR to update their direct deposit information to a new bank account. The employee's real paycheck then goes to the attacker. **Data theft.** A request for W-2s, employee lists, Social Security numbers, or client data, sent to HR or the office manager from what appears to be the CEO. This information is then used for identity theft or sold on the dark web. ## Why small businesses are especially vulnerable Small businesses are the ideal target for BEC because they often have fewer approval layers for financial transactions. One person may handle all payments, and a request from the owner is rarely questioned. There is often no formal verification process for changing vendor payment details or processing wire transfers. Smaller teams also mean fewer people to notice something is off. In a larger company, a suspicious wire transfer request might pass through multiple approvals and raise questions. In a 15-person company, the person who handles the books may simply process the request because the email looks like it came from the boss. The amounts requested in BEC attacks are often deliberately calibrated. Attackers request amounts large enough to be profitable but small enough to avoid triggering bank fraud alerts or unusual payment scrutiny. A $28,000 wire transfer feels urgent but not outlandish, which is exactly the point. ## Protection step 1: Implement verification procedures The most effective defense against BEC is a simple human process: verify before you act. Require verbal (phone call) confirmation for any wire transfer, payment change, or new vendor setup. Call the person using a phone number you already have on file, not a number provided in the email. If the CEO sends an email requesting a wire transfer, call the CEO on their known cell phone number and confirm it. Require dual authorization for wire transfers and payments above a set threshold. No single person should be able to initiate and approve a large payment on their own. Never change vendor payment details based solely on an email request. Always verify new banking information through a known contact at the vendor company, using a phone number from your records. These verification steps may feel like extra work, but they are far cheaper than losing $50,000 to a fraudulent wire transfer. ## Protection step 2: Secure your email accounts If an attacker cannot compromise your actual email accounts, they are limited to spoofing or lookalike domains, which are easier to detect. Locking down your email is critical. **Enable MFA on all email accounts.** This is the single most effective technical protection against account compromise. If an attacker phishes an employee's password, MFA stops them from signing in. Use Conditional Access policies in Entra ID to enforce MFA across your entire Microsoft 365 tenant, not just for users who remember to turn it on. **Configure anti-phishing policies in Microsoft Defender for Office 365.** Defender for Office 365, included with Microsoft 365 Business Premium, provides impersonation protection that flags emails where the sender's name matches a known internal user but the email address does not. This catches many BEC attempts before they reach the inbox. **Enable mailbox auditing** to detect unauthorized access to email accounts. Microsoft 365 has mailbox auditing enabled by default, but verify it is active for all users. **Set up alerts for mail forwarding rule changes.** One of the first things an attacker does after compromising an account is set up a forwarding rule to intercept replies. Configure alerts in the Security & Compliance center to notify admins when new forwarding rules are created. Huntress provides identity threat detection and response (ITDR) that monitors for suspicious sign-in activity, credential attacks, and account takeover attempts across your Microsoft 365 environment. This adds a layer of 24/7 human monitoring that catches identity-based threats that automated tools may miss. ## Protection step 3: Protect against domain spoofing Configure SPF, DKIM, and DMARC on your email domain to prevent attackers from sending email that appears to come from your exact domain. With DMARC set to a "reject" policy, spoofed emails are blocked by the receiving server and never delivered. This does not prevent lookalike domains (athencla.com vs. athencia.com), but it stops exact-domain spoofing. For a detailed setup guide, see our article on [how to secure your business email against spoofing with SPF, DKIM, and DMARC](/kb/cybersecurity/how-to-secure-your-business-email-against-spoofing-with-spf-dkim-and-dmarc). ## Protection step 4: Train your team Make BEC a specific topic in your security awareness training, separate from general phishing awareness. BEC attacks are different because they often contain no malicious links or attachments. They rely entirely on social engineering, which means technical email filters may not catch them. Use real-world examples relevant to your industry. A law firm should hear about fake settlement wire requests; a construction company should hear about fraudulent subcontractor invoices. The scenarios need to feel real to your team. Emphasize that urgency and authority are the primary manipulation tools in BEC. Any request that is both urgent and involves money or sensitive data should trigger a verification call, every time. Create a culture where questioning a financial request is expected, not disrespectful. The bookkeeper should feel comfortable calling the CEO to verify a wire transfer, even if the email says "don't call me, I'm in a meeting." That is exactly when they should call. Huntress provides security awareness training as part of its platform, including targeted BEC scenarios and phishing simulations that help employees practice identifying these attacks in a safe environment. ## What to do if you suspect a BEC attack Act fast. Every hour matters, especially if money has already been sent. 1. **Do not send the requested payment or information.** If you have not acted on the request yet, stop. 2. **Verify the request** through a separate communication channel. Call the supposed sender using a known phone number. 3. **If money was already sent, contact your bank immediately.** Wire recalls have a narrow window (often 24 to 48 hours). The sooner you call, the better your chances of recovering the funds. 4. **Report to the FBI's IC3** at [ic3.gov](https://www.ic3.gov/) and your local FBI field office. BEC is a federal crime and the IC3 has a Recovery Asset Team that works with banks to freeze fraudulent transfers. 5. **If an email account was compromised,** reset the password, revoke all active sessions, check for forwarding rules and inbox rules, and review recent sent items to see what the attacker sent from the account. 6. **Notify your cyber insurance carrier.** Most policies have specific timelines for breach notification, and delayed reporting can affect your claim. ## Need help? BEC is the costliest form of cybercrime for small businesses, and prevention starts with the right combination of training, verification procedures, and email security. If you want help hardening your email environment or responding to a suspected compromise, [contact Athencia](/contact). We handle BEC prevention and incident response for small businesses across the country. #### What Is Ransomware and How Can Small Businesses Protect Against It > Plain-language explanation of ransomware, how it targets small businesses, and the practical steps you can take to prevent and recover from an attack. URL: https://athencia.com/kb/cybersecurity/what-is-ransomware-and-how-can-small-businesses-protect-against-it Ransomware is malicious software that encrypts your business files and demands payment (a ransom) to unlock them. Small businesses are the most common target because they often lack the security layers that larger companies have, and they are more likely to pay to get their data back quickly. ## How ransomware works Ransomware typically enters your network through a phishing email, a compromised website, or an unpatched vulnerability in your software. Once inside, the malware spreads across the infected computer and any connected network drives, encrypting files as it goes. Documents, spreadsheets, databases, images, and backups (if they are accessible on the network) all get locked. A ransom note then appears on screen demanding payment, usually in cryptocurrency like Bitcoin, in exchange for the decryption key. There is typically a deadline, and the attacker threatens to increase the ransom or permanently delete the key if you do not pay in time. Modern ransomware attacks frequently use a tactic called double extortion. The attacker steals a copy of your data before encrypting it, then demands two payments: one to decrypt your files and another to prevent them from leaking your data publicly. This means that even if you have good backups and can restore your files without paying, you still face the threat of sensitive data being published. Typical ransom demands for small businesses range from $10,000 to $250,000 or more, depending on the attacker's assessment of what you can afford. ## Why small businesses are prime targets Attackers have figured out the sweet spot: small businesses are big enough to pay meaningful ransoms but small enough to have significant security gaps. Most small businesses do not have dedicated IT security staff or advanced endpoint protection. Systems are often running outdated software with unpatched vulnerabilities. Backup and recovery plans exist on paper but have never been tested. And when a ransomware attack hits, the pressure to pay is enormous because extended downtime can threaten the survival of the business. Attackers know all of this. They specifically target small businesses because the return on effort is high. A single phishing email can lead to a six-figure payout. ## How ransomware gets in (common entry points) Understanding how ransomware enters your network is the first step to blocking it: - **Phishing emails** with malicious attachments or links are the most common entry point. An employee opens a file or clicks a link, and the malware installs silently in the background. - **Remote Desktop Protocol (RDP)** exposed to the internet with weak or default credentials. Attackers scan the internet for open RDP ports and brute-force their way in. - **Unpatched vulnerabilities** in software, firewalls, or VPN appliances. Known vulnerabilities in widely used products are exploited within days of being disclosed. - **Compromised credentials** purchased on the dark web from previous data breaches. If an employee reused a password that was exposed in a breach, attackers buy it and try it against your systems. - **Infected USB drives or personal devices** connected to the business network without proper security controls. ## Protection step 1: Implement strong email security Since phishing is the most common delivery method for ransomware, email security is your first line of defense. Microsoft Defender for Office 365, included with Microsoft 365 Business Premium, provides Safe Attachments and Safe Links. Safe Attachments opens email attachments in a secure sandbox environment before delivering them to the recipient. If the attachment is malicious, it is blocked before it ever reaches the inbox. Safe Links rewrites URLs in emails and checks them at the moment the user clicks, blocking access to known malicious sites even if the URL was safe when the email was originally sent. Configure anti-phishing policies in Defender to detect impersonation attempts and flag suspicious emails. These policies catch many ransomware delivery emails before employees ever see them. Complement your email security with employee training. Even the best filters will miss some phishing emails, so your team needs to know how to recognize them. See our guide on [how to recognize a phishing email](/kb/cybersecurity/how-to-recognize-a-phishing-email-a-guide-for-small-business-employees) for practical tips you can share with your staff. Implement SPF, DKIM, and DMARC on your email domain to prevent attackers from spoofing your domain in phishing campaigns. ## Protection step 2: Keep everything patched and updated Unpatched software is one of the easiest ways for ransomware to enter your network. Every patch you skip is a known vulnerability that attackers can exploit. Enable automatic Windows updates on all business PCs. For remote workers who are not on the office network, this is especially important since they may miss updates that a local patch management server would push. Keep third-party software updated as well. Browsers (Chrome, Edge, Firefox), Adobe Reader, Java, and Zoom all receive regular security patches. Outdated versions of these applications are common entry points. Patch network equipment firmware including routers, firewalls, and wireless access points. These devices sit at the edge of your network and are often forgotten in patching routines. Replace end-of-life software and hardware that no longer receives security updates. Running Windows 10 after its end-of-life date, for example, means known vulnerabilities will never be patched, leaving your systems permanently exposed. If your business uses Microsoft 365 Business Premium, Microsoft Intune can enforce update policies across all enrolled devices, ensuring that patches install automatically even on remote laptops. ## Protection step 3: Use endpoint protection (not just antivirus) Traditional antivirus works by scanning files against a database of known malware signatures. Modern ransomware is specifically designed to evade signature-based detection. It changes its code with every attack, encrypts itself to avoid detection, and uses legitimate system tools to carry out malicious actions. Endpoint Detection and Response (EDR) takes a fundamentally different approach. Instead of just checking files against a list, EDR monitors the behavior of processes running on your computer. If a process starts encrypting files rapidly, disabling backups, or communicating with known command-and-control servers, EDR detects and stops it. Athencia deploys Microsoft Defender for Business as the endpoint protection foundation on every managed device, then layers Huntress on top to provide a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. Defender handles real-time protection and automated responses; Huntress adds persistent foothold detection, SIEM log analysis, and human-led investigations that catch threats automated tools miss. Other EDR options in the SMB space include SentinelOne and CrowdStrike. The key point: you need both automated detection and human monitoring. Automated tools catch the obvious threats; human analysts catch the sophisticated ones that know how to blend in. ## Protection step 4: Maintain tested backups Backups are your last line of defense against ransomware. If everything else fails, a clean, recent backup means you can restore your data without paying the ransom. Follow the 3-2-1 backup rule: maintain 3 copies of your data, on 2 different types of media, with 1 copy stored offsite or in the cloud. At least one backup must be air-gapped or immutable. An air-gapped backup is physically disconnected from your network, so ransomware cannot reach it. An immutable backup cannot be modified or deleted once written, even by an administrator. This is critical because modern ransomware specifically targets and encrypts backup files that are accessible on the network. Dropsuite provides cloud backup for Microsoft 365 email, OneDrive, and SharePoint, giving you an independent copy of your data that lives outside your Microsoft 365 environment. If ransomware compromises your tenant or an attacker deletes data, Dropsuite lets you restore from a clean backup. Test your backup restoration regularly. A backup you have never tested is not a backup. At least quarterly, restore a sample of files from your backup to verify that the process works, the data is intact, and you know how long recovery actually takes. Knowing your recovery time objective (RTO) before a crisis hits is far better than discovering it during one. ## Protection step 5: Limit access and privileges Ransomware spreads faster and does more damage when the infected account has broad access to files and systems. Limiting privileges reduces the blast radius of an attack. **Remove local admin rights** from everyday user accounts. Employees do not need admin privileges for their daily work, and removing those privileges prevents ransomware from making system-level changes on the infected computer. **Apply the principle of least privilege** for file share and application access. Users should only have access to the files and systems they need for their job, nothing more. **Segment your network** so that an infection on one computer cannot spread to every shared drive and system on your network. At minimum, separate guest Wi-Fi from your business network and isolate critical systems like accounting and HR databases. **Disable Remote Desktop Protocol (RDP)** unless it is absolutely necessary. If RDP must be used, protect it with a VPN and require MFA to connect. Exposed RDP is one of the most exploited entry points for ransomware. ## What to do if you are hit by ransomware If ransomware hits your business, speed and containment are critical. Here is what to do: 1. **Disconnect infected computers from the network immediately.** Unplug the Ethernet cable and disable Wi-Fi. The goal is to stop the ransomware from spreading to other devices and network drives. 2. **Do not pay the ransom.** Payment does not guarantee you will get your data back. It funds future attacks and marks your business as willing to pay, making you a target for repeat attacks. 3. **Contact your IT provider or MSP immediately.** Ransomware response requires expertise in containment, forensics, and recovery. Do not try to handle it alone. 4. **Report the incident** to the FBI's IC3 at [ic3.gov](https://www.ic3.gov/) and your cyber insurance carrier. Most insurance policies have specific timelines for reporting incidents. 