Software Licence Compliance: Surviving a Microsoft True-Up

Software licence compliance means you hold a valid, paid licence for every copy of every program your business runs. A vendor “true-up” or audit is when Microsoft, Adobe, Autodesk or another publisher checks whether what you’ve deployed matches what you’ve bought. Get it wrong and the bill arrives at list price.

What a true-up and an audit actually are

The two terms get used interchangeably, but they’re not the same thing. A true-up is the reconciliation built into a volume licensing agreement. If you signed a Microsoft Enterprise Agreement or similar, you committed to a baseline number of licences and agreed to “true up” annually for anything extra you deployed during the year. It’s routine accounting: you report the additional seats, you pay for them, the agreement rolls on. Where it bites is when nobody has tracked the additions and the annual reconciliation surfaces twelve months of unlicensed growth at once.

An audit is the adversarial version. The vendor, or a third party acting for them, exercises the audit clause in your licensing contract and asks you to prove compliance. They’ll count installs against entitlements and present you with a “compliance gap”. A right to audit is written into almost every software agreement you’ve ever clicked through. Microsoft, Adobe and Autodesk all do it, and so do Oracle, SAP and IBM, who are notoriously aggressive about it.

Why vendors audit

Because it pays. Software is one of the few products where the customer self-reports how much they’re using, and self-reporting drifts. In any business of reasonable size, deployment creeps past entitlement as staff are added, machines are reimaged and VMs are spun up. An audit converts that drift into revenue, usually at full list price with no discount.

The triggers are predictable: a sharp drop in renewal spend, a merger or acquisition, switching away from a vendor’s product, a jump in headcount, or simply the random rotation a publisher runs through its mid-market customers. Subscription licensing has made it easier still: when your software phones home, the vendor already knows who’s using what before they send a letter.

How SMEs end up non-compliant

Almost no one sets out to pirate software. Non-compliance is nearly always sloppiness, not theft, and it accumulates quietly. These are the patterns we see most across Melbourne SMEs.

  • Over-deployment. You bought 40 Microsoft 365 licences, you’ve grown to 52 staff, and the extra dozen are using the platform on borrowed credentials or seats that were never purchased. The headcount moved; the licence count didn’t.
  • Wrong licence type for the use. Running software licensed for development on a live production server, or using education and not-for-profit pricing in a commercial entity that no longer qualifies.
  • Mixing Business and Enterprise plans. Microsoft 365 Business plans (Basic, Standard, Premium) are capped at 300 seats. Plenty of growing firms blow past 300 users still stacking Business licences, when they should have moved to Enterprise (E3/E5) plans.
  • Client Access Licences (CALs). On-premises Windows Server and SQL Server still need a CAL for every user or device that connects. CALs are the most commonly under-counted licence in Australian SMEs, because the server “just works” whether or not the paperwork exists.
  • Unlicensed virtual machines. Spinning up a new VM from a template often clones a Windows Server or SQL install without anyone buying the licence to cover it.
  • Shared accounts. Three people on reception sharing one Adobe Acrobat or Microsoft 365 login. Named-user subscriptions are licensed per person, not per desk, and sharing breaches the terms even though it feels economical.

The real cost of getting it wrong

When a true-up or audit finds a gap, you don’t buy the shortfall at the keen price your reseller would normally quote. You typically pay back-charges for the period you were under-licensed, the licences at full list price, and in audit scenarios potentially penalties or the vendor’s audit costs on top. There’s no negotiating leverage, because you’ve been caught short and the clock is running.

The other cost is the rushed purchase. Faced with a deadline, businesses buy whatever the vendor puts in front of them, at list, often more than they need. A manufacturer in Dandenong we work with discovered during a routine Autodesk reconciliation that several engineering machines were running design software well beyond the seats they’d paid for. The catch-up purchase, under time pressure and at list, cost several times what an orderly renewal would have. The licences were genuinely needed; the panic premium wasn’t.

How to stay compliant

Compliance isn’t a once-a-year scramble. It’s an ongoing discipline, and most of it is unglamorous record-keeping that pays for itself the first time a letter lands.

Maintain a licence register

The foundation is knowing what you own. A licence register is a single, maintained record of every software product you’ve bought: publisher, product and edition, licence type (subscription or perpetual), quantity, purchase date and proof of purchase, and any agreement number. Most SMEs don’t have one, which is exactly why audits hurt. When you can produce entitlement evidence on demand, an audit becomes an afternoon’s work instead of a crisis. This sits inside broader IT asset management, the same discipline that tracks your hardware, warranties and end-of-life dates.

Reconcile assigned versus purchased seats

For Microsoft 365, the Microsoft 365 admin centre tells you exactly how many licences you’ve purchased against how many are assigned. Under Billing > Licences, you see each product, the seats you’re paying for and the seats in use. Reconciling this regularly catches both problems at once: seats assigned beyond what you’ve bought (a compliance gap) and seats you’re paying for that nobody uses (wasted spend). Do it monthly and neither surprise builds up.

Right-size unused licences

This is where compliance work actually saves money. The same register that protects you in an audit usually reveals seats you’re paying for and not using: the staff member who left three months ago whose Microsoft 365 and Adobe licences are still billing, the premium plan assigned to someone who needs the basic one, the perpetual product everyone forgot they retired. Reclaiming those licences, or cancelling them at renewal, frequently funds the cost of the housekeeping. Compliance and cost control are the same job done properly.

Understand subscription versus perpetual

The two licensing models carry different risks, and most environments are now a mix of both.

SubscriptionPerpetual
What you’re paying forThe right to use the software for a set term (monthly/annual)The right to use a specific version indefinitely, bought once
ExamplesMicrosoft 365, Adobe Creative Cloud, Autodesk subscriptionsOlder Office perpetual, on-prem Windows/SQL Server, legacy Acrobat
Compliance riskOver-assigning seats; the vendor can see live usageRunning more installs or versions than the licence allows; CALs untracked
If you stop payingThe software stops workingYou keep using the version you own, but get no updates or support

Autodesk and Adobe have moved almost entirely to subscription. Microsoft offers both, and a typical Melbourne SME runs Microsoft 365 subscriptions alongside perpetual on-premises Windows Server and its CALs. Knowing which model each product sits under tells you where your audit exposure actually lies.

SaaS sprawl makes this harder

Licence compliance used to mean counting installs on machines you owned. Now most software is bought as a subscription, often on a corporate card by whoever needed it, and the result is SaaS sprawl: dozens of overlapping tools, nobody sure who’s paying for what, and licences quietly renewing for people who left. A law firm in Hawthorn we onboarded was running three separate PDF and e-signature subscriptions across different teams, none fully used. You can’t licence-manage software you don’t know you have. The fix is the same register and the same reconciliation, applied to every subscription.

What to do if you receive an audit or true-up notice

Don’t panic, and don’t ignore it. The worst outcomes come from businesses that either go quiet, hoping it’ll pass, or that rush to admit a gap before they’ve established whether one exists.

  1. Read the agreement first. Find the audit or verification clause being relied on, and check what it actually entitles the vendor to: notice periods, scope and how data is gathered.
  2. Reconcile your own position before you respond. Run the numbers internally, deployments against entitlements, so you walk in knowing where you stand rather than learning it from the vendor. Your licence register is your evidence; don’t volunteer deployment data you haven’t verified.
  3. Bring in your licensing partner. Your reseller or MSP has dealt with these before and can challenge an over-stated gap, identify licences you already hold that the vendor missed, and negotiate the commercial close rather than accepting the first number.
  4. Treat the deadline as real but not immovable. Reasonable engagement buys time. A measured response almost always lands better than a fire-sale purchase.

Where the MSP and CSP partner fit

Most SMEs don’t buy Microsoft licences direct; they buy through a Cloud Solution Provider (CSP), and that’s usually their MSP. A good CSP partner does more than process the order. They right-size your seats at every renewal, flag when you’ve crossed a threshold like the 300-seat Business cap, keep the licence register current, and stand beside you if an audit ever lands. As a Melbourne MSP founded in 2014 with 13 Australian-employed engineers, TechAssist runs licence reconciliation as part of ongoing Microsoft 365 management, not as a billable scramble when the renewal looms. If you’ve never been sure your setup is right-sized, our Microsoft 365 support covers exactly this housekeeping.

Frequently asked questions

How often do software vendors actually audit small businesses?

Less often than large enterprises, but it does happen, and subscription products are effectively audited continuously because usage data flows back to the vendor automatically. For Microsoft 365 and similar SaaS, the bigger risk isn’t a formal audit but the annual true-up or renewal where over-assigned seats get reconciled at once. Perpetual on-premises software (Windows Server, SQL Server, older Office and Adobe) is where traditional formal audits are still most likely.

What’s the difference between a true-up and a fine?

A true-up is the routine process of paying for extra licences you deployed during the year under a volume agreement, no penalty, just the cost of the seats. A fine or penalty comes from an audit that finds you running software with no valid licence at all, where you may pay back-charges, list-price licences and potentially the vendor’s costs. The first is housekeeping; the second is what good housekeeping prevents.

Do we still need CALs if we’re moving to the cloud?

If you still run any on-premises Windows Server or SQL Server, yes, those CALs remain a live obligation regardless of how much else has moved to the cloud. Once a workload is fully migrated to a cloud service like Microsoft 365 or Azure, the CAL requirement for that service usually falls away, because the licensing is built into the subscription. The trap is a hybrid setup where the old server still runs and everyone assumes the cloud move dealt with the licensing. It didn’t.

Getting ahead of it

Software licence compliance is far cheaper to maintain than to fix under audit pressure. A current licence register, a monthly reconciliation in the Microsoft 365 admin centre, and a CSP partner who right-sizes at renewal will keep you compliant and usually trim your spend. If you’re not confident what you own versus what you’re running, that’s worth sorting before a true-up letter forces the issue. Get in touch with our team and we’ll audit your licensing before a vendor does.

The honest answer on Microsoft Copilot ROI is that it is real but uneven: Copilot saves genuine time on drafting, summarising and analysis for a subset of your staff, while the rest barely touch it. Whether you see a return depends far more on your data hygiene and rollout discipline than on the tool itself.

Microsoft 365 Copilot is an add-on at AUD $44.90 per user per month, billed annually, on top of an eligible Microsoft 365 licence. That is a meaningful line item, and the pitch invites you to buy it for everyone at once. That is usually the wrong move. This post sets out where Copilot earns its keep, where it does not, and how to measure the return before you commit the whole company.

What Microsoft 365 Copilot actually is

Copilot is a layer across Word, Excel, PowerPoint, Outlook, Teams and the rest of Microsoft 365. It uses a large language model, grounded in your organisation’s data through the Microsoft Graph, to draft, summarise, analyse and answer questions. The important detail is the grounding: Copilot writes using your files, emails and chats — the ones the asking user already has permission to see.

That grounding is the source of both its usefulness and its risk. Used well, it summarises the right Teams meeting or drafts an email referencing the right project. Used on a messy tenant, it surfaces the payroll spreadsheet someone parked in the wrong SharePoint site years ago.

Where Copilot genuinely saves time

We have watched Copilot across a range of Melbourne SMEs, and the time savings are real in a specific set of tasks worth paying for:

  • First-draft documents. A blank Word page is the expensive part. Copilot turns a few bullet points and a reference document into a serviceable first draft of a proposal, policy or report. You still edit it heavily — but editing beats writing from nothing.
  • Summarising Teams meetings. For recorded or transcribed meetings, the recap, action items and “what did I miss” summary are the standout feature. Staff who attend a lot of meetings get the clearest return.
  • Email triage and drafting in Outlook. Summarising a long thread before you reply, and drafting a reply in your tone, genuinely shaves minutes off a busy inbox.
  • Excel analysis. For people competent in Excel but not power users, Copilot explains formulas, suggests analysis and surfaces trends without writing the PivotTable by hand. It is an accelerator, not a substitute for knowing your data.

