Microsoft 365 security that holds up in day-to-day operations
A selection of completed projects – from tenant setup to a full security check. Presented anonymized at the request of individual clients.
A secure Microsoft 365 foundation for a growing consulting firm
As an expanding consulting firm running several client projects in parallel, the company needed a robust Microsoft 365 foundation from day one. We set up the tenant from scratch, provisioned the appropriate licenses, and configured Microsoft Entra ID including Conditional Access policies (mandatory MFA, device compliance, role-based access control). In addition, all endpoints were onboarded to Microsoft Defender for Endpoint and monitored centrally, and sensitive project and client data was classified with sensitivity labels via Microsoft Purview.
After several years in production, a full security check across all areas followed. It revealed a number of gaps that had grown over time – among them admin permissions and device compliance – which were closed quickly. The result: a noticeably and significantly improved security posture within a short time, without interrupting ongoing consulting operations.
A secured cloud environment for sensitive customer data
For a growing telecommunications company handling sensitive customer and network data, securing the Microsoft 365 environment was a priority from the outset. We set up the tenant and licensing, configured Entra ID with Conditional Access and role-based access policies, and protected all endpoints against current threats using Microsoft Defender for Endpoint. Information protection policies for confidential business and customer data were additionally introduced via Microsoft Purview.
A comprehensive security check carried out a year later confirmed the solid foundation, but also uncovered untapped optimization potential – for example in fine-tuning the access policies. After implementation, the improvement in security posture was immediately noticeable, with no additional license costs, as existing capabilities were simply used more consistently.
Confidential practice data reliably protected
For an ENT practice in Cologne, protecting sensitive practice data was the focus of the Microsoft 365 rollout. We set up a new tenant, provisioned the appropriate licenses, and secured Microsoft Entra ID with Conditional Access – including multi-factor authentication for access on the move. Practice computers and mobile devices are monitored via Microsoft Defender for Endpoint, and confidential data was classified with the corresponding sensitivity labels via Microsoft Purview.
A security check carried out after several years of operation brought additional optimization potential to light, which was implemented right away. For the practice, this meant noticeably improved protection within a short time – a key trust factor, particularly in a medical environment where confidentiality is an especially high priority.
From local sign-ins to a centrally managed Microsoft 365 environment
For an engineering office in Hesse, replacing a local identity platform and local client sign-ins was the focus of the modernization. We migrated identities entirely to Microsoft Entra ID and secured them properly with Conditional Access, mandatory multi-factor authentication, break-glass accounts, a role-based permission model (RBAC), and security baseline policies. Device provisioning has since been automated via Windows Autopilot.
In addition, part of the previous terminal server environment was replaced by Azure Virtual Desktop; for individual workplaces, high-performance notebooks were used instead of terminal server sessions. All endpoints are managed centrally via Microsoft Intune, protected by Microsoft Defender for Endpoint, and classified with sensitivity labels via Microsoft Purview. For the company, this meant a centrally managed, significantly more secure environment at noticeably lower running costs.