Microsoft 365

What Microsoft 365 Management Includes, and What Unmanaged Microsoft 365 Costs a Tulsa Business

Microsoft 365 rarely fails all at once. It drifts. Someone leaves and their account stays open. A license bought for a project two years ago is still on the invoice. Multi-factor authentication is on for most people, except the three who complained. Nobody has tried restoring a deleted mailbox, so nobody knows whether it works. Each of these is small. Together they are what “unmanaged” means.

The short answer

Microsoft 365 management is the ongoing work of keeping accounts, licenses, security settings, and backups correct as your business changes — plus day-to-day help for the people using Outlook, Teams, SharePoint, and OneDrive. Microsoft runs the service. It does not decide who in your company should have access to what, notice that you are paying for seats nobody uses, or restore a file someone deleted four months ago.

The cost of leaving it unmanaged shows up in four places: licenses you pay for and do not use, accounts that stay open after people leave, sign-ins without multi-factor authentication, and data you assumed was backed up. The sections below take each in turn.

What Microsoft 365 management includes

What Microsoft 365 management covers and why it matters
AreaWhat gets doneWhat it prevents
Day-to-day supportSign-in problems, mail delivery, shared mailboxes, Teams, and OneDrive and SharePoint syncing and permissions.The same email and file-sharing problems costing your people time every week.
Joiners, movers, leaversAccounts and licenses set up for new staff, access changed when roles change, and access secured and mail and files handed over when someone leaves.Former employees who can still read mail or open shared files.
LicensingA regular review of subscriptions, unassigned and unused licenses, and whether each person is on the plan their work needs.Paying for seats nobody uses, or for a plan above what the role requires.
Sign-in securityMulti-factor authentication for everyone, administrator roles reviewed, and conditional access policies where your licenses support them.One stolen password turning into a compromised mailbox.
Sharing and retentionHow files are shared outside the company, who owns each Team and site, and retention settings that match your obligations.Client files reachable through a link that was shared once and never reviewed.
Backup and recoveryIndependent backup of mail and files, backup checks, and restores that are actually tested.Discovering, after the retention window has closed, that the data is gone.

This is the scope of NSN Management’s Microsoft 365 management for Tulsa businesses. The exact coverage is written into your proposal, along with anything scoped as a separate project, such as a migration or a tenant cleanup.

Cost one: licenses you pay for and do not use

Microsoft 365 is billed per user, per month, so every unused seat is a recurring charge. Two details in Microsoft’s own documentation explain why the waste builds up quietly.

  • Deleting a user does not stop the charge. Microsoft’s admin guidance says it plainly: after you delete an account, “you’re still paying for the license” until someone reduces the license count as a separate billing step.
  • Annual commitments limit what you can remove. On an annual plan, a license generally cannot be removed from the subscription until the commitment ends — so the time to right-size is before renewal, not after.

Source: Microsoft Learn, “Delete a user from your organization”.

A worked example, with a made-up price so the arithmetic is easy to follow: suppose a 30-person company has six licenses nobody uses at $20 per user per month. That is $120 a month, or $1,440 a year, for nothing. This is hypothetical arithmetic, not a Microsoft price, an NSN quote, or a client result — check Microsoft’s current business plan pricing for the real figure on your plan, then count your own unassigned and inactive seats.

The opposite mistake costs money too: putting everyone on the top plan when part of the team only needs email, or buying security add-ons that a higher plan you already own includes. A licensing review looks at both directions.

Cost two: accounts that outlive the employee

When someone leaves, several things need to happen in the right order: block the sign-in, hand their mail and files to the right person, remove them from groups and shared mailboxes, then free the license. Skip the order and you either leave a door open or lose data you wanted to keep.

Microsoft’s defaults give you a window, not a safety net. A deleted user can be restored for 30 days; after that the data is permanently deleted. Their OneDrive is kept for 30 days by default, then sits in a recycle bin for a further 93 days that only an administrator using PowerShell can recover from. If nobody moved the files a manager needed, they are gone. (Same Microsoft Learn article.)

A managed offboarding process means the business decides what happens to the mailbox and files — before the clock runs out rather than after.

Cost three: sign-ins without multi-factor authentication

Most attacks on a small business’s Microsoft 365 do not break anything. They sign in, with a password that was phished or reused.

79% of ransomware attacks now start with a compromised identity rather than a technical exploit. Sophos, The State of Ransomware 2026 (opens in a new tab)

Multi-factor authentication blocks more than 99.2% of account-compromise attacks. Microsoft Entra documentation (opens in a new tab)

The expensive part of a compromised mailbox is rarely the cleanup. It is the invoice sent from your real address with someone else’s bank details, read and paid by a customer who trusted it. Multi-factor authentication for every account — including the owner’s, the shared front-desk login, and the old administrator account nobody remembers creating — is the least expensive control you can buy. For the detail, read our guide to Microsoft Entra ID (formerly Azure AD) for small businesses.

Cost four: assuming Microsoft backs up your data

Microsoft keeps the service available. Recycle bins and retention windows protect you from a mistake you notice quickly. They are not a backup with a point-in-time restore.

