Intune & Windows 11 Implementation
Our flagship end-to-end transformation: from SCCM, MDT and Group Policy to a cloud-native, security-hardened Intune and Windows 11 estate. Security baselines enforced, Conditional Access designed, Autopilot provisioning, application packaging, Group Policy migration and a phased Windows 11 rollout, all in one structured programme.
What you get
- Governed, security-hardened Intune environment assessed against CIS, NCSC and Microsoft security baselines
- Conditional Access policy design
- Zero-touch Autopilot provisioning across the estate
- Full documentation and knowledge transfer
Engagement shape: Typically 6 months for full delivery, in structured phases with governance checkpoints.
A future-ready platform combining Intune, Autopilot, Entra ID and Windows 11. Delivered for an NHS urgent-care provider ahead of the Windows 10 end-of-support deadline, and for a London university (including SCCM decommissioning) inside a six-month window.
Windows Autopilot Design & Implementation
Replace imaging infrastructure entirely: new devices ship straight to users and configure themselves out of the box. Discovery of your current build process, a Low-Level Design, Autopilot profiles, Intune enrolment, packaging standards and a supported pilot rollout.
What you get
- Low-Level Design document
- Autopilot profiles and Intune enrolment configured
- Supported pilot rollout
- MDT/PXE imaging retired
Engagement shape: Design-and-pilot engagements from as little as 14 days; full transformations run to around 6 months.
Zero-touch enrolment with no IT hands on any device, and no imaging infrastructure to maintain. Designed and piloted within 14 days for a healthcare group's device-refresh programme; delivered as part of a full six-month modern-management transformation for a private bank.
Exchange Server Migration
A phased, zero-disruption migration off unsupported on-premises Exchange onto the latest Exchange Subscription Edition: schema preparation, Database Availability Group setup, phased mailbox migration, coexistence maintained throughout, and legacy servers decommissioned.
What you get
- Migration design with clearly defined phases and joint responsibilities
- DAG configuration for resilience
- Phased mailbox and service migration with coexistence
- Legacy decommissioning
Engagement shape: Phased delivery, planned around your third-party integrations and timeline.
A fully supported messaging platform with no mail-flow disruption, and a clean stepping stone to Microsoft 365 when you're ready. For a specialist IP law firm we delivered Exchange 2016 to 2019 to Subscription Edition with zero disruption to email service.
OneDrive Migration
A run-book-driven move from mapped drives and UNC paths to OneDrive for Business: group model alignment, Intune configuration, tested migration scripts, communications planning and post-migration clean-up. The step that completes the cloud-native user experience.
What you get
- Entra ID group structures aligned and corrected
- Migration scripts tested against real user experience
- Structured run book with rollback options
- Post-migration clean-up
Engagement shape: Pilot cohort first; the run book then lets remaining users migrate with minimal IT overhead.
A clean, auditable OneDrive rollout that closes the hybrid-storage gap driving support tickets and data risk. Delivered for a private bank with piloted scripts and a run book their own team executed.
Azure Cross-Tenant Access
Secure collaboration between two Microsoft tenants in days, not months: requirements discovery across both organisations, security policy review, and governed cross-tenant access for Teams, shared resources, applications and data. The low-risk first step ahead of a merger-driven tenant consolidation.
What you get
- Cross-tenant requirements defined across both organisations
- Security and compliance policies reviewed
- Teams, file and application sharing configured and governed
Engagement shape: Around 3 days of discovery; implementation delivered in days.
Immediate, secure cross-tenant productivity while the full consolidation is planned: no guest-account workarounds. Delivered twice for a multi-academy trust as it merged with successive partner trusts: live within days of discovery the first time, and delivered on schedule when the trust merged again.