M365-02
Cloud, Microsoft 365 and the workplace
Microsoft 365 foundation — identity, mail and Intune
Who it's for: a migration from Exchange, Lotus or a hybrid environment still to be completed — and, beyond mail, the identity, device management and collaboration foundation that goes with it.
The problem: a successful Microsoft 365 migration is not decided on the mailbox transfer but on what precedes it and what follows — a clean directory, a properly designed identity synchronisation, an authentication method suited to the context, and a device management foundation in place before users move across. Without that, the technical cutover succeeds and day-to-day operations become unmanageable.
What I do
- scoping, inventory and preliminary audit of the Active Directory: structure, duplicates, attributes, stale accounts, readiness for synchronisation
- design of the hybrid architecture and of the target identity model
- implementation or takeover of Entra Connect: synchronisation, filtering, transformation rules, PHS, PTA, seamless SSO or federation depending on the context
- identity hardening: conditional access, multi-factor authentication, privileged accounts
- design and deployment of Intune: enrolment of Windows devices and mobiles, compliance policies, configuration profiles, application deployment, Windows Autopilot
- implementation of SharePoint Online and Teams: site architecture, governance, migration of file shares, permissions and external sharing
- pilot on a restricted scope, then migration waves
- full cutover and controlled decommissioning of the existing environment
- change management and training of the technical and user teams
Deliverables
- architecture document: identity, mail, collaboration, device management
- directory readiness report and corrective actions carried out
- wave-based migration plan, with criteria for moving from one wave to the next
- cutover and rollback procedures
- operating documentation and matrix of the policies applied
- training sessions and level 1/2 support guides
What changes
a planned and reversible cutover, on an identity and device management foundation built to last — not a cutover endured, followed by two years of catching up.
Prerequisites: administrator access to the directory and to the tenant, a Microsoft 365 tenant provisioned with the required licences, control of the public DNS zone, an endpoint contact available.
Quoted on request — reply within 48h