Master Reference · Internal

AM Surveying & Block Management — On-Prem to Cloud Migration

Single source of truth for the migration project. Everything decided across planning has been captured here. If it's not in this document, treat it as not yet decided. This is the working field reference for Gemma (ADV Multimedia) throughout the project.

Retiring amssrv01 · Windows Server 2012 R2 Out of Microsoft extended support since October 2023 ⏰ Licences → Premium by 21 Sep 2026 🎯 Server off end Oct / early Nov 2026

Timescale at a glance: delivered over ~2 months — September–October 2026. Workstreams overlap; the pace is set by the AM Automate critical path and AMJ's device re-homing. Two fixed dates: licences to Business Premium by 21 Sep 2026, and amssrv01 switched off by end Oct / early Nov 2026 (fully in the cloud). Full week-by-week schedule and Gemma's availability in Section 9.

1

Project Objective

Decommission the on-prem Windows Server 2012 R2 entirely. Every role it currently performs is being replaced with a cloud-native or Microsoft 365-based equivalent — this is not a hardware refresh, and no replacement on-prem server or NAS is being purchased.

2

Staffing Model

Locked · Final

Three parties involved. This scope split is a final decision — not open for reconsideration. The only outstanding action is obtaining AMJ's revised price for the scope below; that pricing step does not reopen whether AMJ is engaged.

WorkstreamOwner
Identity & device (AD/GPO → Entra ID + Intune)AMJ IT Services
Network services (DHCP/DNS → firewall/router)AMJ light touch
Windows Updates (WSUS → Windows Update for Business)AMJ via Intune
Print serving → Universal PrintAMJ
Antivirus rollout (Bitdefender → Defender for Business)AMJ light, via Intune
Safe retirement of AD / DHCP / DNS on the old serverAMJ
Photo storage migration to SharePointGemma + Claude not AMJ
AM Automate migration to AzureClaude + Gemma not AMJ

Why this split: AMJ's items share three traits — broad blast radius (a mistake stops everyone logging in, printing, or updating), hard to reverse once cut over, and require tacit specialist knowledge (Conditional Access lockout risk, GPO-to-Intune mapping, profile-safe device migration) plus professional accountability. Gemma + Claude's items are contained, reversible, and rehearsable — including AM Automate, which Claude built and knows in full.

AMJ owns the identity cutover night — the single highest-risk, hardest-to-reverse window in the whole project.

Quotes cancelled / superseded

Outstanding action: AMJ to be re-quoted against the narrowed specialist scope above (identity/device, network services, updates, print, antivirus rollout, safe AD/DHCP/DNS retirement) — a pricing formality, not a re-decision.

3

Licensing Change

~½ day effort

⏰ Hard deadline — 21 September 2026

The current annual Business Standard subscription term ends 21 Sep 2026. It must be converted to Business Premium before that date. If it auto-renews as Standard first, a Microsoft annual (NCE) commitment generally cannot be cancelled or downgraded mid-term — that would lock the business into Standard until Sep 2027 and stall the whole cloud-native approach (or force paying for Premium in parallel).

  • Action: before 21 Sep, either set the subscription to renew as Business Premium, or let Standard lapse and provision Premium — action it in your own Microsoft 365 admin centre, as licences are paid direct to Microsoft (no CSP or reseller involved). NCE conversion rules are fiddly and the cancellation window is narrow, so do it in good time.
  • Scope of the deadline: only the licences need to be in place by 21 Sep — not the technical migration. The Entra / Intune / Defender / Universal Print buildout can follow afterwards at its own pace. This deadline is a procurement action, not the whole project.
CurrentMicrosoft 365 Business Standard, £11.00/user/month, 30 users
Moving toMicrosoft 365 Business Premium, ~£16.90–17.60/user/month, 30 users
WhyPremium bundles Entra ID P1, Intune, Defender for Business, and Universal Print at a lower combined price than buying these as standalone add-ons on top of Standard. This licensing change is the enabler for the entire cloud-native approach — nothing in Section 4 is possible without it.

Note: confirm actual current invoiced Standard price (vs list price) before the upgrade is ordered, as real pricing may differ from list price used in planning.

