The Unification Project
You run more than one email address and probably more than one company. This is how to put it all on your laptop and your phone — safely, without your IT admin finding out from a breach report.
This isn't best practice. It's the best version of your practice.
Best practice says don't do this at all. One identity, one device, keep personal and business fully separate — every company, kept on its own hardware, never touching your own inbox. That's the textbook answer, and it's correct.
You're not going to do that. You own more than one company, or you sit on more than one board, or you're the CEO who also has a life outside the P&L — and you're going to check all of it from the same phone regardless of what any policy says. That's not a failure of discipline. It's just what running things actually looks like once you're senior enough that "just don't do that" stops being a real option.
Fine. If you're going to blend personal and multiple companies on one laptop and phone anyway, this guide is how to do it as securely, as manageable for your IT admin, and as close to real best practice as the situation allows. It starts from the constraint instead of pretending it away. Every choice below is the most secure, most supportable version of an inherently compromised arrangement — built so your IT admin can sleep, and so you don't have to think about any of it again after the first afternoon.
The shape of the problem
This guide is for exactly one situation. If it doesn't describe you, most of it still applies — just skip what doesn't.
- You have a personal email address (Gmail, Yahoo, AOL, or your own domain) that's been yours for years and isn't going anywhere.
- You have one or two Microsoft 365 business accounts — your own company, a company you invested in, a board seat, a family business — and they're run by different IT admins who don't talk to each other.
- You want to check all of it from one laptop and one phone, without three different sign-in prompts fighting for your attention every time you tap the mail icon.
- You are willing to accept that this device will never be as clean as a single-purpose company laptop — in exchange for it being usable.
One hub. Everything else layers underneath it.
The whole guide is one idea, applied consistently: pick a single personal identity as your contacts-and-calendar hub, then add every business mailbox to your devices as a guest — never as the owner, and never with a return path back out.
Solid arrow = mail actually forwards this direction. Dashed line = mail is added as an account, never forwarded — the tenant keeps its own mailbox and nothing leaves it.
How long this actually takes
Answer a few questions about your actual setup. This is the same estimate we quote clients for the exact same build — adjusted up if you're doing it yourself instead of handing it to an admin. Your answers are remembered if you come back.
Where your contacts and calendar actually live
Every business account you add gets layered underneath this one identity. Get this choice right and everything downstream gets easier.
Free personal Gmail
If you already have a Gmail you've used for a decade, there's no urgent reason to move. Simplest possible path — if you're fine living with Google's quirks.
- Zero cost, zero setup
- Fine indefinitely if you're not precious about the address
Custom domain via Microsoft 365 Business Basic
A single self-administered, one-person Microsoft 365 tenant — roughly $6–8.40/user/month depending on billing. Yes, it's technically a tiny business tenant, but you're the only person in it and you administer it yourself. This is how you get a real custom domain through Microsoft without an MSP, now that Microsoft's old personal-tier custom-domain option is gone (see below).
- Self-service, no MSP or IT department needed
- A real custom domain address you control
- Outlook.com-grade rules engine, same server-side reliability taught in Chapter 7
Own domain via Cloudflare + Google Workspace
Register a domain through Cloudflare (~$10–15/yr), route it to a Google account. A solid alternative specifically for people who want to stay in Google's ecosystem for their own custom domain.
- Cloudflare Email Routing forwards it for free — no separate mail hosting bill
- Survives you leaving Google entirely later — the domain moves with you
Doesn't have to catch everything — in the Cloudflare dashboard's Email Routing rule you can exclude specific senders or domains if you want a few things to stay on the old address.
Out options (retiring these as active inboxes): Yahoo, AOL, and optionally an old Gmail or Hotmail/Outlook.com/Live account. In option (the hub itself): your Business Basic custom domain (recommended), or Gmail (simpler fallback) — never a free consumer Microsoft account, and never a business tenant. Business mailboxes are never a valid forwarding target, in either direction — see the confirmation step in Chapter 7.
Setting up a custom domain via Microsoft 365 Business Basic
- Sign up for Business Basic at microsoft.com.
- In the Microsoft 365 admin center, go to Settings → Domains → Add domain.
