Glossary

IT, Microsoft & cloud terms, in plain English

88 of the acronyms and terms that come up across Microsoft cloud, security, endpoint and application delivery, explained in plain English and linked to the guidance, services and resources that go deeper.

A

AiTM (Adversary-in-the-Middle)
A phishing technique that sidesteps multi-factor authentication by proxying the login and stealing the resulting session token, so the attacker inherits an already-authenticated session. Defended with phishing-resistant MFA, device-bound Conditional Access and token protection.See: Microsoft 365 security gaps · Security Services
App Attach
A Windows feature that streams MSIX-packaged applications into Azure Virtual Desktop or Windows 365 sessions on demand, instead of baking them into every image, giving a lighter, faster-to-update base image.See: Application Packaging & MSIX · CI/CD packaging workflows
App-V (Application Virtualization)
A Microsoft technology that virtualises applications into isolated packages so they run without being fully installed on the OS. Microsoft is retiring App-V in favour of MSIX, and Systech migrates App-V estates to MSIX.See: App-V to MSIX migration · Application Packaging & MSIX
Application Modernisation
Moving the applications a business relies on onto modern, supported platforms, incrementally rather than via a risky big-bang rewrite, often replatforming onto Azure and the Microsoft stack.See: Development & Application Modernisation · Modernisation without a rewrite
Autopilot (Windows Autopilot)
A Microsoft service that configures a new device into your standard build from its out-of-box state, so a replacement machine can be shipped straight to a person rather than imaged by hand first. It delivers whatever configuration you have defined, which means it is only as good as the state of your Intune configuration underneath it.See: Endpoint Management · Intune device management checklist
Azure
Microsoft's public cloud platform for hosting virtual machines, storage, databases, networking and more. Systech helps businesses migrate to, optimise and control the cost of their Azure estate.See: Cost Management & Azure Optimisation · Cutting Azure waste
Azure Virtual Desktop (AVD)
Microsoft's cloud virtual desktop (VDI) service, delivering a full Windows desktop from Azure to any device. AVD supports multi-session and is flexible and cost-effective at scale.See: End-User Computing · Windows 365 vs AVD · AVD cost optimisation

B

Backup (3-2-1 & immutable)
Keeping recoverable copies of servers, endpoints and Microsoft 365 data. Good backup is monitored and regularly restore-tested, and keeps immutable, ransomware-resilient copies that an attacker cannot alter or delete.See: Backup Services
BEC (Business Email Compromise)
A targeted attack where a criminal impersonates a trusted person, often an executive or supplier, to trick staff into transferring money or data. Impersonation protection and email security defend against it.See: Email Security & Archive · Microsoft 365 security gaps
Break-fix
Paying for IT help only when something has already gone wrong, with no ongoing contract or coverage in between. It looks like the cheapest model because there is no monthly baseline, but nothing is monitored, patched or protected between incidents, so cost moves out of a predictable line item and into downtime, data-loss risk and premium emergency call-out pricing. Generally the most expensive model in practice for any business with real dependencies on its systems.See: Managed IT vs in-house vs break-fix
BYOD (Bring Your Own Device)
Staff using personally owned phones or laptops for work. It is usually cheaper and almost always harder to evidence, because personal devices accessing organisational data are in scope for frameworks like Cyber Essentials whether or not anyone counted them.See: Endpoint Management · Cyber Essentials Certification

