How a 40-person business moved off Google Workspace and put every account behind managed identity
~40-employee business · one office + field staff · Cleveland, TN
The challenge
Where they started.
Google Workspace itself ran fine — Gmail’s filtering was genuinely good. The gap was configuration, and the fact that nobody was watching the console: 2-Step Verification was available but optional, a permissive link-sharing policy let staff share folders with anyone holding the URL, and the Windows laptops had no directory behind them at all. Then a cyber-insurance renewal asked how the business enforced MFA, protected endpoints, and encrypted disks. Nobody could attest to any of the three.
Specific pain points
- 2-Step Verification available but never enforced — roughly half the staff had skipped it
- Windows laptops unmanaged: no directory, no disk encryption, no patch policy
- Company files scattered across personal My Drives, one owned by a departed employee
- Folders shared with anyone holding the link, and no record of who held them
- Dozens of third-party apps holding OAuth grants nobody had ever reviewed
The approach
What we did.
We priced staying on Google first — moving up a tier for endpoint management and retention — and the decision turned on the unmanaged Windows fleet and on putting mail, files, and devices behind one directory. Identity and device posture landed before a single mailbox moved: a pilot group, weeks of pre-seeding, then one cutover weekend onto Microsoft 365 Business Premium.
What we delivered
- Conditional Access enforcing MFA tenant-wide, with two monitored break-glass admin accounts excluded
- Entra ID join and Intune on every company laptop, BitLocker enforced with escrowed recovery keys
- Exchange and SharePoint restricted to compliant company devices or app-protected mobile
- Mail, calendar, and contacts migrated in batches, with retention policies suspended so migrated items kept their real dates
- Drive and Shared Drive content moved into OneDrive and SharePoint with sharing rebuilt deliberately rather than inherited
- Defender for Business on every endpoint, and Defender for Office 365 impersonation protection on finance and leadership
- Shared mailboxes replacing generic logins, offboarding that revokes sessions, and a restore-tested backup
The outcomes
What changed.
Every account now sits behind enforced MFA on a managed, encrypted device, and mail, files, and endpoints answer to one directory instead of none. Per-seat licensing costs more than the Google tier they left, and the business accepted that knowingly — device management, EDR, and conditional access were controls it had just been asked to evidence and would otherwise have bought separately. Complex spreadsheets still needed hand-checking after conversion, and external share links had to be reissued.
- Inventoried and remediatedFiles shared with anyone-who-has-the-link
- 0 → 100%Laptops encrypted with escrowed recovery keys
- All; unsanctioned revokedThird-party OAuth grants reviewed
- Completed and timedTested restore of the new tenant
- MFA, EDR, encryptionInsurance controls the business can now evidence
Services involved
The Equal Tech stack behind this engagement.
Managed IT
Proactive monitoring, patching, and unlimited help-desk for desktops, laptops, and end users — flat-fee per seat.
Cybersecurity
Endpoint detection, dark-web monitoring, phishing-resistant MFA, and security awareness training — built for SMBs.
Cloud Services
Microsoft 365, Azure, Google Workspace, hybrid infrastructure, VDI, and immutable cloud backup — designed and operated end-to-end.
CIO Services
Executive-level IT leadership without the executive-level salary — roadmaps, budgets, vendor management, and digital transformation.
More case studies
Other engagements worth a read.
Dental group: HIPAA + Microsoft 365 migration
East TN dental group on a Microsoft 365 reseller, no admin access, HIPAA risk analysis 18 months overdue. We migrated to a direct tenant and closed every gap.
CPA firm: FTC Safeguards + tax-season scaling
Knoxville CPA firm hit FTC Safeguards deadlines and tax-season RDS slowdowns. We built the WISP, moved to Windows 365, and made tax season their fastest ever.
Ready when you are
Let's talk about your IT.
A 30-minute call is all it takes to know whether we're the right partner. No pressure, no jargon, no obligation.
What to expect
- 130-minute discovery call
We listen first — your environment, pain points, and goals.
- 2Free IT assessment
Senior engineer reviews your stack and flags real risks.
- 3Plain-English roadmap
Clear scope, clear pricing. Walk away with a plan, not a pitch.
