Free guide · Executives & the admins who support them

The Unification Project

You run more than one email address, and probably more than one company. Here is how to put all of it on your laptop and your phone — safely, and in a way your IT admin can stand behind.

2Devices, one identity
<1 dayTypical build time
2 tracksExec + Admin
00 Foreword

This isn't textbook best practice. It's the best version of your practice.

Best practice says don't do this at all. One identity, one device, keep personal and business fully separate — every company, kept on its own hardware, never touching your own inbox. That's the textbook answer, and it's correct.

Most executives can't live that way, and that's not a discipline problem. You own more than one company, or you sit on more than one board, or you have a life outside the P&L — and you check all of it from the same phone. Once you're senior enough, "just don't do that" stops being a real option. This guide starts from that reality instead of arguing with it.

So here is the secure way to blend personal and multiple companies on one laptop and one phone: as safe as the situation allows, as easy for your IT admin to support as we can make it, and as close to real best practice as possible. Every choice below is the most secure, most supportable version of an arrangement that will never be perfectly clean — built so your admin can sleep, and so you don't have to think about any of it again after the first afternoon.

Read this before you build anything One rule survives every version of this guide: business mailboxes never forward mail out, and never accept a forward in. Everything else here is about making two or three Microsoft tenants — Microsoft's term for a separate, self-contained business account, one per company — and one personal life share a device peacefully. That one rule is what keeps them from also sharing their mail.
01 Is this you?

The shape of the problem

This guide is for exactly one situation. If it doesn't describe you, most of it still applies — just skip what doesn't.

  • You have a personal email address (Gmail, Yahoo, AOL, or your own domain) that's been yours for years and isn't going anywhere.
  • You have one or two Microsoft 365 business accounts — your own company, a company you invested in, a board seat, a family business — and they're run by different IT admins who don't talk to each other.
  • You want to check all of it from one laptop and one phone, without three different sign-in prompts fighting for your attention every time you tap the mail icon.
  • You are willing to accept that this device will never be as clean as a single-purpose company laptop — in exchange for it being usable.
02 The shape of the fix

One hub. Everything else layers underneath it.

The whole guide is one idea, applied consistently: pick a single personal identity as your contacts-and-calendar hub, then add every business mailbox to your devices as a guest — never as the owner, and never with a return path back out.

Diagram: personal hub in the center, two business tenants and legacy personal mail feeding in one-way, laptop and phone layered on top, nothing feeding back out Personal hub contacts + calendar Legacy personal Yahoo / AOL — retiring Northline Metal Works daily driver, device-joined, no forward Vantage Public Affairs app-only, no device join, no forward Laptop + phone both devices, layered on top

Solid arrow = mail actually forwards this direction. Dashed line = mail is added as an account, never forwarded — the tenant keeps its own mailbox and nothing leaves it.

03 Estimate your time

How long this actually takes

Answer a few questions about your actual setup. This is the same estimate we quote clients for the exact same build — adjusted up if you're doing it yourself instead of handing it to an admin. Your answers are remembered if you come back.

1
Laptops
1
Phones
1
Yahoo
1
AOL
0
Old Gmail
0
Everything else
0
Adding a hardware keyYubiKey or similar, per device owner
Doing this yourselfOff = your IT admin does it
Estimated time
hrs
If an admin does it
If you DIY
Rough guide, not a quote. Two tenants with prior conditional-access lockouts, forgotten admin passwords, or a company that's merged/renamed recently will run longer — see the Foreword.
04 Choose your personal hub

Where your contacts and calendar actually live

Every business account you add gets layered underneath this one identity. Get this choice right and everything downstream gets easier.

The standard — we recommend this

Custom domain via Microsoft 365 Business Basic

A single self-administered, one-person Microsoft 365 tenant — roughly $6–8.40/user/month depending on billing. Yes, it's technically a tiny business tenant, but you're the only person in it and you administer it yourself. This is how you get a real custom domain through Microsoft without an MSP, now that Microsoft's old personal-tier custom-domain option is gone (see below). It is also the only hub an outside IT provider — ours or anyone's — can genuinely support.

  • Self-service, no MSP or IT department needed
  • A real custom domain address you control
  • Outlook.com-grade rules engine, same server-side reliability taught in Chapter 7
  • Supportable: GDAP and standard admin access work exactly as described in this guide
Supportable, but slower

Own domain via Cloudflare + Google Workspace

Register a domain through Cloudflare (~$10–15/yr), route it to a Google account. For people who want to stay in Google's ecosystem for their own custom domain. Workspace has an admin console, so delegated support is possible — just expect any admin task to take longer than the Microsoft equivalent.

  • Cloudflare Email Routing forwards it for free — no separate mail hosting bill
  • Survives you leaving Google entirely later — the domain moves with you

Doesn't have to catch everything — in the Cloudflare dashboard's Email Routing rule you can exclude specific senders or domains if you want a few things to stay on the old address.

Not recommended — largely unsupportable

Free personal Gmail

Listed because so many readers already have one, not because it's a good hub. A free consumer Gmail has no admin or delegation mechanism at all, so nobody outside can ever act on your behalf — not us, not your own IT. It works only for a reader who will never want help with this setup.

