Workplace & AV
Business Email & Exchange in the UAE
Part of Microsoft 365 for Business in the UAE
Email migration is judged on one question: did anyone lose anything. Everything else about the project is forgotten within a month, and that single failure is remembered for years — so the plan matters more than the platform.
SPF, DKIM and DMARC, which most UAE domains have incomplete
These three DNS records decide whether somebody else can send email that appears to come from your domain. Configured properly, an impersonation attempt is rejected before it reaches anyone. Left incomplete — which is the common case — your own domain can be used against your own staff and your own customers.
This matters disproportionately in the Emirates, where invoice-redirection fraud against trading companies is the dominant email-borne loss. An attacker does not need to compromise anything if your domain will accept being spoofed.
SPF
Which servers may send as your domain, listed accurately rather than left permissive.
DKIM
Outgoing mail signed so recipients can verify it genuinely came from you.
DMARC
A policy telling receiving servers what to do with mail that fails — and reporting so you can see attempts.
Monitored over time
Records reviewed when a new sending service is added, since each one breaks SPF quietly.
Migration without losing anything
Mailboxes, calendars, contacts, shared mailboxes and distribution lists all move, and the last two are where migrations most often leave something behind because nobody inventoried them first.
We run a pilot group before the main cutover and schedule the switch so problems surface while there is time and attention available — not at nine on a Monday when the whole business is trying to work.
After the migration: the controls that matter
Business email compromise is the loss that actually happens to UAE companies, and it is not technically sophisticated. An attacker reads a mailbox quietly for weeks, then intervenes in a real invoice thread with amended bank details.
The controls are unglamorous: multi-factor authentication, alerting when a mailbox starts forwarding externally, external-sender marking so a lookalike domain is visible, and a finance rule that changed bank details are verified by phone to a number held beforehand.
Multi-factor authentication
On every mailbox, including the ones whose owners ask to be excluded.
Forwarding alerts
Notification when a rule starts sending mail elsewhere — the classic first sign.
External-sender marking
So a lookalike domain is visible to the person reading the message.
Out-of-band verification
Bank detail changes confirmed by phone, which is the control that actually stops the loss.
What’s included
- Mailbox, calendar and contact migration
- Shared mailbox and distribution list inventory
- SPF, DKIM and DMARC configuration
- Multi-factor authentication rollout
- Forwarding rule alerting
- External sender marking
- Retention and archiving
- Mobile device access controls
Platforms we support
How we deliver
- 01
Discover
We map your current setup, constraints and priorities before proposing anything.
- 02
Architect
A written design with fixed deliverables, so scope is agreed before work starts.
- 03
Implement
Phased rollout with rollback points — production is never left in an unknown state.
- 04
Support
A named engineer, agreed response times and a handover your team can actually run.
Common questions
Other Microsoft 365 & Workspace
Microsoft 365 Business Premium
The tier most UAE SMEs should be on — device management, conditional access and the controls that stop email fraud.
See more →Microsoft Teams
Teams for UAE organisations — meeting rooms, external collaboration and voice within what is licensed here.
See more →SharePoint & OneDrive
File storage that replaces the office server — structure, permissions and retention decided rather than inherited.
See more →