# Systech IT Solutions: full text > UK Microsoft-first IT partner, built on four pillars: **Microsoft Cloud** > (Microsoft 365, Azure, Windows 365 and AVD), **cyber security** (managed > firewall, EDR/XDR, email security, Cyber Essentials), **AI** (Copilot adoption, > AI engineering) and **managed services** (24/7 UK-based support, backup, > application packaging and legacy modernisation). For growing businesses that > want enterprise-grade IT without the enterprise complexity or cost. > Founder-led by Ryan Mangan, a Microsoft MVP and author of "Mastering Azure > Virtual Desktop". Based in Brough, East Yorkshire; serving the UK and Europe. This is the expanded companion to https://systechitsolutions.co.uk/llms.txt. It carries the complete text of the pages most worth quoting, the comparison guides, the service pillar pages, the glossary and the free resources, so an answer engine can work from the source rather than a summary. Every line below is generated from the site's own page sources at build time. The index of every other page on the site, including case studies, industries, service areas and the blog, is in llms.txt. ## Comparison guides Neutral, standalone comparisons of the options a growing UK business chooses between. Full text of each guide follows. ### Azure Virtual Desktop vs Windows 365 vs traditional desktops URL: https://systechitsolutions.co.uk/compare/avd-vs-windows-365-vs-traditional-desktops Cost model, management overhead and the situations each one actually suits, compared straight, so you can pick the right desktop strategy for your business. Category: Cloud & End-User Computing | Last updated: 2026-08-18 Every growing business eventually asks the same question: do we buy laptops and desktops the way we always have, or do we move the desktop itself into the cloud? And if we go cloud, is that Azure Virtual Desktop or Windows 365? There's no universally right answer, only the right answer for your workforce, your applications and how predictable your usage actually is. In short: Windows 365 gives every user a fixed-cost, dedicated Cloud PC with the simplest management overhead of the three, and suits stable, predictable headcount. Azure Virtual Desktop is more flexible and can be cheaper at scale or with variable usage, but demands real ongoing engineering to configure, scale and secure properly. Traditional desktops still make sense for specialist hardware, offline-first work, or genuinely small, static teams where cloud desktop infrastructure is more than the problem needs. Most growing businesses end up using a mix rather than picking one exclusively. This isn't a hypothetical decision. It's one we get asked to help with regularly, usually by a business that's either replacing an ageing desktop fleet, supporting a hybrid or remote workforce for the first time, or trying to work out why last year's laptop refresh budget keeps growing. This guide compares all three approaches honestly, including where each one falls down, not just where it shines. #### What are you actually choosing between? It helps to be precise about what each option actually is, because the marketing language around all three tends to blur the lines. ##### Azure Virtual Desktop (AVD) AVD is Microsoft's virtual desktop infrastructure (VDI) platform, built on Azure. You (or a partner) design and manage the host pools, the virtual machines that actually run Windows, decide how sessions are pooled or dedicated, configure autoscaling, choose VM sizes, and manage the FSLogix profile storage that keeps a user's desktop consistent between sessions. It's powerful and flexible, but it's genuine infrastructure you're responsible for configuring and maintaining, not an out-of-the-box product. ##### Windows 365 Windows 365 is Microsoft's Cloud PC service: a defined, fixed-configuration virtual machine assigned to a single named user, provisioned automatically once you assign a licence. There's no host pool to design, no VM sizing decision beyond picking a plan, and no scaling plan to configure, Microsoft handles the underlying infrastructure. The trade-off for that simplicity is less flexibility: you're choosing from a smaller set of pre-defined configurations rather than architecting the environment yourself. ##### Traditional (physical) desktops The model most businesses grew up on: a physical PC or laptop per user, purchased outright or leased, with applications, data and the user profile living locally (with file sync or backup layered on top, if you're doing it properly). Management happens through tools like Intune or a traditional device management platform, and hardware failure means the user is down until that specific device is fixed or replaced. #### Cost model compared The single biggest source of confusion in this decision is that all three options spend money in structurally different places, which makes a like-for-like number nearly impossible to give honestly, and anyone who quotes you one figure without asking about your usage pattern first is guessing. ##### How AVD is priced You pay for the underlying Azure compute (the VMs themselves), storage (for FSLogix profiles and any attached disks), networking, and the Windows/Microsoft 365 licensing that makes multi-session Windows legally usable. Because it's metered infrastructure, cost scales with actual usage: an autoscale scaling plan that shuts hosts down outside working hours genuinely reduces the bill, and a pool sized for real demand rather than "just in case" makes a material difference. That's the upside. The downside is that cost also scales with configuration quality: a poorly tuned AVD environment, oversized VMs, no autoscaling, premium storage nobody needed, can quietly cost more than either of the alternatives. ##### How Windows 365 is priced A flat, fixed, per-user, per-month licence cost set by Microsoft based on the Cloud PC's compute, memory and storage specification. You choose a plan up front and the cost is predictable regardless of how much or how little that user actually works that month. There's no variable Azure consumption bill to reconcile, no surprise from a scaling plan misfire. The trade-off is that you're paying the same amount whether a Cloud PC is used eight hours a day or barely logged into, there's no automatic reward for low usage the way AVD's autoscaling offers. ##### How traditional desktops are priced Capital cost (or lease payments) for the hardware itself, spread across a refresh cycle that typically runs several years, plus the ongoing cost of on-site support, hardware repairs, and the IT time spent managing a fleet of physical devices that all age and fail on their own separate schedules. It's easy to underestimate this model's total cost because so much of it, break/fix time, replacement parts, the admin overhead of tracking asset lifecycles, doesn't appear as a single clean line item the way a cloud subscription does. "None of the three models is free of cost, they just put the cost in different places: a metered cloud bill, a fixed monthly licence, or a hardware refresh cycle and a support desk. The question isn't which one costs nothing, it's which one matches how your business actually works." #### Management overhead Cost is only half the decision. The other half is how much ongoing effort each option demands from whoever is running your IT, whether that's an internal team or a managed provider. ##### AVD management overhead This is where AVD asks the most of you. Host pools need to be designed correctly from day one, session host images need to be maintained and patched, FSLogix profile storage needs monitoring, and autoscaling plans need setting up and revisiting as usage patterns change. Done well, AVD runs efficiently and flexibly. Done once at launch and never revisited, which is depressingly common, it tends to become an expensive, static environment that nobody wants to touch. AVD rewards ongoing, competent management far more than it punishes a one-off configuration mistake. ##### Windows 365 management overhead Deliberately the lightest of the three. Assign a licence, the Cloud PC provisions itself, and day-to-day management largely happens through the same Intune/Microsoft 365 tooling you'd already use to manage any other Windows endpoint. There's no host pool, no VM sizing decisions to keep revisiting, no scaling plan. The trade-off is that when you do need something outside the standard plan menu, more storage, a different vCPU/memory ratio, GPU acceleration, Windows 365 simply doesn't offer it, and that's a real limitation for some workloads. A less-discussed difference sits underneath both of these: blast radius when something actually fails. A real-world AVD session host typically carries somewhere around 20-30 concurrent users, not the higher figure Microsoft's own published sizing guidance might suggest is achievable, so a single host going down takes that whole group offline at once. A Windows 365 Cloud PC is dedicated to one named user; if it has a problem, exactly one person is affected. Neither model is wrong, but it's a real operational trade-off that a pure cost comparison misses. ##### Traditional desktop management overhead Physical asset management: tracking which device belongs to which user, coordinating repairs and replacements, managing local patching and software deployment across a fleet spread across however many locations your people actually work from, and handling the logistics of collecting and reissuing hardware when someone leaves or a device fails. None of this is exotic, but it scales roughly linearly with headcount and device count, in a way that cloud desktop management generally doesn't. #### Where each one actually fits ##### When AVD makes sense Genuinely variable or seasonal usage where autoscaling has real work to do; specialist workloads needing GPU-backed VMs, custom VM sizing, or pooled multi-session hosts for cost efficiency at scale; organisations with the in-house skill (or a specialist partner) to configure and actively manage the environment rather than deploy it once and leave it; and scenarios needing configurations Windows 365's fixed plans simply don't offer. ##### When Windows 365 makes sense Stable, predictable headcount where most users need a similar, consistent desktop experience; businesses that want cloud desktop resilience (work from anywhere, fast recovery from a lost or broken device) without taking on infrastructure management; and organisations without the in-house appetite to actively tune and monitor a virtual desktop environment, where "provision and forget" is genuinely the right trade-off, not a shortcut. ##### When traditional desktops still make sense Specialist or legacy hardware dependencies that don't virtualise cleanly, high-performance local workloads with heavy graphics or hardware peripheral requirements, genuinely offline-first work where connectivity can't be assumed, and small, static teams where the operational overhead of any virtual desktop platform, AVD or Windows 365, is more infrastructure than the problem actually needs. Cloud desktops solve a real problem; they're not automatically the right answer for every team size. #### The full comparison | | Azure Virtual Desktop | Windows 365 | Traditional desktops | | --- | --- | --- | --- | | Cost model | Metered Azure compute, storage and networking | Fixed per-user, per-month licence | Capital/lease cost plus ongoing support | | Cost predictability | Variable, scales with usage and configuration | High, fixed regardless of usage | Predictable per refresh cycle, variable support cost | | Management overhead | Highest, ongoing host pool and scaling management | Lowest, provision-and-manage via Intune | Physical asset and on-site support overhead | | Flexibility | Highest, custom VM sizing, GPU, pooled hosts | Fixed plan menu, no custom configuration | Full hardware choice, but per-device | | Recovery from device loss | Fast, session isn't tied to hardware | Fast, session isn't tied to hardware | Slow, user is down until device is fixed/replaced | | Best suited to | Variable usage, specialist or elastic workloads | Stable headcount wanting simplicity | Specialist hardware, offline-first, small static teams | #### Common mistakes when choosing The most common mistake is picking a platform based on what a vendor or a case study recommends for a business that doesn't resemble yours. A pooled AVD environment tuned for a call centre with predictable shift patterns is a poor template for a professional services firm with unpredictable, spiky usage, and vice versa. The second most common mistake is treating the decision as permanent and irreversible: it isn't, and plenty of businesses run a mixed estate, Windows 365 for most of the workforce, AVD for the elastic or specialist minority, and a handful of traditional desktops for the roles that genuinely need dedicated hardware. The third is underestimating management overhead on the AVD side specifically: an environment configured once at launch and never revisited tends to be the most expensive of all three options, not the cheapest, because none of the levers that make AVD cost-efficient get pulled without ongoing attention. #### When is AVD more cost-effective than Windows 365, and vice versa? **Short answer:** AVD wins on cost when concurrency is well below headcount, because pooled hosts and autoscale stop billing for seats nobody is using. Windows 365 wins when concurrency is close to headcount, because there is nothing left for AVD's flexibility to save and the design overhead buys you nothing. The crossover point is not a number of users, which is the first thing worth unlearning. We have seen two businesses of near-identical headcount land on opposite answers, because one ran a nine-to-five office where almost everybody was signed in at once, and the other ran shifts where peak concurrency never exceeded 40% of staff. ##### The ratio that actually decides it What actually decides it is the ratio between peak concurrent sessions and total licensed users. If 100 people share a platform but only 45 are ever signed in at the same time, AVD can size the pool to 45-ish with headroom and ramp it down overnight and at weekends. Windows 365 bills all 100 whether they are working or not. That gap is where AVD's saving lives, and it compounds every hour the pool is smaller than the headcount. Invert it and the logic inverts too. If 95 of those 100 are signed in every weekday morning, the pool never shrinks meaningfully, autoscale has nothing to reclaim, and you have taken on host pool sizing, image management, storage design and scaling plans in exchange for a saving that did not materialise. At that point the fixed per-user price is not just simpler, it is usually cheaper once you count the management time honestly. Three situations override the concurrency maths entirely: - **GPU workloads.** Windows 365 has no GPU option. If you run CAD, rendering or GPU-accelerated analysis, AVD is the only one of the two that can do it, at any headcount. - **Shift patterns with Frontline.** Windows 365 Frontline lets a pool of licences rotate across shift workers, which claws back some of AVD's concurrency advantage for exactly the pattern that usually favours AVD. Worth checking before assuming AVD wins on a shift-based estate. - **Nobody to own it.** AVD's saving is conditional on somebody tuning it. An untuned AVD estate reliably costs more than Windows 365, because host pools sized for a Monday peak keep running at that size every night and weekend. #### TCO analysis: AVD vs Windows 365 **Short answer:** A genuine TCO comparison has four lines, not one. Licensing, infrastructure consumption, storage, and the management effort to keep it correct. Comparing only the first two is what produces business cases that look right and then drift. ##### Licensing Windows 365 is a single per-user, per-month figure that covers the desktop and the compute together. AVD splits it: the Windows access right usually comes bundled in a licence you already hold, Microsoft 365 E3, E5, F3, Business Premium or Windows Enterprise E3 and E5, and the compute is billed separately as Azure consumption. That bundling is why AVD licensing looks free at first glance and why AVD estates so often carry duplicate-purchased access rights. ##### Infrastructure This is the line Windows 365 does not have and AVD lives or dies by. Session host VMs are billed by the hour they run, which means the real driver is not the VM size but how many hours per week the pool is actually up. A pool that runs 168 hours a week when the business works 50 is paying more than three times what it needs to, and no VM right-sizing exercise recovers that. ##### Storage FSLogix profile containers on Azure Files, and the tier choice here is a genuine trap. Standard tier looks cheaper per gigabyte and bills per transaction, and an active virtual desktop workload generates tens of thousands of transactions per user per day across logon, logoff, application launches and file syncs. Standard routinely costs more than Premium once transactions are counted, which is the opposite of what the per-gigabyte price suggests. Windows 365 has no equivalent line because the profile lives on the Cloud PC. ##### Management The line most business cases omit, and the one that most often decides the answer. AVD needs somebody to own autoscale tuning, image versioning, storage tier review and capacity checks on an ongoing cycle, not once at go-live. Whether that is internal time or a managed service, price it, because a TCO model that values it at zero will always recommend AVD and will always be wrong when nobody has the time. A model built on those four lines usually produces a different answer than the licensing comparison people start with, and it is the model we use at assessment rather than a rule of thumb. #### AVD management vs Windows 365 management **Short answer:** Windows 365 management is subscription management. Assign a licence, a Cloud PC appears; remove it, it goes. AVD management is infrastructure management for infrastructure you do not physically own, and none of its decisions stay correct on their own as usage changes. The distinction that matters is not how much work each takes on day one. Both are straightforward to stand up. It is how much work each takes in month six, and whether that work has an owner. ##### With Windows 365: licence hygiene With Windows 365, the ongoing job is licence hygiene and Intune policy. Are leavers' Cloud PCs reclaimed? Is anybody on a bigger size than they need? Is the Intune configuration still matching how people work? That is real work but it is bounded, and getting it wrong costs money rather than breaking things. ##### With AVD: the environment itself With AVD, the ongoing job is the environment itself. Scaling plans need revisiting as working patterns shift, because a ramp-up schedule built around a 9am login wave is wrong the moment the business moves to staggered starts. Golden images need versioning and rebuilding, because an image that accumulates applications boots slower, patches slower and takes longer to roll out every cycle. Storage tier needs reviewing against measured transaction volume. Host pool sizing needs checking against actual concurrency rather than the number it was set to at go-live. None of that trips an alarm when it stops being correct. It shows up as a slowly rising invoice and slowly worsening logon times, which is why AVD estates so often reach a renewal review with nobody able to explain how they got there. #### Feature comparison of AVD and Windows 365 management platforms **Short answer:** They are managed through overlapping but different planes. Windows 365 is governed almost entirely through Intune and the Microsoft 365 admin centre. AVD adds the Azure portal, host pools, scaling plans, the Compute Gallery and storage configuration on top of that same Intune layer. | Management concern | Windows 365 | Azure Virtual Desktop | | --- | --- | --- | | Primary plane | Intune and Microsoft 365 admin centre | Azure portal, plus Intune for the guest OS | | Provisioning | Assign a licence and a provisioning policy | Build host pools, session hosts and app groups | | Capacity control | Change the Cloud PC size | Host pool sizing, VM SKU choice, session density | | Scaling | None to configure | Scaling plans with ramp-up, peak and ramp-down | | Image management | Gallery image or a custom image | Azure Compute Gallery with versioning and staged rollout | | Profile storage | On the Cloud PC, nothing to design | FSLogix containers on Azure Files, tier and size chosen by you | | Application delivery | Intune Win32 apps | Image, Intune Win32, or MSIX App Attach | | Monitoring | Endpoint analytics | Azure Monitor, per-host metrics, Log Analytics | | Identity and access | Entra ID with Conditional Access | Entra ID with Conditional Access, plus RBAC on Azure resources | | Patching | Intune update rings | Update rings plus session host patching and image rebuilds | Read down the AVD column and the pattern is clear: every row where Windows 365 says "nothing to configure" is a row where AVD gives you a lever. Those levers are precisely why AVD can be cheaper and faster than a Cloud PC, and precisely why it is not automatically either. #### What is the best way to manage both AVD and Windows 365? **Short answer:** Standardise everything that can be shared, and keep the platforms separate only where they genuinely differ. Identity, Conditional Access, application packaging and Intune policy should be common. Host pool design and scaling stay AVD-only, because Windows 365 has no equivalent. Mixed estates are common and they work well when they are designed as one estate with two delivery mechanisms, rather than as two projects that happen to share a tenant. The parts that should be shared: - **Identity and Conditional Access.** One set of policies covering both, so a Cloud PC and an AVD session are held to the same access standard. Two divergent policy sets is how a gap opens. - **Application packaging.** Package once, deliver to both. MSIX and Intune Win32 packages work across the two, so maintaining separate application estates is avoidable effort. - **Intune configuration and update rings.** The guest operating system is Windows in both cases, so device configuration, security baselines and update rings should not fork. - **Monitoring and service desk process.** Users do not care which platform their desktop runs on, and neither should the first line of a support ticket. The parts that stay separate: host pool sizing, scaling plans, FSLogix storage and image versioning are AVD concerns with no Windows 365 counterpart, and Cloud PC size assignment and licence reclamation are Windows 365 concerns with no AVD counterpart. Trying to force those into a single process creates work rather than saving it. The allocation rule we use most often is simple. Permanent staff with predictable hours go on Windows 365, because nothing needs sizing and the cost is known in advance. Task workers, contractors, seasonal staff and anyone needing GPU or a specialist VM series go on AVD, where the pool can flex around them. #### What are the challenges of managing AVD and Windows 365 separately? **Short answer:** Duplicated effort and divergent policy. Two application packaging streams, two sets of Conditional Access rules, two monitoring approaches and two support runbooks, for one population of users doing one job. The cost is rarely visible as a line item and usually shows up as drift. The specific failure modes we see most often: **Policy divergence.** Conditional Access is tightened on one platform after a review and not the other. Six months later the looser platform is the way in, and nobody planned it that way. **Application drift.** An application gets updated in the AVD golden image but not in the Intune package that serves Cloud PCs, or the reverse. Users on different platforms are now running different versions of the same line-of-business software, which turns a support call into an investigation. **Inconsistent onboarding.** A new starter's experience depends on which platform they land on, so the process has two branches and the less-used branch quietly decays. **Split cost visibility.** Windows 365 shows up as a licence line and AVD as Azure consumption, on different bills, often owned by different people. Nobody sees total desktop cost in one place, which is how a business ends up unable to answer what its desktops actually cost. **Duplicate licensing.** The one that costs real money quietly. AVD access rights bundled into Microsoft 365 E3, E5 or Business Premium get purchased again as standalone licences because the two platforms were procured by different processes. None of these are arguments against running both. They are arguments against running both as two estates. #### What overlooked factors drive up AVD and Windows 365 costs? **Short answer:** On AVD, the hours the pool runs rather than the VM size, the FSLogix storage tier, and image bloat. On Windows 365, licences that are never reclaimed. In both cases, duplicate-purchased access rights already bundled in Microsoft 365. The costs people expect are VM size and licence count. The ones that actually cause the drift are less obvious: - **Running hours, not VM size.** Right-sizing a VM saves a percentage. Ramping the pool down out of hours and at weekends saves a multiple. A business working 50 hours a week on a pool that runs all 168 is carrying the single largest recoverable cost in most AVD estates, and it is a configuration change rather than new infrastructure. - **FSLogix on the wrong storage tier.** Standard tier bills per transaction, and virtual desktops generate enormous transaction volumes. The per-gigabyte saving is routinely wiped out and then some. This one stays invisible until somebody reads the storage bill by transaction rather than by capacity. - **Image bloat.** Every application baked into a golden image makes every host boot slower, patch slower and take longer to roll out. The cost is not a line item, it is compounding time on every cycle. - **Cloud PCs assigned to nobody.** The commonest Windows 365 waste by a distance. Leavers, long-term absence and role changes leave licences assigned and billing at full rate. There is no autoscale to catch it, so it needs a reclamation routine or it accumulates indefinitely. - **Duplicate access rights.** AVD access is included in Microsoft 365 E3, E5, F3, Business Premium and Windows Enterprise E3 and E5. Buying it again standalone is easy when licensing and infrastructure sit with different people. - **Log Analytics retention.** Diagnostic settings left at defaults on a large estate quietly ingest and retain far more than anyone needs, and it lands on the Azure bill rather than anywhere anyone associates with desktops. Our AVD cost optimisation quick wins post works through the AVD side in the order we tackle it, and the full AVD cost optimisation checklist sits on our Azure Virtual Desktop consultancy page. #### How to actually decide Start with usage pattern, not price. If most of your workforce logs in for similar hours most days, that predictability favours Windows 365's flat cost and low overhead. If usage genuinely varies, seasonal headcount, seasonal contractors, workloads that spike and then go quiet, AVD's metered model has real room to earn its extra management overhead back. Then layer in workload requirements: anything needing GPU acceleration, custom VM sizing, or pooled multi-session cost efficiency at real scale points toward AVD regardless of usage pattern, because Windows 365 simply doesn't offer those configurations. Finally, be honest about who's going to manage whichever platform you pick, day two matters more than day one, and an AVD environment without someone actively tuning it tends to underperform both the alternatives. If you're weighing this up for your own business, our end-user computing service covers Azure Virtual Desktop and Windows 365 design and consultancy, working out which model (or mix of models) actually fits your usage pattern and workforce, before anything gets built. We've also written a more focused Windows 365 vs AVD comparison if you've already ruled out traditional desktops and want to go deeper on just those two. And if managed support for whichever platform you choose is the next question, our managed IT support team covers the day-to-day running of all three models, not just the ones we've built ourselves. #### Frequently asked questions **Is Azure Virtual Desktop or Windows 365 cheaper?** It depends entirely on usage pattern, not on which platform is inherently cheaper. AVD is metered compute and storage, so a workforce with genuinely variable or seasonal usage (some users part-time, hosts scaled down overnight and at weekends) can cost less than a fixed per-user Windows 365 licence. A workforce that's logged in and working consistently, five days a week, often ends up costing about the same either way once you account for the engineering time AVD's flexibility demands. Traditional desktops move the cost elsewhere entirely, into hardware refresh cycles and on-site support, which doesn't show up on a monthly cloud bill but is very real. The caveat worth stating plainly is that AVD's cost also scales with configuration quality, not just usage: oversized VMs, no autoscaling plan and premium storage nobody needed can leave a poorly tuned environment costing more than either alternative. The saving is earned by ongoing tuning rather than granted by the platform. **Can you run Windows 365 and AVD side by side?** Yes, and plenty of organisations do. It's common to put predictable, steady-state users on Windows 365 for the flat cost and consistent performance, and use AVD for elastic scenarios: contractors, seasonal peaks, dev/test pools, or specialist workloads that need pooled multi-session hosts or GPU-backed VMs Windows 365 doesn't offer. The two aren't mutually exclusive, and mixing them by workload is often the right answer rather than a compromise. The trade-off is that you take on both management models at once. The Windows 365 side stays light, provisioning itself when you assign a licence and managed through the same Intune tooling as any other Windows endpoint, while the AVD side still needs host pools, session host images, FSLogix profile storage and scaling plans actively maintained. That's a reasonable price when a real workload needs configurations the fixed Windows 365 plan menu doesn't offer, and hard to justify when nothing does. **Do I still need on-premises servers if I move to AVD or Windows 365?** Not for the desktop itself, but line-of-business applications and file shares that depend on on-premises infrastructure don't disappear just because the desktop moved to the cloud. Some organisations run virtual desktops that still depend on an on-premises domain controller, an ERP server, or a legacy application server over a site-to-site VPN or ExpressRoute. Moving the desktop layer to the cloud is a real step forward, but it's not automatically a full migration off on-premises infrastructure unless you plan for that separately. What it does remove is the part of the estate that scales with headcount: the per-device hardware refresh cycle, the on-site support and the asset-lifecycle admin that grow roughly linearly with the number of physical machines you own. What's left behind is a fixed, countable set of servers, and treating their migration as its own project with its own timeline is more honest than assuming the desktop move quietly carried them along too. **What happens to a traditional desktop rollout during a hardware failure?** The user is typically down until the device is repaired or replaced, because their profile, applications and data live on that specific machine (or are only partially synced to the cloud). With AVD or Windows 365, a failed physical device is far less disruptive: the user's session lives in Azure, so they log in from a different device, a personal laptop, a loan machine, even a tablet, and are back at their desktop within minutes. This is one of the most underrated differences between the models and rarely shows up in a pure cost comparison. The honest counterweight is that cloud desktops move the failure rather than remove it. A real-world AVD session host typically carries somewhere around 20-30 concurrent users, so a host going down takes that whole group offline at once, while a Windows 365 Cloud PC is dedicated to one named user and fails for exactly one person. Neither is wrong, but it's the trade-off a pure hardware-failure comparison misses. **Is Windows 365 the same as a remote desktop connection to a normal PC?** No. A remote desktop connection (RDP to a physical PC, or a basic remote-access tool) still depends on that physical machine being switched on, on the network and working. Windows 365 provisions a genuine Cloud PC, a persistent virtual machine that exists independently of any physical hardware, with its own compute, storage and Windows licence, hosted in Microsoft's cloud rather than routed through an office PC. The user experience looks similar from the login screen, but the underlying architecture, resilience and management model are completely different. The management difference is the practical one: a Cloud PC provisions itself once you assign a licence and is then managed through the same Intune and Microsoft 365 tooling as any other Windows endpoint, with no office machine that has to stay switched on. The limit is that you pick from a fixed menu of plans, so anything needing GPU acceleration or a custom vCPU and memory ratio falls outside what Windows 365 offers. ### Managed IT support vs in-house IT vs break-fix URL: https://systechitsolutions.co.uk/compare/managed-it-vs-in-house-vs-break-fix The right IT support model changes as you scale. How managed IT, an in-house team and break-fix compare on cost, response time and coverage for 15-250 seats. Category: Managed IT | Last updated: 2026-08-18 Somewhere between "the founder's nephew fixes the printer" and "we have a full internal IT department," every growing business has to decide how it actually wants IT support to work. Get it right early and it barely gets discussed again. Get it wrong, and it becomes the recurring meeting nobody enjoys, the outage that costs a day of trading, or the hire that never quite covers what you needed. In short: Break-fix IT (paying only when something breaks) is the cheapest model on paper but the most expensive in practice once outages, security gaps and lost productivity are counted. In-house IT gives you dedicated, embedded knowledge but is limited by one team's skills, headcount and availability. Managed IT support trades some of that direct control for predictable cost, broader specialist coverage and proactive prevention rather than reactive fixing. For a growing business in the 15-250 seat range, the model that fits usually shifts as headcount grows, and increasingly, the answer for larger teams in that range is a co-managed mix of the two rather than picking one exclusively. This comparison is written specifically for that 15-250 seat range, because it's the range where the "obvious" answer actually changes. A 15-seat business and a 250-seat business are choosing between genuinely different trade-offs, even though both might describe their problem the same way: "our IT support isn't working the way we need it to." #### The three models, in plain terms ##### Managed IT support A managed service provider takes ongoing, contracted responsibility for some or all of your IT estate, monitoring, patching, security, service desk, and (where agreed) strategic input, for a predictable recurring cost. The relationship is proactive by design: the provider is paid to prevent problems as much as to fix them, through practices like scheduled, owned patch management and identity-based Conditional Access controls, and typically carries a broader bench of specialist skills across security, cloud, networking and infrastructure than a single internal hire realistically can. ##### In-house IT You directly employ the people responsible for your IT, whether that's one generalist wearing every hat or a small internal team split across specialisms. The advantage is deep, embedded knowledge of your business, its people, its quirks and its priorities, built up over time by people who work only for you. The constraint is capacity: one person, or even a small team, has finite hours, finite specialist knowledge, and finite availability outside normal working hours, all of which have to be planned around rather than assumed away. ##### Break-fix No ongoing contract. You call an IT company (or manage it internally, ad hoc) when something breaks, pay for that specific piece of work, and there's no relationship or coverage in between incidents. It looks like the cheapest option because there's no baseline monthly cost, but nothing is being monitored, patched proactively or protected until a problem has already happened, which shifts cost from a predictable line item into unpredictable downtime, data loss risk and emergency call-out pricing. #### Cost predictability This is where the three models genuinely differ, not just in amount but in shape. - **Managed IT support** is built around a predictable, typically per-user or per-device, recurring cost that's straightforward to budget against and scale as headcount changes. - **In-house IT** looks predictable too. On the surface it's a salary, or a small team's combined salaries, but the real cost is less stable than it looks: training, tooling, recruitment when someone leaves, and the gap in coverage while a role sits vacant all add variable cost that doesn't show up in the base salary figure. - **Break-fix** is the least predictable of all three by a wide margin. Cost tracks incidents, and incidents don't arrive on a schedule. A quiet quarter can be followed by an expensive one with no warning, and emergency, out-of-hours or urgent call-outs are typically priced at a premium precisely because they're unplanned. "Break-fix isn't actually the cheapest model, it's the model where the cost is easiest to underestimate, because most of it is hidden in downtime, lost productivity and emergency pricing rather than a single monthly invoice." #### Response time and coverage - **Managed IT support** is generally structured around defined coverage hours and a service desk built to handle volume, so issues are typically triaged and actioned faster simply because responding to them is the provider's core job, not a distraction from someone's other responsibilities. - **In-house IT** response time depends entirely on who's available. A single in-house hire covers their own working hours, and anything outside that, evenings, weekends, annual leave, sick days, is a genuine coverage gap unless the business has explicitly planned for it, which many haven't. - **Break-fix** response time is the least predictable of the three. You're not a contracted priority, you're a new job being slotted into whatever queue the provider already has, and urgent issues outside business hours are often the most expensive and slowest to resolve of any model here. #### Where each model breaks down as you scale ##### Break-fix breaks down first Break-fix tends to work adequately for a genuinely small operation with simple, low-risk IT needs, where an outage is inconvenient rather than costly. It breaks down quickly once a business has real dependencies: a growing customer base relying on continuous uptime, compliance obligations that require evidence of proactive security management (not just reactive fixes), or simply enough people that the cumulative cost of small, unaddressed issues starts to add up. By the time a business reaches the lower end of the 15-250 seat range, break-fix is usually already the most expensive option in practice, even though it still looks the cheapest on an invoice. ##### In-house breaks down next A single in-house IT hire, or even a small internal team, tends to hold up well until the range of technical demands outgrows what that team can realistically specialise in. Security, cloud infrastructure, networking, compliance and day-to-day service desk volume are each deep enough to be a specialism on their own; expecting one generalist, or even three or four people, to be genuinely expert across all of them becomes harder to sustain the more the business (and its technology estate) grows. This is usually where the gap first becomes visible, not because the in-house team isn't good, but because the breadth of what's being asked of them has outgrown what any small team can cover alone. ##### Where managed IT still holds Managed IT support scales more gracefully because the provider's job is specifically to maintain broad coverage across specialisms as client needs grow, spreading that cost and expertise across many clients rather than one. It isn't infinitely elastic either, a provider that's grown too fast or spread too thin has its own version of the in-house capacity problem, but a genuinely capable managed provider (rather than a small team of specialists stretched across too many clients) is generally the model best positioned to keep up as a business moves through and beyond the 15-250 seat range. #### The full comparison | | Managed IT support | In-house IT | Break-fix | | --- | --- | --- | --- | | Cost shape | Predictable, recurring | Mostly predictable, hidden variable costs | Unpredictable, tracks incidents | | Proactive vs reactive | Proactive by design | Depends on team capacity | Purely reactive | | Specialist coverage | Broad, spread across a specialist bench | Limited to the team's own skills | Whoever's available at the time | | Coverage hours | Defined, typically extends beyond office hours | Limited to the team's working hours | No guaranteed availability | | Scales with growth | Generally scales well | Strained once demands outgrow the team | Breaks down early | | Best suited to | Growing businesses needing broad, predictable coverage | Businesses needing deep, embedded institutional knowledge | Very small, low-dependency operations | #### A practical way to think about the 15-250 seat range - **At the lower end**, the choice is usually between break-fix and managed IT support, because a dedicated in-house hire is a significant fixed cost relative to headcount, and the breadth of coverage a managed provider offers tends to outweigh what one generalist can realistically provide. - **In the middle**, businesses often already have some in-house presence: an IT lead, or an office manager who's become the accidental IT contact. The real decision is whether to keep building that internally or bring in a managed provider to cover what internal capacity can't. - **At the upper end**, co-managed IT, an internal lead or small team working alongside a managed provider, becomes increasingly common. The business is large enough to justify embedded knowledge of its own priorities and vendor relationships, but still benefits from a provider's broader specialist bench for day-to-day volume and the 24/7 coverage a small internal team can't sustain alone. #### Common mistakes growing businesses make The most common mistake is staying on break-fix for too long simply because the monthly cost looks lower, without ever adding up what outages, emergency call-outs and lost productivity actually cost across a year. The second is hiring one in-house generalist and expecting them to cover security, cloud, networking and service desk volume equally well indefinitely, which is a lot to ask of any one person as the business grows around them. The third is treating managed IT and in-house IT as mutually exclusive, when for many businesses in the upper half of this range, a co-managed model gets more of the benefit of both than picking one exclusively ever would. The same hidden-cost pattern shows up in narrower slices of the estate too, not just the IT function as a whole. Our managed firewall vs DIY cost comparison walks through exactly this dynamic for a single piece of infrastructure: the visible cost of doing it yourself looks lower right up until the patching, monitoring and out-of-hours cover nobody owned turns out to be where the real cost was hiding. #### How to decide **Count what break-fix has actually cost you over the last year.** Not just the invoices, but the downtime, the delayed projects, and the times something waited longer than it should have because nobody was actively watching for it. If that number is uncomfortable, or you can't answer it because nobody's been tracking it, that's usually the clearest sign that reactive support has already become the more expensive option. **Then be honest about what an in-house team can realistically cover.** Deep knowledge of your business is genuinely valuable and hard to replace, but it isn't the same thing as broad specialist coverage across every area IT now touches, security, cloud, compliance and infrastructure among them. For most growing businesses in the 15-250 seat range, the answer that holds up longest is managed IT support, either as the whole solution or alongside an in-house lead who keeps the institutional knowledge in-house while a provider covers the rest. ##### Where to go next If you want a straight read on which model fits where you are right now, our managed IT support team can talk through what's actually covered, and what a co-managed setup could look like if you already have some in-house capability worth keeping. We're based in Brough, East Yorkshire, and support businesses in this exact seat range across the region, from our Leeds, Sheffield, Hull and York pages through to the full Yorkshire coverage area. And if the desktop and device side of your IT strategy is the next question, our AVD vs Windows 365 vs traditional desktops comparison covers that decision in the same straight, neutral way. #### Frequently asked questions **At what size should a business stop using break-fix IT support?** There's no fixed headcount where break-fix stops working, but the pattern is consistent: once IT problems start interrupting revenue-generating work often enough that reacting to them, rather than preventing them, becomes a noticeable drag, break-fix has already become the more expensive option even though the invoices look smaller. For most growing businesses that point arrives somewhere in the early stages of the 15-250 seat range, well before headcount alone would suggest it. Two things tend to bring it forward. Compliance obligations that require evidence of proactive security management, rather than a record of reactive fixes, are hard to satisfy when nothing is being monitored or patched between incidents. And urgent, out-of-hours call-outs are typically priced at a premium precisely because they're unplanned, so the quarters that go wrong go wrong expensively. The clearest test is to add up what the last year actually cost, including downtime and delayed projects, not just the invoices. **Is it cheaper to hire an in-house IT person or use managed IT support?** It depends on what you actually need covered. A single in-house hire covers one person's working hours, skill set and availability, evenings, weekends, holidays and sick leave are gaps unless you plan around them. A managed IT provider spreads cost across many clients, giving you access to a wider bench of specialist skills and broader coverage hours than one salary typically buys. The honest comparison isn't salary versus contract cost, it's what each one actually covers, and what's left uncovered, for a similar spend. A salary is also less fixed than it looks: training, tooling, recruitment when someone leaves and the coverage gap while the role sits vacant all sit outside the base figure, and none of them show up in the comparison most businesses run. Managed support is billed the other way round, as a predictable per-user or per-device recurring cost that scales with headcount rather than with who happens to be employed that month. **Can managed IT support and an in-house team work together?** Yes, and it's one of the most common models for businesses in the upper end of the 15-250 seat range. An in-house IT lead or small team handles the parts of the business only someone embedded in it can, day-to-day priorities, vendor relationships, strategic input, while a managed provider handles the 24/7 monitoring, patching, service desk volume and specialist coverage that's hard to justify hiring for directly. Co-managed IT is a real, common model, not a compromise between the two. It becomes the obvious answer at that size for a structural reason: the business is large enough to justify embedded knowledge of its own priorities and vendor relationships, but security, cloud infrastructure, networking, compliance and service desk volume are each deep enough to be a specialism on their own, and no small internal team stays genuinely expert across all of them as the estate grows around it. Co-managed keeps the institutional knowledge in-house and buys the breadth alongside it. **What's the real difference between managed IT and just calling an IT company when something breaks?** The difference is proactive versus reactive. Break-fix support, even from a good provider, only engages once something has already gone wrong: a server is down, a user is locked out, a laptop won't boot. Managed IT support is paid to prevent that call from happening in the first place, through monitoring, patching, security controls and regular review, and to respond faster when something does get through. You're not just buying a faster fix, you're buying fewer things that need fixing. The speed difference has a structural cause worth understanding. On break-fix you aren't a contracted priority, you're a new job being slotted into whatever queue the provider already has, and anything urgent outside business hours tends to be both the slowest to resolve and the most expensive. Under a managed contract, owned patch management and identity-based Conditional Access mean a share of those calls never get made at all, and the ones that do arrive against defined coverage hours rather than into a queue. **Does managed IT support replace the need for any in-house IT knowledge at all?** Not entirely, and it shouldn't try to. Even fully outsourced IT benefits from someone in the business, not necessarily a technical specialist, who owns the relationship, understands what's covered, and can make timely decisions when the provider needs input. What managed IT removes is the need for that person to be the one doing hands-on technical work, not the need for anyone to be paying attention. In practice that person also holds the things a provider can't hold from outside: day-to-day priorities, vendor relationships and the reasons the business does things the way it does. At the lower end of the 15-250 seat range that's often an existing manager wearing the hat part-time. Towards the upper end it usually formalises into an IT lead or small internal team working alongside the provider, which is the co-managed model, and that's a deliberate design rather than a gap left over from outsourcing. ### Microsoft 365 licensing: Business vs Enterprise, E3 vs E5 URL: https://systechitsolutions.co.uk/compare/microsoft-365-licensing-guide What Business Basic, Standard, Premium, E3, E5 and F3 include, where Copilot fits, why education buys the A series instead, and where the overspend is. Category: Microsoft 365 & Licensing | Last updated: 2026-08-18 Microsoft 365 licensing looks like a simple choice from the sign-up page: pick a tier, assign it to everyone, done. In practice it's one of the most common sources of quiet overspend we find when we review a business's Microsoft estate, not because anyone made an obviously wrong decision, but because the right tier for a 12-person business at sign-up isn't the right tier for the same business three years and forty hires later, and nobody's gone back to check. In short: Business Basic, Standard and Premium (capped at 300 users) cover the vast majority of UK SMBs, and Business Premium's added Defender, Intune and conditional access features are worth the jump for most businesses handling any sensitive data. The Enterprise tiers, E3, E5 and F3, matter once you outgrow 300 seats or need specific enterprise-only compliance and device management capabilities; E5 adds real advanced security and compliance value, but at real extra cost, and it's not something every business needs by default. Microsoft 365 Copilot sits on top as a separate per-user add-on, worth evaluating on adoption readiness and concentrated use cases, not blanket rollout. And the biggest cost lever for most businesses isn't which tier you pick once, it's whether anyone keeps that assignment right as the team changes. This guide covers what each tier actually includes, where Copilot fits, the licensing mistakes we see most often, and the difference between choosing a tier once and keeping your licensing under control on an ongoing basis, which are two different problems that get treated as one far too often. #### What are you actually choosing between? Microsoft splits its Microsoft 365 plans into two families, and which one applies to you is mostly decided by headcount and complexity, not preference. ##### Business Basic, Standard and Premium (up to 300 users) These three tiers are built for small and mid-sized organisations and are capped at 300 licensed users per tenant. - **Business Basic** gives you Exchange, Teams, SharePoint and OneDrive along with the web and mobile versions of the Office apps, but not the installed desktop apps. It suits roles that live mostly in a browser. - **Business Standard** adds the full desktop versions of Word, Excel, Outlook and PowerPoint plus Teams webinar and some collaboration features. It is the tier most knowledge-worker roles actually need day to day. - **Business Premium** adds a meaningful step up in security and device management on top of Standard: Microsoft Defender for Business, Intune for mobile device and app management, Windows Autopilot for automated device provisioning, and conditional access policies that gate sign-in on device compliance and risk signals. For any business handling client data, financial information or anything you would genuinely mind losing, Business Premium's added protection is usually worth the extra cost over Standard. It is a small percentage increase in licence spend for a real reduction in your most common attack surface: compromised accounts and unmanaged devices. ##### E3, E5 and F3 (Enterprise, no seat cap) The Enterprise tiers have no 300-user ceiling and are built for larger or more complex organisations. - **Microsoft 365 E3** includes the full desktop Office apps, Windows 11 Enterprise upgrade rights, and a deeper set of Intune device management and baseline compliance features (retention policies, basic eDiscovery) than the Business tiers offer. It is the natural landing point once you outgrow 300 seats, or need enterprise-specific device and compliance controls Business Premium does not include, even below that threshold. - **Microsoft 365 E5** adds Microsoft's most advanced security and compliance capabilities on top of E3: Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps, Insider Risk Management, Advanced eDiscovery, Communication Compliance, Power BI Pro, and Teams Phone calling plans. - **Microsoft 365 F3** is the frontline worker plan, built for shift-based staff in retail, warehouse or clinical roles who need core Teams, Outlook and SharePoint access without a full desk-based licence, and priced well below E3 to reflect that narrower scope. E5 is genuinely strong tooling, and for businesses in regulated sectors, or with a real and current need for advanced threat protection and compliance evidence, it earns its cost. It is also the tier we see oversold most often, bought because it is the top of the list rather than because a specific capability in it is going to be used. ##### If you are a school, college or trust, none of the above applies This guide compares the commercial plans, and education does not buy them. Schools, colleges and multi-academy trusts license on the **A series**, which is a different product family with different tiers and very different pricing. Reading an E3-versus-E5 comparison and trying to map it onto an education tenant produces the wrong answer at every step. The three tiers are cumulative, in the same way the commercial ones are: - **A1** is **free for eligible institutions**. It covers Teams, the web and mobile Office apps, Exchange Online and OneDrive. Not the installed desktop apps. - **A3** adds the full desktop Office apps plus the advanced management and security tooling, and is where most schools that need managed devices end up. - **A5** adds the most advanced security, compliance and analytics capabilities on top of A3. Two things about the A series catch people out. The first is that A1 being free means a large number of schools are running on it without ever having made a decision, and are then surprised that device management or desktop Office is not there. The second is the **Student Use Benefit** attached to A3 and A5, which lets students install the desktop apps on personal devices, and which is frequently paid for separately by institutions that already have it. There is also a genuine risk of the opposite mistake. Education pricing is generous enough that some capabilities are free or heavily discounted, and it is common to find a school that has bought something it was already entitled to. ###### How schools actually buy: the routes that change the price The tier is only half the decision. The purchasing route changes the price materially, and this is where the largest savings sit. - **Students are frequently included at no additional cost.