Microsoft 365

Microsoft 365: tenant, identities and operations

Tenant baseline, Microsoft Entra ID, Exchange, Teams and SharePoint with clear rules.

  • Tenant baseline and hardening based on documented rules
  • Identity and access with Microsoft Entra ID, MFA and Conditional Access
  • Governance for Exchange Online, Teams and SharePoint, migrations from on-premises

A Microsoft 365 tenant grows with every project: new groups, new shares, new exceptions. We help make sure the foundation holds when applications, compliance requirements and security features are built on top of it.

Tenant baseline

New tenant or grown environment: we review the basic settings against Microsoft’s current recommendations and against your own standards, document deviations and implement the agreed changes. This covers organisation settings, domains and DNS records, group-based licensing, administrator roles and break-glass accounts.

  • Inventory with Secure Score, settings export and conversations with the people responsible
  • Administrator role concept with as few standing privileges as possible
  • Documented configuration that serves as the reference for later changes

Identity and access

Microsoft Entra ID is where security and usability meet. We set up multi-factor authentication with suitable methods, design Conditional Access policies with a clear purpose and explicit exceptions, and connect on-premises directories through Entra Connect or Cloud Sync.

  • Authentication methods, registration and self-service password reset
  • Conditional Access with pilot and report-only mode before enforcement
  • Guests, external collaboration and entitlement management with expiry dates

Collaboration and governance

Exchange Online, Teams and SharePoint work without rules, but not well for long. Together with you we define who may create teams and sites, how naming, classification and retention look, and how external sharing is controlled. For mailboxes we take care of transport rules, anti-spam and anti-phishing policies and the protection of outbound mail with SPF, DKIM and DMARC.

Migration

When moving away from on-premises Exchange, file or SharePoint environments we plan sequence, communication and fallback options, carry out the migration and decommission the legacy systems in a controlled way afterwards.

Talk to us about this

Tell us what it is about. A person will reply.

German office (sales and engineering)

Berlin, Germany