Microsoft Azure Services
Azure engagements at OMAV start at the identity layer, because that is where Azure projects go wrong more often than anywhere else. Entra ID, conditional access and privileged access are assessed before landing zones and workloads.
Identity first, then everything else
Azure estates fail at the identity layer. Conditional access policies that overlap and contradict, privileged accounts with standing rather than just-in-time access, guest accounts nobody reviewed, and legacy authentication still enabled because disabling it broke something once.
This matters more in Azure than in other clouds because identity is the control plane for both the cloud estate and Microsoft 365. A weakness there is not confined to infrastructure — it reaches email, files and everything federated to it.
So we assess identity first, then account and landing zone design, then workloads one at a time. We do not resell Azure capacity, so the sizing advice has no margin attached to it.
What an Azure engagement covers
Six workstreams, in this order deliberately.
Identity and access review
Entra ID configuration, conditional access policy set, privileged role assignments, guest access and legacy authentication — reviewed for contradictions as well as for gaps.
Privileged access
Standing administrative rights replaced with just-in-time elevation and approval where the tenant supports it, because permanent global administrators are the finding that matters most and is easiest to fix.
Landing zone and subscriptions
Management group hierarchy, subscription design, policy assignment and networking baseline, so new workloads inherit governance rather than inventing it.
Workload assessment
Each workload assessed individually — move, re-platform, or leave it where it is — with the cost of each option stated rather than a blanket recommendation.
Backup and recovery
Azure Backup and Site Recovery configured to agreed RPO and RTO, with restores actually performed and dated rather than configuration treated as completion.
Cost governance
Tags, budgets, reservations modelled against measured usage, and a monthly review with a named owner.
How an Azure engagement runs
Assess identity
Entra ID, conditional access, privileged roles and legacy authentication reviewed, with findings ranked by exploitability rather than by count.
Remediate access
Privileged access tightened and conditional access rationalised into a coherent policy set, tested against real sign-in patterns before enforcement.
Design the landing zone
Management groups, subscriptions, policy and networking baseline established so future workloads land governed.
Assess workloads
Each workload given a disposition with costed options, sequenced by risk and dependency.
Baseline and review
Backup and recovery configured and restore-tested, cost governance in place with an owner, then a monthly review cycle.
Identity findings by priority
Where remediation effort returns the most.
| Finding | Risk | Effort to fix | Priority |
|---|---|---|---|
| Standing global administrators | Very high | Low | Immediate |
| Legacy authentication enabled | High | Low to moderate | Immediate |
| Contradictory conditional access | High | Moderate | High |
| Unreviewed guest accounts | Moderate | Low | High |
| No break-glass account | Moderate | Very low | High |
| Missing sign-in risk policies | Moderate | Low | Medium |
What we will say before starting
Conditional access cannot be tightened safely without knowing how people actually sign in. Policies enforced without testing against real sign-in patterns lock out legitimate users, usually on a Monday morning and usually including someone senior. We test in report-only mode first, which adds a week and prevents that.
We also scope Microsoft 365 only where it touches identity, security posture and backup. Full tenant administration — licensing, Teams governance, SharePoint architecture — is a different discipline, and we would rather name that boundary than accept the work and cover it thinly.
- Identity is the control plane for both Azure and Microsoft 365. Start there.
- Standing global administrators are the highest-risk, lowest-effort finding in most tenants.
- Test conditional access in report-only mode before enforcing it.
- Assess workloads one at a time; a blanket migration recommendation has not been done.
Questions buyers ask about this
Why start with identity rather than infrastructure?
Because in Azure, identity is the control plane for the cloud estate and for Microsoft 365 simultaneously. A weakness there is not contained to infrastructure. It is also where we find the highest-risk, lowest-effort remediations — standing global administrators and legacy authentication in particular.
We are mid-migration and stuck. Can you take over?
Yes. The first deliverable is an honest state assessment: what moved, what half-moved, what is now running in two places, and what identity or networking decisions were made implicitly along the way. That assessment is usually uncomfortable and it is the only sound basis for finishing.
Do you cover Microsoft 365 as well?
Where it touches identity, security posture and backup, yes — that is inseparable from Azure identity work. Full tenant administration including licensing, Teams governance and SharePoint architecture is a separate discipline, and we say so rather than covering it thinly.
AWS or Azure?
Usually decided by what your team already operates and what your software estate assumes, not by feature comparison. Microsoft-centric organisations with Entra ID, Windows Server and SQL Server have a genuine advantage in Azure. Where there is no such gravity, either works and the deciding factor is your team’s existing skills.
How do you handle cost?
Tags and budgets with named owners, reservations modelled against measured usage rather than provisioned size, and a monthly variance review. We have no margin on your consumption, so the recommendations tend toward less of it.
Marked up as FAQPage structured data, matching the visible text exactly.
Still not sure this is the right service?
Answer four questions and we will tell you which one fits — or that none of them do.
Tell us what you are trying to fix.
A short conversation about the objective, the constraints and the timing. If we are not the right fit, we will say so.