** Under Microsoft's Enrollment for Education Solutions (EES), you license your faculty and staff, counted as Education Qualified Users, and student coverage comes with it. An institution buying student licences separately alongside staff licences is usually paying for something it already has. - **EES normally requires 1,000 Education Qualified Users**, which puts it out of reach of most individual schools. In the UK, the **Chest agreement run by Jisc reduces that minimum to 100**, which brings it within reach of a great many more schools, sixth form colleges and multi-academy trusts. Ordering runs through a Jisc contracted reseller. - **Volume tiers and term length both move the price.** Higher pricing levels apply above certain user counts, with further discounts available for a multi-year commitment rather than an annual one. - **A1 is free**, so the honest question is often not "which tier should we buy" but "which users genuinely need to move off the free one". The practical consequence is that two schools of identical size can pay very different amounts for the same thing, entirely on purchasing route. If nobody has looked at yours since it was set up, that is where to start. If you are in this sector, the first exercise is establishing what your existing entitlement actually covers before pricing anything new. Our education page covers the sector properly, and the DfE digital and technology standards set out what you are being measured against. #### Where Microsoft 365 Copilot fits Copilot for Microsoft 365 sits on top of whichever tier you're already on, as a separate per-user, per-month add-on rather than a replacement for any of them. It doesn't change which base tier is right for a role, it's a second decision layered on top, and the two shouldn't be conflated: getting the base tier right is about what each role needs to do its job; adding Copilot is about whether that specific person has a task Copilot genuinely accelerates, often enough to justify the ongoing cost. ##### Cost The two things worth checking before adding seats are cost and adoption readiness. On cost, Microsoft has adjusted Copilot's packaging and pricing more than once since launch, so treat any figure you've seen as a starting point to verify, not a fixed number, your Microsoft partner or your current agreement will have the live price. ##### Adoption readiness On adoption readiness, the return on a Copilot licence comes overwhelmingly from a smaller number of people using it heavily on tasks it's actually good at, not from spreading a licence thinly across everyone in the business "to see who uses it." We've written a fuller framework on this in is Microsoft 365 Copilot worth it?, and if data hygiene and access control are the open question before you commit to seats, our free Copilot readiness assessment scores exactly where your tenant stands first. "The tier decision and the Copilot decision get made together far too often. They're separate questions: one is about what a role needs to do its job, the other is about whether a specific person has a task Copilot genuinely speeds up, often enough to be worth paying for every month whether they use it or not." #### The full comparison Prices below are Microsoft's own published list pricing at the time of writing, per user per month, and are given as rough bands rather than exact figures: Microsoft's pricing, currency and promotions vary by region, agreement type and time, and change more often than this page will be updated. Confirm current pricing for your tenant and region before budgeting against any of these. | Tier | Family | Best suited to | Added beyond the base apps | Rough monthly cost per user* | | --- | --- | --- | --- | --- | | Business Basic | SMB (≤300 users) | Browser-first roles, light collaboration needs | Web/mobile Office apps, Exchange, Teams, SharePoint | Low, roughly £4-5 | | Business Standard | SMB (≤300 users) | Most knowledge-worker roles | Full desktop Office apps, Teams webinars | Mid, roughly £9-11 | | Business Premium | SMB (≤300 users) | Any role handling sensitive data or a managed device | Defender for Business, Intune, Autopilot, conditional access | Higher, roughly £19-21 | | F3 | Enterprise (no cap) | Frontline, shift-based staff | Core Teams/Outlook/SharePoint access, no desktop apps | Low, roughly £7-8 | | E3 | Enterprise (no cap) | Larger or more complex estates, 300+ seats | Windows 11 Enterprise rights, deeper Intune and compliance | High, roughly £29-32 | | E5 | Enterprise (no cap) | Advanced security/compliance/voice needs specifically | Defender suite, Insider Risk, Advanced eDiscovery, Teams Phone | Highest, roughly £50-54 | *Approximate bands based on Microsoft's published list pricing, per user/month, at time of writing. Actual pricing depends on region, currency, agreement type (CSP, EA, direct) and any current promotions, and Microsoft revises these regularly, treat this table as directional, not a quote. #### The licensing mistakes that actually drive overspend Most Microsoft 365 overspend we find during a licensing review doesn't come from picking the "wrong" tier at the outset. It comes from what happens to that decision over the following one to three years, while headcount, roles and risk all change and the licensing assignment doesn't keep up. ##### Shelfware This is the single most common and easiest issue to find: licences still assigned to disabled accounts, leavers who were offboarded from email but never unlicensed, or shared mailboxes and service accounts sitting on a full user licence they don't need. On any tenant we review that hasn't had a recent audit, this is where we look first, and it's rarely a small number. ##### Over-licensing This is paying for E5, or Business Premium's full security stack, on roles that will never use most of what it adds. It's not wrong to standardise a tier across a team for simplicity, but it's worth being honest about whether that's a deliberate trade-off (simplicity is worth the extra spend) or an assumption nobody's tested (we've always given everyone E5, so we still do). ##### Under-licensing This is the mirror image and the one that's easy to miss because it doesn't show up as a cost until something goes wrong: a finance or HR role on Business Basic with no conditional access, no managed device policy and no advanced threat protection, handling exactly the kind of data an account compromise would be most damaging to lose. The licence itself looks cheaper. The incident it doesn't prevent almost never is. ##### Inconsistent tier assignment across a growing team This is what happens when the first three problems compound: new starters get whatever tier IT had spare capacity for at the time, promotions and role changes don't trigger a licensing review, and eighteen months later nobody can explain why two people doing the same job are on different tiers with different security postures. None of this is negligence, it's what happens by default when licensing is treated as a one-off setup task rather than something that needs revisiting as the business changes. #### Picking a tier vs keeping it under control Everything above answers one question: which tier fits which role, right now. That's a real decision and worth getting right, but it's a different problem from keeping licensing right over time as your team grows, roles change and Microsoft itself revises what each tier includes. A one-off licensing review fixes the picture on the day it happens; it doesn't stop shelfware or inconsistent assignment creeping back in six months later, which is exactly what tends to happen without someone actively watching for it. That ongoing piece is what our licensing and cost management service is built for: not a single audit, but continuous oversight of tier assignment, shelfware and renewal timing, so the gap between what you're paying for and what you're actually using stays closed rather than reopening every time someone joins, leaves or changes role. If the immediate question is a broader Microsoft 365 tenant setup or governance project rather than ongoing cost control specifically, our Microsoft 365 services cover migration, governance and Intune configuration directly. And if Azure spend is part of the same conversation as your licensing, our cost optimisation team looks at both together, since the two are usually reviewed at the same time in practice. #### How to decide Start with headcount and complexity: under 300 seats with straightforward needs, the Business tiers cover almost everyone, and Business Premium is worth the step up from Standard for any role touching sensitive data. Above 300 seats, or with specific enterprise compliance or device management requirements, E3 is the natural baseline. From there, only add E5 where a specific capability in it, advanced threat protection, Insider Risk Management, Advanced eDiscovery, Teams Phone, is something you'd actually use, not because it's the most complete tier on the page. Treat Copilot as a separate decision layered on top, sized to genuine use cases rather than headcount. And whichever combination you land on, put a date in the diary to check it again, because the tier that's right today is rarely the tier that's still right in two years without anyone looking. If your desktop and device strategy is the next question alongside licensing, our AVD vs Windows 365 vs traditional desktops comparison covers that decision in the same straight, neutral way. For further reading on the tiers themselves, Microsoft's own plans for Enterprise page and its security and compliance licensing guidance are worth reading directly, along with the Copilot for Microsoft 365 overview if you're weighing that decision too. #### Frequently asked questions **What's the difference between Business Premium and E3?** Business Premium is capped at 300 users and built for SMBs: it adds Defender for Business, Intune device management, Autopilot and conditional access on top of the full desktop Office apps, at a fraction of E3's cost. Microsoft 365 E3 has no seat cap, adds Windows 11 Enterprise upgrade rights and a deeper set of Intune and compliance capabilities aimed at larger, more complex estates, but its baseline security add-ons aren't as complete as Business Premium's out of the box. For a business under 300 seats, Business Premium usually covers the same practical security ground as E3 for meaningfully less per user; the main reasons to move to E3 are outgrowing the 300-seat cap or needing specific enterprise-only compliance or device management features Business Premium doesn't include. For scale, Microsoft's published list pricing puts Business Premium at roughly £19-21 per user per month against about £29-32 for E3, bands that vary by region, currency and agreement type and are worth confirming for your own tenant. **Do I need E5 for security?** Almost never as a first step, and often not at all. E5's security value is real, Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps and advanced compliance tooling are genuinely strong, but most businesses get more security improvement per pound spent by properly configuring what Business Premium or E3 already includes: conditional access, MFA everywhere, Defender for Business or Defender for Endpoint, and a real oversharing review. E5 earns its cost when a specific capability it adds is something you'd actually use and can't get any other way, not as a blanket upgrade because it's the top tier and sounds safer. The gap is material at list pricing: E5 sits at roughly £50-54 per user per month against about £29-32 for E3, so rolling it across a whole team is one of the larger single lines on a Microsoft bill. Insider Risk Management, Advanced eDiscovery and Teams Phone are the capabilities most likely to justify that, if you'd genuinely use them. **Can I mix licence tiers across my team?** Yes, and for most businesses beyond a handful of people, you should. Assigning every user the same tier regardless of role is one of the most common sources of overspend on one end (paying for E5 features a receptionist never touches) and under-protection on the other (a finance director on Business Basic with no advanced threat protection). Frontline or shift-based staff who only need core Teams and Outlook access are often better suited to F3 than a full desk-based licence. The only real constraint is keeping the mix deliberate and documented, based on what each role actually needs, rather than whatever tier someone happened to be assigned when they joined. F3 shows the size of the prize: at list pricing it sits around £7-8 per user per month against about £29-32 for E3. It deliberately leaves out the desktop Office apps, though, so it only suits roles that genuinely work out of Teams, Outlook and SharePoint rather than spending their day in Word and Excel. **How much does Microsoft 365 Copilot cost on top?** It's sold as a per-user, per-month add-on on top of an existing qualifying Microsoft 365 licence, and Microsoft has adjusted its packaging, eligibility and pricing more than once over the past couple of years, so a specific figure printed here would likely be wrong by the time you read it. What matters more for planning is the shape of the cost: it's flat per seat regardless of how much that person actually uses it, so the return depends entirely on concentrating licences on people with a genuine, frequent use case rather than spreading them thinly across the whole business. Check your current Microsoft 365 agreement for the live price and eligibility before committing to seat numbers. It also sits on top of a qualifying Microsoft 365 licence rather than replacing one, so the base tier decision comes first and stays separate. And if data hygiene and access control are unresolved, sorting those out before you buy seats matters more than the price does. **How do I stop paying for licences nobody uses?** Start with a straightforward audit: cross-reference assigned licences against active sign-ins over the last 60-90 days, and against your leavers list, shelfware (licences left on disabled or departed accounts) is usually the single biggest and easiest win to reclaim. After that, check whether anyone's on a higher tier than their role justifies, and whether anyone's missing security features their role genuinely needs. Shared mailboxes and service accounts sitting on a full user licence belong in that same first sweep, since they rarely need one and rarely get checked. The harder part isn't finding the waste once, it's stopping it from creeping back in after every starter, leaver and promotion, which is a process problem more than a one-off clean-up. Building the check into your starter and leaver steps, and doing one deliberate pass before each renewal date, is what keeps the gap closed rather than reopening it every few months. ### Cyber Essentials vs Cyber Essentials Plus: which one do you need? URL: https://systechitsolutions.co.uk/compare/cyber-essentials-vs-cyber-essentials-plus Same five controls, two very different levels of proof. What each certification verifies, what it costs, and which one your contracts require. Category: Security & Compliance | Last updated: 2026-08-19 Two certifications, one scheme, and a surprising amount of confusion between them. Cyber Essentials and Cyber Essentials Plus cover exactly the same five technical controls, which is why the names sit so close together, and yet they cost different amounts, take different lengths of time, and prove genuinely different things to the customer asking for them. Picking the wrong one is an expensive way to learn the difference. In short: Cyber Essentials and Cyber Essentials Plus assess the same five controls: firewalls, secure configuration, security update management, user access control and malware protection. Cyber Essentials is a self-assessment questionnaire, signed off by a director and reviewed by a certification body. Cyber Essentials Plus keeps that questionnaire and adds an independent hands-on technical audit, where an assessor scans a sample of your real devices to verify the answers. You must hold Cyber Essentials before Plus, awarded within the previous three months. Choose based on what your contracts specify: where a buyer asks for Plus, self-assessment will not satisfy it. This guide is written for businesses that have been asked for one of these by a customer, an insurer or a tender, and need to work out what is actually involved before committing budget to it. It covers what each certification verifies, what the five controls require in practice, where the real effort goes, and how to decide which level you need. #### The two certifications, in plain terms ##### Cyber Essentials Cyber Essentials is the UK government-backed baseline, overseen by the National Cyber Security Centre and delivered through IASME as the scheme's accreditation body. You complete a self-assessment questionnaire covering the five control themes, a board-level director signs a declaration confirming the answers are accurate, and a certification body reviews and marks the submission. The key characteristic is that it is an assertion. No external party logs into your systems, scans a device or inspects a configuration. The certification body checks that your answers are coherent, complete and consistent with the scheme requirements, and can query or reject a submission that is not. But the underlying facts are the ones you have supplied about your own estate. That is not a criticism of the scheme. A baseline that most organisations can realistically reach does more good across the economy than a rigorous one that few attempt, and the five controls genuinely do block the large majority of commodity internet attacks. It simply means everyone should be clear about what the badge represents. ##### Cyber Essentials Plus Cyber Essentials Plus starts from exactly the same questionnaire and adds independent verification. An assessor from a certification body conducts a hands-on technical audit: vulnerability scans against a representative sample of your devices, tests that malware protection actually blocks what it should, and checks that email filtering behaves as described. The sample is chosen by the assessor, not by you. Because the audit tests the estate described in the self-assessment, you must already hold a valid Cyber Essentials certificate, awarded within the previous three months, before the Plus audit can proceed. The two are sequential stages, not alternatives. "The controls are identical. What you are buying with Plus is not more security, it is independent proof that the security you already claimed is genuinely there." #### The five controls, and what each actually requires The five control themes are the same at both levels, so the remediation work is the same regardless of which certification you are heading for. This is the part most businesses underestimate, because it is where the real effort lives. ##### Firewalls Every device must sit behind a correctly configured firewall, and that includes the software firewall on laptops that leave the office and connect from homes, hotels and client sites. Boundary firewalls need default administrative passwords changed, administrative interfaces unreachable from the internet, and any inbound rule justified and documented. Unjustified open ports are one of the most common findings. ##### Secure configuration Devices and software ship configured for ease of setup rather than security, and the control is about undoing that. Remove or disable unnecessary accounts, software and services; change every default password; and disable auto-run behaviour that executes code without the user choosing to. On a mature Microsoft estate a good deal of this is handled through Intune configuration profiles rather than device by device, which is why centrally managed estates certify so much faster than unmanaged ones. ##### Security update management All software must be supported by its vendor and still receiving security updates, and high-risk or critical updates must be applied within 14 days of release. Two things fail this control repeatedly: an operating system that has passed end of support and is still in service, and a patching process that covers Windows well but leaves third-party applications, browsers, PDF readers and line-of-business software to drift. Unsupported software in scope is a hard fail rather than an observation. ##### User access control Accounts must be created through an approved process, reviewed, and removed promptly when someone leaves. Administrative privilege must be granted deliberately and used only for administrative tasks, which in practice means day-to-day work does not happen in an admin account. Multi-factor authentication is required on cloud services. Leavers who still have active accounts and users with permanent local administrator rights are the two findings that come up most. ##### Malware protection Devices need anti-malware protection that is active and updating, or an equivalent approach such as application allow-listing where that suits the estate better. For most Microsoft-centric businesses this is Defender, correctly configured and actually reporting, rather than installed and forgotten. #### What Cyber Essentials Plus tests that Cyber Essentials does not The Plus audit is not a paperwork review. The assessor works against a sample of live devices and looks for the gap between what the questionnaire claimed and what the estate does. Vulnerability scanning is the core of it: authenticated scans against sampled devices to identify missing patches and unsupported software. Because the standard is that high-risk and critical updates are applied within 14 days, a device that is three months behind will be found, regardless of what the patching policy says on paper. Malware protection is tested rather than assumed, confirming that protection is present, active and behaves correctly. Email and web filtering are checked to see whether malicious content is handled the way the self-assessment described. The sample matters. The assessor selects which devices to test, so an estate where most machines are well managed and a handful are not cannot rely on the good ones being chosen. This is the single biggest practical difference between the two certifications, and the reason Plus is worth meaningfully more to a buyer. #### The full comparison | | Cyber Essentials | Cyber Essentials Plus | | --- | --- | --- | | Assessment method | Self-assessment questionnaire | Self-assessment plus hands-on technical audit | | Who verifies the answers | Certification body reviews the submission | Independent assessor tests real devices | | Technical testing | None | Vulnerability scans, malware and email filtering tests | | Prerequisite | None | Valid Cyber Essentials awarded in the previous 3 months | | Control themes covered | All five | All five, identical | | Device sampling | Not applicable | Assessor chooses the sample | | Relative effort | Lower, concentrated in remediation | Higher, remediation plus audit readiness | | Relative cost | Lower | Higher | | What it proves to a buyer | You have asserted the controls are in place | The controls were independently verified as working | #### Which one do you actually need? Start with the contract wording, not with a general sense of which sounds better. Where a tender or customer agreement specifies Cyber Essentials, base-level certification satisfies it. Where it specifies Plus, only the audited version does, and certifying at the wrong level means paying twice. Beyond contractual requirements, the question is what the certificate is for. If it exists to satisfy a procurement checkbox and give you a structured reason to fix the basics, Cyber Essentials does that job well and is the sensible starting point for most businesses that have never certified. If it exists to give a customer genuine assurance, particularly where you handle their data or connect to their systems, Plus is what carries weight, because it is the version that survives the question "but did anyone check?" There is also a sequencing argument worth taking seriously. Because Plus requires a Cyber Essentials certificate awarded within the previous three months, a business that expects to need Plus eventually is better off treating both as one project. Close the gaps once, certify, then move to the audit while the estate still matches what you described. Splitting them a year apart means doing the self-assessment twice. #### Where businesses actually lose time Almost none of the effort is in the questionnaire. It is in the estate. The most common delay is discovering nobody has a reliable inventory of what is connected. You cannot answer questions about patching, malware protection or supported operating systems for devices you have not enumerated, and building that picture from scratch is often the longest single task in the project. The second is unsupported software still in service, which is a hard fail rather than something to explain around. An old operating system, a line-of-business application pinned to a version that requires it, or a server that everyone knows about and nobody owns will each stop certification until resolved. Where the blocker is a legacy application rather than the operating system beneath it, application modernisation or MSIX packaging can move the application forward onto a supported platform without a rewrite. The third is scope confusion, particularly around cloud services and personal devices. Microsoft 365 and Azure are in scope where they hold organisational data. Personal devices used for organisational work are generally in scope too. Businesses that assume otherwise tend to find out late, when the questionnaire asks a question they cannot answer. #### How we approach it We run this as a gap assessment first, because the questionnaire is not the work. We establish what is actually in the estate, test each of the five control themes against what the scheme requires, and produce a list of what needs to change before certification is realistic. Where the remediation is Microsoft-centric, which it usually is, the fixes sit in ground we already manage: identity and MFA in Entra ID, device configuration and patch compliance through Intune, and Defender for malware protection. ##### Which level, and what happens after the gap assessment From there the route depends on the answer you need. - **If Cyber Essentials satisfies your contracts**, we close the gaps and take you through the self-assessment. - **If you need Plus**, we plan both stages inside the three-month window, so the audit lands while the estate still matches the submission. We run our own vulnerability scan against a representative sample first, so the assessor's findings are not the first time anyone has looked. ##### Related reading Our Cyber Essentials readiness checklist walks through the five control themes and what assessors look for, and our Cyber Essentials in 30 days write-up covers what a compressed timeline realistically involves. If certification is a supply-chain requirement rather than a one-off, our compliance packs cover the policies and evidence that sit alongside it, and the cyber security service page explains the underlying controls we manage day to day. We work with businesses across Yorkshire and the UK from our base in Brough, East Yorkshire, including Hull, Leeds, Sheffield and York, and you can see the full coverage area if you are elsewhere in the county. If you would rather talk it through before committing to a level, get in touch and we will tell you which one your contracts actually need. #### Frequently asked questions **What is the actual difference between Cyber Essentials and Cyber Essentials Plus?** The controls are identical. The difference is entirely in how they are proved. Cyber Essentials is a self-assessment: you answer a questionnaire about your own estate, a board-level director signs a declaration that the answers are true, and a certification body reviews the submission. Nobody from outside your organisation logs into anything or scans a device. Cyber Essentials Plus keeps that questionnaire as its foundation and then adds an independent technical audit on top, where an assessor tests a sample of your actual devices to confirm the answers hold up in practice. So Cyber Essentials tells a customer you have said the five controls are in place. Cyber Essentials Plus tells them somebody independent checked. That distinction is the entire value gap, and it is why the two certifications are priced and treated so differently in procurement, despite covering exactly the same technical ground. **Do I need Cyber Essentials before I can get Cyber Essentials Plus?** Yes, and the timing matters more than most businesses expect. You must hold a valid Cyber Essentials certificate before the Plus audit, and that certificate must have been awarded within the previous three months. This catches people out: a business that certified at Cyber Essentials in January and decides in September that a contract now requires Plus cannot simply book the audit, because the three-month window has closed and the self-assessment has to be redone first. If you already know Plus is where you need to end up, the sensible approach is to treat them as one project with two stages rather than two separate exercises a year apart. Close the gaps once, certify at Cyber Essentials, then move to the Plus audit inside the window while the estate is still in the state you just described on the questionnaire. **What are the five Cyber Essentials controls?** Firewalls, secure configuration, security update management, user access control, and malware protection. Firewalls covers the boundary between your network and the internet, including the software firewall on devices that leave the office. Secure configuration means removing the things that ship enabled by default and are not needed: default passwords, unnecessary accounts, unused software and services. Security update management requires that software is supported by its vendor and that high-risk and critical patches are applied within 14 days of release. User access control covers how accounts are created, reviewed and removed, and requires that administrative privilege is granted deliberately rather than by habit, with multi-factor authentication on cloud services. Malware protection requires anti-malware on devices, or an equivalent approach such as application allow-listing. The list has been stable for years; what changes between scheme versions is the detail of how each one is interpreted, particularly around cloud services and personal devices. **How long does Cyber Essentials take, and how long does Plus add?** The assessment itself is quick. The remediation before it is what takes the time, and it varies enormously depending on where you are starting. A business with a well-managed Microsoft 365 tenant, centrally managed devices, MFA already deployed and a working patch process can often complete the Cyber Essentials questionnaire in a matter of days. A business with unmanaged laptops, no device inventory, local administrator rights everywhere and an unsupported operating system still in service can spend a couple of months on remediation before the questionnaire is worth submitting. Cyber Essentials Plus then adds the audit itself, which is usually a day or two of assessor time depending on estate size, plus scheduling. The honest planning assumption is that the paperwork is never the bottleneck and the device estate always is, so start by finding out what you actually have. **Which one do our customers or contracts actually require?** Read the wording, because the two are not interchangeable and vague summaries cause real problems. UK central government contracts involving handling personal information or providing certain ICT services have required Cyber Essentials for years, and some specify Plus. Where a contract says Cyber Essentials without qualification, base-level certification satisfies it. Where it says Cyber Essentials Plus, only the audited version does, and no amount of self-assessment will substitute. In private-sector supply chains the requirement increasingly arrives through a customer's own procurement or insurance obligations rather than regulation, which means the wording is less standardised and worth checking carefully. If a tender is ambiguous, ask the buyer directly before you spend money, since the cost difference between the two is significant and certifying at the wrong level is an expensive way to discover the distinction. **Does Cyber Essentials cover cloud services like Microsoft 365?** Yes, and this is one of the most commonly misunderstood parts of the scheme. Cloud services you use to hold organisational data or run organisational services are in scope, which for most businesses means Microsoft 365 and Azure sit squarely inside the assessment boundary rather than outside it. That has practical consequences: multi-factor authentication on cloud accounts, sensible administrative role assignment in Entra ID, and control over how data is shared externally all become things you have to be able to evidence. Businesses sometimes assume that because a service is managed by Microsoft, its security is Microsoft's responsibility and therefore out of scope. The scheme takes the opposite view. Microsoft secures the platform; how you configure identity, access and sharing within it is yours, and that configuration is what the assessment asks about. **What happens if we fail the Cyber Essentials Plus audit?** It is not usually terminal, but the rules around retesting are time-bound. Where the assessor finds issues during the audit, there is normally a short window to fix them and be retested rather than starting the whole process again, provided the problems are remediable rather than fundamental. What causes a genuine restart is discovering during the audit that the estate does not resemble what the self-assessment described, for example unsupported operating systems still in service that were not declared, or devices nobody knew existed. The practical lesson is that the Plus audit is not the place to find out what is on your network. Run your own vulnerability scan against a representative sample of devices before the assessor does, confirm every device is on a supported and patched operating system, and check that malware protection and email filtering behave as you believe they do. ### MSP vs internal IT: replace, supplement or co-manage URL: https://systechitsolutions.co.uk/compare/msp-vs-internal-it You already have someone doing IT. Should a provider replace them, work alongside them, or stay out of it? The three arrangements, compared honestly. Category: Managed IT | Last updated: 2026-08-19 Most comparisons of managed IT and in-house IT assume you are starting from nothing. Plenty of businesses are not. There is already someone doing IT, formally or otherwise, and the real question is not "which model should we adopt" but "what happens to the arrangement we already have". In short: There are three honest options when internal IT already exists. Replace makes sense when the role is a single point of failure the business can no longer carry, or when the estate has outgrown what the role was designed for. Supplement (co-managed) is the most common outcome and usually the best value: the internal person keeps the business knowledge and user relationships, the provider takes monitoring, patching, out-of-hours cover and specialist depth. Neither is a legitimate answer if the current arrangement is genuinely covering the estate and nothing is being deferred. The deciding factor is rarely cost. It is almost always coverage and breadth. If you are choosing a support model from scratch rather than deciding what to do with an existing one, the underlying cost and coverage comparison is set out in managed IT vs in-house IT vs break-fix. This guide picks up where that one leaves off. #### What an internal IT person actually gives you It is worth being precise about this, because it is the part that is easiest to undervalue when a provider is quoting and easiest to overvalue when the incumbent is well liked. An internal person holds context. They know that the finance system has to be up before the month-end run, that the warehouse team cannot be interrupted between certain hours, that a particular integration was built by a supplier who has since gone quiet, and that the reason a server is still running is a licence nobody can replace. None of that is written down anywhere, and none of it can be acquired by an external provider quickly, or in some cases at all. They are also present. A person who sits in the building notices that a team has quietly started working around a problem instead of reporting it. That is a genuinely different signal from a ticket queue, and no amount of monitoring replaces it. What they cannot do is be in two places at once, be current in six specialisms simultaneously, or be available while asleep, ill or on leave. Those are structural limits rather than performance ones, and they do not improve with a better hire. #### What a managed provider actually gives you A provider brings breadth and continuity. The breadth is the part most businesses underestimate: security, identity, cloud infrastructure, networking, backup and compliance each move fast enough that staying current in one is a real commitment. A provider spreads that cost across many clients, so you get access to people who are current in each rather than one person doing their best across all of them. The continuity is less obvious but often matters more. Monitoring runs whether anyone is in the building or not, patching happens on a schedule rather than when someone gets to it, and cover does not disappear because one person booked a fortnight in Spain. It is the difference between IT being attended to and IT being attended to by someone specific. What a provider cannot do is know your business the way somebody inside it does, and any provider claiming otherwise in a first meeting is overselling. "The question worth asking is not whether your internal person is good. It is what happens to the estate during the fortnight they are away, and whether the answer to that is acceptable." #### The three options at a glance - **Replace.** The role is a single point of failure the business cannot carry, or was never really an IT role. - **Supplement (co-managed).** The internal person keeps context and relationships; the provider takes monitoring, patching and out-of-hours. - **Neither.** The estate is genuinely covered today and nothing is being deferred. #### Option one: replace Replacing an internal role with a provider is the least common of the three and works in a narrower set of circumstances than providers tend to suggest. It genuinely fits when the role has become a single point of failure the business cannot carry, and the estate is standard enough that the institutional knowledge is recoverable through documentation rather than irreplaceable. A business running almost entirely in Microsoft 365, with cloud-hosted line-of-business applications and no unusual infrastructure, has less unwritten context to lose than a manufacturer with a production network and twenty years of accumulated decisions. It also fits when the role was never really an IT role. Plenty of small businesses have an office manager, a finance lead or a technically confident director who absorbed IT because someone had to. That is not a job anyone designed, it is usually costing the business the work that person was actually hired for, and handing it to a provider is straightforwardly better for everyone including them. The risk to plan for is knowledge transfer. If you are replacing rather than supplementing, the handover period is the whole game, and it needs to be measured in weeks with documentation as a deliverable, not a final-week conversation. #### Option two: supplement, or co-managed IT This is where most businesses with existing internal IT end up, and generally for good reasons. The division that works is roughly this. The internal person keeps what benefits from presence and context: day-to-day user support, business priorities, vendor and supplier relationships, project ownership, and being the person who decides what matters this quarter. The provider takes what benefits from scale and continuity: 24/7 monitoring, patch management, security tooling and response, backup verification, out-of-hours cover, and the specialist work that comes up a few times a year and has to be right. Done well, the internal role usually gets better rather than smaller. The week stops being consumed by patching, backup checks and password resets, and starts including the projects that were permanently deferred because there was never a clear fortnight. The failure mode is specific and worth naming: both sides assuming the other is watching something. It is entirely preventable, and the prevention is a written responsibility matrix agreed at the start covering who owns monitoring, who owns patching, who responds out of hours, who holds the tenant's privileged accounts, and who is accountable when something falls between the two. If a provider will not produce one, that tells you something. #### Option three: neither, for now Not every business with internal IT needs a provider, and it is worth stating plainly because almost nobody selling managed services will. If your internal arrangement is genuinely covering the estate, if patching is happening on a schedule, backups are being tested rather than assumed, security tooling is in place and current, out-of-hours risk is understood and accepted, and nothing significant is being permanently deferred, then the honest answer is that you do not currently have a problem that a provider solves. The reason this is worth checking rather than assuming is that most of those things fail quietly. Nobody notices that backups have not been restore-tested until the restore matters. The useful exercise is not a sales conversation but an audit. When was the last successful test restore? What is the current patch compliance figure across devices? What happens at 2am? And what has been on the "when we get time" list for more than six months? If those answers are comfortable, wait. #### The full comparison | | Replace | Supplement (co-managed) | Neither | | --- | --- | --- | --- | | Institutional knowledge | At risk, needs formal transfer | Retained internally | Retained internally | | Coverage outside working hours | Provider's defined hours | Provider's defined hours | Unmanaged gap | | Specialist breadth | Provider's bench | Provider's bench | Limited to the individual | | Single point of failure | Removed | Removed | Present | | Cost shape | Contract replaces salary | Salary plus contract | Salary only | | Best suited to | Standard estates, or where the role was never really an IT role | Most businesses with existing internal IT | Estates genuinely well covered today | | Main risk | Losing context that was never written down | Unclear split of responsibility | Quiet failures nobody is watching for | #### How to work out which one you are Four questions, answered honestly, usually settle it. **What happens during a fortnight's leave?** If the answer is "things wait", you have a coverage problem, and it is the most common reason businesses move. If the answer is "nothing, it is covered", ask who is doing the covering and whether they agreed to it. **How much is being deferred?** Every internal IT function has a list of things that would be good to do. If that list has not moved in a year, capacity is the constraint, and supplementing addresses it directly. **How many specialisms does the estate actually demand?** Count them honestly: identity, endpoint security, network, backup, cloud infrastructure, compliance, and the line-of-business applications. If the number is above three or four and one person is covering all of them, breadth is the constraint. **What is written down?** If the answer is very little, that is an argument for supplementing before replacing, because the handover risk in a replacement is proportional to how much only lives in one person's head. #### Where Systech fits We work in all three of these arrangements and are straightforward about which one we think fits. Co-managed is the most common shape of our work with businesses that already have internal IT, and it is usually what we recommend, because it keeps the thing that is genuinely hard to buy, the knowledge of your business, in your business. We are also clear about our own limits. If what you actually want is somebody physically present most days handling desk-side requests as they arise, an internal hire will serve you better than we will. Where we are a strong fit is Microsoft cloud, identity, security and well-run managed support behind whoever holds the relationship internally. Our published starting price and what sits inside it are on the pricing page, and the underlying support models are compared in full in managed IT vs in-house IT vs break-fix. If you are still working out what kind of provider you are shopping for, MSP vs CSP vs MSSP is the shorter read. #### Frequently asked questions **Does using an MSP mean making our IT person redundant?** It shouldn't, and in most arrangements it doesn't. The co-managed model exists precisely because the two roles are complementary rather than competing: an internal person holds the institutional knowledge a provider cannot hold from outside, the priorities, the vendor relationships, the reasons things are set up the way they are, while the provider carries the 24/7 monitoring, patching, out-of-hours cover and specialist depth that no single hire sustains across security, cloud, networking and compliance at once. Where roles do change, it is usually the shape of the job rather than its existence: the person stops spending their week on password resets and patching and starts owning projects, vendors and internal priorities. If a provider's first proposal is to replace your internal person entirely, ask them specifically what happens to the knowledge that person holds, and how they plan to acquire it. **At what point does one internal IT person stop being enough?** Usually not at a headcount, but at a breadth threshold. A capable generalist covers a surprising amount until the estate starts demanding genuine specialism in several directions at once. Security, cloud infrastructure, networking, identity, compliance and day-to-day service desk volume are each deep enough to be a career on their own, and the point where one person can no longer be current in all of them arrives well before the point where the business could justify hiring a second, third and fourth specialist. The other common trigger is coverage rather than skill: the moment the business genuinely cannot tolerate IT being unavailable during annual leave, illness or outside working hours, one person has become a single point of failure regardless of how good they are. **What is co-managed IT?** An arrangement where an internal IT person or small team and an external provider divide responsibility for one estate deliberately, rather than one covering for the other's absence. In practice the internal side usually keeps user-facing support, business priorities, vendor relationships and project ownership, while the provider takes monitoring, patching, security tooling, out-of-hours cover and the specialist work that comes up occasionally but has to be right when it does. The important part is that the split is written down. Co-managed arrangements fail when both sides assume the other is watching something, and that failure mode is entirely preventable by agreeing a responsibility matrix at the start rather than after the first incident. **Is a managed provider cheaper than hiring someone internally?** It depends on what you need covered, and comparing a salary against a monthly contract is the wrong comparison. A salary buys one person's working hours, one person's skill set, and nothing during their annual leave, illness or notice period. It also carries costs that sit outside the base figure: recruitment, training, tooling, and the coverage gap while the role is vacant. A managed contract buys defined coverage hours and access to a wider bench, spread across many clients. The honest question is not which is cheaper but what each leaves uncovered for a similar spend, and for many businesses the answer that actually fits is neither alone but a smaller internal role alongside a provider. **We have an IT person who is very good. Why would we bring in a provider at all?** Often for the things that are structurally impossible for one person rather than anything to do with their ability. One person cannot be awake at 3am, on holiday and in a meeting simultaneously. One person cannot be current across security, cloud, identity, networking and compliance as all five move. And one person is a single point of failure for institutional knowledge, which becomes acute the moment they hand in notice. A provider alongside them removes those structural limits without removing the thing that makes them valuable. If none of those limits is currently causing you a problem, that is a legitimate reason to wait. ### IT outsourcing vs managed services: what the difference actually is URL: https://systechitsolutions.co.uk/compare/it-outsourcing-vs-managed-services The terms are used interchangeably and mean different things. What each one buys, how the contracts differ, and which one you are actually shopping for. Category: Managed IT | Last updated: 2026-08-19 These two phrases are used as though they mean the same thing, including by people selling both. They do not, and the difference is not academic: it determines who is responsible when something is not done, which is exactly the thing you are trying to settle when you buy either. In short: Traditional IT outsourcing buys capacity. You hand over work, direct how it is done, and pay against time or headcount. Responsibility for the outcome stays with you. A managed service buys an outcome. The provider takes responsibility for a defined function being in an agreed state, brings its own tooling and process, and is measured on that state rather than on hours. Managed services are a subset of outsourcing, not an alternative to it. The practical test is simple: if you decide how the work gets done, it is outsourcing in the traditional sense; if the provider does, within an outcome you agreed, it is managed. #### Why the confusion exists Partly because managed services genuinely are a form of outsourcing, so both labels are accurate at once. And partly because "outsourcing" acquired a reputation, largely from offshore call centre and back-office arrangements in the 2000s, that the industry then spent twenty years relabelling its way out of. "Managed services" arrived as the newer, better-regarded phrase, and plenty of providers applied it to arrangements that had not changed. That history matters when you are reading proposals, because the word alone tells you almost nothing. What tells you something is the answer to three questions: who owns the process, what is the provider measured on, and what happens when something nobody asked about goes wrong. #### Who owns the process This is the clearest dividing line. Under traditional outsourcing, you own the process. The provider works to your standards, uses your ticketing system, follows your escalation paths, and does what your managers direct. That is genuinely valuable when the work is specific to your business, when you already have a way of doing things that works, or when regulatory constraints mean the process cannot simply be handed over. Under a managed service, the provider owns the process. They bring their own monitoring platform, their own patching schedule, their own security tooling and their own runbooks, and the reason that is worth having is that those things are the product of doing it across many estates rather than one. You give up some control over the how, and what you get back is not having to design, maintain and staff the how yourself. Neither is better in the abstract. The mistake is buying one while expecting the other, which is where most disappointment in this market comes from. #### What the provider is measured on Traditional outsourcing is measured on delivery: hours worked, tickets closed, people supplied, projects completed. It is a straightforward relationship and easy to audit, and its limitation is that it only measures what was asked for. A managed service is measured on state. Is the estate patched to the agreed level. Are backups restoring when tested. Is the monitoring coverage complete. Were incidents responded to within the agreed hours. That is a harder thing to specify, which is why the contract matters more, and it is also the thing that catches the work nobody thought to request. "Under a time-based arrangement, everything that nobody asked for competes for budget with everything that somebody did. Patching, backup testing and security maintenance lose that competition almost every time, right up until they matter enormously." #### Where the cost sits Traditional outsourcing prices against time or headcount. Cost tracks demand, which is transparent and fair, and it means a busy quarter is an expensive one. It also means the baseline maintenance work is a discretionary spend competing with visible priorities. Managed services price against the size of the estate, usually per user or per device per month. That produces a predictable, budgetable figure that scales with headcount rather than with incident volume, and it moves the maintenance work from discretionary to baseline. What it does not do is make everything cheaper: a well-scoped managed contract prices the work honestly, and if a lot of work is genuinely needed, that shows up in the number. Systech publishes its own starting figure and what sits inside it on the pricing page, including which items are in the base rate and which are scoped separately, which is the distinction that actually determines whether two quotes are comparable. #### Staff augmentation, the third thing in this conversation Staff augmentation gets grouped with both and is genuinely distinct. You are adding people to your own team, under your own management, using your processes and tools. It is the purest form of buying capacity. It fits well where the work is specific to your business and you hold the design: a migration you have planned, a development project with your own architecture, a period of unusual load. It fits badly as a substitute for a managed service, because the accountability stays with you while the knowledge walks out at the end of the engagement. Many businesses run both deliberately, and that is usually the right answer rather than a compromise: managed services for the recurring operational functions, augmentation for the project work where they want to keep control of the how. #### The full comparison | | Traditional outsourcing | Managed services | Staff augmentation | | --- | --- | --- | --- | | What you buy | Capacity | An outcome | People | | Who owns the process | You | The provider | You | | Measured on | Hours, tickets, delivery | State of the estate | Time supplied | | Cost shape | Tracks demand | Predictable, tracks estate size | Tracks headcount and duration | | Tooling | Usually yours | The provider's | Usually yours | | Preventive work | Competes for budget | Baseline | Not included unless directed | | Best suited to | Work specific to your processes | Recurring operational functions | Projects where you hold the design | #### Which one you are actually shopping for Most businesses asking this question want a managed service and describe it as outsourcing, because outsourcing is the more familiar word. A useful way to check is to finish this sentence: "I want to stop having to think about ___". If the blank is a function, keeping systems patched, knowing backups work, someone watching out of hours, that is a managed service. You are trying to transfer responsibility, not hours. If the blank is a workload, we have more tickets than people, we need three developers for six months, that is outsourcing or augmentation. You are trying to add capacity to something you still intend to run. If it is both, which is common, they can be bought separately and usually should be, because bundling them tends to obscure which parts of the contract carry an accountability and which carry an hour count. #### What to ask before signing either Four questions expose the difference quickly, whatever the proposal calls itself: - **What specifically are you responsible for keeping in a particular state, and what is that state?