Free guide · Executives & the admins who support them

The Unification Project

You run more than one email address, and probably more than one company. Here is how to put all of it on your laptop and your phone — safely, and in a way your IT admin can stand behind.

2Devices, one identity
<1 dayTypical build time
2 tracksExec + Admin
00 Foreword

This isn't textbook best practice. It's the best version of your practice.

Best practice says don't do this at all. One identity, one device, keep personal and business fully separate — every company, kept on its own hardware, never touching your own inbox. That's the textbook answer, and it's correct.

Most executives can't live that way, and that's not a discipline problem. You own more than one company, or you sit on more than one board, or you have a life outside the P&L — and you check all of it from the same phone. Once you're senior enough, "just don't do that" stops being a real option. This guide starts from that reality instead of arguing with it.

So here is the secure way to blend personal and multiple companies on one laptop and one phone: as safe as the situation allows, as easy for your IT admin to support as we can make it, and as close to real best practice as possible. Every choice below is the most secure, most supportable version of an arrangement that will never be perfectly clean — built so your admin can sleep, and so you don't have to think about any of it again after the first afternoon.

Read this before you build anything One rule survives every version of this guide: business mailboxes never forward mail out, and never accept a forward in. Everything else here is about making two or three Microsoft tenants — Microsoft's term for a separate, self-contained business account, one per company — and one personal life share a device peacefully. That one rule is what keeps them from also sharing their mail.
01 Is this you?

The shape of the problem

This guide is for exactly one situation. If it doesn't describe you, most of it still applies — just skip what doesn't.

  • You have a personal email address (Gmail, Yahoo, AOL, or your own domain) that's been yours for years and isn't going anywhere.
  • You have one or two Microsoft 365 business accounts — your own company, a company you invested in, a board seat, a family business — and they're run by different IT admins who don't talk to each other.
  • You want to check all of it from one laptop and one phone, without three different sign-in prompts fighting for your attention every time you tap the mail icon.
  • You are willing to accept that this device will never be as clean as a single-purpose company laptop — in exchange for it being usable.
02 The shape of the fix

One hub. Everything else layers underneath it.

The whole guide is one idea, applied consistently: pick a single personal identity as your contacts-and-calendar hub, then add every business mailbox to your devices as a guest — never as the owner, and never with a return path back out.

Diagram: personal hub in the center, two business tenants and legacy personal mail feeding in one-way, laptop and phone layered on top, nothing feeding back out Personal hub contacts + calendar Legacy personal Yahoo / AOL — retiring Northline Metal Works daily driver, device-joined, no forward Vantage Public Affairs app-only, no device join, no forward Laptop + phone both devices, layered on top

Solid arrow = mail actually forwards this direction. Dashed line = mail is added as an account, never forwarded — the tenant keeps its own mailbox and nothing leaves it.

03 Estimate your time

How long this actually takes

Answer a few questions about your actual setup. This is the same estimate we quote clients for the exact same build — adjusted up if you're doing it yourself instead of handing it to an admin. Your answers are remembered if you come back.

1
Laptops
1
Phones
1
Yahoo
1
AOL
0
Old Gmail
0
Everything else
0
Adding a hardware keyYubiKey or similar, per device owner
Doing this yourselfOff = your IT admin does it
Estimated time
hrs
If an admin does it
If you DIY
Estimated project cost, if we do it for you
$–
See what's included, and the fine print →
Rough guide, not a quote. Two tenants with prior conditional-access lockouts, forgotten admin passwords, or a company that's merged/renamed recently will run longer — see the Foreword.
04 Choose your personal hub

Where your contacts and calendar actually live

Every business account you add gets layered underneath this one identity. Get this choice right and everything downstream gets easier.

The standard — we recommend this

Custom domain via Microsoft 365 Business Basic

A single self-administered, one-person Microsoft 365 tenant — roughly $6–8.40/user/month depending on billing. Yes, it's technically a tiny business tenant, but you're the only person in it and you administer it yourself. This is how you get a real custom domain through Microsoft without an MSP, now that Microsoft's old personal-tier custom-domain option is gone (see below). It is also the only hub an outside IT provider — ours or anyone's — can genuinely support.

  • Self-service, no MSP or IT department needed
  • A real custom domain address you control
  • Outlook.com-grade rules engine, same server-side reliability taught in Chapter 7
  • Supportable: GDAP and standard admin access work exactly as described in this guide
Supportable, but slower

Own domain via Cloudflare + Google Workspace

Register a domain through Cloudflare (~$10–15/yr), route it to a Google account. For people who want to stay in Google's ecosystem for their own custom domain. Workspace has an admin console, so delegated support is possible — just expect any admin task to take longer than the Microsoft equivalent.

  • Cloudflare Email Routing forwards it for free — no separate mail hosting bill
  • Survives you leaving Google entirely later — the domain moves with you

Doesn't have to catch everything — in the Cloudflare dashboard's Email Routing rule you can exclude specific senders or domains if you want a few things to stay on the old address.

Not recommended — largely unsupportable

Free personal Gmail

Listed because so many readers already have one, not because it's a good hub. A free consumer Gmail has no admin or delegation mechanism at all, so nobody outside can ever act on your behalf — not us, not your own IT. It works only for a reader who will never want help with this setup.

  • Zero cost, zero setup — and zero support path
  • If you keep it, plan to do every step in this guide yourself, forever

Business Basic is the standard. It's the only option above that gets you a real, Microsoft-native custom domain without ever needing to loop in an MSP, and the only one anyone can properly support — which matters, because everything else in this guide is already a Microsoft-centric build. Google Workspace is a workable second choice if you are committed to Google. Free Gmail is not a hub we recommend to anyone who might ever want help.

Which of these can we actually help you with?

This is worth knowing regardless of whether you ever hire us for anything — it's a real technical tradeoff, not a sales pitch. Support from an outside IT provider depends entirely on whether that provider can actually get into the account, and the three hub options above are not equal on that front.

  • M365 Business Basic — works cleanly. It's a real Microsoft tenant, which means GDAP and standard admin access both work exactly as described throughout this guide. This is the option that pairs best with real outside support, ours or anyone else's.
  • Cloudflare + Google Workspace — technically supportable. Workspace has its own admin console, so delegated access is possible. Worth knowing plainly, though: Google Workspace IT work generally runs about 50% longer than the equivalent Microsoft admin work, for any given task — ours or your own internal IT's. It's not that we can't help here, it's that it's slower, and slower costs more in practice. We'd need the same kind of admin-level access here as with Microsoft.
  • Personal Gmail (free/consumer, not Workspace) — the one to flag hardest. A free consumer Gmail account has no delegation or admin mechanism at all. The only way anyone outside could get in is if you handed over your actual account password — which we don't do, and no provider that takes security seriously should. If you want any real, meaningful support from us (or anyone) going forward, a free personal Gmail hub isn't a workable choice. Either pick one of the other two options, or go in understanding that support will be severely limited — effectively "we can advise, but we can't act on your behalf" — for as long as you stay on it.
Watch for this one Microsoft's consumer plans — Microsoft 365 Personal and Family — don't support adding a custom domain. If you want a custom domain through Microsoft without an MSP, Business Basic (above) is the real path.
Pay attention The recommended default recipient for forwarded mail is your Business Basic custom domain mailbox — that's what "a personal Microsoft account" means throughout this guide — despite being more setup work than Gmail. Two reasons: its rules and categories mirror what you already use for work, and its web-based rules are server-side and survive your laptop being off, exactly like the OWA rule-reliability behavior taught in Chapter 7. A free consumer account at outlook.com or live.com is not what we mean by this and isn't something we recommend setting up new — see "Which of these can we actually help you with?" above for exactly why. Free Gmail is not a recommended hub. It is workable only for a reader who will never want outside help with this setup; for everyone else it is largely unsupportable, for the reasons above.
Security: comparableEffort: Microsoft costs more setup time

