Skip to content
Equal Tech Solutions
Anonymized client engagement

How a 40-person business moved off Google Workspace and put every account behind managed identity

Small business2026

~40-employee business · one office + field staff · Cleveland, TN

Result 01
100%
Accounts with MFA enforced
Result 02
0 → 100%
Company laptops managed and encrypted
Result 03
One weekend
Mail cutover window

The challenge

Where they started.

Google Workspace itself ran fine — Gmail’s filtering was genuinely good. The gap was configuration, and the fact that nobody was watching the console: 2-Step Verification was available but optional, a permissive link-sharing policy let staff share folders with anyone holding the URL, and the Windows laptops had no directory behind them at all. Then a cyber-insurance renewal asked how the business enforced MFA, protected endpoints, and encrypted disks. Nobody could attest to any of the three.

Specific pain points

  • 2-Step Verification available but never enforced — roughly half the staff had skipped it
  • Windows laptops unmanaged: no directory, no disk encryption, no patch policy
  • Company files scattered across personal My Drives, one owned by a departed employee
  • Folders shared with anyone holding the link, and no record of who held them
  • Dozens of third-party apps holding OAuth grants nobody had ever reviewed

The approach

What we did.

We priced staying on Google first — moving up a tier for endpoint management and retention — and the decision turned on the unmanaged Windows fleet and on putting mail, files, and devices behind one directory. Identity and device posture landed before a single mailbox moved: a pilot group, weeks of pre-seeding, then one cutover weekend onto Microsoft 365 Business Premium.

What we delivered

  • Conditional Access enforcing MFA tenant-wide, with two monitored break-glass admin accounts excluded
  • Entra ID join and Intune on every company laptop, BitLocker enforced with escrowed recovery keys
  • Exchange and SharePoint restricted to compliant company devices or app-protected mobile
  • Mail, calendar, and contacts migrated in batches, with retention policies suspended so migrated items kept their real dates
  • Drive and Shared Drive content moved into OneDrive and SharePoint with sharing rebuilt deliberately rather than inherited
  • Defender for Business on every endpoint, and Defender for Office 365 impersonation protection on finance and leadership
  • Shared mailboxes replacing generic logins, offboarding that revokes sessions, and a restore-tested backup

The outcomes

What changed.

Every account now sits behind enforced MFA on a managed, encrypted device, and mail, files, and endpoints answer to one directory instead of none. Per-seat licensing costs more than the Google tier they left, and the business accepted that knowingly — device management, EDR, and conditional access were controls it had just been asked to evidence and would otherwise have bought separately. Complex spreadsheets still needed hand-checking after conversion, and external share links had to be reissued.

  • Inventoried and remediated
    Files shared with anyone-who-has-the-link
  • 0 → 100%
    Laptops encrypted with escrowed recovery keys
  • All; unsanctioned revoked
    Third-party OAuth grants reviewed
  • Completed and timed
    Tested restore of the new tenant
  • MFA, EDR, encryption
    Insurance controls the business can now evidence

Ready when you are

Let's talk about your IT.

A 30-minute call is all it takes to know whether we're the right partner. No pressure, no jargon, no obligation.

What to expect

  1. 1
    30-minute discovery call

    We listen first — your environment, pain points, and goals.

  2. 2
    Free IT assessment

    Senior engineer reviews your stack and flags real risks.

  3. 3
    Plain-English roadmap

    Clear scope, clear pricing. Walk away with a plan, not a pitch.