Ready-Made Blueprints for Your Microsoft Projects

A platform for AI-powered Microsoft consulting. IT services delivered by AI agents. Proven blueprints. Your team implements and learns along the way.

What Is a Blueprint?

What Is a Blueprint?

Not an AI tool. A digital consulting process

A blueprint is a guided delivery process for a Microsoft project. Not a static document.

A blueprint is a guided delivery process for a Microsoft project. Not a static document.

Inside every blueprint: David and Richard's project experience. What steps in what order. What architecture decisions at what point. What pitfalls to avoid. Distilled from their practice. Trained into the AI agents.

Inside every blueprint: David and Richard's project experience. What steps in what order. What architecture decisions at what point. What pitfalls to avoid. Distilled from their practice. Trained into the AI agents.

The agents adapt the blueprint to your tenant and generate PowerShell scripts, admin center deep-links, step-by-step guidance, and auto-documentation for every change. Your team decides. The AI agents deliver.

The agents adapt the blueprint to your tenant and generate PowerShell scripts, admin center deep-links, step-by-step guidance, and auto-documentation for every change. Your team decides. The AI agents deliver.

All Available Blueprints

Every AI agent has a clearly defined role — like in an experienced consulting team

All
Microsoft 365
Security
Data & AI
Azure
All
Microsoft 365
Security
Data & AI
Azure
Icon
M365 Tenant Readiness

Microsoft 365

Security

Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.

Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access

Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.

Icon
MFA & Conditional Access

Microsoft 365

Security

Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.

Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live

Result: Verifiably secured access with clear policies and high usability.

Icon
Defender for Office 365

Microsoft 365

Security

Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.

Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material

Result: A documented, tuned email security architecture your team can operate.

Icon
Privileged Identity Management

Microsoft 365

Security

Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.

Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM

Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.

Icon
Self-Service Password Reset

Microsoft 365

Security

Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.

Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout

Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.

Icon
Mobile App Protection

Security

Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.

Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)

Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.

Icon
Intune Device Enrollment

Microsoft 365

Security

Problem: Without central device management, compliance control and enforceable security policies are missing.

Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations

Result: Existing endpoints centrally managed — the foundation for all further scenarios.

Icon
Intune Autopilot

Microsoft 365

Security

Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.

Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices

Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.

Icon
Intune LAPS

Security

Microsoft 365

Problem: Static local admin passwords pose a significant security risk during attacks.

Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team

Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.

Icon
Exchange Online Mailflow

Microsoft 365

Security

Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.

Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over

Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.

Icon
OneDrive Migration

Microsoft 365

Problem: Traditional network drives hinder mobile work and cause high operational overhead.

Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption

Result: Secure, mobile file access and a file server that can be switched off on a planned date.

Icon
MS Teams Collaboration

Microsoft 365

Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.

Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live

Result: Unified, scalable, and secure Teams collaboration across all organizational units.

Icon
External Collaboration

Microsoft 365

Problem: External collaboration must not run through shadow IT or insecure channels.

Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook

Result: Efficient, secure collaboration with partners directly in Microsoft Teams.

Icon
Microsoft Purview DLP

Security

Microsoft 365

Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.

Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting

Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.

Icon
Microsoft Purview Information Protection

Security

Microsoft 365

Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.

Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout

Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.

Icon
Microsoft Bookings

Microsoft 365

Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.

Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption

Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.

Icon
WSUS Replacement

Microsoft 365

Security

Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.

Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan

Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.

Icon
M365 Apps Configuration

Microsoft 365

Security

Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.

Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group

Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.

Icon
Universal Print

Microsoft 365

Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.

Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan

Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.

Icon
Chat with Your Own Data

Data & AI

Azure

Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.

Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup

Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.

Icon
Azure Landing Zone Setup

Azure

Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.

Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose

Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.

Icon
Azure Backup

Azure

Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.

Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook

Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.

Icon
Azure Data Archiving

Azure

Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.

Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy

Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.

Icon
Defender for Business

Security

Microsoft 365

Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.

Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook

Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.

Icon
Cloud Apps Discovery

Security

Microsoft 365

Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.

Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook

Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.

Icon
Defender for Cloud Apps

Security

Microsoft 365

Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.

Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware

Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.