4

Server Role Replacement

AMJ-led
On-prem role (being retired)Cloud replacement
Active DirectoryMicrosoft Entra ID
Group Policy Objects (GPOs)Microsoft Intune configuration profiles
DHCPFirewall/router
Internal DNSFirewall/router / Entra-joined device resolution
WSUS (Windows Update management)Windows Update for Business policies (via Intune)
Print serverUniversal Print (included in Business Premium)

Device re-homing: ~30 machines move from AD-joined to Entra-joined + Intune-enrolled, preserving user profiles/data (wipe-and-Autopilot vs in-place, decided per device by AMJ).

In-person laptop configuration: device re-homing is hands-on — every staff laptop (~30) is brought into the office and reconfigured in person, not remotely. This is delivered by AMJ's on-site presence — the physical-attendance element of their retained scope, and a key reason a locally-attending specialist is kept for this piece. It is phased across a Monday–Friday week during the migration (a batch of laptops each day), so staff are never all without their machines at once and each person is down only briefly.

Network services cutover: DHCP/DNS move onto the firewall/router, after AMJ audits what currently resolves against the server by name (scanners, MFPs, or anything hardcoded to the server).

AMJ's delivery scope in full indicative — confirm on re-quote

Workstream total: ~2–3 weeks effort — device re-homing dominates. Indicative only; AMJ's re-quote confirms.

5

Antivirus Change

~½ day · within the Intune rollout
OutBitdefender GravityZone, £250/month (~£3,000/year)
InMicrosoft Defender for Business, included in Business Premium at no extra cost
Net effectthe Premium licensing uplift (~£2,150–2,400/year extra vs current Standard spend) is more than offset by dropping Bitdefender — close to cost-neutral or better overall once Bitdefender is cancelled.

Confirmed decision: Bitdefender is being dropped in favour of Microsoft Defender for Business — this is settled, not an open question. Implementation note for AMJ: switch on the full Defender for Business feature set (EDR, attack surface reduction, automated remediation), not just the base antivirus engine, so detection is at its strongest given the leaseholder financial/legal data the business holds.

6

Photo Database Migration

Locked · FinalGemma + Claude

6.1 Destination and interim UX

This decision is final. Not Azure Files/Blob, not on-prem NAS.

6.2 Why this is safe this time (root cause of the prior failure)

Roughly 5 years ago, an attempt to store the photo database in SharePoint failed. The failure was not caused by SharePoint itself — it was caused by Picasa, a desktop photo-browsing tool installed locally on each laptop. Picasa's local indexing forced full download/hydration of every cloud-synced photo to the laptop's hard drive, which crashed the machines. The combination of Picasa + local sync was at fault, not SharePoint storage. This migration avoids that failure mode entirely — see Section 7 (AM PhotoStore).

6.3 Execution plan — 5 phases

Scale: 1,200 folders, ~480GB, mapping to 250 currently-managed sites.

  1. Canonical site list — pull the definitive list of 250 current site names from Blockman/the site register, including known aliases or old names. ~½ day
  2. AI-assisted fuzzy matching pass — run via Claude Code, on the server. Produces a reviewable spreadsheet: folder name, matched site (or "no match"), confidence level, reason. ~½–1 day
  3. Human review and sign-off — every match reviewed before any data moves, especially low-confidence/unmatched folders. Folders for no-longer-managed sites or discontinued business areas go into a dedicated "bin" folder — never silently dropped. ~1–2 days
  4. Bulk copy — via a proper bulk transfer tool (SharePoint Migration Tool, PnP PowerShell, or a Graph API script), not file-by-file agent copying. ~1–3 days transfer
  5. Verification — folder/file counts checked source vs destination, total size compared, spot-check that images open correctly post-move. ~½–1 day

Workstream total: ~1–1.5 weeks elapsed — a few days' work plus background transfer time for 480GB (bandwidth-dependent).

6.4 Backup caveat (open item, not yet decided)

"No on-prem storage" does not mean "backups solved." Cloud data in SharePoint/OneDrive still needs its own data-protection/retention strategy under Microsoft's shared-responsibility model — a separate, not-yet-made decision, distinct from the Azure VM + PostgreSQL backups already covered under AM Automate.

7

AM PhotoStore

future build · not a migration blocker

Once the photo migration (Section 6) is complete, a custom internal tool called AM PhotoStore will be built as a future module of AM Automate.