The common thread: Copilot rewards people who deal in a high volume of text and meetings. A senior manager, a bid writer or a practice manager will use it ten times a day. A warehouse supervisor or a hands-on tradesperson will open it once and forget it exists.

Where it underdelivers or needs guardrails

Being fair to the tool means being honest about its limits. Copilot is not a research assistant you can trust unsupervised.

  • It still gets things wrong. Copilot can confidently produce a summary that misses a meeting’s key point, or a draft that invents a figure. Everything needs a human check, which caps the time saving on anything high-stakes.
  • It is only as good as your prompts. Staff who type one vague line get one vague output, decide Copilot is useless, and stop. Adoption lives or dies on a little training.
  • It surfaces what your permissions expose. Copilot does not break permissions — it respects them exactly. But most SMEs have far looser permissions than they think. If a file is readable by “everyone”, Copilot will find it and quote it. Nobody used to browse to it; now they just ask.
  • It does not fix bad data. If your SharePoint is a swamp of duplicated, mislabelled, out-of-date documents, Copilot draws on the swamp. Garbage in, confident garbage out.

The prerequisite most SMEs underestimate: govern the data first

This is where most Copilot business cases quietly fall apart. The assumption is that you buy the licences and the value arrives. In practice it arrives only if your data is governed first — and that work is invisible until you go looking for it. Three things matter before Copilot touches your tenant:

  • Permissions. Audit who can actually read what. The classic finding is a SharePoint site shared with the whole company holding something it shouldn’t — client financials, salary data, scanned identity documents. Tighten access before Copilot makes it discoverable in plain English.
  • Sensitivity labels. Apply labels such as Confidential to data Copilot should never reuse, with encryption on the most sensitive. A labelled, encrypted file is protected even if a permission is wrong.
  • SharePoint hygiene. Clear out stale and duplicated content, fix the obvious oversharing, and get your file structure into a state you would be comfortable having an AI read aloud.

The tool that ties this together is Microsoft Purview, the governance and compliance suite built into Microsoft 365. Sensitivity labels, Data Loss Prevention and retention all live there, and they decide what Copilot is allowed to surface. We have written a full walkthrough of what is included with Microsoft 365 support in Melbourne, and a Purview-before-Copilot review is now common work for us. There is a regulatory angle too: under the Australian Privacy Principles in the Privacy Act 1988, you must take reasonable steps to protect personal information. Letting Copilot surface that data to the wrong staff member is the opposite of reasonable steps.

A Box Hill scenario

An accounting firm in Box Hill we work with wanted Copilot across thirty staff before end of financial year. We ran a permissions and labelling review first, and found a “Team Documents” SharePoint site, readable by everyone, holding a folder of client tax file numbers and the partners’ remuneration spreadsheet. Had Copilot gone live first, any junior could have asked “what does the firm pay its partners?” and received a tidy answer. We tightened the permissions, applied Confidential labels with encryption, set a DLP rule on TFNs, then enabled Copilot — for a pilot of eight, not the whole firm. The governance work took longer than the licensing. It always does, and it is the part that protects you.

How to actually measure Copilot ROI

“It feels useful” is not a return. If you are spending real money per seat, measure it properly. The method that works is unglamorous and deliberately small.

  1. Run a pilot group, not a company-wide rollout. Pick eight to fifteen text- and meeting-heavy people — the staff most likely to benefit. This contains the cost while you learn.
  2. Define the tasks you expect savings on. Be specific: drafting client proposals, summarising weekly meetings, triaging the shared inbox. Vague goals produce vague results.
  3. Track time saved, honestly. Ask the group to estimate hours saved per week on those tasks. A consistent rough number across several weeks tells you whether the saving is minutes or hours.
  4. Track adoption. The Microsoft 365 admin centre and Copilot usage reports show who is actually using it. If half the pilot group has not opened Copilot in a fortnight, that is your answer — usually a training problem, not a tool problem.
  5. Compare against licence cost. At roughly $45 per user per month, a user needs to save a little over an hour a month to break even on most professional salaries. A low bar for the right person, impossible for the wrong one.
StageWhat to doWhat good looks like
BeforePermissions, labels and SharePoint review in PurviewNo oversharing; sensitive data labelled and encrypted
Pilot8–15 text- and meeting-heavy users; defined tasksClear list of tasks Copilot is expected to help with
MeasureTrack time saved and adoption weekly for 6–8 weeksConsistent hours saved; most of the group using it regularly
DecideExpand only to roles that match the pilot’s winnersLicences land on people who use them, not everyone

Licensing realities and the “not everyone on day one” rule

Copilot requires an eligible base licence — for most SMEs, Microsoft 365 Business Standard or Business Premium, or an enterprise plan. The add-on is then billed per user on an annual commitment. The consumer Copilot and the in-tenant Microsoft 365 Copilot are different products; there is no free tier that does what the paid one does.

Because the commitment is annual and per seat, buying it for everyone on day one is the single most expensive mistake we see — paying for forty seats when twelve people use it. Do the opposite: govern the data, pilot with the obvious beneficiaries, measure, then expand only to the roles where the pilot showed a real return. If you cannot tell which roles those are, that is exactly the question a virtual CIO engagement answers — mapping the spend to the work rather than the marketing.

Frequently asked questions

How much does Microsoft 365 Copilot cost in Australia?

AUD $44.90 per user per month, billed on an annual commitment, on top of an eligible base licence such as Microsoft 365 Business Standard or Business Premium. There is no equivalent free version for business use.

Should I buy Copilot for the whole company?

No. Start with a pilot of eight to fifteen text- and meeting-heavy staff, measure time saved and adoption over six to eight weeks, then expand only to the roles that showed a real return. A minority of staff usually drive most of the value.

Does Copilot create a data security risk?

Not by breaking permissions — it respects them. The risk is that it surfaces data your permissions already expose but nobody used to browse to. Governing your data first with Microsoft Purview turns that risk into a non-issue.

The honest verdict

Microsoft 365 Copilot delivers a clear return for the right people doing the right work — and very little for everyone else. The return is not in the tool; it is in the discipline around it. Govern the data, pilot with the staff who live in documents and meetings, measure against the licence cost, then expand deliberately.

TechAssist has run Microsoft 365 for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. For a governance review before Copilot, a scoped pilot, or a plain read on whether the per-seat cost is worth it, get in touch. We will tell you which of your people will get value from it, and which seats you would be wasting money on.

Azure is worth it for a small business when you have a workload that genuinely needs cloud infrastructure — a server to retire, a line-of-business app to host, virtual desktops for a hybrid team. For most Melbourne SMEs, though, Microsoft 365 plus a small NAS does the job, and Azure becomes a bill you didn’t need.

Microsoft Azure small business deployments fail in one of two ways: a business pays for cloud infrastructure it doesn’t need, or it lifts a server into Azure with no cost controls and gets a quarterly bill that triples overnight. Both are avoidable. The trick is knowing what Azure actually does, where it earns its keep for an SME, and where a cheaper option does the same job without the meter running.

What Azure actually is, in plain terms

Azure is Microsoft’s public cloud — a set of data centres you rent compute, storage and networking from by the hour or the gigabyte. Instead of buying a physical server, racking it in a cupboard at your office and replacing it every five years, you run the same workload on Microsoft’s hardware and pay for what you use.

The catalogue is enormous — hundreds of services — but a small business touches a small slice of it. The services that matter for an SME are virtual machines (a server in the cloud), identity (Microsoft Entra ID, formerly Azure AD), file storage, backup, and virtual desktops. Everything else is for software developers and large enterprises, and you can safely ignore it.

One point of confusion worth clearing up: Microsoft 365 is not Azure. Microsoft 365 — your email, Teams, SharePoint and Office apps — runs on Microsoft’s cloud, but it’s a finished, fixed-price product. Azure is the raw infrastructure underneath. Plenty of businesses run entirely on Microsoft 365 and never touch Azure at all, and that’s a perfectly good place to be.

Where Azure earns its keep for an SME

Azure makes sense when you have a specific workload that needs infrastructure. Here are the use cases we actually deploy for Melbourne small businesses, rather than the marketing list.

Lift-and-shift a server as a virtual machine

The most common entry point. You’ve got an ageing physical server running an accounting package, a file share or a legacy app, and it’s due for replacement. Rather than spend $8,000 on new hardware that sits idle most of the day, you rebuild it as an Azure virtual machine. No cupboard, no UPS, no five-year refresh cycle. This is genuinely useful when the app can’t move to a SaaS alternative — but it’s also where the bill-shock stories start, because a VM bills every hour it’s switched on whether anyone’s using it or not.

Identity with Microsoft Entra ID

If you’re on Microsoft 365 you already use Entra ID — it’s the directory your staff log in against. Azure lets you extend it: conditional access, single sign-on to other apps, and proper multi-factor enforcement. We treat identity as the foundation of any cloud build, and we’ve written separately about conditional access policies in Microsoft 365 because getting them right is what stops a leaked password becoming a breach.

Azure Files and Azure Backup

Azure Files gives you a cloud file share that maps like a normal network drive. Azure Backup and Azure Site Recovery protect servers and workloads — Backup for restoring files and machines, Site Recovery for failing a whole server over to the cloud if your primary site goes down. These are solid, and we use them, but they’re only one ingredient in a proper recovery plan. The thinking that matters is your RTO and RPO — how long you can be down and how much data you can afford to lose — not the tool itself.

Hosting a line-of-business app

If your business runs on a specific Windows application — a job-management system, a CAD licence server, an old ERP — and the vendor won’t or can’t move it to SaaS, Azure is a sensible home for it. You get a reliable, monitored, backed-up environment without owning the hardware. This is where Azure clearly beats a server in the cupboard.

Virtual desktops: Azure Virtual Desktop and Windows 365

If you have staff who need a full Windows desktop from anywhere — contractors, a hybrid team, people on locked-down or BYO laptops — virtual desktops put that desktop in Azure. Azure Virtual Desktop is the flexible, consumption-priced option; Windows 365 is the simpler fixed-per-user-per-month version (a Cloud PC). Windows 365 is usually the better fit for a small business precisely because the price is predictable. AVD is more powerful but needs someone watching the meter.

The cost model reality

This is the part nobody enjoys, and it’s the part that decides whether Azure is worth it. Azure is consumption-based: you pay for compute by the hour, storage by the gigabyte, and data movement by the transaction. There’s no fixed monthly number on the box. That flexibility is the whole appeal, and it’s also exactly how businesses overspend.

A few realities to hold onto:

  • VMs bill while they’re running, not while they’re being used. A server left on 24/7 that’s only needed during business hours is burning roughly three times the cost it should. Auto-shutdown schedules fix this in minutes.
  • Reserved instances cut compute costs sharply. If a VM is going to run for the long haul, committing to a one- or three-year reservation can cut the compute price by 40 percent or more versus pay-as-you-go. Most SMEs leave this money on the table.
  • Storage and egress add up quietly. Old backups, orphaned disks from deleted VMs, and data being pulled out of Azure all bill in the background. These are the line items that make a quarterly invoice mysterious.
  • Data residency matters. For Australian businesses, you deploy into the Australia East region (Sydney). Your data stays onshore, which keeps you comfortable for privacy and contractual reasons under the Privacy Act and the OAIC’s expectations. Don’t let a default drop your data into a US region.

Azure vs Microsoft 365 plus a NAS vs staying on-prem

Azure is not the default answer. For a lot of Melbourne SMEs, the right call is the cheaper one. Here’s how we frame the decision.