Out options (retiring these as active inboxes): Yahoo, AOL, and optionally an old Gmail or Hotmail/Outlook.com/Live account. In option (the hub itself): your Business Basic custom domain (the standard), or — not recommended — a Gmail you already own — never a free consumer Microsoft account, and never a business tenant. Business mailboxes are never a valid forwarding target, in either direction — see the confirmation step in Chapter 7.

Before you follow these literally Providers change their settings screens over time. If a detailed step below doesn't match what's on your screen, fall back to the high-level version — look for a gear icon and, if the settings page has one, a search box you can type "Forwarding" or "Domains" into.

Setting up a custom domain via Microsoft 365 Business Basic

  • Sign up for Business Basic at microsoft.com.
  • In the Microsoft 365 admin center, go to Settings → Domains → Add domain.
  • Run the verification wizard (one-click via Domain Connect on supported registrars like GoDaddy, or manual TXT/MX records otherwise).
  1. Sign up at microsoft.com/microsoft-365/business/microsoft-365-business-basic — this creates your own one-person tenant.
  2. Sign in to the Microsoft 365 admin center and go to Settings → Domains → Add domain.
  3. Enter the domain you already own (or register one first through any registrar).
  4. If your registrar is a Domain Connect partner (GoDaddy and several others), the wizard verifies and configures DNS in close to one click. Otherwise, you'll add a few technical domain-ownership records manually — a TXT record to prove you own the domain, then MX and CNAME records to point mail at Microsoft. If those terms are unfamiliar, your domain registrar's own support chat can usually paste these in for you — this one step is also easy to hand to any IT-savvy contact.
  5. Once verified, create your mailbox on the new domain (e.g. jamie.castell@yourdomain.com) and set it as your primary address.

Source: learn.microsoft.com — Add a domain →

admin.microsoft.com/Adminportal/Home#/Domains
Domainyourdomain.com
Domain Connect (GoDaddy, etc.)AVAILABLE
Verification statusVERIFIED
What you'll roughly see under Settings → Domains — exact layout may vary.

The exact DNS records, if you're doing this manually

The domain wizard's one-click Domain Connect option only exists for specific registrar partnerships — if your domain sits on Cloudflare, that's not one of them, so you'll add these manually instead. Microsoft's own domain wizard gives you the exact values for the placeholders below; these four records are the reliable current pattern for a Cloudflare-hosted domain.

TypeNameValuePriority / TTL
TXT@MS=ms<verification-code>TTL 30 min
MX@<domain-key>.mail.protection.outlook.comPriority 1, TTL 30 min
TXT@v=spf1 include:spf.protection.outlook.com -allTTL 30 min
CNAMEautodiscoverautodiscover.outlook.comTTL Auto

Only one SPF TXT record is allowed per domain. If a TXT record starting with v=spf1 already exists on this domain, add Microsoft's include:spf.protection.outlook.com into that existing record instead of creating a second one — two separate SPF records break SPF entirely, for everyone, not just Microsoft mail.

Cloudflare itself applies DNS changes in seconds. Microsoft's own verification check can take up to about 15 minutes to notice and recognize them — a "not yet verified" result right after saving usually just means early, not wrong.

Don't skip this because it's "just" your personal tenant Even though this is a one-person, self-administered tenant, it's still a real Microsoft 365 tenant underneath — which means the same "add a second admin" guidance from the build order's admin bonus chapter applies here too, not only to your work tenants. Bringing us in as that second admin via GDAP is what actually lets us help if something breaks here: DNS records get fat-fingered, verification gets stuck, domains lapse near renewal without anyone noticing. A personal hub tenant with no second admin is exactly the kind of thing that quietly breaks at the worst moment, with nobody but you able to fix it.
Extra credit — optional, but cheap insurance while you're already in here

Set up DMARC while the DNS panel is open anyway

DMARC tells other mail servers what to do with messages that claim to be from your new domain but fail the SPF and DKIM checks above — in plain terms, it's what stops a stranger from spoofing you@yourdomain.com. It's polish, not a requirement: the core mail setup above works completely without it.

In Cloudflare DNS, add: Type TXT · Name _dmarc · Content v=DMARC1; p=none; rua=mailto:you@yourdomain.com (swap in your own address).

Start with p=none on purpose. That setting only monitors and reports — it doesn't block or quarantine a single message while you get this in place. Watch the reports for a few weeks, confirm nothing legitimate is failing, then graduate to p=quarantine and eventually p=reject once you're confident.

DMARC checks alignment against SPF and Microsoft's own DKIM signing — both need to already be working first (the table above covers SPF; Microsoft signs DKIM automatically once your domain is verified). Add DMARC after those are in place, not instead of them.

Retiring an old Outlook.com, Live, or Hotmail account

If you've had a free outlook.com, live.com, or hotmail.com account for years and want to fold it into your new hub, forward it the same way you would Yahoo or AOL below — this isn't the recommended hub itself, just how you retire one of these as an active inbox.

  • Settings gear → Mail → Forwarding → enable, enter the forwarding address, save.
  1. Sign in at outlook.com and click the Settings (gear) icon.
  2. Go to Mail → Forwarding.
  3. Toggle Enable forwarding on.
  4. Enter the forwarding address you want mail routed to — your Business Basic custom domain mailbox, or Gmail.
  5. Optionally check Keep a copy of forwarded messages in this mailbox.
  6. Click Save.

If two-step verification isn't already on for this Microsoft account, turning on forwarding will prompt you to enable it — that's expected, not an error.

outlook.live.com/mail/options/mail/forwarding
Enable forwardingON
Forward tojamie.castell@yourdomain.com
Keep a copy of forwarded messagesOFF
What you'll roughly see under Settings → Mail → Forwarding — exact layout may vary.

Gmail forwarding (if retiring an old Gmail as legacy)

  • Settings gear → See all settings → Forwarding and POP/IMAP → Add a forwarding address → verify the confirmation link → come back and turn it on.
  1. Click the Settings (gear) icon in Gmail, then See all settings.
  2. Open the Forwarding and POP/IMAP tab.
  3. Click Add a forwarding address, enter the address, then Next → Proceed → OK.
  4. Gmail emails a confirmation link to the new address — open it and click the link.
  5. Back in Gmail Settings, refresh the page and revisit Forwarding and POP/IMAP.
  6. Select Forward a copy of incoming mail to [address] and choose what happens to Gmail's own copy.
  7. Click Save Changes.

Want partial forwarding instead of everything? Disable the blanket auto-forward above, then use Show search options to build filter criteria, click Create filter, check Forward it, pick the address, and click Create filter again.

