Each engagement follows the same structure—Assess, Design, Implement—and ends with a documented environment and measurable improvements in security posture, operational efficiency, or governance.
migration downtime incidents
MFA coverage achieved every time
avg. licensing savings identified
avg. time to full documentation
An 85-person accounting firm had operated its Microsoft 365 tenant for three years with default settings. MFA was technically available but not enforced. No DMARC record existed. Audit logging had never been enabled. The firm had no documentation of its tenant configuration and no runbook for new employee onboarding.
We conducted a full tenant audit and delivered a written findings report within one week. We then implemented Conditional Access MFA enforcement, configured DMARC/DKIM/SPF, enabled and configured unified audit logging, implemented device compliance policies via Intune, and produced a complete architecture document and admin runbook.
MFA coverage moved from 0% to 100% across all accounts in two weeks. DMARC policy moved from absent to p=reject within six weeks. The firm's internal IT contact described the architecture document as "the first time we actually know what we have." Onboarding time dropped from 3 hours of tribal knowledge to a 45-minute documented process.
MFA coverage across all user accounts
DMARC policy enforced within 6 weeks
from assessment to fully documented environment
Olson Tech Services took the time to understand our business before recommending changes. They identified risks we hadn't recognized, explained our options clearly, and helped us prioritize what would have the greatest impact. We never felt like we were being sold something we didn't need.
A 120-person manufacturing company was running Exchange Server 2016 on aging on-premises hardware. The server was approaching end-of-support and the IT team had no roadmap for migration. Licensing for the target Microsoft 365 environment had been purchased without architecture review, resulting in over-licensed accounts for most users.
We designed the target M365 tenant architecture, conducted a licensing audit and restructuring, and executed a phased hybrid Exchange migration with a coexistence period for user communication. Security hardening was implemented in parallel—not after. We deployed MFA, Intune device management, and email authentication before cutover.
Migration completed with zero reported email downtime. Licensing restructuring reduced monthly licensing spend by 40%. The company moved from a completely undocumented environment to a fully documented cloud architecture. For the first time, the IT team could describe exactly how the environment was configured and why.
users migrated from Exchange on-prem to M365
reported email downtime during migration
reduction in licensing cost through tier optimization
Olson Tech Services brought a level of technical expertise that gave us confidence in our technology and security. They looked beyond the obvious issues, identified areas of risk we hadn't considered, and provided practical recommendations our team could actually implement.
A healthcare provider operating three clinic locations had grown through organic expansion, resulting in three loosely federated Microsoft 365 tenants with inconsistent MFA policies, no conditional access, and shared admin credentials used across sites. HIPAA audit season was six weeks out, and the practice had no unified audit trail across locations.
We designed and executed a Zero Trust identity consolidation: unified the three tenants under a single Azure AD architecture with per-location administrative units, deployed risk-based Conditional Access (device compliance + location + sign-in risk signals combined), eliminated all shared credentials in favor of individually audited privileged access, and built a centralized Sentinel-based logging pipeline spanning all three sites for HIPAA-aligned audit reporting.
All three locations passed HIPAA audit with zero identity-related findings—the first clean audit in the practice's history. Conditional access now covers 100% of sign-in attempts across all sites, evaluated in real time against device health and risk signals. Admin credential incidents dropped from a monthly occurrence to zero in the six months following rollout.
fragmented tenants unified into one governed architecture
of sign-ins evaluated by risk-based Conditional Access
HIPAA audit findings related to identity or access
What stood out most about Olson Tech Services was their approach. They didn't start with a product or predetermined solution. They started by understanding what we were trying to accomplish and then helped us determine the right approach. Their recommendations were practical, transparent, and aligned with our business.
A 60-person law firm detected unusual encryption activity on a partner's workstation late on a Friday evening—an in-progress ransomware attempt that had gained a foothold through a compromised legacy VPN credential with no MFA. The firm had no incident response plan, no isolated backup strategy, and client-privileged data potentially at risk.
We were engaged within two hours of detection. Immediate containment isolated the affected endpoint and forced a tenant-wide credential reset. Over the following 48 hours we conducted a full forensic review to confirm no data exfiltration occurred, retired the vulnerable legacy VPN entirely in favor of Zero Trust conditional access, deployed immutable offline backup replication, and stood up 24/7 SIEM-based alerting with defined escalation paths—then delivered a full incident report suitable for cyber insurance and client disclosure requirements.
Forensic review confirmed zero data exfiltration—the attack was contained before encryption completed and before any privileged client data left the environment. The firm's cyber insurance renewal proceeded without a premium increase, citing the new incident response documentation and control set. The legacy VPN attack surface that enabled the breach no longer exists.
from detection to full incident containment
confirmed data exfiltration or client data exposure
SIEM alerting now standing guard over the environment
Technology and security can be difficult to navigate. Olson Tech Services made those decisions much easier for us by translating complex technical issues into clear, practical recommendations. They helped us understand not only what we should do, but why.
A professional services firm completed three acquisitions in eighteen months, inheriting three separate Microsoft 365 tenants, three different identity providers, overlapping domain names, and no consistent security baseline. Leadership needed a single unified environment before the next fiscal year—without disrupting client-facing teams mid-engagement.
We built a phased tenant-to-tenant migration plan sequencing all three acquisitions by risk and complexity. Mailboxes, OneDrive content, and Teams data were migrated in scheduled cutover windows outside business hours, with a dual-run coexistence period for cross-tenant calendar and free/busy visibility. A single unified Conditional Access and licensing baseline was applied as each entity landed, rather than retrofitted afterward—eliminating the security gap that typically follows M&A integration.
All 450 mailboxes across three acquired entities were consolidated into a single governed tenant with zero data loss and zero missed client deadlines during transition. What leadership had budgeted as a six-month integration timeline per acquisition was compressed to roughly ten weeks each once the migration framework was established after the first entity.
acquired tenants consolidated into one governed environment
mailboxes migrated with zero data loss
average integration time, down from a 6-month estimate
Olson Tech Services went beyond solving the immediate problem. They helped us look at our technology, security, and overall environment more strategically and gave us a roadmap for where we needed to go next. We came away with a stronger foundation and much more confidence in our technology decisions.