Outlook rules are the single fastest way to stop drowning in email. They sort, file, flag and forward messages automatically, the moment they arrive, so your inbox shows you what matters and quietly parks the rest. Combine them with Focused Inbox, Quick Steps and templates, and Outlook starts working for you instead of the other way around.
This is a practical guide to the features that genuinely save time across the new Outlook, Outlook on the web and the classic desktop app. No theory, no clearing of throats. The examples come from configuring Microsoft 365 for Melbourne SMEs day in, day out, and there is a short security note near the end that every business owner should read.
Rules: the workhorse
A rule is a simple instruction: when a message meets a condition, do something with it. When it is from your accountant, move it to the Finance folder. When the subject contains “invoice”, flag it. When it is sent to a distribution list you only skim, mark it read and file it. You build them once and they run forever.
Server-side versus client-side rules
This distinction matters more than most people realise. Server-side rules run on the Exchange Online server, so they work whether or not your computer is on. A rule that files newsletters runs at 2am while your laptop is shut. Client-side rules only run while the classic Outlook desktop app is open and connected, because they depend on something only the desktop app can do.
The trigger for the difference is the action. Conditions and actions that Exchange understands on its own — move, copy, delete, forward, flag, mark as read — stay server-side. The moment a rule includes something the server cannot do, such as “display a desktop alert”, “play a sound”, or “move to a folder in a local PST”, the whole rule becomes client-only. In Outlook you will see these flagged with “on this computer only”.
The practical advice: keep your important filing and forwarding rules server-side so they run reliably from any device, including the Outlook mobile app and the web. Save client-side rules for cosmetic things you genuinely only want while sitting at that one machine. If you live across a desktop, a laptop and your phone, server-side is the only way to get consistent behaviour everywhere.
Where to build them
In the new Outlook and Outlook on the web, go to Settings > Mail > Rules and select Add new rule. In classic desktop Outlook, it is File > Manage Rules & Alerts, or right-click a message and choose Rules > Create Rule to pre-fill the conditions from that message. Building from an example message is the quickest way to get a rule right first time.
Rule recipes that earn their keep
- Tame distribution lists. Mail sent to a group you are on but rarely need urgently: move it to a dedicated folder and mark it read. You read it when you choose, not when it pings.
- Surface the important senders. Mail from your top clients or your boss: flag for follow-up and keep it in the inbox so it never gets buried.
- File the predictable stuff. Statements, system notifications, monitoring alerts and receipts: route straight to topic folders so the inbox stays for things that need a human decision.
- Catch the subject keywords. Anything with “PO”, “RFQ” or a project code in the subject into the relevant project folder, so nothing scatters.
One caution: rules run in order, top to bottom, and some can “stop processing more rules”. A common trap is a tidy-up rule near the top quietly swallowing messages a later rule was meant to catch. Review the order when something stops arriving where you expect it.
Focused Inbox, Other and Sweep
Focused Inbox splits your inbox into two tabs: Focused for the mail Outlook judges important, and Other for the rest — newsletters, notifications, bulk mail. It learns from your behaviour. Move something from Other to Focused a couple of times and it gets the message. It is on by default in most Microsoft 365 tenants and you can toggle it under View > Show Focused Inbox.
People either love it or fight it. The honest take: Focused Inbox is machine-guessed and changes daily, whereas a rule is a guarantee you wrote yourself. Use Focused Inbox as a soft first pass for mail you have not categorised, and use rules for anything where you need certainty. If you turn Focused Inbox off, your rules still do their job.
Sweep is the underused companion. Select a sender, hit Sweep, and you can delete all current mail from them, delete everything older than a set number of days, or keep only the latest and auto-delete the rest going forward. It is the fastest way to clear a sender who emails you forty times a week — a standing instruction rather than a one-off delete.
Quick Steps: one click, several actions
Quick Steps (classic desktop and increasingly the new Outlook) bundle a sequence of actions behind a single button. Where a rule runs automatically, a Quick Step runs when you click it — perfect for the repetitive handling you do by hand.
A help desk in Cremorne we set up uses one called “To Project” that, in a single click, moves the selected email to a project folder, marks it read and categorises it. Other useful ones: “Reply & Archive”, “Forward to team and flag”, or a “Done” button that files and clears. You will find them on the Home ribbon, and you can build your own from the Manage Quick Steps option. Five minutes setting up three Quick Steps removes hundreds of repeated clicks a month.
Templates, My Templates and Quick Parts
If you type the same reply more than twice, template it.
- My Templates is an add-in built into Outlook on the web and the new Outlook. Open the My Templates pane while composing, click a saved snippet, and it drops straight into the message body. Ideal for standard responses — opening hours, “received, we’ll be in touch”, booking confirmations.
