Single source of truth for the migration project. Everything decided across planning has been captured here. If it's not in this document, treat it as not yet decided. This is the working field reference for Gemma (ADV Multimedia) throughout the project.
Timescale at a glance: delivered over ~2 months — September–October 2026. Workstreams overlap; the pace is set by the AM Automate critical path and AMJ's device re-homing. Two fixed dates: licences to Business Premium by 21 Sep 2026, and amssrv01 switched off by end Oct / early Nov 2026 (fully in the cloud). Full week-by-week schedule and Gemma's availability in Section 9.
Decommission the on-prem Windows Server 2012 R2 entirely. Every role it currently performs is being replaced with a cloud-native or Microsoft 365-based equivalent — this is not a hardware refresh, and no replacement on-prem server or NAS is being purchased.
Three parties involved. This scope split is a final decision — not open for reconsideration. The only outstanding action is obtaining AMJ's revised price for the scope below; that pricing step does not reopen whether AMJ is engaged.
| Workstream | Owner |
|---|---|
| Identity & device (AD/GPO → Entra ID + Intune) | AMJ IT Services |
| Network services (DHCP/DNS → firewall/router) | AMJ light touch |
| Windows Updates (WSUS → Windows Update for Business) | AMJ via Intune |
| Print serving → Universal Print | AMJ |
| Antivirus rollout (Bitdefender → Defender for Business) | AMJ light, via Intune |
| Safe retirement of AD / DHCP / DNS on the old server | AMJ |
| Photo storage migration to SharePoint | Gemma + Claude not AMJ |
| AM Automate migration to Azure | Claude + Gemma not AMJ |
Why this split: AMJ's items share three traits — broad blast radius (a mistake stops everyone logging in, printing, or updating), hard to reverse once cut over, and require tacit specialist knowledge (Conditional Access lockout risk, GPO-to-Intune mapping, profile-safe device migration) plus professional accountability. Gemma + Claude's items are contained, reversible, and rehearsable — including AM Automate, which Claude built and knows in full.
AMJ owns the identity cutover night — the single highest-risk, hardest-to-reverse window in the whole project.
Outstanding action: AMJ to be re-quoted against the narrowed specialist scope above (identity/device, network services, updates, print, antivirus rollout, safe AD/DHCP/DNS retirement) — a pricing formality, not a re-decision.
The current annual Business Standard subscription term ends 21 Sep 2026. It must be converted to Business Premium before that date. If it auto-renews as Standard first, a Microsoft annual (NCE) commitment generally cannot be cancelled or downgraded mid-term — that would lock the business into Standard until Sep 2027 and stall the whole cloud-native approach (or force paying for Premium in parallel).
| Current | Microsoft 365 Business Standard, £11.00/user/month, 30 users |
| Moving to | Microsoft 365 Business Premium, ~£16.90–17.60/user/month, 30 users |
| Why | Premium bundles Entra ID P1, Intune, Defender for Business, and Universal Print at a lower combined price than buying these as standalone add-ons on top of Standard. This licensing change is the enabler for the entire cloud-native approach — nothing in Section 4 is possible without it. |
Note: confirm actual current invoiced Standard price (vs list price) before the upgrade is ordered, as real pricing may differ from list price used in planning.
| On-prem role (being retired) | Cloud replacement |
|---|---|
| Active Directory | Microsoft Entra ID |
| Group Policy Objects (GPOs) | Microsoft Intune configuration profiles |
| DHCP | Firewall/router |
| Internal DNS | Firewall/router / Entra-joined device resolution |
| WSUS (Windows Update management) | Windows Update for Business policies (via Intune) |
| Print server | Universal Print (included in Business Premium) |
Device re-homing: ~30 machines move from AD-joined to Entra-joined + Intune-enrolled, preserving user profiles/data (wipe-and-Autopilot vs in-place, decided per device by AMJ).
In-person laptop configuration: device re-homing is hands-on — every staff laptop (~30) is brought into the office and reconfigured in person, not remotely. This is delivered by AMJ's on-site presence — the physical-attendance element of their retained scope, and a key reason a locally-attending specialist is kept for this piece. It is phased across a Monday–Friday week during the migration (a batch of laptops each day), so staff are never all without their machines at once and each person is down only briefly.
Network services cutover: DHCP/DNS move onto the firewall/router, after AMJ audits what currently resolves against the server by name (scanners, MFPs, or anything hardcoded to the server).
