Skip to content

Work from anywhere. Prove control everywhere.

Azure Virtual Desktop plus Microsoft 365 hardening, built for EU operators whose staff and contractors work outside the office. Corporate data stays inside the Azure boundary, personal laptops get a contained session, and every access decision is one your auditor can replay.

100%
Device compliance in 30 days
2 tiers
Managed devices and BYOD, enforced differently
EU-hosted
AVD in West / North Europe regions
90 days
Scan to audit-ready evidence pack

The 100% figure is founder casework at a regulated Maltese operator (~100 staff): a full Intune plus Conditional Access rollout across a BYOD-heavy fleet. The story, including what broke first, is in the field notes below.

The problem

Remote work without remote security is a liability.

Your team works from home, co-working spaces, airport lounges. The corporate perimeter dissolved years ago, but your security controls never caught up.

BYOD risk exposure

Personal laptops connect to corporate data over home networks. No disk encryption enforcement, no compliance baseline, no visibility into what leaves the perimeter.

AVD pilot stuck in limbo

You licensed Azure Virtual Desktop six months ago. The PoC ran on a single VM. Nobody deployed it to production because the networking and identity layers were never scoped.

Shadow IT sprawl

Remote workers install unapproved tools, share files via personal Dropbox, and use consumer AI services on corporate data. Every offboarding leaks something.

The mechanism

Every sign-in argues its case.

Conditional Access evaluates identity, device health, sign-in risk and the data boundary on every request. The same person gets a different session from a managed laptop, a personal MacBook or an attacker's VM. Pick a scenario and watch the policy decide.

Loading the interactive console

Illustrative policy set. The production baseline ships as Terraform in your tenant and always starts in report-only mode before anything is enforced.

The device rule

Zero Trust doesn't mean I don't trust my people. It means I don't trust the home laptops their kids are installing pirated game mods on.
- Michal Jatczak, founder · ITSailor
Field notes

The BYOD cleanup that hit 100% compliance in 30 days.

Before ITSailor, the founder ran this rollout at a regulated Maltese operator with roughly 100 staff: total device chaos, BYOD everywhere, no compliance verification, and auditors who actually open the logs.

Case: device trust at a regulated operator

The build. A full Microsoft Intune cycle wired to Conditional Access in Entra ID: BitLocker enforced, MDM or MAM on every device touching corporate data, and access decisions moved from habit to policy.

100%
Device compliance in 30 days
2 days → 30 min
New-hire setup time

The part that went wrong

The first enforcement push locked out the entire marketing team. They were on personal MacBooks without MDM profiles. A VIP exception flow was built on the fly, and the team migrated to corporate machines over a weekend.

What that weekend changed

Two rules came out of the MacBook lockout, and both ship in every build since. Policies start in report-only mode, watched for a week before anything is enforced. And unmanaged devices get their own containment tier with browser sessions and app protection, because a blanket block just teaches people to work around you.

Deeper identity work

Conditional Access policy-as-code, JIT admin and the SCIM joiner-mover-leaver lifecycle have their own narrative on the Zero Trust Security page.

Zero Trust Security
What gets built

Six controls between your data and the coffee shop.

Everything lands in your tenant and your repository, documented in the Exit Kit so the next engineer can pick it up in 24 hours.

Conditional Access policy-as-code

Entra policies in Terraform: MFA enforcement, device filters, risk-based session controls. Reviewed in pull requests, rolled out in report-only mode first.

AVD landing zone

Multi-session Windows 11 host pools, FSLogix profile containers, auto-scaling with cost guardrails. Deployed to West or North Europe, sized to concurrent users.

Device compliance baseline

Intune policies for the fleet you already own: disk encryption, OS minimums, screen lock. Non-compliant means no session, and the user sees why.

BYOD containment tier

Browser-based AVD for personal devices and contractors: downloads off, clipboard controlled, watermark on, sessions that expire. Work happens, data stays.

Data boundary + DLP guardrails

Sensitive content stays inside the Azure boundary. DLP policies cover the common leak paths: mail, chat, personal cloud drives.

Evidence pack

Every control mapped to DORA Art. 9, NIS2 Art. 21 and NIST CSF 2.0, formatted for a supervisory review or an internal audit.

Productized engagements

Measure first. Then fixed scope, never T&M.

The scan is free and self-serve. The implementation and the retainer are agreed before work starts, with no hourly billing at any tier.

Workspace Posture Scan

Run it yourself. See the gaps an attacker would.

FreeSelf-serve · minutes
  • Connect Microsoft 365 read-only: live MFA coverage, Conditional Access gaps, admin roles
  • Risky sign-in and account hygiene findings (inactive, blocked, guest, shared)
  • Shadow SaaS and OAuth-grant inventory with risky scopes ranked
  • DORA / NIS2 / NIST CSF 2.0 gap map, scored per control
  • CFO-ready PDF you keep, no obligation

Outcome

Your remote-access posture measured before anyone sells you anything.

