Modern Workspace
Microsoft 365 and Google Workspace operated like infrastructure: a licence ledger, device baselines, access reviews, and documentation the next engineer can pick up.
Connect Microsoft 365 read-only or drop a CSV. It surfaces dead licences, shadow SaaS and risky app permissions in minutes.
What this covers
Tenant operations for Microsoft 365 and Google Workspace: identity, licences, endpoints, migrations, and procurement routed through the Pax8 marketplace at wholesale.
Who it is for
Operators without a dedicated tenant administrator, and IT leads who want the tenant run to a written baseline instead of tribal knowledge.
Where to start
Start free with the SaaS audit, or book the €499 Architecture Workshop: a 2-hour live session in your tenant and a written deliverable in 5 days.
How it ends
Every engagement closes with an Exit Kit. Another engineer can take the tenant over in 24 hours.
Workspace estates rarely fail loudly. They leak: decisions vanish into inboxes, licences outlive their owners, and onboarding stays manual because nobody wrote the baseline down.
Mailbox permissions, guest access, Teams policies and licence exceptions are granted by email. Once the thread closes, the decision has no record.
Material changes move into one queue with an owner and a dated entry.
Tenant decision register with named owners
Licences are bought per request and never reclaimed. The bill grows while seats sit unused and nobody can say which plan maps to which role.
A licence ledger reconciled against real sign-in activity, with a rationalisation plan priced per seat.
Licence and owner ledger
New hardware means a manual click-and-install session per laptop, and leavers keep working credentials until somebody remembers.
Autopilot enrollment, Intune baselines and a joiner-mover-leaver runbook that runs the same way every time.
Device baseline plus JML runbooks
Solution narratives
3 narratives: full pitch with deliverables, scope and case context
Services in this pillar
6 discrete engagements: fixed scope, written deliverables
Identity and endpoint
Intune and Conditional Access that survived audit pressure.
A regulated operator moved from unmanaged BYOD and manual laptop setup to enforceable device compliance, BitLocker, MDM, and Autopilot onboarding.
Anonymised outcomes from the founder's prior operating roles in regulated industry, stated as such, not ITSailor client engagements.
On the record- 100% device compliance in 30 days
- 2 days to 30 minutes hardware onboarding
Four steps, one destination.
The same sequence on every engagement. It starts read-only and it ends with the Exit Kit in your hands, so the exit is designed before the work begins.
- AuditRead-only discovery in your tenant. Findings arrive in writing, with sources.
- DecideThe €499 Architecture Workshop: a 2-hour live session and a written deliverable in 5 days. You own the plan.
- BuildFixed scope, agreed change windows, evidence recorded as the work lands.
- Hand overExit Kit within 24 hours. Runbooks, source, credentials inventory, architecture record.
Can you take over a tenant that someone else set up?
Yes, and it is the usual starting point. Discovery is read-only first: we document what exists, flag what drifts from the baseline, and agree the order of changes before anything is enforced.
Do we have to move our licences to you?
No. Licensing through the Pax8 marketplace is optional. When you use it, pricing is wholesale and every licence is transferable to your own direct billing through the Exit Kit on day one.
Do we need E5, or is E3 enough?
Anyone can buy E5 licences. The skill is knowing when E3 plus the right Intune policy is the better answer. The licence ledger prices both routes against what your roles actually use before anyone commits.
Can you work alongside our existing helpdesk or MSP?
Yes. The split that works: your helpdesk keeps user-facing tickets, ITSailor owns the tenant baseline, governance and the decision register. Both sides work from the same documentation.
What happens when the engagement ends?
You keep the tenant, every licence, and the documentation. The Exit Kit hands the runbooks, configuration record and credential inventory to whoever runs the estate next, including a competitor.
Google Workspace too, or Microsoft only?
Both, and mixed estates. Google Workspace gets the same treatment: admin baseline, licence review, retention policy, and a documented operating model instead of a shared admin password.