Capability directory

Everything the practice works across

Nine capability areas behind the engagements. Most problems touch several at once — identity affects mail, devices affect access, licensing affects everything — and cross-workload delivery is the point of a single accountable architect.

Entra ID & Identity

Controls who can get in, with what, and for how long, enforced and evidenced.

  • Microsoft Entra ID
  • Conditional Access
  • Multifactor authentication
  • Passkeys, FIDO2 and phishing-resistant authentication
  • Privileged Identity Management
  • Administrator-role cleanup
  • Emergency-access accounts
  • Entra Connect and hybrid identity
  • Access reviews, guest access and application consent
  • Identity investigation and access evidence

Defender, Purview & Security

Deploys, enforces and tests the protections the business already licenses.

  • Microsoft Defender for Office 365
  • Anti-phishing, anti-spam, Safe Links and Safe Attachments
  • Attack simulation
  • SPF, DKIM, DMARC, connectors and mail flow
  • Microsoft Purview sensitivity labels
  • Data Loss Prevention
  • Information protection and encryption
  • Defender for Endpoint and Defender for Identity
  • Microsoft Sentinel integration and security visibility
  • Security baselines, policy registers and cyber-insurance evidence

Exchange & Migrations

Moves mail, files and tenants with rollback rules and a reconciliation sheet at the end.

  • Exchange Online
  • Exchange Server 2016, 2019 and Subscription Edition
  • Hybrid Exchange
  • Mailbox, archive, public-folder and tenant migrations
  • GoDaddy defederation
  • Google Workspace, Rackspace, IMAP and third-party email migrations
  • Tenant-to-tenant and M&A consolidation
  • DNS, transport, DKIM, DMARC, SPF and connectors
  • Migration sequencing, cutover, rollback, reconciliation and rescue

Intune & Endpoint

Devices arrive already set up, stay compliant, and can be wiped the day they walk out.

  • Microsoft Intune
  • Windows Autopilot
  • Compliance and configuration policies
  • Application packaging and deployment
  • Update rings
  • Windows 365 and Azure Virtual Desktop
  • SCCM/MECM, co-management, GPO transition, imaging and endpoint reporting
  • Windows 10 to 11 modernization

SharePoint, Teams & Copilot

Gives collaboration structure, corrects permissions to match intent, and puts Copilot on safe ground.

  • SharePoint information architecture
  • Teams and SharePoint integration
  • Permissions, ownership, metadata, content types and lifecycle
  • Restricted SharePoint Search
  • Microsoft SharePoint Premium (formerly Syntex) document processing
  • File-server and cloud-storage migration
  • Copilot readiness, permissions, licensing, pilot design and adoption
  • Purview controls for Copilot and AI interactions
  • Shadow AI and application-governance discovery

Power Platform & Automation

Rebuilds the processes that ran on email and spreadsheets, with owners and runbooks.

  • Power Automate
  • Microsoft Graph and PowerShell automation
  • Approval, onboarding, offboarding and request workflows
  • License lifecycle automation
  • Operational dashboards and Power BI
  • Runbooks and repeatable administrative tooling

Azure & Infrastructure

Puts cloud, servers, network and recovery on supported paths with named owners.

  • Azure administration, security, identity, compute, networking, storage and governance
  • Hybrid AD and cloud transition
  • Server migration and modernization
  • Site-to-site networking, VPNs, routing and transit design
  • SonicWall, WatchGuard, UniFi, VeloCloud/SD-WAN and hybrid network troubleshooting
  • VMware, Hyper-V and virtualization transition
  • Datto BCDR and backup and recovery
  • Sophos endpoint and network security
  • Backup, disaster recovery and recovery validation

Architecture, Licensing & Governance

Provides the decisions, documentation and ownership that keep the rest working.

  • Technical roadmaps, documentation, as-builts and vendor coordination
  • Microsoft licensing and renewal reconciliation
  • M&A readiness and technology consolidation
  • Tenant takeover and vendor handover
  • Fractional architecture oversight

MSP White-Label Delivery

Delivers complex Microsoft projects behind an MSP’s brand, with fixed scope and handoff.

  • White-label project delivery under NDA
  • Escalation engineering for stalled projects
  • Architecture and scope review before the MSP quotes
  • Written change control and scheduled windows
  • Client ownership always stays with the MSP

A capability on this list does not always mean a packaged offer. Where the work is too variable to standardize honestly, it runs as a custom project: the route, the risks, the completion test and the fixed price are agreed before anything begins. Describe the situation →

What this practice does not sell

Delivery runs in scheduled windows around senior availability. Work that needs someone on call around the clock belongs with a partner built for it, and pretending otherwise would break the first promise that matters.

24/7 incident response. Requires availability a full-time role cannot honestly promise.
Same-day breach containment. Emergency work needs a DFIR partner; scheduled post-containment investigation is the offer instead.
Continuous SOC monitoring. Deployment and handoff are sold; watching the console around the clock is not.
Managed Sentinel or Defender alert response. Same constraint: alerts fire outside the delivery calendar.
Help desk or per-user support. Per-user support competes on availability, which is the one resource this practice cannot scale.
Open-ended "call whenever" consulting. Unbounded availability sold at consulting rates is a promise that breaks the first busy week.
Unbounded MSP overflow support. MSP work is one named project, one contact, written change control, scheduled windows.
Guaranteed daytime emergency availability. Delivery happens in scheduled windows around a full-time role.
Commodity hourly administration. Competes at $120–150/hour against providers built for it; the practice sells outcomes.
Physical on-site infrastructure work without a local partner. Remote-first delivery; hardware racking needs local hands.
Generic AI consulting. Bounded Copilot, governance and automation engagements exist instead; "AI strategy" without scope is effort, not an outcome.
Compliance certification or insurance-approval guarantees. Evidence and control closure are deliverable; a third party’s approval decision is not.

Not sure where your problem fits?

Describe what is happening. A reply comes within one business day with the most direct next step, or a clear answer that this is not the right fit.

Talk Through the Problem →
Talk Through the Problem