- Quick Parts in classic desktop Outlook store reusable blocks of formatted text under Insert > Quick Parts. Better than My Templates when you need formatting, tables or images preserved.
- Email templates proper (.oft files) suit a whole pre-built message you send repeatedly — save via Save As > Outlook Template, reopen via New Items > More Items > Choose Form.
For replies that several staff send identically, templates beat everyone improvising. They keep the wording consistent and on-brand, and they spare you retyping the same paragraph for the hundredth time.
Signatures, and why org-wide ones belong centrally
Per-mailbox signatures are set under Settings > Mail > Compose and reply in the new Outlook, or File > Options > Mail > Signatures in classic desktop. Fine for one person.
For a business, leave individual signatures behind. When everyone manages their own, you get mismatched fonts, dead phone numbers, broken logos and the occasional rogue inspirational quote. Worse, signatures set in Outlook desktop do not follow you to the web or the mobile app, so a phone reply goes out bare. The fix is a centrally managed signature applied at the Microsoft 365 service level — typically a transport rule or a dedicated signature platform — so every message from every device carries a consistent, correct, compliant footer your staff cannot break. We set this up as part of a managed Microsoft 365 environment, and it is one of those small things that quietly makes a business look more professional overnight.
Categories and Search Folders
Colour categories are a flexible tagging layer that works across mail, calendar and tasks. Tag by client, by project, by priority — whatever you actually sort by. Rename the default colours to something meaningful (right-click a message > Categorize > All Categories) and you can later filter or search on them in seconds.
Categories pair beautifully with Search Folders (classic desktop). A Search Folder is a saved, live view that gathers every message matching a rule no matter which folder it physically lives in — “all unread”, “flagged for follow-up”, “anything categorised Urgent”. The mail stays put; the Search Folder is just a smart window onto it. Set up two or three and you stop hunting through folders.
Scheduling: Calendar and Bookings
For internal scheduling, the Outlook calendar’s Scheduling Assistant shows colleagues’ free/busy so you stop the back-and-forth of finding a slot. For external scheduling, Microsoft Bookings — included in most Microsoft 365 Business plans — gives clients a public page to book a time against your real availability, with automatic confirmations and reminders. A consultancy in Box Hill we work with replaced a week of email tag with a Bookings page link in their signature; clients self-serve and the calendar fills itself.
Microsoft 365 mailbox hygiene
Rules and folders only help if the mailbox underneath is healthy.
- Archive, do not hoard. Use the Online Archive (auto-expanding in most business plans) and a retention/archive policy so the primary mailbox stays lean. Searching a 90GB mailbox is slow and painful.
- Unsubscribe, do not just delete. If you delete the same newsletter daily, you are doing manual labour a single unsubscribe would end.
- Audit your rules quarterly. Old rules forwarding to a former colleague, or filing into a folder nobody opens, accumulate quietly. Prune them.
- Keep it in folders, not the inbox. A 12,000-message inbox is a search problem waiting to happen. Let rules and Quick Steps do the filing.
A security note on forwarding rules
This one is not optional reading. Auto-forwarding rules — especially ones that quietly send copies of mail to an external address — are a classic indicator of a business email compromise (BEC). When an attacker phishes a mailbox, one of the first things they do is create a hidden rule that forwards finance-related mail out, or deletes the attacker’s own messages so the real user never sees the fraud playing out. Many breaches run for weeks behind a single forwarding rule nobody noticed.
Treat any unexpected forwarding rule, or a rule sending mail straight to Deleted Items or RSS Feeds, as a red flag worth investigating immediately. In a well-run tenant, external auto-forwarding is blocked or alerted on by default, and we monitor for rule changes as part of mailbox security. If you want the detail on how these attacks work and how to defend against them, our guide to business email security, phishing and BEC walks through it. Convenience features and attacker tools share the same plumbing here — which is exactly why the plumbing needs watching.
Frequently asked questions
Do my Outlook rules work when my computer is off?
Only if they are server-side rules. Move, forward, flag, delete and mark-as-read actions run on the Exchange Online server and work around the clock from any device. Rules with desktop-only actions — alerts, sounds, or moving to a local PST — run solely while the classic desktop app is open and are labelled “on this computer only”.
Should I use Focused Inbox or rules?
Both, for different jobs. Focused Inbox is an automatic best-guess that adapts over time and suits mail you have not specifically sorted. Rules are guarantees you write yourself for senders or subjects where you need certainty. Rules keep working whether Focused Inbox is on or off.
How do I save email templates for replies I send constantly?
Use My Templates (the snippet pane in Outlook on the web and new Outlook) for quick text blocks, Quick Parts in classic desktop when you need formatting preserved, or a saved .oft template for an entire pre-built message. For replies several staff send identically, templates keep the wording consistent.
