Skip to main content
Microsoft 365 tenant, mailbox, Teams, and identity work — the biggest single source of routine requests.

Anti-Spam Policy Tuning

Tune Exchange Online Protection and Defender anti-spam policies from verdict evidence with scoped overrides and time-limited exceptions.

App Protection Policies

Configure Intune MAM-without-enrollment app protection for BYOD to protect org data in managed apps without managing the personal device.

Archive Mailbox Enablement

Enable Exchange Online In-Place Archive mailboxes to solve quota issues, with license checks, move-policy expectations, and archive caveats.

Autopilot Deployment

Run Windows Autopilot deployments end-to-end: hardware hash registration, profile assignment, ESP behavior, and reset-vs-re-enroll decisions.

B2B Collaboration Setup

Configure Entra B2B cross-tenant collaboration between partner organizations with scoped access settings, MFA and device trust, and rollback.

BitLocker Key Retrieval

Handle BitLocker recovery key requests with identity verification, device-ownership match, secure delivery, key rotation, and audit note.

Break-Glass Account Audit

Audit Entra emergency-access break-glass accounts: Conditional Access exclusions, sealed credentials, sign-in alerting, and quarterly test.

Calendar Permissions

Grant or review Exchange calendar sharing and delegation with least-privilege folder roles, owner consent, and private-items handling.

Conditional Access Review

Inventory a tenant's Conditional Access policies to find overlaps, legacy-auth gaps, unprotected apps, with report-only discipline for changes.

Delegate Access Forensics

Investigate mailbox audit logs to identify Send As, Send on Behalf, and owner actions in delegation disputes and unauthorized-email claims.

Device Wipe Workflows

Choose the right Intune remote action - retire, wipe, fresh start, Autopilot reset, or delete - with data-loss warnings and approval gate.

Distribution vs M365 Groups

Pick between distribution lists, Microsoft 365 Groups, mail-enabled security groups, and dynamic groups, and handle DL-to-M365-Group upgrades.

DKIM Enablement

Enable DKIM signing for a custom domain in Exchange Online: publish selector CNAMEs, activate signing, verify records, and plan key rotation.

Email Connector Setup

Route LOB apps, scanners, and printers through Exchange Online using SMTP AUTH, direct send, or an IP/certificate-scoped relay connector.

Enrollment Restrictions

Configure Intune enrollment restrictions: personal vs corporate device rules, platform blocks, device limits, and corporate identifier logic.

Entra PIM Requests

Handle Entra Privileged Identity Management role requests with eligible vs active assignments, activation justification, and time-boxed access.

GDAP Relationship Review

Audit MSP GDAP delegated-admin relationships across client tenants for least-privilege roles, security-group mapping, expiries, and unused access.

Guest Access Audit

Inventory Entra B2B guest accounts, find stale and never-redeemed ones, and enable access reviews and expiration with approval-gated cleanup.

Intune App Deployment

Deploy, update, or remove Intune apps with packaging choice, required vs available intent, pilot-to-broad rings, and approval before forced installs.

Intune Compliance Policies

Create or change Intune device compliance policies with grace periods and Conditional Access blast radius, piloted before broad enforcement.

Intune Enrollment Troubleshooting

Diagnose Windows Intune enrollment failures via a fixed ladder: user licensing, MDM scope, device state, and Entra join type checks.

Journaling & Compliance Mail

Handle Exchange journaling and compliance-copy requests with legal justification, external journal targets, cost impact, and retention alternatives.

M365 Group Lifecycle

Govern Microsoft 365 Groups lifecycle: creation controls, naming, expiration and renewal, ownership handoff, and clean retirement of dead groups.

M365 License Optimization

Right-size Microsoft 365 licensing from usage evidence: reclaim unused licenses, downgrade over-provisioned users, and rationalize add-ons.

