Microsoft 365 and Google Workspace: What Verito Supports
Discover how Verito enhances productivity with Microsoft 365 and Google Workspace support tailored to your business needs.
Table of Contents
Microsoft 365 and Google Workspace: Scope of Support Matrix
Effective August 2026 | Last Updated on 26th August | Published by Parnav Dagar
1. Purpose and how to use this article
This article defines what Verito Technologies manages inside your Microsoft 365 or Google Workspace environment, what we provide on request, and what remains with your firm. It applies to VeritGuard clients whose plan includes cloud platform management.
It is written to answer three questions directly:
- What does Verito administer in our environment day to day?
- What must our firm keep ownership of, or arrange separately?
- What access does Verito need from us, and why does it need that much?
Use Sections 4 and 5 for a quick answer, Sections 6 through 11 to understand what each included service actually covers, and Sections 12 and 13 to identify gaps before a prior provider is disengaged.
Two layers, one console
Microsoft 365 and Google Workspace each have two layers. The day to day layer is where user accounts are created, passwords are reset, and access is granted. Underneath it is the platform layer, where identity architecture, device policy, and data governance are designed.
Both are reached through the same admin console, which is why the line between them is easy to miss. This article draws that line clearly so you always know who to ask.
2. The four support levels
Every item in this article carries one of four labels. Understanding the difference prevents assumptions during onboarding and during an incident.
| Support level | What it means |
|---|---|
| Included | Part of your plan. Raise a ticket and we handle it. |
| On request | We can do this. Because it changes how security behaves for everyone in your firm, we scope each request individually rather than treating it as a standard ticket. |
| Guidance provided | We do not do this for you, but we will advise you, walk you through it, and stay with you until it is done. |
| Not currently managed | Outside our support scope today. Where we are actively building the capability, the plan column says so. |
The agreement always governs
Anything named specifically in your service agreement is covered by that agreement, whatever this article says. Where the two differ, your agreement wins and we will honour it.
3. Access we require
To administer your environment and to activate the services included in your plan, we need administrative access to it. In Microsoft 365 this means a dedicated Verito account holding the Global Administrator role. In Google Workspace it means a dedicated Verito account with Super Admin privileges.
This level of access is not a convenience. Backup, email anti-phishing and spam filtering, and account monitoring all attach at the domain or tenant level, and they cannot be switched on or connected to your domain from a lower level of access. The same applies to much of the routine administration described below.
We always work from a named Verito account rather than a shared or generic one, so every action taken in your environment appears in your audit log and is attributable to us. That access is visible in your admin console at any time. If you ever want to review, restrict, or remove it, tell us and we will help you do it.
4. Microsoft 365 support matrix
| Function | Support level | Plan |
|---|---|---|
| User accounts: create, change, remove | Included | Pro, Elite |
| Password resets | Included | Pro, Elite |
| Multi-factor authentication re-registration | Included | Pro, Elite |
| License purchase and assignment | Included | Pro, Elite |
| Group and distribution list membership | Included | Pro, Elite |
| Shared mailboxes and mailbox permissions | Included | Pro, Elite |
| Calendar permissions and delegation | Included | Pro, Elite |
| Mail flow troubleshooting and quarantine release | Included | Pro, Elite |
| OneDrive and SharePoint access requests | Included | Pro, Elite |
| Email anti-phishing and spam filtering | Included | Pro, Elite |
| Cloud data backup, one year retention | Included | Elite |
| Account monitoring and sign-in alerting | Included | Elite |
| Administrator role assignment | On request | Pro, Elite |
| Conditional Access policy setup | On request | Pro, Elite |
| Ongoing Entra ID identity administration | Not currently managed | On roadmap |
| Intune device management and compliance policy | Not currently managed | On roadmap |
| Identity configuration backup | Not currently managed | On roadmap |
| Retention, eDiscovery, and compliance policy | Not currently managed | On roadmap |
| Domain and DNS record management | Not currently managed | Client managed |
5. Google Workspace support matrix
Our Google Workspace scope mirrors our Microsoft 365 scope with one exception, noted below. Function names differ because the platforms name things differently, but the boundary sits in the same place.