- Run the verification wizard (one-click via Domain Connect on supported registrars like GoDaddy, or manual TXT/MX records otherwise).
- Sign up at microsoft.com/microsoft-365/business/microsoft-365-business-basic — this creates your own one-person tenant.
- Sign in to the Microsoft 365 admin center and go to Settings → Domains → Add domain.
- Enter the domain you already own (or register one first through any registrar).
- If your registrar is a Domain Connect partner (GoDaddy and several others), the wizard verifies and configures DNS in close to one click. Otherwise, you'll add a few technical domain-ownership records manually — a TXT record to prove you own the domain, then MX and CNAME records to point mail at Microsoft. If those terms are unfamiliar, your domain registrar's own support chat can usually paste these in for you — this one step is also easy to hand to any IT-savvy contact.
- Once verified, create your mailbox on the new domain (e.g. jamie.castell@yourdomain.com) and set it as your primary address.
Source: learn.microsoft.com — Add a domain →
Retiring an old Outlook.com, Live, or Hotmail account
If you've had a free outlook.com, live.com, or hotmail.com account for years and want to fold it into your new hub, forward it the same way you would Yahoo or AOL below — this isn't the recommended hub itself, just how you retire one of these as an active inbox.
- Settings gear → Mail → Forwarding → enable, enter the forwarding address, save.
- Sign in at outlook.com and click the Settings (gear) icon.
- Go to Mail → Forwarding.
- Toggle Enable forwarding on.
- Enter the forwarding address you want mail routed to — your Business Basic custom domain mailbox, or Gmail.
- Optionally check Keep a copy of forwarded messages in this mailbox.
- Click Save.
If two-step verification isn't already on for this Microsoft account, turning on forwarding will prompt you to enable it — that's expected, not an error.
Gmail forwarding (if retiring an old Gmail as legacy)
- Settings gear → See all settings → Forwarding and POP/IMAP → Add a forwarding address → verify the confirmation link → come back and turn it on.
- Click the Settings (gear) icon in Gmail, then See all settings.
- Open the Forwarding and POP/IMAP tab.
- Click Add a forwarding address, enter the address, then Next → Proceed → OK.
- Gmail emails a confirmation link to the new address — open it and click the link.
- Back in Gmail Settings, refresh the page and revisit Forwarding and POP/IMAP.
- Select Forward a copy of incoming mail to [address] and choose what happens to Gmail's own copy.
- Click Save Changes.
Want partial forwarding instead of everything? Disable the blanket auto-forward above, then use Show search options to build filter criteria, click Create filter, check Forward it, pick the address, and click Create filter again.
Contacts stay personal. Calendar doesn't.
These two get confused constantly, and the right default is different for each one — so treat them as two separate decisions, not one.
Contacts: unchanged from Chapter 4 — your personal hub (your Business Basic custom domain, or Gmail) stays the seamless primary contacts store on both devices. Every business colleague, vendor, and old Yahoo-era connection ends up findable from one address book, because it's the one identity that isn't tied to a company that could revoke your access to it.
Calendar: a different default. On the laptop, set the default calendar to whichever business calendar you actually live in day to day — for most people that's the daily-driver tenant (Northline Metal Works in our running example), not the personal hub. New events you create without thinking about it should land as business meetings, because that's what most of your day actually is. We'd recommend the same business-default on the phone — but the phone is also where you'll want to manually pick your personal calendar per-appointment for the kid's recital or your own doctor's visit, rather than have it default there.
Setting the actual defaults: iPhone and Android
General framing is easy; the actual OS settings are buried and differ completely by platform. Here's exactly where to go on each.
If you use the Outlook app (recommended)
Outlook's own Settings → Calendar → Default Calendar picks which calendar new events land on when you create one without explicitly choosing — set it to your business calendar, matching the recommendation above. For contacts, Outlook syncs per account rather than through one global default: on iPhone, go to Settings → [account] → Save Contacts and choose to save to your iPhone for your personal hub account; on Android, it's Settings → Accounts → [account] → Sync Contacts. Turn this on only for your personal hub account so new contacts consistently land in the one address book from Chapter 4, not scattered across whichever account you happened to be in.
