GEIDI IT Portal
Multi-tenant Microsoft 365 operations — without the PowerShell tax.
In production, running GEIDI's own managed tenants
- ~40 min — Estimated saving on every user onboarding — from around three-quarters of an hour of console work down to five minutes
- 185 — Management endpoints behind a single sign-in, replacing a console-and-PowerShell scramble per tenant
- 3 — Security baselines it deploys and detects drift against — NIST CSF, ASD Essential Eight and CIS
Anyone running Microsoft 365 for a portfolio knows the drill
Ten tabs of admin console and a command-line window per tenant, because no console spans more than one customer.
Granting a mailbox permission means a trip into another console, one account at a time. Onboarding a new starter is the better part of an hour of clicking; offboarding is the same in reverse, plus a sticky note that says don’t forget the licence. Policy drift happens silently between audits, so the first anyone notices a baseline moved is when someone goes looking for evidence. And answering who changed what, and when? means stacked filters across several consoles.
What it does instead
- Onboarding and offboarding as one workflow. Account, group membership, licence, hardware, access pass and welcome email in a single form — and the reverse in one action, down to reassigning the licence and returning the laptop.
- It can run on a date. Both workflows queue against a future start date or last day and fire on the morning they are due, rather than on someone remembering.
- Re-onboarding that genuinely reverses an offboarding. Mailbox conversion back to a user, directory re-enable, licence restore in the right order. This is the step most tooling gets wrong, because undoing an offboarding is not the same as running an onboarding.
- Baselines and drift detection. Compare a tenant against its approved baseline, see what was added, removed or changed, and redeploy once the drift is acknowledged. Templates are aligned to recognised security frameworks.
- The audit answer in seconds. Sign-in and activity logs surface in the same place as the actions, so evidence takes minutes rather than half a day.
Hybrid is a first-class case
On-premises directory work is integrated rather than ignored. A half-migrated estate is the normal condition of a real business, and it is usually the point where automation quietly stops and someone logs into a server by hand.
The safeguards are the product
This holds administrative access to other people’s tenants, so the controls are not a hardening pass added at the end.
Secrets never live in the codebase — infrastructure secrets in a managed store, per-tenant credentials in a vault reached only server-side. Every operation is scoped to a tenant and an operator role, so access is bounded by function rather than seniority. Privileged mailbox operations run through signed, pre-written automation rather than an interactive session someone can improvise inside. And every operation is recorded against the person who requested it.
Where it fits
- Providers running Microsoft 365 across a portfolio of customer tenants rather than one.
- Teams losing skilled hours to work that is mechanical, repetitive and still somehow error-prone.
- Anyone asked to evidence policy compliance against a recognised framework, and assembling that evidence by hand each time.
- Hybrid estates where the on-premises half is the reason the automation stopped.
Judge it on a real tenant
Walk one real onboarding and one real offboarding through it, then read the audit trail both left behind.