Most enterprises have the licences and none of the outcome. Microsoft 365 is bought, partially deployed, and left with identity half-finished, security baselines unenforced and users working around it. Our Cloud & Microsoft practice exists to close that gap - deploying properly, securing by default, and modernising the workplace on top.
The work is Microsoft-first because that is where our clients' estates are: Microsoft 365 and Entra ID, Intune and Autopilot, Defender and Purview, with Teams Voice where telephony is in scope. Two service lines carry it - the Microsoft 365 Practice for tenant, migration, security and adoption, and Workplace Modernisation for the device, identity and experience layer on top.
Crucially, the same account team that designs the change can run it afterwards. A migration that lands on Monday is in managed service on Tuesday, with the same CMDB, the same service desk and the same SLA - and, where the transition needs hands in twenty countries, the same field workforce doing the deskside work.
Each service line is its own contractable scope, and each runs on the same platform - so you can start with one and add the others without changing tools, portals or account teams.
Tenant-to-tenant and on-premise to 365 migration, Exchange, SharePoint and Teams, with coexistence and cutover planning.
Zero-touch device provisioning, compliance and configuration policy, application packaging and update rings.
Subscription and governance design, networking, policy, cost controls and infrastructure-as-code deployment.
VMware, hyperconverged and hybrid platforms, refresh and consolidation, backup and tested DR.
Entra ID hardening, conditional access, MFA rollout, privileged access and Defender deployment.
Data hygiene, permission and sensitivity review, pilot design and adoption measurement.
Direct Routing and Operator Connect, call flows, contact-centre integration and AV alignment.
Tagging, showback, rightsizing and reservation strategy, reviewed monthly against consumption.
The lifecycle on the left, the platform tooling that runs it in the middle, and the quality loop that holds it on the right. This is the same structure across all eighteen service lines, tuned per practice.
| PRIORITY | DEFINITION | RESPONSE | TARGET RESOLUTION | UPDATES |
|---|---|---|---|---|
| P1 - Critical | Service down, site or revenue-critical system unavailable | 15 minutes | 4 hours | Hourly |
| P2 - High | Major degradation or a group of users affected | 30 minutes | 8 hours | Every 2 hours |
| P3 - Medium | Single user or non-critical function impaired | 2 hours | Next business day | Daily |
| P4 - Low | Request, change or scheduled work | 8 hours | 5 business days | On progress |
Indicative framework - targets are agreed per contract and measured in Cogent OS against the ITIL priority matrix. Attainment reported monthly and reviewed at QBR.
The architects who design the landing zone are in the same company as the workers doing deskside cutover support.
A migration is not only a cloud exercise - we can put badged workers in twenty countries during cutover week.
The same team runs the platform afterwards under managed service, so nobody inherits an undocumented estate.
Identity hardening, conditional access and Defender are part of the migration, not a follow-on project.

Yes, and it is one of the most common engagements. The hard parts are identity, coexistence and the user experience during the overlap period. We map identities and licensing, run mail and file coexistence so both estates keep working, migrate in waves by business unit or country, and provide deskside support in each affected location during its cutover window.
We design for them rather than pretending they will disappear. That usually means a hybrid platform - VMware or hyperconverged on-premise, or Azure IaaS - with the identity, backup, DR and monitoring model unified so the retained estate is governed to the same standard as the cloud one.
It is real work, mostly about data hygiene and permissions. Copilot surfaces whatever a user can technically access, so the readiness exercise is a permission and sensitivity review, oversharing remediation, and a controlled pilot with adoption measurement before broad rollout.
We do, under managed cloud, with your sign-off on decisions. That means tagging and showback so cost is attributable, monthly rightsizing and reservation recommendations, and consumption reported alongside service performance rather than in a separate finance conversation.
Yes. Where an incumbent holds licensing or a specific workload, we scope our part cleanly, agree the interface points and the RACI, and report on our scope. We would rather run a well-defined portion well than force a full displacement the client is not ready for.
Tell us the countries, the sites and the service levels. We will show you which entity, which hub and which workers deliver it.