  • A deleted user’s mailbox is recoverable for 30 days by default.
  • A deleted SharePoint site is retained for 93 days, then permanently deleted with its content and settings (Microsoft Learn, “Restore deleted sites”).
  • Version history and OneDrive’s Files Restore can undo recent damage, but they live inside the same tenant and the same time limits. They are not an independent copy.

The question to ask is simple: if a folder was deleted five months ago and someone needs it today, where does it come from? NSN uses Datto SaaS Protection for Microsoft 365 mail and files, checks the backups, and tests restores, so the answer is written down before anyone needs it. More on the approach: backup and disaster recovery.

What does Microsoft 365 management cost?

Two separate things appear on the bill, and they are worth keeping apart when you compare proposals.

  • Microsoft subscriptions. The per-user licenses themselves, at Microsoft’s published rates for the plans you choose.
  • Management. The work described above. NSN quotes it from your user count, current setup, security and backup needs, and support scope. Migrations and cleanup projects are scoped and priced separately.

Most NSN clients do not buy Microsoft 365 management on its own. Microsoft 365 administration is part of our Managed IT service, which most clients pay $100–$175 per person per month for — and that figure covers the help desk, monitoring and patching, the security layer, and planning as well. It is not a Microsoft 365-only price. See what managed IT costs in Tulsa for how that range breaks down.

A ten-minute check you can do today

If you have administrator access, the Microsoft 365 admin center will answer most of these. If you do not know who has administrator access, that is the first finding.

  • Licenses: how many are purchased, how many are assigned, and how many assigned users have not signed in for 90 days?
  • Leavers: pick the last three people who left. Can any of them still sign in? Who has their mail and files?
  • Administrators: how many global administrators are there, and does each one use multi-factor authentication?
  • Multi-factor authentication: is it enforced for everyone, or merely available?
  • Sharing: can anyone in the company share a file with anyone outside it, with no expiry?
  • Backup: is there an independent backup of mail, OneDrive, and SharePoint — and when was a restore last tested?
  • Renewal: when does the subscription renew, and who reviews the seat count before it does?

Three or more answers of “not sure” is normal for a business without someone assigned to this. It is also the case for having someone assigned to it.

Get a review of your Microsoft 365 setup

NSN Management is a Tulsa-owned managed service provider that has supported local businesses since 2012, from an office at 2448 E 81st Street. We manage the Microsoft 365 environment you already have — you keep your tenant, your email addresses, and your files.

Request an M365 management review, or book a Discovery Call if you want to talk about IT more broadly.

Sources and scope

Retention periods and billing behaviour were read on Microsoft Learn on September 21, 2026, at the pages linked above; they describe Microsoft’s defaults, which an administrator can change and Microsoft can revise. The licensing example is illustrative arithmetic, not a price. Security statistics are cited to their original publishers. Confirm current Microsoft pricing, your plan’s features, and the scope of any management service in a written proposal.

Questions Tulsa businesses ask about this

What does Microsoft 365 management include?

Day-to-day support for Outlook, Teams, SharePoint, and OneDrive; account setup and removal as staff change; license reviews; sign-in security such as multi-factor authentication and administrator access reviews; sharing and retention settings; and independent backup with tested restores. NSN Management writes the exact scope into your proposal.

Doesn't Microsoft manage Microsoft 365 for us?

Microsoft runs the service and keeps it available. It does not decide who in your business should have access, remove accounts when people leave, review the licenses you pay for, or enforce multi-factor authentication for you. Those are administrator responsibilities that belong to your business or the provider you appoint.

Does deleting a user stop the Microsoft 365 license charge?

No. Microsoft's documentation states that after deleting a user you are still paying for the license until the license count is reduced as a separate billing step. On an annual commitment, a license generally cannot be removed until the commitment ends, so seat counts should be reviewed before renewal.

Does Microsoft back up our Microsoft 365 data?

Microsoft provides recycle bins and retention windows, not a point-in-time backup. By default a deleted user can be restored for 30 days and a deleted SharePoint site is retained for 93 days. After that the data is permanently deleted. NSN Management uses Datto SaaS Protection for Microsoft 365 mail and files, with backup checks and tested restores.

How much does Microsoft 365 management cost in Tulsa?

NSN Management quotes Microsoft 365 management from your user count, current setup, security and backup needs, and support scope; Microsoft subscriptions are a separate line. Most clients receive it as part of Managed IT, which most pay $100 to $175 per person per month for — a broader service, not a Microsoft 365-only price.

Do we have to move to a new Microsoft 365 account to work with NSN?

No. NSN Management reviews and manages the Microsoft 365 environment you already have. Changing who manages it generally does not require changing email addresses or moving files. We check account ownership, administrator access, and your current provider's handover requirements first.

How do we know if our Microsoft 365 is unmanaged?

Check whether purchased licenses match active users, whether former employees can still sign in, how many global administrators exist, whether multi-factor authentication is enforced for everyone, and when a restore was last tested. If several answers are unknown, nobody is managing it.

· Founder, NSN Management

Sean founded NSN Management in Tulsa in 2012 after running eMonarch, the managed IT company he started in 1999, and still leads the team. He co-wrote Special Edition Using Microsoft Active Directory (Que, 2001), was named to the Tulsa Business Journal’s 40 Under 40, and led NSN Management to Kaseya/Datto MSP of the Year 2025.

Published · Updated

Microsoft 365IT Budgeting & CostCybersecurity