ScenarioBest fitWhy
Small team, files and email, no legacy server appsMicrosoft 365 + a small NASSharePoint/OneDrive handles documents; a NAS gives fast local storage and cheap backup. No Azure bill, no meter.
Ageing server running a Windows-only line-of-business appAzure VMRetires the hardware, removes the refresh cycle, and hosts an app that can’t move to SaaS.
Hybrid or contractor-heavy team needing full Windows desktopsWindows 365 / Azure Virtual DesktopCentralised, secure desktops from any device, no fleet of company laptops to manage.
Heavy local data, low internet reliability, latency-sensitive workStay on-prem (or hybrid)Large CAD or video files and patchy connectivity make cloud-only painful and slow.
Regulated data with strict residency or recovery requirementsAzure (Australia East) or hybridOnshore region, auditable backups, and documented recovery you can show an insurer or regulator.

The pattern is simple: if your needs are documents, email and collaboration, Microsoft 365 with sensible backup is enough, and Azure is overkill. The moment you have a server-based workload, virtual desktops, or a recovery requirement you can’t meet locally, Azure starts earning its place.

FinOps: the cost-control discipline that makes Azure worth it

FinOps is just the practice of treating cloud spend like any other managed expense — measured, budgeted and reviewed, not left to drift. For a small business it doesn’t need to be a department. It needs a handful of controls:

  1. Budgets and alerts. Set a monthly budget in Azure Cost Management with alerts at 50, 80 and 100 percent. You should hear about an overspend the week it happens, not on the invoice.
  2. Auto-shutdown and right-sizing. Switch off VMs out of hours and match the VM size to the actual workload. Most environments are over-provisioned because someone picked a bigger size “to be safe”.
  3. Reservations for steady workloads. Anything running long-term should be on a reservation, not pay-as-you-go.
  4. Tagging and clean-up. Tag resources by purpose so you can see what’s costing what, and delete orphaned disks, snapshots and old backups on a schedule.

None of this is exotic. It’s the difference between Azure being a controlled line item and Azure being a surprise.

A scenario from the eastern suburbs

A surveying firm in Box Hill we work with came to us after a self-managed Azure setup. They’d lifted their old file-and-app server into a VM, which was the right call — but the VM ran 24/7, the original oversized disk was still being billed alongside its replacement, and there were no budget alerts. Their spend had crept to nearly double what the workload justified. Adding an out-of-hours shutdown schedule, right-sizing the VM, moving it onto a one-year reservation and deleting the orphaned disk brought the monthly cost down by roughly a third — for the same performance. Nothing clever; just the discipline that should have been there from day one.

The MSP role: governance, not just deployment

Anyone can spin up a VM in Azure. The value an MSP adds is everything around it — making sure the build is sized correctly, deployed to Australia East, backed up to a tested standard, secured with proper identity controls, and watched so the bill doesn’t run away. That’s governance, and it’s the part a business can’t easily do for itself between everything else it’s juggling.

At TechAssist we’re a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers — no offshore helpdesk. Our 24/7 NOC at Tecoma monitors the environments we run, so a backup that silently fails or a cost that spikes gets caught by us, not discovered by you on the invoice. We build and manage Azure as part of our broader cloud services, and we’ll tell you plainly when Azure is the wrong answer and Microsoft 365 plus a NAS would serve you better and cheaper. We’re also Essential Eight aligned, which matters once you’re putting business data into the cloud.

The honest position is this: Azure is a powerful tool that’s worth it for the right workload, with the right controls, in the right region — and an expensive mistake without them. The job is matching the tool to your actual needs.

Frequently asked questions

Is Azure cheaper than buying a server?

Sometimes. Over five years, a well-governed Azure VM with a reservation and an out-of-hours shutdown can beat the total cost of owning, powering and replacing a physical server — and you avoid the capital outlay. Without those controls, Azure is usually more expensive. The cost discipline is what decides it.

Where is my data stored if I use Azure in Australia?

If you deploy into the Australia East region, your data sits in Microsoft’s Sydney data centres and stays onshore. This is the right default for Australian businesses with privacy or contractual obligations. Always confirm the region at deployment — don’t assume it.

Do I need Azure if I already have Microsoft 365?

Usually not. Microsoft 365 already covers email, documents and collaboration. You only need Azure on top of it when you have a workload that needs actual infrastructure — a server, a hosted line-of-business app, or virtual desktops.

How do I avoid a surprise Azure bill?

Set budgets and alerts in Azure Cost Management, switch off VMs out of hours, use reservations for steady workloads, and delete orphaned resources. An MSP managing the environment should be doing all of this and reviewing the spend with you regularly.

Can a small business run virtual desktops affordably?

Yes. Windows 365 gives you a fixed per-user-per-month Cloud PC, which keeps costs predictable for a small team. Azure Virtual Desktop is more flexible but consumption-priced, so it needs the cost discipline to stay affordable.

Not sure whether Azure is worth it for your situation, or worried an existing setup is costing more than it should? Talk to us — we’ll give you a straight answer, not a sales pitch.

If you are still running Windows Server 2012 R2 or 2016, the clock has already gone off. Windows Server end of support arrived for 2012 and 2012 R2 in October 2023, and Server 2016 leaves mainstream support behind with extended support ending in January 2027. Unsupported means no security patches. Plan the migration now, before something forces your hand.

Where the dates actually sit

The confusion around server end-of-support comes from Microsoft’s two-phase lifecycle. Every server release gets a mainstream support window, then an extended support window where you only receive security updates. When extended support ends, the patches stop completely. That is the date that matters.

ProductMainstream support endedExtended support endsStatus today
Windows Server 2012 / 2012 R2October 201810 October 2023Out of support — no patches
Windows Server 2016January 202212 January 2027Security updates only — plan now
Windows Server 2019January 2024January 2029Extended support
Windows Server 2022October 2026October 2031Current, supported

So 2012 and 2012 R2 have been unsupported for getting on two years. If you are running one, every month that box stays online is a month of unpatched vulnerabilities sitting on your network. Server 2016 is in a better spot, but “January 2027” is not far away once you account for procurement, testing and a cutover that has to happen outside business hours. The businesses that get caught are the ones that treat 2027 as a 2026 problem and discover in November that the line-of-business app vendor needs six weeks to certify the new platform.

What “unsupported” really costs you

The headline risk is obvious: no security updates. When a critical vulnerability lands in an unsupported Windows Server, Microsoft does not ship a fix for it, and attackers know exactly which versions are exposed. But the knock-on effects are where most Melbourne SMEs actually feel the pain.

  • Cyber insurance. Insurers now ask whether you run supported operating systems. Running an out-of-support server can void a claim or get your renewal declined outright. We cover this in detail in our cyber insurance guide for Australian SMEs.
  • Compliance and the Essential Eight. Patching operating systems is a core Essential Eight control. You cannot patch an OS that no longer receives patches, so an unsupported server is an automatic black mark in any maturity assessment.
  • Software compatibility. Vendors drop support for old server platforms too. Newer versions of your accounting package, your SQL-backed database or your industry software may refuse to install or run.
  • Hardware. Servers that old are frequently running on hardware well past its warranty, so you are carrying a failure risk on top of the patching risk.

A construction firm in Box Hill we work with discovered this the hard way at renewal time. Their broker’s questionnaire asked, in plain terms, whether any server ran an unsupported operating system. The honest answer was yes — a 2012 R2 box still hosting their estimating software. The premium loaded, and the underwriter wanted a remediation date in writing before they would bind cover. The migration that had been “next year’s project” became a four-week sprint.

The question nobody asks first: do you even need the server?

Before you price up a replacement, ask the harder question. A lot of the on-premises servers we decommission across Melbourne metro exist out of habit, not necessity. The workloads they were bought for have moved on, and the business is paying to keep a box alive that it could retire entirely.

Work through what the server actually does, role by role, because the answer changes the whole project:

  • Active Directory / domain controller. If AD is the main reason the server exists, many smaller businesses can move to Entra ID (Azure AD) and Intune, manage devices in the cloud, and drop the on-prem domain controller altogether. Others genuinely still need it. This is the role that most often decides whether you keep a server at all.
  • File server. File and folder shares are one of the easiest things to move. SharePoint and OneDrive in Microsoft 365 handle most SME file needs without a server, with versioning and external sharing built in. Heavy CAD or large-media workflows sometimes still warrant on-prem or a hybrid approach.
  • Line-of-business applications. The make-or-break role. Some legacy apps only run on a Windows Server and tie you to keeping one. Increasingly, the vendor has a SaaS version, and migrating to it removes the server requirement and the maintenance burden together.
  • SQL Server. Often hiding behind a line-of-business app. SQL Server 2012 and 2014 are themselves out of support, so a server migration is the moment to deal with the database engine too — either upgrading it or moving to Azure SQL.

For a genuinely cloud-ready SME, the best migration is often no server at all. Move files to Microsoft 365, identity to Entra ID, the line-of-business app to its SaaS edition, and the box goes in the bin. No replacement hardware, no Server licence, no patching for the next five years. That is not the right answer for everyone, but it should be the first option you rule in or out.

Your migration options

Once you know what the server does, there are three broad paths. Most businesses end up using a mix.

1. Replace with Windows Server 2022 or 2025

If you have workloads that genuinely belong on a server — heavy file workloads, an app the vendor only supports on-prem, a domain controller you are keeping — then a clean build on Windows Server 2022 or the newer 2025 release is the straightforward path. You provision new hardware or a new virtual machine, build it current, migrate the roles and data across, and retire the old box. This keeps everything on-premises and under your direct control, which suits businesses with specific latency, data-sovereignty or application-compatibility reasons to stay local.

2. Move to Azure

Lifting the workload into Microsoft Azure replaces the physical box with a cloud virtual machine. You stop worrying about hardware failure and capacity, and you can scale up or down. There is one detail worth knowing: if you run Windows Server 2012/2012 R2 or 2016 inside Azure, Microsoft provides Extended Security Updates at no additional cost while you complete your migration to a current version. Running those same versions on-premises means paying for ESU separately. So Azure can buy you a supported runway while you finish the project properly, rather than leaving an unpatched box exposed. Our cloud services team handles these migrations end to end.

3. Retire the server into SaaS and cloud platforms

The option covered above — move the workloads to cloud services and decommission the server entirely. No replacement, no licensing, no ongoing maintenance. For many SMEs this is both the cheapest long-term option and the most secure, because there is simply less infrastructure to patch and protect.

PathBest whenServer to maintain?ESU situation
New Windows Server 2022/2025Workloads must stay on-premYesCurrent version, fully supported
Azure VMYou want cloud flexibility, less hardware riskManaged VMFree ESU for 2012/2016 during migration
SaaS / cloud, retire serverApps and files can move to the cloudNoNot applicable — no legacy OS left

Planning the migration properly

A server migration goes wrong when it is treated as a like-for-like swap done over a weekend. It is a project with a discovery phase, and the discovery is where the surprises live — the scheduled task nobody documented, the printer driver hosted on the old box, the app that authenticates against the local domain.

  1. Assess. Inventory every role, application, dependency and integration on the server. Confirm with each software vendor which platforms they support and what they need. This is where you decide replace, move to Azure, or retire.
  2. Back up first. A verified, tested backup of the current server is non-negotiable before you touch anything. If the cutover goes sideways, the backup is your way home. Our backup and recovery approach treats this as the foundation of any migration, not an afterthought.
  3. Build and test in parallel. Stand up the new environment alongside the old one and test the line-of-business apps against it before you commit. Catch the compatibility problems while the old server is still running.
  4. Cut over outside business hours. Schedule the switch for an evening or weekend, with a rollback plan and a tested backup behind you. Communicate the window to staff so nobody loses work mid-flight.
  5. Decommission cleanly. Once the new environment is confirmed stable, retire the old server, revoke its access, and update your documentation and asset register so the next person knows what changed.