Outlook's own default-calendar control has moved between app versions before, especially on Android — if Settings → Calendar → Default Calendar isn't where you expect it, the reliable fallback is the same trick as the native-Android workaround below: only enable Calendar sync for the account you want new events to land on.
iPhone (native Mail/Calendar/Contacts)
- Contacts default: Settings → Apps → Contacts → Default Account — set to your personal hub account. This option only appears once more than one account has Contacts turned on; with just one account there's nothing to choose.
- Calendar default: Settings → Apps → Calendar → Default Calendar — set to your business calendar, per the recommendation above. Same override-per-event behavior applies: the default only decides what happens when you don't pick one.
- On older iOS versions, these same settings live directly under Settings → Contacts and Settings → Calendar, without the "Apps" step — Apple moved per-app settings under Settings → Apps starting with iOS 18.
Android (native Google/Samsung apps — messier, be aware)
Android doesn't have one clean equivalent to iOS's toggles, and what you do depends on which apps you're actually using:
- Default account for new contacts, Google Contacts app: open Google Contacts → tap your profile picture → Contacts app settings → Default account for new contacts → choose your personal hub account.
- Default account for new contacts, Samsung Contacts app: open Samsung Contacts → the three-line menu → Manage contacts → Set default storage location → choose your personal hub account.
- Calendar default — the honest answer: stock Google Calendar does not have one reliable cross-account default the way iOS does. Each Google account can have its own default calendar for events created while that account is selected (in the app, tap the menu → your account email → Default calendar), but when a phone has several different accounts configured — a personal Google account plus a separate Microsoft/Exchange account — which one a brand-new event actually lands on tends to follow whichever calendar you last viewed or created an event in, not a fixed setting. This is a long-standing, widely reported source of confusion (Google's own feature-request tracker has an open request for a real cross-account default), not something you're doing wrong.
This is exactly the gap the Outlook app closes: Outlook applies one default-calendar setting across every account it manages, sidestepping the account-switching ambiguity that stock Google Calendar has on Android. It's the single most concrete reason to prefer Outlook over stock Google apps on an Android device carrying both a business tenant and a personal hub.
The Microsoft 365 matrix that actually matters
Setting the marketing names aside, here's what each tier actually buys you, for the features an executive notices.
| What you get | Business Basic | Business Standard | Business Premium |
|---|---|---|---|
| Outlook on the web & mobile app | Yes | Yes | Yes |
| Desktop versions of Word / Excel / PowerPoint / Outlook | No — web only | Yes | Yes |
| Self-service password reset (SSPR) | Yes | Yes | Yes |
| Conditional Access (the policies in the admin bonus chapter) | No — needs Entra ID P1 | No — needs Entra ID P1 | Yes, included |
| Device compliance / Intune management | No | No | Yes |
| Advanced phishing & malware protection | Basic only | Basic only | Yes (Defender) |
Do it in this order
Each step assumes the ones before it are done. You marks something the executive does; Admin marks something that needs an IT admin with tenant access.
Saved privately in your browser only — nothing is sent to us, and it won't follow you to a different device or browser.
-
Create the break-glass account(s) Admin
Every business tenant needs one account that exists purely to get you back in if everything else locks you out — never assigned to a person, never used day-to-day, excluded from every Conditional Access policy.
Naming convention: bg-emergency-1@<tenant>.onmicrosoft.com — use the tenant's built-in
.onmicrosoft.comdomain, not your custom domain. If your custom domain's federation or DNS ever breaks, the onmicrosoft.com address still works; that's the one scenario this account exists for.- 32+ character random password, stored split across two places only a company officer can reach (not in a password manager tied to your daily-use MFA — multi-factor authentication, the extra code or app-tap you provide beyond your password).
- Excluded from every Conditional Access policy, including MFA — that's the point of the account.
- Set an alert rule: any sign-in, password change, or role change on this account should page someone immediately. It should never fire.
-
Create your named admin account Admin
A second account, tied to you specifically, used only for tenant-admin tasks — never for reading mail, never for Teams chat.
