Services

Managed IT & Microsoft 365 Operations

Your tenant, directory, devices and licences, administered continuously, with every change planned, verified against live state, and reversible.

Directory lattice passing through a gate from disorder to order, marked with an amber check

How a Change Actually Happens

Most of what goes wrong in a Microsoft 365 tenant is not an attack. It is an administrator making a reasonable change without a record, without checking the state first, and without a way back. We operate through a layer we built to remove all three problems.

1

Plan

The change is written down with its target, its effect and its reversal before anything runs. Ambiguous targets are refused rather than guessed.

2

Gate

Five checks run in order. Anything that would touch a privileged or break-glass account, escalate a permission, or write to an unbounded set of objects is refused, and the refusal is recorded.

3

Verify

Live state is snapshotted before the write and read back after it. If the tenant drifted between plan and apply, the change aborts. If the result cannot be read back, it is reported as unconfirmed, never as done.

Rollback is built from the snapshot taken before the write, so it undoes exactly what was changed. Privileged accounts sit inside a boundary the tooling cannot reach, enforced by Microsoft rather than by our good intentions. You receive the record of every change, and a monthly report of where the tenant stands.

What We Operate

Identity and Access

  • MFA rolled out in waves, with a readiness check per account so nobody is locked out of a factor they never registered
  • Conditional Access scoped by group, with legacy clients excluded deliberately so the copier keeps working
  • Passkeys and authenticator apps enabled, email one-time codes and legacy authentication removed
  • Break-glass accounts designed, registered and kept out of reach of automation

Directory and Provisioning

  • Hybrid directory: Entra sync, cloud provisioning agents, service accounts done properly
  • Active Directory restructures scripted, dry-run first, then executed and verified
  • HR-to-directory provisioning integrations
  • Microsoft support cases opened with evidence and carried to a decisive answer

Joiners, Movers and Leavers

  • Onboarding with the right licences, groups and factors on day one
  • Offboarding planned and verified: sign-in blocked, mail handled, forwarding tested end to end, licences released
  • Litigation hold, archive and retention handled correctly rather than worked around
  • Mailbox quota and archive capacity managed before it becomes an outage

Licensing and Cost

  • Fleet-wide audit of owned versus assigned seats, with free and trial SKUs filtered so the number means something
  • Unassigned billable seats reclaimed and reported
  • Provisioning checked against what you are billed for
  • Subscription position managed with your licensing provider

Devices and Support

  • Patch and endpoint management with posture reported monthly
  • Helpdesk and support with a single accountable engineer
  • Vendor coordination for line-of-business applications and connectivity
  • Notification routing audited so alerts reach the people who act on them

Reported Monthly

Identity, endpoint, email and backup posture arrive in one report on the first of the month through Argos Security Assurance. You see what changed, what drifted and what needs a decision.

Who This Is For

Professional-services firms of 25 to 250 people on Microsoft 365 that hold client data and need their environment run with a record: architecture, legal, property, marine and financial practices. Typically there is no in-house IT, or one person carrying it alongside another job, and the previous provider left no documentation of what was changed or why.

Start with a posture report.

You will see the state of identity, licensing, email and backup before anyone talks about a contract.