TL;DR: I understand why non-technical companies choose M365, but why do technically capable companies, especially in the EU, place so many critical services behind Microsoft SaaS when on-premises or hybrid infrastructure is a realistic alternative? If you genuinely considered both, what ultimately made Microsoft win?
I’m probably what many people here would call an old-fashioned sysadmin. I run a mixture of Linux services and Windows Server, with authentication, storage and other important services kept on infrastructure under our control and largely detached from Microsoft SaaS.
This is not intended as a “cloud bad, on-prem good” post. I’m genuinely trying to understand the reasoning of companies that have chosen the Microsoft-first approach.
The recent Outlook outage, together with posts about entire M365 tenants becoming disabled or “deauthenticated,” made me think about this again. A general outage is usually temporary and affects many customers, while a tenant-specific issue may leave a small company completely dependent on Microsoft support. Both cases demonstrate how many critical business functions can depend on the same provider.
From a business-continuity perspective, being locked out of a tenant for a day, or any prolonged period, is no better than hardware-related downtime in an on-premises environment. If employees cannot access email, files or other essential systems, the business is down regardless of whether the failed component is in the company’s server room or a provider’s cloud.
Microsoft’s infrastructure is obviously far more redundant than anything a small company could build. What worries me is not only a normal service outage, but a tenant-specific administrative problem where the company depends on Microsoft support to restore access. A smaller customer may not have an enterprise account team capable of escalating the issue immediately, so the business could potentially be seriously affected for days.
I understand many of the advantages: remote onboarding, tight integration between identity and endpoint management, collaboration through Teams and SharePoint and no need to maintain certain local infrastructure.
I also understand that the Microsoft route may well be the most sensible option for many non-technical organizations. A small law firm, for example, probably does not want to operate its own server room or rent and maintain servers somewhere else.
What puzzles me more is seeing technology companies make the same choice even when they already have the necessary knowledge in-house. They could realistically operate at least some of these services themselves, or design a hybrid environment, yet many still place identity, email, documents, endpoint management, telephony and authentication for unrelated SaaS applications under the same tenant. That seems to create an enormous common failure domain that they have the technical ability to avoid.
I’m also not convinced that this necessarily eliminates much administration. Operating local servers requires hardware maintenance, patching, monitoring, backups and disaster recovery. But properly managing M365 means dealing with licensing, Entra, Intune and who knows how many other interconnected services, along with constantly changing portals and Microsoft support. It seems more like a different type of system administration than substantially less system administration.
The question is especially interesting to me in the EU. Apart from GDPR and data residency, there is also the broader issue of making a company’s entire operation dependent on a single US provider.
So my question is mainly for people who genuinely considered both options, especially those working at technology companies with the skills to self-host: if on-premises infrastructure was a realistic alternative and there was an actual debate, what ultimately made you choose the Microsoft route?
I’m also entirely open to the possibility that I am overestimating the risks or underestimating the advantages. I would simply like to understand why the industry is moving so decisively in this direction while the traditional on-premises approach appears to be gradually disappearing.