Run the free scan
Most popular

Secure Workspace Implementation

AVD, hardening and the two enforcement tiers, wired and evidenced.

Scoped to youFixed scope · 6-8 weeks
  • AVD host pools with FSLogix and cost-guarded autoscaling
  • Conditional Access baseline as Terraform, report-only before enforcement
  • Device compliance for corporate machines + BYOD containment tier
  • DLP guardrails on the common leak paths
  • Evidence pack, runbooks and Exit Kit in your repository

Outcome

Remote access runs on policy instead of habit, and the evidence pack lands with the handover.

Scope the implementation

Managed Workspace

We hold the posture. Your team just signs in.

Scoped to youMonthly retainer · 6 months min.
  • Monthly posture report with remediation tracking
  • AVD scaling and cost review as headcount moves
  • Policy updates as staff, apps and vendors change
  • Quarterly access review with a signed evidence refresh
  • Single Slack channel to the engineer who built it

Outcome

Posture stays green as the team changes, and audit prep stops being a season.

Talk about managed
Malta & EU compliance

DORA, NIS2 and NIST CSF 2.0, mapped per control.

ITSailor delivers from the EU. Every workspace control ships with an explicit mapping to the clauses your auditor will ask about.

DORAArt. 9

ICT protection and prevention. AVD isolation, Conditional Access and endpoint compliance map directly to the control objectives.

NIS2Art. 21

Cyber security risk management. Remote access policies, device baselines and DLP controls documented in the handover pack.

NIST CSF 2.0A.5 / A.8

Access control, teleworking security and endpoint management, mapped per policy for regulated EU operators.

Provisioned stack

Licences that can sit under Secure Remote Workforce.

ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.

Microsoft

Microsoft 365 Business Premium EEA (no Teams)

€19.54 / user / month

Monthly commit

Includes Defender for Business, Defender for Office 365 P1, Entra ID P1, Intune P1 - never double-sell these alongside BP.

View bundle

Microsoft

Microsoft 365 E3 EEA (no Teams)

€36.43 / user / month

Monthly commit

Microsoft

Microsoft 365 E5 EEA (no Teams)

€60.85 / user / month

Monthly commit

Microsoft

Microsoft Defender for Office 365 (Plan 1)

€2.08 / user / month

Monthly commit

Microsoft

Microsoft Entra ID P1

€7.32 / user / month

Monthly commit

Microsoft

Microsoft Entra ID P2

€10.44 / user / month

Monthly commit

Nord Security

NordLayer Business VPN (ZTNA)

Usage-based, quoted

Monthly commit

Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user network-access platform: apps plus browser extension, ZTNA/SASE, central gateway and logs. Business-correct alternative to consumer VPNs (Surfshark/NordVPN). Sold quoted/usage-based.

Nord Security

NordPass Business (password manager)

Usage-based, quoted

Monthly commit

Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user password manager with admin console and policy. Pairs with NordLayer in the Secure Remote Workforce / Zero Trust Starter bundles (planned). Sold quoted/usage-based.

FAQ

Honest answers to the questions buyers actually ask.

We already have Microsoft 365. Why do we need a separate AVD deployment?

+

Microsoft 365 gives you apps. AVD gives you a full Windows desktop streamed from Azure, with corporate data that never touches the endpoint. For BYOD-heavy or contractor-heavy teams, this is the difference between "data stays in the EU" and "data lives on a personal laptop in a coffee shop".

Do we need to buy new laptops for this?

+

No. Corporate devices you already own get enrolled into the compliance baseline; personal and contractor devices get the contained browser tier. Device procurement is deliberately out of scope at ITSailor today, so the design assumes your existing fleet.

How does pricing work for Azure Virtual Desktop?

+

AVD has two cost components: Azure compute for host pools (pay-as-you-go or reserved instances) and the Microsoft 365 licence you already own (E3/E5 includes AVD rights). We size the deployment to your concurrent user count, not total headcount, which typically reduces compute costs by 40-60% vs 1:1 VMs.

Can contractors and external partners use AVD without a corporate device?

+

Yes. AVD supports browser-based access with no client install, and Conditional Access enforces MFA plus session time limits for external identities. Sensitive data never leaves the Azure boundary regardless of the endpoint.

How does this map to DORA?

+

Every control in the deployment carries an explicit mapping to DORA Article 9 (ICT protection and prevention), NIS2 Article 21 and NIST CSF 2.0. The implementation closes with an evidence pack formatted for your next supervisory review or internal audit.

Who actually does the work?

+

One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person holding the Terraform plan.

Decide which device states are allowed to reach company data.

Compliance policy, conditional access and the unmanaged-device path are one conversation. The workshop settles them against the devices your people actually use.