This is core MSP work, and it is exactly the kind of project our managed IT services are built around. TechAssist has been migrating Melbourne SMEs off ageing infrastructure since 2014, with 13 Australian-employed engineers and same-business-day on-site support across the metro when a cutover needs hands on the hardware. We run the assessment, handle the build, and own the cutover so your team is not improvising at 9pm on a Saturday.

Frequently asked questions

Is Windows Server 2016 still safe to use right now?

It still receives security updates until extended support ends on 12 January 2027, so it is patched for now. But “supported until 2027” is not the same as “leave it until 2027”. Migrations take planning, vendor coordination and a tested cutover, so start the assessment well before the deadline rather than scrambling in the final months.

Can I just keep running Windows Server 2012 R2 if it still works?

Technically it runs, but it has had no security patches since October 2023. New vulnerabilities go unfixed, it can void a cyber insurance claim, and it fails Essential Eight patching expectations. “It still works” is true right up until it is the entry point for a breach. Treat it as a liability to remove, not a server to keep.

How do free Extended Security Updates in Azure work?

If you migrate a Windows Server 2012/2012 R2 or 2016 workload into an Azure virtual machine, Microsoft provides Extended Security Updates for that legacy operating system at no extra charge while it runs in Azure. Running the same version on your own hardware means buying ESU separately. It is a runway to finish your move to a current version, not a permanent fix.

Do we actually still need an on-premises server?

Often, no. If your file shares can move to SharePoint and OneDrive, your identity to Entra ID, and your main application to a SaaS version, you can retire the server entirely. The deciding factor is usually one stubborn line-of-business app or a heavy file workload. The assessment tells you which camp you are in.

The short version

Windows Server 2012 and 2012 R2 are already out of support, and Server 2016 follows in January 2027 — so this is a now problem, not a later one. Start by asking whether you still need the server at all, then choose between a current Windows Server build, an Azure move with free Extended Security Updates while you migrate, or retiring the box into cloud and SaaS. Whichever path fits, the work is the same: assess properly, back up first, test in parallel, and cut over with a rollback plan. If you are running an ageing server and want a clear-eyed assessment of where it should go, get in touch and we will map your options before the deadline maps them for you.

Windows 10 reached windows 10 end of life on 14 October 2025. Microsoft has stopped shipping security updates, bug fixes and technical support for it. Every Windows 10 machine still running in your business is now an unpatched, slowly widening hole in your defences — and the clock has already passed midnight.

This isn’t a future problem to schedule for next quarter. If you’ve been telling yourself “we’ll deal with it later”, later arrived in October 2025. The good news: the path forward is well understood, and you have more options than panic-buying a truckload of new laptops. The bad news: every month you wait, the risk and the cost both climb.

What “end of support” actually means

End of support is not a switch that bricks your machines. Windows 10 still boots, your line-of-business apps still run, and your staff probably won’t notice anything different on the surface. That’s exactly what makes it dangerous. The operating system keeps working while the protection underneath it quietly rots.

From 14 October 2025, Microsoft no longer issues:

  • Security updates for newly discovered vulnerabilities. When a critical flaw is found — and they are found constantly — Windows 11 gets a patch and Windows 10 does not.
  • Reliability and bug fixes, so problems compound over time rather than getting resolved.
  • Technical support from Microsoft, including for Microsoft 365 apps running on Windows 10. Office will keep functioning, but you’re on your own when something breaks.

An unpatched OS is the single softest target in most networks. Attackers don’t need to be clever; they just scan for known vulnerabilities that will never be fixed. Within months of an OS going end of life, exploit kits start treating it as low-hanging fruit.

The real risks of running an unsupported OS

The exposure here goes well beyond “you might get a virus”. For an Australian business, four distinct problems stack on top of each other.

Cyber security

Every month after October 2025 widens the gap between the threats in the wild and the defences on your endpoints. A single unpatched workstation can be the foothold an attacker uses to move laterally, harvest credentials and deploy ransomware across your whole environment. Endpoint detection helps, but it’s compensating for a structural weakness, not fixing it.

Compliance and the Essential Eight

The Australian Cyber Security Centre (ACSC) Essential Eight lists patch operating systems as one of its eight core mitigation strategies. The mitigation explicitly requires using an operating system that is still receiving vendor support. Run Windows 10 past end of life and you fail that control outright — you cannot reach even Maturity Level One. If you’re a government supplier, tendering for work, or contractually bound to Essential Eight alignment, an unsupported OS is a straight non-compliance. Our 90-day Essential Eight guide walks through how the patching controls are actually assessed.

Cyber insurance

Insurers have tightened their proposal forms considerably. Most now ask directly whether you run supported, patched operating systems and apply security updates within defined timeframes. Running an end-of-life OS can breach a policy condition, and if a claim arises from a vulnerability on an unsupported machine, you’re handing the insurer a clean reason to reduce or decline the payout. We cover this trap in detail in our cyber insurance guide for Australian SMEs. The premium you’ve paid for years may be worth far less than you think.

Privacy obligations

If a breach traced to an unsupported system exposes personal information, the Office of the Australian Information Commissioner (OAIC) Notifiable Data Breaches scheme can require you to notify affected individuals and the regulator. “We knew the OS was unsupported and kept using it” is not a position you want to defend to the OAIC, your customers, or your board.

Extended Security Updates — a stopgap, not a strategy

Microsoft offers Extended Security Updates (ESU) to keep critical and important security patches flowing after end of life. It is a deliberate bridge, not a destination, and it’s priced to make sure you treat it that way.

For consumers, Microsoft made a one-year ESU option available, including a free route for individuals who enable certain settings. That consumer path is genuinely a stopgap for a home PC — it is not a business strategy.

For business and enterprise, ESU is sold per device and the price escalates every year — Microsoft’s commercial ESU programme roughly doubles the per-device cost in year two and doubles again in year three. The model is intentional: it buys you breathing room while making procrastination progressively more painful. Pay for three years of ESU across a fleet and you’ll usually have spent more than it would have cost to simply replace or upgrade the machines.

Use ESU when you have a genuine, time-boxed reason — a legacy application that won’t run on Windows 11 yet, or a hardware refresh you can’t physically complete before the deadline. Do not use it as a way to avoid making a decision. Budget for ESU as a one-year bridge with a hard exit date, not a recurring line item.

Is your fleet ready for Windows 11?

Windows 11 is the obvious destination, but it has stricter hardware requirements than Windows 10, and that’s where most businesses get caught. A machine that runs Windows 10 perfectly well may be ineligible for an in-place upgrade.

The two requirements that trip people up most:

  • TPM 2.0 — a Trusted Platform Module security chip. Many machines from the mid-2010s either lack it or have it disabled in the firmware. Sometimes it’s present and just needs enabling in the BIOS; sometimes it isn’t there at all.
  • CPU compatibility — Microsoft only supports a defined list of processors, broadly Intel 8th generation and newer, and equivalent AMD Ryzen chips. Older CPUs are unsupported even if everything else checks out.

You can’t eyeball this across a fleet. A proper readiness assessment inventories every device, checks TPM status, CPU model, RAM and storage, and sorts each machine into one of three buckets: upgrade in place, replace, or bridge with ESU. That inventory is the foundation of every decision that follows. If you don’t have a current picture of what’s actually on people’s desks, that’s step one — and it’s something our managed IT services team handles as standard.

Your four options compared

There’s no single right answer for a whole business. Most Melbourne SMEs end up with a mix, machine by machine. Here’s how the four realistic paths stack up.

OptionBest forUpfront costWatch out for
Upgrade in placeMachines that already meet Windows 11 requirements (TPM 2.0, supported CPU)Low — labour onlyConfirm app compatibility; allow time per device
Replace hardwareOlder machines that fail the CPU or TPM checkHigh — new device per userLead times; staged budget; secure disposal of old units
Cloud PC / Windows 365Shift/hybrid workers, thin-client setups, fast scalingOngoing per-user subscriptionNeeds reliable internet; recurring cost vs one-off
ESU bridgeA small number of machines tied to legacy apps, time-boxedPer-device, escalating yearlyStopgap only; set a hard exit date

Cloud PC and Windows 365 deserve a closer look if you’re already invested in Microsoft 365. They run a full Windows 11 desktop from Microsoft’s cloud, streamed to whatever device the user has — which can extend the useful life of older hardware that’s no longer fit to run Windows 11 locally. It’s not right for everyone, but for the right workforce it sidesteps the hardware problem entirely. We can map this against your existing Microsoft 365 licensing so you’re not paying twice for the same capability.

A Melbourne scenario

A construction firm in Box Hill we work with came to us in early 2025 with about forty workstations, a mix of site-office desktops and project-manager laptops. A readiness scan put roughly half on supported hardware that could upgrade in place, a quarter on machines too old to meet the CPU requirement, and the rest as borderline. Two estimating PCs were locked to an older take-off application the vendor hadn’t yet certified for Windows 11.

The plan wrote itself once we had the data: upgrade the compliant half over a few weekends, replace the oldest quarter in two budgeted waves across two quarters, and put just those two estimating PCs on a one-year ESU bridge with a firm cut-off once the software vendor shipped its update. No big-bang spend, no scramble, and every machine accounted for. The difference between that and a panicked December rush was simply starting with an inventory.

Building the migration plan and budget

A workable migration plan is mostly about sequencing and money, not heroics. The pattern we use across Melbourne metro businesses:

  1. Inventory everything. Every device, its Windows 11 eligibility, and the apps it depends on.
  2. Triage into the three buckets — upgrade, replace, bridge — and flag any legacy-app blockers early.
  3. Stage the spend. Spread hardware replacement across two or three budget periods so it doesn’t land as one brutal capital hit.
  4. Prioritise by risk. Machines handling sensitive data or facing the internet move first; back-office spares can wait.
  5. Set hard dates for any ESU-bridged devices so the stopgap doesn’t quietly become permanent.

This is the kind of forward planning a virtual CIO engagement is built for — turning a looming deadline into a costed, scheduled programme your board can actually sign off. TechAssist has been doing exactly this for Melbourne SMEs since 2014, and our thirteen Australian-based engineers handle the rollout end to end rather than leaving you a spreadsheet and good luck.

Why “we’ll deal with it later” is now overdue

The deadline has passed. Every Windows 10 machine on your network today is unsupported, unpatched against new threats, and counting against your Essential Eight posture, your insurance position and your privacy obligations. None of that is alarmist — it’s just where the calendar sits as of June 2026.

The fix is straightforward once you’ve got an inventory and a plan, and it’s far cheaper to do deliberately over a quarter or two than as an emergency. The businesses that started early are already done. The ones still running Windows 10 are carrying risk every day they wait.

Frequently asked questions

Can I still use Windows 10 after October 2025?

Technically yes — the machines keep working. But they no longer receive security updates, so each one becomes a growing vulnerability. For a business, continuing on Windows 10 without ESU means accepting cyber, compliance and insurance risk that compounds month by month.

How much does business ESU cost?

Microsoft prices commercial ESU per device, and the cost escalates each year — roughly doubling in year two and again in year three. Over three years it typically exceeds the cost of upgrading or replacing the machine, which is by design. Treat ESU as a one-year bridge, not an ongoing plan.

How do I know if my computers can run Windows 11?

The common blockers are TPM 2.0 and CPU compatibility — broadly Intel 8th generation or newer and equivalent AMD chips. A fleet-wide readiness assessment checks every device automatically and sorts them into upgrade, replace or bridge. Guessing device-by-device isn’t reliable at scale.

