
Ready-Made Blueprints for Your Microsoft Projects
A platform for AI-powered Microsoft consulting. IT services delivered by AI agents. Proven blueprints. Your team implements and learns along the way.

What Is a Blueprint?
What Is a Blueprint?
Not an AI tool. A digital consulting process
A blueprint is a guided delivery process for a Microsoft project. Not a static document.
A blueprint is a guided delivery process for a Microsoft project. Not a static document.
Inside every blueprint: David and Richard's project experience. What steps in what order. What architecture decisions at what point. What pitfalls to avoid. Distilled from their practice. Trained into the AI agents.
Inside every blueprint: David and Richard's project experience. What steps in what order. What architecture decisions at what point. What pitfalls to avoid. Distilled from their practice. Trained into the AI agents.
The agents adapt the blueprint to your tenant and generate PowerShell scripts, admin center deep-links, step-by-step guidance, and auto-documentation for every change. Your team decides. The AI agents deliver.
The agents adapt the blueprint to your tenant and generate PowerShell scripts, admin center deep-links, step-by-step guidance, and auto-documentation for every change. Your team decides. The AI agents deliver.
All Available Blueprints
Every AI agent has a clearly defined role — like in an experienced consulting team
M365 Tenant Readiness
Microsoft 365
Security
Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.
Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access
Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.
MFA & Conditional Access
Microsoft 365
Security
Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.
Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live
Result: Verifiably secured access with clear policies and high usability.
Defender for Office 365
Microsoft 365
Security
Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.
Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material
Result: A documented, tuned email security architecture your team can operate.
Privileged Identity Management
Microsoft 365
Security
Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.
Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM
Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.
Self-Service Password Reset
Microsoft 365
Security
Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.
Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout
Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.
Mobile App Protection
Security
Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.
Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)
Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.
Intune Device Enrollment
Microsoft 365
Security
Problem: Without central device management, compliance control and enforceable security policies are missing.
Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations
Result: Existing endpoints centrally managed — the foundation for all further scenarios.
Intune Autopilot
Microsoft 365
Security
Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.
Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices
Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.
Intune LAPS
Security
Microsoft 365
Problem: Static local admin passwords pose a significant security risk during attacks.
Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team
Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.
Exchange Online Mailflow
Microsoft 365
Security
Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.
Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over
Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.
OneDrive Migration
Microsoft 365
Problem: Traditional network drives hinder mobile work and cause high operational overhead.
Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption
Result: Secure, mobile file access and a file server that can be switched off on a planned date.
MS Teams Collaboration
Microsoft 365
Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.
Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live
Result: Unified, scalable, and secure Teams collaboration across all organizational units.
External Collaboration
Microsoft 365
Problem: External collaboration must not run through shadow IT or insecure channels.
Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook
Result: Efficient, secure collaboration with partners directly in Microsoft Teams.
Microsoft Purview DLP
Security
Microsoft 365
Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.
Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting
Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.
Microsoft Purview Information Protection
Security
Microsoft 365
Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.
Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout
Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.
Microsoft Bookings
Microsoft 365
Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.
Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption
Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.
WSUS Replacement
Microsoft 365
Security
Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.
Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan
Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.
M365 Apps Configuration
Microsoft 365
Security
Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.
Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group
Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.
Universal Print
Microsoft 365
Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.
Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan
Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.
Chat with Your Own Data
Data & AI
Azure
Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.
Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup
Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.
Azure Landing Zone Setup
Azure
Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.
Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose
Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.
Azure Backup
Azure
Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.
Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook
Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.
Azure Data Archiving
Azure
Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.
Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy
Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.
Defender for Business
Security
Microsoft 365
Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.
Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook
Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.
Cloud Apps Discovery
Security
Microsoft 365
Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.
Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook
Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.
Defender for Cloud Apps
Security
Microsoft 365
Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.
Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware
Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.
Windows Hello for Business
Security
Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.
Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials
Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.
Microsoft Foundry Platform Setup
Data & AI
Azure
Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.
Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment
Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.
M365 License Optimization
Microsoft 365
Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.
Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center
Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.
Intune Mobile Device Configuration
Microsoft 365
Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.
Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout
Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.
Microsoft Copilot Readiness Assessment + Copilot Chat
Microsoft 365
Data & AI
Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.
Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules
Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.
Microsoft 365 Copilot Activation & Rollout
Microsoft 365
Data & AI
Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.
Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live
Result: Copilot active for a defined user group, with enabled users and usage you can measure.
M365 Tenant Readiness
Microsoft 365
Security
Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.
Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access
Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.
MFA & Conditional Access
Microsoft 365
Security
Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.
Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live
Result: Verifiably secured access with clear policies and high usability.
Defender for Office 365
Microsoft 365
Security
Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.
Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material
Result: A documented, tuned email security architecture your team can operate.
Privileged Identity Management
Microsoft 365
Security
Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.
Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM
Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.
Self-Service Password Reset
Microsoft 365
Security
Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.
Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout
Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.
Mobile App Protection
Security
Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.
Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)
Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.
Intune Device Enrollment
Microsoft 365
Security
Problem: Without central device management, compliance control and enforceable security policies are missing.
Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations
Result: Existing endpoints centrally managed — the foundation for all further scenarios.
