Skip to content

Cloud & Email

Set up properly once, instead of accumulated in a hurry.

Nearly every tenant we inherit grew by accretion — accounts created for people who left, sharing set wide because a permission problem needed solving on a deadline, licences bought for a project and never released. None of it was a mistake at the time and all of it compounds. This is the work of getting identity, access and mail security into a state somebody deliberately chose, and then keeping it there.

DMARC, not left in monitor mode
EnforcedDMARC, not left in monitor mode
MFA and access by group, not per person
ConsistentMFA and access by group, not per person
External sharing found and decided
AuditedExternal sharing found and decided

Sounds like

You might recognise one of these.

  • We are paying for licences for people who left.

  • Nobody knows which files are shared outside the company.

  • We had a phishing email get through and we cannot tell how far it went.

  • Multi-factor is on for some people and we could not tell you which.

What this includes

The work, specifically.

Not every engagement needs all of it. This is the range we cover and what each part is actually for.

  • Identity and access

    One source of identity, groups that mean something, conditional access and multi-factor applied consistently rather than per person.

  • Mail security

    SPF, DKIM and DMARC actually enforcing rather than in monitor mode indefinitely, plus filtering and the reporting to see what got through.

  • Sharing and data governance

    Finding what is currently shared externally, deciding what should be, and setting defaults so the next document does not repeat it.

  • Tenant migration and consolidation

    Moving between tenants or merging them after an acquisition, including mail, files and identity, with a cutover plan and a way back.

  • Licence review

    What you are paying for, who is using it, and which tier each person actually needs. Usually the fastest money this division saves.

What you get

Deliverables, not documents.

  • A documented identity and access model
  • Conditional access and MFA applied estate-wide, with exceptions listed and justified
  • DMARC moved to enforcement, with the reporting to prove nothing legitimate broke
  • An external-sharing audit and revised defaults
  • A licence position with recommendations and their annual value

Shapes

How this usually runs.

  1. Tenant review

    1–2 weeks

    Identity, access, sharing, mail authentication and licensing as they stand, with the risks and the waste ranked.

  2. Remediation and hardening

    3–6 weeks

    Fixing what the review found, in an order that does not lock anybody out of their own mail on a Monday morning.

  3. Managed administration

    Ongoing

    Joiners and leavers, access changes, licence position and tenant configuration kept in the state you chose.

Tooling

What we build it with.

No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.

Platforms
  • Microsoft 365
  • Google Workspace
  • Microsoft Entra ID
Mail
  • SPF, DKIM and DMARC
  • Mail filtering
  • DMARC aggregate reporting
Governance
  • Conditional access
  • Sharing and retention policy
  • Licence reporting

Questions

Cloud & email, honestly.

  • Whichever you are already on, in most cases. Migrating platforms is rarely worth the disruption on its own — the problems we are usually asked about are configuration problems, and they exist identically on both. Where a move genuinely is warranted, it is because of a specific requirement, and we would name it.

  • It can, which is why nobody should move straight to enforcement. We run it in monitor mode first and read the reports until every legitimate sender is accounted for — including the invoicing system and the marketing tool nobody remembered. Enforcement comes after that, not before.

  • We can, or you keep your existing reseller relationship and we just tell you what to buy. The review is worth having either way, and it is not conditional on moving the purchasing.

Next step

Tell us what’s breaking.

Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.