Work from anywhere. Prove control everywhere.
Azure Virtual Desktop plus Microsoft 365 hardening, built for EU operators whose staff and contractors work outside the office. Corporate data stays inside the Azure boundary, personal laptops get a contained session, and every access decision is one your auditor can replay.
The 100% figure is founder casework at a regulated Maltese operator (~100 staff): a full Intune plus Conditional Access rollout across a BYOD-heavy fleet. The story, including what broke first, is in the field notes below.
Remote work without remote security is a liability.
Your team works from home, co-working spaces, airport lounges. The corporate perimeter dissolved years ago, but your security controls never caught up.
BYOD risk exposure
Personal laptops connect to corporate data over home networks. No disk encryption enforcement, no compliance baseline, no visibility into what leaves the perimeter.
AVD pilot stuck in limbo
You licensed Azure Virtual Desktop six months ago. The PoC ran on a single VM. Nobody deployed it to production because the networking and identity layers were never scoped.
Shadow IT sprawl
Remote workers install unapproved tools, share files via personal Dropbox, and use consumer AI services on corporate data. Every offboarding leaks something.
Every sign-in argues its case.
Conditional Access evaluates identity, device health, sign-in risk and the data boundary on every request. The same person gets a different session from a managed laptop, a personal MacBook or an attacker's VM. Pick a scenario and watch the policy decide.
Illustrative policy set. The production baseline ships as Terraform in your tenant and always starts in report-only mode before anything is enforced.
The device rule
“Zero Trust doesn't mean I don't trust my people. It means I don't trust the home laptops their kids are installing pirated game mods on.”
The BYOD cleanup that hit 100% compliance in 30 days.
Before ITSailor, the founder ran this rollout at a regulated Maltese operator with roughly 100 staff: total device chaos, BYOD everywhere, no compliance verification, and auditors who actually open the logs.
The build. A full Microsoft Intune cycle wired to Conditional Access in Entra ID: BitLocker enforced, MDM or MAM on every device touching corporate data, and access decisions moved from habit to policy.
The part that went wrong
The first enforcement push locked out the entire marketing team. They were on personal MacBooks without MDM profiles. A VIP exception flow was built on the fly, and the team migrated to corporate machines over a weekend.
What that weekend changed
Two rules came out of the MacBook lockout, and both ship in every build since. Policies start in report-only mode, watched for a week before anything is enforced. And unmanaged devices get their own containment tier with browser sessions and app protection, because a blanket block just teaches people to work around you.
Deeper identity work
Conditional Access policy-as-code, JIT admin and the SCIM joiner-mover-leaver lifecycle have their own narrative on the Zero Trust Security page.
Zero Trust SecuritySix controls between your data and the coffee shop.
Everything lands in your tenant and your repository, documented in the Exit Kit so the next engineer can pick it up in 24 hours.
Conditional Access policy-as-code
Entra policies in Terraform: MFA enforcement, device filters, risk-based session controls. Reviewed in pull requests, rolled out in report-only mode first.
AVD landing zone
Multi-session Windows 11 host pools, FSLogix profile containers, auto-scaling with cost guardrails. Deployed to West or North Europe, sized to concurrent users.
Device compliance baseline
Intune policies for the fleet you already own: disk encryption, OS minimums, screen lock. Non-compliant means no session, and the user sees why.
BYOD containment tier
Browser-based AVD for personal devices and contractors: downloads off, clipboard controlled, watermark on, sessions that expire. Work happens, data stays.
Data boundary + DLP guardrails
Sensitive content stays inside the Azure boundary. DLP policies cover the common leak paths: mail, chat, personal cloud drives.
Evidence pack
Every control mapped to DORA Art. 9, NIS2 Art. 21 and NIST CSF 2.0, formatted for a supervisory review or an internal audit.
Measure first. Then fixed scope, never T&M.
The scan is free and self-serve. The implementation and the retainer are agreed before work starts, with no hourly billing at any tier.
Workspace Posture Scan
Run it yourself. See the gaps an attacker would.
- Connect Microsoft 365 read-only: live MFA coverage, Conditional Access gaps, admin roles
- Risky sign-in and account hygiene findings (inactive, blocked, guest, shared)
- Shadow SaaS and OAuth-grant inventory with risky scopes ranked
- DORA / NIS2 / NIST CSF 2.0 gap map, scored per control
- CFO-ready PDF you keep, no obligation
Outcome
Your remote-access posture measured before anyone sells you anything.
Secure Workspace Implementation
AVD, hardening and the two enforcement tiers, wired and evidenced.
