Glossary
IT, Microsoft & cloud terms, in plain English
88 of the acronyms and terms that come up across Microsoft cloud, security, endpoint and application delivery, explained in plain English and linked to the guidance, services and resources that go deeper.
A
- AiTM (Adversary-in-the-Middle)
- A phishing technique that sidesteps multi-factor authentication by proxying the login and stealing the resulting session token, so the attacker inherits an already-authenticated session. Defended with phishing-resistant MFA, device-bound Conditional Access and token protection.See: Microsoft 365 security gaps · Security Services
- App Attach
- A Windows feature that streams MSIX-packaged applications into Azure Virtual Desktop or Windows 365 sessions on demand, instead of baking them into every image, giving a lighter, faster-to-update base image.See: Application Packaging & MSIX · CI/CD packaging workflows
- App-V (Application Virtualization)
- A Microsoft technology that virtualises applications into isolated packages so they run without being fully installed on the OS. Microsoft is retiring App-V in favour of MSIX, and Systech migrates App-V estates to MSIX.See: App-V to MSIX migration · Application Packaging & MSIX
- Application Modernisation
- Moving the applications a business relies on onto modern, supported platforms, incrementally rather than via a risky big-bang rewrite, often replatforming onto Azure and the Microsoft stack.See: Development & Application Modernisation · Modernisation without a rewrite
- Autopilot (Windows Autopilot)
- A Microsoft service that configures a new device into your standard build from its out-of-box state, so a replacement machine can be shipped straight to a person rather than imaged by hand first. It delivers whatever configuration you have defined, which means it is only as good as the state of your Intune configuration underneath it.See: Endpoint Management · Intune device management checklist
- Azure
- Microsoft's public cloud platform for hosting virtual machines, storage, databases, networking and more. Systech helps businesses migrate to, optimise and control the cost of their Azure estate.See: Cost Management & Azure Optimisation · Cutting Azure waste
- Azure Virtual Desktop (AVD)
- Microsoft's cloud virtual desktop (VDI) service, delivering a full Windows desktop from Azure to any device. AVD supports multi-session and is flexible and cost-effective at scale.See: End-User Computing · Windows 365 vs AVD · AVD cost optimisation
B
- Backup (3-2-1 & immutable)
- Keeping recoverable copies of servers, endpoints and Microsoft 365 data. Good backup is monitored and regularly restore-tested, and keeps immutable, ransomware-resilient copies that an attacker cannot alter or delete.See: Backup Services
- BEC (Business Email Compromise)
- A targeted attack where a criminal impersonates a trusted person, often an executive or supplier, to trick staff into transferring money or data. Impersonation protection and email security defend against it.See: Email Security & Archive · Microsoft 365 security gaps
- Break-fix
- Paying for IT help only when something has already gone wrong, with no ongoing contract or coverage in between. It looks like the cheapest model because there is no monthly baseline, but nothing is monitored, patched or protected between incidents, so cost moves out of a predictable line item and into downtime, data-loss risk and premium emergency call-out pricing. Generally the most expensive model in practice for any business with real dependencies on its systems.See: Managed IT vs in-house vs break-fix
- BYOD (Bring Your Own Device)
- Staff using personally owned phones or laptops for work. It is usually cheaper and almost always harder to evidence, because personal devices accessing organisational data are in scope for frameworks like Cyber Essentials whether or not anyone counted them.See: Endpoint Management · Cyber Essentials Certification
C
- Call-Off Contract (day packs)
- A block of days bought up front and drawn down as needed, rather than quoting each piece of work separately. Common in public sector procurement and increasingly used privately, mainly because it removes the purchase order that otherwise sits in front of every small job.See: Call-off day packs
- CI/CD (Continuous Integration / Delivery)
- An automated pipeline that builds, tests and deploys software, or application packages, repeatably, replacing slow, manual, person-dependent work. Systech builds CI/CD packaging workflows for customers.See: CI/CD packaging workflows · Application Packaging & MSIX
- Co-managed IT