** A managed service can answer this precisely. An outsourcing arrangement will answer in terms of activities instead, which is fine, as long as you know that is what you are buying. - **Whose tooling is this, and what happens to it if we leave?** Provider-owned tooling is normal in a managed service. What is not normal is being unable to leave with your own data and documentation. - **What is included that we have not asked for?** The preventive work is the whole value of a managed contract. If the answer is "whatever you raise", it is a support arrangement. - **What are the coverage hours and who answers within them?** A 24/7 claim can mean an engineer or an answering service that raises a ticket for the morning. The full set of questions to put to any provider, and the answers that should give you pause, is in how to choose an IT support company. If you already have someone doing IT internally and are working out how a provider would fit alongside them, MSP vs internal IT covers that decision directly. #### Frequently asked questions **Is a managed service provider the same as outsourcing?** Managed services are a form of outsourcing, but not all outsourcing is a managed service, and the distinction is about what you are buying. Traditional outsourcing buys capacity: people or hours that work to your direction, on your processes, usually billed against time or headcount. A managed service buys an outcome: the provider takes responsibility for a defined function being in a particular state, brings its own tooling and processes, and is measured against that state rather than against hours delivered. The practical test is who decides how the work gets done. If that is you, it is outsourcing in the traditional sense. If that is the provider, within an agreed outcome, it is a managed service. **What is the difference between managed services and staff augmentation?** Staff augmentation adds people to your team under your management. They use your processes and tools, attend your meetings, and are directed by your managers; you are essentially renting capacity and retaining full responsibility for how it is used. A managed service transfers responsibility for a defined outcome, along with the tooling and process to deliver it. The trade-off is control against accountability: augmentation keeps you in charge of the how, which matters when the work is genuinely specific to your business, but it also means the result remains entirely your responsibility. Many businesses use both at once, augmentation for project work where they hold the design, managed services for the recurring operational functions where they would rather buy the result. **Which is cheaper, IT outsourcing or managed services?** They price differently rather than one being reliably cheaper. Traditional outsourcing is usually billed against time or headcount, so cost scales with how much work there is and is only as predictable as your demand. Managed services are usually billed as a recurring per-user or per-device fee, so cost is predictable and scales with the size of the estate instead. Where managed services tend to win over time is on the work that never gets billed under an hourly model because nobody asked for it: patching, monitoring, backup verification and security maintenance. Under a time-based arrangement those are line items competing with everything else. Under a managed contract they are the baseline. **Can you outsource IT without a long contract?** Yes, though the terms vary a great deal and the length is usually tied to how much the provider has to invest at the start. Onboarding a managed service involves documenting an estate, deploying agents and tooling, and getting a real picture of what is there, which is genuine front-loaded work, and that tends to be reflected in the term. Project and consultancy outsourcing typically carries no ongoing term at all because it is scoped to a deliverable. What matters more than the length is what happens at the end: notice period, what becomes of your data, your tenant and your documentation, and whether you leave with a working estate or a dependency. Ask that before you sign, not after. **What does 'managed' actually mean in managed services?** It means the provider carries responsibility for a function staying in an agreed state, not just for responding when it is not. In IT specifically, that usually covers monitoring the estate continuously, applying patches on a schedule the provider owns, maintaining security tooling, verifying that backups actually restore, and responding within agreed hours when something goes wrong. The word does real work in the contract: an arrangement where you call someone and they fix things is a support arrangement, not a managed one, however good the support is. If a proposal uses the word 'managed' without listing what is being managed and to what standard, that is the question to ask. ### Buying Microsoft licences through a partner, or direct from Microsoft URL: https://systechitsolutions.co.uk/compare/buying-through-a-partner-vs-direct What a partner actually adds, what it costs you, and the cases where buying direct from Microsoft is genuinely the better answer. Category: Licensing | Last updated: 2026-08-20 Short answer: Through a partner, unless you have someone in-house who genuinely enjoys licensing. The list price is set by Microsoft and most partners sell at or near it, so the decision is rarely about price. It is about whether anyone is watching your tier mix, your unused licences and your renewal dates, because that is where the money actually goes, and nothing in the direct channel is going to tell you. #### The assumption worth testing first Almost everyone approaching this assumes a partner is a middleman taking a cut, and that going direct removes the cut. It is a reasonable assumption and it is usually wrong. Microsoft publishes list prices. A partner in the Cloud Solution Provider programme buys at a partner rate and sells to you, most often at or very near that same list price, because the customer can check it in thirty seconds and there are thousands of other partners. The margin is funded out of the gap between partner rate and list, not added to what you would otherwise pay. So price is rarely the thing that separates the two routes. What separates them is whether anybody is paying attention. #### Where the money actually goes Not to a markup. In the estates we review, the recoverable spend is almost always in three places, and none of them are visible from an invoice. - **Wrong tier.** People on E5 who need Business Premium, or on E3 when a cheaper F-series licence matches what they actually do. The invoice looks correct because the count is correct. - **Licences assigned to nobody.** Leavers, long-term absence, role changes. These bill at full rate indefinitely, and nothing in the direct channel flags it. - **Add-ons already included.** Paying separately for something a licence you already hold covers, usually because the two purchases were made by different people a year apart. "The argument about partner margin is an argument about a few per cent. The argument about tier mix and unused licences is routinely an argument about twenty or thirty. Almost nobody has the second conversation, because the first one feels like the frugal one." None of that is exotic, and none of it requires a partner to fix in principle. It requires somebody to sit down with the assignment list and the tier definitions once or twice a year. The honest question is not whether a partner adds value, it is whether that review is going to happen if nobody is being paid to do it. #### What "value added" has to mean, or it means nothing Value-added reseller is a category that includes both genuine advisory work and simply putting an invoice in the middle. Ask any prospective partner to describe what it does under each of these four headings. Vagueness under any of them is the answer. - **Tier and mix advice.** Who should be on what, reviewed as headcount and roles change, not set once at signup. - **Commercial flexibility.** Adjusting counts, splitting billing across cost centres, aligning renewal dates. The direct portal is less accommodating on all three. - **One accountable point.** A licensing question and a service problem go to the same place, rather than being two queues that each say the other owns it. - **Someone who notices.** Unused licences, an expiring term, a new SKU that would let you drop an add-on. This is the one most partners skip and the one worth most. #### When buying direct is the better answer There are real cases, and any partner unwilling to name them is selling rather than advising. - **You already have the capability in-house.** Someone who understands the licensing model, reviews assignments and is confident choosing tiers. A partner is a layer you do not need. - **Your estate is small and static.** A handful of people, one plan, nothing changing. The review that a partner earns its place with has nothing to review. - **Procurement policy favours the manufacturer.** Some organisations, particularly in the public sector, have rules about this. It is not worth fighting. - **The partner will only sell licensing bundled with a managed service you do not want.** That is a reason to go direct, not a reason to buy the service. #### How this works at Systech, and what we sell We are a Microsoft partner and we do sell licensing, so treat the section above as something to hold us to rather than as neutral commentary. Three things we would rather state plainly than have you discover. **We sell licensing and managed services separately.** You can buy licences through us with no managed contract, and you can buy a managed service with your licences somewhere else. We think the combination is usually better, because the provider managing your estate can see the licensing consequences of what it does, but it is a recommendation and not a condition. **Some of what we resell, we built.** EtherApps Forge, EtherInsights and EtherAssist come from our sister company EfficientEther, and they exist because we spent years doing this work by hand: cost attribution, posture analysis, compliance documentation and legacy application capture, all of it slow and all of it repetitive. The tooling is why a review is quick enough to be worth doing before you have decided anything, and we will still tell you where one of them is the wrong tool. **Our licensing and cost review is free and you keep the findings.** It is not a sales gate. If it concludes you are on the right tiers with no shelfware, we will tell you that, and there is nothing to sell you. #### Frequently asked questions **Is it more expensive to buy Microsoft 365 through a partner?** Usually not, and it is a fair thing to assume. Microsoft sets the list price for its subscriptions, and a partner in the Cloud Solution Provider programme buys at a partner rate and sells to you. Most partners sell at or near list, because they are competing against Microsoft's own published price and against every other partner, so a large markup is not sustainable in a market where the customer can check the list price in thirty seconds. The margin a partner earns is funded by Microsoft out of that gap, not added on top of what you would otherwise have paid. Where a partner costs you more is when the licensing advice is poor and you end up on the wrong tier, or carrying licences nobody uses. That is a much larger number than any plausible markup, and it is the thing worth interrogating. **What does a Microsoft partner actually add over buying direct?** Four things, and it is reasonable to ask for each of them specifically. Advice on tier and mix, so you are not paying E5 rates for people who need Business Premium, or buying an add-on that is already included in a licence you hold. Commercial flexibility, because a partner can usually adjust counts, split billing across cost centres and align renewal dates in ways the direct portal does not. A single accountable point when something breaks, rather than a support queue that treats a licensing question and a service outage as separate tickets. And someone who notices, because a licence assigned to a leaver bills at full rate indefinitely and nothing in the direct channel is going to flag it. If a partner cannot describe what it does under each of those headings, it is a reseller rather than a value-added one, and you are better off direct. **When is buying direct from Microsoft the better option?** When you have the in-house capability to do the licensing work yourself and no interest in delegating it. If you have someone who understands the licensing model, reviews assignments regularly, tracks renewal dates and is confident choosing between tiers, a partner is adding a layer you do not need. Buying direct is also simpler if your estate is genuinely small and static, or if your organisation has a procurement policy that favours buying from the manufacturer. And if a partner will only sell you licences as part of a bundled managed service you do not want, that is a reason to go direct rather than a reason to buy the service. **Can I move my Microsoft licences to a different partner?** Yes, and it is a normal, supported process rather than a favour. Subscriptions can be transferred between partners, and the mechanics depend on your agreement type and where you are in the term. The practical constraints are timing rather than permission: a transfer is cleanest at renewal, and an annual term part-way through may carry commitments that follow the subscription. Ask any prospective partner to explain the transfer, including what happens to your existing term, before you commit to anything. A partner who is vague about how you would leave is telling you something. **Does using a partner for licensing mean they manage my IT too?** No. They are separate decisions and it is worth keeping them separate in your own head, even when one company does both. Cloud Solution Provider describes where your subscriptions are bought and billed. A managed service describes who is responsible for your estate day to day. A business can buy licences through a partner and manage everything internally, or run a managed service while its licences sit somewhere else entirely. The combination is common and often sensible, because the provider managing your estate can see the licensing consequences of what it is doing. It should still be a choice rather than a condition. ### MSP vs CSP vs MSSP: which kind of IT provider do you need? URL: https://systechitsolutions.co.uk/compare/msp-vs-csp-vs-mssp Three acronyms, three different businesses. What a managed service provider, a cloud solution provider and a managed security service provider each do. Category: Managed IT | Last updated: 2026-08-19 Three acronyms that get used as though they are interchangeable, sometimes by the companies using them about themselves. They describe genuinely different businesses, and knowing which one you are talking to changes what you should expect from the conversation. In short: An MSP (managed service provider) takes ongoing responsibility for running your IT: monitoring, patching, endpoint protection, backup and a service desk, for a recurring fee. A CSP (Cloud Solution Provider) is a Microsoft partner programme for reselling and supporting Microsoft 365 and Azure licences; it describes a commercial licensing relationship, not a scope of work. An MSSP (managed security service provider) specialises in threat detection and response, usually with a 24/7 security operations centre. Most small and mid-sized businesses need an MSP, often one that is also a CSP, and comparatively few need a separate MSSP. #### MSP: managed service provider This is the broadest of the three and the one most businesses are actually shopping for when they start looking. An MSP contracts to keep your IT estate in a working, maintained state rather than to fix it when it stops. In practice that means continuous monitoring, a patching schedule the provider owns, managed endpoint protection, backup that is verified rather than assumed, and a service desk with defined coverage hours. The commercial model is recurring, usually per user or per device per month, which is what allows preventive work to be baseline rather than a line item competing for budget. The term carries no certification. Anyone can describe themselves as an MSP, which is why the meaningful signals are elsewhere: ISO 27001 and ISO 9001 for how the provider runs itself, Cyber Essentials for baseline security hygiene, and vendor partner status for depth in a specific stack. Systech's are listed on the certifications page, and every one of them is verifiable through a public registry rather than a logo. #### CSP: Cloud Solution Provider CSP is the one most often misunderstood, because it sounds like a category of company and is actually a programme. Microsoft's Cloud Solution Provider programme is the channel through which partners sell Microsoft 365 and Azure subscriptions. A partner in the programme handles your licensing commercially, bills you directly rather than Microsoft billing you, can adjust licence counts, and provides first-line support for the subscriptions themselves. That is a licensing and billing relationship. It says nothing about whether the partner also manages your devices, watches your estate or answers the phone at 2am. ##### Why the same company usually does both In practice the same company usually does both, and there is a genuine advantage to that: the provider managing your Microsoft estate can see the licensing implications of what it is doing, which is where a lot of avoidable overspend comes from. Licence tiers that no longer fit, duplicate products bought to solve a problem an existing licence already covered, and renewals timed badly are all easier to catch when one party sees both sides. That work is a service in its own right, and it is set out on the Microsoft licensing and cost management page. What matters when you are comparing providers is not to treat "Microsoft CSP" as a statement about managed service quality. It is a statement about where your licences are bought. "Microsoft partner status tells you a company can sell you licences and has met Microsoft's bar for doing so. It does not tell you who answers when your file server stops responding on a Sunday. Those are separate questions and worth asking separately." #### MSSP: managed security service provider An MSSP concentrates on the detection and response half of security. The characteristic capability is a security operations centre: analysts monitoring telemetry continuously, threat hunting, and a contracted response when something is found. Some run this themselves, some layer it over a vendor platform, and the difference between those two is worth establishing early. The reason most smaller businesses do not need one separately is a matter of sequence rather than value. The controls that remove the most risk at that scale are preventive and are standard MSP work: multi-factor authentication and Conditional Access on identity, managed endpoint protection, disciplined patching, email security, and backup that has actually been restore-tested. Buying continuous monitoring before those are in place produces a stream of alerts about an estate you already knew was exposed. Where a dedicated MSSP earns its place is where the risk profile genuinely warrants it: a regulatory obligation that specifies monitoring, a sector under sustained targeted attack, or an estate large enough that security has become a full-time discipline rather than an aspect of running IT well. Between the two extremes sits the common middle: an MSP delivering managed EDR and XDR with response, which is more than baseline endpoint protection and less than a dedicated SOC contract. That is what most businesses in the 15 to 250 seat range end up with, and for most of them it is the proportionate answer. Systech's version of that is on the security services page. #### The full comparison | | MSP | CSP | MSSP | | --- | --- | --- | --- | | What it is | A service model | A Microsoft partner programme | A security specialism | | Core deliverable | A maintained, monitored IT estate | Licence supply, billing and subscription support | Threat detection and response | | Typical scope | Monitoring, patching, endpoints, backup, service desk | Microsoft 365 and Azure subscriptions | SOC monitoring, threat hunting, incident response | | Commercial model | Recurring per user or per device | Margin on subscriptions | Recurring, often per endpoint or per log volume | | Certification behind the term | None inherent; look at ISO 27001, Cyber Essentials | Formal Microsoft status, verifiable | None inherent; ask what the SOC actually is | | Who typically needs it | Most businesses | Anyone buying Microsoft licences through a partner | Regulated, targeted or large estates | #### How to tell which one you are talking to Providers rarely describe themselves narrowly, so the labels on a website are a weak signal. Three questions sort it out quickly. **"What are you contracted to keep in a particular state?"** An MSP answers with a list of functions and standards. A CSP-only relationship answers in terms of subscriptions and billing. An MSSP answers in terms of detection coverage and response times. **"Who is watching, when, and what do they do when they see something?"** This separates a provider running genuine security operations from one that has deployed a security product and forwarded the alerts to your inbox. Both are legitimate offerings; they are not the same purchase. **"Where do our licences sit, and can we take them with us?"** Licensing through a partner is normal and usually beneficial. Being unable to move them without disruption is not, and it is worth establishing before rather than after. #### What most businesses actually end up buying For a business somewhere between 15 and 250 seats, the arrangement that fits is usually one provider acting as MSP and Microsoft CSP together, delivering managed security as part of the service rather than as a separate SOC contract, with specialist security services added if and when the risk profile changes. That is the shape of what Systech does. Where the security requirement genuinely exceeds what a managed service should carry, we will say so rather than stretch the label, because a provider describing itself as an MSSP on the strength of a deployed product is exactly the confusion this page exists to clear up. If you are working out whether you need a provider at all alongside existing internal IT, MSP vs internal IT covers that. If you are choosing between providers, how to choose an IT support company has the questions worth asking, and our own starting price is published on the pricing page. #### Frequently asked questions **What does MSP stand for?** Managed service provider. It describes a company that takes ongoing, contracted responsibility for some or all of a customer's IT estate, typically covering monitoring, patching, endpoint security, backup and a service desk, for a recurring fee rather than per incident. The defining characteristic is that the provider is responsible for keeping things in a particular state rather than only for responding when they are not, which is what separates a managed service provider from an IT company you call when something breaks. In UK business usage MSP almost always means this. The abbreviation is also used for Member of the Scottish Parliament, and in retail for minimum selling price, so context matters when searching. **What is the difference between an MSP and a CSP?** An MSP manages your IT; a CSP sells you cloud licences. Cloud Solution Provider is a specific Microsoft partner programme through which partners resell Microsoft 365 and Azure subscriptions, handle billing and provide first-line support for those subscriptions. It describes a commercial relationship for licensing, not a scope of managed work. The two are frequently the same company, because a provider managing your Microsoft estate is often also the partner your licences sit with, and that combination is generally convenient. They are not the same thing though: a business can buy licences through a CSP and manage everything itself, or use an MSP while its licences sit elsewhere entirely. **Do I need an MSSP as well as an MSP?** For most small and mid-sized businesses, no, because a competent MSP already includes the security controls that matter most at that scale: endpoint protection, patching, multi-factor authentication, Conditional Access, email security and backup. A managed security service provider is a specialist that concentrates on threat detection and response, typically running a security operations centre with 24/7 analysts, threat hunting and incident response. That becomes worth buying separately when you have a regulatory obligation that requires it, a threat profile that justifies continuous human monitoring, or an estate large enough that security is a full-time discipline rather than part of good IT management. The realistic question is not which acronym to hire but what level of detection and response your risk actually warrants. **Can one company be an MSP, a CSP and an MSSP?** Yes, and many are, though the depth behind each label varies enormously. Being a Microsoft Cloud Solution Provider is a formal partner status that can be verified. Being an MSP is a description of a service model with no certification attached to the term itself, though standards like ISO 27001, ISO 9001 and Cyber Essentials are meaningful proxies. 'MSSP' is the least regulated of the three, and is sometimes applied to a provider that has deployed a security product rather than one running a genuine detection and response capability. If security operations matter to you, ask specifically who is watching, at what hours, from where, and what they are contracted to do when they see something. **Which type of provider does a 50-person business usually need?** Almost always an MSP, frequently one that is also a Microsoft CSP so licensing and management sit together, and rarely a separate MSSP. At that size the security work that reduces the most risk is the work a good MSP does as standard: identity hardening, endpoint protection, patching discipline, tested backup and email security. Buying a dedicated security operations service before those fundamentals are in place tends to produce alerts about an estate that has not been secured, which is an expensive way to find out what you already knew. The exception is a business in that range carrying an unusual obligation or threat profile, where a specialist alongside the MSP is proportionate. ### How to choose an IT support company in the UK URL: https://systechitsolutions.co.uk/compare/how-to-choose-an-it-support-company The questions that separate providers, the answers that should worry you, and how to compare two quotes that are not pricing the same service. Category: Managed IT | Last updated: 2026-08-19 Every IT support company's website says broadly the same things. Responsive, proactive, trusted, UK-based, 24/7. The words are free, which is why they are all there. This guide is about the questions that are not free to answer, and what the answers tell you. In short: Price is the worst first filter, because per-user rates are only comparable once you know what sits inside them. Fix the inclusion list first, then price it with every provider. The questions that separate providers are: what is in the rate and what is billed on top, what the coverage hours are and who physically answers, where the service desk is, what certifications can be verified independently, what the exit terms are, and who will actually do the work. Providers that answer all six plainly are worth shortlisting; the ones that will not answer some of them have told you something useful. We are an IT support company, so read this accordingly. What follows is the set of questions we think buyers should ask, which we have written so that they work as well against us as against anyone else. Where we have a limitation, it is named. #### Start with the inclusion list, not the price The single most common mistake in this purchase is comparing per-user rates before establishing what a per-user rate covers. "Fully managed IT" is not a defined term. It can describe a service where endpoint protection, patching, monitored backup, 24/7 cover and firewall management are all inside the monthly figure, and it can equally describe a service desk with each of those added later as line items. Both providers will quote per user per month, both will use similar language, and the numbers will not be describing the same product. The fix is straightforward and puts you back in control of the comparison. Write down the specific list of things you want covered before speaking to anyone. At minimum: service desk with defined hours, OS and application patching, endpoint protection, backup with tested restores, identity security including multi-factor authentication, and monitoring. Then ask every provider to price that same list, and to say plainly which items they have priced as included and which as extra. Once the lists match, the numbers mean something. Our own starting figure and the exact contents of it are on the pricing page, published for the same reason: an unpublished price cannot be compared. #### The six questions ##### 1. What is inside the rate, and what is billed on top? Ask for both lists explicitly. The second list matters as much as the first, and should cover project work, on-site attendance, out-of-hours work, and user onboarding and offboarding, which is a recurring cost most businesses forget to ask about and which adds up quickly in a growing team. ##### 2. What are the coverage hours, and who answers within them? "24/7" is doing a lot of work in this market. It can mean a UK engineer who will start working on the problem, or an answering service that logs a ticket for the morning. Both may be reasonable for your risk profile. They are very different purchases, and the distinction is rarely visible on a website. Ask what happens specifically at 2am on a Sunday, and who the person answering is. ##### 3. Where is the service desk? A straightforward factual question with a straightforward answer. Offshore delivery is not inherently worse and is often what makes a low rate possible, but it should be a decision you make knowingly rather than discover during the first incident. Ours is 100% UK-based, which is part of why our rate sits where it does. ##### 4. What certifications do you hold, and can I check them? Certifications are a genuine signal, but only the verifiable ones. ISO 27001 and ISO 9001 say something about how the provider runs itself. Cyber Essentials and Cyber Essentials Plus say something about baseline security hygiene, and the difference between the two is meaningful rather than cosmetic, which we have written up in Cyber Essentials vs Cyber Essentials Plus. Microsoft partner status says something about depth in that stack. The important part is the checking. Every one of these has a public registry. A logo on a footer is not evidence, and asking for the certificate number is a reasonable request that a certified provider will answer without hesitation. Ours are listed with their registry references on the certifications page. ##### 5. What are the exit terms? Ask before signing, because the answer is much harder to get afterwards. Notice period, what happens to your data, whether you retain administrative ownership of your own Microsoft tenant, and whether the documentation of your estate leaves with you. The tenant ownership question is the one worth being firm about. Your Microsoft 365 tenant should be yours, with the provider holding delegated access to it, rather than the provider owning the tenant your business runs inside. The second arrangement is not unheard of and makes leaving substantially harder. ##### 6. Who will actually do the work? The person presenting is frequently not the person delivering. Ask who your day-to-day contact will be, what happens when they are unavailable, and how many clients a typical engineer carries. A provider stretched thin has the same capacity problem as an overloaded internal hire, just less visibly. "A provider that answers all six of these plainly, including the answers that are not flattering, is usually a better bet than one with a lower quote and a smooth response to five of them." #### Warning signs None of these is disqualifying alone. Two or three together usually are. - **The rate cannot be broken down.** If a provider will not say what is inside the number, there is a reason. - **Certifications with no registry entry.** Logos are free. - **A 24/7 claim that dissolves under a follow-up question.** Ask who is awake and where. - **Exit terms deferred until after signature.** This is the point of maximum leverage for you and they know it. - **A proposal to replace your internal IT person that does not address knowledge transfer.** The context that person holds is the hardest thing to replace, and a provider that has not thought about it has not thought about your estate. - **No price until the third meeting.** Scoping genuinely is required for a firm quote on a complex estate. A refusal to indicate any figure at all is a negotiating tactic. #### Local, regional or national This gets more weight in the decision than it usually deserves, in both directions. Physical proximity genuinely matters for a specific and fairly short list: cabling and network hardware in a new or refitted premises, switch, firewall and access point installs, comms room and server decommissioning, office moves, hands-on device rollouts, and face-to-face review meetings or workshops. For that work, a provider an hour away is meaningfully better than one four hours away. For everything else, the distance is close to irrelevant, because the work happens remotely and the person fixing it starts within seconds rather than after a drive. Microsoft 365, Azure, identity, security and device management are all delivered identically wherever the engineer sits. The honest limit of our own model, which we say on every location page: if what you want is somebody physically in your building most days handling desk-side requests as they arise, an internal hire or a provider with staff sitting in your town will serve you better than we will. We are based in Brough, near Hull, and cover Yorkshire on site and the rest of the UK remotely. #### Normalising two quotes When you have two proposals and they look close: 1. Take the cheaper quote's inclusion list as the baseline. 2. Add every item the more expensive quote includes that the cheaper one does not. 3. Ask the cheaper provider to price those additions. 4. Compare again. Very often the gap narrows sharply or reverses, because the cheaper quote was a smaller service rather than better value. Then compare the things a spreadsheet will not show: coverage hours and who answers, notice period and exit terms, where the desk is, and who is accountable when something falls between two suppliers. #### Before you start looking at all One question worth answering first, because it changes what you are shopping for: do you already have someone doing IT internally? If so, the decision is not simply which provider to hire but whether one should replace, supplement or work alongside them, and the three arrangements have very different economics. That is covered in MSP vs internal IT. If you are choosing a support model from scratch, the underlying comparison of managed IT, in-house and break-fix is in managed IT vs in-house IT vs break-fix. And if the acronyms in the proposals are the confusing part, MSP vs CSP vs MSSP is the shorter read. #### Frequently asked questions **What questions should I ask an IT support company before signing?** Six cover most of the ground. What exactly is inside the per-user rate, and what is billed on top. What are the coverage hours, and is the person answering out of hours an engineer or a service that raises a ticket for the morning. Where is the service desk physically located. What certifications do you hold, and can I verify them independently. What is the notice period, and what happens to our data, tenant access and documentation if we leave. And who specifically will be doing the work, given that the person selling is rarely the person delivering. A provider that answers all six plainly is usually worth shortlisting largely regardless of which quote is lower. **How much should IT support cost per user in the UK?** There is no single right figure, because the spread between providers reflects genuinely different inclusion lists rather than different margins on the same service. A rate that covers only a service desk and a rate that covers the desk plus endpoint protection, patching, backup and 24/7 monitoring are not comparable numbers even though both are quoted per user per month. The useful approach is to fix the inclusions first, write down the specific list of things you want covered, then ask every provider to price that same list. Systech publishes its own starting figure and exactly what sits inside it, which is the detail that makes any published price meaningful. **Should I choose a local IT support company or a national one?** It depends far more on what you run than on where the provider parks. A national provider brings scale and round-the-clock cover but accountability can be harder to pin down. A one-person local outfit is personal and affordable until they are ill or on holiday. A regional specialist sits between the two. The questions that actually matter are the same for all three: is the service desk UK-based, who picks up outside working hours, how deep does the technical expertise genuinely go, and are they certified to standards you can verify. Physical proximity earns its keep for cabling, hardware installs, office moves and face-to-face review meetings, and matters much less for everything else. **What are the warning signs when choosing an IT provider?** A refusal to say what is inside the rate is the clearest one. Others: a 24/7 claim that cannot be explained in terms of who is awake and where; certifications displayed as logos with no registry entry to check; unwillingness to state the notice period and exit terms before signing; a proposal that replaces your internal IT person without addressing what happens to the knowledge they hold; and a quote that arrives only after several meetings, which is a negotiating position rather than a scoping requirement. None of these is proof of a bad provider on its own. Two or three together usually is. **How do I compare two IT support quotes that look similar?** Normalise them before comparing. Take the cheaper quote's inclusion list, add every item the more expensive quote includes that the cheaper one does not, and ask the cheaper provider to price those additions. Very often the gap closes or reverses. Then compare the non-price terms that will not show up in a spreadsheet: coverage hours and who actually answers, response commitments, notice period and exit terms, and who is accountable when something falls between two parties. The quote that looked cheaper frequently turns out to be a different service rather than a better price for the same one. ### VM backup compared: Hornetsecurity vs Nakivo vs Veeam URL: https://systechitsolutions.co.uk/compare/vm-backup-hornetsecurity-vs-nakivo-vs-veeam Three backup products compared on hypervisor coverage, licensing model and where each genuinely wins, including the cases where Veeam is worth the money. Category: Backup & Recovery | Last updated: 2026-08-20 Veeam is the default answer in this market, which means most comparisons of it are written either by Veeam or by someone trying to displace it. We sell Hornetsecurity and Nakivo and work with Veeam estates, so what follows includes the cases where Veeam is the right answer and we would tell you to buy it. In short: Hornetsecurity VM Backup suits Hyper-V, VMware or Proxmox estates that want the fewest moving parts, and deliberately does less. Nakivo suits mixed or mid-migration estates, licensing per workload with units reassignable between types, and covering Nutanix AHV, physical machines, Oracle and EC2. Veeam does more than either, integrates with more, and has the largest pool of engineers who know it, at meaningfully higher cost and complexity. The decision is not which is best; it is whether you will use what the extra buys. #### The three, in one screen - **Hornetsecurity VM Backup.** Hyper-V, VMware, Proxmox. Simple by design. Small and mid-sized estates. - **Nakivo Backup & Replication.** Adds Nutanix AHV, physical machines, Oracle databases, EC2. Per-workload licensing, reassignable. Three editions. - **Veeam.** The broadest coverage, deepest integrations and largest ecosystem. The most expensive and the most to run. #### Hypervisor and workload coverage This is the first filter, and for some estates it is the only one that matters, because it eliminates options outright. | | Hornetsecurity VM Backup | Nakivo | Veeam | | --- | --- | --- | --- | | VMware | Yes | Yes | Yes | | Hyper-V | Yes | Yes | Yes | | Proxmox | Yes | Check current release | Check current release | | Nutanix AHV | No | Yes | Yes | | Physical machines | Limited | Yes | Yes | | Oracle database | No | Yes | Yes | | Amazon EC2 | No | Yes | Yes | Two entries in that table decide most shortlists on their own. **Nutanix AHV** removes the simpler products from consideration entirely. **Proxmox** is the newer question, and the one worth checking against current release notes rather than a comparison table, because support for it has been moving. "Check what you already own before you shop. A meaningful number of businesses looking at Proxmox assume their existing backup will not follow them, and buy something new when the product they already pay for covers it." #### Licensing, and why the rates are not comparable The most common mistake in this comparison is treating three prices as three prices. They are three different units. Nakivo licenses **per workload**: one VM, one physical machine, one Oracle database or one EC2 instance, with physical counted as one server or three workstations. Units can be reassigned between workload types during the subscription, which is genuinely useful mid-migration and is the strongest practical argument for it in a changing estate. A perpetual option exists priced per CPU socket instead. Hornetsecurity VM Backup is priced for host-based estates and aimed squarely at small and mid-sized deployments. Veeam's model varies by product and edition, and is the one most likely to need a conversation rather than a calculator. Because the units differ, the only reliable method is to count your own estate properly, then price that same estate with each. That count is also where estates discover they have been paying for decommissioned machines, or protecting fewer servers than they thought. #### Where each one genuinely wins ##### Hornetsecurity VM Backup A single-hypervisor estate that wants backup to be a solved problem rather than a project. It does less than the other two, and for a business with twenty virtual machines and no Nutanix, no Oracle and no orchestration requirement, doing less is the feature rather than the limitation. It is also the one to check first if Proxmox is in your plans. ##### Nakivo Mixed estates, and estates in motion. If you run VMware and Hyper-V together, or virtual alongside a meaningful number of physical servers, or you are partway through a migration, per-workload licensing that can be reassigned removes a real problem. Nutanix AHV support is the clearest single differentiator: if you run it, the field narrows immediately. ##### Veeam Large estates, heavily regulated environments, and anywhere backup has to integrate with something else rather than stand alone. Two advantages get undersold in comparisons written by its competitors. The ecosystem is deep, so tooling, documentation and third-party integrations exist for situations you have not met yet. And the pool of engineers who know Veeam is by far the largest, which matters when you need to hire, hand over or get help at short notice. That is an operational advantage, not a marketing one, and it is worth real money in an estate that will outlive its current administrator. #### What a comparison table will not tell you Every product here will protect your estate competently when configured properly. Every one of them will also fail you in the same three ways, none of which appear on a feature matrix. **The job that has been failing quietly.** Backup software reports errors; somebody has to read the report. The most common serious finding in an estate audit is a job that has been erroring for months. **The scope that never included the thing that mattered.** New servers get built and not added. A hypervisor gets migrated and the old job keeps running against nothing. **The restore nobody timed.** A business assuming four hours and a restore taking four days is not a backup problem, it is a planning one, and it is only ever discovered by testing. The gap between a tested backup and an assumed one is larger than the gap between any two products on this page. #### How we would advise If your estate is a single hypervisor, under about fifty virtual machines, with no Nutanix, no Oracle and no orchestration requirement, start with Hornetsecurity VM Backup and stop there. If it is mixed, in motion, or includes anything beyond virtual machines, look at Nakivo and count the workloads carefully before pricing it. If you are large, regulated, or need backup to integrate rather than operate alone, price Veeam properly rather than dismissing it on cost. There are estates where it is straightforwardly the right answer, and telling you otherwise to sell you something we resell would be a poor trade for both of us. And whichever you choose, agree a recovery point and recovery time objective with the business rather than inheriting a default, then test a restore against them. That is what our backup and disaster recovery service adds on top of the product, and it is the part that decides how the bad day actually goes. #### Frequently asked questions **What is the best alternative to Veeam?** There is no single answer, because Veeam's competitors are not trying to be Veeam. Hornetsecurity VM Backup is the alternative if your estate is Hyper-V, VMware or Proxmox and you want the fewest moving parts; it deliberately does less. Nakivo is the alternative if your estate is mixed or mid-migration, because it licenses per workload with units reassignable between types, and covers Nutanix AHV, physical machines, Oracle databases and EC2. The honest framing is not which product beats Veeam, it is whether you will use what Veeam's extra cost and complexity buy. For a lot of mid-sized estates the answer is no, and for large or heavily regulated ones it is usually yes. **Is Veeam worth the extra cost?** It depends almost entirely on scale and obligation rather than on features. Veeam does more, integrates with more, and has the deepest ecosystem and the largest pool of engineers who know it, which is a real operational advantage when you need to hire or hand over. Where that stops being worth paying for is a mid-sized estate that needs reliable backup and tested restores rather than orchestration, deep application integration and automation. Buying the most capable product and using a fraction of it is a common and expensive way to feel safe. **Which backup product supports Proxmox?** Hornetsecurity VM Backup covers Proxmox alongside Hyper-V and VMware. This matters more than it used to: VMware's licensing changes have pushed a meaningful number of businesses to evaluate Proxmox, and most assume their existing backup product will not follow them there. Check what you already own before buying something new. Veeam and Nakivo both have broad hypervisor coverage of their own, so the sensible order is to confirm your current product's support first and only then compare. **How do the licensing models differ?** They are not comparable rates, which is the single most common mistake in this comparison. Nakivo licenses per workload, where a workload is one VM, physical machine, Oracle database or EC2 instance, with physical counted as one server or three workstations, and units reassignable between types during the subscription. A perpetual option exists priced per CPU socket. Hornetsecurity VM Backup is priced for host-based estates and aimed at small and mid-sized deployments. Veeam's model varies by product and edition. Because the units differ, the only reliable comparison is to count your own estate properly and price the same estate with each. **Do any of these back up Microsoft 365?** Hornetsecurity's 365 Total Backup does, and Nakivo and Veeam both offer Microsoft 365 backup as separate products from their VM backup lines. Worth knowing before you compare: Microsoft now sells a first-party backup product of its own, generally available since late 2024, which covers OneDrive, SharePoint and Exchange Online with one-year retention. The third-party case is no longer that Microsoft offers nothing; it is that Microsoft's copies stay inside its own service boundary, so they are not an independent copy. **What actually matters more than the product choice?** Whether restores have been tested, and how long they take. Every product on this page will back up your estate competently if configured properly, and every one of them will fail you if the job has been erroring for months and nobody read the report, or if the scope never included the server that mattered. The differences between these three are real but they are smaller than the difference between a tested backup and an assumed one. If you take one thing from this comparison, make it the restore test rather than the shortlist. ### Citrix vs Parallels RAS vs Azure Virtual Desktop: what to move to URL: https://systechitsolutions.co.uk/compare/citrix-vs-parallels-ras-vs-avd Leaving Citrix after a renewal quote. What Parallels RAS covers, where native AVD and Windows 365 win, and the management layer you lose going native. Category: End-User Computing | Last updated: 2026-08-21 Nobody arrives at this comparison casually. It is almost always prompted by a renewal quote that came back at a number nobody budgeted for, with about ninety days to decide. In short: Citrix remains the strongest option for very large estates, difficult network conditions and graphics-heavy work, and is increasingly hard to justify below that. Parallels RAS is the better fit for on-premises and hybrid estates publishing applications, licensed by concurrent user rather than named user, with load balancing, gateway and multi-tenancy in the one product. Native Azure Virtual Desktop and Windows 365 is the better fit where the estate is already Microsoft-centric and people need desktops rather than published applications, with EtherInsights at £0.79 per licensed user per month supplying the cost, posture and day-two management layer that Citrix used to bundle. #### Why the question is being asked at all Citrix has not become a worse product. It has become a differently priced one. Under Cloud Software Group, licensing moved from à la carte to bundled subscriptions, minimum seat commitments arrived, and renewal quotes have come back substantially higher, in some cases at roughly double, usually with about ninety days of notice. Components that an estate does not use turn up in the bundle, and the seat floor frequently sits above real headcount. For a large organisation using most of the platform, that can still be the right buy. For a business of a few hundred seats that adopted Citrix when it was the only credible option, and now publishes a dozen applications to a workforce that is partly part-time, it means paying enterprise pricing for a fraction of the product. A renewal deadline is the worst possible condition to choose a remoting platform under, and vendors know it. If there is not enough runway to migrate properly, a short renewal on the best available terms while the replacement is designed is usually a better decision than either a rushed migration or a three-year commitment signed under pressure. #### Parallels RAS: the on-premises and hybrid answer RAS publishes applications and desktops from RDSH, VDI or Azure Virtual Desktop, and brokers across VMware ESXi, Hyper-V, Nutanix and Scale as well as Azure and AWS. That breadth is the point: it meets an estate where it currently is, rather than requiring it to move first. Two things decide most cases. **Concurrent-user licensing.