  • Zero cost, zero setup — and zero support path
  • If you keep it, plan to do every step in this guide yourself, forever
Watch for this one Microsoft's consumer plans — Microsoft 365 Personal and Family — don't support adding a custom domain. If you want a custom domain through Microsoft without an MSP, Business Basic (above) is the real path.
Pay attention The recommended default recipient for forwarded mail is your Business Basic custom domain mailbox — that's what "a personal Microsoft account" means throughout this guide — despite being more setup work than Gmail. Two reasons: its rules and categories mirror what you already use for work, and its web-based rules are server-side and survive your laptop being off, exactly like the OWA rule-reliability behavior taught in Chapter 7. A free consumer account at outlook.com or live.com is not what we mean by this and isn't something we recommend setting up new — it's a real mailbox on Microsoft's shared consumer service, not a tenant you administer, so there's no real way for anyone to help manage it later if you ever want that. Free Gmail is not a recommended hub. It is workable only for a reader who will never want outside help with this setup; for everyone else it is largely unsupportable, for the reasons above.
Security: comparableEffort: Microsoft costs more setup time

Out options (retiring these as active inboxes): Yahoo, AOL, and optionally an old Gmail or Hotmail/Outlook.com/Live account. In option (the hub itself): your Business Basic custom domain (the standard), or — not recommended — a Gmail you already own — never a free consumer Microsoft account, and never a business tenant. Business mailboxes are never a valid forwarding target, in either direction — see the confirmation step in Chapter 7.

Before you follow these literally Providers change their settings screens over time. If a detailed step below doesn't match what's on your screen, fall back to the high-level version — look for a gear icon and, if the settings page has one, a search box you can type "Forwarding" or "Domains" into.

Setting up a custom domain via Microsoft 365 Business Basic

  • Sign up for Business Basic at microsoft.com.
  • In the Microsoft 365 admin center, go to Settings → Domains → Add domain.
  • Run the verification wizard (one-click via Domain Connect on supported registrars like GoDaddy, or manual TXT/MX records otherwise).
  1. Sign up at microsoft.com/microsoft-365/business/microsoft-365-business-basic — this creates your own one-person tenant.
  2. Sign in to the Microsoft 365 admin center and go to Settings → Domains → Add domain.
  3. Enter the domain you already own (or register one first through any registrar).
  4. If your registrar is a Domain Connect partner (GoDaddy and several others), the wizard verifies and configures DNS in close to one click. Otherwise, you'll add a few technical domain-ownership records manually — a TXT record to prove you own the domain, then MX and CNAME records to point mail at Microsoft. If those terms are unfamiliar, your domain registrar's own support chat can usually paste these in for you — this one step is also easy to hand to any IT-savvy contact.
  5. Once verified, create your mailbox on the new domain (e.g. jamie.castell@yourdomain.com) and set it as your primary address.

Source: learn.microsoft.com — Add a domain →

admin.microsoft.com/Adminportal/Home#/Domains
Domainyourdomain.com
Domain Connect (GoDaddy, etc.)AVAILABLE
Verification statusVERIFIED
What you'll roughly see under Settings → Domains — exact layout may vary.

Retiring an old Outlook.com, Live, or Hotmail account

If you've had a free outlook.com, live.com, or hotmail.com account for years and want to fold it into your new hub, forward it the same way you would Yahoo or AOL below — this isn't the recommended hub itself, just how you retire one of these as an active inbox.

  • Settings gear → Mail → Forwarding → enable, enter the forwarding address, save.
  1. Sign in at outlook.com and click the Settings (gear) icon.
  2. Go to Mail → Forwarding.
  3. Toggle Enable forwarding on.
  4. Enter the forwarding address you want mail routed to — your Business Basic custom domain mailbox, or Gmail.
  5. Optionally check Keep a copy of forwarded messages in this mailbox.
  6. Click Save.

If two-step verification isn't already on for this Microsoft account, turning on forwarding will prompt you to enable it — that's expected, not an error.

outlook.live.com/mail/options/mail/forwarding
Enable forwardingON
Forward tojamie.castell@yourdomain.com
Keep a copy of forwarded messagesOFF
What you'll roughly see under Settings → Mail → Forwarding — exact layout may vary.

Gmail forwarding (if retiring an old Gmail as legacy)

  • Settings gear → See all settings → Forwarding and POP/IMAP → Add a forwarding address → verify the confirmation link → come back and turn it on.
  1. Click the Settings (gear) icon in Gmail, then See all settings.
  2. Open the Forwarding and POP/IMAP tab.
  3. Click Add a forwarding address, enter the address, then Next → Proceed → OK.
  4. Gmail emails a confirmation link to the new address — open it and click the link.
  5. Back in Gmail Settings, refresh the page and revisit Forwarding and POP/IMAP.
  6. Select Forward a copy of incoming mail to [address] and choose what happens to Gmail's own copy.
  7. Click Save Changes.

Want partial forwarding instead of everything? Disable the blanket auto-forward above, then use Show search options to build filter criteria, click Create filter, check Forward it, pick the address, and click Create filter again.