Source: support.google.com/mail/answer/10957 →

05 Contacts & calendar defaults

Contacts stay personal. Calendar doesn't.

These two get confused constantly, and the right default is different for each one — so treat them as two separate decisions, not one.

Contacts: unchanged from Chapter 4 — your personal hub (your Business Basic custom domain, or Gmail) stays the seamless primary contacts store on both devices. Every business colleague, vendor, and old Yahoo-era connection ends up findable from one address book, because it's the one identity that isn't tied to a company that could revoke your access to it.

Calendar: a different default. On the laptop, set the default calendar to whichever business calendar you actually live in day to day — for most people that's the daily-driver tenant (Northline Metal Works in our running example), not the personal hub. New events you create without thinking about it should land as business meetings, because that's what most of your day actually is. We'd recommend the same business-default on the phone — but the phone is also where you'll want to manually pick your personal calendar per-appointment for the kid's recital or your own doctor's visit, rather than have it default there.

Pay attention Some people will instead want their phone's default calendar to be personal, flipping the recommendation above. That's a perfectly reasonable choice — but it splits the experience at the device level: you now have to actively think about which calendar you're in on each device, instead of one consistent default everywhere. Make the choice deliberately, not by accident.
User impact: your callEffort: 2 min per device
One app, one look, on both platforms Our default recommendation for the phone itself: install the Microsoft Outlook app — on iPhone and on Android — and run mail, calendar, and contacts for everything through it, including your personal hub. Outlook's mobile app supports adding Gmail and other personal accounts right alongside your Microsoft ones, so instead of juggling native Mail, native Calendar, native Contacts, and a separate Gmail app, you get one consistent app and one consistent look across every account, on both iPhone and Android. We still cover the native OS-level settings below, because some readers won't use Outlook mobile — but Outlook is the lead recommendation.

Setting the actual defaults: iPhone and Android

General framing is easy; the actual OS settings are buried and differ completely by platform. Here's exactly where to go on each.

If you use the Outlook app (recommended)

Outlook's own Settings → Calendar → Default Calendar picks which calendar new events land on when you create one without explicitly choosing — set it to your business calendar, matching the recommendation above. For contacts, Outlook syncs per account rather than through one global default: on iPhone, go to Settings → [account] → Save Contacts and choose to save to your iPhone for your personal hub account; on Android, it's Settings → Accounts → [account] → Sync Contacts. Turn this on only for your personal hub account so new contacts consistently land in the one address book from Chapter 4, not scattered across whichever account you happened to be in.

Outlook's own default-calendar control has moved between app versions before, especially on Android — if Settings → Calendar → Default Calendar isn't where you expect it, the reliable fallback is the same trick as the native-Android workaround below: only enable Calendar sync for the account you want new events to land on.

iPhone (native Mail/Calendar/Contacts)

  • Contacts default: Settings → Apps → Contacts → Default Account — set to your personal hub account. This option only appears once more than one account has Contacts turned on; with just one account there's nothing to choose.
  • Calendar default: Settings → Apps → Calendar → Default Calendar — set to your business calendar, per the recommendation above. Same override-per-event behavior applies: the default only decides what happens when you don't pick one.
  • On older iOS versions, these same settings live directly under Settings → Contacts and Settings → Calendar, without the "Apps" step — Apple moved per-app settings under Settings → Apps starting with iOS 18.

Android (native Google/Samsung apps — messier, be aware)

Android doesn't have one clean equivalent to iOS's toggles, and what you do depends on which apps you're actually using:

  • Default account for new contacts, Google Contacts app: open Google Contacts → tap your profile picture → Contacts app settingsDefault account for new contacts → choose your personal hub account.
  • Default account for new contacts, Samsung Contacts app: open Samsung Contacts → the three-line menu → Manage contactsSet default storage location → choose your personal hub account.
  • Calendar default — the honest answer: stock Google Calendar does not have one reliable cross-account default the way iOS does. Each Google account can have its own default calendar for events created while that account is selected (in the app, tap the menu → your account email → Default calendar), but when a phone has several different accounts configured — a personal Google account plus a separate Microsoft/Exchange account — which one a brand-new event actually lands on tends to follow whichever calendar you last viewed or created an event in, not a fixed setting. This is a long-standing, widely reported source of confusion (Google's own feature-request tracker has an open request for a real cross-account default), not something you're doing wrong.

This is exactly the gap the Outlook app closes: Outlook applies one default-calendar setting across every account it manages, sidestepping the account-switching ambiguity that stock Google Calendar has on Android. It's the single most concrete reason to prefer Outlook over stock Google apps on an Android device carrying both a business tenant and a personal hub.

User-facingEffort: 5 min per device
06 License what you need

The Microsoft 365 matrix that actually matters

Setting the marketing names aside, here's what each tier actually buys you, for the features an executive notices.

What you getBusiness BasicBusiness StandardBusiness Premium
Outlook on the web & mobile appYesYesYes
Desktop versions of Word / Excel / PowerPoint / OutlookNo — web onlyYesYes
Self-service password reset (SSPR)YesYesYes
Conditional Access (the policies in the admin bonus chapter)No — needs Entra ID P1No — needs Entra ID P1Yes, included
Device compliance / Intune managementNoNoYes
Advanced phishing & malware protectionBasic onlyBasic onlyYes (Defender)
Pay attention If your admin wants to use the Conditional Access playbook in the admin bonus chapter for your account specifically, you need at least Entra ID P1 (Microsoft's identity and access-management add-on — separate from your mailbox plan, and what unlocks Conditional Access) — bundled into Business Premium, or purchasable as an add-on to a cheaper plan. This is usually the single highest-leverage dollar you'll spend in this whole project.
Security: highEffort: none — it's a license, not a project
07 The build order

Do it in this order

Each step assumes the ones before it are done. You marks something the executive does; Admin marks something that needs an IT admin with tenant access.

Your progress 0 / 9 done

Saved privately in your browser only — nothing is sent to us, and it won't follow you to a different device or browser.

  1. Create the break-glass account(s) Admin

    Every business tenant needs one account that exists purely to get you back in if everything else locks you out — never assigned to a person, never used day-to-day, excluded from every Conditional Access policy.

    Naming convention: bg-emergency-1@<tenant>.onmicrosoft.com — use the tenant's built-in .onmicrosoft.com domain, not your custom domain. If your custom domain's federation or DNS ever breaks, the onmicrosoft.com address still works; that's the one scenario this account exists for.

    • 32+ character random password, stored split across two places only a company officer can reach (not in a password manager tied to your daily-use MFA — multi-factor authentication, the extra code or app-tap you provide beyond your password).
    • Excluded from every Conditional Access policy, including MFA — that's the point of the account.
    • Set an alert rule: any sign-in, password change, or role change on this account should page someone immediately. It should never fire.
    Security: criticalEffort: 15 min per tenant
  2. Create your named admin account Admin

    A second account, tied to you specifically, used only for tenant-admin tasks — never for reading mail, never for Teams chat.

    Naming convention: adm-jamie@northlinemetal.com (prefix + first name). Give it Global Admin (the highest level of administrative access in a Microsoft 365 tenant) or a scoped admin role, and nothing else lives in its mailbox.