Workstream total: ~2–3 weeks effort — device re-homing dominates. Indicative only; AMJ's re-quote confirms.
| Out | Bitdefender GravityZone, £250/month (~£3,000/year) |
| In | Microsoft Defender for Business, included in Business Premium at no extra cost |
| Net effect | the Premium licensing uplift (~£2,150–2,400/year extra vs current Standard spend) is more than offset by dropping Bitdefender — close to cost-neutral or better overall once Bitdefender is cancelled. |
Confirmed decision: Bitdefender is being dropped in favour of Microsoft Defender for Business — this is settled, not an open question. Implementation note for AMJ: switch on the full Defender for Business feature set (EDR, attack surface reduction, automated remediation), not just the base antivirus engine, so detection is at its strongest given the leaseholder financial/legal data the business holds.
This decision is final. Not Azure Files/Blob, not on-prem NAS.
Roughly 5 years ago, an attempt to store the photo database in SharePoint failed. The failure was not caused by SharePoint itself — it was caused by Picasa, a desktop photo-browsing tool installed locally on each laptop. Picasa's local indexing forced full download/hydration of every cloud-synced photo to the laptop's hard drive, which crashed the machines. The combination of Picasa + local sync was at fault, not SharePoint storage. This migration avoids that failure mode entirely — see Section 7 (AM PhotoStore).
Scale: 1,200 folders, ~480GB, mapping to 250 currently-managed sites.
Workstream total: ~1–1.5 weeks elapsed — a few days' work plus background transfer time for 480GB (bandwidth-dependent).
"No on-prem storage" does not mean "backups solved." Cloud data in SharePoint/OneDrive still needs its own data-protection/retention strategy under Microsoft's shared-responsibility model — a separate, not-yet-made decision, distinct from the Azure VM + PostgreSQL backups already covered under AM Automate.
Once the photo migration (Section 6) is complete, a custom internal tool called AM PhotoStore will be built as a future module of AM Automate.
AM Automate is the suite of six in-house business apps currently hosted on amssrv01: PayFlow, SalesFlow, Fire Doors, WebServe, Dispatch, CaseFlow.
This migration was fully scoped and locked separately, on the Claude instance connected to the server that built AM Automate. Refer to that runbook directly for all implementation detail — it is not duplicated here:
amautomate.amsbm.co.ukAM Automate is the gating workstream — its cutover must be complete and proven stable for approximately one week before the server can be retired. But it is not the only gate: see the full decommission gate in Section 9.
How AM Automate is edited and updated must not change for staff. Today, every change to AM Automate is made by talking to one Claude — the machine in the IT cupboard — which makes the edit and posts it live. Only certain (non-technical) staff use it; they either remote in or walk over to the cupboard. There is no second tool and no hand-off between a "draft" Claude and a "live" Claude — the one cupboard Claude does both.
This model carries over unchanged. The cupboard Claude runs on a separate machine from the server, so when the server is decommissioned that machine stays. It is simply re-pointed — once, during the migration — to reach the AM Automate apps on the Azure VM instead of the old local server. To anyone using it, nothing changes: same machine, same remote-in / walk-over, same "talk to it → the edit goes live."
Location — locked for now, optimise later: the AM Automate Claude stays in the IT cupboard after the migration — not because it has to (the server it sat next to is gone), but because that is where staff expect to find it. Whether to relocate the "go-to Claude" to a more convenient spot is a future optimisation, deliberately kept OUT of the migration mechanics. The migration's only job here is to re-point the existing cupboard Claude at the cloud; moving it comes later, if at all.
End goal for Gemma: after cutover, the IT-cupboard Claude machine is set up with secure access to the Azure VM (edit the app folder + restart services) and folder snapshots enabled — so the single-Claude, edit-and-post-live experience continues exactly as before, just pointed at the cloud. This re-pointing is a required migration task, not an afterthought — it is done at cutover and verified with a live test edit before the old server is decommissioned (it is the fourth item in the decommission gate, Section 9). Without it, switching the server off would leave AM Automate running in the cloud but un-editable.
Order of execution. The workstreams overlap heavily — the stages below are the priority order, not strict start/finish gates, except where marked. AM Automate leads because it is the one workstream that gates switching the server off.
Rough timeline: ~2–3 weeks prep → one AM Automate cutover evening → ~1 week soak → server free to retire once the other gates have also closed.
| Workstream | Can start independently? | Blocks server retirement? |
|---|---|---|
| Licensing upgrade (Standard → Premium) | Yes | No — but prerequisite for the AMJ workstream |
| AM Automate migration to Azure (Claude + Gemma) | Yes | Yes — the gating workstream |
| Photo migration to SharePoint (Gemma + Claude) | Yes | Yes — data lives on the server |
| Identity/network/print/AV migration (AMJ) | Yes | Partly — device re-homing + AD/DHCP/DNS retirement must complete before switch-off |
| Physical server (amssrv01) decommission | — | Terminal step — only once all three gates above have closed |
Target: complete within ~2 months (September–October 2026), with end of October / early November 2026 as the hard deadline to switch off amssrv01 and be fully in the cloud. Two fixed dates anchor the plan: licences to Premium by 21 Sep, server off by end Oct / early Nov.