- An arrangement where internal IT staff and an external provider divide responsibility for one estate deliberately. Typically the internal side keeps user-facing support, business priorities, vendor relationships and project ownership, while the provider takes monitoring, patching, security tooling, out-of-hours cover and occasional specialist work. Common in businesses at the upper end of the 15-250 seat range. The failure mode is both sides assuming the other is watching something, which a written responsibility matrix prevents.See: MSP vs internal IT
- Co-management
- Running Microsoft Intune and Configuration Manager against the same Windows devices at once, with individual workloads moved from one to the other a piece at a time. It is the supported route away from an on-premises estate, and it is reversible, which is why it is safer than a cutover.See: Endpoint Management
- Compliance Policy (Intune)
- An Intune rule set defining what a 'healthy' device looks like (encryption, OS version, security settings). Paired with Conditional Access, it ensures only compliant, managed devices can reach company data.See: Intune management & reporting · Intune device management checklist
- Conditional Access
- Microsoft Entra policies that control who can access Microsoft 365 and under what conditions, for example requiring MFA, a compliant device or a trusted location. The backbone of a strong identity security posture.See: Microsoft 365 security gaps · Security Services
- Configuration Manager (SCCM/MECM)
- Microsoft's long-standing on-premises management product for Windows devices and servers, now called Microsoft Configuration Manager. Still stronger than Intune at complex application deployment, task-sequence operating system builds and bandwidth-constrained networks, which is why plenty of estates keep it deliberately.See: Endpoint Management
- Copilot (Microsoft 365 Copilot)
- Microsoft's AI assistant embedded across Microsoft 365 apps. Copilot inherits each user's existing access, so a readiness assessment of data and permissions is essential before switching it on.See: AI Solutions · Copilot readiness · Copilot Readiness Assessment
- Copilot Agent
- A configured Copilot with its own instructions and a defined set of sources, published for other people to use. The governance question changes at the point of publishing, because an agent answers from whatever it has been pointed at, to whoever can reach it.See: AI & Copilot Adoption
- Credential Stuffing
- Automated login attempts using username and password pairs stolen from some other breach, on the assumption that people reuse passwords. It is why a password that has never leaked from your systems can still be the one that lets somebody in.See: Security Services
- CSP (Cloud Solution Provider)
- Microsoft's partner programme for reselling and supporting Microsoft 365 and Azure subscriptions. A CSP partner bills you directly rather than Microsoft doing so, can adjust licence counts, and provides first-line support for the subscriptions themselves. It describes a licensing and billing relationship, not a scope of managed work, so Microsoft CSP status says nothing on its own about who answers when a server stops responding.See: MSP vs CSP vs MSSP · Licensing & Cost Management
- Cyber Essentials
- A UK government-backed certification covering five basic security controls. A self-assessed scheme increasingly required for public-sector and supply-chain contracts and cyber insurance.See: Cyber Essentials in 30 days · Cyber Essentials checklist
- Cyber Essentials Plus
- The independently audited version of Cyber Essentials, where an assessor verifies the controls through hands-on technical testing rather than self-assessment.See: Cyber Essentials vs Plus · Security Services
D
- Disaster Recovery (DR)
- The plan and tooling for restoring systems and data quickly after a major incident such as ransomware, hardware failure or human error. Only as good as the last tested restore.See: Backup Services
- DMARC, SPF & DKIM
- Email authentication records that prove a message genuinely came from your domain, making it far harder for attackers to spoof you. A core part of defending against phishing and BEC.See: Email Security & Archive · Microsoft 365 security gaps
- DSP Toolkit (Data Security and Protection Toolkit)
- The NHS self-assessment that organisations handling health and care data complete annually to evidence their data security position. Required of suppliers as well as providers, which catches out businesses who did not think of themselves as being in healthcare.See: Compliance Packs & Audit Readiness
E
- EDR (Endpoint Detection and Response)
- Security technology that continuously monitors devices (endpoints) for threats and enables rapid investigation and response, going well beyond traditional antivirus.See: Security Services
