Services

Six disciplines. One team accountable for all of them.

Each one is scoped, priced, and run to the same standard. Most engagements start with one and end up touching three.

01

Microsoft 365 architecture

The tenant, identity, and endpoint architecture enterprises run on, built right the first time instead of patched together over five years. Every decision documented, every policy justified, so the next person who touches it understands why it's built the way it is.

What we deliver

  • Entra ID design: Conditional Access, just-in-time admin, no standing Global Admin
  • Intune and Autopilot from zero-touch provisioning to compliance gating
  • Licensing standardized by role: Business Premium, E3, F3, F1, and what each actually needs
  • Apple Business Manager and iOS MDM, with BYOD on app protection instead of full enrollment
  • Purview retention and DLP designed before the data sprawls, not after
  • Teams Voice and the collaboration stack tied to the same identity model

Typical situations

  • A tenant nobody designed, grown one exception at a time.
  • A company standing up Microsoft 365 properly for the first time.
  • An acquisition that needs two tenants to become one.
Talk to us about architecture

How the layers fit together

02

Security and hardening

Defender, WDAC, attack surface reduction, and the configuration that turns a real audit or pen test into a formality instead of a scramble. Findings get remediated once, properly, not patched over until the next assessment surfaces the same gap.

What we deliver

  • Defender for Endpoint P2 in block mode: attack surface reduction, WDAC, network protection
  • Defender for Office 365: admin-only quarantine, Safe Attachments, impersonation controls
  • Conditional Access and device compliance that actually gate access
  • Privileged access: just-in-time roles, break-glass accounts tested, admin workstations where warranted
  • Pen test and red team remediation in production, with evidence, without breaking the business
  • Insurance and customer security questionnaires answered from configuration, not from memory

Typical situations

  • A pen test came back with findings you've seen before.
  • The insurance renewal wants MFA, EDR, and backups proven, not promised.
  • A phishing incident got further than it should have.
Talk to us about hardening

03

Process and governance

Documentation, change control, and operational standards that mean your systems outlast any one person. The goal isn't dependency on Corbel. It's a foundation your team can own and run.

What we deliver

  • A written standard for every tenant setting, with the reason behind it
  • Change control sized for a small team, not a bureaucracy
  • A knowledge base your team actually uses
  • Help desk with categories, SLAs, and reporting from day one
  • Joiner, mover, leaver process tied to HR and reconciled against the census
  • Quarterly review of what changed, what drifted, and what to fix

Typical situations

  • Your last admin left and nobody knows why anything is set the way it is.
  • The board wants IT to be auditable.
  • Onboarding takes a week and offboarding takes a month.
Talk to us about governance

04

Co-managed IT and tooling

The operations and security stack we run, licensed through Corbel and deployed into your tenant. We own the standards, the vendors, and the escalations. Your team owns the day to day.

What we deliver

  • RMM and tenant backup, run to a written standard and reported every cycle
  • Third-party patching inside a defined window, not assumed
  • 24x7 managed detection and response layered on Defender, with a human on the other end
  • Email security and DNS filtering on Windows and iOS
  • Password management with SSO, deployed once and run for you
  • Escalation to senior engineers, not a ticket queue

Typical situations

  • You have an IT team but no security operations.
  • The MSP charges for everything and owns nothing.
  • You want the tooling without a full outsource.
Talk to us about co-managed IT

05

Licensing, hardware, and cost

Microsoft CSP licensing, hardware procurement, and the cost analysis nobody does before a renewal. Margin disclosed. We'll tell you when not to buy.

What we deliver

  • CSP transfer off your incumbent without a lapse in service
  • Licensing bands by job title, with orphaned and overspecified SKUs retired
  • Laptop fleet refresh: tiered specs, vPro as the floor, Autopilot-registered from the factory
  • Azure and SIEM spend modeled from your own cost exports before you sign anything
  • Renewal prep: what you use, what you pay for, what to cut

Typical situations

  • The Microsoft renewal is in 60 days.
  • Half the fleet is out of warranty.
  • Nobody can explain the Azure bill.
Talk to us about licensing

06

Transitions and integrations

Acquisitions, carve-outs, and MSP exits. The work between signing and stable, run by people who have done the cutover and know where it breaks.

What we deliver

  • Tenant-to-tenant migration and identity consolidation for acquisitions
  • Carve-outs: a clean tenant stood up out of a parent company's environment
  • Cutover off an incumbent MSP: identities removed, agents replaced, help desk live before the old contract ends
  • Mobile migration off legacy or carrier MDM into Intune and Apple Business Manager
  • A written handoff so your team runs it without us in the room

Typical situations

  • The deal closes in 90 days and IT hasn't been scoped.
  • The MSP contract ends next quarter.
  • Two companies, two tenants, one board.
Talk to us about a transition