Gemma's availability (from 1 Sep 2026): every Wednesday (full day), Thursday & Friday afternoons, and weekends if needed — roughly 2–3 effective days per week. This is the binding constraint on the hands-on work; the AM Automate critical path is largely Claude-driven and can progress between her windows.
| Window | Focus / milestone | Lead | Gemma's part |
|---|---|---|---|
| Early Sept by 21 Sep — hard | Convert licences → Business Premium — enables the AMJ workstream | Gemma | Action the conversion directly in the Microsoft 365 admin centre (~½ day) |
| Weeks 1–3 Sept | AM Automate → Azure — provision, build, migrate data/secrets, parallel testing (runbook Phases 1–5) | Claude | Spot-check & sign-off on Wednesdays |
| Weeks 2–4 Sept | Photo migration — site list → AI match → review → bulk copy → verify | Gemma + Claude | Review matches + verify on her days |
| From mid-Sept after Premium live | AMJ build — Entra + Intune baseline, Conditional Access | AMJ | Coordinate access |
| Late Sept – Oct laptop week: Mon–Fri | AMJ rollout — device re-homing (~30 laptops brought in, reconfigured in person, phased Mon–Fri), Universal Print, WUfB, Defender, DHCP/DNS | AMJ | AMJ on-site for the laptop week; Gemma coordinates + assists |
| Early–mid Oct a weekend | AM Automate cutover evening → ~1 week soak | Claude + Gemma | Present for the cutover (weekend window) |
| Late Oct | Retire AD / DHCP / DNS — all three decommission gates close | AMJ | Coordinate |
| End Oct / early Nov HARD | Decommission amssrv01 — fully in the cloud | AMJ + all | Physical switch-off |
Biggest risk to the end-October deadline: not the software work — AM Automate is Claude-driven and can run ahead — but AMJ's device re-homing across ~30 machines, which needs AMJ time, Gemma on-site, and staff availability, all within a limited number of days. Book AMJ now and batch the device sessions across Gemma's Wednesdays, Thursday/Friday afternoons and weekends. AM Automate must also cut over by ~mid-October to leave its ~1-week soak before switch-off.
AMJ currently charges a recurring fee of about £6,500 a year for four things: backing up the on-prem server, monitoring it, backing up our Microsoft 365 email, and a small annual support retainer.
The key realisation is that three of those four exist only because of the old server — and this migration removes that server completely. Its backup and monitoring have nothing left to look after once it's gone, so they simply stop. The support retainer is cancelled outright. That leaves just one service worth keeping — protecting our email — and even that isn't handed to a new supplier: it is replaced by tools already included in the Microsoft 365 Business Premium licences we're upgrading to anyway (Purview retention, the Online Archive and eDiscovery). We pay for those capabilities the moment we move to Premium; switching them on costs nothing more.
So the migration doesn't merely move our systems to the cloud — it dissolves the reason AMJ's ongoing services exist. Their recurring bill goes to £0, with no replacement supplier and no new spend; the migration itself, plus licences we're already buying, do the whole job. All of it is Microsoft 365 admin configuration — a Gemma + Claude task, not server work and not AMJ's. The detail below sets out each line, what happens to it, and exactly how the Business Premium tools cover email retention and recoverability.
Scope: this eliminates AMJ's ongoing / recurring services. It is separate from the one-off identity-migration specialist role in Section 2 — whether that cutover uses AMJ or another specialist is a different decision and does not affect the exit below.
| AMJ service | Net / year | Fate |
|---|---|---|
| Server backup (Cloud Backup Safe, 750 GB) | £1,128 | Ends — no server left to back up (at decommission) |
| Server monitoring agent | £26 | Ends — nothing left to monitor (at decommission) |
| Email backup (Backup Cloud O365, ~76 units) | £5,016 | Replaced — native Microsoft 365 retention + archive + eDiscovery (10.2–10.3) |
| Support retainer (3rd-level O365 block hours) | £360 | Cancelled — final decision |
| Total ongoing AMJ | ~£6,530 | → £0 |
AMJ ongoing spend goes to £0 — with no licence replacement cost. Shared mailboxes are kept under 50 GB so they stay free (no archive, no licence): applying the 6-year rule trims their lifetime sizes down, and any that remain over 50 GB are split into smaller sub-sets (e.g. Blocks A–C, D–G) rather than licensed. Hard policy: we do not pay to store old email.