Why should signatures be managed centrally?
Because signatures set in one Outlook app do not follow you to the web or mobile, and self-managed signatures drift into broken logos, dead numbers and inconsistent formatting. A signature applied at the Microsoft 365 service level applies to every message from every device, stays consistent, and cannot be broken by individual users.
Are forwarding rules dangerous?
Legitimate ones are fine, but an unexpected rule that forwards mail to an external address is one of the most common signs of a compromised mailbox. Attackers use them to siphon finance emails or hide their tracks. Review your rules periodically and have external auto-forwarding blocked or alerted on at the tenant level.
Make Outlook earn its keep
None of this needs new software — it is all sitting in the Microsoft 365 you already pay for. An hour spent building a handful of rules, a few Quick Steps and some templates pays itself back every single week. The catch is doing it properly: server-side where it counts, central signatures, sensible retention, and a tenant configured so the convenience features cannot be turned against you.
We are a Melbourne-based MSP with 13 Australian-employed engineers, and getting clients the full value of their Microsoft 365 — configured securely, not just switched on — is core to what we do. If you would like your tenant set up so Outlook genuinely works for your team, get in touch and we will sort it.
Microsoft Purview is Microsoft’s data governance and compliance suite inside Microsoft 365 — the rebranded, expanded successor to what used to be called the Microsoft 365 Compliance Centre. It is how you classify, protect, retain and audit your organisation’s data, and it is the layer that decides what Copilot is allowed to see.
For a Melbourne SME, the practical question is not “what is Purview” but “which bits do I already pay for, and what should I switch on first?” This post answers both, without the marketing gloss.
What Microsoft Purview actually is
Purview is an umbrella brand. Under it sit a set of tools that used to be scattered across separate portals. They are now grouped at purview.microsoft.com and broadly cover two jobs: knowing where your sensitive data is, and controlling what happens to it.
The capabilities that matter to most small and mid-sized businesses are:
- Sensitivity labels — tags like Confidential or Internal that travel with a file or email and can enforce encryption and access rules.
- Data Loss Prevention (DLP) — rules that stop sensitive data, such as credit card or Tax File Numbers, from leaving the organisation by email, Teams or to USB.
- Retention policies and labels — rules that keep records for a set period and delete them when they expire, which is how you meet records-keeping obligations without hoarding everything forever.
- eDiscovery — the ability to search across mailboxes, SharePoint and Teams to find content for a legal matter, dispute or regulator request.
- Audit — a searchable log of who did what: who opened a file, who deleted a mailbox item, who changed a permission.
- Insider risk management — analytics that flag risky behaviour, such as a departing employee mass-downloading client files.
- Communication compliance — monitoring of internal messaging for harassment, code-of-conduct breaches or regulated-industry conduct rules.
You will not use all of these on day one, and you should not try to. The point is that Purview is where data governance lives once you decide to take it seriously.
What you get with Business Premium, and what needs E5
This is where most decisions get made, because the licensing split is real and it is easy to overspend or assume you have features you do not.
Microsoft 365 Business Premium — the plan most Melbourne SMEs land on — includes a genuinely useful slice of Purview. You get manual sensitivity labels, basic DLP for Exchange, SharePoint, OneDrive and Teams, basic retention policies, standard audit logging, and basic eDiscovery (search and export). For a business under 300 seats, that is enough to make a real difference.
The advanced tier sits behind Microsoft 365 E5, the E5 Compliance add-on, or standalone Purview add-ons. That is where you find automatic labelling, DLP that extends to endpoints and browsers, communication compliance, insider risk management, eDiscovery (Premium) with legal hold and review sets, and longer audit retention.
| Capability | Business Premium | E5 / E5 Compliance |
|---|
| Sensitivity labels (manual) | Yes | Yes |
| Automatic labelling | No | Yes |
| DLP for Exchange, SharePoint, OneDrive, Teams | Yes (basic) | Yes |
| Endpoint DLP (USB, browser, copy) | No | Yes |
| Retention policies and labels | Yes (basic) | Yes (auto-apply, event-based) |
| eDiscovery | Standard (search and export) | Premium (legal hold, review sets) |
| Audit | Standard | Long-term retention |
| Insider risk management | No | Yes |
| Communication compliance | No | Yes |
The honest advice: do not buy E5 because the feature list looks impressive. Buy it when you have a specific obligation — a regulator, an insurer, a contract — that needs automatic labelling, endpoint DLP or insider risk. Most SMEs get years of value out of the Business Premium tier first. If you are weighing up the plans, our guide to what is included with Microsoft 365 support in Melbourne sets out where the lines fall.
What to do first: labels and DLP
If you take one thing from this post, take this. Start with sensitivity labels and DLP. They give you the most protection for the least effort, and everything else builds on them.