| Function | Support level | Plan |
|---|---|---|
| User accounts: create, change, remove | Included | Pro, Elite |
| Password resets | Included | Pro, Elite |
| 2-Step Verification re-enrolment | Included | Pro, Elite |
| License purchase and subscription management | Guidance provided | Pro, Elite |
| Google Group membership and settings | Included | Pro, Elite |
| Mailbox delegation and shared access | Included | Pro, Elite |
| Calendar sharing and delegation | Included | Pro, Elite |
| Mail flow troubleshooting and quarantine release | Included | Pro, Elite |
| Shared drive access and permissions | Included | Pro, Elite |
| Email anti-phishing and spam filtering | Included | Pro, Elite |
| Cloud data backup, one year retention | Included | Elite |
| Account monitoring and sign-in alerting | Included | Elite |
| Administrator role assignment | On request | Pro, Elite |
| Context-Aware Access policy setup | On request | Pro, Elite |
| Organizational unit restructuring | On request | Pro, Elite |
| Ongoing identity and directory administration | Not currently managed | On roadmap |
| Mobile and endpoint device management | Not currently managed | On roadmap |
| Identity configuration backup | Not currently managed | On roadmap |
| Vault retention, legal hold, and eDiscovery | Not currently managed | On roadmap |
| Domain and DNS record management | Not currently managed | Client managed |
Two Google-specific notes. Context-Aware Access is available only on certain Google Workspace editions, so if you are interested in it we will confirm your edition supports it before scoping the work. Organizational units carry policy as well as structure, which is why restructuring them is handled on request rather than as routine administration.
6. Day to day user administration
These requests make up most of a firm's activity and need no special handling. Send them to us and we take care of them.
- Creating an account for a new staff member and completing their setup.
- Disabling or removing an account when someone leaves, including converting their mailbox so their email stays accessible to the firm.
- Updating names, titles, and departments.
- Password resets.
- Re-registering multi-factor authentication when someone changes phones or loses their authenticator.
- Adding or removing people from groups and distribution lists.
- Creating shared mailboxes and granting access to them.
- Calendar permissions, mailbox delegation, and out of office settings.
- Tracing a message that did not arrive and releasing legitimate email from quarantine.
- Granting access to a OneDrive, SharePoint, or shared drive location where the permission structure already exists.
One note on groups. Most groups simply organise people, but some also control access, carry licensing, or grant application permissions. Where a group does more than it appears to, we check what depends on it before making a change. This occasionally adds a short delay to what looks like a routine request, and it is deliberate.
7. Licensing
For Microsoft 365, we purchase licenses on your behalf and assign them to your users. Licenses bought through us appear on your Verito invoice, so there is no separate billing relationship for your firm to manage and no second vendor to reconcile at month end. This covers new licenses when you hire, additional licenses when you grow, and changes to a different license type when your requirements change.
Tell us about new hires as early as you can. Provisioning is quick, but the earlier we know, the more of the setup is finished before their first morning.
Google Workspace is different. We do not purchase or manage Google Workspace licensing on your behalf, so that subscription stays in your firm's name and is billed to you directly by Google. We will still help you get it right. Tell us what you need and we will advise on the correct edition, walk you through the purchase, and make sure the licences land where they should. You handle the transaction, we handle the guidance.
8. Administrator roles
An administrator role gives a user authority over your environment rather than access to their own mail and files. It is worth understanding the difference, because three things are often confused. A license gives someone the right to use a product. Group membership puts someone on a list. An administrator role grants control over other people's accounts and your firm's settings.
The roles requested most often:
| Role | What it allows |
|---|---|
| Global Administrator | Complete control of the environment, including access to any mailbox and the ability to change security settings |
| Exchange Administrator | Full control of mail, mailboxes, and mail flow rules |
| User Administrator | Create, change, and remove users, and reset passwords |
| Helpdesk Administrator | Reset passwords for standard users only |
| Billing Administrator | Manage subscriptions and purchases |
We assign administrator roles on request. When you ask, we will usually ask what the person needs to accomplish before we act. That is not a delay tactic. A Global Administrator can read every client file in your environment, and under the FTC Safeguards Rule and IRS Publication 4557 the principle of least privilege means each person should hold the smallest role that lets them do their job. Very often the right answer is a narrower role than the one originally requested, and choosing it keeps your firm on the right side of an audit question.