The definitive email policies Gemma applies in Microsoft 365 (Purview + Exchange Online) — the rules that let the AMJ email backup be switched off.
| Policy | Rule |
|---|---|
| Retention period | All email retained 6 years, then permanently deleted (Purview retain-then-delete). Applied to staff and shared mailboxes. |
| Archive tiering | Mail older than 24 months auto-moves to the Online Archive. So 0–2 yr = primary mailbox, 2–6 yr = archive — both live in Outlook and are self-searchable. |
| Deleted-items self-recovery | The user "Recover Deleted Items" window is set to the 30-day maximum. |
| Staff self-service | Staff find any email they sent or received in the last 6 years themselves in Outlook (primary + archive) — no IT needed. |
| eDiscovery — IT only | Restricted to the IT / compliance account (Gemma). Used only for the three cases below. |
| Shared mailboxes | Kept under 50 GB so they stay free (trimmed by the 6-year rule; split into sub-sets if any remains over). Stores only — the compliance copy sits on the licensed staff mailboxes (10.4). |
Where IT (Gemma, via eDiscovery) is needed — and only here:
The retention policy is the recoverability/backup for email against data loss by deletion, accidental or malicious — this is the answer to "what replaces the AMJ email backup for actually getting lost emails back."
Worked example — a staff member maliciously deletes every email in their own inbox: the mail is still fully recoverable. When they delete and then purge it, the items move to a hidden Recoverable Items → Purges folder the user cannot open, and the 6-year retention policy forbids Exchange from actually removing them. Gemma recovers them via eDiscovery. A user cannot destroy retained mail — they can only move it into a vault they can't reach. The same holds for accidental deletion or a mailbox wipe.
The one limit: this protects against staff-level deletion completely. It does not protect against a compromised global administrator who disables the policy — that residual risk is covered by locking down admin access (few admins, MFA, Conditional Access), not by a backup product. Native retention is the deliberate choice; no third-party backup, no per-GB Microsoft 365 Backup.
Because mailboxes currently hold more than 6 years, enabling "retain-then-delete" will begin permanently deleting everything older than 6 years. Apply retain-only first, confirm no active dispute relies on older mail (litigation-hold any that does), then enable deletion. Irreversible once on.
The whole email plan runs on three tools, and all three are included in Microsoft 365 Business Premium — no backup product, no add-ons. Here is exactly what each one does and which requirement it serves.
| Tool | In plain terms — what it does | What it serves |
|---|---|---|
| Microsoft Purview retention policy | The rulebook and the vault. It (a) keeps all email for 6 years — preserving it even if someone deletes or purges it — and (b) permanently deletes it once it passes 6 years. It doesn't let you browse; it enforces keep/delete and holds a protected copy nobody can tamper with. | Retention (the 6-year rule) + recoverability / backup (protects against deletion) |
| Online Archive Exchange Online | A second, larger mailbox attached to a user's account that appears in their Outlook. Mail older than 24 months auto-moves here, keeping the main inbox tidy while everything stays searchable by the user themselves. | Access / self-service (staff find their own old mail) + storage headroom |
| eDiscovery a Purview tool | The search-and-recover tool for IT. Gemma can search across every mailbox at once — by sender, recipient, date, keyword — reach into the hidden preserved copies the retention vault holds, and export the results to a folder / PST. Only the IT / compliance account has it. | Recoverability (pull deleted mail back) + cross-mailbox production for disputes |
How they fit together: Purview keeps and protects everything for 6 years; the Online Archive is where staff see and search their own older mail; eDiscovery is how Gemma searches across everything and recovers deleted or cross-mailbox mail from what Purview has preserved. Retention, self-service access, and recoverability — all covered, with no third-party or per-GB backup product.
The three tools apply in full to normal staff mailboxes. Shared inboxes are handled differently — they're unlicensed stores, so they get no Online Archive — as set out below.
| Tool | Normal staff user account | Shared inbox (separate handling) |
|---|---|---|
| Purview retention (keep 6 yr + preserve) | Applies fully — keep, protect, delete at 6 yr | 6-year retention applies; the preserved / legal copy actually sits on the licensed staff mailbox the mail came from (shared inboxes are only stores) |
| Online Archive (auto-tier >24 mo) | Applies — included free, self-searchable in Outlook | Not used — enabling it would need a licence. Instead the inbox is kept under 50 GB (trim, then split) so no archive is needed |
| eDiscovery (IT search / recover) | Applies — Gemma can search & recover | Applies — Gemma's eDiscovery searches shared inboxes too, licence or not |
So the shared-inbox policy is: retention on, eDiscovery-searchable, no Online Archive, kept under 50 GB (trim / split), no licence. Staff mailboxes get all three tools in full. Both are covered by Business Premium at no extra cost.
