Cogent NetworksCogent Networks Cogent NetworksDriving Innovation, Powering Success. Cogent OS
HOME/SERVICES/CLOUD & MICROSOFT/MICROSOFT 365 PRACTICE
Service line

Microsoft 365,
deployed properly.

Advisory, migration, security and adoption across the Microsoft stack - anchored by a deployment discipline where nothing is deleted before cutover and every phase carries a rollback plan.

TENANT TO INBOXZERO-DATA-LOSS MIGRATIONSSECURITY-FIRSTCOPILOT-READY
6
Phases, each with a rollback plan
0
Mailboxes lost to date
MFA
Enforced from day one
24/7
Desk cover through hypercare
The proposition

The licences are bought. The outcome usually is not.

Most organisations we meet already own Microsoft 365. What they do not have is a tenant that was designed, an identity model that was finished, a security baseline that is actually enforced, or users who work with the platform rather than around it.

We run Microsoft as a practice, not a project queue. That means the same team advises on tenant and licensing strategy, executes the migration, hardens identity and endpoint, and then either hands over a documented estate or keeps running it. The advisory is not sold by one company and delivered by another.

The migration discipline underneath it is deliberately conservative: coexistence before cutover, backup before deletion, differential sync at the switch, and a monitored soak period before anything legacy is decommissioned. Unglamorous, and the reason we do not lose mail.

Five pillars

What the practice covers

Advisory & tenant strategy

The decisions that are expensive to reverse: how the tenant is structured, what you are actually licensed for, and what the governance model is.

·Licensing optimisation and true-up review·Tenant architecture and data-residency selection·Multi-tenant consolidation after acquisition·Naming, governance and lifecycle standards·Admin-role separation and least privilege

Migration & deployment

Mail, files and collaboration moved in waves with coexistence maintained, so nobody works in two places without knowing it.

·Exchange, hybrid Exchange and tenant-to-tenant·SharePoint and OneDrive file migration·Teams migration and coexistence·Historical mail from PST and local stores·Cutover playbook with rollback per wave

Identity & endpoint

The layer everything else depends on - and the one most often left half-configured after a self-service migration.

·Entra ID configuration and hardening·Conditional Access and MFA enforcement·Intune policy and compliance baselines·Autopilot zero-touch provisioning·Mobile and BYOD enrolment models

Security & compliance

Defender and Purview deployed as a programme with measured posture, not switched on and left at defaults.

·Defender for Endpoint, Office and Identity·Purview DLP, retention and sensitivity labels·Secure-score improvement programme·Privileged access and break-glass accounts·Audit and eDiscovery readiness

Adoption & Copilot

The part that decides whether the investment returns anything - permission hygiene first, then pilots, then measurement.

·Copilot readiness: data hygiene and oversharing review·Permission and sensitivity remediation·Pilot cohorts with prompt training·Usage and adoption analytics·Champion network and floor-walking support
Deployment methodology

Six phases, and nothing deleted early

This is the discipline we apply to every tenant and email deployment. Each phase has an exit gate, a rollback position and an evidence pack in Cogent OS under ITIL change control.

NOTHING DELETED EARLY
01
Scope & discovery
Domain and DNS audit including registrar access and current MX and SPF state. Mailbox and distribution-group inventory with open versus closed membership documented per group. Email-client landscape and current data storage audit - local PST and OST mapping, sizes and backup state.
02
Tenant foundation
Admin-role separation: global admin for configuration, delegated user admin for account operations. Data-residency region selected. Licence plan and assignment model agreed. DNS prepared for coexistence - a low-priority MX added for the new tenant while the legacy MX stays live. Nothing is deleted before cutover.
03
Identity & groups
Users created in bulk from a validated import template, licences assigned. Distribution groups versus Microsoft 365 groups chosen deliberately per use case. SPF, DKIM and DMARC enabled. Corporate disclaimer applied. Intune enrolment enabled. MFA and Conditional Access enforced from day one - the security baseline is not deferred to a later phase.
04
Client setup & data migration
New profiles configured on the mail client. Historical mail migrated by network upload or staged migration, with backup before any deletion as a hard rule. Shared mailboxes, delegations and calendar permissions rebuilt and tested.
05
Cutover & decommission
Cutover date agreed with the business. MX priority flipped to the new tenant. Differential sync of mail received during migration. Monitored soak period. The legacy platform is decommissioned only after written sign-off.
06
Hypercare & handover
A defined support window with floor-walking or remote cover, priority routing for newly migrated users, then knowledge transfer with a runbook and the full evidence pack.
6
Phases with exit gates
Coexistence
Legacy MX stays live until cutover
Backup
Before any deletion, without exception
Sign-off
Required before decommission
Beyond email

The full workload view

Email and tenant is where most engagements start. It is rarely where they end.

Teams & collaboration

Teams deployment, governance and lifecycle policy, channel and guest-access models, and migration from legacy collaboration platforms.

SharePoint & OneDrive

File estate migration from on-premise shares or a legacy tenant, with permission mapping, sensitivity review and a known-good folder structure.

Exchange hybrid

Where a hybrid posture is required for compliance or a phased move, designed and operated properly rather than left as a permanent temporary state.

Multi-tenant consolidation

Post-acquisition tenant merges: identity mapping, coexistence, licensing rationalisation and phased user migration by business unit.