C

Call-Off Contract (day packs)
A block of days bought up front and drawn down as needed, rather than quoting each piece of work separately. Common in public sector procurement and increasingly used privately, mainly because it removes the purchase order that otherwise sits in front of every small job.See: Call-off day packs
CI/CD (Continuous Integration / Delivery)
An automated pipeline that builds, tests and deploys software, or application packages, repeatably, replacing slow, manual, person-dependent work. Systech builds CI/CD packaging workflows for customers.See: CI/CD packaging workflows · Application Packaging & MSIX
Co-managed IT
An arrangement where internal IT staff and an external provider divide responsibility for one estate deliberately. Typically the internal side keeps user-facing support, business priorities, vendor relationships and project ownership, while the provider takes monitoring, patching, security tooling, out-of-hours cover and occasional specialist work. Common in businesses at the upper end of the 15-250 seat range. The failure mode is both sides assuming the other is watching something, which a written responsibility matrix prevents.See: MSP vs internal IT
Co-management
Running Microsoft Intune and Configuration Manager against the same Windows devices at once, with individual workloads moved from one to the other a piece at a time. It is the supported route away from an on-premises estate, and it is reversible, which is why it is safer than a cutover.See: Endpoint Management
Compliance Policy (Intune)
An Intune rule set defining what a 'healthy' device looks like (encryption, OS version, security settings). Paired with Conditional Access, it ensures only compliant, managed devices can reach company data.See: Intune management & reporting · Intune device management checklist
Conditional Access
Microsoft Entra policies that control who can access Microsoft 365 and under what conditions, for example requiring MFA, a compliant device or a trusted location. The backbone of a strong identity security posture.See: Microsoft 365 security gaps · Security Services
Configuration Manager (SCCM/MECM)
Microsoft's long-standing on-premises management product for Windows devices and servers, now called Microsoft Configuration Manager. Still stronger than Intune at complex application deployment, task-sequence operating system builds and bandwidth-constrained networks, which is why plenty of estates keep it deliberately.See: Endpoint Management
Copilot (Microsoft 365 Copilot)
Microsoft's AI assistant embedded across Microsoft 365 apps. Copilot inherits each user's existing access, so a readiness assessment of data and permissions is essential before switching it on.See: AI Solutions · Copilot readiness · Copilot Readiness Assessment
Copilot Agent
A configured Copilot with its own instructions and a defined set of sources, published for other people to use. The governance question changes at the point of publishing, because an agent answers from whatever it has been pointed at, to whoever can reach it.See: AI & Copilot Adoption
Credential Stuffing
Automated login attempts using username and password pairs stolen from some other breach, on the assumption that people reuse passwords. It is why a password that has never leaked from your systems can still be the one that lets somebody in.See: Security Services
CSP (Cloud Solution Provider)
Microsoft's partner programme for reselling and supporting Microsoft 365 and Azure subscriptions. A CSP partner bills you directly rather than Microsoft doing so, can adjust licence counts, and provides first-line support for the subscriptions themselves. It describes a licensing and billing relationship, not a scope of managed work, so Microsoft CSP status says nothing on its own about who answers when a server stops responding.See: MSP vs CSP vs MSSP · Licensing & Cost Management
Cyber Essentials
A UK government-backed certification covering five basic security controls. A self-assessed scheme increasingly required for public-sector and supply-chain contracts and cyber insurance.See: Cyber Essentials in 30 days · Cyber Essentials checklist
Cyber Essentials Plus
The independently audited version of Cyber Essentials, where an assessor verifies the controls through hands-on technical testing rather than self-assessment.See: Cyber Essentials vs Plus · Security Services

D

Disaster Recovery (DR)
The plan and tooling for restoring systems and data quickly after a major incident such as ransomware, hardware failure or human error. Only as good as the last tested restore.See: Backup Services
DMARC, SPF & DKIM
Email authentication records that prove a message genuinely came from your domain, making it far harder for attackers to spoof you. A core part of defending against phishing and BEC.See: Email Security & Archive · Microsoft 365 security gaps
DSP Toolkit (Data Security and Protection Toolkit)
The NHS self-assessment that organisations handling health and care data complete annually to evidence their data security position. Required of suppliers as well as providers, which catches out businesses who did not think of themselves as being in healthcare.See: Compliance Packs & Audit Readiness