Sensitivity labels
A sensitivity label is a tag a user applies to a document or email. A typical SME set is three or four labels: Public, Internal, Confidential, and perhaps Highly Confidential. The label can be cosmetic (a footer marking) or it can enforce real controls — encryption, a watermark, blocking external sharing.
Start cosmetic, get people used to choosing a label, then add enforcement to the top one or two. A label that encrypts Confidential files means a document forwarded to the wrong address is unreadable to the recipient. That single control has saved more SMEs than any firewall rule.
Data Loss Prevention
DLP inspects content against patterns and conditions you set, then acts. The patterns Australian businesses care about are built in or easy to define: Tax File Numbers, Medicare numbers, credit card numbers, ABNs, driver licence details. A starter DLP policy might warn a user — or block outright — when they try to email a spreadsheet containing more than a handful of TFNs to an external address.
Begin every DLP rule in audit-only mode. Let it run for a fortnight, see what it would have flagged, and tune out the false positives before you switch to blocking. Turn DLP straight to block on day one and you will have the finance team locked out of legitimate work by Tuesday. DLP sits naturally alongside the rest of your cyber security services stack — it is the data-layer complement to identity controls like conditional access.
Retention, eDiscovery and audit: the records side
The governance half of Purview is about keeping the right things for the right length of time, and being able to find them.
Retention answers a question every business eventually faces: how long do we keep this? Some records have legal minimums — employee records under the Fair Work Act, financial records under the Corporations Act, health records under state health-records legislation. Retention policies enforce those minimums automatically and, just as importantly, delete data once the obligation lapses so you are not holding a decade of client files that are now pure liability.
eDiscovery earns its keep the day you receive a subpoena, a Fair Work claim or an OAIC enquiry. Instead of an engineer manually trawling mailboxes, you run a content search across Exchange, SharePoint and Teams and export exactly what is in scope. Standard eDiscovery in Business Premium handles most SME needs.
Audit is the quiet hero. When something goes wrong — a deleted file, a mailbox rule someone did not set, a permissions change — the audit log tells you who and when. It is also frequently the first thing a cyber insurer or incident responder asks for. If you are thinking about coverage, audit logging is part of what makes a claim defensible; our cyber insurance guide for Australian SMEs covers the broader picture.
Governance before AI: Purview and Copilot
This is the use case pushing Purview up the priority list for 2026. Microsoft 365 Copilot answers questions using your organisation’s data — every file, email and chat the asking user already has permission to see. That is the catch. Copilot does not break permissions; it surfaces what loose permissions already expose.
If your SharePoint has a “Company” site everyone can read, and someone parked the payroll spreadsheet there three years ago, Copilot will happily summarise salaries when an employee asks. The file was always accessible — nobody ever browsed to it. Copilot removes that friction.
This is why governance comes before AI, not after. Sensitivity labels let you mark and encrypt the data Copilot should never reuse. DLP and retention reduce the volume of stale, mislabelled data sitting in shared locations. Auditing tells you what Copilot has been asked. Switching on Copilot without doing this first is how a tidy-looking rollout becomes a quiet data-exposure incident.
The same logic applies to the Privacy Act 1988. Under the Australian Privacy Principles, you are obliged to take reasonable steps to protect personal information and to not keep it longer than needed. Reforms now working through Parliament are tightening those expectations, including around automated decision-making and data minimisation. Purview’s labelling, DLP and retention are precisely the “reasonable steps” the Office of the Australian Information Commissioner (OAIC) expects you to be able to demonstrate.
A Hawthorn scenario
A professional services firm in Hawthorn we work with wanted to roll out Copilot across forty staff. Before flicking it on, we ran a labelling and permissions review. We found three SharePoint sites with broad read access holding client financials and a folder of scanned passports from an old onboarding process. We applied Confidential labels with encryption to the sensitive sites, tightened the permissions, set a DLP rule on TFNs and Medicare numbers, and added a retention policy that purged the passport scans that should have been deleted years earlier. Copilot went live two weeks later — on data that was actually governed. The firm now has something concrete to show their professional indemnity insurer.
That sequence — govern, then enable — is the whole game. TechAssist has run Microsoft 365 for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma, and the Purview-before-Copilot review has become one of the more common pieces of work we do.
Frequently asked questions
Is Microsoft Purview a separate product I have to buy?
No. Purview is the brand for governance and compliance tools built into Microsoft 365. A meaningful set is already included with Business Premium. You only pay extra — through E5 or the E5 Compliance add-on — for advanced features such as automatic labelling, endpoint DLP and insider risk management.
What is the difference between sensitivity labels and retention labels?