    When to use it: only when you're in the Microsoft Entra admin center or Microsoft 365 admin center making a change. Sign out of it the rest of the day. If you find yourself signed into adm- to read email, that's the tell that daily-driver and admin have blurred together again.

    Security: highEffort: 10 min
  3. Set up your daily-driver account YouAdmin

    Naming convention: jamie@northlinemetal.com — the address people actually email. This is the one your business colleagues know, and the one added to your devices as an ordinary user account, no admin rights attached.

    On the phone specifically: install the Microsoft Outlook app (iPhone and Android both) and add every business tenant plus your personal hub to it, rather than spreading them across native Mail, native Calendar, and a separate Gmail app. Chapter 5 covers Outlook's own default-account settings once everything's added.

    User-facingEffort: 10 min
  4. Forward legacy personal mail, and tag it as it lands You

    In Yahoo/AOL (and an old Gmail, if you're retiring one) settings, turn on mail forwarding to your personal hub, and leave a copy on the old account for a few weeks rather than deleting on send — just in case. Full step-by-step for each provider is in Chapters 4 and 11.

    In your hub, create a rule/filter per legacy source that catches mail still addressed to an old address and files it into its own category or folder — e.g. Legacy · Yahoo, Legacy · Old Gmail — because the original "To" address is preserved even after a forward. That label is how you'll spot, a year from now, exactly who still has an old address on file.

    Migrate or leave it — a rule of thumb: don't bother chasing down every sender. Leave low-stakes senders on the old forwarding address forever — newsletters, random retail accounts, anything spammy or low-consequence. Actively go update the sender-of-record for anything that matters — utility bills, rent or mortgage, insurance, banking, anything where a missed or delayed message causes real problems. Those should point at your new address directly, not stay dependent on a forwarding rule that could silently break.

    User-facingEffort: 20 min
  5. Use plus-addressing and aliases so mail sorts itself You

    Both Gmail and Microsoft personal accounts treat jamie.castell+bank@gmail.com (or jamie.castell+bank@outlook.com) as the same inbox as the plain address — mail still arrives, but you can filter on the +bank tag to auto-label or auto-file it. Hand out a tagged variant any time you're giving your address to a new company, a newsletter, or a one-off signup, and you'll always know exactly who leaked it if it starts getting spam.

    A worked example: give your electric utility jamie.castell+billing@outlook.com instead of your plain address. Build one rule: if sender is the utility and subject matches "your bill is ready" or "payment successful," route it straight to a Bills — OK folder and mark it read. Anything from that same sender that doesn't match — a failed payment, an account issue, an error notice — falls through to your real inbox instead of getting buried with the routine stuff.

    On the Microsoft business side, your admin can add true aliases (proxy addresses) to your business mailbox — e.g. jamie.castell@northlinemetal.com as an alias of jamie@northlinemetal.com — so old business cards and typo'd addresses still land in one place.

    User-facingEffort: 5 min, ongoing habit
  6. Build mail rules in the browser, not the desktop app YouAdmin

    Create Outlook rules at outlook.office.com (OWA — Outlook on the web), not inside the Outlook desktop app. Rules made in OWA run on Microsoft's servers and keep working even when your laptop is closed; several common rule types made in the desktop client are flagged "client-only" and silently stop working the moment Outlook isn't open. Same logic applies as a tenant admin setting mail-flow rules — do it from the admin center, not a local client.

    Pay attention This is the single most common reason a "working" mail rule mysteriously stops sorting mail three weeks later. If a rule needs to survive your laptop being off, it has to be built where Microsoft — not your PC — runs it.
    ReliabilityEffort: same as any rule — just build it in the right place
  7. Confirm business tenants don't forward, and don't accept forwards Admin

    Two checks per tenant, both in the Exchange admin center:

    • No mailbox in this tenant has auto-forwarding set to an external address (check Mail flow rules and each mailbox's own forwarding setting).
    • No mail-flow rule accepts and silently redistributes mail forwarded in from an external personal account.

    If Northline Metal Works and Vantage Public Affairs are two different companies you're both involved in, this is what keeps them from quietly becoming one company's data sitting inside the other's mailbox.

    Security: criticalEffort: 10 min per tenant
  8. Decommission the setup account Admin

    Whatever account did the actual buildout — a temporary admin login, a vendor's service account, your own adm- account if it was over-scoped for the day — get its permissions back down to normal, or disable it outright if it was only ever meant to exist for this project.

    Security: highEffort: 5 min
  9. Verify, end to end You

    Send a test email through every path: old Yahoo address → confirm it lands labeled in your hub; each business address → confirm it lands in its own account, not the hub. Sign in on both devices and count your MFA prompts for one normal day — if it's more than one or two, something upstream is misconfigured, not "just how it is."

    User-facingEffort: 15 min
08 Secure your new tenant

If you're standing up a brand-new Microsoft 365 tenant

Sometimes the second (or third) company in this guide doesn't exist yet as a tenant — you're creating it. Do these before anything else touches it, in this order.

  1. Name it like it's permanent Admin

    The tenant name and default .onmicrosoft.com domain are annoying to change later. Use the real company name, not a placeholder or a project codename — the break-glass account in the next step is going to live on this domain forever.

  2. Set up the break-glass account first Admin

    Before you touch licensing, before you add a single user — create the break-glass account exactly as described in Chapter 7, step 1. Everything else in this list depends on having a way back in if you lock yourself out while setting the rest of it up.

  3. Global Admin password + MFA, immediately Admin

    Strong, unique, generated password on the Global Admin account, MFA registered before you do anything else with it — sign in and register at mysignins.microsoft.com/security-infoAdd sign-in method. Enable Self-service password reset (SSPR) for the tenant while you're in there — it's one setting and it prevents a large share of future lockout tickets.

  4. Turn on a baseline day one Admin

    New tenants get Security Defaults enabled automatically in most cases — leave it on until you're ready to replace it with real Conditional Access policies (see the admin bonus chapter). Don't end up in the gap where Security Defaults gets turned off "to test something" and nothing takes its place.

  5. Review default sharing settings Admin

    SharePoint/OneDrive external sharing and Teams external access both ship with defaults that are looser than most companies want. Check both before real data lands in the tenant, not after.

Reference: Microsoft Entra admin center · What is Microsoft Entra ID? →

09 Zoom, Teams & meetings

Pick your meeting tool per audience, not by habit

Teams works fine inside one tenant. Across two companies, it stops being simple fast — and there's a cleaner option available.

Teams across multiple tenants: the Teams client supports guest access and lets you switch between organizations you belong to, but the reality on a shared device is an org switcher — a little tenant picker you'll click every time a notification from the "wrong" company shows up while you're in the other one's Teams. Chats, channels, and presence don't blend across tenants; you're really running two separate Teams experiences that happen to share an icon. On a device already juggling two companies, that's real notification overload, not a minor annoyance.

Zoom as the neutral option: for any meeting that includes people from both companies, or an external party who isn't in either tenant, Zoom (or simply the calendar on your personal hub) sidesteps the tenant-switching problem entirely — nobody has to pick an org, nobody needs a guest invite accepted in advance. Recommend Zoom as the default for cross-company and external meetings, and reserve native Teams calls for meetings that stay inside a single tenant.