** RAS bills the maximum number of simultaneous connections, not the number of people with accounts. Where a workforce is shift-based, part-time, seasonal, or working from shared devices on a clinical or factory floor, peak concurrency sits well below headcount and the gap is the saving. Where everybody works full time and connects all day, it saves very little, and that is worth establishing in an hour rather than assuming for a quarter. **One product rather than editions.** HALB load balancing, the secure gateway, multi-tenancy, FSLogix profile container support, MSIX app attach and App-V integration, and clients for Windows, macOS, Linux, iOS, Android and the browser are all in the single product rather than distributed across tiers. The honest limits are real. HDX is ahead over poor networks and for graphics-heavy work. At many thousands of seats with deep ecosystem integration, replacement is a programme rather than a swap. And Citrix App Layering has no exact equivalent, so where that is genuinely in use it can decide the answer by itself. #### Native AVD and Windows 365: the Microsoft-centric answer If the applications are modern, the estate is already Microsoft-centric, and what people need is a desktop rather than finely controlled published applications, the simplest answer is usually no third-party broker at all. Azure Virtual Desktop is metered Azure consumption, which suits variable and elastic usage. Windows 365 is a fixed per-user subscription, which suits predictable full-time users and removes the sizing exercise entirely. Our AVD vs Windows 365 vs traditional desktops guide covers choosing between those two in detail. One vendor instead of two is a genuine advantage, and we say so as a company that sells the broker as well. #### The management layer nobody prices in Here is the part that catches estates out, and it is the strongest single argument in the whole comparison. Citrix bundles two different things: brokering sessions, and the console that shows you what the estate is doing. Leave Citrix for native Microsoft and you keep the desktops, but you lose the single place where cost, usage, posture and day-two management were visible. Microsoft's own tooling covers pieces of it across several different portals, and the gap usually surfaces a few months later, when somebody asks what the Azure bill is being spent on per team, or which accounts are over-permissioned, and the answer takes a week to assemble. EtherInsights is the layer we put in its place on AVD and Windows 365 estates. Cloud cost attribution and forecasting, Microsoft 365 security posture, Copilot readiness and day-two management, in one view, at **£0.79 per licensed user per month**. On a 250-seat estate that is roughly £198 a month. Set against a Citrix bundle priced per named user with a seat floor, the comparison is not close, and it is worth being precise about why: you are no longer buying brokering and visibility as one product. The brokering question gets answered by AVD or Windows 365, and the visibility question gets answered separately and far more cheaply. It is an analysis platform, not a managed service and not a remediation tool. It tells you what is true and what it is costing. It does not broker sessions, and it is not a Citrix replacement on its own. #### The full comparison | | Citrix | Parallels RAS | AVD and Windows 365 | | ---------------------- | ------ | ------------- | ------------------- | | Licensing model | Bundled subscription, named user, minimum seat commitment | Single product, concurrent user | AVD metered Azure consumption; Windows 365 fixed per user | | What is included | Bundle contents fixed, components you may not use | Load balancing, gateway, multi-tenancy, FSLogix, MSIX app attach | Microsoft platform only, no third-party broker | | Back ends brokered | Broad, plus deep ecosystem integration | RDSH, VDI, Azure, AVD across VMware, Hyper-V, Nutanix, Scale | Azure only | | Protocol strength | HDX, strongest over poor networks and for graphics | Good for typical office workloads | Good for typical office workloads | | Management layer | Included in the bundle | Included in the product | Not included; EtherInsights at £0.79 per user per month | | Best fit | Very large estates, difficult networks, graphics-heavy work | On-premises and hybrid, published applications, variable concurrency | Microsoft-centric estates needing desktops | | Where it stops making sense | Bundle and seat floor exceed what the estate uses | Very large scale, or HDX-class performance required | Applications must be published to mixed on-premises back ends | #### How to decide, in order Take these in sequence, because answering them out of order is what produces the wrong platform. 1. **Inventory what is actually published.** Applications, who uses them, from where, on what devices. This is almost always shorter than people expect, and it determines feasibility more than any other factor. 2. **Measure peak concurrency against named licences.** An hour's work, and it either makes the concurrent-user argument or removes it. 3. **Find the dependencies that decide it.** HDX-class performance, App Layering, a specific integration. One real dependency outranks every cost argument on this page. 4. **Ask where the applications and data actually live.** On-premises and hybrid points at RAS. Microsoft-centric and modern points at native AVD or Windows 365. 5. **Decide the management layer deliberately**, at the point of migration rather than six months afterwards. 6. **Pilot with real users and real peripherals.** Printing, scanners, smart cards, USB devices and the one undocumented legacy application are where remoting migrations fail, and they only surface with people doing actual work. #### Where we land For **on-premises and hybrid estates**, Parallels RAS is the stronger answer, and it has the additional advantage of letting you solve the renewal now and decide about Azure later, on its own merits, rather than turning one deadline into two projects. For **AVD and Windows 365 deployments**, go native and add EtherInsights for the cost, posture and management visibility. That combination is the way forward for a Microsoft-centric estate, and at £0.79 per licensed user per month the visibility costs a fraction of what it did as part of a bundle. For **very large estates, difficult network conditions or graphics-heavy work**, stay on Citrix and negotiate. We would rather tell you that than sell you a migration that makes your users' day worse. We deliver all three, including the Parallels RAS work, the AVD and Windows 365 consultancy, and the endpoints people connect from. The recommendation does not change depending on which one you pick. #### Frequently asked questions **Why are so many businesses leaving Citrix?** Commercial reasons rather than technical ones. Under Cloud Software Group, Citrix moved from à la carte licensing to bundled subscriptions, introduced minimum seat commitments, and renewals have come back substantially higher, in some cases at roughly double, typically with around ninety days' notice. For a large estate using most of the platform that can still be defensible. For a mid-sized estate that adopted Citrix when it was the only credible option and now publishes a handful of applications, it means paying enterprise pricing for a fraction of the product. Citrix has not got worse; it is priced for a different customer than the one it used to serve, and a lot of estates no longer are that customer. **Is Parallels RAS or Azure Virtual Desktop the better Citrix replacement?** It depends on where your applications and infrastructure actually live, and the split is fairly clean. Parallels RAS is the stronger answer for on-premises and hybrid estates: it brokers to RDSH and VDI across VMware, Hyper-V, Nutanix and Scale as well as Azure, and it publishes individual applications with fine-grained control, which is what most long-standing Citrix deployments are actually used for. Native AVD with Windows 365 is the stronger answer where the estate is already Microsoft-centric, the applications are modern, and what people need is a desktop rather than a set of published applications. The mistake is choosing on licence price alone, because the two are solving slightly different problems. **How does concurrent-user licensing change the cost?** It bills the maximum number of simultaneous connections rather than the number of people with accounts, which only matters for particular workforce shapes. Shift-based work, part-time and job-share staff, seasonal peaks, and shared devices on clinical, retail or factory floors all produce a peak concurrency well below headcount, and that gap is the saving. Where everyone works full time and connects all day, concurrency saves very little and anyone telling you otherwise has not looked. The test takes about an hour: pull peak simultaneous sessions from your existing platform's own reporting and compare it against the named licences you currently pay for. **What do you lose by moving from Citrix to Parallels RAS?** Three things, and they are worth establishing before a migration rather than during one. HDX, which is genuinely ahead over poor networks and for graphics-heavy or 3D work, so users on satellite links, in poorly connected sites, or running CAD will feel the difference. Scale and ecosystem, because at many thousands of seats with deep monitoring and automation integration a replacement becomes a programme rather than a swap. And specific features such as Citrix App Layering, which have no exact equivalent. In most mid-sized estates nobody is using the third category, but where one of those dependencies is real it decides the answer on its own. **If we go native to AVD or Windows 365, what management do we lose?** The console. Citrix bundles brokering and management together, so leaving it for native Microsoft means you keep the desktops and lose the single place where cost, usage, posture and day-two management were visible. Microsoft's own tooling covers pieces of this across several portals, and most estates discover the gap a few months in, when somebody asks what the Azure bill is actually being spent on per team, or which accounts are over-permissioned. That gap is fillable cheaply, but it should be a decision made deliberately at the point of migration rather than a surprise afterwards. **What does EtherInsights cost and what does it actually do?** £0.79 per licensed user per month. It covers cloud cost attribution and forecasting, Microsoft 365 security posture, Copilot readiness and day-two management, in one place. It is an analysis platform rather than a managed service or a remediation tool: it tells you what is true and what it is costing, and it does not broker sessions or replace a remoting platform. On a 250-seat estate that is around £198 a month, which is the context that makes the Citrix comparison stark: the management visibility you were paying enterprise bundle pricing for is available as a separate, considerably cheaper layer once the brokering question is answered somewhere else. **Can we leave Citrix without moving to Azure at the same time?** Yes, and it is frequently the right sequence. Parallels RAS runs on the infrastructure you already have, so the commercial problem, the renewal, can be solved on its own timetable, and the architectural question of whether to move into Azure can be answered later on its merits. RAS also integrates with Azure Virtual Desktop directly and can manage it rather than replace it, so that later move does not mean another migration off the broker. Trying to do both at once is how remoting migrations stall, because a single project then depends on two sets of decisions, two budgets and two sets of testing. ### Windows 10 ESU vs upgrading to Windows 11 vs moving to a Cloud PC URL: https://systechitsolutions.co.uk/compare/windows-10-esu-vs-windows-11-vs-cloud-pc Windows 10 support ended in October 2025 and ESU pricing doubles each year. Three routes forward compared on cost, effort and how long each one buys. Category: Legacy Modernisation | Last updated: 2026-08-19 Windows 10 support ended on 14 October 2025. The machines carried on booting, which is exactly why so many estates are still running it. But the security updates stopped, the compliance clock started, and every month that passes adds unpatched vulnerabilities to devices that will never receive a fix. There are three honest routes forward, and the right one depends almost entirely on your hardware. In short: Extended Security Updates buy security patches only, at a per-device annual cost that rises sharply each year, and end after three years. Upgrading to Windows 11 returns you to a fully supported operating system at little or no licence cost, but only for hardware that meets the TPM 2.0, Secure Boot and supported-processor requirements. Moving to a Cloud PC takes the desktop off the physical device entirely, so hardware age stops governing the operating system, in exchange for an ongoing per-user subscription. Most estates end up using all three: upgrade what qualifies, bridge the blockers on ESU, and move the rest to Cloud PCs rather than replacing them. This guide is for businesses that still have Windows 10 devices in service and need to decide what to do about it, particularly where a compliance requirement or an insurance renewal has made the deadline concrete. It compares the three routes on cost shape, effort and how long each one actually buys you. #### The three routes, in plain terms ##### Extended Security Updates ESU is a paid programme that continues delivering security updates for Windows 10 after end of support. It is deliberately narrow: security patches only, with no new features, no non-security fixes and no general technical support. It runs for three years from end of support, priced per device per year, and the price steps up substantially each year. The critical thing to understand is that ESU is not a destination. Microsoft has priced it to be increasingly uncomfortable, because its purpose is to buy time for a migration that is already planned, not to defer the decision indefinitely. It is also bought in sequence, so skipping a year and rejoining later generally means paying for the year you skipped too. Used well, ESU is genuinely useful: it takes deadline pressure off a specific set of devices with a specific blocker while that blocker is resolved. Used badly, it becomes an annual payment that funds inaction and gets more expensive every time. ##### Upgrading to Windows 11 For hardware that qualifies, this is the straightforward answer and usually the cheapest. Windows 11 is a free upgrade for licensed Windows 10 devices, so the cost sits in the work rather than the licence: application compatibility testing, driver and peripheral checks, user communication, and the rollout itself. The constraint is the hardware requirements. Windows 11 needs TPM 2.0, Secure Boot, UEFI firmware and a processor on Microsoft's supported list, and it is the processor requirement that excludes most machines. Devices that feel entirely adequate are frequently ruled out by CPU generation alone. One detail is worth checking before writing hardware off: some devices fail only because TPM or Secure Boot is switched off in firmware rather than missing. A proper readiness scan usually reclaims a meaningful share of an estate that a quick assumption would have condemned. ##### Moving to a Cloud PC The third route changes the question rather than answering it. With Windows 365 or Azure Virtual Desktop the operating system runs in Microsoft's cloud and the physical device becomes an access terminal. A machine that cannot run Windows 11 locally can very comfortably run a browser or a remote desktop client, so hardware that fails the requirements can continue in service for years as a thin client. Which of the two you land on matters, because they are priced and managed very differently. Our Windows 365 consultancy covers the fixed per-user Cloud PC route, where nothing has to be sized; our Azure Virtual Desktop consultancy covers the cases where pooled multi-session hosts, autoscaling or GPU-backed workloads justify the extra design effort. That is the structural appeal: it ends the recurring cycle where the hardware refresh calendar dictates the operating system calendar. It also moves cost from a periodic capital bill to a steady per-user subscription, which some businesses prefer and others do not. "ESU buys time. Upgrading buys a supported estate. A Cloud PC changes the question, so that the age of the laptop on the desk stops deciding which operating system you are allowed to run." #### The full comparison | | Windows 10 ESU | Upgrade to Windows 11 | Move to a Cloud PC | | --- | --- | --- | --- | | What it solves | Security patching only | Returns you to full support | Removes hardware as the constraint | | Cost shape | Per device, per year, rising each year | Mostly project effort, plus replacement hardware | Ongoing per-user subscription | | Hardware implications | None, runs on what you have | Non-qualifying devices must be replaced | Existing devices continue as thin clients | | Immediate effort | Lowest | Moderate, concentrated in app testing | Highest, changes how the estate is run | | How long it buys | Three years maximum, then nothing | A normal support lifecycle | Ongoing, no refresh cliff | | New features | None | Yes | Yes | | Best suited to | Devices with a specific unresolved blocker | Estates where most hardware qualifies | Estates facing mass replacement, or hybrid work | #### How to decide: start with a hardware count Almost every sensible version of this decision begins with one number: what proportion of your devices actually meet the Windows 11 requirements? Until you know that, every option is speculation. If most of the estate qualifies, upgrading in place is nearly always the right answer. It is the cheapest route, it returns you to a supported platform, and the remaining work is application testing rather than procurement. If a large share fails, the arithmetic changes. A business facing replacement of most of its laptops at once is looking at a substantial capital bill, and that is exactly the situation where Cloud PCs become financially interesting rather than merely modern, because the existing hardware keeps working as an access device instead of going to disposal. If a small number of devices fail and the rest qualify, the mixed answer is usually best: upgrade everything that can be upgraded, and make a deliberate decision per remaining device about whether to replace it, bridge it on ESU, or move that user to a Cloud PC. #### The dependency that actually blocks people In practice the operating system is rarely the hard part. The blocker is almost always a line-of-business application: something that only runs on Windows 10, or is certified against it, or was installed years ago by a supplier who no longer exists, or depends on a component that a current operating system will not load. This is where ESU earns its place. Buying a defined period of security updates for the specific devices running that application is a reasonable way to take deadline pressure off while the application problem is solved properly. What is not reasonable is buying ESU without simultaneously starting that work, because the programme ends whether or not the dependency has been resolved. Where the application is the obstacle, application packaging and MSIX conversion can often move it onto a supported platform without source code or original media, and broader application modernisation covers the cases where replatforming or an Azure migration is the better answer. Our write-up on legacy apps and their security, cost and carbon impact covers why these applications tend to cost more than they appear to. #### Do not plan the desktop in isolation Windows Server 2016 reaches end of extended support on 12 January 2027. If you have both problems, and many businesses do, planning them together is meaningfully more efficient than running two projects, because the difficult part is identical: understanding which applications depend on what, and which of those dependencies are genuine rather than assumed. The discovery work substantially overlaps. So does the remediation, since an Azure migration or a replatforming exercise often resolves the desktop and server sides of the same application at once. Our Windows Server 2016 end of support guide covers that side of the timeline in detail. #### How we approach it We start with a readiness assessment rather than a recommendation, because the recommendation depends on numbers nobody has yet. That means a full device inventory, a Windows 11 eligibility check across the estate including devices that fail only on firmware settings, and an application dependency map that identifies which software is genuinely tied to Windows 10 rather than assumed to be. ##### The plan is usually a mix, with dates attached Three moves, in this order: - **Upgrade the qualifying devices first.** It shrinks the problem immediately and cheaply. - **Put a defined ESU period around the genuine blockers**, so the exception has an end date rather than becoming permanent. - **Evaluate Cloud PCs** for the users and devices where replacement would otherwise be the only option. If the Cloud PC route is on the table, our AVD vs Windows 365 vs traditional desktops comparison covers how those two platforms differ and which suits which workload, and the engagement itself runs as either Windows 365 consultancy or Azure Virtual Desktop consultancy depending on where that lands. ##### Windows 10 without ESU will not certify The certification angle is worth naming too. If you hold Cyber Essentials or are working towards it, unsupported software in scope is a hard fail, so an estate still on Windows 10 without ESU will not certify. Our Cyber Essentials vs Cyber Essentials Plus guide covers what that requirement means in practice. ##### Related reading You can read more on our legacy modernisation and OS migration and end-user computing service pages, or see our legacy migration roadmap for the planning framework. We work with businesses across Yorkshire and the UK from our base in Brough, East Yorkshire, including Hull, Leeds, Sheffield and York, with the full coverage area listed if you are elsewhere. If you want a straight read on how many of your devices actually qualify, get in touch and we will run the numbers first. #### Frequently asked questions **What actually happens now Windows 10 support has ended?** Windows 10 reached end of support on 14 October 2025. The machines did not stop working, and that is precisely what makes the risk easy to underestimate. What stopped is the flow of security updates: newly discovered vulnerabilities in Windows 10 are no longer fixed for devices outside the Extended Security Updates programme. The practical consequences arrive on three fronts. Security exposure compounds over time, because every month adds unpatched vulnerabilities to a device that will never receive a fix. Compliance obligations bite sooner than most people expect, since Cyber Essentials and most cyber insurance policies require software to be supported by its vendor, so an unsupported operating system in scope is a straightforward fail rather than a discussion. And application vendors progressively stop testing against and supporting Windows 10, so problems increasingly get met with an instruction to upgrade first. **How much do Extended Security Updates cost, and do they get more expensive?** Yes, and the escalation is the defining feature of the programme rather than a detail. Commercial ESU for Windows 10 is priced per device per year, and the price increases substantially each year across the three-year programme, with each year's cost stepping up from the last. Microsoft has designed it that way deliberately: ESU is intended as a bridge that becomes progressively less attractive, not as a stable long-term arrangement. There is also a cumulative catch worth knowing about. ESU is bought in sequence, so an organisation that skips the first year and wants coverage in the second generally has to buy the earlier year as well, which means delaying the decision does not avoid the earlier cost. Budget on the assumption that each additional year costs more than the one before, and that the total across the programme approaches or exceeds the cost of simply replacing an older device. **What if our hardware does not meet the Windows 11 requirements?** This is the constraint that drives most of the decision, and it is worth measuring precisely rather than assuming. Windows 11 requires TPM 2.0, Secure Boot, UEFI firmware and a processor on Microsoft's supported list, and the processor requirement is what excludes most otherwise-serviceable machines. Plenty of devices that feel perfectly adequate are ruled out by their CPU generation alone. Some devices fail only because TPM or Secure Boot is disabled in firmware rather than absent, and those are recoverable with a settings change rather than a purchase, so a proper readiness scan usually reclaims a percentage of the estate that a spreadsheet would have written off. For genuinely ineligible hardware there are three honest options: replace the device, keep it on ESU while you plan, or stop treating the local hardware as the thing that runs the operating system and move the desktop to a Cloud PC, which is exactly the situation where that third route becomes financially interesting. **Is moving to a Cloud PC cheaper than buying new laptops?** It depends on the shape of the cost you prefer, not simply the total. Replacing hardware is capital expenditure concentrated at a point in time, followed by several quiet years, then another refresh. A Cloud PC converts that into an ongoing per-user subscription with no refresh cliff, while letting existing hardware continue as a thin client well past the point where it could run a current operating system locally. Over a typical device lifetime the totals are often closer than either side of the argument admits. The cases where Cloud PCs are clearly favourable share a pattern: a large proportion of the estate failing the Windows 11 hardware requirements at once, so the alternative is a single very large replacement bill; a workforce already hybrid or remote, where the desktop being location-independent has value beyond the licensing; or a business that would rather carry a predictable monthly cost than a lumpy capital cycle. Where most hardware already meets the requirements, upgrading in place is usually both cheaper and simpler. **Can we mix these approaches across one estate?** Yes, and for most businesses of any size a mix is the realistic answer rather than a compromise. The three routes address different constraints, and estates rarely have just one constraint. A common pattern is to upgrade every device that already meets the Windows 11 requirements straight away, since that is the cheapest and least disruptive move available and it shrinks the problem immediately. Devices that fail the requirements but are tied to a specific application or workflow go onto ESU for a defined period while that dependency is resolved. Users whose work suits it move to Cloud PCs, which lets their existing hardware carry on as a thin client rather than being replaced. What makes a mix work is treating it as a plan with dates rather than a permanent arrangement, because the failure mode is an estate where ESU quietly becomes the default for anything difficult and the same conversation happens again when the programme ends. **What about Windows Server 2016, which is heading the same way?** Windows Server 2016 reaches end of extended support on 12 January 2027, which is roughly one budget cycle away and close enough that it should be planned alongside the desktop work rather than after it. The pattern is familiar: an ESU programme exists as a paid bridge, the underlying decision is migrate or modernise, and the applications rather than the operating system are what make it difficult. Treating the desktop and server end-of-life problems as one programme is usually more efficient than running them separately, because the hard part in both cases is the same, namely the line-of-business applications with dependencies nobody has fully documented. The discovery work you do for one substantially serves the other, and Azure migration or replatforming often resolves both at once. ## Services ### IT & Microsoft Cloud Services URL: https://systechitsolutions.co.uk/services Systech's managed IT services: 24/7 support, managed firewall, Microsoft 365 and Azure, cyber security, cost optimisation, AI adoption and modernisation. Every service Systech delivers: - Managed IT (https://systechitsolutions.co.uk/services/managed-it): Fully managed IT with 100% UK-based 24/7 support. - Managed Firewall (https://systechitsolutions.co.uk/services/managed-firewall): Fully managed firewall service, monitored around the clock. - Cyber security (https://systechitsolutions.co.uk/services/security): EDR, XDR, email security and Cyber Essentials. - Compliance packs (https://systechitsolutions.co.uk/services/compliance-packs): Policies, procedures, SOPs and internal audit readiness. - Microsoft 365 (https://systechitsolutions.co.uk/services/m365): Tenant migration, governance, Teams, SharePoint and Intune. - Azure cost optimisation (https://systechitsolutions.co.uk/services/cost): Cutting Azure and licence waste; most firms overspend 30-40%. - AI & Copilot adoption (https://systechitsolutions.co.uk/services/ai): Microsoft 365 Copilot readiness and rollout. - AI engineering (https://systechitsolutions.co.uk/services/ai-engineering): RAG over your own data, small language models and custom AI apps. - Application modernisation (https://systechitsolutions.co.uk/services/modernisation): Azure migration, replatforming and Power Platform. - Application packaging (MSIX) (https://systechitsolutions.co.uk/services/app-packaging): MSIX packaging as a managed service, App-V to MSIX, CI/CD pipelines. - Legacy modernisation & OS migration (https://systechitsolutions.co.uk/services/legacy): Windows 11 rollouts and Server 2012/2016 upgrades. - End-user computing (Windows 365 & AVD) (https://systechitsolutions.co.uk/services/euc): Cloud PC and virtual desktop design and management. - Azure Virtual Desktop consultancy (https://systechitsolutions.co.uk/services/avd-consultancy): AVD cost assessment, TCO analysis, host pool design and migration. - Windows 365 consultancy (https://systechitsolutions.co.uk/services/windows-365-consultancy): Cloud PC and licence sizing, network readiness, rollout and management. - Microsoft licensing & cost management (https://systechitsolutions.co.uk/services/licensing-cost-management): Licence tier rightsizing, shelfware removal, Azure cost and renewal timing. - Email security & archiving (https://systechitsolutions.co.uk/services/email-security): Anti-phishing, continuity and compliant archiving. - Backup & disaster recovery (https://systechitsolutions.co.uk/services/backup): Monitored, tested backup for servers, endpoints and Microsoft 365. - White-label IT delivery (https://systechitsolutions.co.uk/services/white-label): Enterprise-grade technical execution for vendors and MSPs. - Development services (https://systechitsolutions.co.uk/services/development): Reporting apps, bespoke business applications, data work, service desk AI and CRM replacements. - Cyber Essentials certification (https://systechitsolutions.co.uk/services/cyber-essentials): Pre-assessment, remediation and support through the questionnaire, for Cyber Essentials and Plus. - Endpoint management (https://systechitsolutions.co.uk/services/endpoint-management): Microsoft Intune management and the estate-wide reporting it does not give you, plus Configuration Manager. - Remote Desktop Services (RDS) (https://systechitsolutions.co.uk/services/remote-desktop-services): Session host sizing, Connection Broker and Gateway design, logon performance and CAL licensing. - Networking (https://systechitsolutions.co.uk/services/networking): Network design, VLAN segmentation, Wi-Fi that works at density, starting with what is actually wrong. - Microsoft 365 licensing review (https://systechitsolutions.co.uk/services/microsoft-365-licensing-review): Which tier you should actually be on, and what your licence already includes that nobody has switched on. ### Microsoft-First Managed IT Services URL: https://systechitsolutions.co.uk/services/managed-it Outsourced managed IT for UK businesses: 24/7 monitoring, a UK-based service desk, patching, backup and device management, at a predictable monthly cost. Round-the-clock monitoring and proactive support that keeps your systems, and your people, running. Most IT problems aren't dramatic. They're the slow drip of missed patches, unlogged tickets and a device nobody's checked in months, until the day one of them takes the business offline. This service is for you if: - You have no in-house IT team, or a stretched one firefighting instead of improving things - Support today is reactive: you call someone when something breaks, not before - You want one accountable partner for your whole estate, at a predictable monthly cost The cost of doing nothing: Break-fix IT feels cheaper until the first serious outage: an unpatched server, a failed backup nobody was monitoring, a ransomware hit that spreads because no one was watching. The cost of doing nothing shows up all at once, usually at the worst possible moment. #### Your outsourced IT department We look after the day-to-day running of your IT so your team can focus on the business. Proactive monitoring spots issues before they become outages, and our UK-based service desk is on hand whenever you need us. From a single point of contact to full lifecycle management of your devices and infrastructure, we become the IT department you'd hire if you could, at a fraction of the cost. What's included: - 24/7 monitoring and alerting, with daily infrastructure checks - UK-based service desk and rapid incident response - Security patching on staged rings, and a quarterly firmware cycle - Weekly firewall configuration backups - Asset and lifecycle management - Monthly service reporting and reviews - Clear, predictable monthly pricing #### What does 'managed' actually cover compared with break-fix? The difference is who carries the risk of things going wrong. Under break-fix you pay per incident, which means your provider only earns when something has already failed, and the work that prevents failure (patching, monitoring, backup verification, capacity checks, lifecycle planning) has no natural home. Under a managed agreement the provider is paid a fixed fee to keep the estate healthy, so unglamorous preventative work becomes their cost of doing business rather than a billable extra. That incentive flip is the substance of the model; the tooling and the service desk follow from it. What varies between providers is where the boundary falls between included work and project work. Migrations, office moves, new site builds and major upgrades are almost always scoped separately, and any provider claiming otherwise is either pricing that risk into your monthly fee or planning to argue about it later. #### What actually happens, and how often? Most managed IT is sold on adjectives. Proactive, responsive, enterprise-grade. None of those are checkable, so here is the rhythm the service actually runs to, which is. Patching and firmware are deliberately on different clocks, and it is worth understanding why. Security patches for Windows and third-party software cannot wait for a quarter: Cyber Essentials expects critical and high-severity updates inside fourteen days, and that work runs continuously on the ring model above. Firmware for firewalls, switches and infrastructure is the opposite case, where the update itself carries a real risk of taking something down, so it belongs in a planned window with change control around it. #### What does proactive monitoring actually detect? Proactive monitoring catches the class of problems that degrade before they fail. None of those are outages yet. All of them become outages if nobody looks. The value is therefore in what happens to the alert, not in the alert existing. A monitoring platform that emails a shared mailbox nobody reads is theatre. What makes it worth having is a defined owner for each alert type, a triage step that separates noise from signal, and a record of what was done, so that a recurring warning gets fixed at the cause rather than acknowledged every night for six months. #### Why do patching rings matter, and what happens without them? Patching rings exist because the two obvious strategies are both wrong. Patch everything immediately and a bad update takes out the whole estate at once; defer patching until someone has time and you accumulate exactly the exposure that most ransomware relies on. A ring model splits devices into staged groups (typically a small pilot group of IT and tolerant users, then a broader group, then the rest, then the sensitive machines that need change windows) with a deferral period between each. A problematic update surfaces in the pilot group where the blast radius is small, and everything behind it can be paused. Two things make or break the model. The first is that rings must be populated by risk profile, not alphabetically: the finance workstation running the practice management client and the theatre PC driving a piece of medical hardware do not belong in the same wave as a general office laptop. The second is that third-party software needs the same treatment as Windows itself, because browsers, PDF readers, Java runtimes and remote access tools are consistently among the most exploited applications in the estate and are the ones most often left to update themselves, or not. #### What should you check before signing any managed IT contract? Start with the boundary, not the price. Ask precisely what is included and what becomes chargeable project work, because that line is where most disputes live. Then check what 'unlimited support' means in the small print, whether targets are for response or for resolution, what the out-of-hours arrangement genuinely covers versus what triggers an escalation charge, and how many hours of on-site attendance are included if any. A rate card for out-of-scope work should be in the contract from the start rather than produced after you need it. Then check ownership and exit, which buyers routinely miss. You should own your Microsoft tenant and your domain registration, hold your own break-glass Global Administrator credentials that the provider does not control, and have licences purchased in your name where the agreement allows it. Ask what happens to documentation, passwords, monitoring agents and configuration at the end of the term, whether offboarding assistance is included or billed, and what security accreditations the provider itself holds. A supplier with administrative control of your identity platform is part of your attack surface, and should be assessed as one. #### Co-managed or fully outsourced: which model fits? Fully outsourced fits when there is no internal IT function, or when the one person you have is spending their week on password resets instead of the work you actually hired them for. Co-managed fits when you already have internal capability worth keeping and want to extend it rather than replace it: the internal team keeps the business-context work, the applications nobody else understands and the relationships with the rest of the organisation, while the provider supplies the things that are uneconomic to build in-house: out-of-hours cover, enterprise-grade tooling, specialist depth in areas you touch once a year, and holiday and sickness resilience. Co-managed only works if the split is written down. The common failure is an ambiguous boundary where both parties assume the other is watching backups, patching the servers or reviewing the alert queue, and the answer turns out to be nobody. Agree which systems belong to which party, who holds which administrative roles, who is first responder for each alert type, where tickets are raised and how they are escalated between teams. Done properly it is the strongest model available to a mid-sized organisation; done vaguely it produces two teams and one gap. #### Does it matter whether the service desk is UK-based? For some organisations it is a preference; for others it is a contractual requirement. If you work in healthcare, in central or local government, in defence or in a regulated supply chain, your own obligations may specify where data is processed and who can access it, and support staff with administrative access are accessing data. NHS Data Security and Protection Toolkit commitments, public-sector procurement conditions and client security questionnaires all routinely ask where support is delivered from. If you cannot answer, you may not be able to bid. Beyond compliance, the practical arguments are working hours and shared context. A desk in your own time zone means the person who took the call at nine can still be handling it at four, rather than a handover across shifts on a problem that needed continuity. What matters most, though, is not geography but whether the same engineers see the same estate often enough to know it: a UK desk with total churn is not better than a well-run offshore one. #### Looking for an IT support company near me: does location still matter? Less than the phrase implies, and not in the way you would expect. Most managed IT work now happens inside your Microsoft tenant rather than in your building, so the engineer fixing a Conditional Access policy or a broken mail flow is doing identical work whether they sit ten miles away or two hundred. What genuinely changes with distance is the small proportion of work that needs somebody physically present: a failed switch, a network fault nobody can see remotely, an office move. So the question worth putting to any IT support company is not where its office is, it is what happens when a job needs hands on site, and whether the people answering the phone are the same people who know your estate. A local address attached to a service desk somewhere else buys you nothing. We are straight about our own geography: our engineers are based in Brough in East Yorkshire, we cover Yorkshire and the Humber on site as a matter of course, and we work with businesses across the rest of the UK remotely. Where proximity does earn its keep is the first ninety days. Onboarding goes faster when somebody can spend a day walking the estate rather than inferring it from a remote scan, and that is the point at which we would rather be in the room. #### What does asset and lifecycle management actually involve? It starts with an accurate inventory, and most organisations do not have one. A usable asset record covers every device and its owner, purchase and warranty dates, operating system build and support end date, firmware level, encryption status, installed software, and licence entitlements, and it is generated from your management tooling rather than kept in a spreadsheet, because spreadsheets are out of date the day after they are written. Without that record you cannot answer basic questions, such as how many machines will fall out of support before the next Windows end-of-life date. Lifecycle management is the discipline of acting on the inventory. That means a refresh plan that spreads replacement cost across years instead of concentrating it into one painful capital request; a build standard so new devices arrive configured rather than hand-assembled; and a defined end-of-life route covering secure data destruction, certificates of erasure for anything holding personal data, and WEEE-compliant disposal. Devices out of vendor support are the awkward part, because unsupported hardware and operating systems fail Cyber Essentials and are frequently excluded from cyber insurance. #### Frequently asked questions **What does a managed IT service actually include?** Proactive 24/7 monitoring, a UK-based service desk for your users, patch and update management, backup oversight, device and asset lifecycle management, and regular service reviews, all for a fixed monthly fee rather than per-incident charges. **Is managed IT cheaper than hiring an in-house IT team?** For most small and mid-sized UK businesses, yes. You get a whole team's worth of skills, tooling and out-of-hours cover for less than the cost of one or two full-time hires, with no recruitment, holiday or single-point-of-failure risk. **Do you support hybrid and remote workers?** Yes. We manage devices, identity and access wherever your people work, using Microsoft Intune and conditional access so a laptop at home is as controlled and supported as one in the office. **What's the difference between a managed service provider and an IT support company?** An IT support company sells you time, usually reactively and often by the hour or by pre-paid block. A managed service provider sells you an outcome (a working estate) for a fixed fee, and takes on the monitoring, maintenance and reporting that keeps it working. The practical test is whether the provider makes more money when things break. Under a genuine managed agreement they do not, so preventative work is in their interest as well as yours. **If IT is outsourced, do we still need our own IT policies?** Yes. A provider can operate and enforce controls, but they cannot decide on your behalf what your organisation permits: whether staff can use personal devices, what happens to data when someone leaves, who approves administrative access, or how long records are retained. Those are business decisions with legal and regulatory weight, and under UK GDPR you remain the data controller regardless of who administers the systems. Outsourcing changes who operates the controls, not who is accountable for them. **Is putting a monitoring agent on every device a security risk in itself?** It is a real consideration and worth asking about. Remote monitoring and management tooling holds privileged access across an entire estate, which is exactly why attackers have targeted these platforms to reach many organisations at once. The mitigations are specific: multi-factor authentication on every technician account without exception, role-based access so engineers hold only the rights their work requires, restricted and logged use of remote-control and scripting functions, and prompt patching of the tooling itself. Ask a prospective provider how they secure their own platform, and treat a vague answer as the answer. **How should we handle staff joining, moving and leaving?** Treat it as one controlled process rather than three ad hoc requests. Joining should provision identity, licences, group membership and a device from a defined role template, so access is granted by role rather than by copying an existing user: copied accounts are how privilege quietly accumulates. Moving should remove the old role's access as well as adding the new, which is the step most often skipped. Leaving should disable the account immediately, revoke active sessions and tokens rather than only resetting the password, reclaim the device, and deal with the mailbox and OneDrive content before the retention window closes. **How do we tell whether a managed contract is delivering value?** Look past ticket volume, which mostly measures how much is going wrong rather than how well it is handled. More telling metrics are the trend in repeat incidents against the same system, the proportion of tickets resolved at first contact, patch compliance across the estate expressed as a percentage of devices current, backup success and, more importantly, verified restore tests, and the count of devices and applications running out of vendor support. A provider who brings you problems you had not spotted yet is doing the job; one whose reporting only ever shows green is not looking hard enough. **Does managed IT include dealing with our other software vendors?