Icon
Windows Hello for Business

Security

Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.

Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials

Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.

Icon
Microsoft Foundry Platform Setup

Data & AI

Azure

Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.

Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment

Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.

Icon
M365 License Optimization

Microsoft 365

Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.

Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center

Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.

Icon
Intune Mobile Device Configuration

Microsoft 365

Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.

Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout

Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.

Icon
Microsoft Copilot Readiness Assessment + Copilot Chat

Microsoft 365

Data & AI

Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.

Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules

Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.

Icon
Microsoft 365 Copilot Activation & Rollout

Microsoft 365

Data & AI

Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.

Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live

Result: Copilot active for a defined user group, with enabled users and usage you can measure.

Icon
M365 Tenant Readiness

Microsoft 365

Security

Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.

Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access

Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.

Icon
MFA & Conditional Access

Microsoft 365

Security

Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.

Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live

Result: Verifiably secured access with clear policies and high usability.

Icon
Defender for Office 365

Microsoft 365

Security

Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.

Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material

Result: A documented, tuned email security architecture your team can operate.

Icon
Privileged Identity Management

Microsoft 365

Security

Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.

Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM

Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.

Icon
Self-Service Password Reset

Microsoft 365

Security

Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.

Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout

Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.

Icon
Mobile App Protection

Security

Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.

Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)

Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.

Icon
Intune Device Enrollment

Microsoft 365

Security

Problem: Without central device management, compliance control and enforceable security policies are missing.

Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations

Result: Existing endpoints centrally managed — the foundation for all further scenarios.

Icon
Intune Autopilot

Microsoft 365

Security

Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.

Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices

Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.

Icon
Intune LAPS

Security

Microsoft 365

Problem: Static local admin passwords pose a significant security risk during attacks.

Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team

Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.

Icon
Exchange Online Mailflow

Microsoft 365

Security

Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.

Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over

Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.

Icon
OneDrive Migration

Microsoft 365

Problem: Traditional network drives hinder mobile work and cause high operational overhead.

Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption

Result: Secure, mobile file access and a file server that can be switched off on a planned date.

Icon
MS Teams Collaboration

Microsoft 365

Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.

Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live

Result: Unified, scalable, and secure Teams collaboration across all organizational units.

Icon
External Collaboration

Microsoft 365

Problem: External collaboration must not run through shadow IT or insecure channels.

Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook

Result: Efficient, secure collaboration with partners directly in Microsoft Teams.

Icon
Microsoft Purview DLP

Security

Microsoft 365

Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.

Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting

Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.

Icon
Microsoft Purview Information Protection

Security

Microsoft 365

Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.

Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout

Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.

Icon
Microsoft Bookings

Microsoft 365

Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.

Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption

Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.

Icon
WSUS Replacement

Microsoft 365

Security

Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.

Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan

Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.

Icon
M365 Apps Configuration

Microsoft 365

Security

Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.

Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group

Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.

Icon
Universal Print

Microsoft 365

Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.

Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan

Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.

Icon
Chat with Your Own Data

Data & AI

Azure

Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.

Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup

Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.

Icon
Azure Landing Zone Setup

Azure

Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.

Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose

Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.

Icon
Azure Backup

Azure

Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.

Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook

Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.

Icon
Azure Data Archiving

Azure

Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.

Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy

Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.

Icon
Defender for Business

Security

Microsoft 365

Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.

Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook

Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.

Icon
Cloud Apps Discovery

Security

Microsoft 365

Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.

Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook

Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.

Icon
Defender for Cloud Apps

Security

Microsoft 365

Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.

Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware

Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.

Icon
Windows Hello for Business

Security

Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.

Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials

Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.

Icon
Microsoft Foundry Platform Setup

Data & AI

Azure

Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.

Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment

Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.

Icon
M365 License Optimization

Microsoft 365

Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.

Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center

Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.

Icon
Intune Mobile Device Configuration

Microsoft 365

Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.

Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout

Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.

Icon
Microsoft Copilot Readiness Assessment + Copilot Chat

Microsoft 365

Data & AI

Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.

Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules

Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.

Icon
Microsoft 365 Copilot Activation & Rollout

Microsoft 365

Data & AI

Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.

Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live

Result: Copilot active for a defined user group, with enabled users and usage you can measure.