Naming convention: adm-jamie@northlinemetal.com (prefix + first name). Give it Global Admin (the highest level of administrative access in a Microsoft 365 tenant) or a scoped admin role, and nothing else lives in its mailbox.
When to use it: only when you're in the Microsoft Entra admin center or Microsoft 365 admin center making a change. Sign out of it the rest of the day. If you find yourself signed into
adm-to read email, that's the tell that daily-driver and admin have blurred together again. -
Set up your daily-driver account YouAdmin
Naming convention: jamie@northlinemetal.com — the address people actually email. This is the one your business colleagues know, and the one added to your devices as an ordinary user account, no admin rights attached.
On the phone specifically: install the Microsoft Outlook app (iPhone and Android both) and add every business tenant plus your personal hub to it, rather than spreading them across native Mail, native Calendar, and a separate Gmail app. Chapter 5 covers Outlook's own default-account settings once everything's added.
-
Forward legacy personal mail, and tag it as it lands You
In Yahoo/AOL (and an old Gmail, if you're retiring one) settings, turn on mail forwarding to your personal hub, and leave a copy on the old account for a few weeks rather than deleting on send — just in case. Full step-by-step for each provider is in Chapters 4 and 11.
In your hub, create a rule/filter per legacy source that catches mail still addressed to an old address and files it into its own category or folder — e.g. Legacy · Yahoo, Legacy · Old Gmail — because the original "To" address is preserved even after a forward. That label is how you'll spot, a year from now, exactly who still has an old address on file.
Migrate or leave it — a rule of thumb: don't bother chasing down every sender. Leave low-stakes senders on the old forwarding address forever — newsletters, random retail accounts, anything spammy or low-consequence. Actively go update the sender-of-record for anything that matters — utility bills, rent or mortgage, insurance, banking, anything where a missed or delayed message causes real problems. Those should point at your new address directly, not stay dependent on a forwarding rule that could silently break.
-
Use plus-addressing and aliases so mail sorts itself You
Both Gmail and Microsoft personal accounts treat jamie.castell+bank@gmail.com (or jamie.castell+bank@outlook.com) as the same inbox as the plain address — mail still arrives, but you can filter on the
+banktag to auto-label or auto-file it. Hand out a tagged variant any time you're giving your address to a new company, a newsletter, or a one-off signup, and you'll always know exactly who leaked it if it starts getting spam.A worked example: give your electric utility jamie.castell+billing@outlook.com instead of your plain address. Build one rule: if sender is the utility and subject matches "your bill is ready" or "payment successful," route it straight to a Bills — OK folder and mark it read. Anything from that same sender that doesn't match — a failed payment, an account issue, an error notice — falls through to your real inbox instead of getting buried with the routine stuff.
On the Microsoft business side, your admin can add true aliases (proxy addresses) to your business mailbox — e.g. jamie.castell@northlinemetal.com as an alias of jamie@northlinemetal.com — so old business cards and typo'd addresses still land in one place.
-
Build mail rules in the browser, not the desktop app YouAdmin
Create Outlook rules at outlook.office.com (OWA — Outlook on the web), not inside the Outlook desktop app. Rules made in OWA run on Microsoft's servers and keep working even when your laptop is closed; several common rule types made in the desktop client are flagged "client-only" and silently stop working the moment Outlook isn't open. Same logic applies as a tenant admin setting mail-flow rules — do it from the admin center, not a local client.
Pay attention This is the single most common reason a "working" mail rule mysteriously stops sorting mail three weeks later. If a rule needs to survive your laptop being off, it has to be built where Microsoft — not your PC — runs it. -
Confirm business tenants don't forward, and don't accept forwards Admin
Two checks per tenant, both in the Exchange admin center:
- No mailbox in this tenant has auto-forwarding set to an external address (check Mail flow rules and each mailbox's own forwarding setting).
- No mail-flow rule accepts and silently redistributes mail forwarded in from an external personal account.
If Northline Metal Works and Vantage Public Affairs are two different companies you're both involved in, this is what keeps them from quietly becoming one company's data sitting inside the other's mailbox.