Sensitivity labels control protection — encryption, access and markings on a file. Retention labels control lifecycle — how long an item is kept and when it is deleted. They solve different problems and you typically use both: sensitivity to protect, retention to keep or dispose.
Do I need Purview before turning on Copilot?
You should. Copilot surfaces anything the asking user can already access, so existing over-permissioned data becomes far easier to stumble across. Sorting out labels, permissions and DLP first stops Copilot turning a hidden exposure into an obvious one.
Does Purview help with the Privacy Act?
It helps you demonstrate compliance. The Australian Privacy Principles require reasonable steps to protect personal information and to not retain it beyond need. Purview’s DLP, sensitivity labels and retention policies are practical, auditable controls that show the OAIC you have taken those steps.
Where to start
Do not boil the ocean. Pick three or four sensitivity labels, switch on a couple of DLP rules in audit mode, and set retention on your one or two most regulated record types. That alone puts you ahead of most SMEs and gives you a defensible governance baseline — and the foundation you need before any AI tool touches your data.
If you would like a hand scoping a Purview rollout, sorting your Microsoft 365 licensing, or running a governance review before you enable Copilot, get in touch with TechAssist. We will tell you plainly what you already have, what is worth turning on, and what you can safely leave alone.
For most Australian SMEs the honest answer to Microsoft 365 vs Google Workspace comes down to how your team actually works. Google suits lean, cloud-native businesses that live in a browser. Microsoft suits desktop-heavy, Windows-fleet, compliance-driven operations. Both are mature, secure platforms — the wrong fit just costs you in friction.
We’re a Microsoft-centric MSP, so I’ll declare that bias up front. But there are plenty of Melbourne businesses where I’d point a client to Google without hesitation. This is a fair comparison, not a sales pitch, and below there’s a table to cut through the marketing on both sides.
The quick comparison
| Area | Microsoft 365 | Google Workspace |
|---|
| Productivity apps | Full desktop Word, Excel, PowerPoint, Outlook (plus web versions) | Web-first Docs, Sheets, Slides — fast, but lighter than desktop Office |
| Email | Exchange Online + Outlook — rich rules, shared mailboxes, calendaring | Gmail — excellent search and spam filtering, simpler admin |
| Storage | OneDrive (per user) + SharePoint (team sites), 1 TB+ per user | Google Drive + Shared Drives, pooled storage by tier |
| Meetings & chat | Teams — meetings, chat, calls, channels, deep app integration | Google Meet + Google Chat/Spaces — clean, lightweight |
| Identity | Microsoft Entra ID — granular conditional access, hybrid AD | Google identity / Cloud Identity — strong, but less enterprise-deep |
| Admin & security | Defender, Purview, very granular controls — steep but powerful | Admin console — simpler, faster to learn, fewer knobs |
| Data residency (AU) | Australian data centres available for core data at rest | Regional storage options; some data still processed globally |
| Entry pricing (AUD, ex GST) | Business Basic ~$8.20/user/mo; Standard ~$17.20; Premium ~$30.20 | Business Starter ~$10/user/mo; Standard ~$20; Plus ~$32 |
| Best fit | Desktop-heavy, Windows fleets, regulated industries | Cloud-native startups, lean teams, browser-first work |
Pricing changes regularly and varies by term and reseller, so treat those figures as a guide rather than a quote. The real cost difference between the two is usually rounding error compared with the cost of choosing the platform that fights your workflow.
Apps: desktop power vs web speed
This is the clearest fork in the road. Microsoft gives you the full desktop Office suite — the real Excel, with the pivot tables, Power Query, macros and add-ins that finance teams and engineers depend on. If your business runs complex spreadsheets, branded Word templates, or PowerPoint decks that have to look identical every time, desktop Office still has no equal.
Google Workspace is web-first and proud of it. Docs, Sheets and Slides load instantly, autosave constantly, and make real-time co-editing feel effortless. For a marketing agency or a startup where two people are in the same document at once all day, that collaboration model is genuinely better. The trade-off is depth: heavy Excel users hit Sheets’ ceiling quickly, and complex formatting can drift.
Where Google clearly wins: if your team already does everything in a browser and nobody opens a desktop app from one week to the next, paying for desktop Office you’ll never install is waste.
Email: Outlook vs Gmail
Exchange Online with Outlook is the workhorse of Australian business email. Shared mailboxes, delegate access, distribution groups, calendar scheduling across a team — it’s all mature and granular. For a law firm in Hawthorn juggling shared client inboxes and rigid retention rules, Exchange and Microsoft Purview make that straightforward.
Gmail’s strength is search and filtering. Its spam and phishing detection is excellent, the interface is clean, and conversation threading is hard to beat. Smaller teams often find Gmail simply gets out of the way. Either way, email is your single biggest attack surface — we cover that in our guide to business email security and BEC, and the controls matter more than the brand.
