Microsoft 365 as a working environment that hangs together.
I design, migrate and support Microsoft 365 environments so that identities, devices, email, data and collaboration fit together, from licensing through to security and governance.
Starting point
Microsoft 365 is in use in many companies without the environment ever having been designed as a whole. Licences, identities, devices, permissions and file structures have grown side by side over the years. Security features that are already paid for go unused, and new topics such as Copilot make existing problems with permissions and file storage worse.
Goal
A cleanly structured and secured Microsoft 365 environment: the right licences, protected identities, managed devices, clear rules for Teams, SharePoint and OneDrive, and documentation your in-house IT can carry on itself. That lays the basis for collaboration, compliance and AI.
Services
Microsoft 365 does not automatically mean Windows. I design and run fully Mac-based company environments just as readily, with Intune, Entra ID and Apple Business Manager — from projects I know these at over 150 staff.
-
Licence advice and tenant review
A review of licensing and the existing configuration with a concrete recommendation: what is genuinely needed, what is already paid for, and which measures come first?
-
Tenant design and governance
Built to clear rules: identities, policies, naming conventions, storage locations and access rights for Teams, SharePoint and OneDrive.
-
Identity and access management
Entra ID with multi-factor authentication, Conditional Access, a role model and protection for privileged accounts.
-
Device management
Managing, securing and provisioning Windows and macOS devices centrally and to a standard, with Microsoft Intune and, for Apple devices, through Apple Business Manager: compliance policies, FileVault and BitLocker, software deployment, device configuration and automated onboarding. iPhones and Android devices run in the same system. Building device management from scratch or migrating from another MDM.
-
Migration and go-live
Moving from Exchange, IMAP, Google Workspace or file servers to Exchange Online and SharePoint, in waves and without data loss.
-
Security and compliance
Microsoft Defender, technical data protection and compliance settings, retention policies and backup for Microsoft 365.
-
Training and adoption
Briefings for staff and in-house IT so new structures actually take hold day to day.
-
Copilot readiness
Preparing permissions, data quality and governance so Microsoft 365 Copilot can be introduced safely.
What I work with — and why.
These are the building blocks I use, depending on the requirement.
- Entra ID
- Central identities, roles and single sign-on for Microsoft 365 and connected applications.
- Conditional Access
- Controlling access by user, device, location and risk.
- Intune
- Device management for Windows, macOS, iOS and Android: configuration, compliance, app deployment, BitLocker and FileVault.
- Exchange Online
- Mailboxes, rules, archiving and protection against spam and phishing.
- SharePoint, Teams, OneDrive
- File storage and collaboration with governance rules and permissions you can follow.
- Microsoft Defender
- Protection for devices, email and identities within Microsoft 365.
- Privileged Identity Management
- Administrator rights granted for a limited time, with a reason and an audit trail.
How a project usually runs.
-
01
Analysis
Tenant review, licences, requirements and goals.
-
02
Design
A target picture for identities, devices, governance and migration, with sequence and effort.
-
03
Delivery
A gradual rollout and migration during normal operation: security first, then structure.
-
04
Operation
Documentation, training and, if you want it, an ongoing managed service.
What clients want to know in advance.
Not finding what you want to know? Ask me directly.
Usually yes. Most tenants have grown over the years. A review shows which security and governance features are already licensed but not switched on, and where permissions and structures should be cleaned up.
For many small and mid-sized companies Business Premium is a sensible starting point, because device management and important security features are already included. Which licence fits, however, depends on what you actually need. I do not recommend the larger licence automatically just because it can do more.
Through Intune and Apple Business Manager, on an equal footing with Windows devices: automated provisioning, compliance policies, FileVault and software deployment. For heavily Apple-based environments a specialist MDM such as Mosyle or Jamf can be the better choice. I support both and handle migrations between MDM systems.
Want to talk through a specific project?
Send me a couple of lines about it, or just call. You reach me directly, no call centre.