User impact: fewer notificationsEffort: a habit, not a setup task
10 When your companies work together

If the two companies need to share files or channels

Most people using this guide keep their two tenants firmly separate. But if Northline Metal Works and Vantage Public Affairs genuinely work together enough to want shared files or a shared Teams channel, here's what that setup actually involves — grounded in how Microsoft's cross-tenant collaboration really works, not marketing language.

MechanismWhat it isRequires
B2B collaboration Invite-based guest accounts. Simplest option, works with almost any identity provider on the other side, no special licensing relationship between the tenants. Just an invite, accepted once per guest.
B2B direct connect Mutual trust configured between two Entra organizations directly — no guest account created at all. This is what powers Teams Connect shared channels, where a channel appears natively inside both companies' Teams. Entra ID P1 in both tenants, plus cross-tenant access settings configured on both sides.
Teams shared channels Shared channels themselves are on by default in Teams — but external (cross-tenant) collaboration on a shared channel is off by default, even though the feature exists. A Teams admin center policy change, plus Entra cross-tenant access settings on both organizations. Changes can take up to 6 hours to propagate before they take effect.

In practice: if you just need to send someone at the other company a file occasionally, a normal B2B guest invite is enough — nobody needs to touch tenant-wide settings. If you want an actual shared channel that feels native on both sides, budget for a real conversation between both companies' admins, Entra ID P1 in both tenants, and a same-day-but-not-instant rollout once the settings are changed.

Admin references: Entra admin center (cross-tenant access settings) · Teams admin center (external access & shared channel policies).

11 Retiring your old inbox

Actually forwarding Yahoo and AOL, step by step

Chapter 7 told you to forward your legacy mail. Here's exactly where to click, provider by provider — the mockups below are illustrative; exact layout may vary as providers update their settings pages.

Before you follow these literally Providers change their settings screens over time. If a detailed step below doesn't match what's on your screen, the high-level version above it should still point you to the right settings page. Using a provider that isn't Yahoo or AOL? Skip straight to "Forwarding from anywhere else" below — it works for almost any provider.

Yahoo Mail

  • Settings gear → More settings → Mailboxes → pick the mailbox → Forwarding → enter address → verify the confirmation code → save.
mail.yahoo.com/d/settings/mailboxes
ForwardingON
Forward tojamie.castell@yourdomain.com
Keep a copy of forwarded messagesOFF
What you'll roughly see under Mailboxes → Forwarding — exact layout may vary.
  1. Sign in at mail.yahoo.com and click the Settings (gear) icon, then More settings.
  2. Open Mailboxes and click the mailbox you want to forward.
  3. Find the Forwarding section and toggle it on.
  4. Enter your forwarding address — your new hub, e.g. jamie.castell@yourdomain.com (or your existing Gmail, if you kept it as your hub).
  5. Yahoo emails a confirmation code to that forwarding address. Open that email, copy the code.
  6. Paste the confirmation code back into Yahoo to verify the forward.
  7. Choose whether to keep a copy of forwarded messages in the Yahoo mailbox or not — keeping a copy for the first few weeks is a reasonable safety net.

Yahoo help: help.yahoo.com/kb/SLN3618.html →

AOL Mail

  • Settings gear → More Settings → Forwarding → toggle on → enter address → click the verification link AOL emails you → choose keep-copy or not.
mail.aol.com/settings/forwarding
ForwardingON
Forward tojamie.castell@yourdomain.com
Keep a copy in AOL MailOFF
What you'll roughly see under Settings → Forwarding — exact layout may vary.
  1. Sign in at mail.aol.com and click the Settings (gear) icon, then More Settings.
  2. Choose Forwarding from the settings list.
  3. Toggle forwarding on and enter your forwarding address.
  4. AOL sends a confirmation email to the new address — open it and click the verification link.
  5. Choose whether to keep a copy of forwarded mail in AOL Mail, or not.

AOL help: help.aol.com/articles/aol-mail-set-up-mail-forwarding →

Forwarding from anywhere else

Every provider we haven't named follows roughly the same pattern, and it's easy to find your way there:

  • Look for a gear icon or "Settings" — usually top-right of the inbox.
  • If the settings page has a search box, just type "Forwarding" into it.
  • Most providers require you to verify the destination address — a confirmation code or a click-through link — before the forward actually activates. Don't skip this step; forwarding silently won't work until it's done.
  • Most also let you choose whether to keep a copy in the original inbox. Keeping a copy for a transition period is usually the safer default.

Outlook.com and Gmail forwarding walkthroughs are in Chapter 4. Gmail's own filter settings (for the receiving-side rules described in Chapter 7): mail.google.com → Settings → See all settings → Filters and Blocked Addresses.

Optional side quest: a full contacts reset and consolidation Optional

Not required for the base build — but once mail from everywhere is flowing into one hub, you'll usually find you've accumulated duplicate and scattered contacts across every account you're consolidating: personal Gmail, each business tenant, old Yahoo/AOL if you ever kept contacts there, plus whatever's stuck locally on the phone itself. The clean fix isn't a merge tool — it's a full export, dedupe, and reset onto exactly one authoritative store. Budget an hour; do it once and you won't need to again.