- Egress Charges
- What a cloud provider bills for moving data out of its platform. Frequently missed in cloud cost modelling, and worth understanding before a migration rather than after, because it is one of the few costs that grows when you decide to leave.See: Cost Management & Azure Optimisation · Cutting Azure waste
- Email Archiving
- Keeping a complete, searchable, tamper-proof record of every message independent of the mailbox, for compliance, legal hold and reconstructing what happened after an incident.See: Email Security & Archive
- Entra ID (formerly Azure AD)
- Microsoft's cloud identity service, and the thing that actually decides who can reach what across Microsoft 365 and Azure. Renamed from Azure Active Directory in 2023, which is why documentation and job adverts still use both names for the same product.See: Microsoft 365
- EU AI Act
- The EU's regulation on artificial intelligence, which classifies systems by risk and attaches obligations accordingly. It applies to UK businesses selling into the EU or serving EU users, and it phases in over several years, so what is currently in force matters more than the headline dates: the transparency duties and the high-risk obligations have different timelines. Unlike ISO 42001 it is law rather than a voluntary standard, and certification to a standard does not confer conformity with it.See: What actually started in August 2026
- Extended Security Updates (ESU)
- Paid security patches Microsoft offers for an operating system after free support ends, buying time to migrate. In use for Windows 10 following its October 2025 end of life.See: Windows 10 end of life · Legacy Modernisation & OS Migration
F
- FinOps
- The practice of managing cloud spend as an ongoing discipline rather than an annual clean-up, by attributing costs to the teams and projects that create them so the people making the decisions can see what they cost.See: Cost Management & Azure Optimisation
G
- Gap Analysis
- Comparing what a framework requires against what you actually do, and listing the difference. The useful version produces a ranked list of what would fail today; the less useful version restates the framework back at you.See: Compliance Packs & Audit Readiness · Cyber Essentials Certification
- Grounding
- Constraining an AI model to answer from specific source material rather than from what it absorbed in training. It is the mechanism that makes an answer traceable, and its absence is why an ungrounded model produces confident, plausible, unverifiable text.See: AI Engineering
H
- Hallucination
- An AI model stating something false with the same fluency it states something true. Not a bug to be patched out, but a property of how these systems generate text, which is why production systems need retrieval, citations and an explicit route to saying they do not know.See: AI Engineering
I
- IaaS, PaaS & SaaS
- The three cloud service models, distinguished by how much you still run yourself. Infrastructure as a Service gives you virtual machines and leaves the operating system to you; Platform as a Service runs the platform and leaves you the application; Software as a Service is the finished product. The practical consequence is where your responsibility for patching and backup stops.See: Azure & Cloud Migration
- Immutable Backup
- A backup that cannot be altered or deleted for a set period, including by an administrator. It is the control that separates a backup which survives ransomware from one an attacker encrypts alongside everything else, and insurers increasingly ask about it by name.See: Backup & Disaster Recovery · VM backup compared
- Internal Audit
- Checking your own controls against a framework before somebody external does. The point is not the report, it is finding the things that would fail while there is still time and no deadline attached to fixing them.See: Compliance Packs & Audit Readiness
- Intune (Microsoft Intune)
- Microsoft's cloud device management (MDM) service. Intune enrols, secures, patches, reports on and, if needed, wipes company and personal devices, and enforces compliance through Conditional Access.See: Intune management & reporting · End-User Computing · Intune device management checklist
- ISO 27001
- The international standard for information security management systems (ISMS). Certification demonstrates a structured, audited approach to managing information security risk.See: ISO 27001 audit partnership · Security Services
- ISO/IEC 42001 (AI Management System)