9. Email protection
On Pro and Elite plans we deploy and manage an email anti-phishing and spam filtering layer that sits in front of your mailboxes. It screens inbound mail for phishing attempts, impersonation of partners and clients, malicious links, and unsafe attachments, adding protection beyond what the platform provides on its own.
We handle the configuration, tuning, and ongoing management. If a legitimate message is held, contact us and we will release it and adjust the rules so the same sender is not caught again. If something suspicious reaches an inbox, report it to us and we will investigate.
10. Account monitoring and alerting
On the Elite plan we monitor your cloud accounts for activity that suggests a problem. This includes sign-ins from unexpected locations, repeated failed sign-in attempts, unusual mailbox forwarding rules, permission changes, and file sharing that departs from normal patterns.
This matters because account compromise in an accounting firm rarely looks dramatic. An attacker who obtains credentials typically watches quietly, sets a forwarding rule, and waits for a payment conversation. Detecting the forwarding rule is what catches it early.
11. What is backed up and what is not
On the Elite plan we back up your Microsoft 365 or Google Workspace data with one year retention. That covers mailboxes, OneDrive and Google Drive files, SharePoint and shared drive documents, and Teams content. If a file is deleted, corrupted, or encrypted by ransomware, we can restore it.
Worth knowing before you need it
A data backup protects your content. It does not capture your identity configuration, meaning your security policies, administrator role assignments, group structures, and connected applications. If one of those is changed or deleted, restoring your files will not bring it back.
This is a characteristic of cloud backup generally rather than anything specific to your setup. Backing up identity configuration is a separate discipline and is not part of our current service. If you are unsure whether anyone is covering it for your firm, raise it with us and we will help you work out where you stand.
12. Available on request
Some work sits outside routine administration because it changes how security behaves for everyone in your firm. We are glad to take it on, and we scope each request individually rather than treating it as a standard ticket.
Conditional Access and Context-Aware Access policies. These are the rules that decide who can sign in, from where, on which devices, and under what conditions. Well designed, they are among the strongest controls available to a firm holding client tax data. Configured without care, they can lock every user out of the environment simultaneously, including the administrators needed to undo it. We have implemented these for clients and we are happy to discuss yours. We handle each case on its own terms so the policy fits how your firm actually works.
Administrator role assignment. Covered in Section 8. Ask us and we will scope the right level of access with you.
Organizational unit restructuring in Google Workspace. Because organizational units carry policy, moving people between them changes the settings that apply to them. We treat this as a scoped change rather than a routine one.
13. Not currently managed
We would rather be straightforward about the edges of our service than have you discover them at an inconvenient moment.
Entra ID, Intune, and their Google equivalents as ongoing disciplines. We do not currently provide ongoing management of identity administration or device management. In practical terms that means identity governance, privileged access management, access reviews, application registrations and single sign-on integrations, directory synchronisation, and the design and maintenance of device compliance and configuration policies.
We are actively building these capabilities within our support team. It is a genuine investment in training and tooling rather than a switch we can flip, so the realistic timeline is measured in months. We will update this article and let affected clients know directly as that work completes. In the meantime, if you have a specific need in this area, raise it with us. Some individual tasks we can already help with on request, and where we cannot, we will tell you plainly rather than attempt something we are not yet set up to support properly.
Retention, eDiscovery, and data governance policy. Legal hold, retention labelling, and eDiscovery configuration intersect with your firm's legal obligations, and are best handled alongside your legal advisor. This is also on our roadmap.
Domain and DNS management. Your domain registrar account and DNS records remain under your firm's control. We can advise on a specific record change and tell you exactly what is needed, but we do not manage registrar accounts on an ongoing basis.
14. When a request falls outside our scope
Outside our scope does not mean we walk away. It means we do not make the change ourselves. What we do instead:
- We finish the diagnosis and identify exactly what is causing the issue.
- We tell you specifically what needs to change and who is best placed to make the change.
- We keep your ticket open until it is resolved rather than closing it at handover.
- We confirm the outcome with you.
One note on timing. Our response commitments cover our own work. Where something depends on a third party, we do not control how quickly it is completed, and we will be straightforward with you about that rather than quoting a timeline we cannot hold.
15. Getting help
If you are not sure which side of the line a request falls on, send it to us anyway. Working that out is our job, not yours. Our support team is available 24 hours a day.
Table of Contents