Storage: OneDrive/SharePoint vs Drive
Microsoft splits storage into OneDrive (your personal files) and SharePoint (team document libraries). Done well, SharePoint is a proper intranet and document-management system with versioning, metadata and permissions. Done badly, it’s a sprawl of sites nobody can navigate. It rewards structure.
Google Drive with Shared Drives is more intuitive out of the box. Files live where you’d expect, sharing is a couple of clicks, and there’s less to misconfigure. For a business that just wants files in folders without a SharePoint information-architecture project, Drive is the gentler path.
Meetings: Teams vs Meet and Chat
Teams is the centre of gravity in the Microsoft world — meetings, calls, persistent chat, channels and an app platform all in one. For organisations already on Microsoft, that integration is a real advantage; for ones that aren’t, Teams can feel like a lot. Plenty of people find it heavy.
Google Meet and Google Chat are deliberately lighter. Meet is reliable, browser-based and quick to join with no client to install. If your meetings are mostly external and you value “click the link and you’re in”, Meet’s simplicity is a genuine plus. Microsoft’s edge shows up in internal collaboration depth, calling features and telephony integration.
Identity, admin and security
This is where Microsoft pulls ahead for businesses that need it. Microsoft Entra ID (the identity platform formerly known as Azure AD) offers some of the most granular access controls available — you can require multi-factor authentication only from unmanaged devices, block sign-ins from outside Australia, or enforce compliant-device checks. We walk through this in our piece on conditional access policies in Microsoft 365. Defender and Purview add threat protection and data-loss prevention that map neatly onto frameworks like the Essential Eight.
Google’s admin console is more approachable. Fewer settings means less to get wrong, which for a small team without dedicated IT is a real benefit. Google’s identity and security are strong — context-aware access and solid MFA — but Microsoft’s controls go deeper for complex, regulated or hybrid environments where on-premises Active Directory is still in the mix.
Compliance and data residency
For Australian businesses bound by the Privacy Act and the OAIC’s Notifiable Data Breaches scheme, data residency and auditability matter. Microsoft offers Australian data centres for core data at rest and gives detailed control over retention, legal hold and audit logging through Purview — useful for sectors under AHPRA, ASIC or similar oversight.
Google Workspace provides regional storage options and strong compliance certifications, though some processing still happens across its global infrastructure. For most SMEs that’s perfectly acceptable. For a healthcare practice or a firm with strict data-handling obligations, Microsoft’s granular controls usually make the compliance conversation easier — see our notes on healthcare IT and OAIC obligations.
Migration effort
Moving platforms is rarely trivial. Email migrates reasonably well in both directions, but the friction lives in the details: shared mailboxes, calendar permissions, distribution lists, and re-training people on a new interface. Document migration is messier — Google formats don’t always survive a clean trip into Office, and complex Excel or SharePoint structures don’t always land neatly in Sheets and Drive.
The practical rule is to migrate once, deliberately, and stay put. Bouncing between platforms because of a price tweak costs far more in lost time than it saves. Whichever way you go, plan the cutover properly and run the two systems in parallel briefly so nothing falls through the cracks.
A Melbourne example
A construction firm in Box Hill we work with came to us split down the middle — the site teams lived in Gmail on their phones, while the office ran Excel-heavy estimating and project schedules that Sheets simply couldn’t handle. They’d been arguing about it for a year. We standardised them on Microsoft 365 because the desktop Office dependency was non-negotiable for their estimators, then used Teams to pull the field and office staff onto one platform. Had their work been browser-only, we’d have recommended Google and meant it.
That’s the point. TechAssist is a Melbourne-based MSP founded in 2014 with 13 Australian-employed engineers, and most of our client base runs Microsoft because that’s where desktop-heavy, compliance-driven Australian businesses tend to land. But the right answer is the one that fits how your people actually work, not the one your MSP is most comfortable supporting.
Frequently asked questions
Is Microsoft 365 more secure than Google Workspace?
Neither is inherently more secure — both are mature, well-defended platforms. The difference is control depth. Microsoft Entra ID and Defender offer more granular configuration, which helps in regulated or complex environments. Google’s simpler model means fewer settings to misconfigure, which suits smaller teams. Security comes from how you configure either platform, not the logo.
Can I run both Microsoft 365 and Google Workspace?
You can, and some businesses do — for example, Microsoft for email and Office, Google for a specific cloud tool. But running both means two sets of licences, two admin consoles and two security surfaces to manage. For most SMEs the overhead outweighs the benefit. Pick one as your primary platform.
Which is cheaper for a small Australian business?