8

AM Automate Migration

Claude + Gemma

AM Automate is the suite of six in-house business apps currently hosted on amssrv01: PayFlow, SalesFlow, Fire Doors, WebServe, Dispatch, CaseFlow.

This migration was fully scoped and locked separately, on the Claude instance connected to the server that built AM Automate. Refer to that runbook directly for all implementation detail — it is not duplicated here:

Headline summary only

⚠ Critical dependency

AM Automate is the gating workstream — its cutover must be complete and proven stable for approximately one week before the server can be retired. But it is not the only gate: see the full decommission gate in Section 9.

  • Sections 4, 5, and 6 (identity/network migration, antivirus, photo migration) can all start independently and in parallel with AM Automate.
  • But the server cannot be physically switched off until all four gates have closed: AM Automate cut over and soaked ~1 week; the photo database migrated and verified off the server (the 480GB lives here today); devices re-homed off Active Directory; and the control machine re-pointed to the VM with onward edits confirmed (see 8.1 and Section 9).
  • Rough timeline: ~2–3 weeks prep → one cutover evening → ~1 week soak → server free to retire once the other gates have also closed.

8.1 Where AM Automate is controlled from — after the move (end-state)

How AM Automate is edited and updated must not change for staff. Today, every change to AM Automate is made by talking to one Claude — the machine in the IT cupboard — which makes the edit and posts it live. Only certain (non-technical) staff use it; they either remote in or walk over to the cupboard. There is no second tool and no hand-off between a "draft" Claude and a "live" Claude — the one cupboard Claude does both.

This model carries over unchanged. The cupboard Claude runs on a separate machine from the server, so when the server is decommissioned that machine stays. It is simply re-pointed — once, during the migration — to reach the AM Automate apps on the Azure VM instead of the old local server. To anyone using it, nothing changes: same machine, same remote-in / walk-over, same "talk to it → the edit goes live."

Location — locked for now, optimise later: the AM Automate Claude stays in the IT cupboard after the migration — not because it has to (the server it sat next to is gone), but because that is where staff expect to find it. Whether to relocate the "go-to Claude" to a more convenient spot is a future optimisation, deliberately kept OUT of the migration mechanics. The migration's only job here is to re-point the existing cupboard Claude at the cloud; moving it comes later, if at all.

End goal for Gemma: after cutover, the IT-cupboard Claude machine is set up with secure access to the Azure VM (edit the app folder + restart services) and folder snapshots enabled — so the single-Claude, edit-and-post-live experience continues exactly as before, just pointed at the cloud. This re-pointing is a required migration task, not an afterthought — it is done at cutover and verified with a live test edit before the old server is decommissioned (it is the fourth item in the decommission gate, Section 9). Without it, switching the server off would leave AM Automate running in the cloud but un-editable.

9

Project Sequencing

Order of execution. The workstreams overlap heavily — the stages below are the priority order, not strict start/finish gates, except where marked. AM Automate leads because it is the one workstream that gates switching the server off.

Order of execution

  1. 0
    Licensing upgrade — Business Standard → Business Premium. Parallel · from day one
    Zero-risk procurement, and the enabler for everything AMJ does (Sections 4–5). Hard deadline: must be converted before the Standard annual term ends 21 Sep 2026 or the business risks being locked into Standard for another year (Section 3). Confirm the actual invoiced Standard price and the conversion mechanism first.
    ⏰ by 21 Sep 2026
  2. 1
    AM Automate → Azure. First · critical path
    The longest pole and the only workstream that gates decommission, so it starts first. Full 7-phase runbook (Section 8). Does not depend on the licensing upgrade or the identity migration — it can run straight away.
    ~4–5 wks incl. soak
  3. 2
    Photo database → SharePoint. Second
    Gemma + Claude (Section 6). Can overlap AM Automate's testing/soak, but sequenced second so Gemma isn't split across two live migrations at once. Must be complete and verified before the server is switched off.
    ~1–1.5 wks
  4. 3
    Identity / network / print / antivirus migration (AMJ). Then everything else
    Requires Business Premium (Stage 0) to be in place first. The Entra + Intune baseline, Conditional Access, device re-homing, Universal Print, Windows Update for Business and Defender rollout, and the DHCP/DNS cutover (Section 4). The identity cutover night sits here — the highest-risk window, owned by AMJ. The build can begin earlier in parallel; it is placed after AM Automate and photos by priority, not by dependency.
    ~2–3 wks · AMJ
  5. 4
    Decommission amssrv01. Last · terminal step
    The physical switch-off. Gated by three things being true at once (see below) — not by AM Automate alone.
    ~1 hr