-
Decommission the setup account Admin
Whatever account did the actual buildout — a temporary admin login, a vendor's service account, your own
adm-account if it was over-scoped for the day — get its permissions back down to normal, or disable it outright if it was only ever meant to exist for this project. -
Verify, end to end You
Send a test email through every path: old Yahoo address → confirm it lands labeled in your hub; each business address → confirm it lands in its own account, not the hub. Sign in on both devices and count your MFA prompts for one normal day — if it's more than one or two, something upstream is misconfigured, not "just how it is."
If you're standing up a brand-new Microsoft 365 tenant
Sometimes the second (or third) company in this guide doesn't exist yet as a tenant — you're creating it. Do these before anything else touches it, in this order.
-
Name it like it's permanent Admin
The tenant name and default
.onmicrosoft.comdomain are annoying to change later. Use the real company name, not a placeholder or a project codename — the break-glass account in the next step is going to live on this domain forever. -
Set up the break-glass account first Admin
Before you touch licensing, before you add a single user — create the break-glass account exactly as described in Chapter 7, step 1. Everything else in this list depends on having a way back in if you lock yourself out while setting the rest of it up.
-
Global Admin password + MFA, immediately Admin
Strong, unique, generated password on the Global Admin account, MFA registered before you do anything else with it — sign in and register at mysignins.microsoft.com/security-info → Add sign-in method. Enable Self-service password reset (SSPR) for the tenant while you're in there — it's one setting and it prevents a large share of future lockout tickets.
-
Turn on a baseline day one Admin
New tenants get Security Defaults enabled automatically in most cases — leave it on until you're ready to replace it with real Conditional Access policies (see the admin bonus chapter). Don't end up in the gap where Security Defaults gets turned off "to test something" and nothing takes its place.
-
Review default sharing settings Admin
SharePoint/OneDrive external sharing and Teams external access both ship with defaults that are looser than most companies want. Check both before real data lands in the tenant, not after.
Reference: Microsoft Entra admin center · What is Microsoft Entra ID? →
Pick your meeting tool per audience, not by habit
Teams works fine inside one tenant. Across two companies, it stops being simple fast — and there's a cleaner option available.
Teams across multiple tenants: the Teams client supports guest access and lets you switch between organizations you belong to, but the reality on a shared device is an org switcher — a little tenant picker you'll click every time a notification from the "wrong" company shows up while you're in the other one's Teams. Chats, channels, and presence don't blend across tenants; you're really running two separate Teams experiences that happen to share an icon. On a device already juggling two companies, that's real notification overload, not a minor annoyance.
Zoom as the neutral option: for any meeting that includes people from both companies, or an external party who isn't in either tenant, Zoom (or simply the calendar on your personal hub) sidesteps the tenant-switching problem entirely — nobody has to pick an org, nobody needs a guest invite accepted in advance. Recommend Zoom as the default for cross-company and external meetings, and reserve native Teams calls for meetings that stay inside a single tenant.
If the two companies need to share files or channels
Most people using this guide keep their two tenants firmly separate. But if Northline Metal Works and Vantage Public Affairs genuinely work together enough to want shared files or a shared Teams channel, here's what that setup actually involves — grounded in how Microsoft's cross-tenant collaboration really works, not marketing language.
| Mechanism | What it is | Requires |
|---|---|---|
| B2B collaboration | Invite-based guest accounts. Simplest option, works with almost any identity provider on the other side, no special licensing relationship between the tenants. | Just an invite, accepted once per guest. |
| B2B direct connect | Mutual trust configured between two Entra organizations directly — no guest account created at all. This is what powers Teams Connect shared channels, where a channel appears natively inside both companies' Teams. | Entra ID P1 in both tenants, plus cross-tenant access settings configured on both sides. |
| Teams shared channels | Shared channels themselves are on by default in Teams — but external (cross-tenant) collaboration on a shared channel is off by default, even though the feature exists. | A Teams admin center policy change, plus Entra cross-tenant access settings on both organizations. Changes can take up to 6 hours to propagate before they take effect. |
In practice: if you just need to send someone at the other company a file occasionally, a normal B2B guest invite is enough — nobody needs to touch tenant-wide settings. If you want an actual shared channel that feels native on both sides, budget for a real conversation between both companies' admins, Entra ID P1 in both tenants, and a same-day-but-not-instant rollout once the settings are changed.
