For managed service providers
An after hours Microsoft 365 bench for your team
You keep the client and the relationship. I do the careful work in your quiet hours, white label, and every change arrives with its evidence and a rollback that has already been tested.
Your change window
11 pm to 5 am ET
My working morning in Mauritius
7 am to 1 pm
Mauritius runs on UTC+4 all year, eight hours ahead of New York in summer and nine in winter, when the same window is 8 am to 2 pm here. Patching, policy rollouts and migrations happen while your clients sleep, without paying your own team to stay up.
What I take off your plate
Tenant baseline checks
MFA and Conditional Access coverage, stale and over permissioned accounts, guest access, Intune compliance, and the sharing settings that let Copilot surface files people should never see. Read only.
Scripted changes with rollback
Intune policies, Conditional Access, Entra cleanup, mailbox and group changes. Rolled out to a pilot group first, with the before and after state saved to an evidence file your team keeps.
Copilot and AI readiness
Find what Copilot would expose before a client switches it on, fix the permissions that matter, and hand your client a report under your own brand.
AI agents across client tenants
If your team wants Claude or ChatGPT working across client tenants, I build the gateway that keeps each client’s data in its own lane, with role based access and an audit log of every call.
How it works with your clients
- White label by default. My name never reaches your client unless you want it to.
- You approve every change window in writing before anything moves.
- I work from an account you create and control, with the least privilege your delegated admin setup allows. If you prefer, I never touch the tenant at all: I write read only scripts, your team runs them and sends me the output.
- Every change leaves an evidence file: what was there before, what changed, and the exact way back.
Prices
| Work | Price | Timing |
|---|---|---|
| Tenant baseline check with evidence pack | $750 per tenant, or $600 each for three or more | 3 business days |
| Scripted change with a tested rollback | from $450 per change | The next change window you set |
| After hours bench, 20 hours a month | $1,500 a month | Unused hours roll over one month |
| AI agent gateway pilot, two tenants | from $3,000 | 2 to 3 weeks |
Checks are paid in advance. The bench is billed monthly in advance. Changes and pilots are paid half to start and half on acceptance.
Proof you can run yourself
m365-safe-ops is my PowerShell 7 module for safe Microsoft Graph changes: explicit pilot scopes, WhatIf honoured on every change, before and after state written to an evidence file, and a rollback that reads only from that file. Its fourteen checks run against a fake Graph, so you can test it without touching a tenant.
GLPI 11 multi customer isolation shows the same discipline on a helpdesk: every customer walled off from the others, including the direct link bypass test.