5. **Begin recovery from clean backups** once the infection vector has been identified and contained. Restoring before you know how the ransomware got in risks reinfection. The best time to prepare for a ransomware attack is before it happens. Having endpoint protection, tested backups, and a basic incident response plan in place turns a potential disaster into a recoverable event. ## Need help? Ransomware protection requires layers: email security, endpoint protection, backups, patching, and access controls all working together. If you want help assessing your current defenses or building a protection plan for your business, [contact Athencia](/contact). We help small businesses put the right layers in place before an attack happens. #### What to Do If You Think Your Business Email Has Been Compromised > An incident response checklist for business email compromise (BEC). Steps to contain the threat, assess damage, and prevent it from happening again. URL: https://athencia.com/kb/cybersecurity/what-to-do-if-you-think-your-business-email-has-been-compromised ## Recognizing the signs Business email compromise (BEC) is one of the most financially damaging cyberattacks affecting small and mid-size businesses. The FBI's Internet Crime Complaint Center reports BEC losses exceeding $2.9 billion annually in the US alone. You may be dealing with a compromised email account if you notice any of the following: - **Sent items you did not write**, especially messages to vendors, clients, or finance contacts - **Inbox rules you did not create**, such as rules that auto-delete or forward messages - **Password reset notifications** you did not request - **Colleagues or clients reporting suspicious messages** from your address - **Unfamiliar sign-in activity** in your account's sign-in logs - **Missing emails** that should be in your inbox If any of these apply, treat the account as compromised and act immediately. Speed matters. ## Step 1: Contain the account (do this first) The goal is to stop the attacker from continuing to use the account. ### Reset the password 1. Have an administrator reset the user's password from the [Microsoft Entra admin center](https://entra.microsoft.com) 2. Use a strong, unique password (16+ characters) 3. Do not let the user reset their own password from the compromised account ### Revoke active sessions 1. In the Entra admin center, go to **Users** > select the user > **Sign-in sessions** 2. Click **Revoke all sessions** 3. This forces the attacker out of any active sessions immediately ### Disable the account temporarily (if needed) If you cannot confirm containment, disable the account entirely until the investigation is complete. In the Entra admin center, go to **Users** > select the user > **Properties** > **Account status** and toggle sign-in to **Block sign in**. This is the safest option when financial fraud may be in progress. ## Step 2: Check for persistence mechanisms Attackers often set up ways to maintain access even after a password change. Check all of the following. ### Inbox rules 1. Go to **Exchange admin center** > **Recipients** > **Mailboxes** > select user 2. Click **Manage mailbox delegation** or use PowerShell: `Get-InboxRule -Mailbox user@domain.com` 3. Look for rules that forward, redirect, or delete emails 4. Delete any rules you did not create ### Mail forwarding 1. In Exchange admin center, check the user's mailbox properties for **Email forwarding** 2. Verify no external forwarding address has been added 3. PowerShell: `Get-Mailbox user@domain.com | Select ForwardingAddress,ForwardingSmtpAddress` ### OAuth app consents 1. In Entra admin center, go to **Users** > select user > **Applications** 2. Review consented applications 3. Revoke any unfamiliar third-party app permissions ### Registered devices and MFA methods 1. Check **Authentication methods** for the user 2. Remove any MFA methods you do not recognize (unfamiliar phone numbers, authenticator apps) 3. Check **Devices** and remove any unrecognized registered devices ## Step 3: Assess the damage Before you can notify the right people, you need to understand what the attacker did. ### Review sign-in logs 1. Entra admin center > **Sign-in logs** 2. Filter by the affected user 3. Look for sign-ins from unusual locations, IP addresses, or devices 4. Note the earliest suspicious sign-in to establish a timeline If your environment is monitored by Huntress, check the Huntress dashboard as well. Huntress provides identity threat detection and response (ITDR) and SIEM capabilities that correlate sign-in anomalies with other suspicious activity across your environment, giving you a more complete picture of the compromise timeline. ### Review audit logs 1. Check **Unified audit log** in the Microsoft Purview compliance portal 2. Filter by the user and time range 3. Look for mail access, file downloads, sharing changes, and admin actions ### Check for data exfiltration - Were sensitive files accessed or downloaded from SharePoint or OneDrive? - Were emails forwarded to external addresses? - Were contact lists or client data exported? If your organization uses Dropsuite for Microsoft 365 backup, you can compare current mailbox and OneDrive contents against the backup to identify exactly what was deleted, modified, or exported during the compromise window. Document everything you find. You will need this for notifications and potential legal obligations. ## Step 4: Notify stakeholders ### Internal notification - Inform your leadership team and legal counsel - Alert your finance team if the attacker sent payment-related messages - Notify any employees who received suspicious messages from the compromised account ### External notification - Contact any clients or vendors who received fraudulent messages - If financial transactions were redirected, contact your bank immediately (wire recalls have a narrow window) - If personal data was exposed, you may have breach notification obligations under state law (e.g., CCPA) or industry regulations (e.g., HIPAA) ### Law enforcement - File a report with the [FBI's IC3](https://www.ic3.gov/) if financial fraud occurred - File a local police report if required by your cyber insurance policy ## Step 5: Harden the account and environment After containment and investigation, take these steps to prevent recurrence. ### For the affected account - Enable MFA if not already active (see our [MFA setup guide](/kb/microsoft-365/how-to-set-up-multi-factor-authentication-in-microsoft-365)) - Require a fresh MFA registration - Review and re-consent only necessary OAuth applications ### For the entire organization - **Enable Conditional Access policies in Entra ID** to require MFA for all users, block legacy authentication protocols, and restrict sign-ins from non-compliant devices. Conditional Access, included with Microsoft 365 Business Premium, is significantly more flexible than Security Defaults and should be the standard for any organization that has experienced a compromise. - **Disable legacy authentication** (IMAP, POP3, SMTP basic auth) tenant-wide. These protocols do not support MFA and are a common entry point for credential-based attacks. - **Deploy anti-phishing policies** in Microsoft Defender for Office 365 to detect impersonation attempts and block malicious attachments and links before they reach inboxes. - **Deploy Huntress across all endpoints and identities.** Huntress provides 24/7 SOC monitoring with human threat hunters, identity threat detection (ITDR), and SIEM. This ensures that if credentials are compromised again, the suspicious sign-in activity is caught and responded to by a human analyst before the attacker can act. - **Train employees** on recognizing phishing and BEC tactics. Huntress also provides security awareness training with phishing simulations to measure and improve your team's ability to spot these attacks. - **Implement email authentication** (SPF, DKIM, DMARC) to prevent domain spoofing ## Timeline summary | Time Frame | Action | |------------|--------| | First 15 minutes | Reset password, revoke sessions, disable account if needed | | First hour | Check inbox rules, forwarding, OAuth consents, MFA methods | | First 4 hours | Review sign-in and audit logs, assess data exposure | | First 24 hours | Notify internal stakeholders, affected clients, and vendors | | First 48 hours | Contact bank for wire recalls, file IC3 report if needed | | First week | Harden environment, enable MFA, deploy anti-phishing policies | | Ongoing | Employee training, regular access reviews, phishing simulations | ## When to call for help If your organization does not have in-house security expertise, do not try to handle a BEC incident alone. The financial and legal risks are significant. Athencia provides incident response support for business email compromise. We handle containment, investigation, remediation, and hardening so you can focus on running your business. [Reach out to us](/contact) if you need assistance. #### What Your Cyber Insurance Policy Expects from Your IT Security > Guide to the most common IT security requirements in cyber insurance policies and how small businesses can meet them to avoid denied claims. URL: https://athencia.com/kb/cybersecurity/what-your-cyber-insurance-policy-expects-from-your-it-security Cyber insurance policies increasingly require specific IT security controls as a condition of coverage. If you experience a breach and cannot demonstrate that these controls were in place, your claim may be denied. Understanding and meeting these requirements protects both your coverage and your business. ## Why cyber insurance requirements have gotten stricter Ransomware payouts skyrocketed between 2020 and 2024, costing insurers billions and forcing them to tighten underwriting standards dramatically. Many policies now include detailed security questionnaires during the application and renewal process, asking specific questions about MFA, endpoint protection, backup practices, and employee training. Insurers are also actively denying claims when businesses misrepresented their security posture on the application. If you said MFA was enabled on all accounts but it was only enabled on two out of twenty, that discrepancy can void your coverage when you need it most. The good news is that meeting these requirements is not just about keeping your insurer happy. Every control on this list genuinely reduces your risk of a breach. The insurers require them because they work. ## Requirement 1: Multi-factor authentication (MFA) Nearly every cyber insurance policy now requires MFA, and it is the single most common reason for claim denials. The insurer asks "Is MFA enabled on all email accounts and remote access?" on the application, the business checks "yes," and then a breach investigation reveals that MFA was only enabled on some accounts, or was configured but not actually enforced. Where MFA must be enabled: - **Email** (Microsoft 365 or Google Workspace) for all users, not just admins - **VPN and remote access** connections - **Admin accounts** for all systems, including firewalls, servers, and cloud platforms - **Cloud applications** that store sensitive data (accounting, payroll, CRM) Authenticator apps or hardware security keys are preferred. Some policies explicitly state that SMS-based MFA does not satisfy the requirement because it is vulnerable to SIM swapping attacks. The most reliable way to enforce MFA across your organization is through Conditional Access policies in Entra ID, included with Microsoft 365 Business Premium. Conditional Access lets you create rules that require MFA for every sign-in, or for specific conditions like sign-ins from outside your office network or from non-compliant devices. This is enforcement at the platform level, meaning individual users cannot bypass it. ## Requirement 2: Endpoint detection and response (EDR) Traditional antivirus is no longer sufficient for most cyber insurance policies. Insurers now expect some form of EDR or next-generation endpoint protection that actively monitors for threats rather than just scanning for known malware signatures. The specific language varies by insurer. Some policies say "EDR," others say "next-generation antivirus" or "managed detection and response." Read the exact language in your policy and make sure your solution meets the stated requirement. Athencia deploys Microsoft Defender for Business as the endpoint protection foundation on every managed device, then layers Huntress on top to provide a 24/7 SOC with human threat hunters who actively investigate and respond to alerts. This combination satisfies the EDR requirement and the managed detection and response (MDR) requirement that many policies now include. Defender handles real-time protection; Huntress provides the human monitoring, SIEM, and incident response that insurers want to see. Other EDR options in the SMB space include SentinelOne and CrowdStrike. If your policy requires MDR or 24/7 monitoring, make sure you can demonstrate that capability. Having EDR software installed but nobody watching the alerts is a gap that insurers will identify. ## Requirement 3: Regular data backups Policies typically require regular backups with offsite or cloud copies. The bar has been raised beyond simply running a backup job. Insurers now want to see: - **Regular backup frequency.** Daily for most data, more frequently for critical systems like databases and financial records. - **Offsite or cloud storage.** At least one copy of your backup must be stored outside your primary environment. If ransomware encrypts your local server, your backup needs to be somewhere it cannot reach. - **Immutable or air-gapped backups.** Increasingly, policies require that at least one backup copy cannot be modified or deleted, even by an administrator. This prevents ransomware from encrypting your backups along with your production data. - **Documented backup testing.** It is not enough to say backups are running. You need to demonstrate that you have tested restoration and that the data is recoverable. Keep logs of backup test results, including the date, what was restored, and whether it was successful. Dropsuite provides cloud backup for Microsoft 365 email, OneDrive, and SharePoint. This gives you an independent, cloud-based copy of your Microsoft 365 data that lives outside your tenant. If your environment is compromised, Dropsuite lets you restore clean copies of email, files, and sites. Having a third-party backup solution like Dropsuite also demonstrates to your insurer that your backups are genuinely independent from your production environment. ## Requirement 4: Patch management Unpatched systems are one of the most commonly exploited entry points for attackers, and insurers know it. Most policies require a documented patch management process, and many specify a timeframe for applying critical patches, typically within 14 to 30 days of release. This requirement applies to everything: operating systems, applications (browsers, Adobe, Java), network devices (routers, firewalls, VPN appliances), and firmware. End-of-life software that no longer receives security patches is a red flag for insurers and may be grounds for increased premiums or denied coverage. If your business uses Microsoft 365 Business Premium, Microsoft Intune can enforce Windows update policies across all enrolled devices, ensuring patches install automatically on both office and remote computers. For third-party application patching, your MSP or IT provider can implement tools that automate updates for common business software. A documented patch management process does not need to be complicated. A simple written procedure that states "critical patches are applied within 14 days; all other patches within 30 days; end-of-life software is replaced before support ends" gives you a defensible position. ## Requirement 5: Employee security awareness training Most cyber insurance policies require documented security awareness training for all employees. Phishing remains the most common entry point for attacks, and insurers expect you to be actively training your team to recognize and report it. Training should cover: - **Phishing recognition** (email, SMS, and voice phishing) - **Password hygiene** and the use of password managers - **Social engineering tactics** including business email compromise - **Data handling** and what constitutes sensitive information Frequency matters. Annual training is the minimum most policies require, but quarterly training demonstrates a stronger commitment to security. Many policies also expect simulated phishing tests, where fake phishing emails are sent to employees to measure who clicks and who reports. Huntress provides security awareness training (SAT) as part of its platform, combining phishing simulations with targeted training modules. Employees who click on simulated phishing links receive immediate, relevant training. This approach measures actual behavior, not just attendance at a training session, which is exactly what insurers want to see. Keep records of who completed training and when. During a claim, you may be asked to produce training completion reports for all employees. ## Requirement 6: Access controls and privileged account management Insurers expect you to follow the principle of least privilege: users should only have access to the systems and data they need for their job, nothing more. Specific expectations include: - **Separate admin accounts.** Administrators should have a separate account for admin tasks, distinct from their daily email and productivity account. If their daily account is phished, the attacker does not gain admin access. - **Prompt offboarding.** When an employee leaves, their access must be revoked promptly. Document your offboarding process and show that it includes disabling accounts, revoking MFA, and removing access to shared resources. - **Password policies that meet minimum standards.** Minimum length requirements (12+ characters), no password reuse, and the use of a password manager. Athencia recommends 1Password for small businesses because of its balance of security and usability. - **Regular access reviews.** Periodically review who has access to what and remove unnecessary permissions. This does not need to be a formal audit; a quarterly check by your IT provider is sufficient. Entra ID and Conditional Access make it straightforward to enforce these controls across your Microsoft 365 environment. Conditional Access can require compliant devices, block risky sign-ins, and enforce MFA on all admin accounts automatically. ## Other common requirements Beyond the six core requirements above, your policy may also expect: - **Incident response plan.** A documented plan for what to do during a breach. Even a simple one-page plan that covers who to call, how to contain the threat, and how to notify stakeholders satisfies most policies. - **Email security.** SPF, DKIM, and DMARC configured on your domain to prevent spoofing. Microsoft Defender for Office 365, included with Business Premium, provides additional email security through Safe Attachments, Safe Links, and anti-phishing policies. - **Full-disk encryption.** BitLocker on Windows laptops, FileVault on Macs. Both are included with the operating system and can be enforced through Intune. - **Network segmentation.** Guest Wi-Fi separated from your business network. Critical systems isolated from general user traffic. - **Vulnerability scanning.** Regular scanning of internet-facing systems for known vulnerabilities. Your MSP should be doing this as part of their management service. ## How to prepare for your cyber insurance application or renewal Do not wait until the application lands on your desk. Prepare in advance so you can answer every question honestly and completely. 1. **Get a copy of the insurer's security questionnaire** before renewal. Your broker can usually provide this in advance. 2. **Audit your current security posture** against each requirement. Be honest. Misrepresentation can void your coverage entirely. 3. **Fix gaps before submitting the application.** If MFA is not enabled everywhere, enable it now. If backups are not tested, test them. Fixing the gaps before you apply is always better than hoping the insurer does not ask. 4. **Document everything.** Policies, training records, backup test results, patch reports, access reviews. Create a simple folder (physical or digital) where all compliance evidence lives. 