Engagement patterns
Eight shapes this work takes.
Not case records — patterns. Each one is the form the engagement usually takes, the order it has to run in, and what goes wrong when a step is skipped. Substantive enough to tell you what the work actually is, rather than what slogan we'd put on it.
#01 Identity, Security & Compliance
Commercial → GCC High migration with CMMC L2 readiness
Aerospace and defense supply chain · Commercial tenant → GCC High
The pattern: a supplier discovers a prime contract will put CUI in their tenant, and a commercial Microsoft 365 tenant is the wrong place for it. Scope covers tenant provisioning in GCC High, file-share migration with ITAR-relevant content identified before it moves, AD-to-Entra hybrid identity, line-of-business and accounting integrations that have to survive the move, hardware MFA for privileged accounts, and NIST 800-171 control mapping with a written POA&M for residual gaps. The part that catches people: readiness for self-assessment attestation is a different deliverable from a C3PAO third-party assessment, and the second is scoped separately.
#02 Microsoft 365 Copilot Readiness
Copilot readiness assessment, then permission remediation
Regional healthcare network · Copilot readiness before clinical rollout
The pattern: a health network wants Copilot for clinical staff, and the tenant has years of accumulated oversharing nobody has looked at. Assessment finds the same three things almost every time — legacy 'Anyone in the company' links, dormant guest access, and site collections with broken permission inheritance. Remediation collapses that into a reviewable set, then a sensitivity-label baseline and Purview DLP for PHI in chat and mail go in before anyone turns Copilot on. The recommendation is almost always phased, with administrative staff as the canary cohort rather than clinicians, because the cost of a bad answer is not the same in both groups.
#03 VMware Exit & Server Modernization
VMware-to-Hyper-V migration after a Broadcom renewal
Mid-market discrete manufacturing · VMware exit to Hyper-V
The pattern across the mid-market since Broadcom: a renewal arrives at a multiple of the prior year and the estate is not exotic enough to justify it. The first question is whether Hyper-V is already paid for — a shop on Windows Server Datacenter frequently has the licensing and does not know it. Discovery then has to confirm three things before anyone commits: workload portability, whether NSX or vSAN are genuinely in use or merely deployed, and whether the hardware is clean on the Windows Server HCL. Cutover runs in waves, with hypercare after. The decommission is a scheduled step with a date, not an afterthought — estates that skip it keep paying for the thing they migrated off.
#04 Active Directory Audit
Three-layer AD audit (PingCastle + Purple Knight + manual)
Public-sector health and government · Multi-domain AD forest
The pattern: a combined health-and-government operation whose forest grew by acquisition and reorganisation, and nobody has assessed it end to end. Discovery-only, three layers in sequence, because each finds what the others miss — PingCastle for tier scoring and compliance baselines, Purple Knight for AD-specific attack surface, then manual review for the misconfigurations no scanner flags. One thing surfaces in almost every forest of this age: a belief that the domain functional level is higher than it is. Microsoft never shipped a 2019 or 2022 functional level, so Server 2016 is the ceiling for those forests. Hardening is scoped separately from the audit, deliberately — a discovery engagement that quietly becomes an implementation is how remediation gets done without a plan.
#05 Microsoft 365 & Hybrid Exchange
Two-tenant merge against a transition services agreement
M&A tenant integration · Parent acquiring a specialty subsidiary
The pattern: legal close is a fixed date set by lawyers, and tenant cutover is scoped against the transition services agreement rather than against the technology. The complexity is rarely the mailboxes. It is Power Platform apps with environment-scoped data, apps shared externally with partner organisations, Teams chat history an executive team assumes will survive the move, and dual-mailbox routing through the transition window. Mail flow, file shares, Teams and Power Platform consolidate into the parent tenant with licensing reassigned as part of the cutover, not after it — licence reassignment left to the end is how people arrive on Monday without Office.
#06 SharePoint & OneDrive Migration
File-share consolidation to SharePoint + OneDrive (KFM)
Public-sector file-server consolidation · Legacy file estate → SharePoint + OneDrive
The pattern: a legacy file estate that has never been inventoried, where the large majority of data turns out to be cold — untouched for a year or more. That single fact changes the whole design, because migrating cold data is the most expensive way to store it. The work splits in two: actively used shares mapped to SharePoint sites with permissions rationalised rather than copied, and user home drives to OneDrive with Known Folder Move handling desktop, documents and pictures redirection. Cold data is tiered to inexpensive storage with a defined retrieval path instead of being migrated at all. Batching by department is what keeps the blast radius survivable when a permission decision turns out to be wrong.
#07 Microsoft 365 & Hybrid Exchange
Hybrid Exchange decommission against the ESU clock
Professional services · Hybrid Exchange decommission
The pattern: hybrid was meant to be temporary and has run for years to support a small set of mailboxes somebody decided had to stay on-premises. Those get closed out first, because until they do nothing else can move. Then the on-premises Exchange organisation is retired and the hybrid relationship decommissioned in Microsoft's documented sequence — which matters, because recipient management is the step teams skip and then discover they cannot edit a distribution group. The payoff is not only the avoided ESU subscription; it is removing hybrid from the identity and mail-flow architecture permanently, with the runbook handed to internal IT rather than kept.
#08 Identity, Security & Compliance
AD Tier-0 implementation, scaled to a lean IT team
Financial services · AD Tier-0 hardening
The pattern: a firm wants ransomware blast-radius control on on-premises AD, reads Microsoft's Tier-0 guidance, and finds it assumes RedForest, ESAE and JEA infrastructure built for organisations many times their size. The work is deciding what to leave out. A PIM-based admin model, privileged-access workstations defined for Tier-0 administrators, and the unglamorous group-policy and naming-convention work that makes the boundary legible to whoever is on call. The test is not whether the model matches the reference architecture — it is whether a lean internal team can still operate it in six months without us.