GEIDI IT Portal

Multi-tenant Microsoft 365 operations — without the PowerShell tax.

In production, running GEIDI's own managed tenants

category
Managed service operations
deployment
Cloud · connects to Microsoft 365, Entra ID and on-premises Active Directory
  • ~40 min — Estimated saving on every user onboarding — from around three-quarters of an hour of console work down to five minutes
  • 185 — Management endpoints behind a single sign-in, replacing a console-and-PowerShell scramble per tenant
  • 3 — Security baselines it deploys and detects drift against — NIST CSF, ASD Essential Eight and CIS

Anyone running Microsoft 365 for a portfolio knows the drill

Ten tabs of admin console and a command-line window per tenant, because no console spans more than one customer.

Granting a mailbox permission means a trip into another console, one account at a time. Onboarding a new starter is the better part of an hour of clicking; offboarding is the same in reverse, plus a sticky note that says don’t forget the licence. Policy drift happens silently between audits, so the first anyone notices a baseline moved is when someone goes looking for evidence. And answering who changed what, and when? means stacked filters across several consoles.

What it does instead

  • Onboarding and offboarding as one workflow. Account, group membership, licence, hardware, access pass and welcome email in a single form — and the reverse in one action, down to reassigning the licence and returning the laptop.
  • It can run on a date. Both workflows queue against a future start date or last day and fire on the morning they are due, rather than on someone remembering.
  • Re-onboarding that genuinely reverses an offboarding. Mailbox conversion back to a user, directory re-enable, licence restore in the right order. This is the step most tooling gets wrong, because undoing an offboarding is not the same as running an onboarding.
  • Baselines and drift detection. Compare a tenant against its approved baseline, see what was added, removed or changed, and redeploy once the drift is acknowledged. Templates are aligned to recognised security frameworks.
  • The audit answer in seconds. Sign-in and activity logs surface in the same place as the actions, so evidence takes minutes rather than half a day.

Hybrid is a first-class case

On-premises directory work is integrated rather than ignored. A half-migrated estate is the normal condition of a real business, and it is usually the point where automation quietly stops and someone logs into a server by hand.

The safeguards are the product

This holds administrative access to other people’s tenants, so the controls are not a hardening pass added at the end.

Secrets never live in the codebase — infrastructure secrets in a managed store, per-tenant credentials in a vault reached only server-side. Every operation is scoped to a tenant and an operator role, so access is bounded by function rather than seniority. Privileged mailbox operations run through signed, pre-written automation rather than an interactive session someone can improvise inside. And every operation is recorded against the person who requested it.

Where it fits

  • Providers running Microsoft 365 across a portfolio of customer tenants rather than one.
  • Teams losing skilled hours to work that is mechanical, repetitive and still somehow error-prone.
  • Anyone asked to evidence policy compliance against a recognised framework, and assembling that evidence by hand each time.
  • Hybrid estates where the on-premises half is the reason the automation stopped.

Judge it on a real tenant

Walk one real onboarding and one real offboarding through it, then read the audit trail both left behind.

Talk to us