Is Windows 365 a good alternative to buying new PCs?

For shift, hybrid or thin-client workforces it can be, because it streams a full Windows 11 desktop from the cloud and extends the life of older hardware. It’s a recurring per-user cost rather than a one-off purchase, so it suits some teams and not others. It’s worth modelling against your existing Microsoft 365 licensing.

Get a Windows 11 readiness assessment

If you’re still running Windows 10 anywhere in your business, the first move is an honest inventory: what you have, what can upgrade, what needs replacing, and what genuinely needs a short ESU bridge. Get in touch and we’ll scope it for you, then turn it into a staged, budgeted plan — so this gets sorted properly rather than hanging over you into another quarter.

Outlook rules are the single fastest way to stop drowning in email. They sort, file, flag and forward messages automatically, the moment they arrive, so your inbox shows you what matters and quietly parks the rest. Combine them with Focused Inbox, Quick Steps and templates, and Outlook starts working for you instead of the other way around.

This is a practical guide to the features that genuinely save time across the new Outlook, Outlook on the web and the classic desktop app. No theory, no clearing of throats. The examples come from configuring Microsoft 365 for Melbourne SMEs day in, day out, and there is a short security note near the end that every business owner should read.

Rules: the workhorse

A rule is a simple instruction: when a message meets a condition, do something with it. When it is from your accountant, move it to the Finance folder. When the subject contains “invoice”, flag it. When it is sent to a distribution list you only skim, mark it read and file it. You build them once and they run forever.

Server-side versus client-side rules

This distinction matters more than most people realise. Server-side rules run on the Exchange Online server, so they work whether or not your computer is on. A rule that files newsletters runs at 2am while your laptop is shut. Client-side rules only run while the classic Outlook desktop app is open and connected, because they depend on something only the desktop app can do.

The trigger for the difference is the action. Conditions and actions that Exchange understands on its own — move, copy, delete, forward, flag, mark as read — stay server-side. The moment a rule includes something the server cannot do, such as “display a desktop alert”, “play a sound”, or “move to a folder in a local PST”, the whole rule becomes client-only. In Outlook you will see these flagged with “on this computer only”.

The practical advice: keep your important filing and forwarding rules server-side so they run reliably from any device, including the Outlook mobile app and the web. Save client-side rules for cosmetic things you genuinely only want while sitting at that one machine. If you live across a desktop, a laptop and your phone, server-side is the only way to get consistent behaviour everywhere.

Where to build them

In the new Outlook and Outlook on the web, go to Settings > Mail > Rules and select Add new rule. In classic desktop Outlook, it is File > Manage Rules & Alerts, or right-click a message and choose Rules > Create Rule to pre-fill the conditions from that message. Building from an example message is the quickest way to get a rule right first time.

Rule recipes that earn their keep

  • Tame distribution lists. Mail sent to a group you are on but rarely need urgently: move it to a dedicated folder and mark it read. You read it when you choose, not when it pings.
  • Surface the important senders. Mail from your top clients or your boss: flag for follow-up and keep it in the inbox so it never gets buried.
  • File the predictable stuff. Statements, system notifications, monitoring alerts and receipts: route straight to topic folders so the inbox stays for things that need a human decision.
  • Catch the subject keywords. Anything with “PO”, “RFQ” or a project code in the subject into the relevant project folder, so nothing scatters.

One caution: rules run in order, top to bottom, and some can “stop processing more rules”. A common trap is a tidy-up rule near the top quietly swallowing messages a later rule was meant to catch. Review the order when something stops arriving where you expect it.

Focused Inbox, Other and Sweep

Focused Inbox splits your inbox into two tabs: Focused for the mail Outlook judges important, and Other for the rest — newsletters, notifications, bulk mail. It learns from your behaviour. Move something from Other to Focused a couple of times and it gets the message. It is on by default in most Microsoft 365 tenants and you can toggle it under View > Show Focused Inbox.

People either love it or fight it. The honest take: Focused Inbox is machine-guessed and changes daily, whereas a rule is a guarantee you wrote yourself. Use Focused Inbox as a soft first pass for mail you have not categorised, and use rules for anything where you need certainty. If you turn Focused Inbox off, your rules still do their job.

Sweep is the underused companion. Select a sender, hit Sweep, and you can delete all current mail from them, delete everything older than a set number of days, or keep only the latest and auto-delete the rest going forward. It is the fastest way to clear a sender who emails you forty times a week — a standing instruction rather than a one-off delete.

Quick Steps: one click, several actions

Quick Steps (classic desktop and increasingly the new Outlook) bundle a sequence of actions behind a single button. Where a rule runs automatically, a Quick Step runs when you click it — perfect for the repetitive handling you do by hand.

A help desk in Cremorne we set up uses one called “To Project” that, in a single click, moves the selected email to a project folder, marks it read and categorises it. Other useful ones: “Reply & Archive”, “Forward to team and flag”, or a “Done” button that files and clears. You will find them on the Home ribbon, and you can build your own from the Manage Quick Steps option. Five minutes setting up three Quick Steps removes hundreds of repeated clicks a month.

Templates, My Templates and Quick Parts

If you type the same reply more than twice, template it.

  • My Templates is an add-in built into Outlook on the web and the new Outlook. Open the My Templates pane while composing, click a saved snippet, and it drops straight into the message body. Ideal for standard responses — opening hours, “received, we’ll be in touch”, booking confirmations.
  • Quick Parts in classic desktop Outlook store reusable blocks of formatted text under Insert > Quick Parts. Better than My Templates when you need formatting, tables or images preserved.
  • Email templates proper (.oft files) suit a whole pre-built message you send repeatedly — save via Save As > Outlook Template, reopen via New Items > More Items > Choose Form.

For replies that several staff send identically, templates beat everyone improvising. They keep the wording consistent and on-brand, and they spare you retyping the same paragraph for the hundredth time.

Signatures, and why org-wide ones belong centrally

Per-mailbox signatures are set under Settings > Mail > Compose and reply in the new Outlook, or File > Options > Mail > Signatures in classic desktop. Fine for one person.

For a business, leave individual signatures behind. When everyone manages their own, you get mismatched fonts, dead phone numbers, broken logos and the occasional rogue inspirational quote. Worse, signatures set in Outlook desktop do not follow you to the web or the mobile app, so a phone reply goes out bare. The fix is a centrally managed signature applied at the Microsoft 365 service level — typically a transport rule or a dedicated signature platform — so every message from every device carries a consistent, correct, compliant footer your staff cannot break. We set this up as part of a managed Microsoft 365 environment, and it is one of those small things that quietly makes a business look more professional overnight.

Categories and Search Folders

Colour categories are a flexible tagging layer that works across mail, calendar and tasks. Tag by client, by project, by priority — whatever you actually sort by. Rename the default colours to something meaningful (right-click a message > Categorize > All Categories) and you can later filter or search on them in seconds.

Categories pair beautifully with Search Folders (classic desktop). A Search Folder is a saved, live view that gathers every message matching a rule no matter which folder it physically lives in — “all unread”, “flagged for follow-up”, “anything categorised Urgent”. The mail stays put; the Search Folder is just a smart window onto it. Set up two or three and you stop hunting through folders.

Scheduling: Calendar and Bookings

For internal scheduling, the Outlook calendar’s Scheduling Assistant shows colleagues’ free/busy so you stop the back-and-forth of finding a slot. For external scheduling, Microsoft Bookings — included in most Microsoft 365 Business plans — gives clients a public page to book a time against your real availability, with automatic confirmations and reminders. A consultancy in Box Hill we work with replaced a week of email tag with a Bookings page link in their signature; clients self-serve and the calendar fills itself.

Microsoft 365 mailbox hygiene

Rules and folders only help if the mailbox underneath is healthy.

  • Archive, do not hoard. Use the Online Archive (auto-expanding in most business plans) and a retention/archive policy so the primary mailbox stays lean. Searching a 90GB mailbox is slow and painful.
  • Unsubscribe, do not just delete. If you delete the same newsletter daily, you are doing manual labour a single unsubscribe would end.
  • Audit your rules quarterly. Old rules forwarding to a former colleague, or filing into a folder nobody opens, accumulate quietly. Prune them.
  • Keep it in folders, not the inbox. A 12,000-message inbox is a search problem waiting to happen. Let rules and Quick Steps do the filing.

A security note on forwarding rules

This one is not optional reading. Auto-forwarding rules — especially ones that quietly send copies of mail to an external address — are a classic indicator of a business email compromise (BEC). When an attacker phishes a mailbox, one of the first things they do is create a hidden rule that forwards finance-related mail out, or deletes the attacker’s own messages so the real user never sees the fraud playing out. Many breaches run for weeks behind a single forwarding rule nobody noticed.

Treat any unexpected forwarding rule, or a rule sending mail straight to Deleted Items or RSS Feeds, as a red flag worth investigating immediately. In a well-run tenant, external auto-forwarding is blocked or alerted on by default, and we monitor for rule changes as part of mailbox security. If you want the detail on how these attacks work and how to defend against them, our guide to business email security, phishing and BEC walks through it. Convenience features and attacker tools share the same plumbing here — which is exactly why the plumbing needs watching.

Frequently asked questions

Do my Outlook rules work when my computer is off?

Only if they are server-side rules. Move, forward, flag, delete and mark-as-read actions run on the Exchange Online server and work around the clock from any device. Rules with desktop-only actions — alerts, sounds, or moving to a local PST — run solely while the classic desktop app is open and are labelled “on this computer only”.

Should I use Focused Inbox or rules?

Both, for different jobs. Focused Inbox is an automatic best-guess that adapts over time and suits mail you have not specifically sorted. Rules are guarantees you write yourself for senders or subjects where you need certainty. Rules keep working whether Focused Inbox is on or off.

How do I save email templates for replies I send constantly?

Use My Templates (the snippet pane in Outlook on the web and new Outlook) for quick text blocks, Quick Parts in classic desktop when you need formatting preserved, or a saved .oft template for an entire pre-built message. For replies several staff send identically, templates keep the wording consistent.

Why should signatures be managed centrally?

Because signatures set in one Outlook app do not follow you to the web or mobile, and self-managed signatures drift into broken logos, dead numbers and inconsistent formatting. A signature applied at the Microsoft 365 service level applies to every message from every device, stays consistent, and cannot be broken by individual users.

Are forwarding rules dangerous?

Legitimate ones are fine, but an unexpected rule that forwards mail to an external address is one of the most common signs of a compromised mailbox. Attackers use them to siphon finance emails or hide their tracks. Review your rules periodically and have external auto-forwarding blocked or alerted on at the tenant level.

Make Outlook earn its keep

None of this needs new software — it is all sitting in the Microsoft 365 you already pay for. An hour spent building a handful of rules, a few Quick Steps and some templates pays itself back every single week. The catch is doing it properly: server-side where it counts, central signatures, sensible retention, and a tenant configured so the convenience features cannot be turned against you.

We are a Melbourne-based MSP with 13 Australian-employed engineers, and getting clients the full value of their Microsoft 365 — configured securely, not just switched on — is core to what we do. If you would like your tenant set up so Outlook genuinely works for your team, get in touch and we will sort it.

Microsoft Purview is Microsoft’s data governance and compliance suite inside Microsoft 365 — the rebranded, expanded successor to what used to be called the Microsoft 365 Compliance Centre. It is how you classify, protect, retain and audit your organisation’s data, and it is the layer that decides what Copilot is allowed to see.

For a Melbourne SME, the practical question is not “what is Purview” but “which bits do I already pay for, and what should I switch on first?” This post answers both, without the marketing gloss.