Source: support.google.com/mail/answer/10957 →

05 Contacts & calendar defaults

Contacts stay personal. Calendar doesn't.

These two get confused constantly, and the right default is different for each one — so treat them as two separate decisions, not one.

Contacts: unchanged from Chapter 4 — your personal hub (your Business Basic custom domain, or Gmail) stays the seamless primary contacts store on both devices. Every business colleague, vendor, and old Yahoo-era connection ends up findable from one address book, because it's the one identity that isn't tied to a company that could revoke your access to it.

Calendar: a different default. On the laptop, set the default calendar to whichever business calendar you actually live in day to day — for most people that's the daily-driver tenant (Northline Metal Works in our running example), not the personal hub. New events you create without thinking about it should land as business meetings, because that's what most of your day actually is. We'd recommend the same business-default on the phone — but the phone is also where you'll want to manually pick your personal calendar per-appointment for the kid's recital or your own doctor's visit, rather than have it default there.

Pay attention Some people will instead want their phone's default calendar to be personal, flipping the recommendation above. That's a perfectly reasonable choice — but it splits the experience at the device level: you now have to actively think about which calendar you're in on each device, instead of one consistent default everywhere. Make the choice deliberately, not by accident.
User impact: your callEffort: 2 min per device
One app, one look, on both platforms Our default recommendation for the phone itself: install the Microsoft Outlook app — on iPhone and on Android — and run mail, calendar, and contacts for everything through it, including your personal hub. Outlook's mobile app supports adding Gmail and other personal accounts right alongside your Microsoft ones, so instead of juggling native Mail, native Calendar, native Contacts, and a separate Gmail app, you get one consistent app and one consistent look across every account, on both iPhone and Android. We still cover the native OS-level settings below, because some readers won't use Outlook mobile — but Outlook is the lead recommendation.

Setting the actual defaults: iPhone and Android

General framing is easy; the actual OS settings are buried and differ completely by platform. Here's exactly where to go on each.

If you use the Outlook app (recommended)

Outlook's own Settings → Calendar → Default Calendar picks which calendar new events land on when you create one without explicitly choosing — set it to your business calendar, matching the recommendation above. For contacts, Outlook syncs per account rather than through one global default: on iPhone, go to Settings → [account] → Save Contacts and choose to save to your iPhone for your personal hub account; on Android, it's Settings → Accounts → [account] → Sync Contacts. Turn this on only for your personal hub account so new contacts consistently land in the one address book from Chapter 4, not scattered across whichever account you happened to be in.

Outlook's own default-calendar control has moved between app versions before, especially on Android — if Settings → Calendar → Default Calendar isn't where you expect it, the reliable fallback is the same trick as the native-Android workaround below: only enable Calendar sync for the account you want new events to land on.

iPhone (native Mail/Calendar/Contacts)

  • Contacts default: Settings → Apps → Contacts → Default Account — set to your personal hub account. This option only appears once more than one account has Contacts turned on; with just one account there's nothing to choose.
  • Calendar default: Settings → Apps → Calendar → Default Calendar — set to your business calendar, per the recommendation above. Same override-per-event behavior applies: the default only decides what happens when you don't pick one.
  • On older iOS versions, these same settings live directly under Settings → Contacts and Settings → Calendar, without the "Apps" step — Apple moved per-app settings under Settings → Apps starting with iOS 18.

Android (native Google/Samsung apps — messier, be aware)

Android doesn't have one clean equivalent to iOS's toggles, and what you do depends on which apps you're actually using:

  • Default account for new contacts, Google Contacts app: open Google Contacts → tap your profile picture → Contacts app settingsDefault account for new contacts → choose your personal hub account.
  • Default account for new contacts, Samsung Contacts app: open Samsung Contacts → the three-line menu → Manage contactsSet default storage location → choose your personal hub account.
  • Calendar default — the honest answer: stock Google Calendar does not have one reliable cross-account default the way iOS does. Each Google account can have its own default calendar for events created while that account is selected (in the app, tap the menu → your account email → Default calendar), but when a phone has several different accounts configured — a personal Google account plus a separate Microsoft/Exchange account — which one a brand-new event actually lands on tends to follow whichever calendar you last viewed or created an event in, not a fixed setting. This is a long-standing, widely reported source of confusion (Google's own feature-request tracker has an open request for a real cross-account default), not something you're doing wrong.

This is exactly the gap the Outlook app closes: Outlook applies one default-calendar setting across every account it manages, sidestepping the account-switching ambiguity that stock Google Calendar has on Android. It's the single most concrete reason to prefer Outlook over stock Google apps on an Android device carrying both a business tenant and a personal hub.

User-facingEffort: 5 min per device
06 License what you need

The Microsoft 365 matrix that actually matters

Setting the marketing names aside, here's what each tier actually buys you, for the features an executive notices.