5. **Work with your MSP or IT provider** to compile evidence of compliance. An [Athencia One](/athencia-one) managed IT plan includes the security controls that most cyber insurance policies require, and we can help you document them for your insurer. Athencia also provides CIS Controls baseline assessments that map your current security posture against the CIS Controls framework, giving you a clear picture of where you stand and what needs to improve. ## Need help? Cyber insurance requirements can feel overwhelming, but most of them boil down to the same security fundamentals: MFA, endpoint protection, backups, patching, and training. If you need help meeting your policy requirements or preparing for a renewal, [contact Athencia](/contact). We work with small businesses to close security gaps and document compliance so your coverage holds up when you need it. ### General IT #### How to Build an IT Budget for a Small Business > Practical guide to creating an IT budget for a small business, covering hardware, software, security, support, and common budgeting mistakes. URL: https://athencia.com/kb/general-it/how-to-build-an-it-budget-for-a-small-business An IT budget prevents the cycle of emergency spending and deferred maintenance that plagues most small businesses. Without one, you spend money when something breaks rather than when it makes strategic sense. Planning ahead for hardware replacements, software renewals, security tools, and support costs means fewer surprises and better decisions about where your IT dollars go. This guide walks through each spending category, gives you real numbers to work with, and shows you how to put it all together. ## Why small businesses need an IT budget Most small business owners treat IT spending as a series of one-off expenses. A laptop dies, so you buy a new one. A software renewal comes in, so you pay it. A security incident happens, so you scramble to add protections after the fact. This reactive approach almost always costs more than planning ahead. An IT budget forces you to take stock of what you have, what you're spending, and what's coming due in the next 12 months. It turns unpredictable expenses into a manageable monthly or annual plan. It also gives you the data you need to evaluate whether your current IT spending is reasonable. If you're paying $200 per user per month for managed IT but not getting security monitoring or strategic guidance, your budget will make that gap obvious. Budgets also matter when you apply for cyber insurance. Underwriters want to see that you're investing in security, not just hoping for the best. A documented IT budget that includes line items for endpoint protection, backup, and security training shows that you take risk seriously. ## Industry benchmarks: How much should you spend A common guideline is 3 to 7 percent of revenue for total IT costs. Businesses with simple IT needs, such as email and basic cloud apps with no compliance requirements, tend to fall at the lower end around 3 to 4 percent. Businesses with compliance obligations, heavy cloud usage, or complex technology environments typically land in the 5 to 7 percent range. Another way to benchmark is per employee. Total IT costs (hardware, software, support, and security combined) typically run $3,000 to $7,000 per employee per year. A 20-person company should expect to spend somewhere between $60,000 and $140,000 annually on IT, depending on the complexity of its environment and the level of security required. These are benchmarks, not rules. Your actual budget depends on your specific needs, your industry, and your risk tolerance. A law firm handling sensitive client data needs to spend more on security than a landscaping company with five employees. ## Category 1: Hardware Hardware is the most visible IT expense and the one most likely to catch you off guard if you don't plan for it. **Computers.** Plan for laptop replacement every 4 years and desktop replacement every 5 years. Budget $800 to $1,200 per laptop and $600 to $1,000 per desktop. A 20-person office with 4-year laptop cycles replaces about 5 machines per year, which means setting aside $4,000 to $6,000 annually just for computer replacements. **Networking equipment.** Routers, switches, and wireless access points typically last 5 to 7 years. Budget $500 to $2,000 depending on office size. If your wireless network struggles with video calls or drops connections, this line item deserves attention sooner rather than later. **Peripherals.** Monitors, keyboards, mice, headsets, and docking stations wear out or need replacing when new employees join. Budget $200 to $500 per employee per year for replacements and new hires. **Printers.** Replace every 5 to 7 years. Budget for the printer itself plus ongoing toner and ink costs, which can add up to several hundred dollars per year for a busy office printer. **Spare equipment.** Keep one or two configured spare laptops ready for emergency swaps. If someone's laptop fails on a Monday morning, having a spare means they're back to work in minutes instead of days. Budget for these separately from your replacement cycle. ## Category 2: Software and licensing Software costs are recurring, which makes them easier to budget for once you know what you're paying. **Microsoft 365.** Athencia deploys Microsoft 365 Business Premium for its managed IT clients, which runs $22 per user per month. This license tier includes everything most small businesses need: Outlook, Teams, Word, Excel, plus Intune for device management, Defender for Business for endpoint security, and Entra ID with Conditional Access for identity protection. If you're currently on a lower-tier plan like Business Basic ($6 per user per month) or Business Standard ($12.50 per user per month), you may be paying separately for security tools that Business Premium already includes. **Line-of-business applications.** CRM, accounting, practice management, and project management tools vary widely. List every tool your team uses, what it costs per user or per month, and when the renewal date is. Tracking renewal dates in one place prevents surprise charges and gives you a chance to evaluate whether you still need each tool. **Security software.** Endpoint protection, email security, and a password manager typically add $5 to $15 per user per month on top of your Microsoft 365 license. Tools like Huntress Managed EDR (which layers 24/7 human threat hunting on top of Microsoft Defender) and 1Password for credential management are common additions for businesses that take security seriously. **Backup services.** Microsoft 365 does not fully back up your email, OneDrive, or SharePoint data. A dedicated backup solution like Dropsuite runs $2 to $5 per user per month and protects you against accidental deletion, ransomware, and data loss. **Domain and website.** Hosting, domain renewal, and SSL certificates typically run $500 to $2,000 per year. ## Category 3: Managed IT services and support This is where your budget either becomes predictable or stays chaotic. **Managed services (MSP).** A managed IT provider charges a fixed monthly fee per user that covers monitoring, patching, security management, help desk support, and strategic guidance. For context, [Athencia One](/athencia-one) runs $45 to $55 per user per month for IT visibility and baseline security, while [Athencia One Complete](/athencia-one-complete) runs $159 to $199 per user per month for fully managed IT including advanced security, a password manager, and Microsoft 365 licensing. Most MSPs in the market charge between $100 and $250 per user per month for fully managed services. **Break-fix support (if you don't use an MSP).** On-demand IT support typically runs $150 to $250 per hour, and the total is unpredictable. You pay more when things go wrong, which is exactly when you can least afford it. A single server outage that takes 8 hours to resolve can cost $1,200 to $2,000 in labor alone, not counting the productivity your team lost. **Project work.** Migrations, new office setup, and major infrastructure upgrades are one-time costs that should be budgeted separately from your recurring monthly spend. Get scoping estimates for any projects you anticipate in the next 12 months. ## Category 4: Security and compliance Security is not optional, and it has real, recurring costs. **Cyber insurance.** Premiums range from $1,000 to $5,000 or more per year, depending on your coverage limits and industry. Many insurers now require specific security controls (MFA, endpoint protection, backup, security training) as conditions of coverage. Your IT budget should reflect the cost of meeting those requirements. **Security awareness training.** Training your employees to recognize phishing and social engineering attacks costs $2 to $5 per user per month. Some providers, like Huntress, bundle security awareness training with their endpoint detection and response platform. **Compliance audits or assessments.** If your industry requires compliance with HIPAA, PCI, or similar frameworks, budget $2,000 to $10,000 per year for formal assessments. Even if you're not in a regulated industry, a baseline security assessment against the CIS Controls framework identifies your biggest gaps and helps you prioritize spending. **Penetration testing or vulnerability scanning.** Formal penetration testing for a small business typically costs $2,000 to $5,000 annually. This is often a cyber insurance requirement. ## Category 5: Internet and communications **Business internet.** Budget $100 to $300 per month depending on speed and provider. If your team relies heavily on video conferencing and cloud applications, investing in faster, more reliable internet pays for itself in productivity. **Phone system (VoIP).** A cloud phone system runs $20 to $40 per user per month. If you're on Microsoft 365, Teams Phone can replace a standalone phone system, consolidating one more cost into a platform you already pay for. **Backup internet connection.** If your business can't function without internet, a secondary connection from a different provider ($50 to $150 per month) provides failover when your primary connection goes down. ## Building the budget: Practical steps Start by taking a complete inventory of your current IT spending. Pull credit card statements, invoices, and subscription records for the past 12 months. Sort everything into the categories above. Most business owners are surprised by how much they're actually spending once it's all in one place. Next, list known upcoming costs for the next 12 months. Which computers are due for replacement? Which software renewals are coming up? Are there any planned projects like an office move or a system migration? Add up your recurring monthly costs: MSP fees, software licenses, internet, phone, and security tools. Multiply by 12 to get your annual recurring baseline. Finally, add a contingency fund. Set aside 10 to 15 percent of your total IT budget for unexpected needs. A failed switch, a sudden new hire, or a security incident that requires an unplanned investment will happen. The contingency fund keeps these events from blowing up your budget. Review the budget quarterly, not just annually. Technology needs change, prices shift, and new tools come on the market. A quarterly review keeps your budget aligned with reality and gives you a chance to reallocate funds before they're spent. ## Common budgeting mistakes **Not budgeting for hardware replacement.** Computers don't last forever. If your budget doesn't account for a regular replacement cycle, you'll end up scrambling when machines start failing. **Ignoring security costs until forced.** Many business owners don't think about security spending until a cyber insurance application or a compliance audit forces the conversation. By then, you're behind and spending reactively. **Not accounting for growth.** Every new hire needs a computer, a Microsoft 365 license, access to your business applications, and onboarding time from your IT provider. If you're planning to hire 5 people this year, your IT budget needs to reflect that. **Cutting IT to save money short-term.** Deferring hardware replacements, dropping security tools, or canceling your MSP to save money creates a debt that comes due with interest. Downtime, data loss, and security incidents are far more expensive than the monthly costs they prevent. **Not separating recurring costs from one-time projects.** Your monthly IT spend and your project spend are different animals. Mixing them together makes it impossible to track whether your baseline costs are growing and whether your project investments are delivering value. ## Need help? Building an IT budget from scratch takes time, but it pays for itself in predictability and smarter spending. If you want help assessing your current IT costs or building a budget that fits your business, [reach out to Athencia](/contact). We'll walk through it with you. #### How to Choose a Managed IT Provider for Your Small Business > Practical guide for small business owners evaluating managed IT providers (MSPs), covering what to look for, questions to ask, and red flags to avoid. URL: https://athencia.com/kb/general-it/how-to-choose-a-managed-it-provider-for-your-small-business Choosing the right managed IT provider (MSP) is one of the most important infrastructure decisions a small business makes. A good MSP keeps your systems running, your data secure, and your team productive. A bad one creates more problems than it solves. This guide covers when you actually need an MSP, what a good one should provide, the right questions to ask during evaluation, and the red flags that should send you looking elsewhere. ## When does a small business need an MSP Not every business needs managed IT services, but most reach a point where going without one becomes a liability. Here are the common signals. You have 5 or more employees using computers and email daily, and IT issues are eating into time you should be spending on revenue-generating work. You don't have a full-time IT person on staff, and you don't need one yet, but you need consistent, reliable support when something breaks or a new employee starts. You have compliance requirements. If your industry requires HIPAA, PCI, or cyber insurance compliance, you need documented security controls, regular assessments, and someone who can prove your IT environment meets the standard. A friend who "knows computers" cannot provide that. You've experienced a security incident or data loss and want to make sure it doesn't happen again. Or your current IT support, whether it's a part-time contractor, a nephew, or the office manager who happens to be tech-savvy, can't keep up with the growing demands of your business. If any of these sound familiar, it's time to evaluate MSPs seriously. ## What a good MSP should provide When you're evaluating providers, look for these core capabilities. Any MSP worth considering should include all of these in their base offering. **Proactive monitoring.** Your MSP should monitor all of your computers, servers, and network equipment 24/7 for problems before they cause downtime. This means automated alerts when a hard drive starts failing, when a computer stops checking in, or when a security policy isn't applied correctly. You should not be the one discovering problems. **Patch management.** Operating system and application updates need to happen regularly and reliably. A good MSP automates this process so your machines stay current with security patches without disrupting your workday. Ask how they handle patch deployment and what happens when a patch causes an issue. **Endpoint protection.** Every device in your environment needs managed antivirus and endpoint detection and response (EDR). The best MSPs layer additional protection on top of the baseline. For example, Huntress Managed EDR adds 24/7 human threat hunters and a security operations center on top of Microsoft Defender for Business, catching threats that automated tools miss. **Backup management.** Your MSP should configure, monitor, and regularly test your backups. This includes cloud data. Microsoft 365 has limited built-in retention, so a separate backup solution like Dropsuite for your email, OneDrive, and SharePoint data is important. If your business has on-premises servers or data, local backup with a tool like Slide should also be part of the conversation. **Help desk.** A responsive support team for day-to-day IT issues. Ask about average response times and get specific numbers: 15 minutes for critical issues, 1 hour for standard requests, same-day for low-priority items. Vague promises like "we respond quickly" tell you nothing. **Security management.** This goes beyond antivirus. Your MSP should enforce multi-factor authentication across all accounts, manage email security, configure access controls using tools like Conditional Access in Microsoft Entra ID, and provide security awareness training so your employees know how to spot phishing attempts. **Strategic guidance.** Your MSP should function as a technology advisor, not just a help desk. This means regular Technology Business Reviews where they assess your environment, identify risks, and recommend improvements prioritized by business impact. This strategic layer is often called a vCIO (virtual Chief Information Officer) function. **Vendor management.** A good MSP coordinates with your internet provider, phone system vendor, and software vendors on your behalf. When your internet goes down, you shouldn't be the one on hold with the ISP. ## Questions to ask during evaluation These questions separate serious providers from those who are just selling a contract. **How many clients do you support, and what's the typical company size?** You want an MSP experienced with businesses your size. An MSP that primarily manages 500-person enterprises may not be attentive to a 15-person company. **What is your average response time for support requests?** Get specific numbers. If they can't answer this, they aren't tracking it, which is a problem. **What does your onboarding process look like?** A good MSP audits your entire environment before taking over: network, devices, security posture, software, and licenses. They document everything and build a remediation plan before they start managing. An MSP that just installs their tools and calls it done is setting you up for surprises. **What security tools and practices are included in your base offering?** You want to hear specifics: endpoint protection, MFA enforcement, email security, backup, security awareness training, and access controls. If security is an "add-on," that tells you it's not a priority. **How do you handle after-hours and emergency support?** Know what happens when something critical breaks at 7 PM on a Friday. Is there an after-hours team, or does it wait until Monday? **What does your reporting look like?** You should receive regular reports on your IT health, including device status, security posture, open issues, and completed work. A dashboard like the [Athencia One Portal](/athencia-one) gives you real-time visibility into your environment rather than waiting for a monthly PDF. **Can you provide references from clients in my industry or of a similar size?** References are table stakes. If they can't provide them, that's a concern. **What happens if we want to leave?