E

EDR (Endpoint Detection and Response)
Security technology that continuously monitors devices (endpoints) for threats and enables rapid investigation and response, going well beyond traditional antivirus.See: Security Services
Egress Charges
What a cloud provider bills for moving data out of its platform. Frequently missed in cloud cost modelling, and worth understanding before a migration rather than after, because it is one of the few costs that grows when you decide to leave.See: Cost Management & Azure Optimisation · Cutting Azure waste
Email Archiving
Keeping a complete, searchable, tamper-proof record of every message independent of the mailbox, for compliance, legal hold and reconstructing what happened after an incident.See: Email Security & Archive
Entra ID (formerly Azure AD)
Microsoft's cloud identity service, and the thing that actually decides who can reach what across Microsoft 365 and Azure. Renamed from Azure Active Directory in 2023, which is why documentation and job adverts still use both names for the same product.See: Microsoft 365
EU AI Act
The EU's regulation on artificial intelligence, which classifies systems by risk and attaches obligations accordingly. It applies to UK businesses selling into the EU or serving EU users, and it phases in over several years, so what is currently in force matters more than the headline dates: the transparency duties and the high-risk obligations have different timelines. Unlike ISO 42001 it is law rather than a voluntary standard, and certification to a standard does not confer conformity with it.See: What actually started in August 2026
Extended Security Updates (ESU)
Paid security patches Microsoft offers for an operating system after free support ends, buying time to migrate. In use for Windows 10 following its October 2025 end of life.See: Windows 10 end of life · Legacy Modernisation & OS Migration

F

FinOps
The practice of managing cloud spend as an ongoing discipline rather than an annual clean-up, by attributing costs to the teams and projects that create them so the people making the decisions can see what they cost.See: Cost Management & Azure Optimisation

G

Gap Analysis
Comparing what a framework requires against what you actually do, and listing the difference. The useful version produces a ranked list of what would fail today; the less useful version restates the framework back at you.See: Compliance Packs & Audit Readiness · Cyber Essentials Certification
Grounding
Constraining an AI model to answer from specific source material rather than from what it absorbed in training. It is the mechanism that makes an answer traceable, and its absence is why an ungrounded model produces confident, plausible, unverifiable text.See: AI Engineering

H

Hallucination
An AI model stating something false with the same fluency it states something true. Not a bug to be patched out, but a property of how these systems generate text, which is why production systems need retrieval, citations and an explicit route to saying they do not know.See: AI Engineering

I

IaaS, PaaS & SaaS
The three cloud service models, distinguished by how much you still run yourself. Infrastructure as a Service gives you virtual machines and leaves the operating system to you; Platform as a Service runs the platform and leaves you the application; Software as a Service is the finished product. The practical consequence is where your responsibility for patching and backup stops.See: Azure & Cloud Migration
Immutable Backup
A backup that cannot be altered or deleted for a set period, including by an administrator. It is the control that separates a backup which survives ransomware from one an attacker encrypts alongside everything else, and insurers increasingly ask about it by name.See: Backup & Disaster Recovery · VM backup compared
Internal Audit
Checking your own controls against a framework before somebody external does. The point is not the report, it is finding the things that would fail while there is still time and no deadline attached to fixing them.See: Compliance Packs & Audit Readiness
Intune (Microsoft Intune)
Microsoft's cloud device management (MDM) service. Intune enrols, secures, patches, reports on and, if needed, wipes company and personal devices, and enforces compliance through Conditional Access.See: Intune management & reporting · End-User Computing · Intune device management checklist
ISO 27001
The international standard for information security management systems (ISMS). Certification demonstrates a structured, audited approach to managing information security risk.See: ISO 27001 audit partnership · Security Services
ISO/IEC 42001 (AI Management System)
The first international standard for governing artificial intelligence, published in December 2023 and certifiable. It follows the same shape as ISO 27001, with management system clauses 4 to 10 and 38 Annex A controls under nine objectives, of which you implement the ones your risk assessment calls for rather than all of them. It certifies that your organisation governs AI competently, not that any particular AI system is safe, and it does not by itself make you compliant with the EU AI Act.See: Compliance Packs & Audit Readiness

