Microsoft, Cloud & Infrastructure

Your Microsoft estate should work as one.

Identity, devices, Microsoft 365 and cloud deliver more value when they are configured, secured and managed as one connected estate.

Start the 2-minute Microsoft 365 diagnostic

15 questions · Instant score · PDF report

Talk to us first

What are you trying to achieve?

What this reveals

Conditional Access defaults, admin MFA gaps and Intune enrolment that never completed across the full device estate.

What we change

We configure Identity, enforce MFA, complete Intune enrolment and activate Defender - making security measurable, not assumed.

Conditional AccessMFA gapsDefender inactive

Covering

Microsoft 365Entra IDIntuneAzureDefenderTeams & SharePointCopilot & AI readiness

The problem

Most Microsoft environments drift - slowly, silently, and at cost.

Drift

Visibility

Control

What you notice

You are paying for Business Premium or E3/E5 but the team only uses Exchange and Teams.

What is really happening

Defender, Intune, Purview and Entra ID Premium features are inactive - paid for and providing nothing. This is a configuration problem, not a licence problem.

What Assured Digital changes

A licence audit identifies every inactive capability and whether a tier adjustment would close specific gaps - giving a clear picture before any spend decision.

What we own

Every layer of the Microsoft estate - configured and managed.

Select a layer to see scope, common failure points, Assured Digital's responsibility and the technologies involved.

Licence guidance

Microsoft Capability Explorer

Select a plan to see which capability layers it activates, what it enables, and where additional capability may be needed.

Productivity

Partial

Exchange Online, web-only Office apps, OneDrive 1 TB. No desktop Office applications.

Collaboration

Included

Microsoft Teams, SharePoint Online and OneDrive included. Governance and configuration still required - they are not managed by default.

Identity and access

Partial

Entra ID Free. MFA available but Conditional Access not enforced. No self-service password reset. No sign-in risk policies.

Device and security control

Not included

Available through additional licensing or services

Best suited to

Organisations where staff work primarily through web browsers, do not need local Office applications, and have separate MDM or security tooling already in place.

What this plan enables

  • Exchange Online email and calendar
  • Microsoft Teams for communication and meetings
  • SharePoint and OneDrive for file storage
  • Web-only versions of Office applications

Where additional capability may be needed

  • No desktop Office applications - web-only
  • No MDM or device compliance enforcement
  • No Conditional Access policies without Entra ID P1
  • No EDR or centralised threat triage
  • No sensitivity labels or information protection

How Assured Digital adds value

We configure Exchange, Teams and SharePoint governance, activate MFA and implement the strongest security posture achievable within the licence - and identify where additional licensing would address specific gaps.

What changes

Better-configured Microsoft environments deliver measurable outcomes.

Before

Conditional Access left at deployment defaults. MFA exceptions granted temporarily and never reverted. Admin accounts with persistent global admin rights.

What we change

We enforce Conditional Access across all users and devices, close every MFA exception with a documented decision, and separate admin accounts from daily-use accounts using Privileged Identity Management.

Result

Identity configuration that reflects intentional decisions rather than accumulated defaults - with a clear record of what is enforced and why.

Before

Defender for Business or Defender for Endpoint deployed but never reviewed. Alerts accumulating with no triage owner. Device compliance policies defined but not enforced via Conditional Access.

What we change

We connect compliance policies to Conditional Access so device state is a real control, assign alert triage ownership, and review Defender configuration against the environment.

Result

Security tooling that actively limits access based on device state rather than passively recording events.

Before

No visibility of who has access to what across SharePoint, Teams or shared mailboxes. Leavers still present in some systems. Service accounts with permissions that were never scoped.

What we change

We run a structured access review across identity, SharePoint permissions and service accounts ��� producing a prioritised remediation plan tied to existing licence capabilities.

Result

A clear and current picture of access across the estate, with every exception documented and a path to resolution.

Customer evidence

ASDANEducation & awardingStory in preparation

Supporting ASDAN with Microsoft 365 control and data governance.

ASDAN is an education charity and awarding organisation. Assured Digital supports their Microsoft 365 environment, data governance programme and cyber resilience posture - covering the full estate from identity and endpoint management through to SharePoint governance and ongoing licence optimisation.

What Assured Digital delivered

Identity and access configuration across Entra ID
Intune enrolment and device compliance policy
SharePoint governance structure and permissions review
Sensitivity labels and data governance baseline
Ongoing licence optimisation and capability activation
Cyber resilience posture and Defender configuration

Technologies

Microsoft 365Entra IDIntuneSharePointMicrosoft PurviewDefender for Business
Read the customer story
ASDAN  -  education charity and awarding organisation

Microsoft 365 Productivity & Control Review

See where Microsoft 365 control, adoption and AI readiness may be drifting.

Answer 15 questions across five Microsoft 365 control areas. Receive an instant score and PDF report covering governance, collaboration, identity and guest access, information protection and Copilot readiness, plus productivity and automation.

15 questions · Instant score · PDF report

What the diagnostic produces

Five-area control score

A scored view based on your answers across five Microsoft 365 control areas.

Control-gap indicators

Signals around ownership, privileged access, security consistency, collaboration sprawl and external access.

Copilot and information-protection readiness

Indicators covering oversharing, content hygiene, sensitivity labels, DLP and AI readiness.

Productivity and licence-value signals

Potential adoption gaps, licence underuse and workflow-automation opportunities.

Prioritised next steps

Practical actions and relevant support pathways included in your PDF report.