Icon
M365 Tenant Readiness

Microsoft 365

Security

Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.

Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access

Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.

Icon
MFA & Conditional Access

Microsoft 365

Security

Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.

Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live

Result: Verifiably secured access with clear policies and high usability.

Icon
Defender for Office 365

Microsoft 365

Security

Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.

Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material

Result: A documented, tuned email security architecture your team can operate.

Icon
Privileged Identity Management

Microsoft 365

Security

Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.

Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM

Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.

Icon
Self-Service Password Reset

Microsoft 365

Security

Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.

Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout

Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.

Icon
Mobile App Protection

Security

Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.

Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)

Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.

Icon
Intune Device Enrollment

Microsoft 365

Security

Problem: Without central device management, compliance control and enforceable security policies are missing.

Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations

Result: Existing endpoints centrally managed — the foundation for all further scenarios.

Icon
Intune Autopilot

Microsoft 365

Security

Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.

Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices

Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.

Icon
Intune LAPS

Security

Microsoft 365

Problem: Static local admin passwords pose a significant security risk during attacks.

Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team

Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.

Icon
Exchange Online Mailflow

Microsoft 365

Security

Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.

Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over

Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.

Icon
OneDrive Migration

Microsoft 365

Problem: Traditional network drives hinder mobile work and cause high operational overhead.

Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption

Result: Secure, mobile file access and a file server that can be switched off on a planned date.

Icon
MS Teams Collaboration

Microsoft 365

Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.

Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live

Result: Unified, scalable, and secure Teams collaboration across all organizational units.

Icon
External Collaboration

Microsoft 365

Problem: External collaboration must not run through shadow IT or insecure channels.

Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook

Result: Efficient, secure collaboration with partners directly in Microsoft Teams.

Icon
Microsoft Purview DLP

Security

Microsoft 365

Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.

Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting

Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.

Icon
Microsoft Purview Information Protection

Security

Microsoft 365

Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.

Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout

Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.

Icon
Microsoft Bookings

Microsoft 365

Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.

Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption

Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.

Icon
WSUS Replacement

Microsoft 365

Security

Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.

Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan

Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.

Icon
M365 Apps Configuration

Microsoft 365

Security

Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.

Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group

Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.

Icon
Universal Print

Microsoft 365

Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.

Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan

Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.

Icon
Chat with Your Own Data

Data & AI

Azure

Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.

Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup

Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.

Icon
Azure Landing Zone Setup

Azure

Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.

Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose

Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.

Icon
Azure Backup

Azure

Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.

Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook

Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.

Icon
Azure Data Archiving

Azure

Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.

Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy

Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.

Icon
Defender for Business

Security

Microsoft 365

Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.

Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook

Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.

Icon
Cloud Apps Discovery

Security

Microsoft 365

Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.

Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook

Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.

Icon
Defender for Cloud Apps

Security

Microsoft 365

Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.

Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware

Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.

Icon
Windows Hello for Business

Security

Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.

Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials

Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.

Icon
Microsoft Foundry Platform Setup

Data & AI

Azure

Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.

Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment

Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.

Icon
M365 License Optimization

Microsoft 365

Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.

Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center

Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.

Icon
Intune Mobile Device Configuration

Microsoft 365

Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.

Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout

Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.

Icon
Microsoft Copilot Readiness Assessment + Copilot Chat

Microsoft 365

Data & AI

Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.

Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules

Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.

Icon
Microsoft 365 Copilot Activation & Rollout

Microsoft 365

Data & AI

Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.

Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live

Result: Copilot active for a defined user group, with enabled users and usage you can measure.

Icon
M365 Tenant Readiness

Microsoft 365

Security

Problem: Misconfigurations in the tenant lead to security gaps, licensing issues, and compliance risks.

Scope: Review global settings in Admin Center and Entra ID - Assess identity synchronization: Entra Connect Sync vs Cloud Sync against the September 2026 deadline - Consistent UPN strategy and hardening of admin accounts - Onboard domains, assess DNS and network access

Result: A stable, license-compliant M365 tenant as a reliable foundation for all subsequent projects.

Icon
MFA & Conditional Access

Microsoft 365

Security

Problem: Uncontrolled access is a primary risk. Microsoft now deploys its own managed Conditional Access policies into eligible tenants and switches them on after 45 days, planned or not.