L

Landing Zone
A pre-built Azure environment with the identity, network, policy and cost controls already in place, so workloads arrive into a governed structure rather than into an empty subscription. Cheaper to build first than to retrofit once several teams are already running things.See: Cost Management & Azure Optimisation
Least Privilege
Giving an account only the access it needs to do its job, and only for as long as it needs it. Simple to state and awkward to maintain, because access accumulates quietly through role changes and nobody is ever thanked for removing some.See: Security Services · Microsoft 365 security gaps
Legacy Modernisation & OS Migration
Moving off end-of-life operating systems and applications onto modern, supported platforms, including capturing legacy apps that have no install media and repackaging them for a current OS.See: Legacy Modernisation & OS Migration · Legacy apps: security, cost & carbon · Legacy Migration Roadmap
LLM (Large Language Model)
A general-purpose AI model trained on vast amounts of text, able to understand and generate language. LLMs power tools like Copilot and custom AI applications.See: AI Engineering & Custom AI Solutions

M

Managed Detection and Response (MDR)
An outsourced service where people monitor your security alerts around the clock and act on the ones that matter. The distinction from buying an EDR product is that somebody is watching it, which is the part most businesses cannot staff themselves.See: Security Services
Managed Firewall
A firewall service that is continuously monitored, backed up, patched and reported on, rather than installed once and forgotten. Systech's runs on an in-house built platform.See: Managed Firewall · Managed firewall vs DIY · Managed Firewall: what's included
Managed IT Services
Outsourced day-to-day IT: 24/7 monitoring, a service desk, patching, backup oversight and device management for a predictable monthly fee, rather than reactive break-fix support.See: Managed IT Services · Pricing · vs in-house and break-fix
MFA (Multi-Factor Authentication)
Requiring more than a password to sign in, typically a code or approval on a second device. Essential, but on its own it does not stop token-theft attacks, which is why Conditional Access and phishing-resistant methods matter.See: Microsoft 365 security gaps · Security Services
Microsoft 365
Microsoft's cloud productivity and security suite (Exchange, Teams, SharePoint, OneDrive, identity, Intune and more). Systech deploys, governs, secures and supports the whole platform.See: Microsoft 365 · SharePoint vs Teams vs OneDrive
Microsoft 365 Business Premium
The Microsoft 365 plan that bundles the productivity apps with the security stack (Defender, Intune, Conditional Access), best value for most SMBs up to 300 users.See: Business Premium value · Microsoft 365
MSIX
Microsoft's modern, native Windows application packaging format, the supported successor to App-V. MSIX uses built-in container isolation and integrates with Intune and App Attach.See: App-V to MSIX migration · Application Packaging & MSIX
MSP (Managed Service Provider)
A company that takes ongoing, contracted responsibility for running some or all of your IT estate for a recurring fee, rather than charging per incident. The defining test is that an MSP is responsible for keeping things in an agreed state, not only for responding when they are not. The term carries no certification of its own, so ISO 27001, Cyber Essentials and vendor partner status are the signals worth checking. Outside IT, MSP also means Member of the Scottish Parliament and, in retail, minimum selling price.See: MSP vs CSP vs MSSP · MSP vs internal IT · Managed IT Services
MSSP (Managed Security Service Provider)
A provider specialising in threat detection and response, typically running a security operations centre with analysts monitoring telemetry continuously, threat hunting and contracted incident response. Distinct from an MSP, which covers IT operations broadly including preventive security controls. Most small and mid-sized businesses are better served by an MSP delivering managed EDR/XDR than by a separate MSSP contract, until a regulatory obligation or threat profile justifies one.See: MSP vs CSP vs MSSP · Security Services

