Capability directory
The Microsoft and infrastructure work we cover.
Explore nine areas of project work. A migration may also require identity, device or licensing changes; we identify those connections and agree the scope before delivery.
Entra ID & Identity
Configure and test sign-in, administrator access and the rules that limit it.
- Microsoft Entra ID
- Conditional Access
- Multifactor authentication
- Passkeys, FIDO2 and phishing-resistant authentication
- Privileged Identity Management
- Administrator-role cleanup
- Emergency-access accounts
- Entra Connect and hybrid identity
- Access reviews, guest access and application consent
- Identity investigation and access evidence
Defender, Purview & Security
Deploys, enforces and tests the protections the business already licenses.
- Microsoft Defender for Office 365
- Anti-phishing, anti-spam, Safe Links and Safe Attachments
- Attack simulation
- SPF, DKIM, DMARC, connectors and mail flow
- Microsoft Purview sensitivity labels
- Data Loss Prevention
- Information protection and encryption
- Defender for Endpoint and Defender for Identity
- Microsoft Sentinel integration and security visibility
- Security baselines, policy registers and cyber-insurance evidence
Exchange & Migrations
Plan and deliver mail, file and tenant moves, with recovery steps and source-to-destination checks.
- Exchange Online
- Exchange Server 2016, 2019 and Subscription Edition
- Hybrid Exchange
- Mailbox, archive, public-folder and tenant migrations
- GoDaddy defederation
- Google Workspace, Rackspace, IMAP and third-party email migrations
- Tenant-to-tenant and M&A consolidation
- DNS, transport, DKIM, DMARC, SPF and connectors
- Migration sequencing, cutover, rollback, reconciliation and rescue
Intune & Endpoint
Configure device enrollment, applications, access rules and retirement procedures, then test the agreed scenarios.
- Microsoft Intune
- Windows Autopilot
- Compliance and configuration policies
- Application packaging and deployment
- Update rings
- Windows 365 and Azure Virtual Desktop
- SCCM/MECM, co-management, GPO transition, imaging and endpoint reporting
- Windows 10 to 11 modernization
SharePoint, Teams & Copilot
Organize shared files, correct the agreed permissions and assess access before a Copilot rollout.
- SharePoint information architecture
- Teams and SharePoint integration
- Permissions, ownership, metadata, content types and lifecycle
- Restricted SharePoint Search
- Microsoft SharePoint Premium (formerly Syntex) document processing
- File-server and cloud-storage migration
- Copilot readiness, permissions, licensing, pilot design and adoption
- Purview controls for Copilot and AI interactions
- Shadow AI and application-governance discovery
Power Platform & Automation
Rebuilds the processes that ran on email and spreadsheets, with owners and runbooks.
- Power Automate
- Microsoft Graph and PowerShell automation
- Approval, onboarding, offboarding and request workflows
- License lifecycle automation
- Operational dashboards and Power BI
- Runbooks and repeatable administrative tooling
Infrastructure & AI Platforms
Puts cloud, servers, network and recovery on supported paths with named owners.
- Azure administration, security, identity, compute, networking, storage and governance
- Hybrid AD and cloud transition
- Server migration and modernization
- Site-to-site networking, VPNs, routing and transit design
- SonicWall, WatchGuard, UniFi, VeloCloud/SD-WAN and hybrid network troubleshooting
- VMware, Hyper-V and virtualization transition
- Datto BCDR and backup and recovery
- Sophos endpoint and network security
- Backup, disaster recovery and recovery validation
Architecture, Licensing & Governance
Provides the decisions, documentation and ownership that keep the rest working.
- Technical roadmaps, documentation, as-builts and vendor coordination
- Microsoft licensing and renewal reconciliation
- M&A readiness and technology consolidation
- Tenant takeover and vendor handover
- Fractional architecture oversight
MSP White-Label Delivery
Delivers complex Microsoft projects behind an MSP’s brand, with fixed scope and handoff.
- White-label project delivery under NDA
- Escalation engineering for stalled projects
- Architecture and scope review before the MSP quotes
- Written change control and scheduled windows
- Client ownership always stays with the MSP
A capability on this list does not always mean a packaged offer. Where the work is too variable to standardize honestly, it runs as a custom project: the route, the risks, the completion test and the fixed price are agreed before anything begins. Describe what happened →
Agree the operating responsibilities
Alwatheq leads the scoped technical work. Any specialist collaborator is named before delivery. The agreement sets work windows, acceptance checks and the client’s ongoing owner.
Not sure where your problem fits?
Describe what is happening. A reply comes within one business day with the most direct next step, or a clear answer that this is not the right fit.
Get a Fixed Price in Writing →