Capability directory

The Microsoft and infrastructure work we cover.

Explore nine areas of project work. A migration may also require identity, device or licensing changes; we identify those connections and agree the scope before delivery.

Entra ID & Identity

Configure and test sign-in, administrator access and the rules that limit it.

  • Microsoft Entra ID
  • Conditional Access
  • Multifactor authentication
  • Passkeys, FIDO2 and phishing-resistant authentication
  • Privileged Identity Management
  • Administrator-role cleanup
  • Emergency-access accounts
  • Entra Connect and hybrid identity
  • Access reviews, guest access and application consent
  • Identity investigation and access evidence

Defender, Purview & Security

Deploys, enforces and tests the protections the business already licenses.

  • Microsoft Defender for Office 365
  • Anti-phishing, anti-spam, Safe Links and Safe Attachments
  • Attack simulation
  • SPF, DKIM, DMARC, connectors and mail flow
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention
  • Information protection and encryption
  • Defender for Endpoint and Defender for Identity
  • Microsoft Sentinel integration and security visibility
  • Security baselines, policy registers and cyber-insurance evidence

Exchange & Migrations

Plan and deliver mail, file and tenant moves, with recovery steps and source-to-destination checks.

  • Exchange Online
  • Exchange Server 2016, 2019 and Subscription Edition
  • Hybrid Exchange
  • Mailbox, archive, public-folder and tenant migrations
  • GoDaddy defederation
  • Google Workspace, Rackspace, IMAP and third-party email migrations
  • Tenant-to-tenant and M&A consolidation
  • DNS, transport, DKIM, DMARC, SPF and connectors
  • Migration sequencing, cutover, rollback, reconciliation and rescue

Intune & Endpoint

Configure device enrollment, applications, access rules and retirement procedures, then test the agreed scenarios.

  • Microsoft Intune
  • Windows Autopilot
  • Compliance and configuration policies
  • Application packaging and deployment
  • Update rings
  • Windows 365 and Azure Virtual Desktop
  • SCCM/MECM, co-management, GPO transition, imaging and endpoint reporting
  • Windows 10 to 11 modernization

SharePoint, Teams & Copilot

Organize shared files, correct the agreed permissions and assess access before a Copilot rollout.

  • SharePoint information architecture
  • Teams and SharePoint integration
  • Permissions, ownership, metadata, content types and lifecycle
  • Restricted SharePoint Search
  • Microsoft SharePoint Premium (formerly Syntex) document processing
  • File-server and cloud-storage migration
  • Copilot readiness, permissions, licensing, pilot design and adoption
  • Purview controls for Copilot and AI interactions
  • Shadow AI and application-governance discovery

Power Platform & Automation

Rebuilds the processes that ran on email and spreadsheets, with owners and runbooks.

  • Power Automate
  • Microsoft Graph and PowerShell automation
  • Approval, onboarding, offboarding and request workflows
  • License lifecycle automation
  • Operational dashboards and Power BI
  • Runbooks and repeatable administrative tooling

Infrastructure & AI Platforms

Puts cloud, servers, network and recovery on supported paths with named owners.

  • Azure administration, security, identity, compute, networking, storage and governance
  • Hybrid AD and cloud transition
  • Server migration and modernization
  • Site-to-site networking, VPNs, routing and transit design
  • SonicWall, WatchGuard, UniFi, VeloCloud/SD-WAN and hybrid network troubleshooting
  • VMware, Hyper-V and virtualization transition
  • Datto BCDR and backup and recovery
  • Sophos endpoint and network security
  • Backup, disaster recovery and recovery validation

Architecture, Licensing & Governance

Provides the decisions, documentation and ownership that keep the rest working.

  • Technical roadmaps, documentation, as-builts and vendor coordination
  • Microsoft licensing and renewal reconciliation
  • M&A readiness and technology consolidation
  • Tenant takeover and vendor handover
  • Fractional architecture oversight

MSP White-Label Delivery

Delivers complex Microsoft projects behind an MSP’s brand, with fixed scope and handoff.

  • White-label project delivery under NDA
  • Escalation engineering for stalled projects
  • Architecture and scope review before the MSP quotes
  • Written change control and scheduled windows
  • Client ownership always stays with the MSP

A capability on this list does not always mean a packaged offer. Where the work is too variable to standardize honestly, it runs as a custom project: the route, the risks, the completion test and the fixed price are agreed before anything begins. Describe what happened →

Agree the operating responsibilities

Alwatheq leads the scoped technical work. Any specialist collaborator is named before delivery. The agreement sets work windows, acceptance checks and the client’s ongoing owner.

Scheduled project work. Delivery and change windows are agreed in the proposal. Continuous monitoring and standby support need a separately staffed service.
Specialist participation. Any external specialist, access requirement and responsibility is agreed before their work begins.
Handover and support. The client receives the operating record. Any defect-support period and ongoing maintenance are written into the scope.

Not sure where your problem fits?

Describe what is happening. A reply comes within one business day with the most direct next step, or a clear answer that this is not the right fit.

Get a Fixed Price in Writing →