Entry tiers are close — Microsoft 365 Business Basic and Google Business Starter sit within a few dollars of each other per user per month. The bigger cost is fit: paying for desktop Office you never use, or wrestling with Sheets when you need real Excel, costs far more than the licence-price gap.
How hard is it to migrate from Google to Microsoft?
Email migrates fairly cleanly; documents and shared-drive structures are where the work lives. Expect format conversion, permission rebuilding and user re-training. With a planned cutover and a short parallel-run period it’s very manageable — the mistake is doing it ad hoc without a migration plan.
Getting the decision right
If your business is lean, cloud-native and browser-first, Google Workspace is a strong, often better choice — and we’ll tell you so. If you’re desktop-heavy, running a Windows fleet, or carrying real compliance obligations, Microsoft 365 usually wins, and it’s where our Microsoft 365 support is built to add the most value with security and identity configured properly rather than left on defaults.
Not sure which way to jump? Get in touch and we’ll look at how your team actually works before recommending anything. No pressure to switch, and an honest answer either way.
Windows Autopilot is a Microsoft service that lets a brand-new laptop set itself up automatically the first time a staff member turns it on. The device ships from the vendor straight to the user, connects to your Microsoft tenant over the internet, and configures itself — no imaging, no SOE, no IT hands on it.
If onboarding a new hire still means a laptop landing on an engineer’s desk for a day of imaging, this is the fix. Below: what Autopilot does, how a device self-provisions, the moving parts, the deployment modes, the licensing, and where an MSP fits in.
What Windows Autopilot actually is
Autopilot is not an imaging tool — there is no gold image and no USB stick. It takes the standard Windows installation the manufacturer already put on the device and transforms it into your corporate build during the out-of-box experience (the setup screens a user sees on first boot). It runs on two Microsoft cloud services: Microsoft Entra ID (formerly Azure AD) handles identity and joins the device to your directory, and Microsoft Intune — the mobile device management (MDM) platform inside Microsoft 365 — pushes down your policies, apps, baselines and configuration. A machine the user has never touched arrives configured exactly like every other device in the business, enrolled, encrypted and ready to work.
The problem it solves: no more manual imaging or SOE
The traditional approach was the Standard Operating Environment: you built a master image, captured it, and re-applied it to every new or rebuilt machine. The costs add up. Devices have to be shipped to IT first, imaged, then re-shipped to the user — adding days and double the freight. The image goes stale the moment it is captured and needs constant rebuilding. And it does not scale: imaging a laptop for someone starting in a Dandenong warehouse means shipping it to your office or sending an engineer out.
Autopilot removes the imaging step entirely. The configuration lives in the cloud and is applied at first boot, so the same provisioning works whether the user is in your CBD office or at home in Ringwood.
How a device self-provisions on first login
The sequence when an Autopilot-registered device is unboxed:
- The user powers on the laptop and connects to Wi-Fi or ethernet — internet access is the only prerequisite.
- Windows checks in with Autopilot, recognises the device by its hardware identity, and pulls down the assigned profile, which customises the setup screens and applies your branding.
- The user signs in with their Microsoft 365 work account; Entra ID authenticates them and joins the device to your directory.
- Intune enrolment kicks off automatically, pulling down your configuration profiles, security baseline, certificates, Wi-Fi settings and assigned apps.
- The Enrollment Status Page blocks the user from reaching the desktop until the mandatory apps and policies have landed.
When it finishes, the first person to log into that machine is the staff member it was bought for — not an engineer — at a fully managed, encrypted desktop.
The moving parts
Autopilot profiles
A profile is the deployment template you assign to a group of devices in Intune. It controls the out-of-box experience: which setup screens are hidden, whether the user becomes a local administrator or standard user, the deployment mode, the naming convention and your branding. Most businesses run one or two — a user-driven profile for staff laptops, sometimes a separate one for shared devices.
The Enrollment Status Page
The Enrollment Status Page (ESP) shows setup progress and gates access to the desktop until the apps and policies you mark mandatory have installed — so a new starter cannot begin work on a half-configured machine. Block on a slow or flaky app, though, and you leave users staring at a spinner; tuning it well is one of the fiddlier parts of the job.
Hardware hash and device registration
Autopilot identifies each device by a hardware hash — a unique fingerprint of its components — which must be registered against your tenant before first boot. With OEM / CSP registration, the hardware vendor or Cloud Solution Provider partner registers the hash to your tenant at purchase, so the device is Autopilot-ready before it leaves the warehouse — the clean path for volume orders. For devices you already own, manual hash collection exports the hash into Intune with a PowerShell script, but that means handling the device once. Build OEM or CSP registration into your procurement so hardware arrives pre-registered; that is what makes true drop-ship onboarding possible.