** Usually yes for liaison, and it is worth confirming in writing. Most managed agreements include raising and chasing tickets with third parties on your behalf (your line-of-business application vendor, your connectivity provider, your telephony supplier) because the alternative is your staff sitting in someone else's support queue with an issue they cannot describe technically. What that does not include is responsibility for the third party's product. If your practice management system has a defect, the provider can evidence it, escalate it and work around it, but only the vendor can fix it. ### Managed Firewall URL: https://systechitsolutions.co.uk/services/managed-firewall A fully managed firewall built in-house: continuous monitoring, automated config backup, managed patching and 24/7 support. Watched, not just installed. A bespoke firewall monitoring and backup service, developed and built in-house by our own team. A firewall you configured once and haven't looked at since isn't protecting you the way you think it is. It's ageing, drifting out of policy, and one missed patch away from being the incident. This service is for you if: - Your firewall was set up once, possibly by someone who's since left - Nobody could tell you the last time firmware or rules were reviewed - You want a perimeter that's actively monitored and backed up, not just switched on - You have an in-house IT team already, but firewall change control and 24/7 alert triage specifically isn't where you want their time going The cost of doing nothing: DIY firewall management looks cheaper right up until a missed patch, an undetected rule change or configuration drift turns into a network-down incident, at which point the savings evaporate in downtime and emergency support. Most businesses only discover the gap after something has already gone wrong. #### Your perimeter, fully managed Your firewall is the front door to your network, and it deserves more than set-and-forget. Our bespoke, in-house built platform continuously monitors your firewall estate, backs up configuration automatically, and keeps policy tight and current. Because we built it ourselves, we can tailor monitoring and reporting to exactly what your business needs, without paying for a bloated third-party product you'll never fully use. This is a standalone service, not a package deal: plenty of our managed firewall clients have their own in-house IT team already and simply hand us this one piece, backup, monitoring, patching and change control, so their team's time goes elsewhere. What's included: - Proprietary monitoring and backup platform, built in-house - Automated configuration backup and rapid recovery - Full change control: every rule change reviewed, approved and logged with an audit trail - Monthly traffic, threat and compliance reporting - Managed rules, patching and firmware updates - 24/7 monitoring and rapid response - Tailored alerting and escalation to suit your team #### What does a managed firewall service actually cover, end to end? Plenty of arrangements described as managed cover two or three of those. The gaps are usually patching, backup and out-of-hours cover, which are precisely the three that only matter on the day they are missing. The sequence we work through is the same each time. An assessment of what you already run, so we take over from a known position rather than a guess. Then hardening and remediation of whatever that surfaced, agreed with you before anything changes. Then the platform goes on: monitoring, automated configuration backup and alerting tuned to how you actually want to be told about a problem. After that it becomes a routine rather than a project, with patching on an owned schedule, rule changes going through change control, and monthly reporting covering traffic, threats and compliance in plain terms rather than a raw log dump. #### What does the onboarding assessment look for? The things that have drifted, because a firewall in service for a few years has almost always drifted. We read the rule base end to end and look for rules with no owner and no comment, rules referencing hosts or subnets that no longer exist, rules created as a temporary exception years ago, permissive any-to-any entries, and management interfaces reachable from more places than they need to be. We hand that back as a written picture before touching anything, separating what is genuinely urgent from what is untidy. Some of what we find is fine, and we say so rather than manufacturing work. Where hardware is genuinely end-of-life we will tell you plainly and plan a replacement rather than selling you kit you do not need, and where it has life left we take over what you already own. The assessment also establishes the baseline the change log is measured against, which matters later: without a starting point, no audit trail can tell you what actually changed. #### Why do firewall rule bases decay, and what does that look like? Because rules get added under pressure and almost never get removed. A supplier needs access for a project, a new application needs a port opening this afternoon, someone is troubleshooting at eight in the evening and widens a rule to prove where the problem is. Each of those is reasonable in the moment. What makes them a problem is that the project ends, the application is decommissioned and the troubleshooting finishes, and nobody goes back. Rules accumulate over years until the base is longer than anyone will read, which is when people stop reading it. Three specific patterns cause most of the damage. Broad any-to-any rules, usually added to unblock something quickly and left in place because removing them feels riskier than leaving them: they defeat the point of a rule base by making everything below them irrelevant. Rules pointing at IP addresses that have since been reissued to something else entirely, so access intended for one system now reaches another. And rules that only one person understood, who has since left, which is why nobody will delete anything. The cure is unglamorous: a scheduled review, an owner and a business justification recorded against every rule, and a written change history so removal is a decision rather than a gamble. #### Why does outbound traffic matter as much as inbound? Because most incidents involve traffic leaving, not arriving. Blocking inbound connections is the job everybody understands and most firewalls do reasonably well out of the box. What is far less often configured is egress filtering: controlling what your own network is allowed to talk to on the way out. An intrusion that starts with a phishing email or a compromised laptop does not need an inbound rule at all, because the device is already inside. What it does need is a route out to command and control infrastructure, and then a route out for whatever data is being taken. Default outbound-allow is the norm because it never causes a support ticket, which is exactly why it survives. Tightening it is genuine work: you have to know what your systems legitimately talk to before you can restrict them, and getting it wrong breaks things visibly. Done in stages it is one of the higher-value changes available on a perimeter, particularly restricting which internal systems may reach the internet directly at all, and alerting on outbound traffic to destinations and at times that do not fit the pattern. It also converts the firewall from a device that only blocks known bad things into one that tells you when something unexpected is happening. #### Who owns firmware patching, and what happens when nobody does? In most DIY setups the honest answer is nobody, and it is rarely a decision anyone made. Firewall firmware updates carry real risk of disruption, so they get deferred until things are quieter, and things are never quieter. Weeks become months, the appliance falls several releases behind, and the version running is one nobody would deliberately choose. A firewall running old firmware is not a cost saving. It is a known door left ajar, on the one device whose entire purpose is to be the door. Out-of-band vendor advisories for actively exploited vulnerabilities get treated differently again, because those are the ones where waiting for the next comfortable window is the wrong call. The reason we can hold a schedule is that it is our job rather than the eleventh item on someone else's list. #### What does change control on a firewall actually involve? A request, a review, an approval, a record. Every rule change is raised with a stated business reason and a named requester, reviewed for whether the change is as narrow as it can be, approved by someone other than the person who wants it, implemented, and then logged with what changed, who asked, who approved and when. That sounds bureaucratic for a small business until the first time somebody asks why a port is open, and the difference between an answer and a shrug is whether that record exists. The records earn their keep in three specific situations. During troubleshooting, because the first question when something stopped working on Tuesday is what changed on Monday. During an audit, an insurance renewal or a customer security questionnaire, where evidence that changes are controlled is worth more than a description of your intentions. And during an incident, when reconstructing what the perimeter looked like at a point in time is the difference between an investigation and speculation. Requests to add a rule with an expiry date are worth encouraging as well, because a rule created to expire is the only kind that reliably gets removed. #### Why is configuration backup the part people most often miss? In a typical DIY setup none of that exists anywhere except on the box itself. When the box fails, recovery is not a restore. It is a rebuild from memory, under pressure, while the business is offline, by whoever is available rather than whoever built it. Automated backup off the device changes the shape of that day entirely: you replace the hardware, restore the last known-good configuration, and verify. It also gives you something a one-off export does not, which is a history. Being able to compare today's configuration with last month's tells you what has changed, whether that change was approved, and lets you roll back a specific alteration rather than the whole device. Backups need to live somewhere separate from the network they protect, and they need to be restored occasionally rather than merely taken, because a backup nobody has restored is an assumption with a schedule attached. On our managed service that backup runs weekly, alongside daily infrastructure checks and continuous monitoring, with firmware handled on a planned quarterly cycle rather than whenever a release appears. It is worth asking any provider for those numbers specifically, because the common answer is that it happens when somebody remembers, and that is not a schedule. #### What does 24/7 firewall monitoring catch that business-hours checking does not? The things that happen in the gaps, which is most of the week. Evenings, weekends and the small hours are not quiet on a network: they are when scheduled tasks run, when backups compete for bandwidth, when automated scanning is heaviest, and when an intruder would prefer to be working. A DIY setup where somebody reviews logs when they have a spare moment is not monitoring, it is sampling, and it samples exactly the hours when the least is happening. Alerting is then tuned to how your team actually wants to be told, which is the point of having built the platform ourselves rather than reselling a generic product with somebody else's idea of an alert threshold. #### What happens when licences, subscriptions and hardware quietly expire? The firewall keeps passing traffic, which is the problem. Most modern appliances split their capability between the base device and subscription services layered on top, so intrusion prevention, content and web filtering, application control and threat intelligence feeds typically renew annually rather than being permanent. When one lapses the device does not stop: it carries on forwarding packets, with a feature you are still describing in your security documentation now doing nothing, or running on signatures that stopped updating months ago. Nobody notices, because nothing broke. Hardware end-of-life works the same way and matters more. Once a model passes its vendor support date there are no further firmware updates, which means the next vulnerability published against it is permanent. That is not only a security position, it is a compliance one: Cyber Essentials requires software in scope to be within vendor support, so an unsupported appliance can fail an assessment you were treating as a formality, at the point a contract depends on it. Tracking renewal and end-of-life dates ahead of time is dull, unglamorous administration, which is precisely why it is one of the first things to fall off an in-house list. #### How does the firewall fit into Cyber Essentials? Inbound rules need a documented business case, and rules that are no longer needed have to be removed, which is where a decayed rule base and an absent change log both become audit findings rather than untidiness. The theme most likely to catch a firewall out, though, is security update management, because it requires that software in scope stays within vendor support and that critical and high-severity updates are applied within fourteen days. Firmware counts. An appliance several releases behind, or a model past its end-of-support date, is a problem for that control regardless of how well the rules are written. Cyber Essentials Plus goes further and tests rather than takes your word for it. Systech is an accredited Cyber Essentials provider and holds the certification itself, alongside ISO 27001 and ISO 9001, so this is a standard we are assessed against rather than one we only advise on. #### Managed or DIY: where does the crossover actually sit? Not at a headcount, and not at a site count. The threshold to watch for is the moment firewall upkeep stops being somebody's clearly-owned job and becomes nobody's, which is what quietly happens as a network grows. A very small business, single site, simple network, with an IT person who genuinely has the time and the specialism to own the firewall properly, can run it themselves and the saving is real. That is a legitimate position, and we will say so. The risk is manageable when the ownership is genuine rather than assumed. What tips it is that firewall management is not a monthly task, it needs attention every week, and it needs a specialism a generalist has to context-switch into. It is rarely anyone's full-time job, so it competes with everything more visible and loses. The real cost of DIY is not the time it takes while everything is working. It is the outage, or the breach, that lands on the one week nobody was watching. That is the gap this service was built to close, which is also why plenty of our managed firewall clients have a capable in-house IT team and simply hand us this one piece. #### Frequently asked questions **What's the difference between a managed firewall and just having a firewall?** Having a firewall means the hardware is in place. A managed firewall means it's continuously monitored, its configuration is backed up, its firmware and rules are patched and reviewed on a schedule, and someone is watching alerts around the clock, so drift and missed updates never become the incident. **We already have an in-house IT team, can you still help?** Yes, and it's a common setup for us. Your team keeps everything else and we take over the firewall estate specifically: monitoring, backup, patching and change control, with a full audit trail of every rule change. It's a co-managed arrangement, not a replacement for your team, and it's usually the single most time-consuming, specialist piece to keep on top of properly. **Do you support our existing firewall, or do we need new hardware?** In most cases we can take over monitoring, backup and management of your existing firewall estate. Where hardware is genuinely end-of-life we'll tell you plainly and plan a replacement, rather than selling you kit you don't need. **What happens if the firewall fails?** Because we back up configuration automatically, recovery is a restore rather than a rebuild from scratch. Combined with 24/7 monitoring, that means failures are caught fast and resolved without days of reconfiguration. **How often should firewall rules be reviewed?** On a defined cycle rather than when something breaks, and the cycle matters less than the fact that one exists. What makes a review useful is having an owner and a business justification recorded against every rule, so the question during the review is whether each one is still needed rather than whether anyone dares remove it. Rules created for a project, a supplier or a piece of troubleshooting should carry an expiry date from the start, because a rule created to expire is the only kind that reliably gets removed. **What's actually wrong with an 'any to any' rule?** It makes everything beneath it irrelevant. A rule base is evaluated in order, so a broad permit rule near the top means the carefully written rules below it are never reached, and you now have a perimeter that behaves nothing like the one your documentation describes. They almost always start as a temporary measure to unblock something quickly, then survive because removing them feels riskier than leaving them. Replacing one safely means finding out what traffic it is actually carrying first, which is exactly the work that gets skipped when nobody owns the device. **Do we still need a firewall if everything is in Microsoft 365?** Yes, though its job changes. When applications move to the cloud, identity becomes the primary perimeter and Conditional Access does work the firewall used to, so the firewall stops being the single line of defence. What it still does is protect everything that never moved: the network your devices, printers, servers, cameras and any operational equipment sit on, the site-to-site links between offices, and above all the outbound path an intrusion needs in order to reach anything. Cyber Essentials also still requires every in-scope device to be behind a correctly configured boundary or software firewall. **Does a managed firewall help with Cyber Essentials?** It addresses one of the five control themes directly and supports another. The firewalls theme requires correctly configured boundary or software firewalls, default administrative passwords changed, no unnecessary services exposed, inbound rules documented with a business case, and rules removed once they're no longer needed. Security update management then requires the device to stay within vendor support with critical and high-severity updates applied within fourteen days, which catches appliances several firmware releases behind or past their end-of-support date. Managed patching, change control and an audit trail turn all of that from an assertion into evidence. **Who approves a rule change, us or you?** You do, and that boundary is deliberate. We review the request, tell you plainly whether it can be narrower than asked, implement it and log it, but opening a route into your network is a business decision and it stays yours. The record then names who requested it, who approved it, what changed and when. Approval routes are agreed at onboarding, including who can authorise an urgent change out of hours, because the time to decide that is not while an outage is running. ### Security Services URL: https://systechitsolutions.co.uk/services/security Microsoft 365 security assessment plus layered cyber security for UK businesses: Managed Firewall, EDR, XDR, 24/7 threat management and Cyber Essentials. Managed Firewall, EDR, XDR and round-the-clock threat management, layered together instead of bought as disconnected tools. Most breaches don't start with a sophisticated attack. They start with an unused MFA setting, a forgotten guest account, or a Conditional Access policy nobody finished configuring. This service is for you if: - You've bought security tools over time but nobody's watching them as a whole - You run Microsoft 365 but have never had a formal review of the tenant's security posture - You need Cyber Essentials or Cyber Essentials Plus for a contract, insurer or supply chain The cost of doing nothing: Microsoft 365 ships secure defaults, but almost nobody runs them by default: MFA gaps, stale guest access, unmonitored admin roles and unlabelled sensitive data build up quietly until an incident forces the audit. Point tools bought in isolation leave exactly the seams attackers look for. #### Resilient and compliant by design Security isn't a product you buy once, it's a posture you maintain. We bring Managed Firewall, endpoint detection and response (EDR), extended detection and response (XDR) and 24/7 threat management together with Microsoft 365 security and proven frameworks, so nothing sits as a gap between tools nobody's watching as a whole. Whether you're chasing Cyber Essentials certification or hardening your Microsoft tenant, we bring the expertise and the ongoing vigilance to keep your business protected, correlating signals across your perimeter, endpoints and cloud rather than reviewing them in isolation. What's included: - Managed Firewall as part of one joined-up perimeter, not a standalone box - Endpoint Detection and Response (EDR) across every device - Extended Detection and Response (XDR) correlating signals across endpoint, identity, email and cloud - 24/7 threat management, detection and incident response - Independent penetration testing through our CREST-approved partner Punk Security - Cyber Essentials and Cyber Essentials Plus - Microsoft 365 security: Defender, Purview and conditional access #### Antivirus, EDR, XDR and MDR: what's the difference in plain terms? Traditional antivirus asks whether a file matches something known to be bad, and blocks it if so. That works against commodity malware and fails against anything novel or anything that does not involve a file at all, which describes most modern intrusions: attackers increasingly use legitimate administrative tools already present on the machine, so there is no malicious file to match. EDR, endpoint detection and response, changes the question from what a file is to what a process is doing: it records behaviour on the endpoint, flags sequences that look like an attack even when every individual component is legitimate, and gives a responder the ability to isolate the machine. XDR extends the same idea beyond the endpoint by correlating signals across identity, email, cloud applications and infrastructure. This matters because a real intrusion is a sequence, not an event: a phishing email, then a sign-in from an unusual location, then a mailbox rule that hides the attacker's replies, then access to a file share. Reviewed separately, each is a low-priority alert somebody closes. Correlated, they are one obvious incident. MDR is the separate question of who is watching: a managed service where humans triage and respond, rather than a product that generates alerts into a queue. EDR and XDR are capabilities; MDR is staffing. #### What do the five Cyber Essentials controls actually require? Cyber Essentials covers five control themes, each with specific technical requirements rather than general aspirations. Firewalls: every device protected by a correctly configured boundary or software firewall, with default administrative passwords changed and no unnecessary services exposed. Secure configuration: remove or disable unused accounts and software, change default passwords, disable auto-run. The requirement that catches most applicants out is the last one, because it applies to all software, not just operating systems, and because unsupported software is an automatic fail whether or not it is patched. Scope is the other stumbling block: home workers' devices, mobile phones used for work email and cloud services all fall in scope in ways organisations do not expect. Certification is a self-assessment verified annually, and the question set is revised periodically, so answers that passed two years ago may not pass now. Cyber Essentials Plus adds independent technical verification: an assessor testing your actual devices rather than reading your description of them. #### Why isn't MFA on its own enough any more? Because attackers adapted. Multi-factor authentication remains the single highest-value control you can deploy and stops the overwhelming majority of password-based attacks, but three techniques now routinely defeat basic implementations. Adversary-in-the-middle phishing proxies the real login page, captures the session token after you have completed MFA, and replays it: the attacker never needs your password or your code. MFA fatigue pushes repeated approval prompts until a tired user taps accept. And SIM swapping undermines SMS as a factor, which is why SMS is the weakest option still in common use. Conditional Access is what turns authentication from a single gate into a policy decision. Rather than asking only whether the credentials are correct, it evaluates the whole context of the sign-in and applies the appropriate requirement or blocks it. The highest-value policies are requiring a compliant or managed device for access to company data, blocking legacy authentication protocols that cannot enforce MFA at all, and requiring phishing-resistant methods such as passkeys or FIDO2 security keys for administrators. Every organisation should also keep excluded break-glass accounts with long unique credentials stored offline, because a policy that locks out every administrator is a self-inflicted outage that happens more often than anyone admits. #### Why is email still the main way attackers get in? Because it is the one system that must accept unsolicited content from strangers by design. Every other route can be closed; email cannot be. The attacks that succeed are rarely the crude ones. Business email compromise involves no malware at all: the attacker gains access to a mailbox, watches genuine conversations for weeks, then intervenes in a real invoice thread with amended bank details. Because the message comes from a legitimate account, in an existing thread, with correct context, no technical control reliably distinguishes it from the real thing. Supplier compromise works the same way from the other end, which is why 'the email came from our supplier's real address' describes the attack rather than a defence. On the process side, and this is the one that stops the loss: a bank detail change must be verified by telephone on a number already held on file, never a number from the email. Most successful invoice frauds would have been prevented by a single phone call. #### Why is backup a security control rather than just an IT one? Backups that are online, reachable from the same network and accessible with the same domain credentials as everything else are not a recovery position; they are simply more data waiting to be encrypted. The controls that matter are immutability, separated credentials that are not domain accounts, and at least one copy that is offline or logically isolated. The second half is testing. A backup job reporting success proves that data was written, not that a business can be restored from it. Restore testing is the only evidence that matters, and it should answer specific questions: how long a full restore actually takes against the recovery time the business assumed, whether application-consistent restores of databases work, and whether the documentation needed to run the restore is itself stored somewhere that will survive the incident. Extortion has also shifted toward data theft as well as encryption, so backup solves availability but not confidentiality. #### What does 24/7 threat management involve in practice? It means three distinct things, worth separating when comparing providers. Monitoring is collecting and watching telemetry from endpoints, identity, email, cloud and network continuously. Detection is the analytics that turn that telemetry into a prioritised signal, which is where most of the engineering value sits, because raw alert volume from a modern estate is far beyond what any team can read. Response is what happens next: triage to establish whether an alert is real, then containment actions such as isolating a device, disabling an account or revoking active sessions. A service that monitors and detects but escalates every decision back to a customer who is asleep has not solved the out-of-hours problem it was bought for. The questions worth asking are therefore about authority and escalation rather than about tooling. Which containment actions can be taken without waiting for your approval, and which always require it? Who gets contacted at three in the morning, and what happens when they do not answer? Is the underlying tooling yours or the provider's, and what happens to your historical telemetry if you change supplier? How long is data retained, and is that long enough for investigation given that attackers commonly dwell for weeks before acting? #### Managed security services, MSSP, SOC-as-a-service: what do the labels mean? They overlap enough to be genuinely confusing, so here is the plain version. A managed security service provider, or MSSP, is a company that runs some or all of your security controls for you rather than selling you the tools to run yourself. SOC-as-a-service is narrower: the monitoring, detection and response function of a security operations centre, bought as a service instead of staffed in-house. Managed detection and response, or MDR, is SOC-as-a-service with the response part explicitly included rather than stopping at the alert. The distinction that actually matters when you are buying is where the work stops. Some managed security services end at a dashboard and a monthly report, which leaves the hardest part, deciding what to do about an alert at two in the morning, exactly where it was. Ask what happens between detection and resolution, who is authorised to act, and what the response commitment is outside business hours. That answer separates providers far more reliably than any list of tooling. What we do sits in that space and we would rather describe it than badge it: Microsoft 365 and Entra ID hardening, Defender deployed and tuned rather than left at defaults, 24/7 threat monitoring with response, email security, backup treated as a security control, and Cyber Essentials or Cyber Essentials Plus certification where you need to evidence it to a client or an insurer. If you are comparing us against an MSSP or a SOC-as-a-service provider, those are the same questions to put to us. #### Where do most Microsoft 365 tenants have gaps? The recurring findings are remarkably consistent. Legacy authentication protocols still enabled somewhere, which lets an attacker bypass MFA entirely. Global Administrator assigned permanently to more people than need it, often including a departed supplier. Guest accounts accumulated over years, with nobody able to say who invited them. Third-party application consents granted by users, giving applications standing access to mail and files that survives a password reset. Mailbox auditing not fully enabled, so there is no record when an investigation is needed. Anonymous sharing links with no expiry, created years ago and still live. None of these are exotic and all are visible to anyone who looks systematically. The reason they persist is not incompetence but drift: a tenant is configured correctly at a point in time, then absorbs three years of pragmatic exceptions and defaults that changed on Microsoft's side without anyone reviewing the impact. Microsoft's Secure Score is a reasonable starting map but not a target to be maximised, because some recommendations do not fit every organisation and chasing the number rather than the risk produces controls that get switched off the first time they inconvenience someone senior. #### Frequently asked questions **What's the difference between EDR and XDR?** EDR (Endpoint Detection and Response) watches and responds to threats on individual devices. XDR (Extended Detection and Response) correlates signals across endpoints, identity, email and cloud so an attack that touches several of them is seen as one story, not four unrelated alerts. We run both, joined up. **Can you help us get Cyber Essentials certified?** Yes. We assess you against all five Cyber Essentials control themes, close the gaps, and guide you through both Cyber Essentials and the independently audited Cyber Essentials Plus, which is increasingly required for public-sector and supply-chain contracts. **Do you provide 24/7 threat monitoring?** Yes. Our threat management runs around the clock, with detection, triage and incident response, so a security event at 2am on a Sunday is caught and acted on, not discovered on Monday morning. **Does holding Cyber Essentials mean we're secure?** It means you have a verified baseline, which is genuinely worth having, but it is a floor rather than a ceiling. Cyber Essentials addresses the commodity attacks that make up the bulk of incidents. What it does not cover is detection and response, backup and recovery, security monitoring, staff awareness, supplier risk, or incident planning: a certified organisation can still be breached and, without those, may not know for weeks. Treat certification as evidence that the basics are in place and as a procurement requirement you can now satisfy, not as a statement that the risk has been dealt with. **Is cyber insurance a substitute for security controls?** No, and increasingly it is conditional on them. Insurers now ask detailed technical questions at renewal (multi-factor authentication coverage, endpoint detection, offline or immutable backups, patching cadence, whether unsupported software is in use) and price or decline on the answers. Two practical risks follow. First, answering optimistically can leave a claim disputed at exactly the wrong moment, since the declaration forms part of the contract. Second, policies commonly limit losses arising from controls you said were in place and were not. Insurance transfers residual financial risk; it does not transfer the operational disruption or the notification obligations. **Do we need a penetration test or a vulnerability scan?** They answer different questions and are not interchangeable. A vulnerability scan is automated, broad and repeatable: it enumerates known weaknesses and is best run regularly, because its value is in trend and coverage rather than depth. A penetration test is a human exercise where a tester chains findings together to demonstrate what an attacker could actually achieve, which surfaces logic flaws and privilege escalation paths no scanner reports. If you have never scanned, start there. Add penetration testing when you have a specific question worth answering, and keep testing independent of whoever configured the environment. **What should we do first if we think we've been breached?** Contain without destroying evidence, and start the clock on your obligations. Isolate affected devices from the network rather than powering them off, since shutting down discards memory that may be the only record of what ran. Do not wipe and rebuild before anyone has looked. Reset credentials for affected accounts and, critically, revoke active sessions and tokens as well, because a password change alone does not evict an attacker holding a valid session. Preserve logs immediately. Then start the reporting assessment: if personal data is involved, UK GDPR requires notification to the ICO within 72 hours of becoming aware where the breach poses a risk to individuals. **Are Macs and mobile devices covered by endpoint security?** They can be and they should be, though coverage differs by platform. macOS is fully supported by mainstream endpoint detection and response tooling and needs it: the belief that Macs are not targeted has not been true for years. Mobile devices work differently: iOS and Android are more constrained by design, so protection focuses on mobile threat defence, separation of work and personal data, and enrolment into management so a lost phone can have company data removed without wiping personal photos. The gap worth checking is whether unmanaged personal phones can currently reach company mail and files, because in most tenants they can unless a Conditional Access policy says otherwise. **Does moving to Microsoft 365 make us more or less secure?** More secure than a neglected on-premises environment, and less secure than people assume, because the risk changes shape rather than disappearing. You gain a platform patched by Microsoft, resilient infrastructure, and access to detection capability no mid-sized organisation could build alone. What you take on is that your data is now reachable from anywhere with valid credentials, which makes identity the perimeter: a single compromised account with no Conditional Access is an intrusion with no network to breach. Cloud makes strong security achievable at a price point that was previously out of reach; it does not make it automatic. ### Compliance Packs & Audit Readiness URL: https://systechitsolutions.co.uk/services/compliance-packs IT and security policies, procedures, SOPs and audit evidence, built around your real estate. For Cyber Essentials, ISO 27001, SOC 2 and the DSP Toolkit. The IT and security half of your compliance: policies, procedures, SOPs and the evidence an assessor asks IT for, generated around your actual estate rather than bought as templates. Compliance lands on IT without ever really being IT's project. Somebody signs a contract, a framework arrives with a date attached, and the person who has to evidence access reviews and patching is the person already running the estate. This service is for you if: - Compliance has landed on IT and you are the one who has to evidence access reviews, patching and backups - You need the IT and security documents for Cyber Essentials, ISO 27001, SOC 2, the DSP Toolkit or a client's security questionnaire - You have bought template packs before and found they still needed days of rewriting to describe your estate - You want to run internal audits and close gaps yourself, before an assessor or a customer does it for you The cost of doing nothing: Compliance work stalls in the gap between a generic template and a document that describes how your estate actually runs. Policies go stale, evidence is scattered across inboxes and ticket histories, and the first time anyone checks whether it hangs together is the week of the audit, or the day a prospect sends a 200-question security questionnaire to whoever answers those. The cost is not just the scramble, it is the contract you cannot bid for because nobody can produce the paperwork. #### Audit-ready, without the template treadmill We cover the IT and security side of compliance: the access control, asset, patching, backup, incident response, change and supplier documents an assessor asks IT to produce, along with the registers and records that prove they are being followed. Generated with EtherAssist around your actual systems and the framework you are targeting, rather than started from a blank page or reverse-engineered out of a template. From there it becomes a living posture rather than a one-off document dump. Run internal audits and self-assessments in seconds, see where the gaps are, generate the evidence to close them, and keep it current as the estate changes, so Cyber Essentials, ISO 27001, SOC 2 or a customer's security review is a formality rather than a fire drill. Where a framework reaches past IT, and most do, we tell you which parts are yours to own rather than quietly leaving them out. What's included: - IT and security policies, procedures and SOPs written around your estate, not bought as templates - Compliance packs mapped to your framework: Cyber Essentials, ISO 27001, SOC 2, DSP Toolkit and more - Internal audits and self-assessments you can run yourself, on demand - Gap analysis with a prioritised, plain-English list of what to fix first - Audit-ready evidence packs for assessors and customer security questionnaires - Living documents that stay current as your systems and controls change - A clear split of what IT owns and what the wider business owns, agreed up front - Delivered with EtherAssist and backed by our security team's hands-on remediation #### What is actually in a compliance pack? Four layers, and most packs sold as complete only contain the first. Policies state what your organisation has decided and who is accountable. Procedures describe how each decision is carried out. Standard operating procedures take the tasks that must be performed identically every time and write them down step by step, so the outcome does not depend on which person did it. Those are what an assessor asks to see when they want proof rather than intent. Behind all four sits the thing a pack has to do that a document set on its own cannot, which is stay true. A compliance pack has three jobs: describe your controls accurately, prove those controls actually work, and stay current as your environment moves. A folder of documents does the first job approximately, does nothing for the second, and starts failing the third the week after it is written. That is why we treat the pack as a live artefact tied to the framework you are being measured against, rather than a deliverable that gets signed off and filed. #### Is this IT compliance or company-wide compliance? IT compliance, and the distinction is worth settling before you buy anything, because most frameworks reach further than the IT estate and almost every supplier is vague about where they stop. What we cover is the part an assessor asks IT to produce and evidence. That is the substantial half of Cyber Essentials, most of the Annex A controls in ISO 27001 that anyone actually gets audited on, and nearly all of a customer security questionnaire. What is not ours is the rest of the organisation: HR policy and employment matters, finance controls and segregation of duties, health and safety, quality management, and the business continuity planning that covers premises and people rather than systems. Those belong to the people accountable for them, and a supplier who offers to write your HR policy alongside your firewall configuration standard is selling documents rather than compliance. That is a boundary on who does the work, not on what the platform can produce. EtherAssist generates documents for those wider areas perfectly well, and businesses use it that way, so if you want one place for the whole set it is available to you. What changes outside IT is that somebody in the business has to own the content, because a policy nobody in that function agreed to is exactly the kind of document that fails an audit for being unevidenced. #### Policies, procedures and SOPs: what is the difference and why does it matter? A policy is a decision with an owner. It says what your organisation permits and requires, and it should be short, readable and approved at the right level, because it is a management commitment rather than a technical manual. An access control policy states that access is granted by role, reviewed periodically and removed on the day someone leaves. It does not say which button to press. Policies change rarely and are the documents an auditor traces accountability through. A procedure explains how the policy is met in your environment, naming the systems, the roles and the steps. An SOP goes narrower still: a repeatable task written so anyone competent can perform it identically, which is what you want for joiners and leavers, restore tests, access reviews and incident triage. The distinction matters for a practical reason rather than a pedantic one. Organisations that collapse all three into one document end up with a policy so detailed it is wrong the moment a system changes, and so long that nobody reads it, which is the fastest route to a control that exists on paper and nowhere else. Keep the policy stable, let the procedure move with the environment, and keep the SOP where the person doing the work will actually find it. #### Why do off-the-shelf template packs fail? Because they solve the wrong part of the problem. You download a zip of thirty Word documents for a few hundred pounds, and every one of them needs your systems, your roles, your sector and your framework threaded through it. The pack promised to save you weeks and instead hands you a fortnight of rewriting, which is why so many sit half-finished with the placeholders still in them. A generic policy that describes systems you do not run and omits the ones you do is not evidence. It is a liability with your logo on it, and an assessor reading it will reach that conclusion faster than you would like. The second failure is decay. Most template packs are out of date within a year, which is precisely the window in which your next audit, renewal or customer questionnaire lands. You migrate to a new firewall, adopt Intune, change backup provider or bring on a new SaaS platform, and every document referencing the old arrangement is now wrong. Fixing that manually means hunting through thirty documents for every stale reference, which nobody does, so instead the pack quietly becomes fiction. Generating the pack around your real context, and regenerating it when the context changes, removes both problems at once: it fits from day one, and keeping it true is a task measured in minutes rather than weekends. #### What is policy-reality drift, and how do you catch it? It is the gap between what your documents say you do and what your systems are actually configured to do, and it is the single most common finding when we assess an organisation that considers itself compliant. The pattern is always the same. The policy says access is reviewed quarterly and the last review was fourteen months ago. It says multi-factor authentication is enforced on all accounts, and it is enforced on all accounts except three service accounts and a shared mailbox somebody excepted during a rollout. It says backups are tested, and nobody can produce a record of a test. None of these are dishonesty. They are what happens when documents and reality are maintained by different people on different timescales. Drift is caught by checking, and by checking on a schedule rather than when something prompts it. The useful mechanism is an internal audit that samples the actual state of controls against what the documents claim, produces a prioritised list of differences, and forces an explicit decision on each one: fix the reality, or change the document because the documented control was never realistic. Both are legitimate outcomes. What is not legitimate is leaving the two apart, because the moment an assessor or a customer's security team compares them, your paperwork has become evidence against you rather than for you. #### What evidence do assessors and customers actually ask for? Almost none of this is difficult to produce as it happens, and almost all of it is painful to reconstruct afterwards. This is where most organisations are genuinely weakest, because evidence lives scattered across inboxes, shared drives and half a dozen admin consoles rather than anywhere a person could assemble it from. The result is a familiar scramble: the week before the audit, someone spends three days screenshotting admin portals to prove things that were true all along. The same problem shows up commercially when a prospect sends a two-hundred-line security questionnaire that is now blocking a deal, and the answers exist only in the heads of two people who are busy. Deciding in advance where the evidence for each control lives, and who owns producing it, compresses that from weeks into an afternoon. #### How does an internal audit actually work? You test your own controls against your own documented requirements, before someone external does it for you. In practice that means working through the framework control by control, asking what the documents say should happen, gathering the evidence that it did happen, and recording the difference where it did not. The output is a prioritised, plain-English list of what to fix first, ranked by exposure rather than by how easy each item is. Doing it yourself in an afternoon rather than waiting a week for a consultant's report is the difference between an internal audit being a routine and being an event. The worst time to discover a gap is when someone else finds it: an assessor mid-certification, an insurer at renewal, or a prospect three questions into a security questionnaire. Two disciplines make the exercise worth the time. First, audit against evidence rather than against memory, because asking whether you do something reliably produces the answer yes. Second, close the loop: every finding needs an owner, a date and a record that it was actually resolved, because an audit that produces findings nobody tracks has generated paperwork rather than improvement. For ISO 27001 specifically the internal audit programme is not optional, it is part of what the certificate is awarded for. #### Where does this fit on a Cyber Essentials journey? Cyber Essentials is a self-assessment across five control themes, firewalls, secure configuration, security update management, user access control and malware protection, verified by an accredited certification body that reviews your answers. Nobody logs into your systems to confirm what you have said is true, which makes the documentation and evidence behind your answers the thing worth getting right, because you are certifying that a state of affairs exists. The requirements that most often catch applicants out are that all software in scope must remain within vendor support, and that critical and high-severity updates are applied within fourteen days. It must be completed within three months of achieving the base certificate, so the two are best planned as one sequence. Systech is an accredited Cyber Essentials provider and holds the certification itself, and our security team closes the technical gaps rather than only documenting them. #### Where does this fit on an ISO 27001 journey? ISO 27001 is a meaningfully bigger undertaking, because it certifies an Information Security Management System rather than a checklist of technical controls. The management system is the risk assessment methodology, the Statement of Applicability, the documented policies, the internal audit programme and regular management review. You do not implement all 93 automatically: the Statement of Applicability is where you record, control by control, which apply to your scope and why any are excluded, and it is one of the first documents a Stage 1 auditor scrutinises. Certification runs in two stages and then recurs. Stage 1 is a documentation review asking whether the management system exists on paper and whether the scope and exclusions are justified. Stage 2 asks whether it actually operates as documented, with evidence, internal audits that have genuinely happened, management reviews that have genuinely taken place and corrective actions that were tracked. Then it becomes a three-year cycle: lighter surveillance audits in years two and three, and full recertification before the three years are up. Passing first time is almost always a preparation problem rather than a security problem, which is why organisations with sound technical controls still fail Stage 1. Systech holds ISO 27001 and ISO 9001, both certified by NDC Certification Services, so this is a cycle we run ourselves rather than only advise on, and we coordinate with an accredited certification partner for the formal audit rather than pretending to be one. #### What cannot be outsourced, whatever you buy? Accountability, and the decisions that carry it. A policy is a statement of what your organisation has decided, so someone in your organisation has to make and own that decision: whether personal devices may access company data, how long records are retained, who approves administrative access, what happens to data when someone leaves. Under UK GDPR you remain the data controller regardless of who administers the systems, and no supplier arrangement changes who a regulator, an insurer or a customer holds responsible. We can generate the documents, run the assessment, fix the technical controls and stand beside you at the audit. We cannot be the accountable owner. The practical version of this is that every policy needs a named internal owner who understands what it commits the business to, and that at least one person internally has to be able to answer questions about it without reading from the page. Assessors notice when nobody can. It is also why we would rather generate a shorter pack that reflects your actual operating model than a comprehensive one describing an organisation you are not, because the second kind produces confident documents and an internal team who cannot explain them. #### What does maintaining the pack look like after you are certified? It becomes a cycle rather than a project, and the cycle is where certificates are actually lost. An ISMS allowed to lapse quietly between surveillance visits is the most common way organisations lose a certificate they worked hard to earn: the internal audits stop happening, management reviews slip, and the evidence trail the next auditor asks for simply is not there. Cyber Essentials has its own version of the same problem, since it is verified annually and the question set is revised periodically, so answers that passed two years ago may not pass now. Maintaining it properly means a review cadence for the documents, an internal audit schedule that actually runs, evidence captured as it is produced rather than assembled retrospectively, and a trigger to regenerate affected documents whenever the environment changes materially: a new platform, a new supplier, a migration, an office move, a significant change in headcount. That last trigger is the one that keeps the pack honest, because environments change far more often than review dates come round. The practical benefit is that the next audit, renewal or customer questionnaire becomes a formality rather than a fire drill, which is the entire point of the exercise. #### Where does the platform stop and hands-on work start? Generating a policy does not make you compliant, and we are not going to pretend otherwise. Documents are the evidence layer; real compliance also needs the controls behind them to be in place and working. EtherAssist, the compliance platform from our partner EfficientEther, produces the policies, procedures, SOPs and audit evidence around your actual context and lets you run internal audits and self-assessments on demand, which handles the slowest and most painful part of the job. What it cannot do is enforce multi-factor authentication on the three accounts that were excepted, test-restore a backup that has never been restored, or close the hole in a Conditional Access policy. That is where our security team takes over: interpreting the gaps the self-assessment surfaces, remediating the technical controls, and being in the room for the certification audit itself. The division is deliberate and worth stating plainly when you are comparing suppliers, because a compliance offering that only produces documents leaves you with better paperwork and the same underlying risk, and a technical engagement with no evidence layer leaves you secure and unable to prove it. You generally need both, and they should be scoped together rather than bought from two suppliers who each assume the other did the difficult half. #### Frequently asked questions **What is the difference between Cyber Essentials and ISO 27001, and do we need both?** They answer different questions, which is why plenty of businesses end up holding both. Cyber Essentials is a UK government-backed scheme covering five specific technical controls: firewalls, secure configuration, user access control, malware protection and patch management. It is deliberately narrow, it certifies in weeks rather than months, and it is what most UK public sector frameworks and a growing number of private contracts actually ask for. ISO 27001 is an international standard for an information security management system, so it certifies the way you govern security as an ongoing process, not a fixed list of controls. It takes months, costs considerably more, and is usually driven by enterprise customers or overseas clients who expect it. Our honest advice for most SMEs is to start with Cyber Essentials, because it unlocks the contracts soonest, and to pursue ISO 27001 when a specific client or sector genuinely requires it rather than on principle. **Will a compliance pack get us through an ISO 27001 audit on its own?** No, and anyone telling you otherwise is selling you documentation rather than certification. A pack gives you the documented information ISO 27001 requires, the policies, procedures, statement of applicability and risk treatment records, which is genuinely the part most businesses find hardest to produce and keep current. What it cannot do is demonstrate the management system is actually operating: internal audits carried out, management reviews held, risks reviewed and corrective actions closed. An auditor checks for evidence of the system running, not just the existence of the documents describing it. Where we help is producing and maintaining the documentation, keeping it aligned as your estate changes, and working alongside your certification body or ISO consultant rather than pretending to replace them. **How is this different from buying an off-the-shelf compliance template pack?** Templates give you a generic starting point you still have to rewrite to match your business, your systems and the framework you're being assessed against. EtherAssist generates the policies, procedures and SOPs around your actual context in seconds, then keeps them current, so you get a pack that fits from day one instead of one you spend days reverse-engineering. **Do you write our HR, finance and health and safety policies too?** No, and it is worth being clear about that before you buy rather than at the audit. We cover the IT and security estate: access control, assets, patching, backup, incident response, change control, cloud and supplier security, and the records that evidence all of it. That is the part an assessor asks IT to produce, and it is most of Cyber Essentials, most of what gets audited in ISO 27001 and nearly all of a customer security questionnaire. HR, finance, health and safety and quality management stay with the people accountable for them. The platform itself is not the limit here: EtherAssist generates documents for those areas too and plenty of businesses use it that way, but somebody in that function has to own the content, because a policy nobody in the department agreed to fails an audit for being unevidenced rather than for being badly written. **Which frameworks and standards does it cover?** The common ones UK businesses get asked for: Cyber Essentials and Cyber Essentials Plus, ISO 27001, SOC 2, the NHS Data Security and Protection (DSP) Toolkit, and the ad hoc security questionnaires that prospects and insurers send. We map your pack to whichever framework you're targeting rather than a one-size-fits-all bundle. **Can we run our own internal audits, or do we need you every time?** You can run internal audits and self-assessments yourself, in seconds, whenever you need to, that's the point of self-service compliance. Our team is there for the parts that need hands-on work: interpreting the gaps, remediating technical controls, and standing beside you for the certification audit itself. **Does generating the documents actually make us compliant?** No, and we won't pretend it does. Documents are the evidence layer; real compliance also needs the controls behind them to be in place and working. EtherAssist gets the policies, procedures and audit evidence sorted fast, which is usually the slowest, most painful part, and our security team helps you close the technical gaps the internal audit surfaces. **What's the difference between a policy, a procedure and an SOP?** A policy is a decision with an owner: what your organisation permits and requires, approved at the right level and deliberately short. A procedure explains how that decision is met in your environment, naming the systems, roles and steps. A standard operating procedure goes narrower again: a repeatable task written so anyone competent performs it identically, which is what you want for joiners and leavers, restore tests and access reviews. Keeping them separate matters, because collapsing all three into one document produces something too detailed to stay accurate and too long for anyone to read. **How do we stop our policies drifting away from what we actually do?** By checking on a schedule instead of when something prompts it. Policy-reality drift is the most common finding we see in organisations that consider themselves compliant: the policy says access is reviewed quarterly and the last review was over a year ago, or says MFA is enforced everywhere except the three accounts someone excepted during a rollout. An internal audit that samples the actual state of controls against what the documents claim forces an explicit decision on each difference: fix the reality, or change the document because the control as written was never realistic. Both are valid; leaving the two apart is not. **Do we need internal audits if we're only going for Cyber Essentials?** You aren't required to run a formal audit programme the way ISO 27001 requires one, but self-assessing before you submit is still the cheapest thing you can do. Cyber Essentials is verified annually and the question set is revised periodically, so answers that passed two years ago may not pass now, and the requirements that catch people out (all in-scope software within vendor support, critical and high-severity updates inside fourteen days) are exactly the ones that drift quietly. Finding those yourself costs an afternoon. Finding them during a Plus assessment costs more time and money under audit pressure. **You hold ISO 27001 yourselves. Does that cover us?** No, and any supplier suggesting otherwise is worth questioning. Systech holds ISO 27001 and ISO 9001, both certified by NDC Certification Services, and Cyber Essentials with a certificate you can verify online. Those cover how Systech operates, which is a fair thing to weigh when you're assessing us as a supplier, and they mean the processes your work runs through are independently audited rather than self-declared. They are not a certificate you can present as your own. What they do give you is a partner who runs the same surveillance-audit cycle in-house rather than only describing it. **How often should the documents be reviewed?