Admin references: Entra admin center (cross-tenant access settings) · Teams admin center (external access & shared channel policies).
Actually forwarding Yahoo and AOL, step by step
Chapter 7 told you to forward your legacy mail. Here's exactly where to click, provider by provider — the mockups below are illustrative; exact layout may vary as providers update their settings pages.
Yahoo Mail
- Settings gear → More settings → Mailboxes → pick the mailbox → Forwarding → enter address → verify the confirmation code → save.
- Sign in at mail.yahoo.com and click the Settings (gear) icon, then More settings.
- Open Mailboxes and click the mailbox you want to forward.
- Find the Forwarding section and toggle it on.
- Enter your forwarding address — your new hub, e.g. jamie.castell@yourdomain.com (or your Gmail, if that's your simpler-fallback hub).
- Yahoo emails a confirmation code to that forwarding address. Open that email, copy the code.
- Paste the confirmation code back into Yahoo to verify the forward.
- Choose whether to keep a copy of forwarded messages in the Yahoo mailbox or not — keeping a copy for the first few weeks is a reasonable safety net.
Yahoo help: help.yahoo.com/kb/SLN3618.html →
AOL Mail
- Settings gear → More Settings → Forwarding → toggle on → enter address → click the verification link AOL emails you → choose keep-copy or not.
- Sign in at mail.aol.com and click the Settings (gear) icon, then More Settings.
- Choose Forwarding from the settings list.
- Toggle forwarding on and enter your forwarding address.
- AOL sends a confirmation email to the new address — open it and click the verification link.
- Choose whether to keep a copy of forwarded mail in AOL Mail, or not.
AOL help: help.aol.com/articles/aol-mail-set-up-mail-forwarding →
Forwarding from anywhere else
Every provider we haven't named follows roughly the same pattern, and it's easy to find your way there:
- Look for a gear icon or "Settings" — usually top-right of the inbox.
- If the settings page has a search box, just type "Forwarding" into it.
- Most providers require you to verify the destination address — a confirmation code or a click-through link — before the forward actually activates. Don't skip this step; forwarding silently won't work until it's done.
- Most also let you choose whether to keep a copy in the original inbox. Keeping a copy for a transition period is usually the safer default.
Outlook.com and Gmail forwarding walkthroughs are in Chapter 4. Gmail's own filter settings (for the receiving-side rules described in Chapter 7): mail.google.com → Settings → See all settings → Filters and Blocked Addresses.
Optional side quest: a full contacts reset and consolidation Optional
Not required for the base build — but once mail from everywhere is flowing into one hub, you'll usually find you've accumulated duplicate and scattered contacts across every account you're consolidating: personal Gmail, each business tenant, old Yahoo/AOL if you ever kept contacts there, plus whatever's stuck locally on the phone itself. The clean fix isn't a merge tool — it's a full export, dedupe, and reset onto exactly one authoritative store. Budget an hour; do it once and you won't need to again.
-
Export every source to CSV first. Do this from each account that currently holds contacts: personal Gmail, each business tenant, Yahoo/AOL if applicable, and the phone's local contacts. Nothing gets deleted yet — this step is purely capture.
- Google Contacts: contacts.google.com → select all (or the contacts you want) → Export in the left menu → choose Google CSV (moving between Google accounts) or Outlook CSV (for Excel or another app) → Export. Downloads immediately.
- Outlook on the web / new Outlook for Windows: People → Export contacts in the ribbon → under "Contacts from this folder" pick the folder → Export. Saves to Downloads; UTF-8 encoding is recommended.
- Classic Outlook desktop (and how to get a native PST backup at the same time): File → Open & Export → Import/Export → Export to a file → Next → Comma Separated Values → Next → select the Contacts folder → Next → Browse, name the file, OK → Next → Finish. If you already keep a PST backup from Outlook desktop, its Contacts folder can be exported straight to CSV this same way — no separate conversion tool needed.