Deployment modes: user-driven vs self-deploying and kiosk
Autopilot supports several modes, depending on how the device will be used:
| Mode | How it works | Best for |
|---|
| User-driven | User signs in with their work account; the device joins Entra ID and binds to them | Standard staff laptops |
| Self-deploying | No credentials entered; the device provisions itself end to end, using the TPM to prove its identity | Shared devices, digital signage, meeting-room PCs |
| Kiosk | A self-deploying device locked to a single app, with no general desktop | Front-of-house terminals |
User-driven is what most growing teams use. Self-deploying and kiosk modes suit devices no single staff member owns — a reception terminal in a Hawthorn clinic, a warehouse scanning station — and need a TPM 2.0 chip, which any recent business device has.
Prerequisites: what you need before you start
Autopilot is not a standalone product — it is a capability on top of Microsoft 365. You need:
- Microsoft Entra ID for identity and device join — the standard directory in a Microsoft 365 business or enterprise subscription covers this, though some advanced enrolment options want Entra ID P1.
- Microsoft Intune licensing for the MDM management — included in Microsoft 365 Business Premium and the E3/E5 plans. On a cheaper plan you will need to add Intune first.
- Devices that ship with Windows 11 Pro or Enterprise — the Home edition cannot be managed this way.
- A configured tenant — your Intune profiles, security baselines, app deployments and ESP set up before the first device ships.
That last point is the one businesses underestimate: Autopilot delivers whatever you have built in Intune, so the value is in the policies and app packaging, not the provisioning trick itself. If you are reviewing your licensing, our Microsoft 365 support team can tell you whether your plan already covers what Autopilot needs.
Why this matters: fast onboarding and consistent security baselines
Two things drive most businesses to Autopilot. The first is onboarding speed: a drop-shipped self-provisioning laptop takes the engineer, the queue and the freight out of every hire. The second, and arguably more important, is consistent security baselines. Because every device is built from the same Intune configuration, every machine gets BitLocker encryption, the same firewall and account-protection policies, Defender, conditional access and patching automatically — no engineer remembering to tick a box. An enforced baseline across the fleet is exactly what the Essential Eight mitigation strategies expect, and the same Intune layer lets you wipe a lost device remotely the moment a laptop goes missing on a train at Box Hill — it pairs naturally with conditional access policies in Microsoft 365.
A Melbourne scenario
An engineering consultancy in Camberwell we work with was hiring two or three people a month and rebuilding laptops by hand each time — a machine couriered to their office, half a day of imaging, and a checklist someone occasionally skipped, so no two laptops were quite the same and a couple shipped without disk encryption on.
We stood up their Intune configuration, built a user-driven Autopilot profile with a tuned Enrollment Status Page, and arranged for new hardware to be registered at purchase. Now a laptop is drop-shipped to the new hire; they open the box, sign in, and an hour later are working on a fully configured, encrypted device identical to everyone else’s. Their office manager handles onboarding without touching a technical step, and the fleet has a uniform baseline at last.
The MSP role in setting it up
The provisioning is the easy part to demonstrate and the hard part to build well. The work an MSP does sits underneath what the user sees:
- Designing and hardening the Intune configuration — the compliance policies, configuration profiles, security baselines and app deployments every machine inherits — and packaging line-of-business apps to install silently during enrolment.
- Setting up the procurement pipeline so devices arrive Autopilot-ready, tuning the ESP, and integrating Autopilot with conditional access, encryption and your broader MDM strategy so device management is one coherent system.
TechAssist is a Melbourne MSP, founded in 2014, with thirteen Australian-employed engineers — so the people building your Intune environment are local, not offshore. We bundle this into our managed IT services, so device provisioning, patching and security baselines sit inside the fixed monthly per-user fee, not a per-device charge each time you hire.
Frequently asked questions
Do I need to wipe a new laptop before using Autopilot?
No. Autopilot works with the standard Windows installation the manufacturer ships and transforms it into your corporate configuration during first boot — there is no wiping or imaging step. Devices you already own can be reset and will provision on the next boot once registered.
What happens if there is no internet during setup?
Autopilot needs internet to reach Entra ID and Intune, so the device must connect to Wi-Fi or ethernet during the out-of-box experience. Until it does, the laptop sits at the network screen — which is why drop-ship onboarding assumes the user has working internet.
Is Autopilot the same as Intune?
No, but they work together. Intune is the management platform that holds your policies, apps and baselines; Autopilot hands a new device over to Intune at first boot. You need Intune licensing for Autopilot to do anything.
Where TechAssist fits
Autopilot looks like magic in a demo and falls over in practice if the Intune configuration behind it is thin — the provisioning is the visible part, but the policies, baselines and procurement pipeline are what make the fleet secure and consistent. If manual device setup is slowing your onboarding, get in touch and we will scope what your tenant needs.