O

Outsourced IT
Handing IT work to an external company rather than employing the people who do it. Managed services are a form of outsourcing, but not all outsourcing is a managed service: traditional outsourcing buys capacity that works to your direction and processes, usually billed against time or headcount, while a managed service buys an outcome and the provider brings its own tooling and process. The practical test is who decides how the work gets done.See: IT outsourcing vs managed services
Oversharing (data governance)
The gradual build-up of over-permissive sharing links, stale guest access and unlabelled sensitive files in Microsoft 365. Long a risk, and an urgent one once Copilot can surface anything a user can access.See: Copilot readiness · Microsoft 365 Security Posture Assessment

P

Password Manager
Software that generates and stores unique credentials so people are not reusing one password everywhere. The security question worth asking is not whether to use one, it is where the encrypted vault lives, since a shared public vault service is a concentrated target in a way a vault inside your own tenant is not.See: Security Services
Patch Management
Getting security updates onto devices and servers within a defined window, and being able to show that it happened. Cyber Essentials requires critical and high-severity updates inside fourteen days, and the part most estates struggle with is the evidence rather than the patching.See: Endpoint Management · Cyber Essentials Certification
Penetration Testing
A controlled attempt to break into your systems, carried out by people whose job is to find what an attacker would find. Distinct from a vulnerability scan, which lists known weaknesses without establishing whether they can actually be chained into anything.See: Security Services
Phishing
Fraudulent messages designed to trick people into revealing credentials or approving access. Still the number one route in for attackers, countered with email security, MFA and user awareness.See: Email Security & Archive · Security Services
Phishing-Resistant MFA
Multi-factor methods that cannot be relayed by an attacker sitting in the middle, such as passkeys, FIDO2 security keys or certificate-based authentication. Codes and push approvals are multi-factor but not phishing-resistant, which is the gap adversary-in-the-middle attacks exploit.See: Security Services
PIM (Privileged Identity Management)
A Microsoft Entra feature that grants administrative access just-in-time and for a limited time, minimising standing privileged access and reducing the impact of a compromised admin account.See: Microsoft 365 security gaps
Prompt Injection
Text hidden in content an AI system reads, written to make it ignore its instructions or reveal what it should not. It matters most where a system reads material other people can write, because the attack arrives as data rather than as a user request.See: AI Engineering

R

RAG (Retrieval-Augmented Generation)
An AI technique that grounds a language model's answers in your own documents and data, retrieved at query time, so responses are accurate, current and traceable to a source rather than invented.See: AI Engineering & Custom AI Solutions
Reserved Instances & Savings Plans
Azure commitment-based discounts that cut the cost of predictable workloads in exchange for a one- or three-year term. A core lever in Azure cost optimisation.See: Cost Management & Azure Optimisation · Cutting Azure waste
Right-sizing
Matching cloud resources (VM sizes, storage tiers, licences) to real utilisation, cutting waste without starving workloads of the capacity they genuinely need.See: Cost Management & Azure Optimisation · Microsoft 365 cost checklist
RMM (Remote Monitoring and Management)
The tooling an MSP uses to see and act on a customer estate remotely: an agent on each managed device reporting health, patch status and alerts, with the ability to deploy software and run remediation without attending site. It is the mechanism that makes proactive management possible at all, and it is provider-owned, which is one reason exit terms and documentation ownership are worth settling before signing a managed contract.See: Managed IT Services · Intune