What Microsoft Purview actually is

Purview is an umbrella brand. Under it sit a set of tools that used to be scattered across separate portals. They are now grouped at purview.microsoft.com and broadly cover two jobs: knowing where your sensitive data is, and controlling what happens to it.

The capabilities that matter to most small and mid-sized businesses are:

  • Sensitivity labels — tags like Confidential or Internal that travel with a file or email and can enforce encryption and access rules.
  • Data Loss Prevention (DLP) — rules that stop sensitive data, such as credit card or Tax File Numbers, from leaving the organisation by email, Teams or to USB.
  • Retention policies and labels — rules that keep records for a set period and delete them when they expire, which is how you meet records-keeping obligations without hoarding everything forever.
  • eDiscovery — the ability to search across mailboxes, SharePoint and Teams to find content for a legal matter, dispute or regulator request.
  • Audit — a searchable log of who did what: who opened a file, who deleted a mailbox item, who changed a permission.
  • Insider risk management — analytics that flag risky behaviour, such as a departing employee mass-downloading client files.
  • Communication compliance — monitoring of internal messaging for harassment, code-of-conduct breaches or regulated-industry conduct rules.

You will not use all of these on day one, and you should not try to. The point is that Purview is where data governance lives once you decide to take it seriously.

What you get with Business Premium, and what needs E5

This is where most decisions get made, because the licensing split is real and it is easy to overspend or assume you have features you do not.

Microsoft 365 Business Premium — the plan most Melbourne SMEs land on — includes a genuinely useful slice of Purview. You get manual sensitivity labels, basic DLP for Exchange, SharePoint, OneDrive and Teams, basic retention policies, standard audit logging, and basic eDiscovery (search and export). For a business under 300 seats, that is enough to make a real difference.

The advanced tier sits behind Microsoft 365 E5, the E5 Compliance add-on, or standalone Purview add-ons. That is where you find automatic labelling, DLP that extends to endpoints and browsers, communication compliance, insider risk management, eDiscovery (Premium) with legal hold and review sets, and longer audit retention.

CapabilityBusiness PremiumE5 / E5 Compliance
Sensitivity labels (manual)YesYes
Automatic labellingNoYes
DLP for Exchange, SharePoint, OneDrive, TeamsYes (basic)Yes
Endpoint DLP (USB, browser, copy)NoYes
Retention policies and labelsYes (basic)Yes (auto-apply, event-based)
eDiscoveryStandard (search and export)Premium (legal hold, review sets)
AuditStandardLong-term retention
Insider risk managementNoYes
Communication complianceNoYes

The honest advice: do not buy E5 because the feature list looks impressive. Buy it when you have a specific obligation — a regulator, an insurer, a contract — that needs automatic labelling, endpoint DLP or insider risk. Most SMEs get years of value out of the Business Premium tier first. If you are weighing up the plans, our guide to what is included with Microsoft 365 support in Melbourne sets out where the lines fall.

What to do first: labels and DLP

If you take one thing from this post, take this. Start with sensitivity labels and DLP. They give you the most protection for the least effort, and everything else builds on them.

Sensitivity labels

A sensitivity label is a tag a user applies to a document or email. A typical SME set is three or four labels: Public, Internal, Confidential, and perhaps Highly Confidential. The label can be cosmetic (a footer marking) or it can enforce real controls — encryption, a watermark, blocking external sharing.

Start cosmetic, get people used to choosing a label, then add enforcement to the top one or two. A label that encrypts Confidential files means a document forwarded to the wrong address is unreadable to the recipient. That single control has saved more SMEs than any firewall rule.

Data Loss Prevention

DLP inspects content against patterns and conditions you set, then acts. The patterns Australian businesses care about are built in or easy to define: Tax File Numbers, Medicare numbers, credit card numbers, ABNs, driver licence details. A starter DLP policy might warn a user — or block outright — when they try to email a spreadsheet containing more than a handful of TFNs to an external address.

Begin every DLP rule in audit-only mode. Let it run for a fortnight, see what it would have flagged, and tune out the false positives before you switch to blocking. Turn DLP straight to block on day one and you will have the finance team locked out of legitimate work by Tuesday. DLP sits naturally alongside the rest of your cyber security services stack — it is the data-layer complement to identity controls like conditional access.

Retention, eDiscovery and audit: the records side

The governance half of Purview is about keeping the right things for the right length of time, and being able to find them.

Retention answers a question every business eventually faces: how long do we keep this? Some records have legal minimums — employee records under the Fair Work Act, financial records under the Corporations Act, health records under state health-records legislation. Retention policies enforce those minimums automatically and, just as importantly, delete data once the obligation lapses so you are not holding a decade of client files that are now pure liability.

eDiscovery earns its keep the day you receive a subpoena, a Fair Work claim or an OAIC enquiry. Instead of an engineer manually trawling mailboxes, you run a content search across Exchange, SharePoint and Teams and export exactly what is in scope. Standard eDiscovery in Business Premium handles most SME needs.

Audit is the quiet hero. When something goes wrong — a deleted file, a mailbox rule someone did not set, a permissions change — the audit log tells you who and when. It is also frequently the first thing a cyber insurer or incident responder asks for. If you are thinking about coverage, audit logging is part of what makes a claim defensible; our cyber insurance guide for Australian SMEs covers the broader picture.

Governance before AI: Purview and Copilot

This is the use case pushing Purview up the priority list for 2026. Microsoft 365 Copilot answers questions using your organisation’s data — every file, email and chat the asking user already has permission to see. That is the catch. Copilot does not break permissions; it surfaces what loose permissions already expose.

If your SharePoint has a “Company” site everyone can read, and someone parked the payroll spreadsheet there three years ago, Copilot will happily summarise salaries when an employee asks. The file was always accessible — nobody ever browsed to it. Copilot removes that friction.

This is why governance comes before AI, not after. Sensitivity labels let you mark and encrypt the data Copilot should never reuse. DLP and retention reduce the volume of stale, mislabelled data sitting in shared locations. Auditing tells you what Copilot has been asked. Switching on Copilot without doing this first is how a tidy-looking rollout becomes a quiet data-exposure incident.

The same logic applies to the Privacy Act 1988. Under the Australian Privacy Principles, you are obliged to take reasonable steps to protect personal information and to not keep it longer than needed. Reforms now working through Parliament are tightening those expectations, including around automated decision-making and data minimisation. Purview’s labelling, DLP and retention are precisely the “reasonable steps” the Office of the Australian Information Commissioner (OAIC) expects you to be able to demonstrate.

A Hawthorn scenario

A professional services firm in Hawthorn we work with wanted to roll out Copilot across forty staff. Before flicking it on, we ran a labelling and permissions review. We found three SharePoint sites with broad read access holding client financials and a folder of scanned passports from an old onboarding process. We applied Confidential labels with encryption to the sensitive sites, tightened the permissions, set a DLP rule on TFNs and Medicare numbers, and added a retention policy that purged the passport scans that should have been deleted years earlier. Copilot went live two weeks later — on data that was actually governed. The firm now has something concrete to show their professional indemnity insurer.

That sequence — govern, then enable — is the whole game. TechAssist has run Microsoft 365 for Melbourne SMEs since 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma, and the Purview-before-Copilot review has become one of the more common pieces of work we do.

Frequently asked questions

Is Microsoft Purview a separate product I have to buy?

No. Purview is the brand for governance and compliance tools built into Microsoft 365. A meaningful set is already included with Business Premium. You only pay extra — through E5 or the E5 Compliance add-on — for advanced features such as automatic labelling, endpoint DLP and insider risk management.

What is the difference between sensitivity labels and retention labels?

Sensitivity labels control protection — encryption, access and markings on a file. Retention labels control lifecycle — how long an item is kept and when it is deleted. They solve different problems and you typically use both: sensitivity to protect, retention to keep or dispose.

Do I need Purview before turning on Copilot?

You should. Copilot surfaces anything the asking user can already access, so existing over-permissioned data becomes far easier to stumble across. Sorting out labels, permissions and DLP first stops Copilot turning a hidden exposure into an obvious one.

Does Purview help with the Privacy Act?

It helps you demonstrate compliance. The Australian Privacy Principles require reasonable steps to protect personal information and to not retain it beyond need. Purview’s DLP, sensitivity labels and retention policies are practical, auditable controls that show the OAIC you have taken those steps.

Where to start

Do not boil the ocean. Pick three or four sensitivity labels, switch on a couple of DLP rules in audit mode, and set retention on your one or two most regulated record types. That alone puts you ahead of most SMEs and gives you a defensible governance baseline — and the foundation you need before any AI tool touches your data.

If you would like a hand scoping a Purview rollout, sorting your Microsoft 365 licensing, or running a governance review before you enable Copilot, get in touch with TechAssist. We will tell you plainly what you already have, what is worth turning on, and what you can safely leave alone.

For most Australian SMEs the honest answer to Microsoft 365 vs Google Workspace comes down to how your team actually works. Google suits lean, cloud-native businesses that live in a browser. Microsoft suits desktop-heavy, Windows-fleet, compliance-driven operations. Both are mature, secure platforms — the wrong fit just costs you in friction.

We’re a Microsoft-centric MSP, so I’ll declare that bias up front. But there are plenty of Melbourne businesses where I’d point a client to Google without hesitation. This is a fair comparison, not a sales pitch, and below there’s a table to cut through the marketing on both sides.

The quick comparison

AreaMicrosoft 365Google Workspace
Productivity appsFull desktop Word, Excel, PowerPoint, Outlook (plus web versions)Web-first Docs, Sheets, Slides — fast, but lighter than desktop Office
EmailExchange Online + Outlook — rich rules, shared mailboxes, calendaringGmail — excellent search and spam filtering, simpler admin
StorageOneDrive (per user) + SharePoint (team sites), 1 TB+ per userGoogle Drive + Shared Drives, pooled storage by tier
Meetings & chatTeams — meetings, chat, calls, channels, deep app integrationGoogle Meet + Google Chat/Spaces — clean, lightweight
IdentityMicrosoft Entra ID — granular conditional access, hybrid ADGoogle identity / Cloud Identity — strong, but less enterprise-deep
Admin & securityDefender, Purview, very granular controls — steep but powerfulAdmin console — simpler, faster to learn, fewer knobs
Data residency (AU)Australian data centres available for core data at restRegional storage options; some data still processed globally
Entry pricing (AUD, ex GST)Business Basic ~$8.20/user/mo; Standard ~$17.20; Premium ~$30.20Business Starter ~$10/user/mo; Standard ~$20; Plus ~$32
Best fitDesktop-heavy, Windows fleets, regulated industriesCloud-native startups, lean teams, browser-first work

Pricing changes regularly and varies by term and reseller, so treat those figures as a guide rather than a quote. The real cost difference between the two is usually rounding error compared with the cost of choosing the platform that fights your workflow.

Apps: desktop power vs web speed

This is the clearest fork in the road. Microsoft gives you the full desktop Office suite — the real Excel, with the pivot tables, Power Query, macros and add-ins that finance teams and engineers depend on. If your business runs complex spreadsheets, branded Word templates, or PowerPoint decks that have to look identical every time, desktop Office still has no equal.

Google Workspace is web-first and proud of it. Docs, Sheets and Slides load instantly, autosave constantly, and make real-time co-editing feel effortless. For a marketing agency or a startup where two people are in the same document at once all day, that collaboration model is genuinely better. The trade-off is depth: heavy Excel users hit Sheets’ ceiling quickly, and complex formatting can drift.

Where Google clearly wins: if your team already does everything in a browser and nobody opens a desktop app from one week to the next, paying for desktop Office you’ll never install is waste.