M365 Tenant Health Report

Produce an advisory digest of Microsoft 365 Service Health incidents and Message Center posts for a client tenant as a plain-language brief.

Mail Flow Reports

Produce periodic Exchange Online mail flow health summaries: volume trends, spam/malware catch rates, top senders, connector health, forwarding.

Mail Forwarding Audit

Inventory every mail forwarding path in a tenant or mailbox: mailbox forwarding, inbox rules, and transport rules, treating external forwarding as risk.

Mail Trace Investigation

Run disciplined Exchange Online message traces with tight timeframes, sender/recipient pairs, verdict reading, and historical traces beyond 10 days.

Mailbox Migration Prep

Build the pre-migration checklist for tenant-to-tenant or on-prem mailbox moves: inventory, breakage list, holds and licensing, and user comms.

Mailbox Permissions Audit

Inventory Exchange mailbox access grants: Full Access, Send As, Send on Behalf, and folder-level permissions, flagging unexpected delegations.

Mailbox Quota Management

Investigate full or filling Exchange mailboxes and choose targeted cleanup, archive enablement, or license upgrade based on where size lives.

MFA Methods Audit

Audit Entra MFA authentication methods per user: phone-only risk, push without number matching, and missing phishing-resistant methods for admins.

OneDrive Storage Governance

Set OneDrive governance: storage quotas, leaver-account retention, sync scope by device or domain, and external-sharing posture for the tenant.

Out-of-Office on Behalf

Set automatic replies on an absent user's mailbox by request: manager or HR authorization verified, message kept minimal, and an end date set.

Plus Addressing & Aliases

Handle requests for extra mailbox addresses: plus addressing for self-service tagging, proxy aliases, and the send-from-alias caveats stated.

Power Automate Governance

Bring Power Automate under control: find orphaned flows from leavers, reassign ownership before breakage, and restrict Power Platform connectors.

Purview DLP Policy

Scope, test, and roll out Microsoft Purview DLP policies with test-mode first, narrow scope, and evidence before enforce to protect PII and PHI.

Resource Mailbox Setup

Create Exchange room and equipment mailboxes with booking policies, auto-accept or delegate approval, and recurring-meeting and duration limits.

Retention Policy Requests

Change Microsoft Purview retention and deletion policies with scope confirmed, legal-hold interaction flagged, and authorization documented.

Safe Attachments and Links Policy

Tune Defender for Office 365 Safe Attachments and Safe Links policies with dynamic delivery, URL rewriting, and scoped exceptions from evidence.

Security Defaults vs Conditional Access

Decide whether a tenant should stay on Entra security defaults or migrate to Conditional Access, sequenced so there is never an unprotected gap.

Sensitivity Labels

Roll out Microsoft Purview sensitivity labels with a small taxonomy, auto-labeling in simulation, and encryption consequences understood upfront.

Shared Mailbox Creation

Create Exchange Online shared mailboxes: naming, licensing at the 50GB threshold, initial delegation, and documentation for team inboxes.

SharePoint Site Provisioning

Provision new SharePoint sites and document libraries with site type, permission model, and sharing defaults chosen deliberately not inherited.

SSPR Rollout

Plan and execute Entra self-service password reset: method choices, registration campaign, hybrid writeback checks, and helpdesk-ticket impact.

Stale Device Cleanup

Clean up stale Entra device objects on a last-activity threshold with BitLocker-key-loss warnings, Autopilot exclusions, and disable-before-delete.

Teams Phone Admin

Configure Microsoft Teams Phone: assign numbers, apply calling and caller-ID policies, and build basic auto-attendants and call queues.

Tenant Onboarding Checklist

Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.

Transport Rule Management

Inspect, add, or change Exchange Online transport rules safely: document current state, test mode before enforce, and disable instead of delete.

Windows Hello for Business

Deploy or troubleshoot Windows Hello for Business: prerequisites by join type, tenant-wide vs targeted enablement, and hybrid on-prem access issues.