What you getBusiness BasicBusiness StandardBusiness Premium
Outlook on the web & mobile appYesYesYes
Desktop versions of Word / Excel / PowerPoint / OutlookNo — web onlyYesYes
Self-service password reset (SSPR)YesYesYes
Conditional Access (the policies in the admin bonus chapter)No — needs Entra ID P1No — needs Entra ID P1Yes, included
Device compliance / Intune managementNoNoYes
Advanced phishing & malware protectionBasic onlyBasic onlyYes (Defender)
Pay attention If your admin wants to use the Conditional Access playbook in the admin bonus chapter for your account specifically, you need at least Entra ID P1 (Microsoft's identity and access-management add-on — separate from your mailbox plan, and what unlocks Conditional Access) — bundled into Business Premium, or purchasable as an add-on to a cheaper plan. This is usually the single highest-leverage dollar you'll spend in this whole project.
Security: highEffort: none — it's a license, not a project
07 The build order

Do it in this order

Each step assumes the ones before it are done. You marks something the executive does; Admin marks something that needs an IT admin with tenant access.

Your progress 0 / 9 done

Saved privately in your browser only — nothing is sent to us, and it won't follow you to a different device or browser.

  1. Create the break-glass account(s) Admin

    Every business tenant needs one account that exists purely to get you back in if everything else locks you out — never assigned to a person, never used day-to-day, excluded from every Conditional Access policy.

    Naming convention: bg-emergency-1@<tenant>.onmicrosoft.com — use the tenant's built-in .onmicrosoft.com domain, not your custom domain. If your custom domain's federation or DNS ever breaks, the onmicrosoft.com address still works; that's the one scenario this account exists for.

    • 32+ character random password, stored split across two places only a company officer can reach (not in a password manager tied to your daily-use MFA — multi-factor authentication, the extra code or app-tap you provide beyond your password).
    • Excluded from every Conditional Access policy, including MFA — that's the point of the account.
    • Set an alert rule: any sign-in, password change, or role change on this account should page someone immediately. It should never fire.
    Security: criticalEffort: 15 min per tenant
  2. Create your named admin account Admin

    A second account, tied to you specifically, used only for tenant-admin tasks — never for reading mail, never for Teams chat.

    Naming convention: adm-jamie@northlinemetal.com (prefix + first name). Give it Global Admin (the highest level of administrative access in a Microsoft 365 tenant) or a scoped admin role, and nothing else lives in its mailbox.

    When to use it: only when you're in the Microsoft Entra admin center or Microsoft 365 admin center making a change. Sign out of it the rest of the day. If you find yourself signed into adm- to read email, that's the tell that daily-driver and admin have blurred together again.

    Security: highEffort: 10 min
  3. Set up your daily-driver account YouAdmin

    Naming convention: jamie@northlinemetal.com — the address people actually email. This is the one your business colleagues know, and the one added to your devices as an ordinary user account, no admin rights attached.

    On the phone specifically: install the Microsoft Outlook app (iPhone and Android both) and add every business tenant plus your personal hub to it, rather than spreading them across native Mail, native Calendar, and a separate Gmail app. Chapter 5 covers Outlook's own default-account settings once everything's added.

    User-facingEffort: 10 min
  4. Forward legacy personal mail, and tag it as it lands You

    In Yahoo/AOL (and an old Gmail, if you're retiring one) settings, turn on mail forwarding to your personal hub, and leave a copy on the old account for a few weeks rather than deleting on send — just in case. Full step-by-step for each provider is in Chapters 4 and 11.

    In your hub, create a rule/filter per legacy source that catches mail still addressed to an old address and files it into its own category or folder — e.g. Legacy · Yahoo, Legacy · Old Gmail — because the original "To" address is preserved even after a forward. That label is how you'll spot, a year from now, exactly who still has an old address on file.

    Migrate or leave it — a rule of thumb: don't bother chasing down every sender. Leave low-stakes senders on the old forwarding address forever — newsletters, random retail accounts, anything spammy or low-consequence. Actively go update the sender-of-record for anything that matters — utility bills, rent or mortgage, insurance, banking, anything where a missed or delayed message causes real problems. Those should point at your new address directly, not stay dependent on a forwarding rule that could silently break.

    User-facingEffort: 20 min
  5. Use plus-addressing and aliases so mail sorts itself You

    Both Gmail and Microsoft personal accounts treat jamie.castell+bank@gmail.com (or jamie.castell+bank@outlook.com) as the same inbox as the plain address — mail still arrives, but you can filter on the +bank tag to auto-label or auto-file it. Hand out a tagged variant any time you're giving your address to a new company, a newsletter, or a one-off signup, and you'll always know exactly who leaked it if it starts getting spam.

    A worked example: give your electric utility jamie.castell+billing@outlook.com instead of your plain address. Build one rule: if sender is the utility and subject matches "your bill is ready" or "payment successful," route it straight to a Bills — OK folder and mark it read. Anything from that same sender that doesn't match — a failed payment, an account issue, an error notice — falls through to your real inbox instead of getting buried with the routine stuff.

    On the Microsoft business side, your admin can add true aliases (proxy addresses) to your business mailbox — e.g. jamie.castell@northlinemetal.com as an alias of jamie@northlinemetal.com — so old business cards and typo'd addresses still land in one place.