Email: Outlook vs Gmail

Exchange Online with Outlook is the workhorse of Australian business email. Shared mailboxes, delegate access, distribution groups, calendar scheduling across a team — it’s all mature and granular. For a law firm in Hawthorn juggling shared client inboxes and rigid retention rules, Exchange and Microsoft Purview make that straightforward.

Gmail’s strength is search and filtering. Its spam and phishing detection is excellent, the interface is clean, and conversation threading is hard to beat. Smaller teams often find Gmail simply gets out of the way. Either way, email is your single biggest attack surface — we cover that in our guide to business email security and BEC, and the controls matter more than the brand.

Storage: OneDrive/SharePoint vs Drive

Microsoft splits storage into OneDrive (your personal files) and SharePoint (team document libraries). Done well, SharePoint is a proper intranet and document-management system with versioning, metadata and permissions. Done badly, it’s a sprawl of sites nobody can navigate. It rewards structure.

Google Drive with Shared Drives is more intuitive out of the box. Files live where you’d expect, sharing is a couple of clicks, and there’s less to misconfigure. For a business that just wants files in folders without a SharePoint information-architecture project, Drive is the gentler path.

Meetings: Teams vs Meet and Chat

Teams is the centre of gravity in the Microsoft world — meetings, calls, persistent chat, channels and an app platform all in one. For organisations already on Microsoft, that integration is a real advantage; for ones that aren’t, Teams can feel like a lot. Plenty of people find it heavy.

Google Meet and Google Chat are deliberately lighter. Meet is reliable, browser-based and quick to join with no client to install. If your meetings are mostly external and you value “click the link and you’re in”, Meet’s simplicity is a genuine plus. Microsoft’s edge shows up in internal collaboration depth, calling features and telephony integration.

Identity, admin and security

This is where Microsoft pulls ahead for businesses that need it. Microsoft Entra ID (the identity platform formerly known as Azure AD) offers some of the most granular access controls available — you can require multi-factor authentication only from unmanaged devices, block sign-ins from outside Australia, or enforce compliant-device checks. We walk through this in our piece on conditional access policies in Microsoft 365. Defender and Purview add threat protection and data-loss prevention that map neatly onto frameworks like the Essential Eight.

Google’s admin console is more approachable. Fewer settings means less to get wrong, which for a small team without dedicated IT is a real benefit. Google’s identity and security are strong — context-aware access and solid MFA — but Microsoft’s controls go deeper for complex, regulated or hybrid environments where on-premises Active Directory is still in the mix.

Compliance and data residency

For Australian businesses bound by the Privacy Act and the OAIC’s Notifiable Data Breaches scheme, data residency and auditability matter. Microsoft offers Australian data centres for core data at rest and gives detailed control over retention, legal hold and audit logging through Purview — useful for sectors under AHPRA, ASIC or similar oversight.

Google Workspace provides regional storage options and strong compliance certifications, though some processing still happens across its global infrastructure. For most SMEs that’s perfectly acceptable. For a healthcare practice or a firm with strict data-handling obligations, Microsoft’s granular controls usually make the compliance conversation easier — see our notes on healthcare IT and OAIC obligations.

Migration effort

Moving platforms is rarely trivial. Email migrates reasonably well in both directions, but the friction lives in the details: shared mailboxes, calendar permissions, distribution lists, and re-training people on a new interface. Document migration is messier — Google formats don’t always survive a clean trip into Office, and complex Excel or SharePoint structures don’t always land neatly in Sheets and Drive.

The practical rule is to migrate once, deliberately, and stay put. Bouncing between platforms because of a price tweak costs far more in lost time than it saves. Whichever way you go, plan the cutover properly and run the two systems in parallel briefly so nothing falls through the cracks.

A Melbourne example

A construction firm in Box Hill we work with came to us split down the middle — the site teams lived in Gmail on their phones, while the office ran Excel-heavy estimating and project schedules that Sheets simply couldn’t handle. They’d been arguing about it for a year. We standardised them on Microsoft 365 because the desktop Office dependency was non-negotiable for their estimators, then used Teams to pull the field and office staff onto one platform. Had their work been browser-only, we’d have recommended Google and meant it.

That’s the point. TechAssist is a Melbourne-based MSP founded in 2014 with 13 Australian-employed engineers, and most of our client base runs Microsoft because that’s where desktop-heavy, compliance-driven Australian businesses tend to land. But the right answer is the one that fits how your people actually work, not the one your MSP is most comfortable supporting.

Frequently asked questions

Is Microsoft 365 more secure than Google Workspace?

Neither is inherently more secure — both are mature, well-defended platforms. The difference is control depth. Microsoft Entra ID and Defender offer more granular configuration, which helps in regulated or complex environments. Google’s simpler model means fewer settings to misconfigure, which suits smaller teams. Security comes from how you configure either platform, not the logo.

Can I run both Microsoft 365 and Google Workspace?

You can, and some businesses do — for example, Microsoft for email and Office, Google for a specific cloud tool. But running both means two sets of licences, two admin consoles and two security surfaces to manage. For most SMEs the overhead outweighs the benefit. Pick one as your primary platform.

Which is cheaper for a small Australian business?

Entry tiers are close — Microsoft 365 Business Basic and Google Business Starter sit within a few dollars of each other per user per month. The bigger cost is fit: paying for desktop Office you never use, or wrestling with Sheets when you need real Excel, costs far more than the licence-price gap.

How hard is it to migrate from Google to Microsoft?

Email migrates fairly cleanly; documents and shared-drive structures are where the work lives. Expect format conversion, permission rebuilding and user re-training. With a planned cutover and a short parallel-run period it’s very manageable — the mistake is doing it ad hoc without a migration plan.

Getting the decision right

If your business is lean, cloud-native and browser-first, Google Workspace is a strong, often better choice — and we’ll tell you so. If you’re desktop-heavy, running a Windows fleet, or carrying real compliance obligations, Microsoft 365 usually wins, and it’s where our Microsoft 365 support is built to add the most value with security and identity configured properly rather than left on defaults.

Not sure which way to jump? Get in touch and we’ll look at how your team actually works before recommending anything. No pressure to switch, and an honest answer either way.

Windows Autopilot is a Microsoft service that lets a brand-new laptop set itself up automatically the first time a staff member turns it on. The device ships from the vendor straight to the user, connects to your Microsoft tenant over the internet, and configures itself — no imaging, no SOE, no IT hands on it.

If onboarding a new hire still means a laptop landing on an engineer’s desk for a day of imaging, this is the fix. Below: what Autopilot does, how a device self-provisions, the moving parts, the deployment modes, the licensing, and where an MSP fits in.

What Windows Autopilot actually is

Autopilot is not an imaging tool — there is no gold image and no USB stick. It takes the standard Windows installation the manufacturer already put on the device and transforms it into your corporate build during the out-of-box experience (the setup screens a user sees on first boot). It runs on two Microsoft cloud services: Microsoft Entra ID (formerly Azure AD) handles identity and joins the device to your directory, and Microsoft Intune — the mobile device management (MDM) platform inside Microsoft 365 — pushes down your policies, apps, baselines and configuration. A machine the user has never touched arrives configured exactly like every other device in the business, enrolled, encrypted and ready to work.

The problem it solves: no more manual imaging or SOE

The traditional approach was the Standard Operating Environment: you built a master image, captured it, and re-applied it to every new or rebuilt machine. The costs add up. Devices have to be shipped to IT first, imaged, then re-shipped to the user — adding days and double the freight. The image goes stale the moment it is captured and needs constant rebuilding. And it does not scale: imaging a laptop for someone starting in a Dandenong warehouse means shipping it to your office or sending an engineer out.

Autopilot removes the imaging step entirely. The configuration lives in the cloud and is applied at first boot, so the same provisioning works whether the user is in your CBD office or at home in Ringwood.

How a device self-provisions on first login

The sequence when an Autopilot-registered device is unboxed:

  1. The user powers on the laptop and connects to Wi-Fi or ethernet — internet access is the only prerequisite.
  2. Windows checks in with Autopilot, recognises the device by its hardware identity, and pulls down the assigned profile, which customises the setup screens and applies your branding.
  3. The user signs in with their Microsoft 365 work account; Entra ID authenticates them and joins the device to your directory.
  4. Intune enrolment kicks off automatically, pulling down your configuration profiles, security baseline, certificates, Wi-Fi settings and assigned apps.
  5. The Enrollment Status Page blocks the user from reaching the desktop until the mandatory apps and policies have landed.

When it finishes, the first person to log into that machine is the staff member it was bought for — not an engineer — at a fully managed, encrypted desktop.

The moving parts

Autopilot profiles

A profile is the deployment template you assign to a group of devices in Intune. It controls the out-of-box experience: which setup screens are hidden, whether the user becomes a local administrator or standard user, the deployment mode, the naming convention and your branding. Most businesses run one or two — a user-driven profile for staff laptops, sometimes a separate one for shared devices.

The Enrollment Status Page

The Enrollment Status Page (ESP) shows setup progress and gates access to the desktop until the apps and policies you mark mandatory have installed — so a new starter cannot begin work on a half-configured machine. Block on a slow or flaky app, though, and you leave users staring at a spinner; tuning it well is one of the fiddlier parts of the job.

Hardware hash and device registration

Autopilot identifies each device by a hardware hash — a unique fingerprint of its components — which must be registered against your tenant before first boot. With OEM / CSP registration, the hardware vendor or Cloud Solution Provider partner registers the hash to your tenant at purchase, so the device is Autopilot-ready before it leaves the warehouse — the clean path for volume orders. For devices you already own, manual hash collection exports the hash into Intune with a PowerShell script, but that means handling the device once. Build OEM or CSP registration into your procurement so hardware arrives pre-registered; that is what makes true drop-ship onboarding possible.

Deployment modes: user-driven vs self-deploying and kiosk

Autopilot supports several modes, depending on how the device will be used:

ModeHow it worksBest for
User-drivenUser signs in with their work account; the device joins Entra ID and binds to themStandard staff laptops
Self-deployingNo credentials entered; the device provisions itself end to end, using the TPM to prove its identityShared devices, digital signage, meeting-room PCs
KioskA self-deploying device locked to a single app, with no general desktopFront-of-house terminals

User-driven is what most growing teams use. Self-deploying and kiosk modes suit devices no single staff member owns — a reception terminal in a Hawthorn clinic, a warehouse scanning station — and need a TPM 2.0 chip, which any recent business device has.

Prerequisites: what you need before you start

Autopilot is not a standalone product — it is a capability on top of Microsoft 365. You need:

  • Microsoft Entra ID for identity and device join — the standard directory in a Microsoft 365 business or enterprise subscription covers this, though some advanced enrolment options want Entra ID P1.
  • Microsoft Intune licensing for the MDM management — included in Microsoft 365 Business Premium and the E3/E5 plans. On a cheaper plan you will need to add Intune first.
  • Devices that ship with Windows 11 Pro or Enterprise — the Home edition cannot be managed this way.
  • A configured tenant — your Intune profiles, security baselines, app deployments and ESP set up before the first device ships.

That last point is the one businesses underestimate: Autopilot delivers whatever you have built in Intune, so the value is in the policies and app packaging, not the provisioning trick itself. If you are reviewing your licensing, our Microsoft 365 support team can tell you whether your plan already covers what Autopilot needs.

Why this matters: fast onboarding and consistent security baselines

Two things drive most businesses to Autopilot. The first is onboarding speed: a drop-shipped self-provisioning laptop takes the engineer, the queue and the freight out of every hire. The second, and arguably more important, is consistent security baselines. Because every device is built from the same Intune configuration, every machine gets BitLocker encryption, the same firewall and account-protection policies, Defender, conditional access and patching automatically — no engineer remembering to tick a box. An enforced baseline across the fleet is exactly what the Essential Eight mitigation strategies expect, and the same Intune layer lets you wipe a lost device remotely the moment a laptop goes missing on a train at Box Hill — it pairs naturally with conditional access policies in Microsoft 365.

