Skip to main content

Your IT grew with the business. Your security structure did not.

We bring the Microsoft 365 and infrastructure estate of internationally operating mid-market companies to a state that withstands an audit - and on which AI is permitted in the first place.

30 minutes · no sales pitch · an honest read on whether we fit

From the reference list

  • LucaNet AG
  • COMAVA GmbH
  • S.I.S. Süd Industrie-Anlagen-Service GmbH
  • Nexburg GmbH

18 years · more than 50 projects, each one owned by a senior architect

Exploded drawing of a Microsoft 365 and infrastructure estateFive stacked layers: identity and access, devices and endpoints, data and permissions, network and certificates, and the AI layer above them. Each layer is numbered and connected to an annotation.IDENTITYDEVICESDATANETWORKAI LAYER0102030405FOUNDATIONTOP LAYER
  • 01Identity and access. Conditional Access, time-bound privileged roles, tested break-glass accounts.
  • 02Devices and endpoints. Intune compliance, Autopilot, hardening against CIS baselines.
  • 03Data and permissions. External sharing, guest access, Teams and SharePoint structure.
  • 04Network and certificates. 802.1X with certificates instead of passwords, segmentation, PKI.
  • 05AI layer. Without the four layers beneath it, every assistant is an open data leak.
Applies to
200 to 1,500 users
Qualification
SC-100 · AZ-305

Four situations that bring companies to us

They rarely arrive out of curiosity. Usually there is a date, an audit finding, or a management decision that will not wait.

  • A.01You have a NIS2 deadline. The gap analysis has not started.Outcome: a prioritised action list with effort estimates and a version for the board.
  • A.02An acquisition or divestment forces a tenant split on a fixed date.Outcome: a migration plan with a tested cutover and a documented way back.
  • A.03Microsoft 365 is in production, but guest access, Teams sprawl and Conditional Access were never set up properly.Outcome: a governance baseline your team carries on without us.
  • A.04Management has approved AI. Nobody knows which data the assistant would see.Outcome: classification, permission clean-up, and only then the rollout.

Three outcomes, one foundation

Identity, data and devices are the same foundation. That is why one architect can carry all three - and why the order is not negotiable.

Secure IT

Layers 01 - 04

An incident does not take you out of operation, because identity, endpoints, network access and recovery were designed rather than grown.

  • Zero Trust architecture and Conditional Access
  • Endpoint hardening with Intune and CIS baselines
  • PKI, 802.1X and network access control
  • Backup and a tested recovery path

Compliance you can evidence

Layers 01 - 05

NIS2, GDPR and customer audits are not satisfied by looking tidy. They are satisfied when you can prove it. We build the evidence into daily operation instead of collecting it before every audit.

  • NIS2 gap analysis and remediation roadmap
  • Classification and information protection with Purview
  • Recertification of access and guest accounts
  • The ability to answer customer security questionnaires

AI you are allowed to use

Layers 05

From the platform decision to agents that take on real work. On data you control, and in systems an assistant can actually operate.

  • Platform selection with EU hosting as a criterion
  • Processes rethought, with assistants and agents
  • Internal systems connected, via MCP and integrations
  • A business case with effort, payback and the cost of doing nothing

How an engagement runs

Four phases, each with one defined output. No open-ended timesheet, no dependency after handover.

01

Assess

A survey of your environment measured against what regulation and your customers require.

1 to 2 weeks

02

Architect

Governance design and security baseline, cut to your tenant, your team and your obligations.

1 to 3 weeks

03

Implement

Phased delivery, every change tested first, with a documented way back.

2 to 8 weeks

04

Sustain

Handover to your team with operating documentation. After that you continue without us.

final week

What you keepGap analysisArchitecture diagramsSecurity baselineConfiguration scriptsCutover and rollback planAdministrator handbook

See the full engagement process

Tobias Schüle, Microsoft 365 and Azure architect at Opsora

You work with the architect, not with an account manager

Tobias Schüle leads every engagement from the first conversation to handover and is your direct contact. For specialist topics, experienced colleagues join from an established network - per project, never as a rotating junior team.

SC-100Cybersecurity Architect ExpertAZ-305Azure Solutions Architect ExpertMS-102M365 Enterprise AdministratorMD-102Endpoint Administrator

More about Tobias Schüle

What clients say

By name, with role and company. Anonymous quotes prove nothing.

Tobias was exactly the right partner at the right moment. He had an immediate solution for every challenge and our infrastructure was not impacted. If efficiency matters, he is the right person.
Mehmet AltunayMehmet AltunayIT Director, COMAVA GmbH
With Tobias, we modernised our on-premises landscape into a secure Microsoft 365 environment and established clear processes and permissions. Stability, security and collaboration increased noticeably, and administration became faster.
Handren TaherHandren TaherIT Director, S.I.S. Süd Industrie-Anlagen-Service GmbH

Read the full success story

Written from the work

Articles for readers who already know the basics.

See all articles

One conversation and you will know whether we fit

Thirty minutes in which we listen, ask, and tell you whether and how we can help. If we cannot, we say so.

A reply within 1 business day, from a person.