    User-facingEffort: 5 min, ongoing habit
  6. Build mail rules in the browser, not the desktop app YouAdmin

    Create Outlook rules at outlook.office.com (OWA — Outlook on the web), not inside the Outlook desktop app. Rules made in OWA run on Microsoft's servers and keep working even when your laptop is closed; several common rule types made in the desktop client are flagged "client-only" and silently stop working the moment Outlook isn't open. Same logic applies as a tenant admin setting mail-flow rules — do it from the admin center, not a local client.

    Pay attention This is the single most common reason a "working" mail rule mysteriously stops sorting mail three weeks later. If a rule needs to survive your laptop being off, it has to be built where Microsoft — not your PC — runs it.
    ReliabilityEffort: same as any rule — just build it in the right place
  7. Confirm business tenants don't forward, and don't accept forwards Admin

    Two checks per tenant, both in the Exchange admin center:

    • No mailbox in this tenant has auto-forwarding set to an external address (check Mail flow rules and each mailbox's own forwarding setting).
    • No mail-flow rule accepts and silently redistributes mail forwarded in from an external personal account.

    If Northline Metal Works and Vantage Public Affairs are two different companies you're both involved in, this is what keeps them from quietly becoming one company's data sitting inside the other's mailbox.

    Security: criticalEffort: 10 min per tenant
  8. Decommission the setup account Admin

    Whatever account did the actual buildout — a temporary admin login, a vendor's service account, your own adm- account if it was over-scoped for the day — get its permissions back down to normal, or disable it outright if it was only ever meant to exist for this project.

    Security: highEffort: 5 min
  9. Verify, end to end You

    Send a test email through every path: old Yahoo address → confirm it lands labeled in your hub; each business address → confirm it lands in its own account, not the hub. Sign in on both devices and count your MFA prompts for one normal day — if it's more than one or two, something upstream is misconfigured, not "just how it is."

    User-facingEffort: 15 min
08 Secure your new tenant

If you're standing up a brand-new Microsoft 365 tenant

Sometimes the second (or third) company in this guide doesn't exist yet as a tenant — you're creating it. Do these before anything else touches it, in this order.

  1. Name it like it's permanent Admin

    The tenant name and default .onmicrosoft.com domain are annoying to change later. Use the real company name, not a placeholder or a project codename — the break-glass account in the next step is going to live on this domain forever.

  2. Set up the break-glass account first Admin

    Before you touch licensing, before you add a single user — create the break-glass account exactly as described in Chapter 7, step 1. Everything else in this list depends on having a way back in if you lock yourself out while setting the rest of it up.

  3. Global Admin password + MFA, immediately Admin

    Strong, unique, generated password on the Global Admin account, MFA registered before you do anything else with it — sign in and register at mysignins.microsoft.com/security-infoAdd sign-in method. Enable Self-service password reset (SSPR) for the tenant while you're in there — it's one setting and it prevents a large share of future lockout tickets.

  4. Turn on a baseline day one Admin

    New tenants get Security Defaults enabled automatically in most cases — leave it on until you're ready to replace it with real Conditional Access policies (see the admin bonus chapter). Don't end up in the gap where Security Defaults gets turned off "to test something" and nothing takes its place.

  5. Review default sharing settings Admin

    SharePoint/OneDrive external sharing and Teams external access both ship with defaults that are looser than most companies want. Check both before real data lands in the tenant, not after.

Reference: Microsoft Entra admin center · What is Microsoft Entra ID? →

09 Zoom, Teams & meetings

Pick your meeting tool per audience, not by habit

Teams works fine inside one tenant. Across two companies, it stops being simple fast — and there's a cleaner option available.

Teams across multiple tenants: the Teams client supports guest access and lets you switch between organizations you belong to, but the reality on a shared device is an org switcher — a little tenant picker you'll click every time a notification from the "wrong" company shows up while you're in the other one's Teams. Chats, channels, and presence don't blend across tenants; you're really running two separate Teams experiences that happen to share an icon. On a device already juggling two companies, that's real notification overload, not a minor annoyance.

Zoom as the neutral option: for any meeting that includes people from both companies, or an external party who isn't in either tenant, Zoom (or simply the calendar on your personal hub) sidesteps the tenant-switching problem entirely — nobody has to pick an org, nobody needs a guest invite accepted in advance. Recommend Zoom as the default for cross-company and external meetings, and reserve native Teams calls for meetings that stay inside a single tenant.

User impact: fewer notificationsEffort: a habit, not a setup task
10 When your companies work together

If the two companies need to share files or channels

Most people using this guide keep their two tenants firmly separate. But if Northline Metal Works and Vantage Public Affairs genuinely work together enough to want shared files or a shared Teams channel, here's what that setup actually involves — grounded in how Microsoft's cross-tenant collaboration really works, not marketing language.