** Understand data portability, transition support, and contract terms before you sign. You should always own your Microsoft 365 tenant, your domain, and your admin credentials. The MSP should have delegated access, not ownership. **What is NOT included in your monthly fee?** This is where hidden costs live. Project work, after-hours support, hardware procurement, software licensing, and onboarding fees can add up quickly if they're not included. ## Pricing: What to expect Most MSPs charge per user per month. Some charge per device, but per-user pricing is more common and generally simpler to budget for. The typical range for fully managed IT services for a small business is $100 to $250 per user per month. What's included at each price point varies significantly. Look for providers who publish their pricing. Athencia, for example, charges $45 to $55 per user per month for Athencia One (IT visibility, monitoring, and baseline security) and $159 to $199 per user per month for [Athencia One Complete](/athencia-one-complete) (fully managed IT with advanced security, 1Password, and Microsoft 365 Business Premium licensing included). Transparent pricing lets you budget accurately and compare providers on equal terms. Watch out for hidden costs. Some providers quote a low per-user fee but charge extra for everything: project work, after-hours support, hardware markup, even software licensing that should be included. The cheapest option is rarely the best. You get what you pay for in managed IT, and the cost of a security incident or extended downtime dwarfs the monthly savings from choosing a bargain provider. ## Red flags to watch for **No onboarding process.** An MSP that doesn't audit your environment before starting can't protect what they don't understand. If they skip the assessment, they're guessing. **Reactive only, not proactive.** If they only fix things when they break, you're paying for a help desk, not managed services. Proactive monitoring, patching, and security management are what separate an MSP from a break-fix shop. **No documentation.** A good MSP documents your network, accounts, licenses, and configurations. If they don't, you're locked in. When you try to leave, you won't know what you have. **Long-term contracts with no exit clause.** Avoid 3 to 5 year contracts with steep early termination fees. A 1-year agreement with 30 to 60 day notice is reasonable. An MSP that needs a long contract to keep clients has a retention problem. **No security focus.** If they don't mention MFA, endpoint protection, backup, or security awareness training as part of their standard offering, they're behind. Security is not an add-on; it's foundational. **Slow response times.** If it takes hours to get a response during business hours while you're evaluating them, it won't get better after you sign. **They own your domain or admin accounts.** You should always own and control your domain registration, your Microsoft 365 tenant, and your admin credentials. The MSP should have delegated admin access. If they insist on owning your accounts, walk away. This creates a dependency that makes it extremely difficult and expensive to switch providers. ## What to expect during onboarding Once you've chosen an MSP, the onboarding process typically takes 2 to 4 weeks for a small business. Here's what a thorough onboarding looks like. First, the MSP conducts a full audit of your current IT environment: network layout, device inventory, security posture, software licensing, and user accounts. They document everything, including network diagrams, device serial numbers, account credentials stored in a secure password manager like 1Password, and a list of every tool and license you're paying for. Next, they install their monitoring and management agents on all devices. If your business uses Microsoft 365 Business Premium with Intune, device management policies, security configurations, and compliance baselines can be deployed across your entire fleet from a central console. They configure backup, security tools, and automated patching. They migrate you from your previous provider if applicable, and they introduce your team to the help desk and support process so everyone knows how to get help. Finally, they deliver a roadmap of recommended improvements prioritized by risk and impact. This is your first look at the strategic value your MSP should be providing on an ongoing basis. ## Need help? Choosing the right MSP is a big decision, and it's worth getting right the first time. If you're evaluating providers and want a straightforward conversation about what your business needs, [contact Athencia](/contact). No pressure, no pitch, just practical advice. #### How to Decide When to Replace vs. Repair an Office Computer > Practical framework for small businesses to decide whether to repair a struggling office computer or replace it, based on age, cost, and business impact. URL: https://athencia.com/kb/general-it/how-to-decide-when-to-replace-vs-repair-an-office-computer Every small business owner eventually faces the question: is it worth fixing this computer, or should we just buy a new one? The answer comes down to three factors: the age of the machine, the cost of the repair relative to a replacement, and how much the downtime and performance issues are costing your business in lost productivity. This guide gives you a clear framework for making that call so you stop guessing and start making decisions based on numbers. ## The age rule of thumb Age is the single most reliable indicator of whether a repair makes financial sense. Here's a straightforward breakdown. **0 to 3 years old.** A computer in this range is almost always worth repairing unless the damage is catastrophic, like liquid damage that shorted the motherboard or a severe drop that cracked the chassis and display at the same time. A screen replacement, a new battery, or a keyboard swap on a 2-year-old laptop is a smart investment. The machine has years of useful life left, and the repair cost is a fraction of a replacement. **3 to 4 years old.** This is the gray zone. Repair the machine if the cost is under 50 percent of what a comparable new computer would cost. A $300 repair on a 3-year-old laptop that would cost $1,000 to replace makes sense. A $600 repair on that same machine doesn't, because you're paying more than half the price of a brand-new computer and still walking away with aging hardware. **4 to 5 years old.** Strongly consider replacement, especially if the computer is already showing signs of slowing down: long boot times, laggy applications, frequent freezes. At this age, even a successful repair doesn't buy you much runway. You're likely to face another issue within 6 to 12 months. **5+ years old.** Replace it. The repair cost, the lost productivity during the repair, and the security risk of running aging hardware almost always exceed the cost of a new machine. Computers older than 5 years often can't run the latest operating system or security software, which creates real vulnerability in your environment. ## The cost comparison Before deciding, get an actual repair estimate. Don't guess. Then compare the repair cost to the price of a comparable new computer, not the original purchase price you paid years ago. A decent business laptop costs $800 to $1,200 today. A business desktop runs $600 to $1,000. These are the numbers you're comparing against. If the repair is more than 50 percent of the replacement cost on a machine over 3 years old, replace it. If the repair is under 50 percent on a machine under 3 years old, repair it. Don't forget to factor in the labor cost of the repair (your IT provider's time to diagnose, order parts, and complete the work) and the employee's downtime during the process. If a repair takes 3 days and the employee is working from a loaner or not working at all, that lost productivity has a real dollar value. A planned replacement with a pre-configured machine can have the employee back to full speed in under an hour. ## Hidden costs of keeping old computers The sticker price of a repair isn't the full picture. Old computers carry hidden costs that add up quietly. **Productivity loss.** A slow computer costs you employee time every single day. Even 15 minutes of daily waiting, for applications to load, for files to save, for the machine to wake from sleep, adds up to over 60 hours per year per employee. At a $30/hour fully loaded employee cost, that's $1,800 per year in wasted time from a single slow machine. **Security risk.** Computers that can't run the latest operating system or security software are vulnerable to attacks that modern systems handle automatically. Windows 10 reached end of support in October 2025, meaning machines stuck on it no longer receive security patches from Microsoft. If your endpoint protection requires a current OS to function properly, an outdated machine becomes a gap in your security perimeter. **Compatibility issues.** Older hardware may not support new software versions, current video conferencing requirements (Teams and Zoom are resource-hungry), or newer peripherals like USB-C docking stations. Your team ends up working around limitations instead of working productively. **Increasing failure rate.** Hardware failure rates climb significantly after year 4. The cost of an unplanned failure, including emergency replacement, potential data recovery, and extended employee downtime, is much higher than a planned replacement where the new machine is configured and ready before the old one is retired. **Support costs.** Older machines generate more help desk tickets. More crashes, more driver issues, more "it's running slow" calls. Each ticket costs your IT provider time and costs your employee productivity. ## Signs it's time to replace (regardless of age) Sometimes a computer tells you it's done before the calendar does. Replace the machine if any of the following are true. The computer takes more than 2 minutes to boot and be ready to work. Applications freeze or crash regularly during normal use. The computer can't run required software updates or the current operating system. The hard drive is failing, evidenced by clicking sounds, frequent errors, or painfully slow file access, and the machine still runs a spinning hard drive instead of an SSD. The laptop battery holds less than 2 hours of charge, and a battery replacement costs more than a third of the machine's current value. The computer can't handle current video conferencing requirements. If Teams or Zoom calls consistently cause the machine to lag, overheat, or drop audio, the hardware is not meeting the basic demands of modern work. The machine has needed multiple repairs in the past 12 months, which signals that failures are cascading and more are coming. ## When repair makes sense Repair is the right call in several specific situations. The computer is under 3 years old and the repair is straightforward. Screen replacements, battery swaps, and keyboard replacements on newer machines are cost-effective and give you years of additional use. Upgrading to an SSD can extend the useful life of a 2 to 4 year old machine significantly. If the computer has a traditional spinning hard drive, swapping it for an SSD is often the single best upgrade you can make. Boot times drop from minutes to seconds, applications open faster, and the machine feels new again, all for $100 to $200 in parts plus labor. Adding RAM is cheap and effective if the machine is currently under-provisioned. If a computer shipped with 8 GB of RAM and regularly hits 90 percent memory usage, adding another 8 GB can resolve slowness for under $100. The repair is covered under warranty or an extended service plan. If you're not paying for the repair, there's no reason not to take advantage of it. ## Planning for computer replacements The best way to avoid the repair-or-replace dilemma is to plan for replacements before they become urgent. Set a standard lifecycle: 4 years for laptops, 5 years for desktops. Track the purchase date and warranty expiration for every machine in your environment. A 20-person office with 4-year laptop cycles replaces about 5 machines per year, which is a predictable, budgetable expense. Stagger your replacements so you're not buying all new hardware in the same year. If you bought 20 laptops at once when you started the business, you'll face a painful $16,000 to $24,000 replacement bill in year 4 unless you start rotating a few machines each year before then. Keep one or two spare machines configured and ready for emergency swaps. If your business uses Microsoft 365 Business Premium with Intune and Autopilot, provisioning a spare is straightforward. Register the laptop's hardware ID with your Microsoft tenant, and when an employee powers it on and signs in with their credentials, all company policies, apps, and security settings deploy automatically. There's no need for an IT technician to manually configure each machine. This is how [Athencia provisions devices](/athencia-one) for its managed IT clients. ## What to do with old computers Once you've replaced a machine, don't just toss it in a closet or, worse, the trash. Wipe the hard drive securely before disposing of or donating the computer. A factory reset is not enough; it leaves recoverable data on the drive. Use DBAN or a similar tool for traditional hard drives, and use the manufacturer's secure erase utility for SSDs. If the machine was managed through Intune, you can initiate a remote wipe from the admin console before decommissioning it. Remove any asset tags and update your inventory records. Donate the machine to a local nonprofit if it still has useful life, or recycle it through a certified e-waste recycler. Never throw computers in the regular trash. It's both an environmental hazard and a data security risk. ## Need help? If you're trying to figure out whether to repair or replace a machine and want a professional opinion, [get in touch with Athencia](/contact). We'll assess the situation and give you a straight answer. #### How to Write an Acceptable Use Policy for Your Small Business > Template and guide for creating a simple, effective IT acceptable use policy that protects your business and sets clear expectations for employees. URL: https://athencia.com/kb/general-it/how-to-write-an-acceptable-use-policy-for-your-small-business An acceptable use policy (AUP) defines how employees can and cannot use company technology, including computers, email, internet access, and software. It sounds like a formality, but having a written policy protects your business legally, supports your cyber insurance, and sets clear expectations so employees know the rules before they break them. This guide walks you through what to include, how to write it in plain language, and how to make sure it actually gets followed. ## Why you need one The most common reason small businesses finally write an AUP is because a cyber insurance application asks for one. Underwriters want to see that you have documented IT policies. Not having one can mean higher premiums or, worse, a denied claim after an incident because you couldn't demonstrate that employees were trained on acceptable use. Beyond insurance, a written policy gives you a basis for addressing misuse of company technology. Without one, it's difficult to take action when someone installs unauthorized software, stores client data on a personal Dropbox account, or clicks a phishing link they should have recognized. You can't enforce rules that don't exist in writing. Compliance frameworks like HIPAA, PCI, and the CIS Controls all require documented acceptable use policies. Even if your industry isn't formally regulated, following these frameworks strengthens your security posture and demonstrates due diligence. A clear policy also prevents misunderstandings. When everyone knows the expectations, there are fewer awkward conversations and fewer gray areas. New hires read it during onboarding, sign an acknowledgment, and start day one with a clear understanding of what's expected. ## What to include ### Scope Start by defining who the policy applies to and what it covers. The policy should apply to all employees, contractors, interns, and anyone else who uses company technology. It should cover company-owned computers, phones, email accounts, internet access, software, cloud accounts, and network resources. If your business allows employees to use personal devices for work (a BYOD arrangement), the policy should explicitly address that. State what rules apply to personal devices when they're used to access company email, files, or applications. For example, personal devices used for work should have a screen lock enabled, be running a current operating system, and not store company data locally. ### Acceptable use State clearly that company technology is provided for business purposes. Reasonable personal use is fine, such as checking personal email during a break or browsing the web at lunch, as long as it does not interfere with work, violate any other part of the policy, or create security risks. Employees are responsible for the security of their accounts and devices. That means locking their computer when they step away (Windows key + L is the fastest way), not leaving their laptop unattended in a coffee shop, and reporting anything suspicious to IT immediately. Software should only be installed with IT approval. This prevents malware infections from sketchy downloads and avoids software licensing violations that could expose your business to legal liability. If your business manages devices through Microsoft Intune, you can enforce this technically by restricting which applications users can install, but the policy should state the rule in writing regardless. ### Prohibited use Be specific about what's not allowed. Employees should not use company systems for illegal activity, access or distribute inappropriate or discriminatory content, install unauthorized software or browser extensions, or share passwords with anyone, including coworkers. Connecting unauthorized personal devices to the business network is prohibited. This includes personal laptops, USB drives, and IoT devices. Each unauthorized device is a potential entry point for malware or data exfiltration. Storing company data on personal cloud accounts (personal Google Drive, Dropbox, iCloud) is not allowed. Company data belongs on company-approved systems like OneDrive, SharePoint, or your line-of-business applications. This isn't about being controlling; it's about knowing where your data lives so you can protect it and recover it if something goes wrong. Employees should not circumvent security controls. That means no disabling antivirus, no using unauthorized VPN services, and no attempting to bypass Conditional Access policies or web filtering. These controls exist to protect the entire organization, and one person bypassing them creates risk for everyone. Using company email for personal business ventures or side projects is prohibited. ### Email and communication Business email is for business communication. State this plainly and then address the practical details. Employees should not open suspicious attachments or click links in emails they weren't expecting. Security awareness training, which tools like Huntress include alongside their managed EDR platform, teaches employees to recognize phishing