⚠ The decommission gate — all four must be true

  • AM Automate has cut over to Azure and run clean for ~1 week.
  • Photos are fully migrated to SharePoint and verified — the 480GB lives on the server today, so its only copy must be safely in the cloud first.
  • Devices are re-homed off Active Directory (Entra-joined), and AD/DHCP/DNS have been retired — or logins and name resolution break the moment the box goes off.
  • Control re-pointed — the IT-cupboard Claude machine has been re-pointed from the old server to the Azure VM, and a test edit-and-go-live confirmed. Miss this and, once the server is off, there is no way to make onward edits to AM Automate (see 8.1).

Rough timeline: ~2–3 weeks prep → one AM Automate cutover evening → ~1 week soak → server free to retire once the other gates have also closed.

Dependency matrix (reference)

WorkstreamCan start independently?Blocks server retirement?
Licensing upgrade (Standard → Premium)YesNo — but prerequisite for the AMJ workstream
AM Automate migration to Azure (Claude + Gemma)YesYes — the gating workstream
Photo migration to SharePoint (Gemma + Claude)YesYes — data lives on the server
Identity/network/print/AV migration (AMJ)YesPartly — device re-homing + AD/DHCP/DNS retirement must complete before switch-off
Physical server (amssrv01) decommissionTerminal step — only once all three gates above have closed

Delivery schedule — September–October 2026

Target: complete within ~2 months (September–October 2026), with end of October / early November 2026 as the hard deadline to switch off amssrv01 and be fully in the cloud. Two fixed dates anchor the plan: licences to Premium by 21 Sep, server off by end Oct / early Nov.

Gemma's availability (from 1 Sep 2026): every Wednesday (full day), Thursday & Friday afternoons, and weekends if needed — roughly 2–3 effective days per week. This is the binding constraint on the hands-on work; the AM Automate critical path is largely Claude-driven and can progress between her windows.

WindowFocus / milestoneLeadGemma's part
Early Sept
by 21 Sep — hard
Convert licences → Business Premium — enables the AMJ workstreamGemmaAction the conversion directly in the Microsoft 365 admin centre (~½ day)
Weeks 1–3 SeptAM Automate → Azure — provision, build, migrate data/secrets, parallel testing (runbook Phases 1–5)ClaudeSpot-check & sign-off on Wednesdays
Weeks 2–4 SeptPhoto migration — site list → AI match → review → bulk copy → verifyGemma + ClaudeReview matches + verify on her days
From mid-Sept
after Premium live
AMJ build — Entra + Intune baseline, Conditional AccessAMJCoordinate access
Late Sept – Oct
laptop week: Mon–Fri
AMJ rollout — device re-homing (~30 laptops brought in, reconfigured in person, phased Mon–Fri), Universal Print, WUfB, Defender, DHCP/DNSAMJAMJ on-site for the laptop week; Gemma coordinates + assists
Early–mid Oct
a weekend
AM Automate cutover evening → ~1 week soakClaude + GemmaPresent for the cutover (weekend window)
Late OctRetire AD / DHCP / DNS — all three decommission gates closeAMJCoordinate
End Oct / early Nov
HARD
Decommission amssrv01 — fully in the cloudAMJ + allPhysical switch-off

Biggest risk to the end-October deadline: not the software work — AM Automate is Claude-driven and can run ahead — but AMJ's device re-homing across ~30 machines, which needs AMJ time, Gemma on-site, and staff availability, all within a limited number of days. Book AMJ now and batch the device sessions across Gemma's Wednesdays, Thursday/Friday afternoons and weekends. AM Automate must also cut over by ~mid-October to leave its ~1-week soak before switch-off.

10

AMJ Exit Plan

Gemma + Claude

AMJ currently charges a recurring fee of about £6,500 a year for four things: backing up the on-prem server, monitoring it, backing up our Microsoft 365 email, and a small annual support retainer.