Scope: Gather requirements per user group - Policies for location, device/platform, apps, sign-in risk on P2 - Block legacy authentication, activate session controls - Structured rollout: Report-Only → Pilot → Go-Live

Result: Verifiably secured access with clear policies and high usability.

Icon
Defender for Office 365

Microsoft 365

Security

Problem: Phishing and malware via email are among the most common attack vectors in mid-market companies. Since 1 July 2026, Defender for Office 365 Plan 1 sits in Microsoft 365 E3 and Office 365 E3 as well as Business Premium.

Scope: Preset or custom decision per recipient group - Safe Attachments with Dynamic Delivery and Safe Links checked at time of click - Anti-phishing and impersonation protection on a hardened anti-spam and anti-malware baseline - Microsoft Teams message protection, alerting, and end-user awareness material

Result: A documented, tuned email security architecture your team can operate.

Icon
Privileged Identity Management

Microsoft 365

Security

Problem: Permanently assigned admin roles are the preferred target for attackers and insider threats.

Scope: Inventory current Entra ID role assignments - Identify critical roles for PIM protection - Configure just-in-time access, approval workflows, and access reviews - Migrate permanent assignments, including role-assignable groups, into PIM

Result: Every privileged activation time-bound, justified and auditable, approved where the role requires it - even if an admin account is compromised.

Icon
Self-Service Password Reset

Microsoft 365

Security

Problem: Forgotten passwords block employees and burden the helpdesk. From 7 September 2026, SSPR accepts only methods a user registered themselves — synced phone numbers stop counting.

Scope: Implement SSPR in Microsoft Entra ID - Method set decided against the 2027 method retirements - Configure hybrid environments (writeback to on-premises AD) - Structured pilot and staged rollout

Result: Password resets handled by users instead of the helpdesk, writeback validated, and faster resolution for end users.

Icon
Mobile App Protection

Security

Problem: Mobile devices are the foundation of modern work — corporate data must be protected there too.

Scope: App Protection Policies for corporate data in the Microsoft 365 apps and your own apps - Block access when the app protection policy is missing - Selective wipe of corporate data on theft, loss or offboarding, with the device and personal data untouched - Works on managed and unmanaged devices (BYOD)

Result: Protected corporate data on iOS and Android — without enrolling a single personal phone.

Icon
Intune Device Enrollment

Microsoft 365

Security

Problem: Without central device management, compliance control and enforceable security policies are missing.

Scope: Integrate existing Windows 11 devices into Microsoft Intune - Configure enrollment restrictions and compliance policies - Prepare device-based access control via Conditional Access - Documentation and handouts for ongoing operations

Result: Existing endpoints centrally managed — the foundation for all further scenarios.

Icon
Intune Autopilot

Microsoft 365

Security

Problem: Manual provisioning ties up resources, delays productive starts, and is error-prone.

Scope: Windows Autopilot (user-driven or pre-provisioned) or device preparation - Set up dynamic device groups and the Enrollment Status Page - Deploy Microsoft 365 Apps, Edge and Company Portal - End-to-end tests with pilot devices

Result: Provisioning time measured in your pilot instead of estimated, employees productive on day one, and IT no longer touching the hardware.

Icon
Intune LAPS

Security

Microsoft 365

Problem: Static local admin passwords pose a significant security risk during attacks.

Scope: Implement Windows LAPS via Intune - Retire the shared static local admin password on every device - Decommission legacy Microsoft LAPS - Operations handbook for your IT team

Result: Dynamic, centrally managed admin passwords and a verifiably reduced attack surface.

Icon
Exchange Online Mailflow

Microsoft 365

Security

Problem: Microsoft 365 filters spoofed mail by default, but nobody publishes DKIM and DMARC for your domains - that is the gap attackers use.

Scope: Optimize SPF, DKIM, and DMARC records - Map the mail path and every sending system - Staged DMARC rollout: monitoring → quarantine → reject - Restrict auto-forwarding, document and hand over

Result: Your mail authenticates cleanly, spoofing of your domains blocked, forwarding restricted, and deliverability to customers and partners improved.