attempts, but the policy should still state the expectation clearly. Confidential information should not be sent via personal email accounts. If a client sends sensitive information, it stays in the company email system. Company email may be monitored for security purposes. State this directly so there are no surprises. Email signatures should follow the company standard template. ### Internet use Internet access is provided for business purposes, and reasonable personal use is acceptable. Keep this section practical rather than heavy-handed. Employees should not access illegal, inappropriate, or high-risk websites on company devices. They should not download files from untrusted sources. Streaming services like Netflix or Spotify are fine during breaks, but they should not be used in a way that degrades network performance for others, particularly during business hours when video calls and cloud applications need bandwidth. ### Data and confidentiality Company data must be stored on company-approved systems. For most businesses using Microsoft 365, that means OneDrive for personal work files and SharePoint for shared team files. Be specific about where data should and should not live. Employees should not transfer company data to personal devices or accounts. Confidential client information must be handled according to applicable regulations. If your business handles protected health information, financial data, or legal records, reference the specific requirements here or point to a separate data handling policy. Require employees to report any suspected data breach or loss immediately. The faster you know about a potential incident, the faster you can contain it. ### Security responsibilities This section covers the day-to-day security habits you expect from every employee. Lock your computer when stepping away from your desk. Use the company password manager, such as 1Password, for all business accounts. Never reuse passwords across accounts, and never store passwords in a browser, a spreadsheet, or a sticky note. 1Password generates strong, unique passwords for every account and stores them securely, so employees don't need to memorize anything. Enable multi-factor authentication on all accounts that support it. Report suspicious emails, messages, or activity to IT immediately. Do not share credentials with anyone for any reason, including coworkers and managers. Complete security awareness training as assigned. ### Consequences of policy violation State clearly that violations may result in disciplinary action, up to and including termination. Severe violations, such as data theft or illegal activity, may result in legal action. The company reserves the right to monitor and audit the use of company technology. Keep this section straightforward and factual. The goal is not to threaten employees but to make clear that the policy has teeth and that compliance is not optional. ## Keeping the policy effective A 20-page policy that nobody reads is worse than useless. It creates a false sense of security while providing no actual protection. Keep your AUP to 2 to 4 pages maximum. Write in plain language, not legalese. If an employee needs a lawyer to understand the policy, it's too complicated. Use short sentences, clear prohibitions, and concrete examples. Have every employee sign an acknowledgment during onboarding. Store the signed acknowledgments in your HR files. This is the proof that the employee read and understood the policy, and it's the documentation your cyber insurer will want to see if you ever file a claim. Review and update the policy annually, or whenever major changes occur. New remote work arrangements, new compliance requirements, a shift from in-office to hybrid work, these all warrant a policy update. When you update it, have employees re-sign the acknowledgment. Make the policy accessible. Store it somewhere employees can find it without asking, such as a SharePoint site or the company handbook. If people can't find the policy, they can't follow it. ## Need help? Writing an acceptable use policy doesn't have to be complicated, but it does need to be done right. If you want help drafting or reviewing your AUP, [contact Athencia](/contact). We help small businesses put practical IT policies in place. #### IT Offboarding Checklist: How to Securely Remove Access When Someone Leaves > Step-by-step IT offboarding checklist for small businesses to revoke access, preserve data, and recover devices when an employee departs. URL: https://athencia.com/kb/general-it/it-offboarding-checklist-how-to-securely-remove-access-when-someone-leaves When an employee leaves your business, whether they resign or are terminated, every account they had access to becomes a security risk until it's locked down. IT offboarding is the process of revoking all access, preserving important data, and recovering company devices. Doing this quickly and completely prevents ex-employees from accessing company systems and ensures no business data walks out the door. This guide gives you a step-by-step process to follow every time someone departs. ## Timing is critical The single most important factor in offboarding is speed. Every hour a departed employee has active credentials is an hour your business is exposed. For voluntary departures (resignations), complete most steps on the employee's last day. You typically have advance notice, so use it. Coordinate with HR to confirm the departure date and plan the IT steps ahead of time. Have everything ready so that when the employee walks out, their access is revoked within minutes. For involuntary departures (terminations), complete access revocation immediately, ideally before or during the termination meeting. This is not optional. A terminated employee who still has active credentials and remote access to your systems is a significant risk. If your business uses Microsoft 365 Business Premium with Entra ID, you can block sign-in and revoke all active sessions from the admin console in under two minutes. Have IT standing by during any termination meeting so access can be cut the moment the conversation ends. Coordination between HR and IT is essential. IT should never learn about a departure after the fact. Build a process where HR notifies IT as soon as a departure is confirmed, with the expected last day and whether it's voluntary or involuntary. ## Immediate actions (day of departure) ### Revoke sign-in access Start with the employee's Microsoft 365 account, which is usually the gateway to email, files, Teams, and most cloud applications. Reset the employee's Microsoft 365 password to a long, random value. Then block sign-in on the account in the Microsoft 365 admin center (Admin > Users > Active users > Select user > Block sign-in). This prevents the former employee from authenticating even if they know the old password. Revoke all active sessions. This is a step many businesses miss. Blocking sign-in prevents new logins, but it doesn't terminate sessions that are already active on the employee's phone, home computer, or tablet. In Entra ID, navigate to the user's account and select "Revoke sessions" to force sign-out on every device immediately. Disable or reset credentials for VPN access, remote desktop, and any other systems that have their own authentication separate from Microsoft 365. ### Disable accounts in business applications Go through every application the employee used and disable or deactivate their account. This includes your CRM, accounting software, project management tools, practice management system, and any other line-of-business application. Revoke access to third-party cloud services: Slack, Zoom, Dropbox, Canva, and anything else the employee signed up for or was given access to. Check your records or ask the employee's manager for a complete list. Remove the employee from all shared vaults in your password manager. If your business uses 1Password, go to the admin console and remove the user from every vault they had access to. This is critically important. Shared vaults often contain credentials for systems, vendor portals, and social media accounts that the former employee should no longer be able to reach. If any passwords in those shared vaults were known to the departing employee, rotate them. Check for OAuth app consents in Entra ID and revoke them. Employees sometimes grant third-party apps access to their Microsoft 365 account (for example, a scheduling tool that reads their calendar). These consents persist even after the password is changed, so they need to be explicitly revoked. ## Data preservation (same day or within 48 hours) ### Email Convert the employee's mailbox to a shared mailbox in the Microsoft 365 admin center. This preserves all email without consuming a paid license. Once converted, grant access to the shared mailbox to the employee's manager or their replacement so they can review and respond to messages. If the manager needs to receive new messages sent to the former employee's address, set up email forwarding on the shared mailbox. This is common when a salesperson or account manager leaves and clients continue emailing their old address. Set an auto-reply on the mailbox informing senders that the employee is no longer with the company and providing the new point of contact. Keep this professional and brief. ### Files and documents Transfer the employee's OneDrive files to their manager or replacement. In the Microsoft 365 admin center, go to Users, select the departing user, and use the OneDrive tab to grant a delegate access. The delegate has 30 days to access and move files before OneDrive is automatically deleted, so don't wait. Before wiping the employee's computer, check for files stored locally that may not have synced to OneDrive. Desktop files, Downloads folder contents, and documents saved outside the OneDrive sync folder are easy to lose if you wipe the machine first. Transfer ownership of any shared folders, SharePoint sites, or Teams channels the employee owned. If they were the sole owner of a Teams channel, that channel becomes unmanageable until a new owner is assigned. ### Other data Transfer ownership of CRM records, deals, and client relationships. Open tickets and tasks should be reassigned to another team member. Export or transfer any data from tools the employee used that won't transfer automatically when their account is disabled. ## Group memberships and permissions Remove the employee from all Microsoft 365 groups, Teams channels, and distribution lists. Remove their permissions from SharePoint sites they had access to. If they had access to other shared mailboxes (like info@ or support@), remove that access as well. Transfer ownership of any Microsoft 365 groups or Teams the employee created or owned. If they were the only owner, assign a new owner before disabling the account. Don't forget physical access. Remove the employee from building access systems, change alarm codes they knew, and collect keys or security badges. Physical security is just as important as digital security. ## Device recovery Collect the laptop, phone, monitor, headset, docking station, and any other company hardware. Collect access cards, keys, and security tokens. Have a checklist of what was issued to the employee so you can confirm everything is returned. If the device can't be collected immediately, for example if the employee is remote and needs to ship the equipment back, initiate a remote wipe through Intune. This erases all company data and policies from the device regardless of where it is physically. For [Athencia's managed IT clients](/athencia-one), this is a standard part of the offboarding process and can be triggered within minutes. Once the device is returned or wiped, remove it from Entra ID and Intune. Reset it to factory settings so it's ready to be reissued to the next employee. Update your asset inventory to reflect the device's current status. ## Post-departure verification Trust but verify. After completing all of the steps above, test the results. Try to sign in to Microsoft 365 with the former employee's credentials. The login should fail. Verify that access to business applications is disabled by checking each one. Confirm that email forwarding or the shared mailbox is working correctly by sending a test message to the old address. Verify that OneDrive files were transferred successfully and that no critical data was lost. Check audit logs in Microsoft 365 and Entra ID for any suspicious activity in the days leading up to the departure. Look for large file downloads, forwarding rules set up on the mailbox, or data exports from business applications. This is particularly important for involuntary departures, but it's good practice for all offboarding. Remove the employee from your IT documentation, phone lists, emergency contacts, and any internal directories. ## Delete the account (after data is secured) Once you've confirmed that all data is preserved and all access is revoked, delete the Microsoft 365 user account. This frees up the license for reassignment. Microsoft retains the deleted account for 30 days, so if you realize you missed something, you can restore it during that window. After 30 days, the deletion is permanent. ## Offboarding checklist summary Use this as a quick reference each time an employee departs. - Password reset and sign-in blocked on Microsoft 365 - All active sessions revoked in Entra ID - Business application accounts disabled - Password manager access removed and shared passwords rotated - Mailbox converted to shared mailbox with forwarding set up - OneDrive files transferred to manager or replacement - Group memberships and ownership transferred - Devices collected and wiped (remotely via Intune if needed) - Physical access revoked (keys, badges, alarm codes) - Post-departure access verified as fully revoked - Audit logs reviewed for suspicious pre-departure activity - Account deleted and license reclaimed ## Need help? Offboarding done poorly creates security gaps that can haunt your business for months. If you want help building a repeatable offboarding process or need to offboard someone quickly, [contact Athencia](/contact). We'll make sure nothing gets missed. #### IT Onboarding Checklist: Everything to Prepare Before a New Employee Starts > Complete IT onboarding checklist for small businesses covering accounts, devices, access, and training to have ready before a new hire's first day. URL: https://athencia.com/kb/general-it/it-onboarding-checklist-everything-to-prepare-before-a-new-employee-starts A complete IT onboarding process ensures new employees have everything they need on day one: a working device, active accounts, proper access to the tools they'll use, and clear instructions for getting help. Scrambling to set things up after they arrive wastes their time, frustrates their manager, and makes your business look disorganized. This guide walks through every step, from two weeks before the start date through the day-one handoff, so nothing falls through the cracks. ## When to start: Timeline IT onboarding doesn't begin on the new hire's first day. It starts the moment HR confirms the hire. **1 to 2 weeks before the start date.** Order hardware if you don't have a spare available. Create the employee's Microsoft 365 account and email address. Request access to business applications. If you're working with a managed IT provider, notify them of the incoming hire with the employee's name, role, start date, and the applications they'll need. **2 to 3 days before.** Configure the device. Install software. Test everything. Verify that email works, that the employee can access the files and applications they need, and that printers and peripherals function correctly. This testing step is the difference between a smooth first day and an embarrassing one. **Day before.** Final verification. Confirm credentials are ready. Prepare any welcome materials or documentation the employee will receive. Set temporary passwords that will require a change on first login. **Day of.** Hand off the device. Walk through key systems. Introduce the IT support contact. Verify everything works in the employee's hands, not just on the IT bench. ## Hardware and devices Start with the physical equipment the employee will use every day. Order or allocate a laptop or desktop that meets the requirements for the role. Standard office work (email, documents, web browsing, video calls) requires a machine with at least 16 GB of RAM, an SSD, and a current-generation processor. Roles involving design, data analysis, or video editing may need higher specs. Confirm with the hiring manager before ordering. Order a monitor, keyboard, mouse, and headset if the employee will work from an office. For remote employees, decide whether you're providing these items or offering a stipend. Consistency matters here; every employee should have the equipment they need to do their job without making do. If the role requires a desk phone, order it and coordinate with your phone system provider to assign an extension or number. For businesses using Microsoft Teams Phone, this is configured in the Teams admin center and doesn't require separate hardware unless the employee prefers a physical handset. Asset tag every piece of equipment and record serial numbers in your inventory. This takes five minutes per device and saves hours of confusion when it's time to track down equipment during offboarding. ## Accounts and licenses Create the employee's Microsoft 365 account with the appropriate license. If your business runs Microsoft 365 Business Premium (which includes Intune, Defender for Business, and Entra ID with Conditional Access), assign that license so the employee gets the full security stack from day one. Set up their email address following your company's naming convention, typically firstname.lastname@company.com. Create accounts in every business application the employee will use: CRM, accounting software, project management tools, practice management system, and anything else relevant to their role. Don't wait until they ask; have these ready before they arrive. Set up a 1Password account for the employee and add them to the appropriate shared vaults. Shared vaults give new hires immediate access to the credentials they need, such as shared service logins and vendor portals, without anyone having to send passwords over email or chat. If your business uses [Athencia One Complete](/athencia-one-complete), 1Password is included in your per-user fee. Create VPN credentials if the employee needs remote access to on-premises resources. Set temporary passwords for all accounts that require the employee to change their password on first login. Never email passwords in plain text. Use your password manager's secure sharing feature or provide them verbally during the day-one walkthrough. ## Access and permissions Add the employee to the correct Microsoft 365 groups and distribution lists based on their role. Grant access to relevant SharePoint sites and shared drives. Add them to the Teams channels they'll participate in. Set up shared mailbox access if they need it (for example, if they'll be monitoring info@ or support@). Grant access to printers and networked devices. Add them to the company directory and phone system. Apply the principle of least privilege: grant only