Cloud & Email
Set up properly once, instead of accumulated in a hurry.
Nearly every tenant we inherit grew by accretion — accounts created for people who left, sharing set wide because a permission problem needed solving on a deadline, licences bought for a project and never released. None of it was a mistake at the time and all of it compounds. This is the work of getting identity, access and mail security into a state somebody deliberately chose, and then keeping it there.
- DMARC, not left in monitor mode
- EnforcedDMARC, not left in monitor mode
- MFA and access by group, not per person
- ConsistentMFA and access by group, not per person
- External sharing found and decided
- AuditedExternal sharing found and decided
Sounds like
You might recognise one of these.
We are paying for licences for people who left.
Nobody knows which files are shared outside the company.
We had a phishing email get through and we cannot tell how far it went.
Multi-factor is on for some people and we could not tell you which.
What this includes
The work, specifically.
Not every engagement needs all of it. This is the range we cover and what each part is actually for.
Identity and access
One source of identity, groups that mean something, conditional access and multi-factor applied consistently rather than per person.
Mail security
SPF, DKIM and DMARC actually enforcing rather than in monitor mode indefinitely, plus filtering and the reporting to see what got through.
Sharing and data governance
Finding what is currently shared externally, deciding what should be, and setting defaults so the next document does not repeat it.
Tenant migration and consolidation
Moving between tenants or merging them after an acquisition, including mail, files and identity, with a cutover plan and a way back.
Licence review
What you are paying for, who is using it, and which tier each person actually needs. Usually the fastest money this division saves.
What you get
Deliverables, not documents.
- A documented identity and access model
- Conditional access and MFA applied estate-wide, with exceptions listed and justified
- DMARC moved to enforcement, with the reporting to prove nothing legitimate broke
- An external-sharing audit and revised defaults
- A licence position with recommendations and their annual value
Shapes
How this usually runs.
Tenant review
1–2 weeksIdentity, access, sharing, mail authentication and licensing as they stand, with the risks and the waste ranked.
Remediation and hardening
3–6 weeksFixing what the review found, in an order that does not lock anybody out of their own mail on a Monday morning.
Managed administration
OngoingJoiners and leavers, access changes, licence position and tenant configuration kept in the state you chose.
Tooling
What we build it with.
No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.
- Platforms
- Governance
Questions
Cloud & email, honestly.
Whichever you are already on, in most cases. Migrating platforms is rarely worth the disruption on its own — the problems we are usually asked about are configuration problems, and they exist identically on both. Where a move genuinely is warranted, it is because of a specific requirement, and we would name it.
It can, which is why nobody should move straight to enforcement. We run it in monitor mode first and read the reports until every legitimate sender is accounted for — including the invoicing system and the marketing tool nobody remembered. Enforcement comes after that, not before.
We can, or you keep your existing reseller relationship and we just tell you what to buy. The review is worth having either way, and it is not conditional on moving the purchasing.
Often paired with
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.