** On a fixed cadence, plus a trigger whenever the environment changes materially, and the second half is the one that keeps a pack honest. Environments change far more often than annual review dates come round: a new platform, a new supplier, a migration, an office move or a significant change in headcount can invalidate several documents at once. A pack that's regenerated when the context moves stays true between reviews. A pack reviewed only on its anniversary is accurate for one afternoon a year. ### Microsoft 365 URL: https://systechitsolutions.co.uk/services/m365 Microsoft 365 done properly: tenant migration, governance, Teams, SharePoint, identity and Intune, licence optimisation and ongoing UK-based support. Get the full value of Microsoft 365, deployed, governed and supported around how your teams actually work. Almost every business already pays for Microsoft 365. Far fewer actually use what they're paying for, most run a fraction of the platform while the security, governance and productivity gains sit switched off. This service is for you if: - You're on Microsoft 365 but suspect you're using a fraction of what you pay for - A migration, tenant merge or governance clean-up keeps getting put off - Teams, SharePoint and OneDrive have grown organically and now need real structure The cost of doing nothing: An unmanaged Microsoft 365 tenant drifts: sprawling SharePoint sites, oversharing nobody's audited, licences assigned and forgotten, and no clear owner for any of it. It works, until a security review, a leaver, or a Copilot rollout exposes exactly how loose it has become. #### Productivity, done properly Microsoft 365 is far more than email. We help you deploy, secure and get real value from the whole platform, from Teams and SharePoint to identity and device management. Migrations handled cleanly, governance set up correctly, and ongoing support so your people always have the tools they need to do their best work. What's included: - Tenant setup, migration and governance - Identity, Intune and conditional access - Teams telephony and collaboration - SharePoint and OneDrive information architecture - Licence optimisation and administration - Ongoing adoption and support #### Cutover or staged migration: which approach fits? The deciding factors are data volume, user count and how much downtime the business can absorb. A cutover migration moves everyone at a single point, usually over a weekend: mail flow switches once, there is one set of client reconfigurations, and by Monday everybody is on the new platform. It is simpler, cheaper and lower in coordination overhead, and it works well for smaller estates with manageable mailbox sizes. Its weakness is that it is a single event with no partial rollback: if something is wrong on Monday morning, it is wrong for everyone at once. A staged or coexistence migration moves users in batches while both environments run in parallel, with mail routing and, ideally, free/busy calendar lookup working across the boundary. It costs more in complexity and takes longer, but it lets you pilot with a tolerant group, catch problems while they affect ten people rather than three hundred, and pause. Choose it when mailboxes are large, when the migration window is constrained by throttling or bandwidth, when there are shared mailboxes and delegate relationships that must not break mid-move, or when the organisation genuinely cannot be offline. #### What does Microsoft 365 governance actually mean? Governance is the set of decisions about who can create what, who can share what with whom, and what happens to content over time. In a Microsoft 365 tenant it has three practical strands. Sharing: whether external sharing is permitted at all, whether links default to 'anyone with the link' or to named people, whether unauthenticated links expire, and whether guests can be invited by any user. The reason this matters more now than it did five years ago is that search and AI collapse the practical difference between 'technically accessible' and 'findable'. Content buried three levels deep in a forgotten site used to be effectively invisible; a semantic search surfaces it instantly. If a document was overshared in 2021 and nobody noticed because nobody knew the path, the exposure existed all along; Copilot simply makes it visible. Governance work is therefore not a tidy-up exercise, it is the prerequisite for turning anything on that reads across your data. #### Business Premium, E3 or E5: how do you decide? The first hard boundary is headcount: Microsoft 365 Business Premium is capped at 300 seats, so above that the choice is between E3 and E5 regardless of anything else. Below 300, Business Premium is unusually good value because it bundles the Office applications with a security stack most organisations otherwise buy separately: Intune for device management, Entra ID P1 for Conditional Access, Defender for Office 365 for link and attachment protection, and Defender for Business for endpoint detection and response. Bought as add-ons, that collection costs considerably more than the difference in seat price. The E3 versus E5 decision is mostly about whether you would otherwise buy the security and compliance components separately, and whether you have anyone to operate them. E5 adds Entra ID P2, which brings risk-based Conditional Access, Privileged Identity Management for just-in-time administrative access, and access reviews; it adds the higher Defender tiers and the fuller Purview capabilities. The honest test is whether those capabilities will be configured and monitored. E5 licences generating alerts nobody reviews are shelfware with a compliance story attached, and a mixed estate (E5 for administrators, finance and executives, E3 for everyone else) is often the right shape. #### Intune or Group Policy: do you need both? If your devices are domain-joined and never leave the network, Group Policy still works. If they are Entra-joined laptops that connect from home and only see a domain controller when someone happens to be in the office, Group Policy stops applying reliably and you are managing a fleet on trust. Migration is rarely a clean switch. Intune's settings catalogue and ADMX-backed policies cover the large majority of what most GPO estates actually use, and Group Policy analytics will import your existing GPOs and report what has a direct equivalent (a useful reality check, because most estates find a meaningful share of their policies are obsolete rather than untranslatable). What genuinely does not carry over are logon scripts that depend on domain resources, drive mappings to on-premises file servers, and policies for legacy applications that assume a domain context. #### How should Teams, SharePoint and OneDrive fit together? Each has one job, and most tenants get into trouble by blurring them. OneDrive is for work in progress that belongs to one person. SharePoint is the system of record for content the organisation owns, structured into sites that reflect how the business is organised. Teams is the collaboration surface over the top: every team you create silently provisions a Microsoft 365 group and a SharePoint site behind it, and the Files tab in a channel is a folder in that site. Understanding that relationship prevents the most common mistake, which is treating Teams and SharePoint as competing places to put things when they are the same place with two front doors. The structural decisions that matter are how many sites you create and how you handle permissions. Flat and broad beats deep and nested: a smaller number of purposeful sites with clear ownership is easier to secure and easier to search than a hierarchy that mirrors an org chart from three restructures ago. Permissions should be granted through groups rather than to individuals, and unique permissions on individual folders should be rare, because they are invisible to anyone browsing and become impossible to audit at scale. #### What actually breaks in a rushed migration? The failures are consistent, and almost all of them come from discovery that was skipped rather than execution that went wrong. Shared mailboxes and delegate access break when permissions are not mapped before the move, so a PA who has managed a director's calendar for years suddenly cannot see it. Distribution lists get missed. Public folders, which nobody remembers exist, turn out to hold a decade of shared correspondence. Applications, scanners, copiers and line-of-business systems that relayed mail through the old server stop sending, and nobody notices until an invoice run silently fails. The second category is identity and mail hygiene. If SPF, DKIM and DMARC are not corrected as part of the cutover, your legitimate mail starts landing in junk folders at exactly the moment the business is most sensitive to disruption. And if governance is deferred until after go-live, the tenant is built on defaults that permit broad external sharing and unrestricted site creation, which is far harder to unwind later than to set correctly at the start. The pattern is that migration problems are discovery problems. #### Does Microsoft back up your Microsoft 365 data? Not in the way most people assume. Microsoft's shared responsibility model makes them accountable for the availability and resilience of the service, and you accountable for your data within it. Recycle bins have finite windows, and once they lapse the content is gone. The related question is what happens to a leaver's content, because that is where organisations lose data quietly. When a user account is deleted, their OneDrive is retained for a limited default period before permanent deletion, and their mailbox goes the same way unless it was placed on hold before the licence was removed. Both of those are configurable, but only in advance. The decision about how much history you need, for how long, and whether platform retention alone is sufficient is a business and regulatory question that should be answered deliberately rather than inherited from a default. #### Frequently asked questions **Can you migrate us to Microsoft 365 from another platform?** Yes. We handle migrations from on-premises Exchange, Google Workspace and other tenants, moving mail, files and identity cleanly, with governance and security configured correctly from day one rather than bolted on later. **Which Microsoft 365 licence is right for my business?** For most SMBs up to 300 users, Microsoft 365 Business Premium is the best-value option because it bundles the productivity apps with the security stack most businesses are otherwise missing. We'll right-size licences to your actual headcount and usage so you're not paying for shelfware. **Do you provide ongoing Microsoft 365 support or just setup?** Both. We can run a one-off migration or governance project, then support the tenant on an ongoing basis, handling administration, licence optimisation, security and user adoption so it keeps delivering value. **How long does a Microsoft 365 migration take?** It depends on measurable things rather than on a standard timeline, which is why the honest answer comes after a scoping exercise. The variables are total data volume rather than user count, since one 90GB mailbox takes longer than twenty small ones; your available upload bandwidth; Microsoft's service throttling, which is applied to protect the platform and cannot be negotiated away; the number of shared mailboxes and delegate relationships that need mapping; and how many line-of-business systems relay mail. Preparation and discovery routinely take longer than the data movement itself. **Will users lose email or files during a migration?** They should not, and the design of the migration is what determines that. Mail is copied, not moved, so the source remains intact until the project is signed off, which means a rollback position exists throughout. In a staged migration mail flow is maintained across both environments, so messages sent during the transition are delivered rather than bounced. What users typically do experience is short interruption while their client reconnects and rebuilds its local cache. The genuine risks are around content that was never in scope: PST files on individual desktops, or a shared mailbox nobody declared. **Do we still need an on-premises Exchange server after moving to the cloud?** Only if you are still synchronising identity from an on-premises Active Directory. In that arrangement your on-premises directory remains authoritative for the synchronised attributes, so you need a supported way to manage recipients on-premises. Microsoft provides a management-only licensing arrangement for the server that remains, so you are not paying for a server hosting no mailboxes, but it still has to be patched and kept in support like any other internet-facing system: Exchange has been the subject of serious actively exploited vulnerabilities. If you move fully to cloud-managed identity and retire directory synchronisation, the requirement disappears. **Can two Microsoft 365 tenants be merged after an acquisition?** Yes, though it is a genuine project rather than a setting. A tenant-to-tenant migration means moving mailboxes, OneDrive and SharePoint content, Teams and identities into the target tenant. Domain names can only exist in one tenant at a time, so the source domain has to be released and re-verified in the target, which dictates the cutover sequence. User principal names, group memberships and permissions have to be mapped rather than copied, Teams chat history migrates less cleanly than mail and files, and devices need re-enrolling. It is best approached with a staged plan and a coexistence period. **What's the difference between Entra ID P1 and P2?** P1 gives you the controls that decide who gets in: Conditional Access policies based on user, device, location and application, self-service password reset, dynamic group membership and group-based licence assignment. It is included in Microsoft 365 Business Premium, E3 and E5. P2 adds the controls for detecting and containing misuse of legitimate access: Entra ID Protection, which scores sign-in and user risk so Conditional Access can respond automatically; Privileged Identity Management, which makes administrative roles time-limited and approval-gated; and access reviews. For most organisations P1 is the baseline and P2 earns its place first for administrators and high-risk roles. **Do we need Teams Phone, or can we keep our existing phone system?** Both are viable and the choice is about how you want calls routed and licensed. Teams Phone with a Microsoft calling plan is the simplest arrangement, with Microsoft acting as your carrier. Direct Routing keeps your existing telephony provider and connects them to Teams through a session border controller, which suits organisations with an existing contract or number ranges they want to keep. Operator Connect sits between the two. Keeping a separate PBX is also legitimate, particularly where you have contact centre queuing, regulatory call recording, or analogue devices like door entry and lift lines that still need a home. ### Cost Management & Azure Optimisation URL: https://systechitsolutions.co.uk/services/cost Cut Azure waste and Microsoft 365 shelfware. We right-size resources, audit licences and give board-ready reporting, typically recovering 30-40% of spend. Make your cloud pay for itself, by cutting Azure waste and taking control of Microsoft spend. Most Microsoft 365 and Azure estates are quietly overpaying, not through one big mistake, but a year of unassigned licences, oversized VMs and forgotten resources nobody got round to switching off. This service is for you if: - You own or influence the Azure / Microsoft 365 bill and it's crept up without a clear reason - Nobody has audited licence assignment or resource usage in the last 12 months - You need board-ready reporting, not just a one-off spreadsheet clean-up The cost of doing nothing: Unused E5 seats, orphaned disks, oversized VMs and idle test environments: none of it shows up as a single alarming line item, it just erodes margin month after month until a renewal forces the conversation. The audit is the easy part, most businesses simply haven't done it. #### Stop paying for cloud you don't use Most organisations overspend on cloud by 30 to 40%. We continuously monitor your Microsoft and Azure estate to root out waste, right-size resources and re-forecast spend, so every pound works harder. You get board-ready reporting and a partner who treats your cloud budget like their own, turning cost management from a once-a-year panic into a continuous discipline. What's included: - Azure waste and anomaly detection - Right-sizing of compute, storage and licences - Reserved instances and savings plan strategy - Microsoft 365 licence optimisation - Board-ready monthly cost reporting - Continuous forecasting and budget alerts #### Where does Azure waste actually accumulate? In predictable places, and rarely the ones people look at first. Compute is the obvious category: virtual machines sized for a workload that was projected rather than measured, and machines stopped from inside the operating system rather than deallocated, which continues to bill because the resource is still reserved. The less visible categories are usually the fastest growing. Log and telemetry ingestion is the most common surprise, because monitoring and security tooling bills on data volume, so a verbose diagnostic setting enabled during troubleshooting and never reverted can quietly become a significant line. Storage tiering is another: data written to a hot tier and never moved to cool or archive, alongside backup retention policies nobody has revisited. Data transfer charges catch out architectures that move traffic between regions more than the design assumed. And over-provisioned platform tiers persist because nobody owns the question of whether they are still needed. #### Reserved instances, savings plans or autoscale: which applies when? They solve different problems and are frequently combined. A reservation is a one or three year commitment to a specific resource type in a specific region, and it delivers the deepest discount available. It suits workloads that are stable and predictable: the domain controllers, the database server, the always-on production tier. A savings plan is a commitment to spend a fixed hourly amount on compute, applied automatically across eligible services and regions. It discounts less deeply but tolerates change, which makes it the right instrument where the workload is durable but the specific resources are not. Autoscale is a different category entirely: rather than discounting what you consume, it reduces what you consume by adding and removing capacity in response to demand. It applies to variable workloads with a genuine peak and trough, and it is the only one of the three that also improves resilience. The usual mature pattern is layered (reservations for the stable core, a savings plan covering the predictable band above it, and autoscale or scheduled shutdown handling the variable remainder) with the commitment deliberately set below your measured minimum consumption, so you are never paying for a commitment you cannot use. #### What is licence right-sizing, and where does shelfware come from? Shelfware accumulates in four ways, all mundane. Licences assigned to leavers and never reclaimed, because offboarding removed the account's access but nobody released the subscription. Licences bought for a headcount forecast that did not materialise, then renewed annually because renewal is easier than reassessment. Everyone placed on a premium tier when only a subset need its capabilities. And duplicated function, where a bundled entitlement you already own overlaps a separately purchased third-party tool: a separate mobile device management product alongside Intune is the classic pairing. Right-sizing means matching entitlement to actual need and actual use, which requires usage data rather than assumptions. Two cautions are worth stating plainly. First, downgrading a tier can silently remove security capability, so the analysis has to consider what a licence is protecting as well as what it enables. Second, agreements have terms, and mid-term seat reductions are often not permitted, so the practical window for change is at renewal, which means the analysis needs to be done before the renewal, not after it. #### What's the difference between cost cutting and cost control? Cost cutting is an event; cost control is a property of how the estate is run. Cutting produces a satisfying one-off reduction (resources deleted, tiers downgraded, licences reclaimed) and it works, once. What follows is the rebound, because the conditions that produced the waste are unchanged: the same provisioning behaviour, the same absence of ownership, the same lack of any signal when spend moves. Most organisations that run a cost exercise without changing anything structural find themselves close to the original figure inside a year. Cost control means the estate produces a signal before the invoice does. Budgets and anomaly alerts at a level granular enough to identify a cause rather than just a total. Tagging enforced at creation so every resource has an owner. A default expectation that non-production shuts down outside working hours unless someone opts out. Commitments reviewed against actual utilisation on a cycle rather than at renewal panic. The distinction matters commercially because cutting is measured in what you saved this quarter, while control is measured in the gap between what you now spend and what you would have spent: less visible, considerably larger over time. #### How do you attribute cloud spend to teams and projects? Through the structure you create the resources in, and through tags, in that order, because structure is enforced and tags are not. Subscriptions, resource groups and management groups form a hierarchy that maps onto business units, environments and projects, and spend attributed by that hierarchy is reliable because a resource cannot exist outside it. Tags add the dimensions structure cannot express (cost centre, owner, application, environment) but they are not inherited by default and are frequently omitted at creation. The fix is policy that requires or applies tags at creation, so compliance is a condition of provisioning rather than a monthly chase. Attribution then supports two different disciplines. Showback reports each team what their consumption costs without moving money, which is usually enough: visibility alone changes behaviour, because engineers who can see the running cost of a decision make different decisions. Chargeback actually recovers the cost into departmental budgets, which drives sharper accountability but requires the attribution to be defensible. Both stumble on shared costs (networking, monitoring, security tooling) and the workable approach is to agree an allocation method openly and stick to it. #### What does FinOps discipline look like for a mid-sized estate? It looks considerably lighter than the enterprise literature suggests, because most of that literature assumes a dedicated team you do not have. The core idea transfers regardless of scale: cloud spend is a variable operating cost driven by engineering decisions, so it needs the people making those decisions to see the consequences. In a mid-sized organisation that generally means someone owning the number, a monthly review that finance and IT attend together, and cost being a routine consideration at design time rather than a periodic audit. #### Why do cloud bills grow when nothing has obviously changed? Because several cost drivers grow on their own without any deployment. Storage is cumulative (data written and never lifecycled, snapshots retained indefinitely, backup chains lengthening under a retention policy nobody revisits) so a storage line climbs steadily whether or not anyone touches the environment. Log and telemetry ingestion behaves the same way, and scales with the number of systems being monitored. Consumption services bill on activity, so a busier month costs more without any configuration change. Then there are changes made outside your environment. Microsoft periodically adjusts pricing and, for UK organisations, list prices are influenced by currency alignment, so a bill can rise with no change in consumption at all. Licensing terms and product packaging change too, sometimes moving a capability from a bundle into a separately charged item. Without attribution and trend reporting, an increase presents as one aggregate number and the conversation becomes a hunt rather than an answer. #### Frequently asked questions **How much can Azure cost optimisation actually save?** Most organisations overspend on cloud by 30 to 40%. Real recoverable savings depend on your estate, but right-sizing compute, cleaning up orphaned resources, applying reserved instances and cutting licence shelfware typically frees up a meaningful share of the bill within the first quarter. **Is this a one-off audit or ongoing?** We can do either, but the biggest results come from treating cost as a continuous discipline: monitoring, monthly reporting and budget alerts so savings don't quietly reappear as waste again next year. **Will cutting costs affect performance or reliability?** No. Right-sizing means matching resources to real utilisation, not starving them. We base every change on actual usage data, so you cut waste without touching the capacity your workloads genuinely need. **Can we change or cancel an Azure reservation if our needs change?** There is some flexibility, but less than the marketing implies, and Microsoft's terms in this area have changed more than once, so verify the current position before committing rather than relying on what was true at your last renewal. Historically Microsoft has permitted exchanging a reservation for another of equal or greater value and allowed limited refunds subject to an annual cap. The safe planning assumption is that a commitment is a commitment. That is why coverage should be set against your measured baseline consumption rather than your expected consumption. **Does Azure Hybrid Benefit apply to us?** It applies if you already own Windows Server or SQL Server licences with active Software Assurance, or subscription licences carrying equivalent rights. The benefit lets you apply those existing licences to Azure workloads so you pay only the base compute rate rather than compute plus the licence component, and for SQL Server the difference is substantial. Two things are commonly missed. First, it has to be applied: it is a setting on the resource, and virtual machines migrated without it keep paying the full rate indefinitely. Second, it carries eligibility and reporting obligations, so it should be tracked deliberately rather than switched on and forgotten. **Is Microsoft Cost Management enough, or do we need a separate FinOps tool?** For most mid-sized estates the native tooling is sufficient and the gap is process rather than product. Cost Management provides cost analysis, budgets, anomaly alerts, Azure Advisor recommendations and exports for your own reporting, which covers the substantive requirement. Third-party platforms earn their keep at genuine multi-cloud scale. Buying one to solve a discipline problem does not work: an organisation that does not act on the free reports it already has will not act on more expensive ones. **What's the cheapest way to run development and test environments?** Turn them off, first and foremost: a scheduled shutdown outside working hours removes roughly three quarters of the compute cost of a nine-to-five environment, and it is the single highest-return change available in most estates. Deallocate rather than stop from within the operating system, because a machine stopped internally is still allocated and still billed. Beyond scheduling, Azure offers discounted dev/test pricing through eligible subscription types, spot virtual machines cost far less in exchange for being evictable, and non-production rarely needs production-grade storage tiers or redundancy. **Who should own cloud cost: finance or IT?** Both, with different responsibilities, and the failure mode is either owning it alone. Finance alone sees a total with no ability to influence what produced it, so the intervention available is a spending freeze, which is blunt and usually lands on the wrong things. IT alone optimises technically but without visibility of budget cycles or the business value of a workload. The workable split is that IT owns the technical decisions and the accuracy of attribution, finance owns budget, forecast and commercial terms, and both attend the same monthly review looking at the same numbers. **Is cost optimisation just deleting things we might need later?** No, and the distinction is evidence. Deleting resources on the assumption they are unused is how a cost exercise becomes an outage. Defensible optimisation works from measured data: actual CPU, memory and IO utilisation over a period long enough to include month-end and seasonal peaks, last-access timestamps on storage, and dependency mapping to establish what talks to what before anything is touched. Changes should be staged, reversible where possible, and applied to non-production before production. A cost review that cannot show its working is a risk being taken on your behalf. ### AI Solutions URL: https://systechitsolutions.co.uk/services/ai Adopt AI safely: Microsoft 365 Copilot readiness assessment, data and permissions review, governance and rollout support. Productivity without exposure. Practical AI with real outcomes, starting with a Microsoft 365 Copilot readiness assessment. Switch Copilot on before your permissions and data are ready, and it will happily surface files nobody should see. With AI, readiness isn't optional, it's the whole project. This service is for you if: - You're considering or piloting Microsoft 365 Copilot - Nobody has audited SharePoint or OneDrive permissions and oversharing recently - You want measurable productivity gains, with the governance to back them up The cost of doing nothing: Copilot surfaces whatever a user can already access, so existing oversharing, stale permissions or unlabelled sensitive data becomes instantly and disastrously more visible the day you switch it on. Most businesses discover this after rollout, not before. #### Ease your organisation into the world of AI AI only delivers when the groundwork is right. We start with a Copilot readiness assessment, reviewing your data, permissions and governance, then guide a safe, measured rollout. From Microsoft 365 Copilot to custom assistants and process automation, we help you adopt AI with the governance and data protection to back it up, and the productivity gains to prove it. What's included: - Copilot readiness assessment and rollout - Data, permissions and governance review - Custom copilots and process automation - AI governance and data protection - User training and adoption support - Measurable productivity benchmarking #### What does a Copilot readiness assessment actually check? Permissions come first, because Copilot inherits them exactly. So the assessment starts with SharePoint and OneDrive sharing settings, links set to 'anyone with the link', sites with no owner, guest accounts left over from projects that finished, and the company-wide groups that quietly grant everybody access to everything. The rest follows from that. Data lifecycle: whether retention and disposal have ever been applied, because a tenant that has never deleted anything is one where a decade of superseded documents is exactly as available to be surfaced as this month's version. Sensitivity labelling: whether the material that genuinely needs restricting is marked in a way the platform can act on. Identity and device posture: multi-factor authentication, Conditional Access and device compliance, because a Copilot licence raises the value of a compromised account. And the licensing position, which is the easiest part and the one most people start with. #### Why does Copilot surface files people should not see? Because it is doing exactly what it was designed to do. Copilot has no permissions model of its own: it queries content as the signed-in user, so anything they could already have found through search, they can now find by asking a question in plain English. The change is not access, it is discoverability. Files that were technically reachable but practically invisible, buried in a site nobody browses, twelve folders deep, named something meaningless, become one sentence away. None of those are Copilot faults. All of them become Copilot's problem the moment you switch it on. #### What has to be true before you assign the first licence? A short list, and none of it is optional. Multi-factor authentication enforced for every user without exception. Sharing defaults set to named people rather than anyone with the link, with expiry on any anonymous link you do keep. Company-wide access removed from sites that should never have had it. An owner assigned to every site and Team, because an unowned workspace has nobody who can make a decision about its content. Guest access reviewed by last activity rather than by whether the name still looks familiar. Doing the permissions work first is not a delay to the project. It is the project. What follows it is comparatively straightforward. #### What does a safe Copilot rollout look like, step by step? Assess, remediate, pilot, measure, expand. The assessment produces a written picture of permissions, sharing, data and readiness. Remediation fixes what it found, and this is the phase that takes real time, because re-scoping site access and clearing legacy sharing is careful work that changes how people currently get at things. Only then does a pilot start, deliberately small and deliberately chosen: a group with real, repetitive, document-heavy work, rather than whoever asked first. The pilot has to be measured against something. Pick two or three tasks the group genuinely does, record roughly how long they take today, and compare afterwards. Then expand by role rather than by enthusiasm, because the value is uneven: people who spend the day in Outlook, Word, Teams meetings and SharePoint get far more from it than people who spend the day in a line-of-business application Copilot cannot see. Reviewing usage after each expansion, and reclaiming licences from users who stopped, is what stops this becoming an annual renewal for something nobody opens. #### How does Copilot licensing interact with what you already own? Microsoft 365 Copilot is an add-on rather than a plan in its own right, so it sits on top of a qualifying Microsoft 365 subscription and is assigned per user. Two consequences are worth planning for. First, the base licence you hold is part of the decision, and where a tier change is needed it is far easier to handle at renewal than mid-term. Second, it is a per-user cost that runs whether or not anyone opens it, so who receives a licence is a commercial decision rather than an inclusive gesture. There is also more than one thing called Copilot, and conflating them causes most of the confusion in a licensing conversation. A general web chat experience is not the same as the paid Microsoft 365 Copilot that reaches into your own tenant content, and neither is the same as a purpose-built agent published to a named audience. Establishing which one a request actually refers to settles half the argument before price comes up. The wider question of what you own, what you use and what you are paying twice for sits on our licensing and cost management page, and right-sizing there frequently funds a good part of a Copilot pilot. #### What does the published evidence say about Copilot saving time? There is now real published evidence rather than only vendor case studies, and it is worth reading carefully because it is more modest and more useful than the marketing. HMRC published a Phase 3 evaluation covering 3,000 randomly allocated licences plus 500 for volunteers, run from September to December 2024 with 1,364 survey responses. Staff self-reported saving 2 to 3% of their working week, which HMRC put at around 60 minutes, and HMRC then reduced its own headline figures by about 20% to account for non-users and response bias. A separate cross-government trial covering more than 20,000 civil servants reported around 26 minutes a day. Those two numbers are not comparable, and the gap between them is the point. Different populations, measured differently, both self-reported. Anyone quoting one of them at you as the figure your business will achieve is selling rather than advising, and we are not going to do it either. That last figure is the one worth sitting with, because it is the readiness argument made by the users themselves. Nearly half the people who never touched a licence their employer had already paid for stayed away because they were not confident about what it could reach. That is not a training problem and it is not solved after rollout: it is the permissions and governance work, done first, and it is the difference between licences that get used and licences that get quietly abandoned. #### How do you tell whether Copilot is actually delivering value? By choosing how you will measure it before the rollout rather than after. The mistake is to look for a single productivity percentage, which nobody can produce honestly. What works is a small number of concrete tasks with an observable before and after: how long a first draft of a routine report takes, how long it takes someone to catch up on a meeting they missed, how long the monthly summary takes to assemble. Ask the pilot group to record the starting position candidly, including how much they dislike the task, because time recovered from work people resent is worth more than the minutes suggest. Then watch usage rather than licence count. Active use per person, which applications it is being used in, and how many licensed users have stopped entirely are the numbers that predict whether renewal is worth it. A licence assigned to somebody who used it twice in March is a recurring cost with no return, and reclaiming it is not a failure of the project, it is the project working properly. #### What should an AI use policy actually say? Less than most drafts, and far more specifically. A policy people will follow states which tools are approved and which are not, what categories of information must never be pasted into an unapproved tool (client data, personal data, anything under NDA, credentials, unpublished financials), that AI output is a draft and the person who sends it owns it, and where to ask when something is unclear. A policy that opens with a definition of machine learning is one nobody reads to the end of. The part most often missing is the route to yes. If there is no approved way to use a tool people find genuinely useful, they will use it anyway on a personal account, and you lose the control and the visibility together. Naming approved tools and providing a simple request process for new ones converts shadow AI into something you can see. Where automated output feeds a decision about a person, whether that is recruitment, credit or anything else with a consequence, the policy also needs to say who reviews it, because that is a legal position rather than a preference. #### What is shadow AI, and how do you find it? Shadow AI is the use of AI tools nobody approved, on accounts nobody manages, with company information nobody agreed to share. It is almost always well intentioned: somebody had a tedious task and found something that helped. The risk is not the intent, it is that the data has left your control, the output has no audit trail, and when a client or an auditor asks whether their information has been put into a third-party model, the honest answer is that you do not know. Finding it starts with signals you already hold rather than with a survey, because a survey asks people to confess. Sign-in and application consent records in Entra ID show which third-party applications have been granted access to your tenant and by whom. Expense claims and card statements show personal subscriptions. Browser and network telemetry, where you have it, covers the rest. What matters more than the inventory is what happens next: a genuine approved option offered quickly does more to reduce shadow AI than any prohibition. #### Where does Copilot help, and where does it genuinely not? It helps most where the work is language-shaped and the source material already lives in Microsoft 365. Summarising a long thread or a meeting you missed, producing a first draft from documents that already exist, finding the thing you know you read but cannot locate, turning rough notes into something presentable, and restructuring content you already have. In those tasks it changes the shape of the work: instead of starting from nothing you start from something imperfect, which for most people is considerably easier. It helps least where the answer depends on data it cannot see, or on being exactly right. Anything sitting in a line-of-business system outside Microsoft 365 is invisible to it unless deliberately connected. Numerical work needs checking, because a confident wrong figure looks identical to a confident right one. And any output going to a client, a regulator or a court needs a human who is accountable for it, which is a governance decision rather than a technical one. Saying this plainly at the start protects the project, because expectations set too high in month one are the most common reason adoption stalls by month three. #### What are Copilot agents, and what changes when you publish one? An agent is a Copilot pointed at a defined set of content, given instructions, and published to a specific audience. That focus is what makes agents useful, and it is also what makes three questions unavoidable: what content it can reach, who can use it, and who owns it. An agent holds a standing pointer at company data, so one published broadly against a site with loose permissions is the oversharing problem again, in a form that is harder to notice because it presents as a small helpful tool rather than as a search index. The workable position is that every published agent has a named owner, a stated purpose and a review date recorded somewhere central, and that it joins the same review cycle as unowned sites and stale guest accounts. Start narrow. An agent scoped to one well-governed document library and used by one team is a good first agent. An agent scoped to everything is a governance problem with a friendly interface. #### When do you not need this, and where does our scope end? You do not need a readiness engagement if your tenant is small and recently built, sharing is already locked down, multi-factor authentication is everywhere and every site has an owner. In that position, buy a handful of licences, run a pilot and measure it. We do not sell AI as a headcount reduction, and we will say so when the honest answer is that a particular team will get little from it. Where the requirement is AI answering from your own data, or built into your own application, that is a different discipline and it sits on our AI engineering page rather than this one. #### Frequently asked questions **Is my business ready for Microsoft 365 Copilot?** That's exactly what a readiness assessment answers. Copilot inherits every user's existing access, so before licensing anyone we audit SharePoint and OneDrive permissions, sensitivity labelling and governance. If oversharing exists, we fix it first, so Copilot boosts productivity without exposing data. **What's the difference between Copilot and a custom AI assistant?** Microsoft 365 Copilot works across your existing Microsoft apps. A custom copilot or assistant is built for a specific task or dataset, for example answering questions from your own documents. We help with both, and our AI Engineering service goes deeper into fully custom builds. **How do you measure whether AI is actually delivering value?** We benchmark before and after against the tasks that matter, so productivity gains are evidenced, not assumed. Adoption support and training make sure the tools are genuinely used rather than licensed and forgotten. **Can Copilot see files a user doesn't already have access to?** No. It answers as the signed-in user, so it can only reach what that person could already have opened or found through search. That is precisely why readiness work matters: the risk isn't that Copilot grants new access, it's that it makes existing over-permissive access trivially easy to find. Content sitting in a site shared company-wide by mistake was always reachable; before Copilot it was buried, after Copilot it is one question away. **Does Microsoft train its AI models on our company data?** Microsoft's published commitments for Microsoft 365 Copilot state that customer prompts, responses and tenant content are not used to train the underlying foundation models, and that data remains within the service's compliance boundary. Because these terms have been revised more than once, treat the current published terms as the authority rather than any summary, including this one, and check them as part of your own due diligence. The wider point is that the same assurance does not automatically apply to every AI tool your staff might use, which is why an approved tool list matters. **How many Copilot licences should we start with?** Enough for one pilot group doing genuinely document-heavy work, and no more. A pilot exists to produce evidence, and evidence needs a group small enough that you can actually talk to all of them and large enough that one enthusiast doesn't skew the result. Expand by role afterwards, based on what the pilot showed, rather than buying broadly on the assumption that everyone benefits equally. They don't: the value varies enormously depending on how much of someone's day is spent in Microsoft 365 rather than in a line-of-business system. **How long does permissions remediation usually take before a rollout?** It depends almost entirely on how much history the tenant has, which is why we assess before quoting the remediation rather than the other way round. A tenant built in the last couple of years with sharing controls already in place needs comparatively little. A tenant that has run for a decade, with sites nobody owns, guests nobody has reviewed and company-wide access granted to solve one-off problems, needs real work, and that work touches how people currently reach things, so it has to be staged and communicated rather than applied overnight. ### AI Engineering & Custom AI Solutions URL: https://systechitsolutions.co.uk/services/ai-engineering Custom AI engineering: retrieval-augmented generation (RAG) over your own data, small language models, AI API integration and production apps, fully governed. RAG pipelines, small language models and custom AI applications, engineered and integrated properly, not bolted on. Off-the-shelf Copilot licences solve one problem. Building AI into your own data and applications is a completely different discipline, and it's where generic tools quietly stop being enough. This service is for you if: - You want AI answering questions from your own documents, not the public internet - A one-size-fits-all API is too costly, too generic or too risky for your use case - You need AI built into a product or internal tool, with real governance and grounding The cost of doing nothing: Bolting a raw language model onto your business without retrieval, grounding or evaluation produces confident, plausible, wrong answers, and no audit trail for why. In production, an ungrounded model is a liability, not a feature. #### Build AI that actually fits your data and your systems Off-the-shelf Copilot licences solve one problem. Building AI into your own applications and data is a different discipline entirely: retrieval-augmented generation (RAG) over your own documents, small language models (SLMs) sized and hosted for the job rather than a one-size-fits-all API, and integrations that call AI models safely from the systems you already run. We design and build the pipeline end to end, model selection and configuration, retrieval and grounding so answers are based on your real data, and the custom applications or APIs that put it in front of your team or your customers. What's included: - Retrieval-Augmented Generation (RAG) over your own documents and data - Small Language Model (SLM) selection, sizing and hosting - AI API integration and model configuration - Custom AI applications and internal tools - Prompt engineering and evaluation for reliability - Governance, cost control and monitoring for production AI #### When do you need custom AI engineering rather than a Copilot licence? When the answer has to come from data Copilot cannot see, or the AI has to live inside something you built. Microsoft 365 Copilot is very good within its boundary: content in Exchange, SharePoint, OneDrive and Teams, reached as the signed-in user, inside the applications people already use. If your question is 'summarise this thread' or 'draft this from those documents', buy the licence and stop reading. Custom engineering starts where that boundary does: a case management system, a product catalogue, an equipment history, a decade of PDFs in a share nobody has indexed, or a customer-facing feature in your own product. The second trigger is control. A licence gives you the model, the interface and the behaviour Microsoft chose. An engineered system lets you decide what the model may see, how the answer is grounded, what it does when it does not know, what gets logged, where inference runs and what the whole thing costs per query. Most organisations need the licence and not the engineering. The ones that need the engineering usually know why, because they have already tried to solve the problem with a general tool and hit the same wall twice. #### What does a RAG pipeline actually consist of? Five stages, and the interesting work is in the first two rather than the model. Ingestion collects the source material and normalises it, which in practice means dealing with PDFs, scanned documents, spreadsheets, database records and pages that were never written to be machine-read. Chunking splits that content into passages small enough to retrieve precisely and large enough to still make sense on their own, carrying the metadata that says where each passage came from. Indexing turns those passages into a searchable form, typically a vector index, often combined with keyword search because the two fail in different places. Then retrieval selects the passages relevant to a question, and generation asks the model to answer using only those passages, with citations back to the source. Around all of that sits the part people forget: permission filtering, so a user only ever retrieves passages they are entitled to see, and a refusal path, so that when retrieval finds nothing useful the system says so rather than improvising. A pipeline without those two is a demonstration, not a product. #### Where do RAG projects usually go wrong? In retrieval, almost every time, and it gets blamed on the model. If the right passage never reaches the model, no amount of prompt engineering or model upgrading will produce a correct answer. The second failure is stale content. An index built once at launch drifts from reality with every document that changes, and nobody notices, because a confidently wrong answer from a superseded policy is indistinguishable from a right one. The third is permissions, where the pipeline reads everything with a single service identity and hands answers to whoever asks: an oversharing incident with extra steps. The fourth is having no way to tell whether a change made things better, which is why evaluation belongs in the build rather than after it. #### How do you evaluate an AI feature before it goes live? With a fixed test set that you write before you tune anything. That means a collection of real questions people actually ask, each with the passage that should be retrieved and a note on what a good answer contains, including the questions where the correct behaviour is to refuse. It is unglamorous work and it is the difference between engineering and guessing, because without it every change becomes a matter of opinion about whether the last few answers felt better. Evaluate retrieval and generation separately, because they fail separately. Retrieval is measured on whether the right passage came back at all and how far down the list it was; generation is measured on whether the answer is supported by the retrieved passages, whether it cites them, and whether it declines when it should. Add adversarial cases deliberately: questions the source material does not answer, questions that invite the model to speculate, and attempts to talk it out of its instructions. Then run the same set after every change, so improvement is demonstrated rather than asserted. #### When is a small language model the right choice? When the task is narrow, the volume is high, and the data should not leave your control. A large general-purpose model is a good default precisely because it handles anything, but most production tasks are not anything: classifying an enquiry, extracting fields from a form, rewriting text into a house style, routing a ticket. For work with a tight, well-defined shape, a smaller model can meet the quality bar at a fraction of the cost and latency, and can run somewhere you choose rather than somewhere you send data to. The trade is capability and effort. Smaller models are less forgiving of vague prompting, weaker at multi-step reasoning, and more likely to need real evaluation work and sometimes fine-tuning to reach the standard a large model reaches out of the box. The sensible pattern is usually mixed rather than either or: prototype against a capable general model to establish what good looks like, then move the high-volume, well-defined steps to something smaller once you have a test set that proves the smaller model still passes. #### Where should the model actually run? There are three broad options and the decision is mostly about data, not performance. A hosted commercial API is fastest to build against and gives you the strongest models, at the cost of sending content to a third party under their terms. A model hosted in your own Azure subscription keeps inference inside a boundary you control and inside your existing commercial relationship, which matters when a client contract or a regulator asks where processing happens. Self-hosting on infrastructure you own goes furthest on control and is the most work to run, and only makes sense when there is a concrete reason it has to be that way. The practical advice is to decide the data position first and let it constrain the options, rather than picking a platform and then arguing about the data afterwards. Write down what categories of information the system will handle, what your own contracts and policies say about where they may be processed, and what you would have to tell a client if they asked. That usually eliminates one option immediately and makes the remaining choice straightforward. Build the integration so the model is a replaceable component either way, because this part of the market moves faster than your application will. #### How do you keep the cost of a production AI feature under control? Sending an entire document when three retrieved passages would do is the single most common source of avoidable spend, and it usually also makes the answer worse, because relevant content gets diluted. Instrument cost per request and per feature from day one, not after the first bill, and treat a rising cost per answer as a design signal rather than a billing problem. #### What does governance look like for a custom AI application? Human review is not a checkbox, it is a named responsibility with the authority to overrule the system. Where the output influences a decision about a person, the bar rises and the question stops being technical. UK data protection law places real constraints on automated decision-making, and the emerging European rules turn on how a system is used rather than how it was built, so the same model can sit in a low-risk and a high-risk application. The practical response is to record the purpose, the data, the human checkpoint and the review date at design time. Retrofitting that record after launch is considerably harder than writing it while the decisions are still being made. #### How does this fit with the Microsoft stack you already run? Usually as an extension of it rather than an alternative to it. Identity is the first integration point: an internal AI tool should authenticate through Entra ID like everything else, so access is governed by the same groups, the same Conditional Access policies and the same joiner and leaver process, rather than by a separate user list somebody maintains by hand. That single decision removes most of the access-review problems custom applications otherwise create. Beyond identity, the pieces fit where you already have them: Azure for hosting and for keeping inference inside your own subscription, your existing Microsoft 365 content as a source where it is genuinely the right source, and Power Platform for the workflow around the AI rather than the AI itself. The boundary worth respecting is that Microsoft 365 Copilot and a custom system solve different problems, and building a custom answer engine over content Copilot already handles well is expensive duplication. We would rather point you at the licence. #### What does an engagement look like, and where does our scope end? That conversation frequently ends with a recommendation not to build anything, because the problem turns out to be a search or a data quality problem wearing an AI costume, and solving it that way is cheaper and more reliable. Where a build is right, the shape is a narrow prototype against real data and a real test set, an honest assessment of whether it clears the bar, then production hardening: permission filtering, evaluation in the pipeline, logging, cost controls, monitoring and a documented handover. Our scope is the engineering and the governance around it. We are not a data cleansing service, we will not claim an accuracy figure we cannot demonstrate on your own test set, and where the requirement is really Copilot adoption and permissions readiness, that is our AI and Copilot service rather than this one. #### Frequently asked questions **What is retrieval-augmented generation (RAG)?