  1. Export every source to CSV first. Do this from each account that currently holds contacts: personal Gmail, each business tenant, Yahoo/AOL if applicable, and the phone's local contacts. Nothing gets deleted yet — this step is purely capture.
    • Google Contacts: contacts.google.com → select all (or the contacts you want) → Export in the left menu → choose Google CSV (moving between Google accounts) or Outlook CSV (for Excel or another app) → Export. Downloads immediately.
    • Outlook on the web / new Outlook for Windows: People → Export contacts in the ribbon → under "Contacts from this folder" pick the folder → Export. Saves to Downloads; UTF-8 encoding is recommended.
    • Classic Outlook desktop (and how to get a native PST backup at the same time): File → Open & Export → Import/Export → Export to a file → Next → Comma Separated Values → Next → select the Contacts folder → Next → Browse, name the file, OK → Next → Finish. If you already keep a PST backup from Outlook desktop, its Contacts folder can be exported straight to CSV this same way — no separate conversion tool needed.
  2. Combine all the CSVs into one file. Open them all in a spreadsheet (Excel or Google Sheets), stack every source's rows into one sheet, and keep only a consistent set of columns — name, email(s), phone(s), company. A ragged mix of columns is what makes the next step painful, so straighten this out first.
  3. Merge the duplicates. Three ways to get through this fast rather than by hand:
    • Sort the combined sheet by email address or by full name first — duplicates land next to each other and are easy to spot and delete manually.
    • Or skip manual spreadsheet dedup entirely: import the combined CSV into Google Contacts and run Merge & fix (menu icon, top-left → Merge & fix → review suggestions → Merge or Merge all), or import into Outlook and use its automatic duplicate suggestions after import.
    • Simple rule of thumb either way: same email address = same person, even when the name is formatted differently ("J. Smith" vs. "Jane Smith, Northline Metal Works").
  4. Back up natively before deleting anything. Take one native-format backup in addition to the CSV — a PST export from Outlook desktop is the standard "native backup" most business people will recognize (same Import/Export wizard as step 1, choosing Outlook Data File (.pst) instead of CSV, for the whole mailbox or just Contacts). This is the safety net: an imperfect cleanup below is fine, because a real backup exists to fall back on.
  5. Remove all contacts from every device and cloud account. This is the actual reset — delete the contacts stored locally on the phone, and delete them from every cloud contacts store they came from (personal Gmail, each business tenant, etc.), so nothing stale re-syncs back in later.
    • Google Contacts: check the box next to any contact → the dropdown arrow at top-left → All (selects everything) → More (top right) → DeleteMove to trash. Deleted contacts sit in Trash for 30 days before permanent deletion — a second safety net on top of the PST/CSV backup.
    • Outlook.com (web): People → All contacts in the left pane → select contacts (Shift+click for ranges) → Delete → confirm. The web version caps bulk delete at 50 contacts at a time, so a large list takes a few passes — don't be surprised when it doesn't clear everything in one go. Classic desktop Outlook can Ctrl+A the whole list and delete it in a single action, which is faster if you have it installed.
    • Phone-local contacts (iPhone/Android): delete the on-device contact group from your phone's Contacts app settings — exact wording and location vary by phone and OS version, so check your specific device's current menu rather than following a fixed path here.
  6. Upload the cleaned, merged list into the one contacts store that becomes authoritative going forward — whichever you chose as your personal daily-driver hub in Chapter 4. Outlook (personal Microsoft account) if that's your hub: People → Import contacts in the ribbon → Browse → select the CSV → Open → Import. Google Contacts if Google is your hub: Import in the left menu → choose the CSV → confirm. Google maps the header row to its fields automatically and drops the import into a labeled group so you can review it before it joins your main list.
  7. From here forward, work from the cloud/web version of mail and contacts, not a local device cache. The whole point of the reset is that the phone just displays what's synced from the cloud account — it isn't a separate store that can quietly drift out of sync again.
The end state, plainly After all of this, contacts should be syncing onto the device from exactly two places — the personal hub account and the business tenant(s) — nothing else. Concretely: either personal Microsoft account + work Microsoft account(s) if you moved your personal hub to Microsoft, or personal Google account + work Microsoft account(s) if you kept Gmail as your personal hub. No leftover Yahoo, AOL, or other legacy source should be syncing contacts to the device anymore — those accounts are just forwarding mail in now, per Chapter 7, and contribute nothing to the address book.
12 A physical key

Worth the $25–60

A hardware security key (YubiKey or equivalent) is the single cheapest security upgrade in this entire guide, and it removes MFA prompts more than it adds them — a tap replaces typing a code.

ModelConnectorTypical priceGood for
YubiKey 5C NFCUSB-C + NFC (tap on phone)~$55 flatModern laptop + phone, one key for both
YubiKey 5 NFCUSB-A + NFC~$50 flatOlder laptop with USB-A ports
Security Key NFC (Yubico)USB-A/C + NFC~$25–29 flatBudget option, FIDO2/passkeys only — fine for most executives
Pay attention The key itself is cheap and simple. Registering it against your account is not self-service in most tenants — your admin needs to enable FIDO2 security key (the passkey/security-key authentication standard) as an allowed authentication method in Entra ID before you can add one. Buy the key, then send your admin the setup guide below before you try to register it.
Security: very highEffort: 15 min for admin, 2 min for you

Admin setup guide: Enable passwordless security key sign-in in Microsoft Entra ID →

Once your admin confirms it's enabled, your own part is quick: sign in at mysignins.microsoft.com/security-infoAdd sign-in methodSecurity key → follow the on-screen prompt to tap or insert your key. That's the "2 min for you" step above.

★ Bonus chapter — hand this part to your IT admin

Conditional Access, for the person supporting this arrangement

Everything above makes the executive's life easier. This part is what keeps you — the admin — from being the one who explains a breach to the board. Microsoft already turns on a baseline for you; this is what to layer on top, and the one real decision that changes everything downstream.

The floor, whether you touch it or not Microsoft automatically rolls out a set of Microsoft-managed Conditional Access policies to eligible tenants — blocking legacy authentication, requiring MFA for admins and for all users, and requiring MFA for Azure/Entra portal access. They start in report-only and turn on within 30 days unless you act. If you're on E3/E5 or have Microsoft 365 Business Premium, check Entra admin center → Conditional Access → Policies for anything showing Created by: Microsoft — that's your existing floor, not a blank slate. Exclude your break-glass account from these exactly as you would from any policy you wrote yourself.

The one decision that matters

Before setting a single toggle, answer this for the tenant you administer: if this executive's personal device is compromised, are you willing to accept that your company's mail could be exposed to whatever else lives on it? Your answer picks a column below.

Policy areaIf you're OK with cross-company exposure on this deviceIf you want hard isolationWatch for
Device compliance / join requirement Don't require a compliant or hybrid-joined device for this user — allow any device, gated by MFA instead. Require the device to be Intune-compliant or Entra-joined to this tenant — which conflicts directly with a shared, multi-tenant device. Pick this and the executive will get device-join prompts you didn't intend. Grant control: "Require device to be marked as compliant"
Sign-in frequency Standard (Microsoft default, roughly balances security and re-prompting). Shorter re-authentication window (e.g. every 4–8 hours) so a stolen session token expires fast. Session > Sign-in frequency
Persistent browser session Allow — fewer prompts on a device only this person uses. Never persist — force a fresh sign-in every browser session. Session > Persistent browser session
App-enforced restrictions (unmanaged device) Allow full Outlook/OWA functionality. Block download, print, and sync to an unmanaged device — mail is view-only in the browser. Session > Use app enforced restrictions
MFA strength Any MFA method (Authenticator app push is fine). Require phishing-resistant MFA specifically (FIDO2 key or certificate-based) — see Chapter 12's YubiKey section. Grant control: "Require authentication strength"
Legacy authentication Block regardless — there's no version of this arrangement where legacy auth (IMAP/POP/SMTP-basic) should be allowed. Over 99% of password-spray attacks use it. Block regardless. Usually already covered by Microsoft's managed baseline policy
Pay attention The "hard isolation" column is real security, but it's also the column that generates support tickets — a device-compliance requirement in particular will actively fight a device that's deliberately shared across tenants. Most MSPs land on the left column for exactly this scenario and lean on MFA strength + short sign-in frequency to do the real work instead.
User impact: high if you pick isolationSecurity: your callEffort: one policy review per tenant

Naming and structure we'd suggest for your own sanity

  • One Conditional Access policy per control, not one giant policy — CA01-Block-LegacyAuth, CA02-MFA-AllUsers, CA03-MFA-Admins-PhishResistant. Easier to report-only test and roll back individually.
  • Always exclude your two break-glass accounts from every custom policy — the same way you'd exclude them from a Microsoft-managed one.
  • Run every new policy in Report-only for at least a week before enforcing it. This is the cheapest insurance in the whole playbook.

Adding a second admin

For business continuity, any brand-new Microsoft 365 tenant should have a second Global Admin outside the primary user — someone who can get in if the first admin is unreachable. Rather than assigning the Global Admin role directly to an individual account, we'd recommend creating a role-assignable security group (e.g. Tenant Admins) instead, then assigning the Global Admin role to the group and adding actual admin accounts as members. It's easier to audit and easier to revoke than a role sitting on one person's account, and it means removing an admin is a group-membership change, not a role reassignment under pressure.