- AVD host pools with FSLogix and cost-guarded autoscaling
- Conditional Access baseline as Terraform, report-only before enforcement
- Device compliance for corporate machines + BYOD containment tier
- DLP guardrails on the common leak paths
- Evidence pack, runbooks and Exit Kit in your repository
Outcome
Remote access runs on policy instead of habit, and the evidence pack lands with the handover.
Managed Workspace
We hold the posture. Your team just signs in.
- Monthly posture report with remediation tracking
- AVD scaling and cost review as headcount moves
- Policy updates as staff, apps and vendors change
- Quarterly access review with a signed evidence refresh
- Single Slack channel to the engineer who built it
Outcome
Posture stays green as the team changes, and audit prep stops being a season.
DORA, NIS2 and NIST CSF 2.0, mapped per control.
ITSailor delivers from the EU. Every workspace control ships with an explicit mapping to the clauses your auditor will ask about.
ICT protection and prevention. AVD isolation, Conditional Access and endpoint compliance map directly to the control objectives.
Cyber security risk management. Remote access policies, device baselines and DLP controls documented in the handover pack.
Access control, teleworking security and endpoint management, mapped per policy for regulated EU operators.
Licences that can sit under Secure Remote Workforce.
ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.
Microsoft
Microsoft 365 Business Premium EEA (no Teams)
€19.54 / user / month
Monthly commit
Includes Defender for Business, Defender for Office 365 P1, Entra ID P1, Intune P1 - never double-sell these alongside BP.
View bundleMicrosoft
Microsoft 365 E3 EEA (no Teams)
€36.43 / user / month
Monthly commit
Microsoft
Microsoft 365 E5 EEA (no Teams)
€60.85 / user / month
Monthly commit
Microsoft
Microsoft Defender for Office 365 (Plan 1)
€2.08 / user / month
Monthly commit
Microsoft
Microsoft Entra ID P1
€7.32 / user / month
Monthly commit
Microsoft
Microsoft Entra ID P2
€10.44 / user / month
Monthly commit
Nord Security
NordLayer Business VPN (ZTNA)
Usage-based, quoted
Monthly commit
Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user network-access platform: apps plus browser extension, ZTNA/SASE, central gateway and logs. Business-correct alternative to consumer VPNs (Surfshark/NordVPN). Sold quoted/usage-based.
Nord Security
NordPass Business (password manager)
Usage-based, quoted
Monthly commit
Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user password manager with admin console and policy. Pairs with NordLayer in the Secure Remote Workforce / Zero Trust Starter bundles (planned). Sold quoted/usage-based.
Built from three standing services.
Azure Virtual Desktop
Managed AVD: host pools, FSLogix profiles and cost-guarded autoscaling in EU regions.
View serviceMicrosoft 365 Tenant Hardening
ITSailor Microsoft 365 Security Baseline: Conditional Access, Defender configuration and sensitivity labels.
View serviceMicrosoft 365 Management
Day-to-day tenant operations and governance, so the hardened baseline stays hardened.
View serviceHonest answers to the questions buyers actually ask.
We already have Microsoft 365. Why do we need a separate AVD deployment?
+
Microsoft 365 gives you apps. AVD gives you a full Windows desktop streamed from Azure, with corporate data that never touches the endpoint. For BYOD-heavy or contractor-heavy teams, this is the difference between "data stays in the EU" and "data lives on a personal laptop in a coffee shop".
Do we need to buy new laptops for this?
+
No. Corporate devices you already own get enrolled into the compliance baseline; personal and contractor devices get the contained browser tier. Device procurement is deliberately out of scope at ITSailor today, so the design assumes your existing fleet.
How does pricing work for Azure Virtual Desktop?
+
AVD has two cost components: Azure compute for host pools (pay-as-you-go or reserved instances) and the Microsoft 365 licence you already own (E3/E5 includes AVD rights). We size the deployment to your concurrent user count, not total headcount, which typically reduces compute costs by 40-60% vs 1:1 VMs.
Can contractors and external partners use AVD without a corporate device?
+
Yes. AVD supports browser-based access with no client install, and Conditional Access enforces MFA plus session time limits for external identities. Sensitive data never leaves the Azure boundary regardless of the endpoint.
How does this map to DORA?
+
Every control in the deployment carries an explicit mapping to DORA Article 9 (ICT protection and prevention), NIS2 Article 21 and NIST CSF 2.0. The implementation closes with an evidence pack formatted for your next supervisory review or internal audit.
Who actually does the work?
+
One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person holding the Terraform plan.
Decide which device states are allowed to reach company data.
Compliance policy, conditional access and the unmanaged-device path are one conversation. The workshop settles them against the devices your people actually use.