MechanismWhat it isRequires
B2B collaboration Invite-based guest accounts. Simplest option, works with almost any identity provider on the other side, no special licensing relationship between the tenants. Just an invite, accepted once per guest.
B2B direct connect Mutual trust configured between two Entra organizations directly — no guest account created at all. This is what powers Teams Connect shared channels, where a channel appears natively inside both companies' Teams. Entra ID P1 in both tenants, plus cross-tenant access settings configured on both sides.
Teams shared channels Shared channels themselves are on by default in Teams — but external (cross-tenant) collaboration on a shared channel is off by default, even though the feature exists. A Teams admin center policy change, plus Entra cross-tenant access settings on both organizations. Changes can take up to 6 hours to propagate before they take effect.

In practice: if you just need to send someone at the other company a file occasionally, a normal B2B guest invite is enough — nobody needs to touch tenant-wide settings. If you want an actual shared channel that feels native on both sides, budget for a real conversation between both companies' admins, Entra ID P1 in both tenants, and a same-day-but-not-instant rollout once the settings are changed.

Admin references: Entra admin center (cross-tenant access settings) · Teams admin center (external access & shared channel policies).

11 Retiring your old inbox

Actually forwarding Yahoo and AOL, step by step

Chapter 7 told you to forward your legacy mail. Here's exactly where to click, provider by provider — the mockups below are illustrative; exact layout may vary as providers update their settings pages.

Before you follow these literally Providers change their settings screens over time. If a detailed step below doesn't match what's on your screen, the high-level version above it should still point you to the right settings page. Using a provider that isn't Yahoo or AOL? Skip straight to "Forwarding from anywhere else" below — it works for almost any provider.

Yahoo Mail

  • Settings gear → More settings → Mailboxes → pick the mailbox → Forwarding → enter address → verify the confirmation code → save.
mail.yahoo.com/d/settings/mailboxes
ForwardingON
Forward tojamie.castell@yourdomain.com
Keep a copy of forwarded messagesOFF
What you'll roughly see under Mailboxes → Forwarding — exact layout may vary.
  1. Sign in at mail.yahoo.com and click the Settings (gear) icon, then More settings.
  2. Open Mailboxes and click the mailbox you want to forward.
  3. Find the Forwarding section and toggle it on.
  4. Enter your forwarding address — your new hub, e.g. jamie.castell@yourdomain.com (or your existing Gmail, if you kept it as your hub).
  5. Yahoo emails a confirmation code to that forwarding address. Open that email, copy the code.
  6. Paste the confirmation code back into Yahoo to verify the forward.
  7. Choose whether to keep a copy of forwarded messages in the Yahoo mailbox or not — keeping a copy for the first few weeks is a reasonable safety net.

Yahoo help: help.yahoo.com/kb/SLN3618.html →

AOL Mail

  • Settings gear → More Settings → Forwarding → toggle on → enter address → click the verification link AOL emails you → choose keep-copy or not.
mail.aol.com/settings/forwarding
ForwardingON
Forward tojamie.castell@yourdomain.com
Keep a copy in AOL MailOFF
What you'll roughly see under Settings → Forwarding — exact layout may vary.
  1. Sign in at mail.aol.com and click the Settings (gear) icon, then More Settings.
  2. Choose Forwarding from the settings list.
  3. Toggle forwarding on and enter your forwarding address.
  4. AOL sends a confirmation email to the new address — open it and click the verification link.
  5. Choose whether to keep a copy of forwarded mail in AOL Mail, or not.

AOL help: help.aol.com/articles/aol-mail-set-up-mail-forwarding →

Forwarding from anywhere else

Every provider we haven't named follows roughly the same pattern, and it's easy to find your way there:

  • Look for a gear icon or "Settings" — usually top-right of the inbox.
  • If the settings page has a search box, just type "Forwarding" into it.
  • Most providers require you to verify the destination address — a confirmation code or a click-through link — before the forward actually activates. Don't skip this step; forwarding silently won't work until it's done.
  • Most also let you choose whether to keep a copy in the original inbox. Keeping a copy for a transition period is usually the safer default.

Outlook.com and Gmail forwarding walkthroughs are in Chapter 4. Gmail's own filter settings (for the receiving-side rules described in Chapter 7): mail.google.com → Settings → See all settings → Filters and Blocked Addresses.

Optional side quest: a full contacts reset and consolidation Optional

Not required for the base build — but once mail from everywhere is flowing into one hub, you'll usually find you've accumulated duplicate and scattered contacts across every account you're consolidating: personal Gmail, each business tenant, old Yahoo/AOL if you ever kept contacts there, plus whatever's stuck locally on the phone itself. The clean fix isn't a merge tool — it's a full export, dedupe, and reset onto exactly one authoritative store. Budget an hour; do it once and you won't need to again.