- Combine all the CSVs into one file. Open them all in a spreadsheet (Excel or Google Sheets), stack every source's rows into one sheet, and keep only a consistent set of columns — name, email(s), phone(s), company. A ragged mix of columns is what makes the next step painful, so straighten this out first.
-
Merge the duplicates. Three ways to get through this fast rather than by hand:
- Sort the combined sheet by email address or by full name first — duplicates land next to each other and are easy to spot and delete manually.
- Or skip manual spreadsheet dedup entirely: import the combined CSV into Google Contacts and run Merge & fix (menu icon, top-left → Merge & fix → review suggestions → Merge or Merge all), or import into Outlook and use its automatic duplicate suggestions after import.
- Simple rule of thumb either way: same email address = same person, even when the name is formatted differently ("J. Smith" vs. "Jane Smith, Northline Metal Works").
- Back up natively before deleting anything. Take one native-format backup in addition to the CSV — a PST export from Outlook desktop is the standard "native backup" most business people will recognize (same Import/Export wizard as step 1, choosing Outlook Data File (.pst) instead of CSV, for the whole mailbox or just Contacts). This is the safety net: an imperfect cleanup below is fine, because a real backup exists to fall back on.
-
Remove all contacts from every device and cloud account. This is the actual reset — delete the contacts stored locally on the phone, and delete them from every cloud contacts store they came from (personal Gmail, each business tenant, etc.), so nothing stale re-syncs back in later.
- Google Contacts: check the box next to any contact → the dropdown arrow at top-left → All (selects everything) → More (top right) → Delete → Move to trash. Deleted contacts sit in Trash for 30 days before permanent deletion — a second safety net on top of the PST/CSV backup.
- Outlook.com (web): People → All contacts in the left pane → select contacts (Shift+click for ranges) → Delete → confirm. The web version caps bulk delete at 50 contacts at a time, so a large list takes a few passes — don't be surprised when it doesn't clear everything in one go. Classic desktop Outlook can Ctrl+A the whole list and delete it in a single action, which is faster if you have it installed.
- Phone-local contacts (iPhone/Android): delete the on-device contact group from your phone's Contacts app settings — exact wording and location vary by phone and OS version, so check your specific device's current menu rather than following a fixed path here.
- Upload the cleaned, merged list into the one contacts store that becomes authoritative going forward — whichever you chose as your personal daily-driver hub in Chapter 4. Outlook (personal Microsoft account) if that's your hub: People → Import contacts in the ribbon → Browse → select the CSV → Open → Import. Google Contacts if Google is your hub: Import in the left menu → choose the CSV → confirm. Google maps the header row to its fields automatically and drops the import into a labeled group so you can review it before it joins your main list.
- From here forward, work from the cloud/web version of mail and contacts, not a local device cache. The whole point of the reset is that the phone just displays what's synced from the cloud account — it isn't a separate store that can quietly drift out of sync again.
Worth the $25–60
A hardware security key (YubiKey or equivalent) is the single cheapest security upgrade in this entire guide, and it removes MFA prompts more than it adds them — a tap replaces typing a code.
| Model | Connector | Typical price | Good for |
|---|---|---|---|
| YubiKey 5C NFC | USB-C + NFC (tap on phone) | ~$55 flat | Modern laptop + phone, one key for both |
| YubiKey 5 NFC | USB-A + NFC | ~$50 flat | Older laptop with USB-A ports |
| Security Key NFC (Yubico) | USB-A/C + NFC | ~$25–29 flat | Budget option, FIDO2/passkeys only — fine for most executives |
Admin setup guide: Enable passwordless security key sign-in in Microsoft Entra ID →
Once your admin confirms it's enabled, your own part is quick: sign in at mysignins.microsoft.com/security-info → Add sign-in method → Security key → follow the on-screen prompt to tap or insert your key. That's the "2 min for you" step above.
Conditional Access, for the person supporting this arrangement
Everything above makes the executive's life easier. This part is what keeps you — the admin — from being the one who explains a breach to the board. Microsoft already turns on a baseline for you; this is what to layer on top, and the one real decision that changes everything downstream.
