July 01, 2026 by Lionel Pinkhard
I usually write about how we help clients grow. This post is different. It is about the software that runs our own company — Microsoft 365 — and about a project we undertook to migrate to it and secure it properly. I want to share it because the questions we asked ourselves are the same questions every growing business eventually faces: where does our email live, how do our people collaborate, where do our documents go, and who is responsible for keeping all of it secure?
We are a founder-led digital growth and technology agency with a hybrid and remote team. That structure is a gift for talent and a challenge for operations. People work from different cities and time zones, on different devices, on client work that has to stay organized and confidential. The platform we run the business on is not a side detail. It is the backbone.
Here is how we use Microsoft 365, why we chose it, and — more importantly — what the migration taught us about the difference between buying a platform and owning it.
Why We Chose Microsoft 365
There is no shortage of tools a small agency can stitch together: one product for email, another for chat, another for file storage, another for video calls. We ran a version of that patchwork in our early days, and it worked until it did not. Files lived in three places. Permissions were inconsistent. Onboarding a new team member meant setting up half a dozen separate accounts. Every tool was one more login, one more bill, and one more thing that could be misconfigured.
We chose Microsoft 365 because it consolidates the core of how a company operates into a single, well-governed platform:
- Email and calendaring through Exchange Online, with a professional domain and reliable deliverability.
- Real-time collaboration through Microsoft Teams for chat, calls, and meetings.
- Document management through SharePoint and OneDrive, with proper version history and access control.
- The Office applications — Word, Excel, PowerPoint, Outlook — that clients and partners expect to exchange work in.
- Identity and access management through Microsoft Entra, which ties every one of the above to a single, controllable set of user accounts.
That last point is the one most businesses underestimate, and it is the one that changed how I think about the whole platform. When identity is centralized, everything else becomes governable. You add a person once and grant them the right access. You remove a person once and their access to everything is gone. For a company that handles client data, that is not a convenience — it is a control.
How It Actually Helps Us Day to Day
The value shows up in the ordinary moments, not the feature list.
Collaboration without chaos. Our team can co-author a proposal in real time, drop it into the right SharePoint library, and know that the version a client sees is the current one. Comments, tracked changes, and shared calendars mean a distributed team behaves like a team in one room. For hybrid work, this removes an enormous amount of friction.
One source of truth for documents. Client deliverables, contracts, brand assets, and internal process docs live in structured SharePoint sites and OneDrive rather than scattered across personal drives and email attachments. When someone leaves a project or the company, their work does not leave with them.
Reduced operational distraction for leadership. This is the honest, human part. I have the technical ability to configure much of this myself. What I did not want was to be the IT department. Every hour spent tuning mail flow rules or chasing a permissions problem is an hour not spent on strategy, engineering, or clients. A consolidated platform, properly set up, gives that time back.
Predictable, scalable onboarding. Adding a team member is now a repeatable process rather than an improvisation. Licenses, mailbox, storage, and access policies follow a standard. That consistency is what lets a small company scale without the wheels coming off.
The Migration: Buying Is Easy, Owning Is the Work
Here is the lesson I most want other business owners to take from this post.
Purchasing Microsoft 365 is trivial. You enter a credit card, pick a plan, and you have licenses in minutes. What you do not have, at that moment, is a secure, well-governed environment. The default state of any new tenant is a starting point, not a finished configuration. The real project is everything that happens after the purchase: identity hardening, email protection, access governance, and the ongoing discipline of keeping it that way.
We treated our migration as exactly that kind of project — and we deliberately did not do it alone. We brought in MoreMax, a managed IT and cybersecurity firm, to handle the setup and security hardening. MoreMax documented the engagement in a case study on their own site: Microsoft 365 Setup & Security Hardening. I would encourage anyone weighing a similar move to read it, because it lays out the work in concrete terms rather than marketing language.
The reasoning behind bringing in a specialist was simple, and I will quote what I told them at the time: “I had the technical ability to do much of it myself, but I did not want IT admin.” Knowing how to do something and having the time and focus to do it correctly, continuously, are two different things. Security in particular is not a one-time task. It drifts. Configurations that were correct on day one erode as people, devices, and requirements change.
What the hardening actually involved
The work MoreMax did on our environment centered on the areas that matter most for a business our size:
- Identity and access management. Multi-factor authentication and Conditional Access policies, so that access decisions consider who is signing in, from where, and on what device — not just whether they have the password. Microsoft’s own guidance treats Conditional Access as the Zero Trust policy engine, built on the principle of “verify explicitly, use least privilege, assume breach.”
- Email security hardening. Protections against phishing and impersonation, which remain the most common way businesses are compromised. Year after year, the Verizon Data Breach Investigations Report finds that the human element — people being tricked, not systems being hacked — is involved in the large majority of breaches. Email is where that battle is mostly fought.
- Administrative role review. Applying least-privilege principles so that administrative access is granted narrowly and intentionally, rather than everyone accumulating more power than their role requires.
- SharePoint and OneDrive governance. A deliberate structure and permission model so that collaboration is easy internally and controlled externally.
- A security baseline and drift monitoring. Establishing a known-good configuration and watching for the inevitable drift away from it over time.
None of this is exotic. It is the unglamorous, foundational work that separates a business that merely has Microsoft 365 from one that securely owns it. Turning on MFA alone dramatically reduces the risk of account compromise — it is one of the highest-leverage security controls available to any organization, which is why Microsoft and government cybersecurity agencies alike push it so consistently.
What This Taught Us About Serving Our Own Clients
Living through our own migration made us better at the work we do for others. We build websites, applications, and marketing systems for businesses in real estate, home services, hospitality, and technology — and every one of those systems touches customer data, identity, and access.
Experiencing the difference between a default setup and a hardened one, on our own infrastructure, reinforced a principle we already believed: security and governance are not features you bolt on at the end. They are decisions you make at the foundation. It is the same philosophy we apply when we design a platform or a growth system for a client — build it to be owned properly, not just launched.
It also clarified when to bring in a specialist versus when to do it yourself. We are an engineering-capable company, and we still chose to have a dedicated cybersecurity partner handle the parts of our environment where the cost of a mistake is high and the work is continuous. That is not an admission of weakness. It is exactly the kind of focused decision that lets a growing business put its energy where it creates the most value.
The Takeaway for Growing Businesses
If you are considering Microsoft 365 — or already pay for it and are not sure it is set up correctly — here is what our experience suggests:
- Consolidate deliberately. The value of Microsoft 365 comes from putting email, collaboration, documents, and identity under one roof. A patchwork of disconnected tools is more expensive in every way that eventually matters.
- Separate the purchase from the project. Buying licenses is step one of about twenty. Budget time and attention — or a partner — for the configuration, security, and governance that follow.
- Treat identity as the foundation. Multi-factor authentication, Conditional Access, and least-privilege administration are the controls that protect everything else. Do them first, not last.
- Decide honestly what to own and what to delegate. Knowing how to do something is not the same as having the focus to do it well, forever. There is no prize for being your own understaffed IT department.
We run Infinity Curve on Microsoft 365 because it lets a distributed, hybrid team operate like a single, organized company — and because, with the right foundation under it, we can trust it with the work our clients trust us to do.
If you are building or scaling a technology-forward business and want a partner who thinks about platforms, security, and growth as one connected system, explore our technology sector solutions, our web application security services, or get in touch to talk through where you are headed.