S

Secure Score
A Microsoft measurement of an organisation's security posture across identity, data, devices and apps, with recommended actions. A number to act on, not just to report.See: Microsoft 365 Security Posture Assessment · Security Services
Shadow AI
Staff using AI tools the business has not approved, usually because the approved route is slower or does not exist. The risk is not the tools themselves, it is company information being pasted into services nobody has assessed.
SharePoint, Teams & OneDrive
The three core Microsoft 365 collaboration apps. Getting the file structure and permissions right early avoids years of untangling, and is foundational to security and Copilot readiness.See: SharePoint vs Teams vs OneDrive · Microsoft 365
Shelfware
Licences a business pays for but doesn't use, such as unassigned or over-specified Microsoft 365 seats. Auditing and right-sizing them is one of the fastest cost wins in IT.See: Microsoft 365 licensing shelfware · Cost Management & Azure Optimisation
SIEM (Security Information and Event Management)
A system that collects logs from across an estate and correlates them, so an attack visible only as a pattern across several systems can be spotted. Valuable in proportion to whether anyone is actually reading what it produces.See: Security Services
SLA (Service Level Agreement)
The part of a support contract that states what the provider is actually committed to: coverage hours, how quickly different severities of issue will be responded to, and what happens if those commitments are missed. Worth reading closely for the difference between a response target and a resolution target, and for what 24/7 means in practice, since it can describe a UK engineer starting work or an answering service raising a ticket for the morning.See: How to choose an IT support company
SLM (Small Language Model)
A smaller, more focused AI model that can be cheaper, faster, more private and hostable on infrastructure you control. For many specific business tasks an SLM outperforms a general-purpose API on cost and latency.See: AI Engineering & Custom AI Solutions
SoA (Statement of Applicability)
The ISO 27001 document listing which controls apply to you, which do not, and why. It comes early and shapes everything after it, so it is worth scoping properly rather than treating as paperwork to be completed later.See: Compliance Packs & Audit Readiness · ISO 27001 audit partnership
SOC (Security Operations Centre)
The team that monitors and responds to security alerts, in-house or bought as a service. The question worth asking of any provider is what happens at 3am and what they are authorised to do without waking you.See: Security Services · Out-of-hours & on-call cover

T

TCO (Total Cost of Ownership)
The full cost of running something over its life, rather than the price of buying it. In IT the gap between the two is usually licensing, the people who administer it, and the work needed when the platform underneath changes.See: Licensing & Cost Management
Token Theft
Stealing an authenticated session token (often via an AiTM phishing kit) to access an account without needing the password or MFA. Mitigated with token protection and device-bound Conditional Access.See: Microsoft 365 security gaps

U

Update Rings
Groups of devices that receive Windows updates on a staggered schedule, so a problematic update is found on a small pilot group before it reaches everybody. Only works if the pilot group is genuinely representative rather than whoever volunteered.See: Endpoint Management

V

VDI (Virtual Desktop Infrastructure)
Technology that hosts desktops centrally (in a datacentre or the cloud) and delivers them to users on any device, keeping data off the endpoint. Windows 365 and Azure Virtual Desktop are Microsoft's VDI options.See: End-User Computing

W

White-Label IT Delivery
Enterprise-grade technical delivery and advisory provided under another company's brand, letting vendors and MSPs take on contracts that need skills they don't have in-house.See: White-Label Delivery & Advisory
Windows 10 End of Life
Free support for Windows 10 ended in October 2025. Devices still on it are unpatched unless covered by Extended Security Updates, making migration to Windows 11 a priority.See: Windows 10 end of life · Legacy Modernisation & OS Migration
Windows 365
Microsoft's Cloud PC service, giving each user a dedicated Windows desktop in the cloud at a fixed per-user price, reachable from any device, with IT keeping control of the data.See: Windows 365 remote access · End-User Computing
Windows Update for Business
The Microsoft service, managed through Intune, for controlling how and when Windows quality and feature updates are deployed to devices, using deployment rings and schedules.See: Intune management & reporting

X

XDR (Extended Detection and Response)
Security technology that correlates signals across endpoints, identity, email and cloud so an attack touching several of them is seen as one incident rather than separate, unrelated alerts.See: Security Services · Microsoft 365 security gaps

Z

Zero Trust
A security model that stops treating the corporate network as a trusted place and verifies every request on its own merits: who is asking, from what device, in what state. Sold as a product by many vendors and actually an architectural principle, delivered mostly through identity and device controls you already own.See: Security Services

Came here to check what something meant?

Ask us the question behind it. No obligation, no assessment to book first, and we will tell you plainly if the answer is that it does not apply to you.