< cd ../projects

~/projects/m365-tenant-rollout

Microsoft 365 Tenant Rollout

year
2024
role
Migration engineer
client
Professional services firm
  • Microsoft 365
  • Exchange
  • Intune
  • Security

The brief

An on-prem Exchange 2013 server well past end-of-life, no MFA, and staff laptops that had never seen a management policy. The firm's insurer was starting to ask pointed questions.

What I did

  • Planned a staged hybrid migration and moved 120 mailboxes in batches, nights and weekends, with no mail loss and no NDR storms.
  • Enforced MFA and conditional access for all users; blocked legacy authentication.
  • Enrolled all laptops into Intune with compliance policies, BitLocker and automated app deployment.
  • Configured SPF, DKIM and DMARC properly — their mail finally stopped landing in customers' spam folders.
  • Ran short training sessions and wrote one-page guides staff actually kept.

Outcome

  • Exchange server decommissioned, licensing consolidated
  • 100% MFA adoption within three weeks
  • Lost/stolen laptops are now a remote-wipe, not an incident report
  • Passed the insurer's cyber questionnaire on the next renewal