Icon
OneDrive Migration

Microsoft 365

Problem: Traditional network drives hinder mobile work and cause high operational overhead.

Scope: Inventory data, plan pilot with 5-10 users - Migrate home directories including Known Folder Move - Optimize sharing and sync settings - Training and communication packages for adoption

Result: Secure, mobile file access and a file server that can be switched off on a planned date.

Icon
MS Teams Collaboration

Microsoft 365

Problem: Without clear guidelines, Teams usage remains fragmented and inefficient.

Scope: Naming policy and creation restriction in Microsoft Entra ID - Lifecycle process for teams with expiration and owner renewal - App baseline and approval route for new apps - Guest access decision and owner reassignment before expiration goes live

Result: Unified, scalable, and secure Teams collaboration across all organizational units.

Icon
External Collaboration

Microsoft 365

Problem: External collaboration must not run through shadow IT or insecure channels.

Scope: Inventory existing guest accounts, external sharing, and cross-tenant settings - Configure B2B guest access, cross-tenant access settings, and Teams shared channels with a pilot partner - Conditional Access for guests, published labels aligned for external sharing - Decision matrix, partner onboarding and offboarding guide, operational runbook

Result: Efficient, secure collaboration with partners directly in Microsoft Teams.

Icon
Microsoft Purview DLP

Security

Microsoft 365

Problem: Without Data Loss Prevention, sensitive data can leave the organization uncontrolled — via email, SharePoint sharing, or Teams messages. The first time anyone notices is when the data has already left.

Scope: Data inventory and classification strategy for sensitive information types - DLP for Exchange, SharePoint, OneDrive, plus Teams chat on E5 - Phased rollout: review → Simulation → Policy Tips → Enforcement - DLP Alerts Dashboard and incident reporting

Result: Verifiably protected corporate data with clear DLP policies and audit-ready documentation.

Icon
Microsoft Purview Information Protection

Security

Microsoft 365

Problem: Without sensitivity labels, neither employees nor systems know which data is sensitive. Unclassified data cannot be protected.

Scope: Define label taxonomy with 4-6 core labels - Configure sensitivity labels for documents, emails, and containers - Set up default labels and mandatory labeling - Pilot group and phased rollout

Result: Structured data classification as the foundation for DLP, Copilot, and GDPR compliance.

Icon
Microsoft Bookings

Microsoft 365

Problem: Appointment scheduling via email ping-pong wastes time and nerves. External tools like Calendly add costs and data leakage to third parties.

Scope: Activate Bookings and set up shared booking pages - Teams integration for online meeting links - Standardized scheduling policies: time increments, lead time, booking horizon - Governance concept and end-user adoption

Result: Professional appointment booking directly in Microsoft 365 — no third-party tools, no workflow disruption.

Icon
WSUS Replacement

Microsoft 365

Security

Problem: Microsoft deprecated WSUS with Windows Server 2025. It still runs and still gets security updates, but no new features and no further development. The migration path to Intune and Windows Autopatch remains unclear for most IT teams.

Scope: Inventory existing WSUS infrastructure - Configure update ring policies in Intune and switch the scan source - Set up Autopatch groups with staged deployment rings - Create WSUS decommissioning plan

Result: Cloud-based patch management with automated compliance and audit-ready reporting — WSUS server ready for decommissioning.

Icon
M365 Apps Configuration

Microsoft 365

Security

Problem: Office Apps without central configuration: different versions, no macro security, no update channel management. Since the July 2026 release, Semi-Annual and Monthly Enterprise Channel are one channel — devices moved without anyone touching a policy.

Scope: Define update channel strategy (Monthly Enterprise as standard) - Cloud Policy service for macro security and add-in management - Optional M365 Apps Security Baseline via Intune - Phased rollout starting with the pilot group

Result: Centrally managed Office Apps with consistent versions, security baseline, and audit-ready documentation.

Icon
Universal Print

Microsoft 365

Problem: On-premises print servers consume hardware, require maintenance, and need driver management on every endpoint. Remote employees cannot print without VPN. Universal Print is already included in Business Premium, E3, and E5 — every licensed user adds 100 print jobs a month to one tenant-wide pool.