** RAG grounds an AI model's answers in your own documents and data. Instead of relying on what a model was trained on, it retrieves the relevant material at query time and answers from that, so responses are accurate, current and traceable back to a source, which is essential for business use. **Why use a small language model (SLM) instead of a big API?** Small language models can be cheaper, faster, more private and hostable on infrastructure you control. For many focused business tasks an SLM sized for the job outperforms a general-purpose API on cost and latency, without sending your data to a third party. **Can you integrate AI into our existing applications?** Yes. We build AI API integrations and custom applications that call models safely from the systems you already run, with the prompt engineering, evaluation and monitoring needed to keep them reliable in production. **How do you stop an AI system inventing answers?** Three things together, and none of them works alone. Retrieval, so the model answers from passages pulled out of your own material rather than from what it remembers. Citations, so every claim points back to a source a person can open and check. And an explicit refusal path, so that when retrieval finds nothing relevant the system says it does not know instead of producing something plausible. On top of that, an evaluation set that deliberately includes questions your content does not answer, run after every change, so you can see whether the refusal behaviour still holds. **Can a RAG system respect our existing permissions?** It has to, and this is one of the first things to check on any proposal. The wrong design indexes everything under a single service identity and serves answers to whoever asks, which turns a document library's access controls into decoration. The right design carries permission metadata through ingestion and filters retrieval against the identity of the person asking, so a user can only ever be answered from content they could have opened themselves. Ask any supplier to explain exactly how their pipeline does this, and treat a vague answer as the answer. **How long does a custom AI build take?** We scope it after discovery rather than before, because the variable is almost never the model, it is the state of your data. Where the source material is already structured, current and accessible, a narrow prototype comes together quickly. Where it is a decade of scanned PDFs in a share with no consistent naming, the preparation is the project and the AI part is comparatively short. That is why we start with a narrow prototype against real data: it establishes what the real effort is before anyone commits to a production build. **Should we build our own AI tool or wait for the vendor to add it?** Often waiting is the right answer, and we will say so. If the capability you want is on a published roadmap for a platform you already pay for, building your own version of it is a cost you will carry twice. Building makes sense where the need is specific to how your business works, where the data involved is yours rather than the vendor's to reach, or where the capability is a genuine differentiator in your own product. Building because a general tool almost does it is usually the expensive path. ### Development & Application Modernisation URL: https://systechitsolutions.co.uk/services/modernisation Modernise the applications that run your business: Azure migration, replatforming, Power Platform and custom development, delivered incrementally. Turn legacy into leverage, moving the apps your business relies on to the cloud and the Microsoft stack. Every business has at least one application it would rather not talk about, old, awkward, and holding back everything around it. Very few replacements actually happen, because the plan is always the same: stop, rebuild it properly, switch over. That plan is exactly why nothing changes. This service is for you if: - A core application is slowing the business down but a full rewrite feels too risky - You want to move onto Azure and the Microsoft stack without a big-bang cutover - You need a pragmatic roadmap, not a two-year rebuild before anything improves The cost of doing nothing: A big-bang rewrite has to work perfectly on day one to be worth anything, and most run twelve to eighteen months over a moving target while the business gets no value in the meantime. Left alone, the old application keeps ageing, keeps costing, and keeps being the thing nobody dares touch. #### Modernise the applications you depend on The applications that run your business shouldn't hold it back. We assess your estate and chart a pragmatic path to modernise, whether that's replatforming, rebuilding or extending onto the Microsoft stack. You don't have to rebuild everything at once. We take an incremental approach that reduces risk and delivers value at each step, so improvements land continuously instead of arriving all at once, if they arrive at all. What's included: - Legacy application assessment and roadmap - Azure migration and replatforming - Power Platform and custom development - API integration and workflow automation - Incremental modernisation with minimal disruption - Ongoing support and enhancement #### How do you decide what to modernise first? By assessing applications against two axes rather than one: how much pain each causes, and how much value would be released by changing it. Business criticality on its own produces the wrong order, because the most critical application is usually also the most frightening to touch, so the plan stalls at item one. What we look for instead is the highest-pain, highest-value piece, which in practice means whatever generates the most support tickets, whatever blocks the features the business actually wants next, or whatever single system is holding an entire platform decision hostage. The assessment itself is unglamorous and it is where the cost of the whole programme gets decided. For each application we establish what it genuinely does, including the parts nobody documented; who uses it and how often, because usage is regularly a fraction of what people assume; what it depends on and what depends on it; whether the vendor still exists and still supports it; what data it holds and where that data goes; and what the platform underneath it is, along with how long that platform has left. The output is a ranked roadmap where each item names the route, the reason and the trigger, so the sequence survives contact with a busy quarter rather than reverting to whatever is loudest. #### Rehost, replatform, refactor or replace: which applies? The four routes answer different questions, and the mistake that costs the most is choosing one for the whole estate. Rehost, often called lift and shift, moves the application as it is onto new infrastructure without changing it: fastest, lowest risk, and it fixes exactly one problem, which is the hardware or datacentre underneath. Replatform keeps the application broadly intact but swaps components for managed equivalents, most commonly moving a database onto a managed service or a web tier onto an app service, which removes patching and capacity work without touching the code that carries your business logic. Refactor changes the application itself, usually to break a monolith into pieces that can be deployed and scaled separately, or to rewrite one part that has become the constraint. Replace retires the application in favour of something else, whether a product you buy or something built new. The decision rule we use is simple: work out what the actual problem is first. If the problem is the platform, do not touch the code. If the problem is one component, do not rebuild the whole thing. If the problem is the business logic rather than the technology, replatforming faithfully just gets you the wrong thing on newer infrastructure. Most estates end up using two or three of these routes across different applications rather than committing to one. #### Why does lift and shift produce a bigger bill than expected? Because a server sized for a five-year on-premises life gets recreated exactly as it was, and cloud charges by the hour for capacity you owned outright before. On-premises, an oversized machine costs you nothing extra once it is bought; the waste is invisible and permanent. Rehosted, that same over-provisioning becomes a monthly invoice line that grows with every server you move. Add the components that used to be free because they were already in the building, storage tiers chosen out of habit rather than measured need, backup and data transfer, and non-production environments left running around the clock, and the total lands well above the business case. That work is the same discipline as our cost management and Azure optimisation service, and it belongs in the plan from the start. A migration with no optimisation phase scheduled after it is a migration that will produce an uncomfortable invoice review in about four months. #### Why do big-bang rewrite projects fail to ship? Three reasons, and they compound. Scope creep, because the existing application contains undocumented business rules, edge cases nobody remembers the reason for and integrations quietly holding three other systems together, all of which surface one at a time during the rebuild. The business does not get to pause, so the old application has to keep running in full for the entire project, and every hour spent on the new system is an hour not spent improving the one people are actually using. And timing: rewrites commonly take twelve to eighteen months, sometimes longer, by which point the requirements captured at the start have moved, and you can end up delivering a faithful rebuild of a system the business has already outgrown. The structural problem underneath all three is that a big-bang rewrite has to work perfectly on day one to be worth anything. Until the switchover, every penny spent is sunk cost with nothing running to show for it, which is also why these projects are so easy to descope or quietly abandon six or nine months in when budgets tighten. The people who authorised it have seen no value, so there is nothing to defend. That is not an argument against ever rebuilding. It is an argument against making the whole thing contingent on a single future date. #### What does incremental modernisation actually look like? It replaces a legacy system piece by piece, from the outside in, in what is usually called the strangler pattern. You put a stable interface in front of the old application, then build new components behind it one at a time, routing traffic to each new piece as it becomes ready. The legacy system keeps handling everything not yet rebuilt. Nothing is switched off until its replacement is already carrying live traffic successfully, which means there is no single switchover date on which everything has to work, and no point at which the business is betting on a future event. Two ordering rules make the difference between this working and becoming an expensive rewrite in slow motion. Move data and integration layers before touching the interface: getting the data into a stable home and building solid APIs around it gives everything else a foundation, and it is usually less politically sensitive than changing a screen people use every day. And build the new pieces on managed platform services rather than recreating the old architecture in a new location, because rebuilding the same design on newer infrastructure inherits the constraints you were trying to escape. Each increment has to be genuinely deliverable on its own, or you have simply broken a rewrite into instalments nobody can use. #### What does running old and new side by side actually cost? That is a real cost, and pretending otherwise is how incremental programmes get sold optimistically and then judged harshly. The reason it is still usually the better trade is that the cost is bounded and visible, whereas the risk it removes is neither. A big-bang cutover concentrates all the uncertainty into a single weekend, with a rollback plan that gets less credible the longer the new system has been taking transactions. Incremental transition spreads that risk across many small, reversible steps. The discipline that keeps the cost bounded is refusing to let the transition period drift: each increment should have a defined point at which the old path is switched off and decommissioned, because parallel running that never ends is the most expensive outcome available. #### Where does Power Platform genuinely fit, and where does it not? It fits best where the work is forms, workflow, approvals, and putting a usable interface on data that already lives in your Microsoft estate. A departmental process running on a spreadsheet and an email chain, an approval flow currently maintained by someone remembering to chase people, a request or booking system nobody has ever had the budget to build properly: these are exactly what Power Apps, Power Automate and Dataverse are for, and building them conventionally is usually poor value. It also fits as the extension layer around a system you are not replacing, adding the workflow the core product does not do rather than customising the core product into something unsupportable. Where it fits poorly is high-volume transaction processing, genuinely complex algorithmic logic, anything with hard real-time performance requirements, and anything that needs to be portable off the Microsoft platform later. There is also a governance dimension that gets discovered late: low-code makes it easy for anyone to build something the business then depends on, which is how organisations accumulate a second shadow estate with no owner, no documentation and no lifecycle. Licensing needs checking against the actual usage pattern before you commit, because the model differs by connector and by app type and is not something to assume. Used deliberately it is one of the highest-return tools available. Used as a default answer, it becomes next decade's legacy problem. #### What about data, APIs and the integrations nobody documented? The integrations are usually the actual project. Almost every application that has been in service for years has grown connections nobody wrote down: a nightly file drop another system depends on, a database view someone else's reporting tool reads directly, a scheduled task that emails a spreadsheet to finance, a hard-coded server name inside a third system. Discovery has to find these before anything moves, because each one is a way for a successful migration to break something in an unrelated part of the business a week later. The remedy is to put a deliberate interface where an accidental one grew. Replacing direct database access with a documented API is often the single highest-value early increment, because it decouples everything downstream from whatever you do next and lets you change the system behind it without renegotiating with every consumer. Data needs its own plan alongside: what is migrated, what is archived, what is deliberately left behind, how the two sides stay consistent during transition, and how you prove afterwards that nothing was lost. Getting that plan wrong is the failure that is hardest to correct retrospectively, because by the time anyone notices, months of new transactions sit on top of it. #### When is a full rebuild genuinely the right answer? In two situations, and it is worth being strict about them. The first is when the underlying platform is fully unsupported or unsupportable, so there is no stable base left to build anything around: you cannot incrementally strangle a system that will not run on anything you are allowed to deploy. The second is when the business logic itself is wrong rather than the technology it is built on, because a faithful replatform of the wrong process delivers the wrong process, faster and on a better invoice. Even then, the runway question decides the approach. A rewrite is commonly a twelve-to-eighteen-month undertaking, and an application sitting on an already-unsupported operating system rarely has that time available. Where that is the case, capture-based migration onto a modern supported platform buys the breathing room, and the rebuild happens on its own timeline rather than against a security deadline. That is a bridge rather than a destination, and it should be called one in the plan. The failure mode is treating the bridge as the answer, then finding four years later that the temporary arrangement is now the thing nobody dares touch. #### What does modernisation done properly look like? The test is whether value arrived before the project finished. A programme running properly has shipped something usable within the first few months, has an explicit route recorded for every application in the estate including the ones deliberately left alone, has decommissioned at least some of what it replaced rather than accumulating both, and has a cost picture that someone reviews rather than discovers at renewal. It also has fewer surprises over time rather than more, because discovery work done early is what removes them. And then drifted for a decade. Avoiding a repeat means naming an owner, keeping dependencies current rather than pinned, keeping the deployment process automated so releasing is routine, and writing down enough that the next person does not have to reverse-engineer it. Modernisation that produces a better system with the same neglect around it has bought you roughly ten years. #### How does this relate to legacy migration, packaging and cost work? They meet constantly and are usually cheapest scoped together. Our legacy modernisation and OS migration service deals with the platform underneath: Windows and Windows Server versions going out of support, and applications that cannot move because the install media, the source code or the vendor no longer exists. That is frequently the trigger for a modernisation conversation rather than a separate matter, because an end-of-support date is a deadline the business cannot argue with, which makes it the moment the awkward application finally gets attention. Application packaging and MSIX is the delivery side of the same problem: once an application has been captured or rebuilt, it still has to reach users reliably and repeatably, whether that is on managed desktops, in Azure Virtual Desktop host pools or on Windows 365 Cloud PCs. And cost management and Azure optimisation is what stops a successful migration turning into an unpleasant invoice, which is why we schedule it after a rehost rather than treating it as an unrelated engagement. If your modernisation is really an end-of-support problem, or really a cost problem, we will say so rather than selling you the more expensive interpretation. #### Frequently asked questions **Do we have to rewrite the whole application at once?** No, and usually you shouldn't. We favour incremental modernisation, replacing or replatforming piece by piece, so the business gets value at each step and risk stays low, rather than betting everything on a single big-bang rewrite. **When does it make sense to migrate rather than rebuild?** When the application still does its job and the platform underneath it is the problem, migration or replatforming is faster, cheaper and far less risky than a rewrite. We assess each application on its merits and recommend the pragmatic path, not the most expensive one. **Can you modernise applications onto Azure and the Microsoft stack?** Yes. We migrate and replatform onto Azure, extend applications with Power Platform and custom development, and add API integration and workflow automation so legacy systems connect cleanly to the tools your business already uses. **What's the difference between rehosting, replatforming, refactoring and replacing?** Rehosting moves the application as it is onto new infrastructure, which fixes the hardware or datacentre problem and nothing else. Replatforming keeps the application broadly intact but swaps components for managed equivalents, typically the database or web tier, removing patching and capacity work without touching your business logic. Refactoring changes the application itself so parts can be deployed and scaled separately. Replacing retires it for a product or something new. The rule we work to is to identify the actual problem first: if it's the platform, don't touch the code; if it's one component, don't rebuild the whole thing. **Why did our lift and shift end up costing more than expected?** Almost always because servers were recreated at the size they were on-premises, where over-provisioning was invisible and already paid for. In the cloud that same headroom becomes an hourly charge, and it's joined by things that used to be free because they were in the building: storage tiers picked from habit, backup, data transfer, and non-production environments left running around the clock. The fix isn't to undo the migration, it's to treat right-sizing, shutdown schedules, storage tiering and reservations as a scheduled phase after it, against measured usage rather than assumptions. **How do you deliver value before a modernisation project finishes?** By putting a stable interface in front of the old system and replacing pieces behind it one at a time, routing live traffic to each new component as it becomes ready. The legacy system keeps handling whatever hasn't been rebuilt, and nothing is switched off until its replacement is already carrying real work. That removes the single switchover date everything depends on. Two ordering rules matter: move the data and integration layers before touching the interface, and build the new pieces on managed platform services rather than recreating the old architecture somewhere newer. **Where does Power Platform fit, and where would you advise against it?** It fits forms, workflow, approvals and putting a usable interface on data already in your Microsoft estate, and it works well as an extension layer around a system you're not replacing. It fits poorly for high-volume transaction processing, genuinely complex algorithmic logic, hard real-time requirements, or anything that may need to move off the Microsoft platform later. There's also a governance point worth planning for up front: low-code makes it easy for anyone to build something the business then depends on, which is how a second undocumented estate appears. Licensing should be checked against your actual usage pattern rather than assumed, because the model varies by app type and connector. **What usually gets missed when scoping a modernisation?** The undocumented integrations, and they're usually the actual project. A system in service for years grows connections nobody wrote down: a nightly file drop something else depends on, a database view read directly by a reporting tool, a scheduled task emailing a spreadsheet to finance, a hard-coded server name inside a third application. Each one is a way for a successful migration to break something unrelated a week later. Replacing direct database access with a documented API is often the highest-value early piece of work, because it decouples everything downstream from whatever you do next. **Our application is on an unsupported OS. Do we modernise or migrate first?** Deal with the security deadline first, then modernise on your own timeline. A rewrite is commonly a twelve-to-eighteen-month undertaking, and an application on an already-unsupported operating system rarely has that long, so trying to do both at once means running unpatched while a project you can't rush completes. Capture-based migration onto a modern supported platform buys the runway in weeks, which is our legacy modernisation and OS migration service rather than this one. Just be honest in the plan that it's a bridge, because bridges that get relabelled as destinations are how the next legacy problem starts. ### Application Packaging & MSIX URL: https://systechitsolutions.co.uk/services/app-packaging A UK managed service for MSIX packaging, App-V to MSIX migration and app attach for AVD. Vendor-neutral, hands-on, led by a Microsoft MVP. Application packaging run as a managed service: MSIX conversion, App-V migration, app attach for Azure Virtual Desktop, and a packaging pipeline your team can actually run. Search for help with MSIX and you'll mostly find software vendors selling you a tool. A tool doesn't inventory your estate, doesn't work out which of your 300 applications will never convert, and doesn't sit on a call at 8am when an app fails to register on a session host. That's the gap we fill: a UK supplier that does the packaging work, not a product you have to learn first. This service is for you if: - You've still got App-V packages, or an ageing packaging process, and you know MSIX is where Microsoft has gone - Packaging depends on one or two people who know the tricks, and the queue only moves when they're free - You're running Azure Virtual Desktop or Windows 365 and want applications out of the gold image The cost of doing nothing: Ad hoc packaging doesn't scale. Every application becomes a one-off, quality depends on who happened to build it, and there's no way to prove a package will behave the same on the next release. Meanwhile App-V sits on a support clock, the gold image keeps growing because it's easier than packaging properly, and each new starter or new app version reopens the same argument. The cost isn't a line on an invoice, it's the projects that stall behind the packaging queue. #### Application packaging services, delivered as a managed service We package line-of-business, legacy and third-party applications into MSIX and other modern formats so they install cleanly, update predictably and run wherever your users are: physical Windows 11 devices, Azure Virtual Desktop, or Windows 365 Cloud PCs. Conversion, remediation, signing, testing and delivery are all part of the work, not a list of things handed back to you as actions. We're deliberately tool-agnostic. The right approach for a clean MSI is not the right approach for a twenty-year-old app with a kernel driver and no installer left, and we'll tell you plainly when an application shouldn't be converted at all. Where an application needs capturing from its running state because the media is long gone, we bring in our delivery partner EtherApps Forge. Scope, volumes and commercials get sized against your actual estate at assessment rather than guessed at up front. What's included: - MSIX packaging, conversion and repackaging - App-V to MSIX migration, including the parts that don't convert automatically - App attach image builds for Azure Virtual Desktop (VHDX and CIMFS) - Code-signing certificate strategy and session-host trust deployment - Intune Win32 and MSIX packaging and deployment rings - Application testing, remediation and compatibility fixes - CI/CD packaging pipelines built and handed over to your team - Legacy capture with EtherApps Forge where installers no longer exist #### What is MSIX and why is Microsoft pushing it? MSIX is Microsoft's current Windows application packaging format, and it's the direction of travel for anything new. It installs into a container with a defined identity, writes user data to a redirected location rather than scattering it across the file system and registry, updates differentially instead of reinstalling, and uninstalls without leaving debris. It's also the format that app attach on Azure Virtual Desktop is built around. The practical benefit is predictability. An MSIX package behaves the same way on every machine that installs it, which is the thing that ad hoc MSI and EXE deployment never quite delivers. The practical cost is that MSIX is stricter: applications that assume they can write anywhere, install drivers, or register system-level services have to be reworked or left alone. #### Do all applications convert to MSIX? In a real estate you should expect a spread. A large share of well-behaved business apps convert with little or no work; a middle band converts but needs remediation, such as fixing hard-coded paths, splitting out a service component or reworking a shell integration; and a tail either can't convert or isn't worth converting. Part of what an assessment buys you is knowing which application sits in which band before you commit budget, rather than discovering it one app at a time. #### How does App-V to MSIX migration actually work? App-V to MSIX migration is a repackaging exercise, not a file conversion. Then rebuild the behaviour that App-V was providing using MSIX equivalents, test it against the real workflow, and roll it out in rings. App-V support is finite; the estates that struggle are the ones that leave the discovery until the deadline is visible. #### What is MSIX app attach, and do we need it? App attach delivers MSIX applications into an Azure Virtual Desktop session by mounting a disk image from a file share at sign-in, then registering the app for that user, instead of installing it into the gold image. The payoff is a small, stable base image and per-user application assignment, so adding or updating an app doesn't mean rebuilding and redeploying the image to every session host. It's worth it once you have more than a handful of applications, more than one user persona, or an image rebuild cycle that's become an event. If you have a single-purpose host pool running two apps for everybody, baking them into the image is honestly the simpler answer, and we'll say so. Microsoft has also moved on from the original per-host-pool model to a newer app attach design where packages are managed as subscription-level objects; which one you're on changes the operational detail, so we check before recommending anything. #### CIMFS or VHDX for app attach images? CIMFS uses noticeably less host resource per mounted image, which matters when a session host is mounting dozens of them for every user who signs in, so it's the default worth aiming at. VHDX is the older, broader-compatibility option and remains the reliable fallback. In hands-on testing we've hit packages that run correctly natively and from a VHDX image but fail from a CIM, so this isn't a purely theoretical choice. The practical rule: build CIMFS first, smoke-test every package from the image rather than from the MSIX, and fall back to VHDX for the ones that misbehave. CIM images also need housekeeping, because each one produces a .cim file plus object and region files in the same directory. Generate several into one folder and you get sprawl that's genuinely difficult to untangle later, so one folder per image, always. #### Certificate errors: why do app attach packages fail with "App contains untrusted signature"? Because the certificate that signed the package isn't trusted on the session host. Every MSIX must be code-signed, and the signing certificate has to chain to something the machine trusts. With an internal or self-signed certificate that means deploying it into the machine's Trusted People store on every host in the pool. Miss it and AVD returns a metadata expand failure with exactly that message, and MSIXMGR throws 0x800B010A for the same underlying reason. It's the single most common cause of a package that works perfectly on the packaging workstation and dies in production. The fix is boring and that's the point: decide early whether you're using a public CA certificate or an internal PKI, deploy trust as part of session host build automation rather than by hand, and track expiry, because a certificate that lapses takes every package signed with it down at once. #### What are the prerequisites for MSIX app attach? Six things, and a build stalls if any one of them is missing. A supported session host operating system, meaning Windows 10 or 11 Enterprise or their multi-session editions. A file share the session hosts can reach, usually Azure Files or Azure NetApp Files, with both the RBAC role and the NTFS permissions set. Every package expanded into a CIMFS or VHDX image rather than left as a raw MSIX. A code-signing certificate that chains to something every session host trusts. The application registered in Azure as an app attach package and assigned to the right application group. And enough network throughput between hosts and share, because app attach mounts the image at sign-in and a slow share shows up directly as a slow logon. Two things people expect to need and do not: a separate licence, because app attach is included with Azure Virtual Desktop, and a rebuild of the golden image, which is precisely the point of using app attach rather than baking applications in. #### Does app attach work with Citrix, or only Azure Virtual Desktop? App attach itself is an Azure Virtual Desktop feature, so on Citrix you would use Citrix App Layering or its own MSIX support rather than app attach. That said, the two coexist perfectly well in a mixed estate, and the packaging work carries across: an application correctly packaged as MSIX can be delivered through app attach on AVD and through Citrix on the Citrix side, without repackaging it twice. The format is the portable part, the delivery mechanism is not. This matters most to organisations part-way through a Citrix to AVD migration, where both platforms run side by side for a while. Doing the packaging properly once, in MSIX, means the migration stops being an application project as well as an infrastructure one. #### Can you use app attach on-premises, or is it cloud only? App attach is an Azure Virtual Desktop feature and needs the AVD control plane, so there is no on-premises-only version of it. On a traditional on-premises RDS farm the equivalent is delivering MSIX packages through the tools you already have, or using an on-premises file share with a third-party layering product. What does carry over is the packaging. MSIX packages built for app attach install perfectly well on on-premises RDS session hosts and on physical Windows 11 devices, so the conversion work is not wasted if part of the estate stays on-premises or moves later. We package for the format first and the delivery mechanism second, precisely so that decision stays open. #### What does Azure Files need for MSIX app attach? The share needs both layers of permission, and this is where most builds stall. Every session host's computer account needs access, which in practice means putting the machine accounts in a directory group, syncing that group to Entra ID, granting it the Storage File Data SMB Share Contributor role on the storage account, and then also setting the NTFS-level permissions on the file share itself. Getting the RBAC role right but not the share ACL produces a failure that looks like a packaging problem and isn't. Placement matters too. The whole operation of reaching the storage and mounting the image needs to complete inside roughly 400 milliseconds, so the share should sit in the same region as the session hosts, as close as the topology allows. Then exclude .VHD, .VHDX and .CIM files and the UNC path to the share from antivirus scanning; without those exclusions you get sign-in latency and intermittent registration failures that are miserable to diagnose. #### MSIX or Intune Win32: which should we use for what? Use MSIX where you want clean install and uninstall, containerised identity, differential updates, or app attach on AVD. Use Intune Win32 (.intunewin) where the application won't convert, where you need custom detection and requirement rules, dependencies and supersedence, or where you're wrapping an installer that has to run with full system access. Most estates end up running both, and that's the correct answer rather than a compromise. The decision is per application, not per organisation. A modern, well-behaved LOB app is a good MSIX candidate. A CAD package with a licensing service and a hardware dongle driver is not, and forcing it costs more than it returns. What we care about is that the routing decision is made deliberately and recorded, so the next person doesn't have to reverse-engineer why an app was packaged the way it was. #### Can you build us a CI/CD packaging pipeline? Yes, and for most organisations this is the part with the longest tail of value. A packaging pipeline takes a source installer or captured application, builds the package, signs it, runs automated install, launch and uninstall checks, publishes to your distribution point or app attach share, and records what was produced and by whom. Vendor releases a new version, the pipeline runs, and nobody has to remember the manual steps. We build it around what you already have, typically Azure DevOps or GitHub Actions with Intune or AVD at the delivery end, and we hand it over with documentation rather than keeping it as something only we can operate. The point is that packaging stops being a person and becomes a governed, auditable process. #### What if we've lost the installer for an application? It can usually still be packaged, by capturing the application from its current working installation rather than from setup media. This is the situation that blocks more Windows 11 and server migrations than any technical incompatibility: the vendor's gone, the source is gone, the MSI is on a share that was decommissioned in 2014, and one department still depends on the thing daily. For that work we use our delivery partner EtherApps Forge, which captures the installed state of a running application and repackages it for a modern, supported operating system. It's not magic and it isn't right for everything, but it turns "we can't move off that server" into a scoped piece of work with a testable output. #### How do you prove a package works before it reaches users? Every package gets tested against the way the application is actually used, not just whether the icon launches. That means install, launch, core workflow, file associations, printing where relevant, licensing activation, uninstall, and then re-install over the top. For app attach we test from the mounted image on a real session host, because a package can pass on a packaging workstation and still fail on stage or registration. When something fails, the evidence is in the MSIX and app attach event logs, which record the staging and registration sequence and the time each application took to register per user. That timing data is useful beyond troubleshooting; it tells you which applications are quietly adding seconds to every sign-in. Where user acceptance testing is needed, that's coordinated with your application owners, since they're the ones who know what "working" looks like. #### Why use an MSP rather than buying a packaging tool? Because the tool is the cheap part. Licensing a packaging product still leaves you needing someone who knows why a converted app crashes on second launch, how to structure a signing certificate strategy that doesn't expire into an outage, and what to do with the tail of your estate that won't convert. That knowledge takes years to build and walks out of the door when the person holding it resigns. Our packaging work sits on genuine first-hand ground. Our founder, Ryan Mangan, is a Microsoft MVP, a Fellow of BCS and the author of Mastering Azure Virtual Desktop (Packt), and maintains a public MSIX app attach reference wiki and open-source tooling on GitHub. You get that depth as a service you can scale up and down, based in Brough, East Yorkshire, working with organisations across the UK. #### Frequently asked questions **Do all applications convert to MSIX?** No. MSIX runs applications in a container, so anything installing kernel-mode drivers or Windows services, requiring elevation at runtime, installing other applications, hooking deeply into the shell, or writing into its own Program Files directory will either need significant remediation or can't convert at all. In a typical estate a large proportion of well-behaved business applications convert with little work, a middle band needs remediation, and a tail should be delivered another way, usually Intune Win32, or retired. Knowing which is which before you commit budget is the point of an assessment. **Is App-V really being retired, and what is the end of support date?** The date worth knowing is 14 April 2026, and the detail most summaries get wrong is what it applies to. That date is the end of extended support for the App-V server infrastructure: the Management, Publishing and Reporting servers. The App-V client and sequencer shipped in Windows 10 and Windows 11 Enterprise are not covered by it, because they follow the Windows lifecycle instead. So if you read that App-V died in April 2026, or that it did not, both claims are half right. What is unambiguous is that Microsoft's active investment is in MSIX; there will be no new App-V capability. Nothing breaks the day support ends, but you lose fixes and support, and you carry a virtualisation layer no one is developing. The risk in delaying isn't the deadline itself, it's that App-V estates almost always contain undocumented connection groups, scripts and dynamic configuration that take time to unpick. Start the discovery early, even if the migration itself runs later. **Does every MSIX package need a code-signing certificate?** Yes. Windows will not install an unsigned MSIX. You can use a certificate from a public CA or one from your own internal PKI; the requirement is that the signing certificate chains to something the target machine trusts, which for internal certificates means deploying it to the Trusted People store on every device or session host. If it's missing, AVD reports "App contains untrusted signature" and MSIXMGR returns 0x800B010A. Self-signed certificates are fine for lab and testing work but a poor choice for production, mainly because of the trust deployment and expiry burden. **What is the difference between MSIX and APPX?** MSIX is the successor to APPX and is built on the same container format, which is why the two look so similar from the outside. The practical difference is scope. APPX was designed for UWP applications from the Microsoft Store and could not package traditional Windows software. MSIX handles Win32, .NET and UWP in one format, which is the whole reason it can replace MSI, App-V and APPX rather than sitting alongside them. If you are looking at an existing APPX package, it will generally still install, but anything new should be built as MSIX. **Is MSIX app attach being deprecated?** The original MSIX app attach was retired on 1 June 2025 and replaced by app attach, which is the name to use now. It is a replacement rather than a removal: app attach does everything the old feature did and fixes its three worst limitations. Permissions are per application per user, so people only see the applications assigned to them rather than every package on the desktop application group. The same package can be used across multiple host pools instead of needing a separate copy for each. And a package can be upgraded to a new disk image without deleting and recreating the application, so upgrades no longer need a maintenance window. If you built on the legacy feature, moving to app attach is worth doing on its own merits, not just for support. **What's the difference between MSIX and MSIX app attach?** MSIX is the package format; app attach is a delivery mechanism for it on Azure Virtual Desktop. With app attach the MSIX is expanded into a VHD, VHDX or CIM image, stored on a file share such as Azure Files, mounted to the session host and registered for the user at sign-in. The application never gets installed into the gold image. You can absolutely use MSIX without app attach, deploying it through Intune to physical devices or Cloud PCs, and many organisations do exactly that. **Should we use CIMFS or VHDX for app attach images?** Start with CIMFS, because it consumes materially less host resource per mounted image, which matters when a session host mounts many images per user sign-in. Keep VHDX as the fallback: not every MSIX package behaves correctly from a CIM image, and we have seen packages run fine natively and from VHDX but fail from CIMFS. Test each package from the mounted image itself, not just as an MSIX. Whichever format you use, create a dedicated folder per image, because CIM images produce multiple related files that become very hard to separate if they're generated into a shared directory. **What does app attach need from Azure Files?** The session hosts' computer accounts need access to the share at both the RBAC and the NTFS level. In practice: add the machine accounts to a directory group, sync it to Entra ID, grant that group Storage File Data SMB Share Contributor on the storage account, then set permissions on the file share itself. Place the storage in the same region as the session hosts, since the end-to-end operation of accessing and mounting an image needs to complete in roughly 400 milliseconds. Finally, exclude .VHD, .VHDX and .CIM files and the share path from antivirus scanning, or you'll see sign-in delays and intermittent failures. **Will app attach slow down user sign-in?** It can, if it's configured carelessly. Use on-demand registration so full registration is deferred until the user actually launches the application, rather than logon-blocking registration which completes during sign-in and lengthens it. Keep the storage close to the session hosts, apply the antivirus exclusions, and be honest about how many packages you're assigning per user. The MSIX event log records per-application registration time, so you can see precisely which applications are costing you seconds rather than guessing. **Can you package applications where we've lost the installer?** Usually, yes. Rather than needing the original setup media or source code, the application is captured from its current working installation and repackaged for a modern operating system. We do this with our delivery partner EtherApps Forge. It's the route that unblocks most stalled Windows 11 and Windows Server migrations, where the technical blocker isn't the OS at all but one legacy application nobody can reinstall. It isn't right for every application, and we'll tell you at assessment if it isn't right for yours. **Do we have to move all our packaging to you, or can you supplement our team?** Either. Some clients hand over packaging entirely as an ongoing managed service; others have a capable internal team and want us for overflow, for a specific App-V migration, for app attach design, or to build a CI/CD packaging pipeline and hand it over. Where we build a pipeline, it's built on your tooling and documented so your team can run it without us. We'd rather leave you with a capability than a dependency. **How much does application packaging cost?