the access needed for the employee's role, nothing more. It's much easier to add permissions later when a need arises than to audit and remove excessive access after the fact. If your business uses Entra ID with Conditional Access policies, new employees automatically inherit the access controls that apply to their group memberships, including MFA requirements, device compliance checks, and location-based restrictions. ## Device configuration This is the most time-consuming step, and it's also the one that benefits most from automation. If your business uses Microsoft 365 Business Premium with Intune and Autopilot, most of this setup happens automatically. Register the new laptop's hardware ID with your Microsoft tenant, and when the employee powers it on and signs in with their new Microsoft 365 credentials, all company policies, apps (including 1Password and Microsoft Teams), and security settings deploy without anyone touching the machine. The employee gets a fully configured, secured laptop by simply signing in. This is how Athencia provisions devices for its managed IT clients. If you're configuring manually, here's the full checklist. Complete Windows setup and join the device to Entra ID (or your identity system). Install all pending Windows updates. Enable BitLocker drive encryption to protect data if the laptop is lost or stolen. Install endpoint protection; if you're using Microsoft 365 Business Premium, Defender for Business is included and should be configured via Intune policies. Install Microsoft 365 apps: Outlook, Teams, Word, Excel, PowerPoint, and OneNote. Install any business applications specific to the employee's role. Install and configure 1Password or your password manager. Install the VPN client if needed. Connect printers. Configure OneDrive sync so the employee's files are automatically backed up to the cloud. Set security policies including screen lock timeout (5 minutes is a reasonable default) and automatic update settings. ## Email and communication Configure Outlook with the employee's mailbox and verify that sending and receiving works. Set up their email signature following the company template. Add them to relevant distribution lists so they receive team and company-wide communications. Set up Microsoft Teams and verify that audio and video work correctly. A quick test call catches hardware or driver issues before the employee's first meeting with a client. Add the employee to the company phone system. If you use Teams Phone, assign a phone number in the Teams admin center. Share the IT support contact information and explain how to submit help requests, whether that's an email address, a support portal, or a phone number. ## Security Security setup is not optional and should not be deferred to "sometime during the first week." Enable multi-factor authentication on the employee's Microsoft 365 account before they sign in for the first time. Walk them through the MFA setup process during the day-one handoff, which involves installing the Microsoft Authenticator app on their phone and registering it with their account. This takes about three minutes and is the single most effective thing you can do to prevent account compromise. Provide the initial password securely. Do not email it, do not write it on a sticky note, and do not put it in a Teams message. Use 1Password's secure sharing feature or provide it verbally during the in-person handoff. Schedule security awareness training. Whether you use an internal program or a platform like Huntress (which bundles security awareness training with its managed EDR), new employees should complete their first training module within their first two weeks. Phishing attacks target new hires because they're less familiar with company communication patterns. Review the company password policy and acceptable use policy with the employee. Have them sign an acknowledgment that they've read and understood both documents. ## Documentation to provide Give the new employee a simple reference document (one page is plenty) that covers the essentials. Include IT support contact information: who to call, how to submit a ticket, and the process for emergency support. Provide a quick start guide covering how to access email, files, Teams, VPN, and printers. Include password policy instructions and a brief guide to using 1Password. Attach or link to the acceptable use policy. Provide Wi-Fi credentials for the business and guest networks. Store this documentation somewhere the employee can find it later, like a SharePoint page or an internal wiki. First-day information overload is real; they'll need to reference it again. ## Day-one walkthrough The final step is a hands-on walkthrough with the employee. Hand over the device and verify they can sign in. Walk through email, Teams, and file access. Verify printer access works. Show them where to find IT help and how to contact support. Verify that MFA is set up and working on their phone. Walk through the password manager and make sure they can access the shared vaults assigned to them. Answer their questions and confirm everything works. This walkthrough typically takes 20 to 30 minutes and prevents a flood of "how do I..." tickets in the first week. ## Onboarding checklist summary Use this as a quick reference for every new hire. - Hardware ordered, configured, and tested - Microsoft 365 account created with correct license (Business Premium) - Business application accounts created - 1Password account set up with appropriate shared vault access - Appropriate group memberships and permissions assigned - Device fully configured with security settings, software, and policies - Email, Teams, and phone configured and tested - MFA enabled and verified - Security awareness training scheduled - IT documentation and policies provided - Day-one walkthrough completed ## Need help? Getting onboarding right sets the tone for a new employee's experience and protects your business from day one. If you need help building a repeatable onboarding process or want to streamline device provisioning with Autopilot, [contact Athencia](/contact). We do this every day. #### What Is a Technology Business Review and Why Your Small Business Needs One > Explains what a Technology Business Review (TBR) is, what it covers, and how it helps small businesses align IT investments with business goals. URL: https://athencia.com/kb/general-it/what-is-a-technology-business-review-and-why-your-small-business-needs-one A Technology Business Review (TBR) is a structured meeting between your business leadership and your IT provider to evaluate the health of your technology environment, identify risks, and plan investments that align with your business goals. It's the IT equivalent of an annual physical: it catches problems before they become emergencies and gives you a clear picture of where you stand. Having one at least annually prevents your IT from falling behind while you're focused on running the business. ## What a TBR covers A good TBR is not a vague conversation about "how things are going." It's a data-driven review with specific deliverables. Here's what each section should include. **Current state assessment.** This is a clear, honest picture of your IT environment today. It covers your hardware inventory (how many computers, their age, their condition), your software licenses (what you're paying for, what's in use, what's expiring), your security posture (MFA adoption, endpoint protection coverage, backup status), and your network health (internet speed, wireless performance, equipment age). If your IT provider uses a real-time dashboard like the [Athencia One Portal](/athencia-one), much of this data is already collected and can be presented without a manual audit. If they have to scramble to pull this information together before the meeting, that tells you something about their monitoring practices. **Risk identification.** Every IT environment has risks. The question is whether you know what they are. A TBR should identify aging hardware approaching end of life, software nearing end of support (such as applications that won't run on the latest operating system), security gaps (employees without MFA, devices without endpoint protection), compliance issues relevant to your industry, and single points of failure (one server with no redundancy, one person who knows all the passwords). Each risk should be rated by severity and likelihood so you can prioritize the ones that matter most. **Performance review.** This section looks at how well IT is serving your business day to day. Your IT provider should present data on support ticket trends (are tickets increasing or decreasing?), average response and resolution times, system uptime, recurring issues that haven't been permanently resolved, and user satisfaction. If the same printer problem generates a ticket every week, that's not an IT support success story. It's a sign that someone needs to fix the root cause. **Budget review.** A TBR should include a clear summary of what you're currently spending on IT across all categories: hardware, software, managed services, security, internet, and phone. It should highlight areas where costs could be optimized (unused licenses, redundant tools, overprovisioned services) and areas where additional investment is needed (aging hardware, security gaps, compliance requirements). This section turns IT from a mystery expense into a transparent, manageable budget item. **Roadmap and priorities.** The most valuable part of a TBR is the forward-looking plan. Your IT provider should present a roadmap for the next 6 to 12 months, with specific projects ranked by business impact and risk. For example: "Replace the 5 laptops that are over 4 years old (high impact, medium cost), upgrade from Microsoft 365 Business Standard to Business Premium to get Intune and Defender (high impact, moderate cost), implement a formal backup for your Microsoft 365 data using Dropsuite (high impact, low cost)." Each recommendation should include an estimated cost and a clear rationale. ## Why small businesses skip TBRs (and why they shouldn't) The most common excuse is "we're too small for that." But even a 10-person company benefits from a yearly IT checkup. In fact, smaller businesses often benefit more because they have less margin for error. A single security incident or prolonged outage can have an outsized impact on a business with 15 employees. Many small businesses lack internal IT leadership. The owner makes IT decisions on the fly, reacting to problems rather than planning ahead. A TBR gives you an hour or two of structured strategic thinking about technology, guided by someone who does this professionally. It's the closest thing to having a CIO without hiring one. Reactive IT culture is another barrier. When technology only gets attention after something breaks, risks accumulate silently. That 6-year-old server nobody thinks about, the two employees who never set up MFA, the backup that stopped running three months ago but nobody noticed. Without regular reviews, these issues don't surface until they cause an expensive emergency: a server failure, a security breach, or a failed compliance audit. ## What a good TBR should produce Walk out of a TBR with tangible deliverables, not just a handshake and a verbal summary. **Written report.** A document summarizing findings, risks, and recommendations. This is your reference between reviews and your evidence for cyber insurance applications, compliance audits, or board discussions. **Risk register.** A prioritized list of risks with severity, likelihood, and recommended actions. This becomes your "fix it" list, ordered by what matters most. **Hardware lifecycle plan.** A clear picture of which devices need replacement in the next 12 months and the estimated cost. No surprises when a laptop dies if you already knew it was due for replacement. **Security scorecard.** Where your security stands against a recognized framework. A CIS Controls baseline assessment, for example, measures your environment against the Center for Internet Security's recommended controls and identifies specific gaps with actionable recommendations. This gives you an objective measure of your security posture, not just your IT provider's opinion. **Budget projection.** Estimated IT costs for the next 12 months, including recurring costs and planned projects. This feeds directly into your annual business budget. **Priority roadmap.** The top 3 to 5 projects recommended for the next quarter, with rationale, estimated cost, and expected business impact. ## How often to have a TBR **Annually at minimum.** A comprehensive review covering all of the categories above. This is the baseline. Any business working with an MSP should expect at least one thorough TBR per year. **Quarterly is better.** Shorter check-ins (30 to 60 minutes) to review progress on the roadmap, address new issues, and adjust priorities. Quarterly reviews keep the roadmap from becoming a document nobody looks at after the annual meeting. They also catch emerging risks, like a new employee who was onboarded without MFA, before they become problems. **Triggered reviews.** Schedule an additional TBR after a security incident, a major business change (acquisition, rapid hiring, new office location), or a compliance audit. These events change your IT landscape enough to warrant a fresh assessment. For [Athencia's managed IT clients](/athencia-one), triggered reviews are part of the service relationship and can be scheduled on short notice. Most managed IT providers include quarterly or annual TBRs as part of their service agreement. If yours doesn't, ask why. ## What to prepare for your TBR Come to the meeting ready to discuss the business side. Your IT provider brings the technical data; you bring the business context. Share your business goals for the next 12 months. Are you planning to hire? Open a new location? Launch a new service? These plans directly affect your IT needs, and your provider needs to know about them to plan effectively. Bring up any IT frustrations or recurring issues your team is experiencing. Slow computers, unreliable Wi-Fi, confusing software, difficulty accessing files remotely. These issues often get normalized ("that's just how it is"), but they shouldn't be. A TBR is the right time to raise them. Mention upcoming compliance requirements or audits. If your industry requires HIPAA compliance and you have an audit in six months, your IT provider needs to factor that into the roadmap. Be transparent about budget constraints. A good IT provider will work within your budget and help you prioritize spending where it has the most impact. Hiding budget limitations leads to recommendations you can't act on, which wastes everyone's time. Finally, bring questions. If you've heard about a new tool, a new threat, or a technology trend that might affect your business, the TBR is the right place to discuss it. ## Red flags: When your IT provider doesn't offer TBRs An MSP or IT provider that never reviews your environment strategically is operating as a help desk, not a partner. They're solving today's problems without thinking about tomorrow's risks. That distinction matters. Without TBRs, issues like aging hardware, expiring software licenses, and security gaps go unaddressed until they cause a crisis. You end up in a constant cycle of emergency spending, which is both more expensive and more stressful than planned investment. A good IT provider proactively schedules TBRs and comes prepared with data, analysis, and recommendations. They don't wait for you to ask. If your current provider doesn't offer regular TBRs, ask them to start. If they're unwilling or unable, consider it a significant factor in evaluating alternatives. ## Need help? A Technology Business Review is one of the most valuable things an IT provider can offer, and it's one of the easiest to overlook. If you haven't had one in the past year, or if you've never had one at all, [reach out to Athencia](/contact). We'll assess your environment, identify your risks, and give you a clear plan for the next 12 months. ### Microsoft 365 #### How to Add a New Employee to Microsoft 365 and Set Up Their Email > Step-by-step guide for adding a new user account in Microsoft 365, assigning a license, and configuring their business email. URL: https://athencia.com/kb/microsoft-365/how-to-add-a-new-employee-to-microsoft-365-and-set-up-their-email Adding a new employee to Microsoft 365 involves creating a user account in the admin center, assigning a license, and configuring their email. The whole process takes about 10 minutes and does not require any technical background. This guide walks through every step with the exact screens and buttons you will encounter. ## What you need - **Global Administrator** or **User Administrator** access to your Microsoft 365 tenant - An available Microsoft 365 license to assign - The new employee's full name and desired email address - Their job title and department (for the company directory) ## Step 1: Sign in to the Microsoft 365 admin center Go to [admin.microsoft.com](https://admin.microsoft.com) and sign in with your admin credentials. You will land on the admin center home page, which shows a dashboard of your tenant's health and usage. If you are not sure who your admin is, any existing user can check by going to **Settings** > **Org settings** in Microsoft 365 and looking for the admin contact. If your company uses a managed IT provider like [Athencia](/athencia-one), your provider handles user provisioning for you and you can simply send them the new hire's details. ## Step 2: Create the new user account 1. In the left sidebar, click **Users** > **Active users** 2. Click **+ Add a user** at the top of the page 3. Fill in the following fields: - **First name** and **Last name** - **Display name** (auto-populates from the name fields) - **Username**: This becomes the employee's email address. Enter the part before the @ sign and select your company domain from the dropdown (e.g., jsmith@yourcompany.com) 4. Under **Password settings**, choose one of two options: - **Auto-generate a password**: Microsoft creates a random password for you. This is the easiest option. - **Let me create the password**: You type in a temporary password manually. 5. Check the box for **Require this user to change their password when they first sign in**. Always leave this enabled so the employee sets their own password on day one. 6. Click **Next** ## Step 3: Assign a license On the next screen, you will assign a product license. This determines which Microsoft 365 apps and services the employee can use. 1. Check the box next to the license you want to assign 2. If you have multiple license types, choose the one appropriate for the employee's role Here is a quick comparison of the most common license tiers: | Feature | Business Basic | Business Standard | Business Premium | |---------|---------------|------------------|-----------------| | Exchange email | Yes | Yes | Yes | | Web and mobile Office apps | Yes | Yes | Yes | | Desktop Office apps | No | Yes | Yes | | Microsoft Teams | Yes | Yes | Yes | | OneDrive (1 TB) | Yes | Yes | Yes | | Intune device management | No | No | Yes | | Defender for Office 365 | No | No | Yes | | Entra ID Conditional Access | No | No | Yes | Athencia deploys Microsoft 365 Business Premium for all managed clients because it includes Intune, Defender for Office 365, and Conditional Access at no extra cost. These security features are not available in Business Basic or Business Standard, which means organizations on those tiers lack device management, advanced email threat protection, and the ability to enforce sign-in policies. If you have no available licenses, click the link to **Purchase licenses** directly from this screen. The new license is added to your subscription immediately. 