Scope: Printer inventory and compatibility assessment - Universal Print Connector and printer registration - Configure Intune Printer Provisioning and job pool monitoring - Phased migration and print server decommissioning plan

Result: Cloud-based print management without print servers — printers deployed via Intune, license pool controlled.

Icon
Chat with Your Own Data

Data & AI

Azure

Problem: Company knowledge sits in SharePoint, file shares, and databases — but nobody finds it. And every time someone leaves, the knowledge of where things are leaves with them.

Scope: Use case definition and data preparation - Retrieval path: AI Search hybrid index or Foundry IQ - RAG pattern wired up on your existing Microsoft Foundry platform - Security and evaluation setup

Result: AI-powered chat that searches company documents and answers precisely — with source citations and access control.

Icon
Azure Landing Zone Setup

Azure

Problem: Without a structured landing zone, Azure environments grow wild: uncontrolled subscriptions, missing governance, no network isolation. Every subsequent Azure project suffers from the missing foundation.

Scope: Management group hierarchy and dedicated subscriptions - Hub-and-spoke networking with firewall and VPN - Azure Policy initiatives for governance and compliance - Deployment parameter set for the landing zone accelerator you choose

Result: Structured Azure environment following Cloud Adoption Framework — secure, scalable, and ready for workload migrations.

Icon
Azure Backup

Azure

Problem: Mid-market backup is patchy: some VMs backed up, others not. No tested restore process. And the on-premises backup software behind it carries its own annual licence on top.

Scope: Recovery Services Vault and Backup Vault, hardened against ransomware - Backup policies for VMs, SQL, Files, disks, blobs, PostgreSQL - Azure Policy for automatic backup enforcement - Five real restores with measured recovery times, plus runbook

Result: Reliable Azure backup with tested restore processes, automatic enforcement, and audit-ready documentation.

Icon
Azure Data Archiving

Azure

Problem: Old data sits in expensive storage tiers, retention requirements are met manually, tape backups are a dying model. Azure Archive Storage is the lowest-cost storage tier Azure offers — but rarely configured.

Scope: Data classification by access frequency and retention requirements - Lifecycle management policies for automatic tiering - Immutable storage (WORM) for regulated data - Document rehydration strategy

Result: Automated data archiving on the lowest-cost storage tier, with WORM compliance and a rehydration runbook measured in a real test.

Icon
Defender for Business

Security

Microsoft 365

Problem: Most mid-market companies have antivirus — but no Endpoint Detection & Response. Attacks are detected but not automatically stopped. Defender for Business is included in M365 Business Premium, for tenants up to 300 users.

Scope: Device onboarding for Windows, macOS, iOS, Android - Next-Gen Protection and firewall policy review - Web content filtering plus ASR rules and Controlled Folder Access in audit mode first, with a dated switch to block - Automatic Attack Disruption, vulnerability baseline, and incident response playbook

Result: Complete endpoint security with EDR, automatic attack disruption, and audit-ready documentation.

Icon
Cloud Apps Discovery

Security

Microsoft 365

Problem: Shadow IT is a visibility problem: every unsanctioned app is a data leak and GDPR risk, and a policy cannot govern an app nobody knows is in use. Cloud App Discovery is included in M365 E3 but rarely activated.

Scope: Anonymization and works council frame, then continuous log feed - Risk analysis of top 50 apps - App discovery policies and sanctioning strategy - Shadow IT governance playbook

Result: Full transparency over the cloud apps in use — top apps risk-assessed, blocking strategy in place, governance process running.

Icon
Defender for Cloud Apps

Security

Microsoft 365

Problem: Knowing which cloud apps are in use is not protection. Users download confidential files to personal devices, and the OAuth apps in your tenant were consented to one at a time, with nobody holding the list. Reporting a leak afterwards comes too late — the control has to sit in the session itself.