  1. Export every source to CSV first. Do this from each account that currently holds contacts: personal Gmail, each business tenant, Yahoo/AOL if applicable, and the phone's local contacts. Nothing gets deleted yet — this step is purely capture.
    • Google Contacts: contacts.google.com → select all (or the contacts you want) → Export in the left menu → choose Google CSV (moving between Google accounts) or Outlook CSV (for Excel or another app) → Export. Downloads immediately.
    • Outlook on the web / new Outlook for Windows: People → Export contacts in the ribbon → under "Contacts from this folder" pick the folder → Export. Saves to Downloads; UTF-8 encoding is recommended.
    • Classic Outlook desktop (and how to get a native PST backup at the same time): File → Open & Export → Import/Export → Export to a file → Next → Comma Separated Values → Next → select the Contacts folder → Next → Browse, name the file, OK → Next → Finish. If you already keep a PST backup from Outlook desktop, its Contacts folder can be exported straight to CSV this same way — no separate conversion tool needed.
  2. Combine all the CSVs into one file. Open them all in a spreadsheet (Excel or Google Sheets), stack every source's rows into one sheet, and keep only a consistent set of columns — name, email(s), phone(s), company. A ragged mix of columns is what makes the next step painful, so straighten this out first.
  3. Merge the duplicates. Three ways to get through this fast rather than by hand:
    • Sort the combined sheet by email address or by full name first — duplicates land next to each other and are easy to spot and delete manually.
    • Or skip manual spreadsheet dedup entirely: import the combined CSV into Google Contacts and run Merge & fix (menu icon, top-left → Merge & fix → review suggestions → Merge or Merge all), or import into Outlook and use its automatic duplicate suggestions after import.
    • Simple rule of thumb either way: same email address = same person, even when the name is formatted differently ("J. Smith" vs. "Jane Smith, Northline Metal Works").
  4. Back up natively before deleting anything. Take one native-format backup in addition to the CSV — a PST export from Outlook desktop is the standard "native backup" most business people will recognize (same Import/Export wizard as step 1, choosing Outlook Data File (.pst) instead of CSV, for the whole mailbox or just Contacts). This is the safety net: an imperfect cleanup below is fine, because a real backup exists to fall back on.
  5. Remove all contacts from every device and cloud account. This is the actual reset — delete the contacts stored locally on the phone, and delete them from every cloud contacts store they came from (personal Gmail, each business tenant, etc.), so nothing stale re-syncs back in later.
    • Google Contacts: check the box next to any contact → the dropdown arrow at top-left → All (selects everything) → More (top right) → DeleteMove to trash. Deleted contacts sit in Trash for 30 days before permanent deletion — a second safety net on top of the PST/CSV backup.
    • Outlook.com (web): People → All contacts in the left pane → select contacts (Shift+click for ranges) → Delete → confirm. The web version caps bulk delete at 50 contacts at a time, so a large list takes a few passes — don't be surprised when it doesn't clear everything in one go. Classic desktop Outlook can Ctrl+A the whole list and delete it in a single action, which is faster if you have it installed.
    • Phone-local contacts (iPhone/Android): delete the on-device contact group from your phone's Contacts app settings — exact wording and location vary by phone and OS version, so check your specific device's current menu rather than following a fixed path here.
  6. Upload the cleaned, merged list into the one contacts store that becomes authoritative going forward — whichever you chose as your personal daily-driver hub in Chapter 4. Outlook (personal Microsoft account) if that's your hub: People → Import contacts in the ribbon → Browse → select the CSV → Open → Import. Google Contacts if Google is your hub: Import in the left menu → choose the CSV → confirm. Google maps the header row to its fields automatically and drops the import into a labeled group so you can review it before it joins your main list.
  7. From here forward, work from the cloud/web version of mail and contacts, not a local device cache. The whole point of the reset is that the phone just displays what's synced from the cloud account — it isn't a separate store that can quietly drift out of sync again.
The end state, plainly After all of this, contacts should be syncing onto the device from exactly two places — the personal hub account and the business tenant(s) — nothing else. Concretely: either personal Microsoft account + work Microsoft account(s) if you moved your personal hub to Microsoft, or personal Google account + work Microsoft account(s) if you kept Gmail as your personal hub. No leftover Yahoo, AOL, or other legacy source should be syncing contacts to the device anymore — those accounts are just forwarding mail in now, per Chapter 7, and contribute nothing to the address book.
12 A physical key

Worth the $25–60

A hardware security key (YubiKey or equivalent) is the single cheapest security upgrade in this entire guide, and it removes MFA prompts more than it adds them — a tap replaces typing a code.

ModelConnectorTypical priceGood for
YubiKey 5C NFCUSB-C + NFC (tap on phone)~$55 flatModern laptop + phone, one key for both
YubiKey 5 NFCUSB-A + NFC~$50 flatOlder laptop with USB-A ports
Security Key NFC (Yubico)USB-A/C + NFC~$25–29 flatBudget option, FIDO2/passkeys only — fine for most executives
Pay attention The key itself is cheap and simple. Registering it against your account is not self-service in most tenants — your admin needs to enable FIDO2 security key (the passkey/security-key authentication standard) as an allowed authentication method in Entra ID before you can add one. Buy the key, then send your admin the setup guide below before you try to register it.
Security: very highEffort: 15 min for admin, 2 min for you

Admin setup guide: Enable passwordless security key sign-in in Microsoft Entra ID →

Once your admin confirms it's enabled, your own part is quick: sign in at mysignins.microsoft.com/security-infoAdd sign-in methodSecurity key → follow the on-screen prompt to tap or insert your key. That's the "2 min for you" step above.

