Security & Compliance

Modern Workplace & Microsoft 365

Modern workplace only works when identity, device and data controls agree with each other. We deploy Microsoft 365, Entra ID and endpoint management as one design rather than three projects.

The promise of the modern workplace is that a person can be productive from any location on any approved device. The risk is that the same architecture makes an attacker productive from any location on any device.

The difference is whether identity, device compliance and data controls were designed together. CDTS builds the joins: conditional access that reads real device posture, app protection that survives a lost handset, and provisioning that gets a new starter working on day one without a manual build.

We work to Zero Trust principles in the way the ACSC and Microsoft describe them — verify explicitly, use least privilege, assume breach — and we make the trade-offs visible instead of shipping defaults.

What’s included

Scope of the service

The components we deliver and operate under this service. Scope is agreed per engagement — this is the standard shape.

01

Identity & access management

Entra ID design, conditional access policy sets, MFA and phishing-resistant authentication rollout.

02

Zero Trust architecture

Access decisions built on verified user, verified device and verified context — designed, documented and tested.

03

Microsoft 365 deployment

Exchange Online, Teams, SharePoint and OneDrive deployed and hardened, with sensible sharing and retention defaults.

04

Automated provisioning

Windows Autopilot and identity-driven configuration so a new starter is productive on day one without a manual build.

05

Data protection & DLP

Sensitivity labelling and data loss prevention aligned to your classification scheme rather than a vendor template.

06

Collaboration governance

Guest access, lifecycle and sharing rules for Teams and SharePoint so collaboration does not become sprawl.

Platforms & vendors we deliver on
  • Microsoft 365
  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft Defender
  • Windows Autopilot

Common questions

We already have MFA. Is that enough?

It is the single most valuable control you can turn on, and it is no longer sufficient on its own. Push-bombing and adversary-in-the-middle phishing both defeat basic MFA. Phishing-resistant methods plus conditional access that reads real device posture is where the bar sits now.

What does Zero Trust actually mean in practice?

Three things, applied consistently: verify explicitly, use least privilege, assume breach. In practice that is access decisions built on verified user plus verified device plus verified context — not a product you buy. We design it, document the trade-offs, and test it.

How long does a Microsoft 365 deployment take?

It depends far more on data migration and governance decisions than on the technical build. The build is usually weeks; agreeing sharing, retention and labelling rules with the business is what sets the real timeline.

Can you fix a Microsoft 365 tenancy someone else configured?

Yes, and it is common work. We start with a configuration and licence review against your policy, then remediate in a sequence that does not surprise your users.

Next step

Talk to us about Modern Workplace & Microsoft 365

Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.