Guides & Checklists
Hybrid working IT requirements: the checklist for offices of up to 250 people
What hybrid working requires from business IT: MFA and conditional access, managed laptops, Microsoft 365, office Wi-Fi, remote support and policies.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
Hybrid working requires IT built around identity and devices rather than the office: multi-factor authentication and conditional access on every account, company-managed encrypted laptops with endpoint protection and remote patching, files in SharePoint and OneDrive rather than an office server, an office network that copes with video, remote support and written device and data policies.
Most office IT was designed on one assumption: staff sit inside the building, on company PCs, behind the office firewall. Hybrid working removes that assumption. The people, the devices and increasingly the data are outside the building, and the office is one location among several. This is the practical checklist of what that changes, aimed at businesses of up to 250 people in Hertfordshire, west Essex and London who want to get it right without an enterprise budget.
What actually changes
In a single-office setup the network perimeter did most of the security work. If you were plugged in at your desk, you were trusted. Hybrid working replaces that with two questions asked on every sign-in: who is this person, and is this device safe? That is the core of the Zero Trust approach, and for a small business it comes down to identity, device management and where the data lives.
The other change is support. When someone's laptop misbehaves at home, nobody can walk over. Every support process has to work remotely by default.
Identity: MFA and conditional access
Passwords alone are not adequate once sign-ins come from anywhere. The minimum standard for hybrid working is:
- MFA on every account, including directors, shared mailboxes with sign-in enabled, and above all admin accounts. Use the Microsoft Authenticator app with number matching rather than SMS codes, which are easier to intercept.
- Conditional access policies in Microsoft Entra ID that require MFA for all users, block legacy authentication protocols, and can require a compliant, company-managed device to reach SharePoint and email. Conditional access needs Microsoft 365 Business Premium or an Entra ID P1 licence.
- Role-based access. Staff get access to what their role needs. Global admin rights are held by named accounts used only for administration, not for daily email.
- Sign-in monitoring. Impossible-travel alerts and risky sign-in reports are reviewed, not ignored. Microsoft's guidance on securing small-business tenants is at learn.microsoft.com/microsoft-365.
The NCSC's guidance on multi-factor authentication for online services is a short, useful read for anyone setting policy.
Devices: managed, encrypted, patched
A hybrid workforce runs on laptops, and each one is now a small branch office. The requirements:
- Company-owned, standardised laptops. A single model family (Dig IT typically supplies HP or Dell business ranges) makes spares, imaging and remote support far simpler. Every device should meet the Windows 11 hardware floor (TPM 2.0, a supported processor), as Windows 10 has been out of support since October 2025.
- Disk encryption (BitLocker) enforced and keys escrowed to Entra ID or Intune, so a laptop left on a train is a hardware loss rather than a data breach reportable to the ICO.
- Mobile device management (Intune or equivalent) to apply security baselines, push apps, and wipe a lost device remotely.
- Endpoint detection and response on every machine, not just antivirus. Dig IT deploys EDR to client devices so that threats are detected and contained wherever the device is.
- Remote monitoring and patching so Windows and third-party updates install on schedule whether the device is in the office or in a spare bedroom.
- A lifecycle plan. Laptops work harder and travel more than desktops. Budget for a three-to-four-year refresh rather than running them into the ground. See the hardware lifecycle strategy guide.
Data: SharePoint and OneDrive, not the office server
The office file server made sense when everyone was in the building. For hybrid teams it means VPN dependence, slow access from home and a single point of failure. Moving files into SharePoint (team and department libraries) and OneDrive (personal working files) gives everyone the same experience from any location, with versioning and sharing controls built in.
Do this deliberately. A file server copied into SharePoint without planning creates a mess that staff avoid, which is how personal Dropbox accounts and email attachments creep back. Plan the site and library structure, permissions and retention first, and decide what you will do about backup: Microsoft's retention features are not a backup, so a separate Microsoft 365 backup is part of the hybrid stack. A structured SharePoint and Teams setup is usually a week or two of work for a 20-to-50-person business.
Connectivity: the office still matters
Hybrid working puts more strain on the office network, not less. Every meeting now has a Teams component, and the people who did come in expect Wi-Fi that works in every room.
- Wi-Fi coverage designed for the building, with Wi-Fi 6 or 6E access points positioned on a survey rather than guessed. Older or awkward buildings need more care: Dig IT's UniFi mesh installation at a 16th-century mansion with metre-thick walls is an extreme example, but many Hertfordshire offices in converted buildings have similar problems on a smaller scale.
- A business firewall sized for the VPN and web-filtering load, with per-user VPN and MFA for the few systems that still live on site.
- Internet resilience. With staff split across locations, an office outage now cuts off the in-office group from their remote colleagues. A second connection (FTTP or 4G/5G) as automatic failover is inexpensive insurance. Read more on leased lines versus business broadband.
- Home connections are outside your control, but you can set expectations: a wired connection or a decent router, and no work on open public Wi-Fi without the VPN.
Support that works from anywhere
Hybrid support is remote-first. That means a helpdesk that answers the phone, remote control tools the user can approve (Dig IT uses Splashtop), and an RMM agent already on the device so problems are often spotted before the user calls. It also means holding a spare laptop or two, pre-configured, so a hardware failure at home is fixed by a swap rather than a week without a machine.
The volume of support requests also shifts. Fewer are about hardware and more are about collaboration tools, sharing permissions and MFA prompts. Short, regular training beats a one-off induction.
Policies and training
Technology only goes so far. Staff need to know:
- which devices may be used for work, and that personal cloud storage is not permitted for company data
- what to do when a device is lost or stolen (report immediately, so it can be wiped)
- how to recognise and report phishing, and never to approve an MFA prompt they did not trigger
- that video calls and printed documents at home may be seen by others in the household
Security awareness training delivered in short quarterly sessions, backed by simulated phishing, keeps this current without taking a day out.
Business continuity for a distributed team
Continuity planning used to focus on the office being unavailable. Hybrid teams already have that covered. The new dependencies are Microsoft 365, the internet connection at each location and the identity system itself. Your continuity plan should cover how staff communicate if Teams is down, how you would recover from a compromised admin account, and how quickly a stolen laptop's data can be assumed safe. Test it once a year.
The hybrid working IT checklist
| Area | Minimum standard |
|---|---|
| Identity | MFA on all accounts, conditional access, legacy authentication blocked, named admin accounts |
| Devices | Company-owned, Windows 11 capable, BitLocker, Intune-managed, EDR, RMM patching |
| Data | SharePoint and OneDrive with planned structure, sharing controls, separate M365 backup |
| Office network | Surveyed Wi-Fi 6/6E, business firewall, failover internet connection |
| Remote access | Per-user VPN with MFA only for systems that must stay on site |
| Support | Remote-first helpdesk, remote control tools, pre-configured spare laptops |
| Policy | Written acceptable-use and device policy, lost-device process, phishing reporting |
| Training | Short quarterly sessions, simulated phishing |
| Continuity | Plan covering M365 outage, admin compromise and device loss, tested annually |
What to do next
If you have moved to hybrid working on the strength of laptops and a Teams licence, but the items above are patchy, you are carrying risk that is cheap to remove and expensive to ignore. Dig IT's IT health check reviews identity, devices, data and network against this list and gives you a prioritised plan.

