Capability
Platform and cloud operations
Identity, devices and email were set up years ago by different people. Nobody can say who has access to what, and offboarding depends on somebody remembering.
What we deliver
The work itself
- Produce a current-state inventory of tenants, identities, devices, licences and privileged roles
- Consolidate identity onto one provider, with conditional access and multi-factor enforced by policy
- Bring devices under managed configuration, so a new starter is productive on day one
- Automate joiner, mover and leaver flows against your HR system as the source of truth
- Reduce standing administrative access to named, time-bound, logged elevation
- Set recovery objectives per system, then test restores against them and record the result
- Document the network, the firewall rules and the reason each rule exists
- Hand over an access review your auditor can read without an interpreter
How we work
What the engagement looks like
Phases, durations and what each one hands over are listed below. The stack is published in full — nothing about how this is built is a surprise once work starts.
Stack
What we build it with
- PlatformMicrosoft Entra ID · Microsoft 365 · Intune · Exchange Online · SharePoint · Azure
- OperationsConditional access policies · Privileged Identity Management · Microsoft Graph automation · PowerShell · Terraform
- DataBackup with tested restores · Retention and legal hold policies · Audit log export
- RuntimeWindows · macOS · Linux · Site-to-site and zero-trust remote access
Engagement shape
Phases and timeline
- Current state2 weeksInventory, privileged access findings, licence waste, and a prioritised remediation list
- Remediation4 to 10 weeksIdentity consolidated, policies enforced, device baselines applied, restores tested
- Automation2 to 4 weeksJoiner, mover and leaver flows running from your HR system, with an exception report
- Steady stateMonthly, ongoingAccess review, restore test evidence, patch report, and the next quarter's recommendations
What we need from you
- Global administrator access, granted through a time-bound elevation we both log
- The HR system's leaver feed, or agreement on a manual trigger until one exists
- A decision on which legacy authentication can be switched off, and when
- A change window for the policy enforcement that will lock somebody out
After go-live
Who holds it at 3am
- Access reviews run monthly and produce evidence, not reassurance
- Restores are tested on a schedule and the result is reported whether it passed or failed
- Patch compliance is reported as a percentage of the fleet, with the exceptions named
- An out-of-hours escalation path is defined and tested before it is needed