Intune Autopilot
Microsoft 365
Security
Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.
Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices
Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.
Intune LAPS
Security
Microsoft 365
Problem: Static local admin passwords pose a significant security risk during attacks.
Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team
Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.
Exchange Online Mailflow
Microsoft 365
Security
Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.
Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over
Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.
OneDrive Migration
Microsoft 365
Problem: Traditional network drives hinder mobile work and cause high operational overhead.
Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption
Result: Secure, mobile file access and a file server that can be switched off on a planned date.
MS Teams Collaboration
Microsoft 365
Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.
Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live
Result: Unified, scalable, and secure Teams collaboration across all organizational units.
External Collaboration
Microsoft 365
Problem: External collaboration must not run through shadow IT or insecure channels.
Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook
Result: Efficient, secure collaboration with partners directly in Microsoft Teams.
Microsoft Purview DLP
Security
Microsoft 365
Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.
Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting
Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.
Microsoft Purview Information Protection
Security
Microsoft 365
Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.
Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout
Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.
Microsoft Bookings
Microsoft 365
Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.
Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption
Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.
WSUS Replacement
Microsoft 365
Security
Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.
Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan
Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.
M365 Apps Configuration
Microsoft 365
Security
Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.
Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group
Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.
Universal Print
Microsoft 365
Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.
Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan
Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.
Chat with Your Own Data
Data & AI
Azure
Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.
Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup
Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.
Azure Landing Zone Setup
Azure
Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.
Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose
Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.
Azure Backup
Azure
Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.
Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook
Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.
Azure Data Archiving
Azure
Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.
Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy
Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.
Defender for Business
Security
Microsoft 365
Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.
Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook
Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.
Cloud Apps Discovery
Security
Microsoft 365
Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.
Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook
Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.
Defender for Cloud Apps
Security
Microsoft 365
Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.
Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware
Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.
Windows Hello for Business
Security
Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.
Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials
Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.
Microsoft Foundry Platform Setup
Data & AI
Azure
Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.
Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment
Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.
M365 License Optimization
Microsoft 365
Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.
Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center
Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.
Intune Mobile Device Configuration
Microsoft 365
Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.
Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout
Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.
Microsoft Copilot Readiness Assessment + Copilot Chat
Microsoft 365
Data & AI
Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.
Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules
Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.
Microsoft 365 Copilot Activation & Rollout
Microsoft 365
Data & AI
Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.
Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live
Result: Copilot active for a defined user group, with enabled users and usage you can measure.
M365 Tenant Readiness
Microsoft 365
Security
Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.
Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access
Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.
MFA & Conditional Access
Microsoft 365
Security
Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.
Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live
Result: Verifiably secured access with clear policies and high usability.
Defender for Office 365
Microsoft 365
Security
Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.
Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material
Result: A documented, tuned email security architecture your team can operate.
Privileged Identity Management
Microsoft 365
Security
Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.
Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM
Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.
Self-Service Password Reset
Microsoft 365
Security
Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.
Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout
Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.
Mobile App Protection
Security
Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.
Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)
Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.
Intune Device Enrollment
Microsoft 365
Security
Problem: Without central device management, compliance control and enforceable security policies are missing.
Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations
Result: Existing endpoints centrally managed — the foundation for all further scenarios.
Intune Autopilot
Microsoft 365
Security
Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.
Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices
Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.
Intune LAPS
Security
Microsoft 365
Problem: Static local admin passwords pose a significant security risk during attacks.
Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team
Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.
Exchange Online Mailflow
Microsoft 365
Security
Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.
Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over
Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.
OneDrive Migration
Microsoft 365
Problem: Traditional network drives hinder mobile work and cause high operational overhead.
Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption
Result: Secure, mobile file access and a file server that can be switched off on a planned date.
MS Teams Collaboration
Microsoft 365
Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.
Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live
Result: Unified, scalable, and secure Teams collaboration across all organizational units.
External Collaboration
Microsoft 365
Problem: External collaboration must not run through shadow IT or insecure channels.
Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook
Result: Efficient, secure collaboration with partners directly in Microsoft Teams.
Microsoft Purview DLP
Security
Microsoft 365
Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.
Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting
Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.
Microsoft Purview Information Protection
Security
Microsoft 365
Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.
Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout
Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.
Microsoft Bookings
Microsoft 365
Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.
Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption
Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.
WSUS Replacement
Microsoft 365
Security
Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.
Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan
Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.
M365 Apps Configuration
Microsoft 365
Security
Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.
Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group
Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.
Universal Print
Microsoft 365
Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.
Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan
Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.
Chat with Your Own Data
Data & AI
Azure
Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.
Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup
Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.
Azure Landing Zone Setup
Azure
Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.
Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose
Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.
Azure Backup
Azure
Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.
Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook
Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.
Azure Data Archiving
Azure
Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.
Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy
Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.
Defender for Business
Security
Microsoft 365
Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.
Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook
Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.
Cloud Apps Discovery
Security
Microsoft 365
Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.
Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook
Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.
Defender for Cloud Apps
Security
Microsoft 365
Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.
Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware
Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.
Windows Hello for Business
Security
Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.
Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials
Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.
Microsoft Foundry Platform Setup
Data & AI
Azure
Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.
Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment
Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.
M365 License Optimization
Microsoft 365
Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.
Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center
Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.
Intune Mobile Device Configuration
Microsoft 365
Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.
Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout
Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.
Microsoft Copilot Readiness Assessment + Copilot Chat
Microsoft 365
Data & AI
Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.
Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules
Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.
Microsoft 365 Copilot Activation & Rollout
Microsoft 365
Data & AI
Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.
Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live
Result: Copilot active for a defined user group, with enabled users and usage you can measure.
M365 Tenant Readiness
Microsoft 365
Security
Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.
Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access
Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.
MFA & Conditional Access
Microsoft 365
Security
Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.
Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live
Result: Verifiably secured access with clear policies and high usability.
Defender for Office 365
Microsoft 365
Security
Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.
Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material
Result: A documented, tuned email security architecture your team can operate.
Privileged Identity Management
Microsoft 365
Security
Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.
Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM
Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.
Self-Service Password Reset
Microsoft 365
Security
Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.
Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout
Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.
Mobile App Protection
Security
Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.
Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)
Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.
Intune Device Enrollment
Microsoft 365
Security
Problem: Without central device management, compliance control and enforceable security policies are missing.
Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations
Result: Existing endpoints centrally managed — the foundation for all further scenarios.
Intune Autopilot
Microsoft 365
Security
Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.
Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices
Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.
Intune LAPS
Security
Microsoft 365
Problem: Static local admin passwords pose a significant security risk during attacks.
Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team
Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.
Exchange Online Mailflow
Microsoft 365
Security
Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.
Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over
Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.
OneDrive Migration
Microsoft 365
Problem: Traditional network drives hinder mobile work and cause high operational overhead.
Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption
Result: Secure, mobile file access and a file server that can be switched off on a planned date.
MS Teams Collaboration
Microsoft 365
Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.
Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live
Result: Unified, scalable, and secure Teams collaboration across all organizational units.
External Collaboration
Microsoft 365
Problem: External collaboration must not run through shadow IT or insecure channels.
Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook
Result: Efficient, secure collaboration with partners directly in Microsoft Teams.
Microsoft Purview DLP
Security
Microsoft 365
Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.
Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting
Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.
Microsoft Purview Information Protection
Security
Microsoft 365
Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.
Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout
Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.
Microsoft Bookings
Microsoft 365
Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.
Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption
Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.
WSUS Replacement
Microsoft 365
Security
Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.
Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan
Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.
M365 Apps Configuration
Microsoft 365
Security
Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.
Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group
Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.
Universal Print
Microsoft 365
Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.
Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan
Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.
Chat with Your Own Data
Data & AI
Azure
Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.
Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup
Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.
Azure Landing Zone Setup
Azure
Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.
Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose
Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.
Azure Backup
Azure
Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.
Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook
Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.
Azure Data Archiving
Azure
Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.
Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy
Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.
Defender for Business
Security
Microsoft 365
Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.
Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook
Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.
Cloud Apps Discovery
Security
Microsoft 365
Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.
Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook
Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.
Defender for Cloud Apps
Security
Microsoft 365
Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.
Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware
Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.
Windows Hello for Business
Security
Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.
Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials
Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.
Microsoft Foundry Platform Setup
Data & AI
Azure
Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.
Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment
Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.
M365 License Optimization
Microsoft 365
Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.
Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center
Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.
Intune Mobile Device Configuration
Microsoft 365
Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.
Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout
Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.
Microsoft Copilot Readiness Assessment + Copilot Chat
Microsoft 365
Data & AI
Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.
Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules
Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.
Microsoft 365 Copilot Activation & Rollout
Microsoft 365
Data & AI
Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.
Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live
Result: Copilot active for a defined user group, with enabled users and usage you can measure.
In 30 minutes we will show you the blueprint for your specific use case
Find the right blueprint
DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.


© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case
Find the right blueprint
DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.


© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case
Find the right blueprint
DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.


© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case
Find the right blueprint
DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.


© 2026 DAMALO GmbH