A Melbourne scenario

An engineering consultancy in Camberwell we work with was hiring two or three people a month and rebuilding laptops by hand each time — a machine couriered to their office, half a day of imaging, and a checklist someone occasionally skipped, so no two laptops were quite the same and a couple shipped without disk encryption on.

We stood up their Intune configuration, built a user-driven Autopilot profile with a tuned Enrollment Status Page, and arranged for new hardware to be registered at purchase. Now a laptop is drop-shipped to the new hire; they open the box, sign in, and an hour later are working on a fully configured, encrypted device identical to everyone else’s. Their office manager handles onboarding without touching a technical step, and the fleet has a uniform baseline at last.

The MSP role in setting it up

The provisioning is the easy part to demonstrate and the hard part to build well. The work an MSP does sits underneath what the user sees:

  • Designing and hardening the Intune configuration — the compliance policies, configuration profiles, security baselines and app deployments every machine inherits — and packaging line-of-business apps to install silently during enrolment.
  • Setting up the procurement pipeline so devices arrive Autopilot-ready, tuning the ESP, and integrating Autopilot with conditional access, encryption and your broader MDM strategy so device management is one coherent system.

TechAssist is a Melbourne MSP, founded in 2014, with thirteen Australian-employed engineers — so the people building your Intune environment are local, not offshore. We bundle this into our managed IT services, so device provisioning, patching and security baselines sit inside the fixed monthly per-user fee, not a per-device charge each time you hire.

Frequently asked questions

Do I need to wipe a new laptop before using Autopilot?

No. Autopilot works with the standard Windows installation the manufacturer ships and transforms it into your corporate configuration during first boot — there is no wiping or imaging step. Devices you already own can be reset and will provision on the next boot once registered.

What happens if there is no internet during setup?

Autopilot needs internet to reach Entra ID and Intune, so the device must connect to Wi-Fi or ethernet during the out-of-box experience. Until it does, the laptop sits at the network screen — which is why drop-ship onboarding assumes the user has working internet.

Is Autopilot the same as Intune?

No, but they work together. Intune is the management platform that holds your policies, apps and baselines; Autopilot hands a new device over to Intune at first boot. You need Intune licensing for Autopilot to do anything.

Where TechAssist fits

Autopilot looks like magic in a demo and falls over in practice if the Intune configuration behind it is thin — the provisioning is the visible part, but the policies, baselines and procurement pipeline are what make the fleet secure and consistent. If manual device setup is slowing your onboarding, get in touch and we will scope what your tenant needs.

Microsoft Defender for Business is Microsoft’s endpoint detection and response (EDR) product built specifically for small and mid-sized businesses. It bundles next-generation antivirus, EDR, threat and vulnerability management, attack surface reduction and automated investigation into one licence — enterprise-grade endpoint security at a price an SME can actually justify.

It is not the same as the free Defender that ships with Windows

This is the confusion we untangle most often. Every Windows 10 and Windows 11 machine already includes Microsoft Defender Antivirus — the free, built-in scanner that replaced the old Windows Defender. It is genuinely good antivirus. It catches known malware, runs real-time scanning, and for a home PC it is fine.

Microsoft Defender for Business is a different product that sits on top of that engine. The free antivirus protects a single device and tells that device about a threat. Defender for Business adds the layer enterprises pay for: it collects telemetry from every endpoint into a central portal, correlates suspicious behaviour across your fleet, hunts for attacker activity that signature-based antivirus never sees, and gives someone a console to investigate and respond. Antivirus asks “is this file bad?”. EDR asks “is something bad happening on this network right now, and how did it get in?”.

A small construction firm in Ringwood we onboarded last year had Defender Antivirus on every laptop and assumed they were covered. They were covered against commodity malware. They had no visibility into lateral movement, no record of what a compromised account did after a phishing click, and no way to isolate an infected machine remotely. That gap is exactly what Defender for Business fills.

How you get it: Business Premium or standalone

There are two ways to licence it. The first, and the one most Melbourne SMEs land on, is Microsoft 365 Business Premium. Defender for Business is included in that plan at no extra cost, alongside the Office apps, Exchange Online, Intune device management and conditional access. If you are already paying for Business Premium, you own Defender for Business whether or not anyone has switched it on — which, frustratingly often, nobody has.

The second is the standalone Defender for Business licence, sold per user per month for organisations that do not want the full Business Premium stack. It is capped at 300 users, in line with Microsoft’s SMB licensing ceiling. Above that you move into the enterprise Defender for Endpoint Plan 1 or Plan 2 tiers.

For most businesses under 300 staff, Business Premium is the better value because you get the security plus Intune, conditional access and the rest of the productivity suite for not much more than the standalone security licence alone. We cover what that plan actually includes in our guide to Microsoft 365 support in Melbourne, and we deploy it through our Microsoft 365 service.

What it actually does

Defender for Business is not a single feature — it is five capabilities working together. Here is what each one buys you in practice.

Next-generation antivirus

The same cloud-delivered protection as the enterprise product: behaviour-based detection, machine-learning models and near-instant cloud lookups, rather than just a local signature file. It blocks fileless attacks and never-before-seen malware that traditional antivirus misses, and it updates protection across your fleet from the cloud in minutes.

Endpoint detection and response (EDR)

This is the heart of it. Every endpoint reports process activity, network connections and file changes back to the Microsoft 365 Defender portal. When something looks like an attack — credential dumping, suspicious PowerShell, a process spawning where it shouldn’t — it raises an alert with the full chain of what happened. You can remotely isolate a device from the network, collect an investigation package, or stop and quarantine a file across every machine at once.

Threat and vulnerability management

It continuously inventories the software on your devices and flags known vulnerabilities and misconfigurations, ranked by real-world risk. Instead of guessing which of 40 outstanding updates matters, you get a prioritised list: this unpatched browser is being actively exploited, fix it first. This feeds directly into Essential Eight patching discipline.

Attack surface reduction

A set of rules that close the doors attackers walk through — blocking Office apps from spawning child processes, stopping credential theft from the Windows credential store, controlling which USB devices can mount, and filtering web content. These map almost one-to-one to the application control and macro restrictions in the Essential Eight.

Automated investigation and remediation

When an alert fires, Defender can automatically investigate it the way a junior analyst would — examining the affected device, determining whether the threat is real, and remediating low-risk detections without a human touching it. For a small team with no overnight security staff, this quietly handles a lot of the noise so the genuine incidents are the ones that reach a person.

Onboarding devices: Windows, macOS and mobile

Coverage is not Windows-only, which matters because most Melbourne SMEs run a mix. Windows 10 and 11 onboard cleanly through Intune or a local script and need no extra agent — the sensor is already in the operating system. macOS is supported with a downloadable agent, so the designer’s MacBook in the same office gets EDR too. iOS and Android are covered through the Defender app via Intune, mainly for web protection and phishing defence on phones that touch company email.

In a typical rollout we push the Windows configuration through Intune policy, deploy the macOS agent to the handful of Macs, and enrol mobiles through the company portal. Servers are worth noting: Defender for Business includes a server add-on (Defender for Business servers) licensed per server per month, so the Windows Server running your file shares or line-of-business app gets the same EDR coverage. We handle this fleet-wide as part of managed cybersecurity and managed IT services.

How it maps to the Essential Eight

The Australian Cyber Security Centre (ACSC) Essential Eight is the baseline most Australian SMEs are measured against, especially for cyber-insurance and government-adjacent work. Defender for Business does not deliver all eight on its own, but it directly supports several and gives you the evidence to prove it.

Essential Eight mitigationHow Defender for Business helps
Patch applicationsThreat and vulnerability management inventories software and prioritises exploited vulnerabilities
Patch operating systemsSurfaces missing OS updates and known exploited flaws across the fleet
Application controlAttack surface reduction rules block untrusted executables and Office child processes
Configure macro settingsASR rules restrict malicious Office macro behaviour
User application hardeningWeb protection and ASR harden browsers and block credential theft

It does not cover multi-factor authentication, restricting administrative privileges, application allow-listing in full, or regular backups — those need Entra ID conditional access, Intune policy and a separate backup platform. For the full picture, see our Essential Eight compliance work. Defender for Business is a strong contributor to maturity, not a one-click compliance button.

The honest question: is it enough, or do you still need a SOC?

Here is the part most vendors skip. Defender for Business is excellent technology. It is also only as good as the person reading the alerts. The product will detect the ransomware operator moving through your network at 2am on a Sunday — but if nobody is watching the portal at 2am on a Sunday, the alert sits unread until Monday, by which point the damage is done.

This is the difference between having an EDR tool and having managed detection and response. The licence gives you the sensor and the console. It does not give you a human who triages alerts around the clock, escalates the real ones, and actually responds. For a 15-person firm, expecting your one IT-savvy staff member to monitor a security console alongside their day job is wishful thinking.

You have three realistic options. Watch it yourself, which works only if you have someone genuinely capable and available. Accept that alerts get reviewed during business hours and live with the overnight gap — defensible for lower-risk businesses, not for anyone holding sensitive client data. Or put it under managed detection and response, where a team monitors the telemetry 24/7. We dig into the distinctions between SIEM, MDR and EDR in our piece on managed cybersecurity services, and our security operations centre is how we close that monitoring gap for clients who need eyes on the alerts at all hours.

The blunt version: buying Defender for Business and switching it on is the right move for almost every SME. Believing that alone means you are protected is the mistake. A smoke detector that nobody can hear is decoration.

Frequently asked questions

Do I need Defender for Business if I already have Microsoft Defender Antivirus?

Yes, if you want real endpoint detection and response. The built-in antivirus protects individual devices against malware but gives you no central visibility, no investigation tools, no vulnerability management and no way to respond across your fleet. Defender for Business adds all of that. They work together — the antivirus is the foundation, Defender for Business is the security operations layer on top.

Is Defender for Business included in Microsoft 365 Business Premium?

Yes, at no additional cost. If you pay for Business Premium you already own it, even if it has never been configured. It is also sold as a standalone per-user licence for businesses that do not want the full Business Premium suite, capped at 300 users.

Will Defender for Business make me Essential Eight compliant?

No single product does that. It strongly supports patching, application control, macro settings and user application hardening, and it produces evidence for assessments. But you still need multi-factor authentication, restricted admin privileges and tested backups from other tools to reach a defensible Essential Eight maturity level.

Can it protect Macs and phones, not just Windows?

Yes. macOS is supported with a dedicated agent, and iOS and Android are covered through the Defender mobile app deployed via Intune, mainly for web and phishing protection. There is also a per-server add-on for Windows Server. A mixed fleet can be fully covered under one approach.

Do I still need a managed SOC if I have Defender for Business?

It depends on who watches the alerts. The tool detects threats brilliantly but does nothing on its own about an alert raised overnight or on a weekend. If you do not have someone monitoring the console around the clock, managed detection and response fills that gap. For most SMEs with sensitive data, that monitoring is what turns the licence into actual protection.

The short version

Microsoft Defender for Business gives Melbourne SMEs the same class of endpoint security that large enterprises run — next-gen antivirus, EDR, vulnerability management, attack surface reduction and automated investigation — included free with Microsoft 365 Business Premium or available standalone. It is a genuinely strong product and an easy decision to deploy. The catch is that the technology only protects you if someone acts on what it finds. As a Melbourne-based MSP with 13 Australian-employed engineers and a 24/7 NOC in Tecoma, that is the half we handle. If you are paying for Business Premium and have never switched the security on, or you are not sure anyone is watching the alerts, get in touch and we will tell you straight where you stand.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.