Intune & Autopilot

Zero-touch device provisioning, compliance and configuration policy, application packaging and staged update rings.

Defender & Purview

Endpoint, Office and identity protection deployed with tuned policy, plus DLP, retention and sensitivity labels under a governance model.

Why our migrations are safe

Four rules we do not break

Coexistence-first DNS

A low-priority MX for the new tenant goes in while the legacy MX stays live and untouched. Mail flows to both, nothing is orphaned, and the switch is a priority change rather than a leap.

Backup before delete

No local store, mailbox or file share is removed until its content is verified in the new tenant and a restorable backup exists. This is a hard rule, not a best practice we skip under time pressure.

Differential sync at cutover

Mail that arrived during the migration window is synced after the MX flip, so the gap between the last full pass and the cutover is closed rather than accepted as loss.

Evidenced in Cogent OS

Every phase runs as a change record with CAB approval, a documented rollback plan and an evidence pack - so the audit position and the project status are the same artefact.

Engagement models

How you buy it

MODELWHAT IT COVERSCOMMERCIAL SHAPEBEST FOR
Fixed-scope deploymentA defined tenant, migration or security programme with agreed phases, exit gates and hypercare windowFixed price against a scoped statement of workA known move: new tenant, tenant merge, Defender rollout
Managed Microsoft 365 estateOngoing operation: patching and update rings, policy management, security posture, licence optimisation and monthly reportingMonthly fee per user or per tenantOrganisations without a dedicated Microsoft team
Standing practice retainerNamed consultants with a roadmap cadence - quarterly planning, architecture decisions and delivery capacity on callRetained days per month with a roadmap reviewEstates changing continuously, or an internal team needing depth

Most clients start with a fixed-scope deployment and move the result into a managed estate, so the team that built it runs it. Where you keep operations in-house we hand over the runbook and documentation as a contractual deliverable.

The numbers

Migration performance

MAILBOXES MIGRATED PER WEEK · TYPICAL RAMP
Pilot week40
Wave 1-2150
Wave 3-5260
Peak340
WORKLOAD MIX ACROSS ENGAGEMENTS
1,260TOTAL
Exchange / mail 540SharePoint / OneDrive 280Teams 190Identity & endpoint 160Security & Purview 90
SECURE-SCORE UPLIFT AFTER HARDENING
88%
Devices and identities against agreed baseline
Proof

A comparable engagement

CASE STUDY · PROFESSIONAL SERVICES · TENANT AND MAIL DEPLOYMENT
310
Mailboxes migrated
7 hours
Cutover window, out of office hours
Zero
Data loss

A multi-site organisation was running mail on an ageing platform with historical mail scattered across local stores on individual machines, no consistent backup, and distribution groups nobody could account for. A previous attempt to move had been abandoned after a test cutover lost calendar delegations.

We ran the six-phase methodology: a full domain, mailbox and local-storage audit first, then a tenant built with admin-role separation and the data-residency region set deliberately. A low-priority MX went in alongside the live one so coexistence held throughout, users were created from a validated import, and MFA with Conditional Access was enforced before the first mailbox moved rather than after.

Historical mail was migrated with verified backups retained, shared mailboxes and delegations rebuilt and tested against a checklist, then the MX priority was flipped on an agreed date with a differential sync closing the migration window. The legacy platform stayed live through a monitored soak period and was decommissioned only after sign-off.

Anonymised by agreement. Client names available under NDA.

FAQ

Questions buyers ask

How much downtime should we expect?

For mail, effectively none. Coexistence means the legacy MX stays live while the new tenant receives on a low priority, so mail keeps flowing throughout the migration. The cutover itself is a DNS priority change, and a differential sync afterwards closes the window. What users do experience is a new profile on their mail client, which we set up as part of the visit or remote session.

What happens to years of mail sitting in local PST files?

It is audited first - location, size and whether any backup exists - because this is where data is genuinely lost in badly run migrations. Content is then migrated by network upload or staged import, verified in the new tenant, and only then is the local store considered for removal. Backup before deletion is a hard rule with no exceptions for schedule pressure.

You enforce MFA from day one - does that not increase risk of disruption?

It reduces it. Deferring MFA means running a new tenant in a known-vulnerable state during exactly the period when credentials are being reset and users are being phished with migration-themed lures. We enrol users in MFA as part of onboarding with Conditional Access policies scoped so break-glass access remains available, and the enrolment is supported during hypercare.

Can you reduce our licensing cost?

Often, yes, and the review is part of advisory rather than a separate exercise. The common findings are licences assigned to leavers, over-specified tiers for task-based users, duplicate third-party tools already covered by the suite, and add-ons bought before the base licence changed to include them. We present the finding and the risk of each change rather than simply downgrading.

Do you support hybrid Exchange long term?

Yes, where compliance or a phased plan genuinely requires it. What we will not do is leave a hybrid posture in place as an accident with nobody owning it - if it is intentional it gets a documented design, patching and monitoring; if it is a leftover, we plan its retirement.

Related

Other service lines in this practice

Workplace ModernisationPractice overview

Tenant to migrate, or an estate to fix?

Tell us the mailbox count, the countries and the constraints. We will come back with the phase plan, the cutover approach and the rollback position at each gate.

Get a Quote Talk to an expert
+44 20 3936 1085 · INFO@COGENTNETWORKS.COM