The key realisation is that three of those four exist only because of the old server — and this migration removes that server completely. Its backup and monitoring have nothing left to look after once it's gone, so they simply stop. The support retainer is cancelled outright. That leaves just one service worth keeping — protecting our email — and even that isn't handed to a new supplier: it is replaced by tools already included in the Microsoft 365 Business Premium licences we're upgrading to anyway (Purview retention, the Online Archive and eDiscovery). We pay for those capabilities the moment we move to Premium; switching them on costs nothing more.

So the migration doesn't merely move our systems to the cloud — it dissolves the reason AMJ's ongoing services exist. Their recurring bill goes to £0, with no replacement supplier and no new spend; the migration itself, plus licences we're already buying, do the whole job. All of it is Microsoft 365 admin configuration — a Gemma + Claude task, not server work and not AMJ's. The detail below sets out each line, what happens to it, and exactly how the Business Premium tools cover email retention and recoverability.

Scope: this eliminates AMJ's ongoing / recurring services. It is separate from the one-off identity-migration specialist role in Section 2 — whether that cutover uses AMJ or another specialist is a different decision and does not affect the exit below.

10.1 What AMJ bills now → what happens to it

AMJ serviceNet / yearFate
Server backup (Cloud Backup Safe, 750 GB)£1,128Ends — no server left to back up (at decommission)
Server monitoring agent£26Ends — nothing left to monitor (at decommission)
Email backup (Backup Cloud O365, ~76 units)£5,016Replaced — native Microsoft 365 retention + archive + eDiscovery (10.2–10.3)
Support retainer (3rd-level O365 block hours)£360Cancelled — final decision
Total ongoing AMJ~£6,530→ £0

AMJ ongoing spend goes to £0 — with no licence replacement cost. Shared mailboxes are kept under 50 GB so they stay free (no archive, no licence): applying the 6-year rule trims their lifetime sizes down, and any that remain over 50 GB are split into smaller sub-sets (e.g. Blocks A–C, D–G) rather than licensed. Hard policy: we do not pay to store old email.

10.2 Email retention & access — the policy set

The definitive email policies Gemma applies in Microsoft 365 (Purview + Exchange Online) — the rules that let the AMJ email backup be switched off.

PolicyRule
Retention periodAll email retained 6 years, then permanently deleted (Purview retain-then-delete). Applied to staff and shared mailboxes.
Archive tieringMail older than 24 months auto-moves to the Online Archive. So 0–2 yr = primary mailbox, 2–6 yr = archive — both live in Outlook and are self-searchable.
Deleted-items self-recoveryThe user "Recover Deleted Items" window is set to the 30-day maximum.
Staff self-serviceStaff find any email they sent or received in the last 6 years themselves in Outlook (primary + archive) — no IT needed.
eDiscovery — IT onlyRestricted to the IT / compliance account (Gemma). Used only for the three cases below.
Shared mailboxesKept under 50 GB so they stay free (trimmed by the 6-year rule; split into sub-sets if any remains over). Stores only — the compliance copy sits on the licensed staff mailboxes (10.4).

Where IT (Gemma, via eDiscovery) is needed — and only here:

10.2.1 Recoverability — this is the email backup

The retention policy is the recoverability/backup for email against data loss by deletion, accidental or malicious — this is the answer to "what replaces the AMJ email backup for actually getting lost emails back."

Worked example — a staff member maliciously deletes every email in their own inbox: the mail is still fully recoverable. When they delete and then purge it, the items move to a hidden Recoverable Items → Purges folder the user cannot open, and the 6-year retention policy forbids Exchange from actually removing them. Gemma recovers them via eDiscovery. A user cannot destroy retained mail — they can only move it into a vault they can't reach. The same holds for accidental deletion or a mailbox wipe.

The one limit: this protects against staff-level deletion completely. It does not protect against a compromised global administrator who disables the policy — that residual risk is covered by locking down admin access (few admins, MFA, Conditional Access), not by a backup product. Native retention is the deliberate choice; no third-party backup, no per-GB Microsoft 365 Backup.