3. Click **Next** ## Step 4: Configure optional settings This screen lets you set additional details for the user's profile and permissions. **Admin roles**: Leave this set to **User (no admin center access)** unless the employee specifically needs admin privileges. Follow the principle of least privilege: only assign admin roles to people who need them, and use the most limited role that covers their responsibilities. **Profile information**: Fill in the employee's **Job title**, **Department**, **Office**, and **Phone number**. This information populates the company directory and is used by Exchange transport rules (for email signatures), org charts, and the Teams people card. Filling it in now saves you from having to update it later. Click **Next**, then review the summary and click **Finish adding** to create the account. ## Step 5: Add the user to groups and shared mailboxes After the account is created, add the employee to the correct distribution groups, Microsoft 365 groups, and shared mailboxes. 1. Go to **Users** > **Active users** and click on the new user's name 2. Click the **Groups** tab 3. Click **Manage groups** and add them to any relevant groups (e.g., allstaff@, marketing-team@) 4. For shared mailbox access, go to **Teams & groups** > **Shared mailboxes**, click the shared mailbox, and add the new user as a member If your company uses Microsoft Teams for collaboration, the employee will automatically gain access to any Teams channels associated with the Microsoft 365 groups you added them to. ## Step 6: Share login credentials securely Never send a password in a plain-text email. If that email is intercepted or the recipient's inbox is compromised, the attacker has the credentials. Instead, share the temporary password using one of these methods: - **In person or by phone**: The most secure option for employees working on-site. - **Password manager**: If your company uses 1Password, create a secure share link with the temporary credentials. Athencia includes 1Password in its [Athencia One Complete](/athencia-one-complete) package and offers it as an add-on for Athencia One clients. A password manager eliminates the problem of securely transmitting credentials entirely. - **Separate channels**: Send the username by email and the temporary password by text message, so both are never in the same place. Let the employee know what to expect on their first sign-in: they will be prompted to change their password, and if your organization has MFA enabled, they will also be walked through setting up the Microsoft Authenticator app. ## Step 7: Verify the account is working Before considering the setup complete, confirm everything is functioning: 1. **Send a test email** to the new address from another account and verify it arrives 2. **Have the employee sign in** at [outlook.office.com](https://outlook.office.com) and confirm they can access Outlook, Teams, and OneDrive 3. **Check the license** by going to **Users** > **Active users** > clicking their name > **Licenses and apps** to confirm the correct license and services are assigned If your organization uses Microsoft Intune for device management (included with Business Premium), the employee's device enrollment will happen automatically when they sign in to their work account on a company-managed device. For personal devices in a BYOD setup, Intune app protection policies can secure company data on the device without managing the entire phone. ## Device and security setup Once the account is active, the new employee's device needs to be properly secured. On a Business Premium tenant, this includes: - **Microsoft Intune** enrollment, which pushes your company's security policies (encryption, password requirements, screen lock) to the device automatically - **Microsoft Defender for Business**, which provides endpoint protection on the device - **Huntress Managed EDR**, which Athencia layers on top of Defender for 24/7 monitoring by human threat hunters. Defender handles baseline protection; Huntress adds a managed Security Operations Center that catches threats Defender misses. This happens behind the scenes for managed clients. If you are handling IT internally, you will need to configure Intune device enrollment and compliance policies separately. ## Common issues | Issue | Cause | Fix | |-------|-------|-----| | "This username is already taken" | Another account (active or deleted) uses that address | Check the deleted users list under **Users** > **Deleted users**. If found, either restore it or permanently delete it to free the address. | | License assignment fails | No available licenses | Purchase additional licenses from **Billing** > **Purchase services** | | Email not in global address list | Directory sync takes time | Allow up to 24 hours for the new user to appear in the global address list and Outlook autocomplete | | Employee cannot sign in | Account may be blocked or password issue | Verify sign-in is not blocked under the user's account settings and try resetting the password | ## Need help? Adding users is straightforward, but getting the full onboarding right, from license selection to device enrollment to security configuration, takes more planning. If you want help setting up new employees or building a repeatable onboarding process, [contact Athencia](/contact). We handle user provisioning as part of every client onboarding. #### How to Offboard an Employee in Microsoft 365 Without Losing Their Data > Step-by-step guide for securely removing a departing employee from Microsoft 365 while preserving their email, files, and data for your business. URL: https://athencia.com/kb/microsoft-365/how-to-offboard-an-employee-in-microsoft-365-without-losing-their-data Offboarding an employee from Microsoft 365 requires revoking their access immediately while preserving their email, files, and data for business continuity. Doing this in the wrong order can result in permanent data loss or a security gap where the departing employee retains access to company systems. This guide walks through every step in the correct sequence. ## What you need - **Global Administrator** access to Microsoft 365 - Knowledge of which files, emails, and data the departing employee owns - A plan for who should receive access to the employee's mailbox and files (typically their manager or replacement) ## Why order matters The single most common mistake is deleting the user account before preserving their data. Once the account is deleted, you have 30 days to restore it before everything is permanently gone. The correct sequence is: block access first, preserve data second, delete the account last. ## Step 1: Reset the password and block sign-in This should happen immediately, ideally on or before the employee's last day. Every minute the account remains accessible after the employee has left is a security risk. 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Users** > **Active users** 2. Click on the departing employee's name 3. Click **Reset password** at the top of their account page 4. Select **Auto-generate password** and uncheck **Require this user to change their password when they first sign in** (it does not matter since they will not be signing in again) 5. Click **Reset password** 6. Next, click **Block sign-in** on the same user's account page 7. Check the box for **Block this user from signing in** and click **Save changes** Blocking sign-in revokes all active sessions across all devices, including Outlook desktop, Teams, mobile apps, and any browser sessions. The user will be signed out everywhere within about 60 minutes. If you need immediate session revocation, go to the user's account page, click the **Account** tab, and click **Revoke sessions**. If your organization uses Huntress Managed ITDR alongside Microsoft Entra ID, any suspicious sign-in attempts from the former employee's credentials after this point will be flagged and investigated by Huntress's 24/7 SOC team automatically. ## Step 2: Convert the mailbox to a shared mailbox Converting the departing employee's mailbox to a shared mailbox is the best way to preserve their email. A shared mailbox does not require a license, so you stop paying for it immediately, and all email history is retained indefinitely. 1. Go to the [Exchange admin center](https://admin.exchange.microsoft.com) 2. Click **Recipients** > **Mailboxes** 3. Click on the departing employee's mailbox 4. Click **Convert to shared mailbox** (under the Others section at the bottom) 5. Confirm the conversion After converting, add the employee's manager or replacement as a member of the shared mailbox: 1. Go back to [admin.microsoft.com](https://admin.microsoft.com) > **Teams & groups** > **Shared mailboxes** 2. Click on the newly converted shared mailbox 3. Under **Members**, click **Edit** and add the appropriate people The alternative is setting up email forwarding to another user. However, forwarding only captures new incoming mail. It does not preserve the departing employee's email history, sent items, or folder structure. Converting to a shared mailbox preserves everything. If your company needs to retain email data for compliance or legal reasons beyond what the shared mailbox provides, Dropsuite provides independent backup of Microsoft 365 mailboxes, OneDrive, and SharePoint. Athencia includes Dropsuite in its managed stack, which means you can restore email data from any point in time, even if something goes wrong during offboarding. ## Step 3: Transfer OneDrive files The departing employee's OneDrive contains their personal work files. You need to transfer these before deleting the account. 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Users** > **Active users** 2. Click on the departing employee's name 3. Click the **OneDrive** tab 4. Under **Get access to files**, click **Create link to files** 5. This generates a link that opens the employee's OneDrive. Share this link with their manager or replacement. The delegate has 30 days from the date the account is deleted to access and move files. After 30 days, the OneDrive data is permanently deleted. To move the files permanently: 1. Open the link to the employee's OneDrive 2. Select all relevant files and folders 3. Click **Move to** and choose a location in a SharePoint document library or another user's OneDrive 4. Verify the files transferred successfully If you need to extend the 30-day window, go to the SharePoint admin center ([admin.microsoft.com](https://admin.microsoft.com) > **Admin centers** > **SharePoint**) > **Settings** > **OneDrive retention** and increase the retention period (up to 3,650 days). ## Step 4: Remove from groups and transfer ownership The departing employee may be a member or owner of Microsoft 365 groups, Teams channels, distribution lists, and shared mailboxes. You need to handle each: 1. Go to **Users** > **Active users** > click the employee's name > **Groups** tab 2. Review every group they belong to 3. For groups where they are the **sole owner**, add a new owner before proceeding. If the only owner is removed, no one can manage the group. 4. Remove the employee from all groups For Microsoft Teams specifically: 1. Open the Teams admin center at [admin.teams.microsoft.com](https://admin.teams.microsoft.com) 2. Go to **Teams** > **Manage teams** and check each team the employee belonged to 3. If they owned any teams, transfer ownership to another user 4. Remove them from all teams ## Step 5: Revoke access to third-party apps Departing employees often have access to third-party applications through their Microsoft 365 account. These need to be revoked. 1. Go to the [Entra admin center](https://entra.microsoft.com) > **Identity** > **Users** > select the departing user 2. Click **Applications** to see which enterprise applications they accessed 3. Revoke any app-specific permissions 4. Under **Consents and permissions**, review and remove any OAuth consents the user granted to third-party apps This step is frequently overlooked. OAuth consents can persist even after the user's password is reset, allowing third-party apps to continue accessing company data through tokens the user previously authorized. ## Step 6: Review sign-in logs Before deleting the account, check the sign-in logs for any suspicious activity during the employee's final days. 1. In the [Entra admin center](https://entra.microsoft.com), go to **Identity** > **Monitoring & health** > **Sign-in logs** 2. Filter by the departing user's name 3. Look for sign-ins from unusual locations, bulk file downloads, or access to sensitive applications This requires Entra ID P1 licensing, which is included with Microsoft 365 Business Premium. Business Basic and Business Standard do not include sign-in log retention or the ability to filter by user. ## Step 7: Delete the user account Only delete the account after you have confirmed that the mailbox is converted, files are transferred, and group ownership is reassigned. 1. Go to [admin.microsoft.com](https://admin.microsoft.com) > **Users** > **Active users** 2. Select the departing employee 3. Click **Delete user** 4. Confirm the deletion After deletion: - The account moves to **Users** > **Deleted users** and stays there for 30 days. During this window, you can restore the account if needed. - After 30 days, deletion is permanent and the account cannot be recovered. - The license assigned to the deleted user becomes available for reassignment immediately. ## Offboarding checklist Use this checklist to make sure nothing is missed: - [ ] Password reset and sign-in blocked - [ ] Active sessions revoked - [ ] Mailbox converted to shared mailbox - [ ] Manager or replacement added to shared mailbox - [ ] OneDrive files transferred or access granted - [ ] Group memberships reviewed and employee removed - [ ] Group and Teams ownership transferred where needed - [ ] Third-party app access and OAuth consents revoked - [ ] Sign-in logs reviewed for suspicious activity - [ ] User account deleted - [ ] License reclaimed and available for reassignment ## Need help? Employee offboarding involves security, compliance, and data preservation decisions that are easy to get wrong. If you want to make sure nothing falls through the cracks, [contact Athencia](/contact). We handle offboarding for managed clients and can audit your current process for gaps. #### How to Organize Your Company Files in SharePoint for a Small Team > Practical guide to setting up a SharePoint document library that keeps your small team's files organized, accessible, and properly secured. URL: https://athencia.com/kb/microsoft-365/how-to-organize-your-company-files-in-sharepoint-for-a-small-team SharePoint document libraries are the right place for shared company files that multiple people need to access. Setting up a clean structure from the start prevents the tangled mess of duplicated folders, broken permissions, and files nobody can find that plagues most small businesses. This guide covers planning, structure, permissions, and syncing, with specific steps you can follow today. ## What you need - Microsoft 365 admin or SharePoint admin access - A plan for which teams or departments need shared file spaces - A list of who needs access to what Every Microsoft 365 plan that includes Teams also includes SharePoint. The document libraries behind every Teams channel are SharePoint libraries, even if your team never opens SharePoint directly. ## SharePoint sites vs. document libraries vs. folders Before building anything, understand the three layers of SharePoint file organization: - **SharePoint site**: A container for a team or department. Every Microsoft Teams team automatically gets a SharePoint site behind it. Think of a site as a top-level workspace. - **Document library**: A file storage area within a SharePoint site. Each site can have multiple libraries. Think of a library like a filing cabinet. - **Folders**: Subdivisions within a document library. Use these sparingly. SharePoint works best with a flat or shallow folder structure combined with metadata columns for filtering. The key recommendation is one SharePoint site per department or major function, with document libraries and metadata replacing deeply nested folders. If you are coming from a traditional file server with 10 levels of nested folders, this is a significant shift in thinking, but it pays off quickly in usability. ## Step 1: Plan your site structure Keep it simple. For a company with 10 to 30 people, you likely need only two to four SharePoint sites. Here is a practical starting structure: | Site Name | Purpose | Who Needs Access | |-----------|---------|-----------------| | Company-Wide | Policies, templates, shared resources | Everyone | | Operations | Projects, client work, delivery | Operations team | | Finance | Invoices, reports, budgets | Finance team + leadership | | HR | Onboarding docs, policies, personnel files | HR + leadership | Before creating any new sites, check what already exists. Each Teams team creates a SharePoint site automatically. If your marketing team already has a Teams channel, they already have a SharePoint site. Creating a separate SharePoint site for marketing would just create confusion and file duplication. To see existing sites, go to the SharePoint admin center at [admin.microsoft.com](https://admin.microsoft.com) > **Admin centers** > **SharePoint** > **Sites** > **Active sites**. ## Step 2: Create document libraries Within each SharePoint site, create document libraries for major file categories. Each library should represent a distinct type of work or content. 