Proven change
Been told it can’t be done?
See how we’d approach familiar Microsoft 365 problems and check the results.
Project scenarios
Illustrative scenarios, not client results.
What will Copilot find?
A finance team wants to try Copilot, but old project folders still have broad access.
- What we’d do
- Agree a small pilot with the file owners. Review sharing and make only approved access changes.
- How we’d check
- Test users’ access against the agreed permissions before and after. Record the folders checked and any gaps.
Copilot follows existing permissions. Other sites and new content still need review.
When a colleague leaves
A colleague is leaving, but the team still needs their mailbox, files and supplier accounts.
- What we’d do
- Agree when access ends, what to keep and who takes over.
- How we’d check
- Test blocked sign-in, revoked sessions and authorised handovers. Record the Microsoft 365 and supplier accounts covered.
Offline copies, external sessions and retention decisions still need follow-up.
The starting service documents the process and tests it with test accounts. Ongoing administration is separate.
Still sharing an admin account?
Day-to-day admin work uses one shared account. Nobody has recently tested emergency access.
- What we’d do
- Agree and set up named admins with multi-factor authentication and separately controlled, phishing-resistant emergency access.
- How we’d check
- Test routine and emergency sign-in, policy interactions and alerts. Document recovery and authorised access to credentials.
Check which systems still use the old setup, and give ongoing access tests an owner.
New starter, unfinished laptop
New starters wait for apps while IT finishes each laptop by hand.
- What we’d do
- Agree the setup with users, pilot it in Intune on representative devices and document support steps.
- How we’d check
- Test enrolment, app installs, policies and an everyday task. Record results and failures by device type.
Older hardware and specialist apps may need a separate setup.
Will invoice emails still get through?
A business wants stronger email checks, but its newsletter and invoicing tools also send from its domain.
- What we’d do
- List senders with finance and marketing. Agree staged email-authentication changes and a rollback plan.
- How we’d check
- Check each approved sender’s authentication and delivery using headers and reports over the agreed period, before tightening enforcement.
Occasional senders may be missed at first. Check new suppliers too.
Cloud sign-in, older systems
The business wants cloud sign-in, but file shares and an older purchasing app still need Active Directory.
- What we’d do
- Map those dependencies with the app owners. Agree a pilot and rollback plan.
- How we’d check
- Compare sign-in, app and device results before and after. Record failed or untested checks; get owner approval before rollout.
Keep unresolved Active Directory dependencies on the migration plan.
Can you get your files back?
Backups say they’ve worked. The team has no recent proof it can restore an important folder.
- What we’d do
- Agree who can authorise a sample restore and what to recover, without overwriting live work.
- How we’d check
- Open restored files, compare contents and record missing or unreadable items, recovery time and access needed.
A sample tests one situation. Other data and wider outages need separate rehearsal.
Readiness covers a review and test plan. Live restore tests are quoted separately.
Licence renewal is coming up
The list still includes former staff, occasional users and accounts nobody clearly owns.
- What we’d do
- Review needs, dependencies and data with budget and service owners, then agree changes.
- How we’d check
- Compare assignments before and after, test required access and check subscription quantities and costs.
Low use alone doesn’t mean a licence is unnecessary. Unassigning it doesn’t reduce the bill; subscription changes and terms determine savings.
Getting ready for Cyber Essentials
A business wants to apply, but device records and responsibility for cloud services are unclear.
- What we’d do
- Agree the scope, check current scheme requirements across the five controls and assign each gap an owner.
- How we’d check
- Collect evidence for that scope, recheck fixes and list what remains unresolved.
Readiness prepares you for assessment. The certification body decides whether to certify.
Implementation is scoped separately. Certification and assessor fees are not included.
Does this sound familiar?
Get in touch and we can talk through the options.