⚠ The deletion switch is one-way

Because mailboxes currently hold more than 6 years, enabling "retain-then-delete" will begin permanently deleting everything older than 6 years. Apply retain-only first, confirm no active dispute relies on older mail (litigation-hold any that does), then enable deletion. Irreversible once on.

10.3 The three Microsoft tools — what each actually does

The whole email plan runs on three tools, and all three are included in Microsoft 365 Business Premium — no backup product, no add-ons. Here is exactly what each one does and which requirement it serves.

ToolIn plain terms — what it doesWhat it serves
Microsoft Purview
retention policy
The rulebook and the vault. It (a) keeps all email for 6 years — preserving it even if someone deletes or purges it — and (b) permanently deletes it once it passes 6 years. It doesn't let you browse; it enforces keep/delete and holds a protected copy nobody can tamper with.Retention (the 6-year rule) + recoverability / backup (protects against deletion)
Online Archive
Exchange Online
A second, larger mailbox attached to a user's account that appears in their Outlook. Mail older than 24 months auto-moves here, keeping the main inbox tidy while everything stays searchable by the user themselves.Access / self-service (staff find their own old mail) + storage headroom
eDiscovery
a Purview tool
The search-and-recover tool for IT. Gemma can search across every mailbox at once — by sender, recipient, date, keyword — reach into the hidden preserved copies the retention vault holds, and export the results to a folder / PST. Only the IT / compliance account has it.Recoverability (pull deleted mail back) + cross-mailbox production for disputes

How they fit together: Purview keeps and protects everything for 6 years; the Online Archive is where staff see and search their own older mail; eDiscovery is how Gemma searches across everything and recovers deleted or cross-mailbox mail from what Purview has preserved. Retention, self-service access, and recoverability — all covered, with no third-party or per-GB backup product.

10.3.1 How they apply — staff accounts vs shared inboxes

The three tools apply in full to normal staff mailboxes. Shared inboxes are handled differently — they're unlicensed stores, so they get no Online Archive — as set out below.

ToolNormal staff user accountShared inbox (separate handling)
Purview retention (keep 6 yr + preserve)Applies fully — keep, protect, delete at 6 yr6-year retention applies; the preserved / legal copy actually sits on the licensed staff mailbox the mail came from (shared inboxes are only stores)
Online Archive (auto-tier >24 mo)Applies — included free, self-searchable in OutlookNot used — enabling it would need a licence. Instead the inbox is kept under 50 GB (trim, then split) so no archive is needed
eDiscovery (IT search / recover)Applies — Gemma can search & recoverApplies — Gemma's eDiscovery searches shared inboxes too, licence or not

So the shared-inbox policy is: retention on, eDiscovery-searchable, no Online Archive, kept under 50 GB (trim / split), no licence. Staff mailboxes get all three tools in full. Both are covered by Business Premium at no extra cost.

Included in Business Premium — one item to confirm: Purview retention, the Online Archive and eDiscovery / Content Search are all part of Business Premium. The only thing to verify is the exact eDiscovery tier for cross-mailbox export — if it isn't fully included, a small Exchange Online Plan 2 uplift on Gemma's compliance account covers it (a few pounds a month, not thousands). Not required, and not being bought: Microsoft 365 Backup (per-GB) or any third-party backup.

10.4 Storage — no bolt-ons needed

MeasureFigure
Capacity per licensed user (50 + 50)~100 GB
Capacity across 30 users~3 TB
Current usage — all 146 mailboxes~680 GB
Largest single mailbox54 GB (Blocks H-P, all-time)

Current usage is a fraction of licensed capacity, no mailbox is near the 100 GB ceiling, and the 6-year policy will trim the all-time totals down — the Excel figures are lifetime and were never archived. No storage add-ons and no shared-mailbox archive licences are planned. Shared mailboxes are kept under 50 GB to stay free — via the 6-year trim, then splitting a pool into smaller sub-sets (e.g. Blocks A–C, D–G) if any remains over (Blocks H-P, 54 GB, first). Preservation needs no shared-mailbox licence either: the shared inboxes are only stores — every email in them was received in a licensed staff mailbox first and manually filed there under company inbox policy. So the compliance backbone sits on the staff mailboxes, which keep a retained, eDiscoverable copy under the 6-year policy regardless of the store's licence. The stores hold the working copy staff browse and search; the licensed staff mailbox holds the preserved copy — for free. (Pre-policy backlog already sitting in the stores stays eDiscoverable as live mailbox content, and the 6-year rule deletes anything older than 6 years anyway.)

