Skip to content
Griffin IT Group griffin markOakville IT ServicesPowered by Griffin IT Group

Capability

Microsoft 365 and Entra ID

Microsoft 365 is the single most consequential platform in most organisations. It holds the mail, the files, the collaboration and — through Entra ID — the identities that control access to everything else.

At a glance

  • Entra ID design, conditional access and privileged roles
  • Intune device management and compliance policies
  • Exchange Online, Teams and SharePoint configuration
  • Defender and Purview where the licensing supports it

Identity and access

Entra ID is the control plane. Its configuration decides who can sign in, from where, on what device, and what they can reach. We design conditional access policies that reflect real working patterns, separate privileged accounts from daily-use accounts, enable just-in-time elevation where licensing allows, and remove the legacy authentication protocols that bypass MFA entirely.

Application consent is a frequently overlooked area. Left at defaults, any user can grant a third-party application access to organisational data. Restricting consent and reviewing existing grants closes a route that phishing campaigns actively target.

  • Conditional access aligned to device and location
  • Privileged role separation and review
  • Legacy authentication disabled
  • Application consent policy and grant review
  • Guest access governance

Devices, data and collaboration

Intune brings devices under management: enrolment, configuration profiles, compliance policies that feed conditional access, application deployment, encryption enforcement and remote wipe. Without it, device state is unknown and conditional access has nothing meaningful to evaluate.

Exchange Online, SharePoint and Teams configuration determines whether collaboration is usable and whether data leaves in ways it should not. Sharing defaults, retention, sensitivity labelling and mail flow rules all get set deliberately rather than left as installed.

  • Intune enrolment, baselines and compliance policies
  • Application packaging and deployment
  • Exchange Online mail flow and protection rules
  • SharePoint and Teams architecture with lifecycle rules
  • Retention and sensitivity labelling where warranted

Security tooling and licensing

Defender for Office 365 and Defender for Endpoint add meaningful protection when correctly configured and actually monitored. Purview supports retention, data loss prevention and eDiscovery obligations. Both depend heavily on licence tier, which is why licensing review and security design belong in the same conversation.

We reconcile licences against actual staff and requirements, identify capability you already own but have not enabled, and flag where consolidating tiers is cheaper than the current combination of base licences and third-party products.

Questions

Frequently asked questions

Do we need Business Premium or E3?
It depends on which capabilities you actually need — device management, advanced threat protection, retention and DLP all sit at different tiers. We model the options against your requirements rather than defaulting to the highest tier.
Can you enable Copilot safely?
Copilot surfaces content the user can already access, so over-permissioned SharePoint sites become visible problems. Permission remediation and sharing governance come first; rollout follows.
Is third-party backup necessary?
Yes. Microsoft protects the platform, not your data against deletion, sync corruption or ransomware. Point-in-time recovery requires separate backup.

Have your tenant configured deliberately

A tenant review covers administrative sprawl, MFA coverage, sharing defaults, logging and licensing in one exercise.