- The first international standard for governing artificial intelligence, published in December 2023 and certifiable. It follows the same shape as ISO 27001, with management system clauses 4 to 10 and 38 Annex A controls under nine objectives, of which you implement the ones your risk assessment calls for rather than all of them. It certifies that your organisation governs AI competently, not that any particular AI system is safe, and it does not by itself make you compliant with the EU AI Act.See: Compliance Packs & Audit Readiness
L
- Landing Zone
- A pre-built Azure environment with the identity, network, policy and cost controls already in place, so workloads arrive into a governed structure rather than into an empty subscription. Cheaper to build first than to retrofit once several teams are already running things.See: Cost Management & Azure Optimisation
- Least Privilege
- Giving an account only the access it needs to do its job, and only for as long as it needs it. Simple to state and awkward to maintain, because access accumulates quietly through role changes and nobody is ever thanked for removing some.See: Security Services · Microsoft 365 security gaps
- Legacy Modernisation & OS Migration
- Moving off end-of-life operating systems and applications onto modern, supported platforms, including capturing legacy apps that have no install media and repackaging them for a current OS.See: Legacy Modernisation & OS Migration · Legacy apps: security, cost & carbon · Legacy Migration Roadmap
- LLM (Large Language Model)
- A general-purpose AI model trained on vast amounts of text, able to understand and generate language. LLMs power tools like Copilot and custom AI applications.See: AI Engineering & Custom AI Solutions
M
- Managed Detection and Response (MDR)
- An outsourced service where people monitor your security alerts around the clock and act on the ones that matter. The distinction from buying an EDR product is that somebody is watching it, which is the part most businesses cannot staff themselves.See: Security Services
- Managed Firewall
- A firewall service that is continuously monitored, backed up, patched and reported on, rather than installed once and forgotten. Systech's runs on an in-house built platform.See: Managed Firewall · Managed firewall vs DIY · Managed Firewall: what's included
- Managed IT Services
- Outsourced day-to-day IT: 24/7 monitoring, a service desk, patching, backup oversight and device management for a predictable monthly fee, rather than reactive break-fix support.See: Managed IT Services · Pricing · vs in-house and break-fix
- MFA (Multi-Factor Authentication)
- Requiring more than a password to sign in, typically a code or approval on a second device. Essential, but on its own it does not stop token-theft attacks, which is why Conditional Access and phishing-resistant methods matter.See: Microsoft 365 security gaps · Security Services
- Microsoft 365
- Microsoft's cloud productivity and security suite (Exchange, Teams, SharePoint, OneDrive, identity, Intune and more). Systech deploys, governs, secures and supports the whole platform.See: Microsoft 365 · SharePoint vs Teams vs OneDrive
- Microsoft 365 Business Premium
- The Microsoft 365 plan that bundles the productivity apps with the security stack (Defender, Intune, Conditional Access), best value for most SMBs up to 300 users.See: Business Premium value · Microsoft 365
- MSIX
- Microsoft's modern, native Windows application packaging format, the supported successor to App-V. MSIX uses built-in container isolation and integrates with Intune and App Attach.See: App-V to MSIX migration · Application Packaging & MSIX
- MSP (Managed Service Provider)
- A company that takes ongoing, contracted responsibility for running some or all of your IT estate for a recurring fee, rather than charging per incident. The defining test is that an MSP is responsible for keeping things in an agreed state, not only for responding when they are not. The term carries no certification of its own, so ISO 27001, Cyber Essentials and vendor partner status are the signals worth checking. Outside IT, MSP also means Member of the Scottish Parliament and, in retail, minimum selling price.See: MSP vs CSP vs MSSP · MSP vs internal IT · Managed IT Services
- MSSP (Managed Security Service Provider)
- A provider specialising in threat detection and response, typically running a security operations centre with analysts monitoring telemetry continuously, threat hunting and contracted incident response. Distinct from an MSP, which covers IT operations broadly including preventive security controls. Most small and mid-sized businesses are better served by an MSP delivering managed EDR/XDR than by a separate MSSP contract, until a regulatory obligation or threat profile justifies one.See: MSP vs CSP vs MSSP · Security Services
O
- Outsourced IT