10.5 Actions to fully exit AMJ (Gemma + Claude)

  1. Apply the Purview 6-year retention policy — retain-only first, enable deletion only after confirming no active dispute needs older mail.
  2. Set the archive policy to auto-move mail older than 24 months to the Online Archive.
  3. Set the deleted-items recovery window to 30 days.
  4. Keep shared mailboxes under 50 GB so they stay free: apply the 6-year trim, then split any still over 50 GB into smaller sub-sets (e.g. Blocks A–C, D–G). Do not buy archive licences. Start with Blocks H-P.
  5. Grant eDiscovery access to the IT / compliance account (Gemma) only; confirm the eDiscovery tier.
  6. Cancel the AMJ support retainer now (final).
  7. At server decommission, cancel AMJ's server backup + monitoring lines.
  8. Once native retention is verified, cancel the AMJ email backup — closing the ongoing AMJ relationship to £0.
11

Cost Analysis

Where the money goes today, what it becomes after the migration, and the one-off cost to get there. All figures are ex-VAT (reclaimable) and annual unless stated, on the current ~30-user headcount.

11.1 Ongoing costs — now vs after

Ongoing itemNow / yearAfter / yearChange
Microsoft 365 licences (30 users)£3,960 Standard~£6,210 Premium+£2,250
Antivirus£3,000 Bitdefender£0 Defender, in Premium−£3,000
AMJ ongoing services£6,530£0−£6,530
AM Automate hosting (Azure B4ms 16 GB + managed DB)£0 on the old server~£1,300+£1,300
Total ongoing~£13,490~£7,510−£5,980 / yr

Two costs go up — the Premium uplift (+£2,250) and the new Azure hosting (+£1,300) — but they're far outweighed by dropping Bitdefender and AMJ entirely. Net ongoing saving ≈ £6,000 a year, while moving off a dead, corruption-prone server onto a resilient cloud setup and upgrading every user to Premium's security and management.

11.2 One-off costs — the migration itself

One-off itemCost (ex-VAT)Notes
AMJ — identity / device / network cutover~£5,000–7,000 TBCThe specialist migration (Section 2); firm figure on AMJ's re-quote
AM Automate → Azure, photo migration, M365 setup£0 new cashDone by Gemma + Claude — internal effort, not a new bill
Azure / tooling provisioningabsorbedWithin the hosting cost above
Total one-off~£5,000–7,000Dominated by AMJ's migration fee (TBC)

If Gemma's migration hours are billed separately (rather than covered by an existing arrangement), add those as a further one-off. Going cloud also avoids the periodic on-prem server refresh — AMJ quoted ~£7,000+ for a replacement box in 2023 — which never has to be spent again.

11.3 The bottom line

Current ongoing spend~£13,490 / year
New ongoing spend~£7,510 / year
Ongoing saving~£6,000 / year
One-off migration cost~£5,000–7,000 (TBC)
Payback period~1 year (10–14 months) — then ~£6,000/yr saved every year after

The migration pays for itself in about a year and then saves roughly £6,000 a year, every year — while replacing an unsupported, failure-prone server with a resilient cloud stack, ending the AMJ recurring relationship, and putting every user on Business Premium's security and device management. Financially and operationally, it costs more to not do this.

12

Open Items Still Requiring Action

  1. ⏰ Convert M365 Standard → Business Premium before 21 Sep 2026 — hard deadline. If Standard auto-renews first, the annual (NCE) term likely locks the business into Standard until Sep 2027 (Section 3). Licences are paid direct to Microsoft, so action it in the Microsoft 365 admin centre — no third party involved. Most time-critical item on this list.
  2. AMJ re-quote — one-off migration specialist scope only (identity/device cutover, Section 2). Distinct from the ongoing AMJ exit, which is now planned (Section 10). Pricing formality.
  3. SharePoint / OneDrive data protection — resolved: covered by native Microsoft 365 retention + version history + recycle bin (Section 10). Optional Microsoft 365 Backup (per-GB) can be added later if point-in-time site restore is wanted.