Account clean-up
We hunt down leavers' accounts, test users and shared logins. Every account gets an owner or is removed.
The technology is half the job. The other half is agreeing with you and HR who approves access and what a person's first and final day look like.
We hunt down leavers' accounts, test users and shared logins. Every account gets an owner or is removed.
Global admin reserved for two break-glass accounts; everyone else receives narrower roles, say for Exchange or Intune, ideally switched on only for the task at hand.
Mail and SharePoint open only on company-managed devices, and sign-ins from unusual countries are refused.
BitLocker, screen lock, updates and printers pushed out centrally. Where a local domain remains, we use GPOs as well.
Folder and app permissions tied to groups that fill themselves from the department HR records.
Staff unlock their own account after verifying in the app, instead of raising a ticket at 7:30 on a Monday.
Timing depends on company size and the state of the tenant. Changes are rolled out so that nobody loses mail or file access.
We inspect roles, accounts, security defaults and the sync with on-site AD, if there is one.
One department trials the new policies and groups. We smooth out the friction before the rest of the company follows.
MFA, Conditional Access and Intune enrolment, team by team, with a one-page guide for staff.
A starter and leaver form for HR, plus a quarterly permissions review with line managers.
Shared logins like warehouse1 or reception are a blind spot in every audit. Nobody can say who used them, half the staff know the password, and MFA is usually off because apparently it breaks things. We swap them for named accounts, shared mailboxes and group-based rights, and check along the way that the tenant is not relying on a single global admin without MFA.
No courier trips required. With Windows Autopilot and Intune the employee signs in with a work account and the machine fetches its policies, apps and BitLocker settings by itself. Your supplier can even deliver new hardware straight to the employee, an InPost locker for example, ready for work after first boot.
A single email to office@apply.pl with Support in the subject is enough. We lock the account, kill live sessions on phone and laptop, and convert the mailbox to a shared one for the manager. Deletion waits, otherwise the OneDrive files would vanish. If the company laptop remains with the leaver, Intune lets us wipe it remotely.
Frequently, though not in one go. First we list what still leans on the domain: a file server, printers, an elderly payroll package, or Wi-Fi authentication via RADIUS. Files go to SharePoint and the rest gets a cloud replacement. Once nothing talks to the controller, we switch it off and you run on Entra ID alone.
Yes. Rather than SMS codes we introduce Microsoft Authenticator push prompts or passkeys, and on trusted company machines Conditional Access trims the number of challenges. Over time most people stop noticing MFA exists.
Give us your headcount and describe how people log in today. We begin with a review of accounts and roles in your tenant.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.