
Tenant Hygiene
Nearly every tenant we inherit has the same issues: legacy authentication still enabled somewhere, global admin handed out to people who don't need it, no conditional access, mailbox forwarding rules nobody reviewed, and licenses assigned to employees who left last year.
We start with a full audit and a prioritized remediation plan - security first, cost second. Recovering unused licenses often pays for a meaningful share of the engagement.
Day-to-Day
Entra ID and conditional access: MFA enforced, risky sign-ins blocked, device compliance required for access to company data.
Exchange Online: mail flow, anti-phishing and anti-spoofing policies, SPF, DKIM and DMARC configured correctly so your invoices stop landing in spam.
Teams and SharePoint: sane permission structures, external sharing policies, and retention settings that match how your business actually collaborates.
Backup: third-party backup of mail, OneDrive and SharePoint, because Microsoft's retention is not a backup and a compromised account can delete a lot in an afternoon.
What's Next
Microsoft 365 Copilot inherits your permissions - which means it will happily surface that HR folder somebody over-shared in 2022. Before any AI rollout, sensitive content needs to be labeled and oversharing cleaned up.
We run that cleanup first, then pilot Copilot with the teams most likely to get value, measure it, and expand only where it earns the license cost. No fleet-wide purchase on faith.