  • Requires Entra ID P1 or P2.
  • Created in Entra admin center → Groups → New Group, with Microsoft Entra roles can be assigned to the group set to Yes — this option can only be set at group creation, not added later.
  • Assign the Global Admin role to the group itself, then manage membership instead of managing role assignments.
Bring a new tenant under Red Bigfoot's management

Let us be that second admin

Instead of standing up and maintaining that second-admin relationship yourself, a new tenant can bring Red Bigfoot in as a delegated administrator through GDAP — Granular Delegated Admin Privileges. GDAP is Microsoft's least-privilege, time-bound model for partner access via Partner Center: we request only the specific admin roles a relationship needs, for a bounded duration, and nothing is active until you approve it — you click Approve all in the Microsoft 365 admin center yourself.

Set your expectations up front, not after:

  • This has a cost — bringing a tenant under management is a paid engagement, not a free add-on.
  • Bringing a tenant under Red Bigfoot's management typically means raising its security posture to match our platform standards — MFA, a Conditional Access baseline, and the other items in this bonus chapter get enforced, not just recommended.

This starts with a short call, not a cold email; use the button below to book time on our calendar.

13 FAQ

Quick answers

Can I just use my business Microsoft account for everything?
No — the moment a business tenant becomes your contacts/calendar hub, personal data starts living inside a company's Microsoft 365 tenant, which the company can see, export, and legally hold. Keep the hub personal.

What if I'm on three or more business tenants, not two?
Nothing here changes — repeat steps 1–3 of the build order per tenant, and use the calculator in Chapter 3 with your real tenant count.

Does this work if I own the device myself, versus if a company issued it?
Yes to both. On a company-issued device, that company's admin may have more say over device-level policy (the admin bonus chapter's "hard isolation" column becomes more likely for that one tenant specifically) — the account-level steps in Chapter 7 don't change either way.

My old Yahoo/AOL address still gets important mail years later — is that normal?
Very. That's exactly what the Legacy label in Chapter 7 is for — check it occasionally, and update anyone still using the old address directly rather than relying on the forward forever.

14 What this costs to have us do it

Pricing, honestly

We don't know you yet — and this is genuinely one of the harder categories of engagement to price up front. Not because the work is exotic, but because the real variable is you: how much time we spend hunting down access and information, whether it's one focused block or a string of short sessions spread across weeks, how comfortable you already are with this stuff, and how much you're multitasking during our time together. All of that swings the real hours more than the technical work does. So: a range below, not a fixed price — and here's exactly why.

Here's what your normal IT recommends, and why

Most IT shops — including a lot of very good ones — will quote you real hours for a standard employee computer setup, and they're not wrong to. Manual device provisioning commonly runs 1 to 5 hours per device, depending on how much customization is involved — that's the range endpoint-management tooling vendors themselves cite as the norm they're automating away. That's not incompetence; it's genuinely what setting up a computer by hand takes.

ApproachTypical timeWhat's actually driving the cost
Average IT shop, fully manual1–5 hours per deviceReal hands-on labor, paid every time, for every device
Red Bigfoot, our own tooling — a standard setup~12 minutesTooling and scripts; most of the labor already paid for once

Twelve minutes is real, for a standard, single-tenant setup — but it isn't free. It's the result of tooling we license and maintain, plus the engineering labor that actually built the automation, amortized across every client who's benefited from it since. The alternative isn't free either — it's just labor cost paid manually, in full, every single time, instead of paid once to build something that keeps paying for itself.

Why this project isn't a "12-minute" job

A standard, single-tenant, single-account setup is exactly the kind of thing tooling swallows whole. This guide's whole premise — blending a personal identity with two or three separate company tenants, safely, on one shared device — is the opposite of standard. Here's the honest effort comparison, in Stomps, our own rough unit of effort.

Fully manual, no tooling100 Stomps
A standard computer setup, with our tooling6 Stomps
This project35 Stomps

A Stomp is our rough composite unit of effort — a blend of tool cost, the labor that built any relevant automation in the first place, and the hands-on labor still required on top of it. This project lands at 35: well below the fully-manual baseline, because we do bring tooling and process to it too — but well above a standard setup's 6, because this work is inherently bespoke. Diagnosing which of several overlapping sign-in prompts is actually wrong isn't something a template can do for you.

This isn't a one-time tax

The Stomps above aren't a one-time hit — this level of effort recurs almost every time you add a new laptop or phone, because this kind of setup is bespoke by nature and genuinely difficult to safely template around. Security and this kind of cross-company blending don't mix well with "just clone the image" — the whole point of the earlier chapters is that each account, each tenant, and each device needs its own deliberate handling.

Because of that, our recommendation stands, unchanged from earlier in this guide: keep one dedicated, single-purpose work computer per company doing its own separate thing, and let a personal device carry everything else through web-only access rather than deep local integration. For executives and admins specifically, a Cloud PC (Windows 365) is worth serious consideration — a clean, disposable, company-owned Windows instance to work inside, without any of this complexity ever touching your actual physical device. Admins in particular should seriously consider this for themselves first.

The phone layer, by comparison, is much less painful: Outlook for mobile paired with Intune for BYOD devices handles multi-tenant phone access reasonably well without the same bespoke-effort problem the laptop layer has. Almost all of the Stomps in this guide are a laptop story, not a phone one.

The one-time project rate

A project like this typically runs $2,000–$6,000, one-time.

  • Low end (~7–8 hours of work): a cooperative client, one extra tenant beyond the personal hub, and reasonable technical comfort. Most engagements land in this lower half.
  • High end (~20+ hours of work): multiple tenants, several legacy accounts to migrate, low technical comfort, and real rescheduling and hand-holding along the way.

It climbs fast with more moving pieces — but most people reading this guide are closer to the low end than the high end.

If you'd rather do this yourself, that's exactly what the rest of this guide is for. If you're dead-set on having us just do it, here's where to start.

Computer Restore Insurance

This is not device insurance. It does not cover, repair, or replace the physical laptop or phone, in any way — a dropped screen or a dead battery is between you and the manufacturer (or your own device insurance). What this covers is the service of restoring your system — apps, settings, configuration, files — onto a replacement device quickly and cleanly, using the same tooling we already maintain for everything else in this guide.

A real prerequisite, not a soft suggestion: we can only offer this if we have some form of standing admin access to the account, or the ability to get just-in-time access on demand. GDAP on your personal Microsoft account is preferred; a direct admin account on it is the fallback. Without one of those two in place, we can't offer this product to you — see "Which of these can we actually help you with?" in Chapter 4 for what that means for each hub choice.

A restore service, not hardware coverage

Computer Restore Insurance

  • $250 one-time enrollment — about an hour: baseline capture and a test restore
  • $150 per month per laptop
  • $100 per month per phone (or tablet)
  • No minimum device count — a typical executive with one laptop and one phone is $250/month

Each device is priced to stand on its own — a laptop restore and a phone restore are different amounts of work, so they carry different prices, and there is no minimum count. Add a tablet or a second laptop at the same per-device rates. How many restores a year are included is set by the tools we restore with; we state it on your proposal, not in a guide that has to stay true for everyone.