- Handing IT work to an external company rather than employing the people who do it. Managed services are a form of outsourcing, but not all outsourcing is a managed service: traditional outsourcing buys capacity that works to your direction and processes, usually billed against time or headcount, while a managed service buys an outcome and the provider brings its own tooling and process. The practical test is who decides how the work gets done.See: IT outsourcing vs managed services
- Oversharing (data governance)
- The gradual build-up of over-permissive sharing links, stale guest access and unlabelled sensitive files in Microsoft 365. Long a risk, and an urgent one once Copilot can surface anything a user can access.See: Copilot readiness · Microsoft 365 Security Posture Assessment
P
- Password Manager
- Software that generates and stores unique credentials so people are not reusing one password everywhere. The security question worth asking is not whether to use one, it is where the encrypted vault lives, since a shared public vault service is a concentrated target in a way a vault inside your own tenant is not.See: Security Services
- Patch Management
- Getting security updates onto devices and servers within a defined window, and being able to show that it happened. Cyber Essentials requires critical and high-severity updates inside fourteen days, and the part most estates struggle with is the evidence rather than the patching.See: Endpoint Management · Cyber Essentials Certification
- Penetration Testing
- A controlled attempt to break into your systems, carried out by people whose job is to find what an attacker would find. Distinct from a vulnerability scan, which lists known weaknesses without establishing whether they can actually be chained into anything.See: Security Services
- Phishing
- Fraudulent messages designed to trick people into revealing credentials or approving access. Still the number one route in for attackers, countered with email security, MFA and user awareness.See: Email Security & Archive · Security Services
- Phishing-Resistant MFA
- Multi-factor methods that cannot be relayed by an attacker sitting in the middle, such as passkeys, FIDO2 security keys or certificate-based authentication. Codes and push approvals are multi-factor but not phishing-resistant, which is the gap adversary-in-the-middle attacks exploit.See: Security Services
- PIM (Privileged Identity Management)
- A Microsoft Entra feature that grants administrative access just-in-time and for a limited time, minimising standing privileged access and reducing the impact of a compromised admin account.See: Microsoft 365 security gaps
- Prompt Injection
- Text hidden in content an AI system reads, written to make it ignore its instructions or reveal what it should not. It matters most where a system reads material other people can write, because the attack arrives as data rather than as a user request.See: AI Engineering
R
- RAG (Retrieval-Augmented Generation)
- An AI technique that grounds a language model's answers in your own documents and data, retrieved at query time, so responses are accurate, current and traceable to a source rather than invented.See: AI Engineering & Custom AI Solutions
- Reserved Instances & Savings Plans
- Azure commitment-based discounts that cut the cost of predictable workloads in exchange for a one- or three-year term. A core lever in Azure cost optimisation.See: Cost Management & Azure Optimisation · Cutting Azure waste
- Right-sizing
- Matching cloud resources (VM sizes, storage tiers, licences) to real utilisation, cutting waste without starving workloads of the capacity they genuinely need.See: Cost Management & Azure Optimisation · Microsoft 365 cost checklist
- RMM (Remote Monitoring and Management)
- The tooling an MSP uses to see and act on a customer estate remotely: an agent on each managed device reporting health, patch status and alerts, with the ability to deploy software and run remediation without attending site. It is the mechanism that makes proactive management possible at all, and it is provider-owned, which is one reason exit terms and documentation ownership are worth settling before signing a managed contract.See: Managed IT Services · Intune
S
- Secure Score
- A Microsoft measurement of an organisation's security posture across identity, data, devices and apps, with recommended actions. A number to act on, not just to report.See: Microsoft 365 Security Posture Assessment · Security Services
- Shadow AI
- Staff using AI tools the business has not approved, usually because the approved route is slower or does not exist. The risk is not the tools themselves, it is company information being pasted into services nobody has assessed.