Scope: App connectors for Microsoft 365 and your prioritized SaaS apps - OAuth app review and running app governance policies - Conditional Access App Control for critical apps - Three session policies: block downloads to unmanaged devices, inspect uploads, block malware

Result: Controlled cloud app landscape with session control, OAuth governance, and Conditional Access App Control — audit-ready.

Icon
Windows Hello for Business

Security

Problem: A password can be phished, guessed, and reused, and every forgotten one lands on your helpdesk. Windows Hello for Business offers passwordless authentication — included in every Windows Pro, Enterprise, and Education license.

Scope: Cloud Kerberos Trust as the hybrid path (no PKI needed) - Intune WHfB Settings Catalog profile - Conditional Access: WHfB as authentication strength - Pilot group and phased rollout with training materials

Result: Passwordless authentication with biometrics or PIN — phishing-resistant, helpdesk-relieving, Zero Trust compliant.

Icon
Microsoft Foundry Platform Setup

Data & AI

Azure

Problem: Leadership expects AI results, but there is no governed Azure platform to deliver them on.

Scope: Foundry resource and project in Germany West Central by default - RBAC role model along least privilege - EU data residency via deployment type Data Zone Standard - Azure Budgets, cost alerts, and first chat model deployment

Result: A production-ready Foundry environment with EU data residency, active cost control, and a documented governance baseline.

Icon
M365 License Optimization

Microsoft 365

Problem: The license catalog has 100+ SKUs and add-ons — reconciling them per user is impossible by hand, so most mid-market tenants default to E5 for everyone and overpay. The 1 July 2026 suite reshuffle and price step invalidated every calculation made before it.

Scope: Inventory licenses, add-ons, and trial subscriptions across all CSP providers - Analyze 180 days of usage per user and surface orphaned licenses - Model SKU scenarios with annual savings and capability gaps - Operationalize group-based licensing on Entra ID security groups, assigned in the Microsoft 365 admin center

Result: A right-sized license posture with an approved cost savings report, group-based licensing in production, and a quarterly review your team runs itself.

Icon
Intune Mobile Device Configuration

Microsoft 365

Problem: Phones and tablets are enrolled in Intune but still unconfigured — Wi-Fi set up by hand, no restrictions, no compliance signal for Conditional Access to act on.

Scope: Restriction profiles for iOS/iPadOS, Android personally owned work profile, and fully managed - Restriction baseline per device class with UX-relevant settings agreed up front - Wi-Fi and VPN profiles with certificates where authentication needs them - Compliance policies per platform and a filter-based wave rollout

Result: Every enrolled mobile device configured, compliant, and reporting a signal Conditional Access can use.

Icon
Microsoft Copilot Readiness Assessment + Copilot Chat

Microsoft 365

Data & AI

Problem: Employees are asking for AI, and Copilot Chat is already switched on in most tenants with E3, E5, or Business Premium. Nobody decided that, and nobody can say whether Copilot would even reach the work data.

Scope: Readiness assessed across general, Copilot Chat, and Copilot - Work context checked including on-premises data and file shares - SharePoint permissions and sharing exposure Copilot would surface - Copilot Chat decided, configured, and documented with usage rules

Result: A documented readiness verdict, a governed Copilot Chat, and a prioritized action plan for Microsoft 365 Copilot.

Icon
Microsoft 365 Copilot Activation & Rollout

Microsoft 365

Data & AI

Problem: The licenses sit in the tenant and the invoice is running, but nobody opened Copilot. Without a defined user group, recognizable use cases, and enablement, a rollout stalls before it starts.

Scope: Copilot readiness status confirmed before rollout - Initial user group and rollout approach defined - Training, usage rules, and communication ready before assignment - Consumption-billed features switched off before licences go live

Result: Copilot active for a defined user group, with enabled users and usage you can measure.

In 30 minutes we will show you the blueprint for your specific use case

Find the right blueprint

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case

Find the right blueprint

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case

Find the right blueprint

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH

In 30 minutes we will show you the blueprint for your specific use case

Find the right blueprint

Logo Image

DAMALO | AI-native Microsoft Partner. Making IT expertise accessible and affordable for mid-market companies.

Brand Logo
Brand Logo
Bitkom logo

© 2026 DAMALO GmbH