Cogent NetworksCogent Networks Cogent NetworksDriving Innovation, Powering Success. Cogent OS
HOME/SERVICES/CLOUD & MICROSOFT
Practice area · 2 service lines

Microsoft-first
modernisation.

Microsoft 365 and Azure migration, hybrid platforms, identity and security hardening, and workplace modernisation - designed, delivered and then run.

MICROSOFT PARTNERAZURE & AWSZERO-TOUCH PROVISIONING
Overview

What this practice does

Most enterprises have the licences and none of the outcome. Microsoft 365 is bought, partially deployed, and left with identity half-finished, security baselines unenforced and users working around it. Our Cloud & Microsoft practice exists to close that gap - deploying properly, securing by default, and modernising the workplace on top.

The work is Microsoft-first because that is where our clients' estates are: Microsoft 365 and Entra ID, Intune and Autopilot, Defender and Purview, with Teams Voice where telephony is in scope. Two service lines carry it - the Microsoft 365 Practice for tenant, migration, security and adoption, and Workplace Modernisation for the device, identity and experience layer on top.

Crucially, the same account team that designs the change can run it afterwards. A migration that lands on Monday is in managed service on Tuesday, with the same CMDB, the same service desk and the same SLA - and, where the transition needs hands in twenty countries, the same field workforce doing the deskside work.

The practice on one page

Cloud & Microsoft at the centre

Each service line is its own contractable scope, and each runs on the same platform - so you can start with one and add the others without changing tools, portals or account teams.

What's included

Capabilities across the practice

Microsoft 365 Migration

Tenant-to-tenant and on-premise to 365 migration, Exchange, SharePoint and Teams, with coexistence and cutover planning.

Intune & Autopilot

Zero-touch device provisioning, compliance and configuration policy, application packaging and update rings.

Azure Landing Zones

Subscription and governance design, networking, policy, cost controls and infrastructure-as-code deployment.

On-Prem & Hybrid Cloud

VMware, hyperconverged and hybrid platforms, refresh and consolidation, backup and tested DR.

Identity & Security

Entra ID hardening, conditional access, MFA rollout, privileged access and Defender deployment.

Copilot Readiness

Data hygiene, permission and sensitivity review, pilot design and adoption measurement.

Teams Voice

Direct Routing and Operator Connect, call flows, contact-centre integration and AV alignment.

FinOps & Cost Governance

Tagging, showback, rightsizing and reservation strategy, reviewed monthly against consumption.

Lifecycle

Modernisation lifecycle - end to end on Cogent OS

The lifecycle on the left, the platform tooling that runs it in the middle, and the quality loop that holds it on the right. This is the same structure across all eighteen service lines, tuned per practice.

LIFECYCLE
Modernisation lifecycle
01
Assess
Estate, identity, licensing and dependency discovery; risk and readiness scored.
02
Design
Target architecture, landing zone, security baseline and migration waves agreed and documented.
03
Migrate
Pilot, then waves by business unit or country, with rollback points and coexistence maintained.
04
Harden
Conditional access, MFA, privileged access, Defender policy and backup and DR validation.
05
Operate
Handover into managed cloud with monitoring, patching, cost governance and monthly review.
COGENT OS TOOLING
Migration and governance tooling
01 Estate discovery02 Dependency mapping03 Wave planner04 Identity mapping05 Autopilot enrolment06 Security baselines07 Cost & FinOps08 Adoption reporting
COGENT OS · MIGRATION WAVESLIVE
WAVESCOPEOWNERSTATUS
W-04Madrid ES · 420 mailboxes, TeamsA. MolinaComplete
W-05Turin IT · 380 mailboxes, SharePointG. RossiIn flight
W-06Tallinn EE · 210 devices, AutopilotK. SaarScheduled
W-07Las Vegas US · Azure landing zoneM. OrtizDesign
0
Unplanned rollbacks
DELIVERY MANAGER & QUALITY CONTROL
Assurance and governance
01
Field activities
Deskside support during cutover in every affected country, by our own workers.
02
Manage
Wave-by-wave governance with named owners, go/no-go gates and rollback criteria.
03
Report
Migration progress, incident volume during cutover and adoption metrics per wave.
04
Analyse
Post-wave review: what caused tickets, what to change before the next wave.
05
Improve & control
Runbook and baseline updated; security posture and cost reviewed monthly.
20
Countries covered during cutover
ITIL
Change and CAB governed
24/7
Desk support through go-live
The numbers

Measured, not asserted

ESTATE READINESS BY WORKLOAD
Exchange / mailReady
SharePoint / files82%
Identity / Entra74%
Line-of-business apps48%
Legacy on-prem26%
TARGET PLATFORM MIX AFTER PROGRAMME
1,000TOTAL
Microsoft 365 540Azure IaaS / PaaS 280Retained on-prem 120Other cloud 60
SECURITY BASELINE COMPLIANCE
88%
Devices and identities against agreed baseline
Service levels

One SLA framework, applied here too

PRIORITYDEFINITIONRESPONSETARGET RESOLUTIONUPDATES
P1 - CriticalService down, site or revenue-critical system unavailable15 minutes4 hoursHourly
P2 - HighMajor degradation or a group of users affected30 minutes8 hoursEvery 2 hours
P3 - MediumSingle user or non-critical function impaired2 hoursNext business dayDaily
P4 - LowRequest, change or scheduled work8 hours5 business daysOn progress

Indicative framework - targets are agreed per contract and measured in Cogent OS against the ITIL priority matrix. Attainment reported monthly and reviewed at QBR.

Why Cogent for this

Four things that are hard to copy

Design and delivery in one team

The architects who design the landing zone are in the same company as the workers doing deskside cutover support.

Hands in every country

A migration is not only a cloud exercise - we can put badged workers in twenty countries during cutover week.

It does not end at go-live

The same team runs the platform afterwards under managed service, so nobody inherits an undocumented estate.

Security treated as scope

Identity hardening, conditional access and Defender are part of the migration, not a follow-on project.

Cogent cloud engineers at a design workshop with architecture on screen
FAQ

Questions buyers ask

Do you do tenant-to-tenant migrations after an acquisition?

Yes, and it is one of the most common engagements. The hard parts are identity, coexistence and the user experience during the overlap period. We map identities and licensing, run mail and file coexistence so both estates keep working, migrate in waves by business unit or country, and provide deskside support in each affected location during its cutover window.

How do you handle line-of-business applications that cannot move?

We design for them rather than pretending they will disappear. That usually means a hybrid platform - VMware or hyperconverged on-premise, or Azure IaaS - with the identity, backup, DR and monitoring model unified so the retained estate is governed to the same standard as the cloud one.

Is Copilot readiness a real piece of work or a licence purchase?

It is real work, mostly about data hygiene and permissions. Copilot surfaces whatever a user can technically access, so the readiness exercise is a permission and sensitivity review, oversharing remediation, and a controlled pilot with adoption measurement before broad rollout.

Who owns cost after migration?

We do, under managed cloud, with your sign-off on decisions. That means tagging and showback so cost is attributable, monthly rightsizing and reservation recommendations, and consumption reported alongside service performance rather than in a separate finance conversation.

Can you work alongside our incumbent Microsoft partner?

Yes. Where an incumbent holds licensing or a specific workload, we scope our part cleanly, agree the interface points and the RACI, and report on our scope. We would rather run a well-defined portion well than force a full displacement the client is not ready for.

Ready to scope this?

Tell us the countries, the sites and the service levels. We will show you which entity, which hub and which workers deliver it.

Get a Quote Talk to an expert
+44 20 3936 1085 · INFO@COGENTNETWORKS.COM