★ Bonus chapter — hand this part to your IT admin

Conditional Access, for the person supporting this arrangement

Everything above makes the executive's life easier. This part is what keeps you — the admin — from being the one who explains a breach to the board. Microsoft already turns on a baseline for you; this is what to layer on top, and the one real decision that changes everything downstream.

The floor, whether you touch it or not Microsoft automatically rolls out a set of Microsoft-managed Conditional Access policies to eligible tenants — blocking legacy authentication, requiring MFA for admins and for all users, and requiring MFA for Azure/Entra portal access. They start in report-only and turn on within 30 days unless you act. If you're on E3/E5 or have Microsoft 365 Business Premium, check Entra admin center → Conditional Access → Policies for anything showing Created by: Microsoft — that's your existing floor, not a blank slate. Exclude your break-glass account from these exactly as you would from any policy you wrote yourself.

The one decision that matters

Before setting a single toggle, answer this for the tenant you administer: if this executive's personal device is compromised, are you willing to accept that your company's mail could be exposed to whatever else lives on it? Your answer picks a column below.

Policy areaIf you're OK with cross-company exposure on this deviceIf you want hard isolationWatch for
Device compliance / join requirement Don't require a compliant or hybrid-joined device for this user — allow any device, gated by MFA instead. Require the device to be Intune-compliant or Entra-joined to this tenant — which conflicts directly with a shared, multi-tenant device. Pick this and the executive will get device-join prompts you didn't intend. Grant control: "Require device to be marked as compliant"
Sign-in frequency Standard (Microsoft default, roughly balances security and re-prompting). Shorter re-authentication window (e.g. every 4–8 hours) so a stolen session token expires fast. Session > Sign-in frequency
Persistent browser session Allow — fewer prompts on a device only this person uses. Never persist — force a fresh sign-in every browser session. Session > Persistent browser session
App-enforced restrictions (unmanaged device) Allow full Outlook/OWA functionality. Block download, print, and sync to an unmanaged device — mail is view-only in the browser. Session > Use app enforced restrictions
MFA strength Any MFA method (Authenticator app push is fine). Require phishing-resistant MFA specifically (FIDO2 key or certificate-based) — see Chapter 12's YubiKey section. Grant control: "Require authentication strength"
Legacy authentication Block regardless — there's no version of this arrangement where legacy auth (IMAP/POP/SMTP-basic) should be allowed. Over 99% of password-spray attacks use it. Block regardless. Usually already covered by Microsoft's managed baseline policy
Pay attention The "hard isolation" column is real security, but it's also the column that generates support tickets — a device-compliance requirement in particular will actively fight a device that's deliberately shared across tenants. Most MSPs land on the left column for exactly this scenario and lean on MFA strength + short sign-in frequency to do the real work instead.
User impact: high if you pick isolationSecurity: your callEffort: one policy review per tenant

Naming and structure we'd suggest for your own sanity

  • One Conditional Access policy per control, not one giant policy — CA01-Block-LegacyAuth, CA02-MFA-AllUsers, CA03-MFA-Admins-PhishResistant. Easier to report-only test and roll back individually.
  • Always exclude your two break-glass accounts from every custom policy — the same way you'd exclude them from a Microsoft-managed one.
  • Run every new policy in Report-only for at least a week before enforcing it. This is the cheapest insurance in the whole playbook.

Adding a second admin

For business continuity, any brand-new Microsoft 365 tenant should have a second Global Admin outside the primary user — someone who can get in if the first admin is unreachable. Rather than assigning the Global Admin role directly to an individual account, we'd recommend creating a role-assignable security group (e.g. Tenant Admins) instead, then assigning the Global Admin role to the group and adding actual admin accounts as members. It's easier to audit and easier to revoke than a role sitting on one person's account, and it means removing an admin is a group-membership change, not a role reassignment under pressure.

  • Requires Entra ID P1 or P2.
  • Created in Entra admin center → Groups → New Group, with Microsoft Entra roles can be assigned to the group set to Yes — this option can only be set at group creation, not added later.
  • Assign the Global Admin role to the group itself, then manage membership instead of managing role assignments.

If you'd rather have someone else formally manage the tenant, Gravity Limited can take that on directly. We're still building out a formal client-management process, so for now that's either a direct email or a quick call — whichever's easier for you.

Or book a quick intro call →
13 FAQ

Quick answers

Can I just use my business Microsoft account for everything?
No — the moment a business tenant becomes your contacts/calendar hub, personal data starts living inside a company's Microsoft 365 tenant, which the company can see, export, and legally hold. Keep the hub personal.

What if I'm on three or more business tenants, not two?
Nothing here changes — repeat steps 1–3 of the build order per tenant, and use the calculator in Chapter 3 with your real tenant count.

Does this work if I own the device myself, versus if a company issued it?
Yes to both. On a company-issued device, that company's admin may have more say over device-level policy (the admin bonus chapter's "hard isolation" column becomes more likely for that one tenant specifically) — the account-level steps in Chapter 7 don't change either way.

My old Yahoo/AOL address still gets important mail years later — is that normal?
Very. That's exactly what the Legacy label in Chapter 7 is for — check it occasionally, and update anyone still using the old address directly rather than relying on the forward forever.