The one decision that matters
Before setting a single toggle, answer this for the tenant you administer: if this executive's personal device is compromised, are you willing to accept that your company's mail could be exposed to whatever else lives on it? Your answer picks a column below.
| Policy area | If you're OK with cross-company exposure on this device | If you want hard isolation | Watch for |
|---|---|---|---|
| Device compliance / join requirement | Don't require a compliant or hybrid-joined device for this user — allow any device, gated by MFA instead. | Require the device to be Intune-compliant or Entra-joined to this tenant — which conflicts directly with a shared, multi-tenant device. Pick this and the executive will get device-join prompts you didn't intend. | Grant control: "Require device to be marked as compliant" |
| Sign-in frequency | Standard (Microsoft default, roughly balances security and re-prompting). | Shorter re-authentication window (e.g. every 4–8 hours) so a stolen session token expires fast. | Session > Sign-in frequency |
| Persistent browser session | Allow — fewer prompts on a device only this person uses. | Never persist — force a fresh sign-in every browser session. | Session > Persistent browser session |
| App-enforced restrictions (unmanaged device) | Allow full Outlook/OWA functionality. | Block download, print, and sync to an unmanaged device — mail is view-only in the browser. | Session > Use app enforced restrictions |
| MFA strength | Any MFA method (Authenticator app push is fine). | Require phishing-resistant MFA specifically (FIDO2 key or certificate-based) — see Chapter 12's YubiKey section. | Grant control: "Require authentication strength" |
| Legacy authentication | Block regardless — there's no version of this arrangement where legacy auth (IMAP/POP/SMTP-basic) should be allowed. Over 99% of password-spray attacks use it. | Block regardless. | Usually already covered by Microsoft's managed baseline policy |
Naming and structure we'd suggest for your own sanity
- One Conditional Access policy per control, not one giant policy — CA01-Block-LegacyAuth, CA02-MFA-AllUsers, CA03-MFA-Admins-PhishResistant. Easier to report-only test and roll back individually.
- Always exclude your two break-glass accounts from every custom policy — the same way you'd exclude them from a Microsoft-managed one.
- Run every new policy in Report-only for at least a week before enforcing it. This is the cheapest insurance in the whole playbook.
Adding a second admin
For business continuity, any brand-new Microsoft 365 tenant should have a second Global Admin outside the primary user — someone who can get in if the first admin is unreachable. Rather than assigning the Global Admin role directly to an individual account, we'd recommend creating a role-assignable security group (e.g. Tenant Admins) instead, then assigning the Global Admin role to the group and adding actual admin accounts as members. It's easier to audit and easier to revoke than a role sitting on one person's account, and it means removing an admin is a group-membership change, not a role reassignment under pressure.
- Requires Entra ID P1 or P2.
- Created in Entra admin center → Groups → New Group, with Microsoft Entra roles can be assigned to the group set to Yes — this option can only be set at group creation, not added later.
- Assign the Global Admin role to the group itself, then manage membership instead of managing role assignments.
If you'd rather have someone else formally manage the tenant, Gravity Limited can take that on directly. We're still building out a formal client-management process, so for now that's either a direct email or a quick call — whichever's easier for you.
Quick answers
Can I just use my business Microsoft account for everything?
No — the moment a business tenant becomes your contacts/calendar hub, personal data starts living inside a company's Microsoft 365 tenant, which the company can see, export, and legally hold. Keep the hub personal.
What if I'm on three or more business tenants, not two?
Nothing here changes — repeat steps 1–3 of the build order per tenant, and use the calculator in Chapter 3 with your real tenant count.
Does this work if I own the device myself, versus if a company issued it?
Yes to both. On a company-issued device, that company's admin may have more say over device-level policy (the admin bonus chapter's "hard isolation" column becomes more likely for that one tenant specifically) — the account-level steps in Chapter 7 don't change either way.
My old Yahoo/AOL address still gets important mail years later — is that normal?
Very. That's exactly what the Legacy label in Chapter 7 is for — check it occasionally, and update anyone still using the old address directly rather than relying on the forward forever.