1. Open the SharePoint site 2. Click **+ New** in the top bar > **Document library** 3. Enter a name for the library (keep it short, use hyphens instead of spaces) 4. Click **Create** For example, an Operations site might have these libraries: - **Client-Projects**: All client deliverables and working files - **Templates**: Proposal templates, SOW templates, project plans - **Contracts**: Signed contracts and agreements - **Proposals**: Active and archived proposals Keep library names short and descriptive. Avoid spaces in library names because they get replaced with "%20" in URLs, which looks messy and can cause issues with some integrations. To customize the default view, click the column headers and select **Column settings** > **Show/hide columns**. The most useful default view includes: Name, Modified, Modified By, and any custom metadata columns you create in the next step. ## Step 3: Use metadata instead of deep folders This is the step that separates a well-organized SharePoint from one that looks like a cluttered file server. Instead of creating nested folders like Clients > Smith > 2026 > Invoices, create a flat library with metadata columns that let users filter and sort. To add a custom column: 1. Open the document library 2. Click **+ Add column** in the header row 3. Choose the column type: - **Choice**: For categories like Client Name, Document Type, or Status - **Date**: For deadlines or effective dates - **Person**: For assigning an owner or reviewer - **Number**: For invoice amounts, project numbers, etc. 4. Enter the column name and options 5. Click **Save** For a Client-Projects library, useful columns might be: | Column | Type | Options | |--------|------|---------| | Client Name | Choice | List of your clients | | Project Phase | Choice | Discovery, Active, Complete, Archived | | Document Type | Choice | Contract, Proposal, Deliverable, Invoice | | Owner | Person | (pulls from your directory) | Once columns are set up, users can click any column header to sort, or use the **Filter** pane on the right to show only files matching specific criteria. This is dramatically faster than navigating five levels of folders. When folders still make sense: if you need to apply different permissions to different sections of a library (for example, restricting access to certain client files), folders with broken permission inheritance are the way to do it. Otherwise, prefer metadata. ## Step 4: Set permissions SharePoint permissions inherit from the site by default. Everyone who has access to the site can see every library and file within it. For most libraries, this is fine. For sensitive content like HR records or financial data, you need to restrict access. To set permissions on a library: 1. Open the document library 2. Click the gear icon in the top right > **Library settings** > **Permissions for this document library** 3. Click **Stop Inheriting Permissions** to break the inheritance from the site 4. Remove groups that should not have access 5. Add the specific users or groups that need access, selecting the appropriate permission level: - **Full Control**: Can do everything, including managing permissions (use sparingly) - **Edit**: Can add, edit, and delete files - **Read**: Can view files but not modify them Follow the principle of least privilege. Give people the minimum access they need. Not everyone in the company needs to see financial reports or personnel files. Audit permissions quarterly, especially after employee departures. Former employees who were removed from Microsoft 365 lose access automatically, but contractors or external guests with direct permissions may not. ## Step 5: Sync libraries to File Explorer with OneDrive Many employees are more comfortable working with files in File Explorer (Windows) or Finder (Mac) than in a browser. SharePoint libraries can be synced to the desktop so they appear alongside local files. To set up sync: 1. Open the SharePoint document library in a browser 2. Click **Sync** in the toolbar at the top 3. Your browser will prompt you to open OneDrive. Click **Open** 4. OneDrive will begin syncing the library. Files appear under your company's name in File Explorer or Finder. Enable **Files On-Demand** so that synced files do not fill up the employee's hard drive. With Files On-Demand, files appear in the folder tree but are only downloaded when opened. To enable this: 1. Click the OneDrive icon in the system tray 2. Click the gear icon > **Settings** 3. Under the **Sync and backup** tab, check **Save space and download files as you use them** If your organization uses Microsoft Intune for device management (included with Microsoft 365 Business Premium), you can push OneDrive sync settings to all company devices through Intune policies. This ensures every employee's device is configured to sync the correct libraries with Files On-Demand enabled, without any manual setup on their part. ## Step 6: Back up your SharePoint data SharePoint has built-in version history and a recycle bin, but these are not the same as a true backup. If a user accidentally deletes an entire library, or if ransomware encrypts your files, version history alone may not save you. Dropsuite provides independent backup for SharePoint, OneDrive, and Exchange mailboxes. Athencia includes Dropsuite in its managed stack for all clients. With Dropsuite, your SharePoint data is backed up daily to a separate location, and you can restore individual files, folders, or entire libraries to any point in time. Without a third-party backup, you are relying solely on Microsoft's recycle bin (93 days for SharePoint) and version history. That is better than nothing, but it leaves gaps for bulk deletions, ransomware, and retention policy mistakes. ## Common mistakes - **Creating too many SharePoint sites.** More sites means more places to check and more permissions to manage. Start with the minimum and add sites only when there is a clear need. - **Deeply nested folder structures.** If you are recreating your old file server's folder tree in SharePoint, stop. Use metadata columns for filtering instead. - **Not setting permissions on sensitive libraries.** By default, everyone on the site sees everything. Break inheritance on HR, finance, and legal libraries. - **Not syncing libraries to File Explorer.** If employees have to open a browser and navigate to SharePoint every time they need a file, they will store files locally instead. Sync makes SharePoint feel like a local drive. - **No naming conventions.** Establish and enforce naming rules from day one. Files named "FINAL_v3_REAL_USE THIS ONE.docx" are a sign that no one agreed on a naming convention. - **Ignoring version history.** SharePoint keeps version history by default. Make sure it is enabled and set to a reasonable number of versions (50 is a good default). This lets you recover previous versions of any file. ## Need help? Setting up SharePoint well from the start saves hours of cleanup later. If you need help planning your site structure, configuring permissions, or migrating files from a file server or other cloud storage, [contact Athencia](/contact). We set up SharePoint as part of every Microsoft 365 deployment. #### How to Recover Deleted Emails in Outlook for Microsoft 365 > Guide to recovering deleted emails in Outlook, including items purged from the Deleted Items folder, using the Recoverable Items feature. URL: https://athencia.com/kb/microsoft-365/how-to-recover-deleted-emails-in-outlook-for-microsoft-365 Deleted emails in Outlook for Microsoft 365 can usually be recovered, even after being removed from the Deleted Items folder. Microsoft retains purged items for 14 days by default (up to 30 days if your admin has configured it), giving you a recovery window. This guide covers every recovery method available, from the simplest self-service options to admin-level tools for situations where the standard methods do not work. ## Understanding where deleted emails go Emails in Microsoft 365 do not disappear the moment you delete them. They pass through a series of stages, and each stage gives you a chance to recover them. **Stage 1: Deleted Items folder.** When you delete an email (pressing Delete or dragging it to Deleted Items), it moves to the Deleted Items folder. It stays there until you empty the folder or until your organization's retention policy clears it automatically. Recovering from here is as simple as dragging the email back to your Inbox. **Stage 2: Recoverable Items folder.** When you empty your Deleted Items folder, or delete an email from within Deleted Items, the email moves to a hidden folder called Recoverable Items. You will not see this folder in your normal folder list, but it is accessible through a special recovery option in Outlook. Items stay in Recoverable Items for 14 days by default. Your admin can extend this to up to 30 days. **Stage 3: Permanently deleted.** After the retention period in Recoverable Items expires, the email is permanently gone from the mailbox. At this point, only a third-party backup solution or a compliance search (if one was configured before deletion) can recover it. Understanding these stages helps you pick the right recovery method below. ## Option 1: Recover from the deleted items folder This is the simplest recovery. If the email is still in your Deleted Items folder, you can restore it in seconds. ### In Outlook on the web 1. Go to [outlook.office.com](https://outlook.office.com) and sign in 2. Click the **Deleted Items** folder in the left sidebar 3. Find the email you need. If you have a lot of deleted items, use the **Search** bar at the top of the folder and enter the sender's name, subject line, or a keyword from the email. 4. Right-click the email and select **Move** > **Inbox** (or choose another folder) 5. The email is restored to the folder you selected ### In Outlook desktop 1. Click the **Deleted Items** folder in the left sidebar 2. Find the email you need 3. Right-click the email and select **Move** > **Other Folder** 4. Choose **Inbox** or the original folder and click **OK** To recover multiple items at once, hold **Ctrl** (Windows) or **Cmd** (Mac) while clicking each email to select them, then right-click and move them all at the same time. ## Option 2: Recover purged items in Outlook on the web If you have already emptied your Deleted Items folder, the email may still be in the Recoverable Items folder. You can access this directly from Outlook on the web. 1. Go to [outlook.office.com](https://outlook.office.com) and sign in 2. Click the **Deleted Items** folder in the left sidebar 3. At the top of the message list, click **Recover items deleted from this folder** 4. A new window opens showing all recoverable items. Use the search bar to find specific emails by sender, subject, or date. 5. Select the emails you need by checking the box next to each one 6. Click **Restore** at the top of the list Restored items go back to the **Deleted Items** folder, not directly to your Inbox. After restoring, go to Deleted Items and move the emails to your Inbox or the folder where they belong. The items in this recovery window are only available for 14 days (or up to 30 days if your admin has extended the retention period). After that, they are permanently removed and cannot be recovered through this method. ## Option 3: Recover purged items in Outlook desktop The desktop version of Outlook also has access to the Recoverable Items folder, but the menu location varies depending on whether you are using classic Outlook or the new Outlook. ### Classic Outlook (Windows) 1. Click the **Deleted Items** folder in the left sidebar 2. Go to the **Folder** tab in the ribbon 3. Click **Recover Deleted Items** 4. A dialog box opens showing all recoverable items with their subject, sender, and deletion date 5. Select the items you need (hold Ctrl to select multiple) 6. Click **Restore Selected Items** (the envelope icon with the arrow) 7. Items are restored to the Deleted Items folder. Move them to your Inbox afterward. ### New Outlook (Windows and Mac) 1. Click the **Deleted Items** folder 2. At the top of the message list, click **Recover items deleted from this folder** (same as the web version) 3. Select items and click **Restore** If you do not see the **Recover Deleted Items** option in classic Outlook, make sure you have the Deleted Items folder selected. The option only appears when that specific folder is active. If it still does not show, your admin may not have enabled recoverable items for your mailbox. ## Option 4: Admin recovery If the user cannot find the email through any of the self-service options above, an admin can attempt recovery through the Exchange admin center or PowerShell. ### Exchange admin center 1. Sign in to the [Exchange admin center](https://admin.exchange.microsoft.com) 2. Go to **Recipients** > **Mailboxes** 3. Click on the user's mailbox 4. Under **Others**, click **Recover deleted items** 5. Search for the items by date range, subject, or sender 6. Select the items and click **Recover** ### PowerShell (for bulk recovery or advanced scenarios) Admins can use the Exchange Online PowerShell module to recover items that do not appear in the admin center interface. This is useful for bulk recovery or for items that are close to the end of their retention window. The command `Get-RecoverableItems` and `Restore-RecoverableItems` allow filtering by subject, sender, date range, and item type. This requires the Exchange Online PowerShell module and the appropriate admin role. ### Compliance search (last resort) If the email has passed the recoverable items retention window, and your organization has a retention policy or litigation hold in place, the email may still exist in the compliance store. 1. Go to [compliance.microsoft.com](https://compliance.microsoft.com) > **Content search** 2. Create a new search and specify the mailbox, date range, and keywords 3. Run the search and review the results 4. Export the results to recover the email Compliance Search only works if a retention policy, litigation hold, or in-place hold was active at the time the email was deleted. If none of these were configured, the email is gone once it passes the recoverable items window. ## How to prevent this in the future ### Extend the recoverable items retention period By default, Microsoft 365 keeps purged items for 14 days. Your admin can extend this to 30 days, which is the maximum for Exchange Online. To change this, an admin can run the following PowerShell command: ``` Set-Mailbox -Identity user@yourcompany.com -RetainDeletedItemsFor 30 ``` To apply this to all mailboxes at once, your admin can set it as a tenant-wide default. ### Train employees to archive instead of delete Most accidental deletions happen because employees use the Delete key as an organization tool. Encourage your team to use the **Archive** button instead. Archived emails move to the Archive folder, where they remain searchable and accessible without cluttering the Inbox. ### Set up retention policies Retention policies keep email for a defined period regardless of whether the user deletes it. Go to [compliance.microsoft.com](https://compliance.microsoft.com) > **Data lifecycle management** > **Retention policies** to create policies that retain email for one year, three years, or whatever your business or compliance requirements dictate. ### Use a third-party backup solution Microsoft's built-in retention has limits. The recoverable items window maxes out at 30 days, and compliance features require specific licensing. Dropsuite provides independent backup of Microsoft 365 mailboxes, backing up every email daily to a separate location. Athencia includes Dropsuite in its managed stack, which means any deleted email can be restored from backup at any point, regardless of Microsoft's retention windows. This is the most reliable safety net for accidental deletions, ransomware, and compliance requirements. ## Need help? If you have tried the steps above and still cannot find the email you need, or if you want to set up retention policies and backup to prevent this from happening again, [contact Athencia](/contact). We can help recover lost data and put safeguards in place for the future. #### How to Set Up a Consistent Email Signature for Your Whole Team in Microsoft 365 > Guide to creating and deploying a professional, consistent email signature across all employees in Microsoft 365 using transport rules or third-party tools. URL: https://athencia.com/kb/microsoft-365/how-to-set-up-a-consistent-email-signature-for-your-whole-team-in-microsoft-365 A consistent email signature across your entire team makes your business look professional and ensures every outgoing email includes your correct contact information, branding, and any required legal disclaimers. Without a centralized approach, you end up with employees using different fonts, outdated phone numbers, or no signature at all. Microsoft 365 offers several ways to manage signatures, from individual manual setup to fully centralized deployment. ## What you need - A finalized signature design (logo, contact format, colors, any legal disclaimers) - Microsoft 365 admin access for centralized deployment options - Employee names, titles, phone numbers, and other dynamic fields - Your company logo hosted at a public URL (for HTML signatures) ## Option 1: Manual setup in Outlook (simplest, least control) Each employee creates their own signature in Outlook using a template you provide. This works for very small teams where you trust everyone to follow the format. ### Outlook desktop (Windows) 1. Open Outlook and click **File** > **Options** 2. In the Options window, click **Mail** on the left sidebar 3. Click **Signatures** 4. Click **New**, give the signature a name (e.g., "Company Signature") 5. In the editor, paste the signature template you prepared. You can paste formatted HTML directly from a browser or design tool. 6. Under **Choose default signature**, set the signature for both **New messages** and **Replies/forwards** 7. Click **OK** to save ### Outlook on the web 1. Go to [outlook.office.com](https://outlook.office.com) and sign in 2. Click the **Settings** gear icon in the top right 3. Click **Mail** > **Compose and reply** 4. Under **Email signature**, paste your template into the editor 5. Check **Automatically include my signature on new messages I compose** and **Automatically include my signature on messages I forward or reply to** 6. Click **Save** ### Limitations of manual setup - Relies on each employee to set it up correctly and keep it updated - Does not apply to emails sent from mobile devices unless configured separately in the Outlook mobile app - If an employee reinstalls Outlook or gets a new device, the signature is lost and needs to be recreated - No centralized way to push updates (logo change, phone number change) to everyone at once This approach works for offices under five people. Beyond that, the maintenance overhead outweighs the simplicity. ## Option 2: Exchange transport rules (built-in, centralized) Exchange mail flow rules (also called transport rules) let you apply a signature to all outgoing email server-side. This means every external email gets the signature automatically, regardless of which device or app the sender uses. ### Setting up the transport rule 1. Go to the [Exchange admin center](https://admin.exchange.microsoft.com) 2. In the left sidebar, click **Mail flow** > **Rules** 3. Click **+ Add a rule** > **Apply disclaimers** 4. Name the rule (e.g., "Company Email Signature") 5. Under **Apply this rule if**, select **The sender is located** > **Inside the organization** 6. Under **Do the following**, select **Append the disclaimer** > **Enter text** 7. Paste your signature HTML into the text box 8. Under **Fallback action**, choose **Wrap** (this adds the signature even if Outlook cannot insert it inline) 9. Click **Next** through the remaining settings and **Save** ### Using dynamic variables Transport rules support variables that pull data from each user's Entra ID directory profile. This means you can create one template that automatically inserts each person's name, title, and phone number. Common variables: | Variable | Inserts | |----------|---------| | `%%DisplayName%%` | Full name | | `%%Title%%` | Job title | | `%%Department%%` | Department | | `%%PhoneNumber%%` | Office phone | | `%%MobilePhone%%` | Mobile phone | | `%%Email%%` | Email address | Your HTML template might look like this: ```html
%%DisplayName%%
%%Title%% | Your Company
%%PhoneNumber%% | %%Email%%
yourcompany.com