Skip to content
Pro IT NW

How the work runs

Engagement patterns.
Method in lieu of logos.

Our customers don't put their IT consultancy on a logo wall, and we're under NDA on most of the work that would prove the point anyway. So instead of case records: the shape each engagement takes, the sequence it runs in, and the specific failure mode each step exists to prevent.

Most consultancy "case study" pages are built around named logos and quotable customer testimonials. We don't run that play. The customers we work with are buying senior engineering, not marketing rights — and most of them prefer the work to stay private. The trade is fair: you get to see the volume and shape of the work, not the names attached to it.

What you're reading below is a representative sample. Not every engagement appears — some are too recent, some too sensitive, some simply not yet written up. Sector, seat count, pillar, headline, and a paragraph of substantive scope. References available privately during scoping conversations.

Pillars:

Microsoft 365 & Hybrid Exchange VMware Exit & Server Modernization Identity, Security & Compliance Microsoft 365 Copilot Readiness SharePoint & OneDrive Migration Active Directory Audit

Engagement patterns

Eight shapes this work takes.

Not case records — patterns. Each one is the form the engagement usually takes, the order it has to run in, and what goes wrong when a step is skipped. Substantive enough to tell you what the work actually is, rather than what slogan we'd put on it.

#01 Identity, Security & Compliance

Commercial → GCC High migration with CMMC L2 readiness

Aerospace and defense supply chain · Commercial tenant → GCC High

The pattern: a supplier discovers a prime contract will put CUI in their tenant, and a commercial Microsoft 365 tenant is the wrong place for it. Scope covers tenant provisioning in GCC High, file-share migration with ITAR-relevant content identified before it moves, AD-to-Entra hybrid identity, line-of-business and accounting integrations that have to survive the move, hardware MFA for privileged accounts, and NIST 800-171 control mapping with a written POA&M for residual gaps. The part that catches people: readiness for self-assessment attestation is a different deliverable from a C3PAO third-party assessment, and the second is scoped separately.

#02 Microsoft 365 Copilot Readiness

Copilot readiness assessment, then permission remediation

Regional healthcare network · Copilot readiness before clinical rollout

The pattern: a health network wants Copilot for clinical staff, and the tenant has years of accumulated oversharing nobody has looked at. Assessment finds the same three things almost every time — legacy 'Anyone in the company' links, dormant guest access, and site collections with broken permission inheritance. Remediation collapses that into a reviewable set, then a sensitivity-label baseline and Purview DLP for PHI in chat and mail go in before anyone turns Copilot on. The recommendation is almost always phased, with administrative staff as the canary cohort rather than clinicians, because the cost of a bad answer is not the same in both groups.

#03 VMware Exit & Server Modernization

VMware-to-Hyper-V migration after a Broadcom renewal

Mid-market discrete manufacturing · VMware exit to Hyper-V

The pattern across the mid-market since Broadcom: a renewal arrives at a multiple of the prior year and the estate is not exotic enough to justify it. The first question is whether Hyper-V is already paid for — a shop on Windows Server Datacenter frequently has the licensing and does not know it. Discovery then has to confirm three things before anyone commits: workload portability, whether NSX or vSAN are genuinely in use or merely deployed, and whether the hardware is clean on the Windows Server HCL. Cutover runs in waves, with hypercare after. The decommission is a scheduled step with a date, not an afterthought — estates that skip it keep paying for the thing they migrated off.

#04 Active Directory Audit

Three-layer AD audit (PingCastle + Purple Knight + manual)

Public-sector health and government · Multi-domain AD forest

The pattern: a combined health-and-government operation whose forest grew by acquisition and reorganisation, and nobody has assessed it end to end. Discovery-only, three layers in sequence, because each finds what the others miss — PingCastle for tier scoring and compliance baselines, Purple Knight for AD-specific attack surface, then manual review for the misconfigurations no scanner flags. One thing surfaces in almost every forest of this age: a belief that the domain functional level is higher than it is. Microsoft never shipped a 2019 or 2022 functional level, so Server 2016 is the ceiling for those forests. Hardening is scoped separately from the audit, deliberately — a discovery engagement that quietly becomes an implementation is how remediation gets done without a plan.

#05 Microsoft 365 & Hybrid Exchange

Two-tenant merge against a transition services agreement

M&A tenant integration · Parent acquiring a specialty subsidiary

The pattern: legal close is a fixed date set by lawyers, and tenant cutover is scoped against the transition services agreement rather than against the technology. The complexity is rarely the mailboxes. It is Power Platform apps with environment-scoped data, apps shared externally with partner organisations, Teams chat history an executive team assumes will survive the move, and dual-mailbox routing through the transition window. Mail flow, file shares, Teams and Power Platform consolidate into the parent tenant with licensing reassigned as part of the cutover, not after it — licence reassignment left to the end is how people arrive on Monday without Office.

#06 SharePoint & OneDrive Migration

File-share consolidation to SharePoint + OneDrive (KFM)

Public-sector file-server consolidation · Legacy file estate → SharePoint + OneDrive

The pattern: a legacy file estate that has never been inventoried, where the large majority of data turns out to be cold — untouched for a year or more. That single fact changes the whole design, because migrating cold data is the most expensive way to store it. The work splits in two: actively used shares mapped to SharePoint sites with permissions rationalised rather than copied, and user home drives to OneDrive with Known Folder Move handling desktop, documents and pictures redirection. Cold data is tiered to inexpensive storage with a defined retrieval path instead of being migrated at all. Batching by department is what keeps the blast radius survivable when a permission decision turns out to be wrong.

#07 Microsoft 365 & Hybrid Exchange

Hybrid Exchange decommission against the ESU clock

Professional services · Hybrid Exchange decommission

The pattern: hybrid was meant to be temporary and has run for years to support a small set of mailboxes somebody decided had to stay on-premises. Those get closed out first, because until they do nothing else can move. Then the on-premises Exchange organisation is retired and the hybrid relationship decommissioned in Microsoft's documented sequence — which matters, because recipient management is the step teams skip and then discover they cannot edit a distribution group. The payoff is not only the avoided ESU subscription; it is removing hybrid from the identity and mail-flow architecture permanently, with the runbook handed to internal IT rather than kept.

#08 Identity, Security & Compliance

AD Tier-0 implementation, scaled to a lean IT team

Financial services · AD Tier-0 hardening

The pattern: a firm wants ransomware blast-radius control on on-premises AD, reads Microsoft's Tier-0 guidance, and finds it assumes RedForest, ESAE and JEA infrastructure built for organisations many times their size. The work is deciding what to leave out. A PIM-based admin model, privileged-access workstations defined for Tier-0 administrators, and the unglamorous group-policy and naming-convention work that makes the boundary legible to whoever is on call. The test is not whether the model matches the reference architecture — it is whether a lean internal team can still operate it in six months without us.

A note on references

Named references during scoping conversations.

On a serious project, the right reference for you is the customer who did the same project we'd be running for you. Same pillar, similar size, same regulatory or industry context. We provide named references at that level of specificity during scoping conversations — not on a public page where the references have to defend their decision to a curious public.

Reference conversations are with the IT directors, CIOs, and engineering managers who actually partnered on the work. They're free to discuss what worked, what didn't, what they'd do differently, and what surprised them. We don't curate the conversations.

Have a project that fits one of these shapes?

Tell us the workload, the seat count, and the deadline. Two-business-day response with scope, timeline, and references that match your environment.