M365 Seminar With JET IT Services - 5 Key Takeaways and Q&A

Author: Shanghai BenCham

MICROSOFT 365 SEMINAR Global or China Version?

On 1  July 2026, the Benelux Chamber of Commerce, in partnership with JET IT Services, hosted a seminar on the differences between the Global and China versions of Microsoft 365. The session covered practical considerations for businesses operating in and with China, including data residency, security, collaboration, user management, and cross-border workflows. Below are the key takeaways and a Q&A from the discussion.

 

5 Key Takeaways

1. Data storage location and its impact on compliance

Microsoft 365 Global runs in Microsoft's global cloud. Microsoft 365 operated by 21Vianet is a separate China-specific environment operated locally, with customer data stored in Mainland China.

Data residency supports compliance objectives, but it does not determine compliance on its own. Data classification, transfer scenarios and legal requirements still need to be reviewed.

The tenant model should be decided early: which environment owns users, documents and applications, and where cross-border transfers are expected.

 

2. How documents are shared in Microsoft 365

OneDrive is primarily an individual user's work area. Files are private by default and become available to others when the owner shares them.

SharePoint is designed for team, department and company content, with shared ownership, structured permissions, version history and long-term governance.

Business-critical documents should not depend on a single employee's OneDrive. Team-owned content should be stored in a structured SharePoint site.

 

3. Account security in Microsoft 365

Require multi-factor authentication, separate day-to-day user accounts from administrator accounts and apply least-privilege access.

Security also includes email protection, guest-sharing controls, device policies and a reliable off boarding process.

 

4. Account access management during onboarding and offboarding

Use a standard joiner-mover-leaver process so accounts, licenses, group memberships and device access match each employee’s role.

When an employee leaves, block sign-in, revoke sessions, secure mailbox and OneDrive data, transfer business ownership and remove remaining access in line with retention requirements.

 

5. Collaboration between Microsoft 365 China and Microsoft 365 Global

The China and Global environments are separate. A Global account does not sign in to a China tenant, and viceversa.

Supported Teams cross-cloud scenarios can be enabled through administrator configuration, including external

access, allowed domains or guest access. The intended workflows should be tested before rollout.

Teams, Outlook and OneDrive enable cross-version permission-based data access and communication.

 

BUSINESS REVIEW CHECKLIST

Confirm whether the organization uses Microsoft 365 Global, China or a hybrid model.

Map where data is stored and where cross-border transfers occur.

Define who owns licences, accounts, permissions and administrator access.

Set clear rules for OneDrive, SharePoint, Teams and external sharing.

Document onboarding, role-change and offboarding steps.

Test emergency administrator access and recovery procedures.

Test China-HQ calls, chat, file exchange and application integrations under real conditions.

Document legacy ERP, operating-system and vendor-support dependencies.

 

Questions & Answers

1. What is the difference between saving business content in SharePoint and OneDrive?

OneDrive is designed around the individual user. Files are private by default and are managed from that person's account unless they are shared.

SharePoint is designed for shared business content. It gives a team or department a common location with shared ownership, structured permissions, version history and governance.

A useful rule is: draft or individual working files can start in OneDrive; team-owned or business-critical content should live in SharePoint.

 

2. How can a Global Administrator recover access if MFA fails?

It's always advised having 2 Global admin accounts so one can act as "break/fix account to reset the other Global Admin's password or reset MFA. Each account can "rescue" each other.

Create a break glass account and keep the admin and user accounts separate for both management and IT. Store the break glass credentials air-gapped rather than in any shared digital location.

If management and IT are in different locations, split the transfer across two channels: send the username and tenant details on one channel and the password on a separate channel such as a phone call.

If a file must be sent, it should be encrypted before sending and the passphrase shared separately since bad actors may monitor unencrypted data. Each location should hold its own independently stored air-gapped copy rather than shipping

one physical copy between sites.

 

3. Can a legacy on-premises ERP be kept if it depends on an unsupported Windows environment?

Treat this as an application-modernization and risk-management project, not only as a Microsoft 365 or PC upgrade question.

First document the ERP version, database, integrations, endpoint requirements, vendor support and recovery process.

Then test a supported target, such as a supported ERP release, server, virtual desktop or controlled remote-access model.

Even though Microsoft has stopped providing security updates for older systems, they don't actually forbid you from using them. That said, if you're running them in a production environment, you'll need to isolate those devices and make sure they're protected with both antivirus software and firewall rules.

 

4. Why might Microsoft 365 Copilot stop working properly from Mainland China even though it worked before?

On a global tenant Copilot itself is not restricted, so this is likely one of two things. Copilot can detect the user's location from their IP and restrict access if it resolves to mainland China, separate from the tenant type.

The GFW can also fully block specific Copilot domains outright rather than just slow them down, which looks like no access rather than lag.

To confirm which one it is, have the user try a VPN or offshore breakout. If Copilot works with that, it is network level blocking. If it still fails, it is the location-based restriction on Microsoft’s side.

 

RECOMMENDED NEXT STEPS

1. Confirm the target tenant and data-residency model.

2. Review identity security, administrator roles and emergency access.

3. Define file ownership, SharePoint structure and employee lifecycle controls.

4. Test cross-border collaboration, Copilot access and legacy application dependencies.

 

CONTACT

JET IT Services

Email: ervis@jetservices.com.cn

Phone: +86 21-6019-6272

www.jetservices.com.cn