Most small businesses on Microsoft 365 are running whatever configuration got them through their first sign-up, plus whatever got bolted on since. That's not a criticism — it's just how it goes when there's no one dedicated to keeping the settings intentional. Here's what a clean setup actually covers.

Microsoft 365 admin cleanup

The admin center accumulates clutter fast: unused licenses still being paid for, mailboxes for people who left months ago, sharing settings that were opened up for a one-time project and never closed back down. A cleanup pass means going through the tenant with fresh eyes — matching licenses to actual users, confirming distribution groups and shared mailboxes still serve a purpose, and tightening sharing defaults back to something sensible.

Intune policy review

Intune is Microsoft's device management layer — the equivalent of what Jamf does for Apple, but for Windows, and it can also manage iOS and Android. A policy review means checking what compliance and configuration policies actually exist, whether they're being applied to the right groups of devices, and whether there are gaps — devices enrolled but not covered by any meaningful policy, which happens more often than you'd expect.

Security baseline enforcement

This is the practical floor: multi-factor authentication required across the org, conditional access rules that make sense for how the business actually works, and device compliance requirements (encryption, screen lock, minimum OS version) enforced rather than just recommended. None of this is exotic — it's the baseline most breaches happen because someone skipped.

Endpoint compliance and lifecycle documentation

Beyond the baseline, compliance basics cover things like patch status and antivirus health being visible in one place instead of guessed at. And because none of this stays static, a written lifecycle process — what happens when a device is issued, when it's retired, when an employee leaves — means the next person doesn't have to reconstruct the logic from scratch.

Where Jamf fits in if you're on both platforms

If the business runs a mix of Windows and Apple devices, Intune and Jamf typically split the work: Intune covers Windows (and can technically manage Apple and Android devices too), while Jamf handles the deeper, Apple-specific management most businesses actually want for their Macs and iPhones. Getting the division of responsibility right up front avoids devices falling into a gap between the two.