- Shelfware
- Licences a business pays for but doesn't use, such as unassigned or over-specified Microsoft 365 seats. Auditing and right-sizing them is one of the fastest cost wins in IT.See: Microsoft 365 licensing shelfware · Cost Management & Azure Optimisation
- SIEM (Security Information and Event Management)
- A system that collects logs from across an estate and correlates them, so an attack visible only as a pattern across several systems can be spotted. Valuable in proportion to whether anyone is actually reading what it produces.See: Security Services
- SLA (Service Level Agreement)
- The part of a support contract that states what the provider is actually committed to: coverage hours, how quickly different severities of issue will be responded to, and what happens if those commitments are missed. Worth reading closely for the difference between a response target and a resolution target, and for what 24/7 means in practice, since it can describe a UK engineer starting work or an answering service raising a ticket for the morning.See: How to choose an IT support company
- SLM (Small Language Model)
- A smaller, more focused AI model that can be cheaper, faster, more private and hostable on infrastructure you control. For many specific business tasks an SLM outperforms a general-purpose API on cost and latency.See: AI Engineering & Custom AI Solutions
- SoA (Statement of Applicability)
- The ISO 27001 document listing which controls apply to you, which do not, and why. It comes early and shapes everything after it, so it is worth scoping properly rather than treating as paperwork to be completed later.See: Compliance Packs & Audit Readiness · ISO 27001 audit partnership
- SOC (Security Operations Centre)
- The team that monitors and responds to security alerts, in-house or bought as a service. The question worth asking of any provider is what happens at 3am and what they are authorised to do without waking you.See: Security Services · Out-of-hours & on-call cover
T
- TCO (Total Cost of Ownership)
- The full cost of running something over its life, rather than the price of buying it. In IT the gap between the two is usually licensing, the people who administer it, and the work needed when the platform underneath changes.See: Licensing & Cost Management
- Token Theft
- Stealing an authenticated session token (often via an AiTM phishing kit) to access an account without needing the password or MFA. Mitigated with token protection and device-bound Conditional Access.See: Microsoft 365 security gaps
U
- Update Rings
- Groups of devices that receive Windows updates on a staggered schedule, so a problematic update is found on a small pilot group before it reaches everybody. Only works if the pilot group is genuinely representative rather than whoever volunteered.See: Endpoint Management
V
- VDI (Virtual Desktop Infrastructure)
- Technology that hosts desktops centrally (in a datacentre or the cloud) and delivers them to users on any device, keeping data off the endpoint. Windows 365 and Azure Virtual Desktop are Microsoft's VDI options.See: End-User Computing
W
- White-Label IT Delivery
- Enterprise-grade technical delivery and advisory provided under another company's brand, letting vendors and MSPs take on contracts that need skills they don't have in-house.See: White-Label Delivery & Advisory
- Windows 10 End of Life
- Free support for Windows 10 ended in October 2025. Devices still on it are unpatched unless covered by Extended Security Updates, making migration to Windows 11 a priority.See: Windows 10 end of life · Legacy Modernisation & OS Migration
- Windows 365
- Microsoft's Cloud PC service, giving each user a dedicated Windows desktop in the cloud at a fixed per-user price, reachable from any device, with IT keeping control of the data.See: Windows 365 remote access · End-User Computing
- Windows Update for Business
- The Microsoft service, managed through Intune, for controlling how and when Windows quality and feature updates are deployed to devices, using deployment rings and schedules.See: Intune management & reporting
X
- XDR (Extended Detection and Response)
- Security technology that correlates signals across endpoints, identity, email and cloud so an attack touching several of them is seen as one incident rather than separate, unrelated alerts.See: Security Services · Microsoft 365 security gaps
Z
- Zero Trust
- A security model that stops treating the corporate network as a trusted place and verifies every request on its own merits: who is asking, from what device, in what state. Sold as a product by many vendors and actually an architectural principle, delivered mostly through identity and device controls you already own.See: Security Services
Came here to check what something meant?
Ask us the question behind it. No obligation, no assessment to book first, and we will tell you plainly if the answer is that it does not apply to you.