Scope, plainly:

  • Full coverage assumes we have the access we need. If your device is managed by your own internal IT department, we can't guarantee full coverage on our own — scope gets negotiated between your IT department and us, based on what we're actually allowed to reach with our tools, not assumed going in.
  • An alternative some readers choose: a separate, dedicated device that runs entirely under our management, kept deliberately outside your internal IT's scope. We send monthly reports showing it's being maintained properly — one device on one management layer is simply a lot less messy than splitting one device across two.
  • Coordinating with an existing internal IT department (or several, across multiple companies) is available as an optional add-on — but we don't pre-quote it publicly, because the effort varies enormously depending on how cooperative those other IT teams are with each other and with us. Quote-only, not priced here.
  • No discount for partial coverage. If a piece or two of the full picture is missing — say, internal IT won't grant some access — the price doesn't drop. The solution still holds up well with a gap or two, so we don't discount around it.
  • Line-of-business applications are always out of scope, full stop — on every tier and every add-on, this one included. That's always either you or your internal IT's responsibility, never ours.

Prefer ongoing, hands-on support instead?

If a one-time project or a device-by-device Restore plan isn't quite what you're after, the fastest way to sort out what you actually need is a short conversation — book time below.

The Executive Concierge plan

Some clients would rather not think about any of this in "one-time project" terms at all.

White-glove, ongoing

Executive Concierge

$1,500/month
  • Ongoing, hands-on support for this exact setup — not a general helpdesk queue
  • Device replacement and migration handled for you, start to finish
  • Priority access — front of the line, not a ticket queue
  • Fair use, stated plainly: up to four hours a month of hands-on time, plus one full device migration every twelve months, are included. Anything beyond that bills at our published engineering rate. Most executives on this setup use two to three hours a month, so the band is a ceiling you should rarely notice
  • Line-of-business applications are out of scope, as with every tier — always yours or your internal IT's responsibility
  • Mobile devices are not included. Your phone is covered by the optional White Glove Mobile Care line below, not by this plan

This is a premium, white-glove tier, priced like one — for someone who wants this handled for the long term, not a general IT plan.

White Glove Mobile Care — optional line item

Everything above is a laptop story. Your phone is where the identities actually live — the authenticator, the passkeys, every business mailbox — and a lost phone is the single fastest way to be locked out of everything at once, from anywhere. This add-on exists so that never becomes your problem to solve on a Sunday night.

Optional add-on · phone and tablet

White Glove Mobile Care

$800/month
  • $500 one-time setup — about two hours: enrollment, the recovery plan below, a test run
  • Up to two hours a month of hands-on help included; beyond that, our published engineering rate
  • Remote support on your actual phone, at a moment's notice — you approve, we connect. On Android we can drive; on iPhone Apple allows us to see your screen while we guide you. Either way, nobody learns how to set up a support app while on vacation
  • Lost-phone recovery plan, set up in advance: authenticator backup, a hardware key as your second factor (Chapter 12), a remote lock/wipe on the lost device, and a temporary access pass from us so you are signing in again within the hour on any replacement
  • Apps pushed, not hunted — Outlook, Authenticator and the rest arrive on a replacement phone without you rebuilding it from memory; optional opt-in backup of the work container
  • Light, BYOD-friendly management (a work container, not control of your personal side); Android and iPhone; up to two devices

Line-of-business apps stay out of scope here too. This is the phone half of the Concierge idea, sold separately so you only pay for it if you want it.

A password vault, if you want one

Most readers of this guide end up with more accounts than any memory can hold. We gently suggest a personal password vault — we provide and onboard Keeper as an optional upgrade — with one thing said plainly: your passwords are yours. We set the vault up and show you how to use it; we do not hold, manage, or recover your passwords. Ask about it on the same call as anything above; it is priced per user on the proposal, not here.

Support hours, honestly

We don't offer 24/7 support, by design — not because it wouldn't be nice, but because the setup this guide teaches isn't secured tightly enough to responsibly staff around the clock, and doing so would mean staffing far more than the actual need justifies.

After-hours contact is possible, but it's always billable and best-effort — there's no guaranteed response time attached to it.

If something breaks after hours: if it's the kind of issue Self-Service Password Reset (SSPR) can fix, try that first — it's genuinely often faster than waiting on a callback. Otherwise, call, and if no one picks up, leave a voicemail that clearly says "URGENT" so it gets triaged first.

Think you need real extended or near-24/7 coverage? Most people who ask for this don't actually need it. But if there's a genuine case for it — manufacturing operations running near round-the-clock, say — that's a custom, quote-only conversation, not a flat hourly add-on we have a rate card for.

The fine print — how this actually works

This is contract-adjacent content, so we're going to be precise about it rather than vague. Everything below applies whether you're on the Concierge plan, Restore Insurance, or both — it's one shared set of terms, not two separate ones. Here's what engaging us actually means, plainly:

  • Fair use on the Executive Concierge plan. The plan includes up to four hours a month of hands-on time and one full device migration every twelve months. Time beyond that is billed at our published engineering rate, and we tell you before we cross the line, not after — no surprise invoices.
  • Term. This is a one-year rate. After the first year it converts to month-to-month, with 60 days' notice to cancel in either direction. On termination, we hand over a clean copy of the information and access we hold — no held-hostage transition.
  • Privacy during active work. Setting this up requires us to use your actual personal passwords during the process. By engaging us, you're agreeing to that — and you should understand that any expectation of privacy is genuinely gone during that active work. We're not going to pretend otherwise.
  • What access we keep afterward. Once an environment is under management, most credentials and access get reset once we're done with them — except we need to retain standing access to your central personal domain (a Microsoft GDAP relationship on that tenant), and some level of scoped admin access to your business tenant(s): at minimum Global Reader, ideally GDAP there too if that tenant's own IT allows it.
  • How that access is held. It can be just-in-time (JIT) rather than always-on, and logged and audited — we're glad to open a ticket, log the justification, or do whatever's needed so the access stays transparent and defensible, not a standing blank check.
  • Billing for getting to that state. The work of setting up that access relationship is billable, the same as any other setup work. Once it's in place, maintaining it is included in the ongoing fee.
  • When another IT department gets difficult. If a business tenant's own internal IT team becomes obstructive, we may need to bill time-and-materials for the extra friction that creates — which can put you in the middle between us and your own IT. By engaging us, you're accepting that risk, and you remain responsible for payment regardless of how cooperative — or not — your other IT teams turn out to be.
  • Licensing costs are yours. You're responsible for your own licensing and tenant costs — Microsoft, domain registration, Cloudflare, and so on — and you agree to keep those accounts current, including making sure billing and status alerts (payment failures, renewal notices, outage notices) also go to an email address we specify, so we're not blindsided by something breaking on your end.
  • Delegated access to supporting services. For something like Cloudflare, we need at minimum DNS-record access — ideally full delegated/collaborator access to the whole account rather than a narrow slice. The same principle applies to any comparable service we end up depending on.

This is the actual shape of the relationship, stated up front instead of buried in a document you sign later.