Included in Business Premium — one item to confirm: Purview retention, the Online Archive and eDiscovery / Content Search are all part of Business Premium. The only thing to verify is the exact eDiscovery tier for cross-mailbox export — if it isn't fully included, a small Exchange Online Plan 2 uplift on Gemma's compliance account covers it (a few pounds a month, not thousands). Not required, and not being bought: Microsoft 365 Backup (per-GB) or any third-party backup.
| Measure | Figure |
|---|---|
| Capacity per licensed user (50 + 50) | ~100 GB |
| Capacity across 30 users | ~3 TB |
| Current usage — all 146 mailboxes | ~680 GB |
| Largest single mailbox | 54 GB (Blocks H-P, all-time) |
Current usage is a fraction of licensed capacity, no mailbox is near the 100 GB ceiling, and the 6-year policy will trim the all-time totals down — the Excel figures are lifetime and were never archived. No storage add-ons and no shared-mailbox archive licences are planned. Shared mailboxes are kept under 50 GB to stay free — via the 6-year trim, then splitting a pool into smaller sub-sets (e.g. Blocks A–C, D–G) if any remains over (Blocks H-P, 54 GB, first). Preservation needs no shared-mailbox licence either: the shared inboxes are only stores — every email in them was received in a licensed staff mailbox first and manually filed there under company inbox policy. So the compliance backbone sits on the staff mailboxes, which keep a retained, eDiscoverable copy under the 6-year policy regardless of the store's licence. The stores hold the working copy staff browse and search; the licensed staff mailbox holds the preserved copy — for free. (Pre-policy backlog already sitting in the stores stays eDiscoverable as live mailbox content, and the 6-year rule deletes anything older than 6 years anyway.)
Where the money goes today, what it becomes after the migration, and the one-off cost to get there. All figures are ex-VAT (reclaimable) and annual unless stated, on the current ~30-user headcount.
| Ongoing item | Now / year | After / year | Change |
|---|---|---|---|
| Microsoft 365 licences (30 users) | £3,960 Standard | ~£6,210 Premium | +£2,250 |
| Antivirus | £3,000 Bitdefender | £0 Defender, in Premium | −£3,000 |
| AMJ ongoing services | £6,530 | £0 | −£6,530 |
| AM Automate hosting (Azure B4ms 16 GB + managed DB) | £0 on the old server | ~£1,300 | +£1,300 |
| Total ongoing | ~£13,490 | ~£7,510 | −£5,980 / yr |
Two costs go up — the Premium uplift (+£2,250) and the new Azure hosting (+£1,300) — but they're far outweighed by dropping Bitdefender and AMJ entirely. Net ongoing saving ≈ £6,000 a year, while moving off a dead, corruption-prone server onto a resilient cloud setup and upgrading every user to Premium's security and management.
| One-off item | Cost (ex-VAT) | Notes |
|---|---|---|
| AMJ — identity / device / network cutover | ~£5,000–7,000 TBC | The specialist migration (Section 2); firm figure on AMJ's re-quote |
| AM Automate → Azure, photo migration, M365 setup | £0 new cash | Done by Gemma + Claude — internal effort, not a new bill |
| Azure / tooling provisioning | absorbed | Within the hosting cost above |
| Total one-off | ~£5,000–7,000 | Dominated by AMJ's migration fee (TBC) |
If Gemma's migration hours are billed separately (rather than covered by an existing arrangement), add those as a further one-off. Going cloud also avoids the periodic on-prem server refresh — AMJ quoted ~£7,000+ for a replacement box in 2023 — which never has to be spent again.
| Current ongoing spend | ~£13,490 / year |
| New ongoing spend | ~£7,510 / year |
| Ongoing saving | ~£6,000 / year |
| One-off migration cost | ~£5,000–7,000 (TBC) |
| Payback period | ~1 year (10–14 months) — then ~£6,000/yr saved every year after |
The migration pays for itself in about a year and then saves roughly £6,000 a year, every year — while replacing an unsupported, failure-prone server with a resilient cloud stack, ending the AMJ recurring relationship, and putting every user on Business Premium's security and device management. Financially and operationally, it costs more to not do this.