** It depends almost entirely on the mix of applications rather than the headline count, so we size it against your estate at assessment rather than quoting a per-app rate that would be meaningless. A hundred modern, well-documented business applications and a hundred undocumented legacy applications with missing media are very different pieces of work. Discovery gives you a per-application complexity picture first, so the commercials are based on what's actually there. Get in touch and we'll scope it properly. ### Legacy Modernisation & OS Migration URL: https://systechitsolutions.co.uk/services/legacy Migrate off end-of-life Windows and Server safely: Windows 11 rollouts, Server 2012/2016 upgrades and legacy app capture, even without the original media. From Windows 10, Windows 7 and end-of-life servers to Windows 11 and the latest Windows Server, even when the install media is long gone. The real blocker to leaving an unsupported operating system behind usually isn't the OS. It's the one legacy application nobody's touched in years that only runs on it, and that nobody has the install media for any more. This service is for you if: - You're running end-of-life or soon-unsupported Windows desktop or Windows Server - A legacy line-of-business application is the reason migration keeps getting pushed back - The install media, source code or original vendor for that app is long gone The cost of doing nothing: Unsupported servers and applications don't fail gracefully, they fail during an audit, a compliance review, a cyber-insurance renewal, or a hardware death with no vendor left to call. Every month on an unsupported OS is unpatched risk, rising cost and, increasingly, an avoidable carbon footprint on ageing kit. #### Bring legacy systems safely up to date Unsupported operating systems are a serious security and compliance risk, but migrating away from them is rarely straightforward. We move you off Windows 7, Windows 10 and end-of-life Windows Server (2008, 2012, 2016) onto modern, supported platforms. We handle the whole journey, from Windows 11 rollouts to upgrading old servers to Windows Server 2022 or Azure, resolving legacy application compatibility along the way. Where the install media is gone, we capture the application from its running state with EtherApps Forge and repackage it for a modern OS, so nothing gets left behind. What's included: - Windows 7 and Windows 10 to Windows 11 migration - Windows Server 2008, 2012 and 2016 to 2022 or Azure - Legacy application capture and repackaging, even with no install media - Upgrade path assessment and risk planning - Secure decommissioning of old systems - Phased migration with minimal downtime #### Where does a migration off an unsupported OS actually start? With an inventory, because you cannot prioritise what you have not counted. For desktops that means every device with its hardware specification and whether it clears the Windows 11 hardware bar, its operating system build, who uses it and for what, and what is installed on it. Hardware eligibility is the single biggest determinant of which route a machine takes, and it is the one thing organisations most often estimate rather than measure. When it is measured properly, the population that genuinely cannot move is usually smaller than assumed, which changes the budget conversation immediately. For servers the inventory question is different and harder: not what the machine is, but what it does. The awkward finding is rarely a server nobody knew about, it is a server everybody knew about and nobody could fully describe: a month-end scheduled task, a print queue, an SMB share hard-coded into a piece of production equipment, a certificate authority somebody stood up years ago. Discovery is not a formality here. The cost of a server migration is decided during discovery, not during the build, and the projects that overrun are almost always the ones that started building before they finished looking. #### How do you test application compatibility before rollout day? By finding the blockers while there is still time to do something about them, which means testing in a pilot rather than discovering them on the morning of a wave. The blockers cluster in predictable places. Applications tied to a specific runtime, driver or browser behaviour. Anything with a hardware dongle, a serial or parallel interface, or a connection to production equipment. Line-of-business software from a vendor who has not certified the new platform, which is the single most common blocker and is entirely outside your control once you hit it, so ask early and get the answer in writing. Printing and scanning workflows, which are routinely omitted from testing and are the first thing users notice. And the application nobody listed because only three people use it, one of whom is in finance and needs it at month end. #### Windows 10 end of life: what are the options for your devices? Free Windows 10 support ended on 14 October 2025, so every remaining device now sits in one of four routes: upgrade in place, replace the hardware, buy Extended Security Updates, or move the user to a cloud desktop. The important point is that the right answer is a property of the device, not of the business. Most estates end up using two or three of these rather than picking one for everything, and the allocation comes from the inventory rather than from a preference. The back-office machine that never leaves one desk and touches nothing sensitive can wait, provided somebody has decided that deliberately and written it down. #### Windows 10 ESU: when is it the right call, and when is it a trap? It is the right call for a small, named list of devices with a genuine reason and a date attached: an ageing line-of-business application still in compatibility testing, hardware on order with a lead time, staff retraining in progress. For businesses, Windows 10 ESU is purchased through the Volume Licensing Program, and per Microsoft's published pricing it starts from around 61 US dollars per device in year one and doubles each consecutive year for a maximum of three years, which in principle extends protection to October 2028. Run the arithmetic across the full runway rather than one year and it comes to roughly 427 dollars a device over three years, which is a very different number from the one usually presented to a budget holder. #### What is happening with Windows Server, and what is the January 2027 date? Extended support for Windows Server 2016 ends on 12 January 2027. Mainstream support ended on 11 January 2022, so those machines have been on security-fixes-only for several years already, which is why they tend to be the least documented boxes in the estate. Older releases, 2008 and 2012, are further past that line again. If you work on annual budget cycles there is realistically one more budget round between now and the 2027 deadline, so the practical deadline for deciding is this autumn rather than next, and the practical deadline for starting is comfortably before the Christmas change freeze. Server ESU is purchasable for up to three years at a rising annual cost, and it leaves you on the same unsupported platform, so treat it as cover for a migration already scheduled rather than an alternative to one. #### Why is 'just move it to Azure' a different decision now? Because the discount that used to decide it has gone. For previous end-of-support cycles the well-worn move was to lift the server into Azure, where Extended Security Updates were included at no additional cost, which made moving to Azure the obvious financial answer almost regardless of the technical merits. From 1 April 2026, Microsoft moved to consistent ESU list pricing: the same list price for new ESU offerings whether you run in Azure, on-premises or in another public cloud. Some Azure-adjacent platforms such as Azure Local and Azure Stack retain no-cost ESU, but the general route of rehosting and thereby stopping paying is closed. Moving to Azure may still be the right call for your estate. It just has to win on its own merits now: getting out of a datacentre, off ageing hardware quickly, or onto a platform where the workload can be modernised next. What it also has to survive is the consumption question, because a server rehosted at its on-premises size and left unoptimised produces a monthly bill rather than a sunk asset. That is why we schedule cost optimisation as a phase after a rehost rather than treating it as a separate conversation later, and it is the same work as our cost management and Azure optimisation service. #### What does a staged rollout actually look like? Waves, grouped by risk rather than by alphabet or by floor. A pilot group first, small, technically tolerant and drawn from across departments so the applications being exercised are representative rather than just IT's. Then early adopters, then the general population in waves grouped by hardware eligibility and business function, then the sensitive machines last: the ones tied to production equipment, month-end processes or a single irreplaceable application. Each wave has a defined success criterion and a pause point, so a problem found in wave two does not automatically arrive in wave three. The parts that determine whether users experience this as an upgrade or an outage are mundane. A build standard, so devices arrive configured rather than hand-assembled. A tested data and settings migration path, with a rollback for the machine where it goes wrong. Clear communication about what changes and when, because the support calls come from surprise more than from defects. Someone on hand on the morning after a wave, when everybody discovers the thing that was not tested. And a hard end date worked back from, treated as a countdown rather than a comfort blanket, because migrations without a fixed date reliably stall at about seventy per cent when something more urgent appears. #### What actually goes wrong, and how do you avoid it? Four failure modes account for most overruns, and the technical migration is rarely one of them. Nobody knows what the server does, so a role or a dependency surfaces after cutover. The application vendor has not certified a current release, which is the most common blocker and entirely outside your control once you hit it. The server being migrated is also part of what would let you recover, because backup infrastructure lives on the platform you are moving. And licensing gets assumed rather than checked, since server licensing changed meaningfully between older and current releases and the client access licences you hold may not cover what you are moving to. On the desktop side the pattern is different but equally predictable. Unsupported machines are kept alive quietly, outside the plan, because one person needed one thing and nobody logged it, so the estate contains exceptions the reporting does not show. Application blockers are found on rollout day rather than in the pilot, because testing covered the applications IT knows about. Hardware eligibility was estimated rather than measured, so the wave plan is wrong from the start. And ESU gets bought as a decision rather than a bridge, then silently rolls into a second and third year at double and quadruple the price, which is the outcome the pricing model is specifically designed to produce. #### The install media is gone and the vendor no longer exists. Now what? This is the single most common reason a legacy application is still running on a machine nobody is allowed to touch, and it is more solvable than it looks. Reinstalling is therefore not an option, because there is nothing to reinstall from. The working installation becomes the only copy of the application that exists anywhere. That is why the estate freezes. The machine cannot be patched in case it breaks, it cannot be rebuilt because it cannot be reinstalled, and it cannot be retired because the business still needs what it does. Everybody knows it is a problem and nobody can be the person who touches it. The route out is to stop trying to reinstall it. An application can be captured from its current running state, packaging what is actually installed and configured on the machine rather than needing the original installer or the source code. The capture is then deployed and tested on a supported operating system, which turns an irreplaceable machine into a package you can redeploy at will. It does not work in every case, and we will tell you early when it does not. Applications tied to specific hardware, dongles or licence servers that phone home to something that no longer exists need those problems solved separately. But the missing installer on its own, which is what stops most of these projects before they start, is not the obstacle people assume. #### What about applications from the Windows XP era? They are more likely to move than their owners expect, and the reason is that most of them were simpler than modern software. An application written for that era typically does less that a modern operating system objects to: fewer background services, less deep integration, and often nothing more exotic than a database connection and a user interface. The things that genuinely break tend to be a specific and identifiable list rather than a general incompatibility. Most of that list is addressable in packaging or configuration. The 16-bit case is the genuine wall, because there is no supported way to run 16-bit code on 64-bit Windows, and when we find one the honest answer is isolation or replacement rather than a migration that was never going to work. Worth saying plainly: an application of that age should be on a plan to be replaced, and we will say so. But being on a plan is different from being an emergency, and getting it onto a supported, patched, backed-up platform first buys the time to do the replacement properly rather than under pressure. #### What happens when the application genuinely cannot move? It is usually one application holding one machine hostage, rather than a whole estate that is stuck. That machine then becomes the exception in every patching cycle, the device security reporting has to footnote, and eventually the reason a wider upgrade stalls entirely. The reasons the application cannot simply be reinstalled elsewhere are always the same short list: the install media is long gone, the vendor no longer exists, nobody has the source code, or the person who set it up left years ago. Where that is the blocker we capture the application from its current, working installation using EtherApps Forge from our partner EfficientEther, packaging its actual installed state rather than needing the original setup media or source. That capture is then deployed and tested on a modern, supported operating system, typically in weeks rather than months. It is not magic and it is not right for everything: the output still needs testing and remediation, and it does not rescue an application that is fundamentally incompatible with a modern platform. What it does is turn 'we cannot move off that server' into a scoped piece of work with a testable output, which is either the destination or a safe bridge while a proper rebuild happens on its own timeline. #### Why does staying put cost more than it looks? Because the comparison that keeps legacy systems alive counts the migration cost and treats the status quo as free. It is not. All of it sits in budget lines that never get attributed to the machine that caused them. There is engineering time, because legacy systems consume support effort out of proportion to their number, break in ways that can only be worked around, and are understood by two people so the work cannot be distributed. Then there is the exposure that shows up at the worst moment. Cyber Essentials requires software in scope to be supported and receiving security updates, so an unsupported system either fails the assessment or has to be properly segmented out of scope, which is work in itself, and a renewal you were treating as a formality can suddenly block a contract. Cyber insurance applications ask directly whether you run unsupported software, and answering carelessly affects whether a claim gets paid rather than merely what it costs. And there is the opportunity cost, which is the least visible and often the largest: one machine holding a dependency, requiring a flat network segment or an old authentication method, with several other projects sitting in a queue behind it. #### How long does this take, and what happens to the old kit? For a server estate the shape that works for most mid-sized organisations is discovery over two to four weeks, route decision and costing over about two weeks, build and test over four to eight weeks, then cutover in waves and decommissioning afterwards. A small estate of a few servers with well-understood applications is realistically six to eight weeks including testing. Where vendor sign-off is needed or roles are undocumented, plan for three to six months, and expect discovery to be the stage that runs long. Desktop rollouts vary more with headcount and hardware eligibility, which is why the inventory comes first. Decommissioning is the step most often left half-done, and leaving old systems powered on 'just in case' is how an estate ends up with two of everything. Doing it properly means confirming nothing still depends on the machine, keeping a final restorable copy of its data for a defined retention period, removing it from monitoring, backup, licensing and documentation, and then secure data destruction with certificates of erasure for anything holding personal data and WEEE-compliant disposal for the hardware. There is a running cost argument too: older hardware is simply less power-efficient per unit of compute than anything bought recently, so a server room kept alive for one application is a power and carbon line as well as a support line, and that is increasingly something organisations have to report on rather than merely absorb. #### Frequently asked questions **Can you migrate a legacy app if we've lost the install media?** Usually yes, and it is the most common reason these applications are still stuck. The route is to stop trying to reinstall: using EtherApps Forge we capture the application from its current working installation, packaging what is actually installed and configured rather than needing the original setup media, the licence key or the source code. That capture is then deployed and tested on a supported operating system, which turns an irreplaceable machine into something you can redeploy at will. It is not universal. Applications tied to specific hardware, dongles or licence servers that call home to something no longer running need those solved separately, and we will tell you early when that is the case. **Can a Windows XP-era application run on Windows 11?** More often than people expect, because software of that age usually does less that a modern operating system objects to. The failures come from a specific list rather than general incompatibility: assuming administrative rights, writing to protected locations, old runtimes or database drivers that need packaging alongside it, hard-coded paths to servers that no longer exist, and outdated TLS or authentication that modern systems refuse. Most of that is fixable in packaging. The real wall is 16-bit code or installers, which cannot run on 64-bit Windows at all, and where we find that the honest answer is isolation or replacement rather than a migration that was never going to work. **Should we migrate a legacy application or rewrite it?** It depends on runway. A full rewrite is often a twelve-to-eighteen-month project, and an app on an already-unsupported OS rarely has that time. Capture-based migration gets it onto a modern platform in weeks, which can be the destination or a safe bridge while a rewrite happens on its own timeline. **What are the risks of staying on an unsupported operating system?** Unpatched security vulnerabilities, failed compliance and cyber-insurance requirements, no vendor support when hardware fails, and a growing energy and carbon cost from keeping ageing kit running. The risk compounds every month, usually surfacing at the worst possible time. **How much does Windows 10 ESU cost, and can we buy just year two?** For businesses ESU is bought through the Volume Licensing Program, and per Microsoft's published pricing it starts from around 61 US dollars per device in year one and doubles each consecutive year for up to three years, which works out at roughly 427 dollars a device across the full run. You can't buy year two on its own: coverage is cumulative, so if you skipped year one you have to buy it as well to get current. Waiting therefore costs more rather than less, and there's no discount for the months you went unprotected. The escalation is deliberate, and it's the same pattern used for Windows 7. **When does Windows Server 2016 support end, and what should we do now?** Extended support ends on 12 January 2027, and mainstream support ended on 11 January 2022, so those machines have been on security-fixes-only for several years already. If you budget annually there's realistically one more budget round before the deadline, which makes this autumn the practical deadline for deciding and before the Christmas change freeze the practical deadline for starting. The four routes are in-place upgrade, replace the hardware, rehost as an Azure VM, or modernise the workload onto a managed service. Most estates use two or three of those across different servers rather than picking one. **Isn't moving servers to Azure still the free way to get ESU?** Not any more, and this catches people out. For previous end-of-support cycles, lifting a server into Azure came with Extended Security Updates at no additional cost, which made moving to Azure the obvious financial answer almost regardless of technical merit. From 1 April 2026 Microsoft moved to consistent ESU list pricing, meaning the same list price for new ESU offerings whether you run in Azure, on-premises or in another public cloud. Some Azure-adjacent platforms such as Azure Local and Azure Stack retain no-cost ESU. Azure may well still be the right destination, it just has to win on its own merits now. **How do we know which of our devices can actually take Windows 11?** From the inventory, measured rather than estimated, because hardware eligibility is the single biggest determinant of which route each machine takes and it's the thing organisations most often guess at. In practice the population that genuinely can't move is usually smaller than assumed once it's checked properly, which changes the budget conversation straight away. The assessment covers hardware eligibility per device, the applications installed on it, who uses it and for what, and its exposure, so machines can be grouped into waves by risk rather than by department. **Our software vendor hasn't certified the new Windows Server version. What then?** It's the most common blocker we hit and it's entirely outside your control once you're in it, so ask the vendor early and get the answer in writing rather than over the phone. If certification is coming, the date determines your sequence and ESU may be legitimate cover for that specific gap. If it isn't coming, the decision moves from a migration to a replacement or a capture-based migration, and both need lead time you won't have if the question is asked in the build phase. This is exactly why discovery runs before design: the cost of a server migration is decided during discovery, not during the build. **How long does a migration take?** For servers, the shape that fits most mid-sized estates is two to four weeks of discovery, around two weeks to decide and cost the route, then four to eight weeks to build and test before cutover in waves. A small estate of a few servers with well-understood applications is realistically six to eight weeks including testing. Where vendor sign-off is needed or server roles are undocumented, plan for three to six months, and expect discovery to be the stage that runs long. Desktop rollouts vary more, because the timeline is driven by hardware eligibility and application testing rather than by headcount alone. ### End-User Computing URL: https://systechitsolutions.co.uk/services/euc Our founder wrote Mastering Azure Virtual Desktop (Packt). Systech designs, tunes and manages AVD and Windows 365 for UK businesses. Windows 365 and Azure Virtual Desktop, designed and run by a team whose founder wrote the book on AVD. Virtual desktop projects rarely fail on go-live day. They fail three months later, when logons crawl, the Azure bill lands well over forecast, and nobody can say whether one is causing the other. Both trace back to design decisions made early and never revisited. Both are avoidable. This service is for you if: - Your people work across locations and devices, including their own, and the data shouldn't live on any of them - You're weighing up Windows 365, Azure Virtual Desktop or a mix, and want a straight recommendation rather than a licence sale - You already run AVD, it's slower or dearer than it should be, and whoever built it has moved on The cost of doing nothing: Laptops scatter your data across the country and put it one theft away from an incident. The alternative goes wrong just as quietly: an AVD estate stood up from a reference deployment and never revisited bills for session hosts nobody is logged into, mounts profile containers on storage that can't cope with the 9am login wave, and carries an image so stuffed with applications that patching it has become a project. None of that shows on day one. It shows on the invoice, and in the helpdesk queue. #### Virtual desktops that stay fast, and stay affordable We design, build, migrate and manage Windows 365 and Azure Virtual Desktop for UK businesses, and we're platform-agnostic about where you land. Cloud PCs for some users, pooled multi-session hosts for others, or both. The job is matching the platform to how your business actually works, not to whichever licence is easiest to sell. The difference shows up in the unglamorous parts: how profile containers are laid out, what the scaling plan does at six on a Friday, whether an application belongs in the image or attached at sign-in. Those decisions separate an estate people like using from one they merely tolerate. What's included: - Windows 365 and Azure Virtual Desktop design, build and migration - Host pool sizing, user density and autoscale scaling plans - FSLogix profile containers and Azure Files storage design - Golden images versioned through the Azure Compute Gallery - Application delivery, including MSIX packaging and App Attach - Intune, Microsoft Entra ID and Conditional Access integration - Cost review: right-sizing, pooling, storage tiering, reservations - Ongoing management, monitoring and performance tuning #### Windows 365 or Azure Virtual Desktop: which one fits us? Windows 365 if headcount is steady and you want a fixed per-user price with nothing to size. Azure Virtual Desktop if headcount moves, if multi-session economics pay off at your scale, or if you need GPU-backed hosts. The table below compares the points that actually change the answer. It's often both: permanent staff on Cloud PCs where simplicity beats flexibility, seasonal or specialist teams on pooled AVD hosts that scale down when they go home. A mix isn't a fudge, it's usually cheaper. What matters is choosing deliberately rather than defaulting. #### Who actually designs the environment? Ryan Mangan, Systech's founder, wrote Mastering Azure Virtual Desktop for Packt Publishing, across two editions, the first published in March 2022. He's a Microsoft MVP and a Chartered Fellow of the BCS, and maintains a public MSIX App Attach knowledge base that other engineers use when they get stuck. What that's worth to you is narrow but real: reference texts get written by people who have already hit the failure modes and then had to explain them to strangers. You aren't funding someone learning the platform on your estate. The credential is the shortcut; the depth on this page is the evidence. #### Why do Azure Virtual Desktop costs overrun? Nearly always because session hosts run when nobody is logged into them. Pools get sized for Monday-morning peak at launch, then stay that size overnight, at weekends and through every quiet week. An autoscale scaling plan that ramps down out of hours is a configuration change, not new infrastructure, and it's the biggest single lever. Reserve last, after right-sizing, or you commit to the wrong number. #### How do you keep virtual desktops feeling fast? Speed on a virtual desktop is mostly a profile and storage problem, not a CPU one. Users judge it in the thirty seconds after they click connect, and that window is dominated by how quickly the FSLogix container mounts. If the storage behind it can't serve the IOPS of a simultaneous login wave, everyone queues, and adding vCPU fixes none of it. After that: user density per host, media redirected so Teams and browser video render on the endpoint rather than in the session, sensible protocol and graphics settings, and a lean container. We test against a real login wave, because one test login at 2pm proves nothing about Monday at 8:55. #### What goes wrong with FSLogix profiles? Two faults recur. The first is storage sized for capacity instead of concurrency. FSLogix mounts a per-user VHD(X) at sign-in, so a share that copes with a trickle of logins collapses when three hundred people arrive at once. Splitting profiles across shares, and matching the Azure Files tier to real demand, is the fix. The second is containers that grow without limit because nobody set exclusions. Teams and browser caches, OneDrive cached files and search index data end up roaming inside the profile, slowing every mount and eventually filling the share. Add no housekeeping for containers left locked after an ungraceful disconnect, and profiles become the worst part of the day. #### How do you size a host pool without guessing? By measuring peak concurrent sessions, not headcount. Most estates never see more than a fraction of their users signed in at the same moment, so sizing to total staff builds in permanent overspend. Concurrency, the shape of the working day and the mix of light and heavy users are what set the number. vCPU and memory per user then come from the actual application set, not a rule of thumb. A browser-and-Office user and someone running a chatty line-of-business client aren't the same workload and often shouldn't share a pool. Sizing is perishable too, so it gets revisited as applications change. #### How do applications get delivered to a virtual desktop? Three routes, and most estates use all of them: baked into the golden image, installed per host by Intune or Configuration Manager, or attached at sign-in with App Attach. The skill is knowing which application belongs where. Anything that changes often should never be in the image, or every update becomes a rebuild. App Attach expands an MSIX package into a VHDX or CIM image on an SMB share, mounts it to the session host and registers it per user, so the application appears for entitled people without ever being installed. It keeps images thin. It also needs signed packages, the right share permissions for session-host machine accounts, and disciplined CIM folder layout, or you get sprawl. #### How do you manage images without it becoming a chore? By versioning them, and never hand-patching a running host into a snowflake. Images are built repeatably from a current multi-session base, versioned into the Azure Compute Gallery and replicated to the regions your host pools live in, then rolled out in stages with the previous version still there to fall back to. Everything else goes to Intune or App Attach, on its own update schedule. Skip that and you are patching by hand within months. #### Is a virtual desktop actually more secure than a laptop? Generally yes, because the data never reaches the endpoint. The local device renders a session and nothing else, so a laptop that's lost, stolen or quietly kept by a departing contractor has no company data on it to breach. That removes a category of incident rather than mitigating it. The rest comes from what you put around it. Conditional Access can require a compliant device, a known location or an acceptable sign-in risk before a session opens. Intune policy applies to the session host itself. Local admin rights, clipboard and drive redirection are scoped deliberately. Access is revoked centrally the day someone leaves. #### Can you take over an environment somebody else built? Yes, and much of the AVD work we're asked to do starts that way. The trigger is usually one of three things: the bill, logon times, or the person who designed it having moved on with nobody left who knows why it's configured the way it is. We read what's there before changing anything: host pool and scaling plan configuration, image lineage, FSLogix and storage design, licensing, Conditional Access, application delivery. Plenty of it will be sound, and saying so is part of the job. What's genuinely wrong is normally a handful of early decisions, not the whole build. #### Hosted desktop, virtual desktop, Cloud PC: which one do you actually mean? Usually the same thing, described by whichever term you met first, and the vocabulary gets in the way of the decision more often than the technology does. A hosted desktop is a Windows desktop running in somebody else's data centre that you reach over the network. #### What does it cost, and how does an engagement work? It's sized at assessment, because the two variables that drive everything (how many people, and what they actually run) differ enormously between businesses of the same headcount. Anyone quoting a virtual desktop programme without looking at your application set is guessing. Platform cost splits cleanly. Windows 365 is a fixed per-user licence for a given Cloud PC size, predictable to the pound. AVD is per-user licensing plus the Azure compute and storage you actually run, and that second part is the bit good design moves. Our free assessment gives you a straight recommendation and no obligation. #### Frequently asked questions **What's the difference between Windows 365 and Azure Virtual Desktop?** Windows 365 gives each user a dedicated Cloud PC at a fixed per-user, per-month price, with no infrastructure to size. Azure Virtual Desktop runs on your own Azure subscription and supports pooled multi-session hosts, autoscaling and GPU-backed VMs, so it's often cheaper at scale, but it has to be designed and maintained. Plenty of organisations run both. **Why choose Systech for Azure Virtual Desktop?** Because our founder, Ryan Mangan, wrote Mastering Azure Virtual Desktop for Packt Publishing across two editions, and is a Microsoft MVP and Chartered Fellow of the BCS. The decisions that shape your estate (pool sizing, FSLogix, image strategy, application delivery, autoscale) are made by someone who has already documented how each of them goes wrong. **Do we need Intune and Entra ID to run Windows 365?** It depends on the edition. Windows 365 Business is capped at 300 users with no infrastructure prerequisites, so a small team can run without Intune or a domain. Enterprise has no cap and unlocks custom images, Conditional Access and full Intune management, but requires Microsoft Entra ID, Intune, and eligible Windows and Microsoft 365 licences per user. **What is FSLogix, and do we still need it?** FSLogix stores a user's Windows profile in a VHD(X) container on a file share and mounts it at sign-in, so someone landing on a different session host each day still gets their own settings, Outlook data and personalisation. Pooled multi-session AVD needs it, and the storage behind it must be sized for a login wave. On Windows 365 the profile lives on the dedicated Cloud PC. **What is MSIX App Attach, and when is it worth using?** App Attach delivers an application by mounting it from a VHDX or CIM image on an SMB share and registering it per user at sign-in, rather than installing it on the host. It's worth using when you want a thin, stable golden image, when different teams need different applications from one host pool, or when an app updates often. It needs signed packages and correct share permissions. **Can Azure Virtual Desktop handle CAD, design or other GPU workloads?** Yes. AVD supports GPU-backed VM series for CAD, 3D design and rendering, with graphics drivers and protocol settings configured to use them. Those hosts are usually dedicated rather than pooled and are the expensive part of any estate, so they belong on their own host pool with their own scaling plan. Windows 365 has no GPU option, which often settles it for design teams. **Is moving to virtual desktops cheaper than buying laptops?** It changes the shape of the spend more than it guarantees a smaller number. Hardware refresh becomes an operating cost, and endpoints last longer because they only render a session. Whether the total lands lower depends on your user mix and, for AVD, on whether the environment is tuned. An untuned estate can cost more than the laptops it replaced. **Does this help with Windows 10 end of life?** It can, and it's a common reason businesses look now. Moving users onto Windows 11 Cloud PCs or Windows 11 multi-session host pools puts them on a supported desktop without replacing every physical machine, because the endpoint is only rendering the session. For remote workers, contractors and hardware that can't take Windows 11, it's often the least disruptive route. **Do you fully manage the environment, or just build it?** Both are available, and most clients want the ongoing side: scaling plans as working patterns shift, image versions and patching, FSLogix container health and storage performance, application delivery, Conditional Access policy, and periodic cost review. Scope is agreed at assessment, so you're not paying us to manage something you'd rather run yourself. ### Azure Virtual Desktop Consultancy URL: https://systechitsolutions.co.uk/services/avd-consultancy Specialist AVD consultancy: cost assessment, TCO analysis, host pool design and migration, from a Microsoft MVP renewed specifically for AVD. Assessment, migration and cost optimisation for Azure Virtual Desktop, led by the Microsoft MVP who wrote the book on it. An AVD estate almost never fails at go-live. It fails quietly, months later, when the Azure bill has drifted well past the business case and nobody left in the building can explain why host pools are sized the way they are. This service is for you if: - You're evaluating Azure Virtual Desktop against Windows 365 and want a straight recommendation, not a licence sale - You already run AVD and the bill, the logon times, or both, have crept somewhere you can't justify - You need a specialist AVD assessment, migration or cost review, not a generalist reseller's best guess The cost of doing nothing: AVD is the platform with the most levers, which is exactly why it's the one most often left un-tuned. Host pools sized for a Monday peak keep running at that size every night and weekend, FSLogix storage bought on habit rather than measured concurrency, and an image so bloated with applications that a routine patch cycle has become a quarterly project. None of it trips an alarm. It just shows up on the invoice, a little worse every month, until a renewal or a budget review forces the question nobody had an answer to. #### Azure Virtual Desktop, assessed, built and tuned properly We run AVD consultancy as three distinct phases, and we're explicit about which one you're buying. Assessment: a structured review of your current estate, or your requirements if you haven't built yet, covering host pool design, FSLogix and storage, image strategy, autoscale configuration, licensing and actual Azure spend against actual usage. Migration: the build or rebuild itself, sized and sequenced from what the assessment found, not from a template deployment. Optimisation: the ongoing discipline of keeping cost and performance tuned as headcount, applications and Azure's own pricing all keep moving after go-live. Every recommendation is scoped to your actual application set and concurrency pattern rather than a rule of thumb, because that's where AVD's cost and performance both genuinely get decided. Where Windows 365 is a better fit for part or all of your estate, we'll say so in the assessment rather than build AVD anyway. What's included: - AVD cost and performance assessment, with a written TCO analysis against your actual usage - Host pool sizing, VM SKU selection and autoscale scaling plan design - FSLogix profile containers and Azure Files storage design for real concurrency - Golden image build and versioning through the Azure Compute Gallery - Application delivery strategy: image, Intune Win32, or MSIX App Attach - GPU host pools for CAD, design and rendering workloads - Migration of an existing AVD environment someone else built - Ongoing cost optimisation, monitoring and performance tuning #### What does an AVD consultancy engagement actually involve? Three phases, run as separate, honestly scoped pieces of work rather than one undifferentiated project. The assessment comes first and is deliberately cheap to say yes to: we look at what you have or what you're planning to build, and hand back a written recommendation covering platform fit, host pool design, storage, image strategy and a genuine cost projection, not a sales deck. Nothing gets built on the strength of a hunch. #### When is AVD more cost-effective than Windows 365, and when isn't it? AVD wins on cost at scale and with variable demand, because pooled multi-session hosts and autoscale mean you stop paying for a seat the moment nobody's using it. A host pool that ramps down overnight and at weekends can genuinely halve its own footprint compared with the hours it covers at peak, and that saving compounds across every user sharing the pool. It also wins outright wherever the workload needs something Windows 365 doesn't offer at all: GPU-backed hosts for CAD or rendering, or fine-grained control over VM sizing that a fixed Cloud PC tier can't match. Windows 365 wins where headcount is stable and nobody wants infrastructure decisions: a fixed per-user, per-month price with no pool to size, no scaling plan to tune, and a bill that doesn't move with Azure's own pricing changes. The honest crossover point isn't a fixed number of users, it's whether your concurrency is predictable. A team that's logged in nine-to-five, every seat, every day, gets little benefit from AVD's ability to scale down, so the design overhead buys you less than the simplicity Windows 365 offers instead. We size this against your real login data at assessment rather than a rule of thumb, because we've seen the crossover point sit in very different places for two businesses of identical headcount. #### What does a genuine AVD cost optimisation checklist cover? In the order we work through it: autoscale first, because a scaling plan that ramps host pools down out of hours and at weekends is the single biggest lever and it's a configuration change, not new infrastructure. Then VM SKU right-sizing, because pools are routinely left at whatever size the original deployment guide suggested and run under half capacity at peak. Then session density, checking whether users who'd happily share a multi-session host have instead been given dedicated ones out of caution rather than need. Licensing is the final check: AVD access rights bundled into Microsoft 365 E3/E5, Business Premium or a standalone per-user licence are easy to duplicate-purchase without anyone noticing. #### How do you size host pools and scaling plans without guessing? From measured peak concurrent sessions, not headcount. Almost no estate has every user signed in at once, so sizing a pool to total staff bakes in permanent overspend from day one. We look at the actual shape of the working day: when sessions start, when they peak, how long they run, and what proportion of users are ever concurrent, and size the pool to that pattern with headroom rather than to a worst case that rarely happens. VM SKU and user density then come from the application set that pool actually runs, because a browser-and-Office user and someone running a memory-hungry line-of-business client aren't the same workload and often shouldn't share a host at all. The scaling plan is built around the same data: ramp-up ahead of the real login wave, a peak period sized to actual concurrency rather than headcount, and ramp-down that's aggressive enough to matter but doesn't force users to wait for a host to spin up. #### What's genuinely different about managing AVD versus managing Windows 365? Windows 365 management is close to managing a subscription: assign or remove a Cloud PC licence, and Microsoft handles the underlying host. AVD management is closer to managing infrastructure you happen not to own physically: host pools, scaling plans, image versions, storage performance and network configuration are all decisions you make and keep making, because none of them stay correct on their own as usage changes. That's not a criticism of AVD, it's the trade for the control and cost efficiency it offers at scale. What it does mean is that AVD management needs an owner, whether that's an internal team with the time to do it properly or a consultancy running it as an ongoing service. An AVD estate left to run itself after go-live is the single most common reason costs and logon times both drift, because nobody revisits the decisions that were correct when they were made and stopped being correct six months later. #### How does multi-session change the blast radius of an incident? It widens it, and that belongs in the decision alongside cost. A pooled multi-session host runs several users on one operating system instance, which is exactly where AVD's density and cost advantage comes from. It also means an incident on that host is an incident for everyone signed in to it, rather than for one person. Concretely: a malware detection sits on the same OS instance as its neighbours' sessions. One user's runaway process degrades performance for everyone sharing the host. A regression introduced by an image update reaches every session landing on the affected hosts. Taking a host out of service means draining it and moving live users first. By contrast, the equivalent event on a Windows 365 Cloud PC, or on a personal AVD host pool, affects one user and is contained by reprovisioning one machine. Where a workload is regulated, or where per-user isolation is easier to evidence to an auditor than a set of compensating controls, personal host pools or Windows 365 Cloud PCs are often the better answer, and we will say so rather than defaulting to whichever platform the engagement started with. #### FSLogix and storage: what actually goes wrong? Almost always one of two faults. The first is storage sized for capacity rather than concurrency: FSLogix mounts a per-user profile container at sign-in, so a share that copes fine with a trickle of logins collapses under a simultaneous morning wave, and the fix isn't more storage, it's storage tiered and split for the concurrency you actually see. The second is containers that grow without limit because nobody set exclusions, so Teams and browser caches, OneDrive cached files and search index data end up roaming inside the profile, slowing every mount and steadily filling the share. We test against a real login wave rather than a single afternoon test session, because one login at 2pm proves nothing about what happens at 8:55 on a Monday. Housekeeping for containers left locked after an ungraceful disconnect is part of the same problem and is usually the difference between profiles that stay fast for months and ones that quietly degrade. #### How should applications reach an AVD session host? Three routes, and a well-run estate uses all of them deliberately rather than defaulting to one. Baked into the golden image, for agents, baseline configuration and anything that genuinely must be present at boot. Installed per host through Intune, for applications that don't need to be in every image build. Attached at sign-in with MSIX App Attach, which expands a package from an SMB share and registers it per user without ever installing it on the host, keeping the image thin and letting different teams get different applications from the same pool. The skill is in the routing decision, made per application rather than as a blanket policy. Anything that updates often should never live in the image, or every release becomes a rebuild and redeploy across every host pool that uses it. MSIX packaging and App Attach image builds are frequently the same underlying work as our dedicated application packaging service, and estates running both usually save by scoping them together. #### Can you take over an AVD environment someone else built? Yes, and it's one of the most common reasons we're brought in. The trigger is usually the bill, the logon times, or the person who originally designed the environment having moved on with nobody left who knows why it's configured the way it is. We read what's there before changing anything: host pool and scaling plan configuration, image lineage, FSLogix and storage design, licensing, Conditional Access and application delivery. Plenty of what we find is sound, and we say so rather than rebuilding for the sake of it. What's usually wrong is a handful of early decisions rather than the whole build: a scaling plan that was never turned on, an image that's grown unmanaged for two years, storage that was sized once and never revisited. Fixing those is a fraction of the cost of a rebuild and usually delivers most of the saving. #### What should you expect from an Azure Virtual Desktop provider? Three things, and it is worth asking for all of them in writing before anyone quotes. First, a sizing method: ask how the provider arrives at host pool size and VM SKU, and be wary of any answer that starts from headcount rather than measured peak concurrency. Second, who owns the environment after go-live, because AVD is a platform that keeps needing decisions and most virtual desktop providers price the build and leave the tuning unowned. Third, whether they will tell you not to buy it. A provider whose Azure Virtual Desktop services only ever conclude that you need Azure Virtual Desktop is describing a product line, not giving you advice. The Microsoft partner badge on its own is thin evidence here. Almost every reseller carries one, and hosted virtual desktop providers vary enormously in how much AVD-specific engineering sits behind the logo. The questions that separate them are practical: can they show you an FSLogix storage design they have argued against on cost grounds, do they run scaling plans they built a year ago and still review, and will they hand back an assessment that recommends Windows 365 for part of the estate when that is the right answer. #### Does Azure Virtual Desktop make sense for a small business? Often not, and that is worth saying plainly on a page that sells it. Azure Virtual Desktop for small business tends to disappoint below roughly twenty to thirty desktops, because the design and management overhead is close to fixed no matter how many users share it, while the pooled-host saving that pays for that overhead scales with user count. Under about twenty users the sums usually favour Windows 365, where nothing has to be sized and the price is known in advance. The exceptions are real though, and they are about capability rather than headcount. A ten-person design studio needing GPU-backed hosts has no Windows 365 option at all. A small team with wildly variable seasonal demand can still benefit from autoscale. And a business with one specialist application that needs a particular VM series will find AVD is the only platform that offers it. We will tell you which case you are in at assessment rather than after the build. #### Is Azure Virtual Desktop included in Microsoft 365 Business Premium? The Windows licence is, the Azure bill is not, and conflating the two is the most common budgeting mistake we see. Microsoft 365 Business Premium is an eligible licence for Azure Virtual Desktop, alongside Microsoft 365 E3, E5, F3, A3 and A5 and the standalone Windows Enterprise E3 and E5 SKUs. If your users are already on Business Premium, they already carry the AVD access rights and you should not be buying them again. What Business Premium does not cover is the infrastructure. Every session host is an Azure virtual machine you pay for by the hour it runs, plus the storage behind FSLogix profiles, plus egress and any networking. That is the part that moves, and the part a licence-led conversation tends to skip. If you are running Windows Server session hosts rather than Windows multi-session, RDS CALs come into it as well. We check all of this against your existing tenant at assessment, because duplicate-purchased AVD rights are one of the easier savings to find. #### Which AVD management and automation tools are worth it? Native Azure tooling covers more than it used to. Scaling plans, the Compute Gallery and Azure Monitor between them handle autoscale, image versioning and alerting without a third-party product, and for a single host pool with settled working patterns that is often the whole answer. The case for a management layer starts when you are running several host pools, rebuilding images regularly, or need cost reporting that finance will actually accept. Three are worth knowing about, and they solve different problems. Nerdio is the best known and is squarely an AVD and Windows 365 management layer, wrapping autoscale, image lifecycle and cost controls in one console. Hydra by Login VSI comes at it from the testing and user-experience side, which matters most when you need to prove an image or an application change is safe before it reaches the estate. EtherInsights by EfficientEther works on the analysis and cost side, and it is the tooling behind the TCO modelling we use at assessment. EfficientEther is a sister company rather than an arm's-length vendor, and that is where the tooling came from: the same cost and capacity analysis, done by hand often enough that it was worth building properly. Our position is that tooling is a multiplier on a good design and no substitute for one. A management layer applied to host pools sized from headcount rather than measured concurrency automates the wrong configuration faster. We size and tune the estate first, then recommend tooling if the ongoing operational load justifies the licence, and we will say when it does not. #### The credential behind the recommendation Ryan Mangan, Systech's founder, is a Microsoft MVP, an award renewed specifically for his work in Azure Virtual Desktop and Windows 365, and the author of Mastering Azure Virtual Desktop, published by Packt across two editions. He maintains a public MSIX App Attach reference wiki that other engineers use when they get stuck on exactly the failure modes described on this page. The wider team is certified to AZ-140, Microsoft's Azure Virtual Desktop specialty exam, so the engineers who build and run your environment hold the platform credential rather than a general cloud one. What that's worth to you is narrow but real. Reference material gets written by people who have already hit the failure modes and had to explain them clearly enough for someone else to fix theirs. The recommendations here aren't a generalist's best guess at a platform they cover alongside a dozen others, they come from the person who documented how AVD goes wrong for a living. If you are comparing Microsoft AVD partners, that is the specific thing worth comparing: not who holds a badge, but who has had to explain the platform to somebody else in public and be right about it. #### Frequently asked questions **When is AVD more cost-effective than Windows 365, and vice versa?** AVD tends to win on cost once you have enough users to make pooled multi-session hosts and autoscale worthwhile, or wherever demand genuinely varies by time of day or day of week, because you stop paying for capacity nobody's using. Windows 365 tends to win where headcount is stable and predictable, because its fixed per-user price removes the design and tuning overhead AVD needs to realise its saving. The crossover isn't a fixed headcount number, it depends on your actual concurrency pattern, which is exactly what an assessment measures rather than assumes. **What's the real difference between AVD management and Windows 365 management?** Windows 365 management is close to administering a subscription: assign a licence, the Cloud PC exists. AVD management is closer to running infrastructure: host pools, scaling plans, image versions, storage performance and networking are all decisions that need making and then revisiting as usage changes. AVD's extra management overhead is the trade for the cost efficiency and flexibility it offers once you're operating at meaningful scale. **What should a TCO analysis of AVD versus Windows 365 actually include?** More than list price. A genuine TCO comparison needs your measured concurrency pattern (not headcount), the Azure compute, storage and networking AVD would actually consume once autoscaled, the engineering time to design and maintain the AVD environment, and Windows 365's fixed per-seat cost at the Cloud PC size your applications actually need. Comparing sticker prices alone consistently favours whichever platform you compare last. **Is there an AVD cost optimisation checklist you can share?** The order that moves the needle: autoscale scaling plans tuned to your real usage pattern first, since it's the single biggest lever and needs no new infrastructure; then VM SKU right-sizing against measured utilisation; then session density, checking users aren't on dedicated hosts they don't need; then FSLogix storage tier matched to actual concurrency; then image hygiene, so hosts boot and patch faster; and reservations or savings plans applied last, against your measured baseline rather than your peak. **What's the best way to manage both AVD and Windows 365 together?** Treat platform choice as a per-user or per-team decision within one estate rather than an either/or for the whole business, because that's usually the cheapest outcome: stable, predictable teams on Windows 365 Cloud PCs, and variable-demand, GPU or specialist workloads on AVD host pools. Managing both well means the same identity, Conditional Access and Intune policy baseline applied across both, so users and IT see one consistent estate rather than two unrelated platforms that happen to share a sign-in screen. **We already have an AVD environment. Can you just review or fix it, not rebuild it?** Yes, and that's the more common engagement. We assess what's there, host pools, scaling plans, images, storage and licensing, tell you plainly what's sound and what isn't, and fix the specific decisions causing cost or performance problems rather than starting again. Most AVD estates need a handful of things corrected, not a rebuild. **Do you help decide between AVD and Windows 365, or only deliver AVD?** We start every engagement with a straight recommendation, and where Windows 365 is the better fit for some or all of your users we'll say so. We deliver both, and cover Windows 365 consultancy specifically on its own page, so the advice isn't shaped by which platform we'd rather sell you. ### Windows 365 Consultancy URL: https://systechitsolutions.co.uk/services/windows-365-consultancy Windows 365 consultancy from a Microsoft MVP: licence and Cloud PC sizing, network readiness, rollout and ongoing management for UK businesses. Cloud PCs sized, licensed and rolled out properly, so a predictable price doesn't come with an unpredictable experience. Windows 365 is sold on simplicity: pick a size, assign a licence, done. Most of the ways it goes wrong happen before that point, in a sizing decision made without usage data, a network that was never checked against Microsoft's connection requirements, or an edition chosen for its price rather than what it actually unlocks. This service is for you if: - You're weighing up Windows 365 against Azure Virtual Desktop and want a straight recommendation, not a licence sale - You're rolling out Cloud PCs and want the sizing, edition and network readiness decided properly the first time - You already run Windows 365 and suspect you're over-licensed, under-sized, or both The cost of doing nothing: Windows 365's fixed per-user price feels like it removes the decisions, but it just moves them earlier. Buy the wrong Cloud PC size and users get a desktop that stutters under their actual workload; buy too generous a size and you're paying a premium every month for headroom nobody uses. Pick Enterprise when Business would have covered you, or Business when you needed Enterprise's Conditional Access and custom images, and you find out at the point it's disruptive to change. None of it shows up until users are already logged in and unhappy, or the renewal invoice lands larger than the headcount justifies. #### Cloud PCs, sized and rolled out properly We run Windows 365 consultancy as three phases. Assessment: which edition fits, what Cloud PC size each user group genuinely needs based on their actual application set, whether your network meets Microsoft's connection requirements, and a straight recommendation on whether Windows 365, Azure Virtual Desktop, or a mix of both is the right fit for your business. Migration: provisioning, image and policy build, Conditional Access and Intune integration, and a staged rollout. Optimisation: reviewing licence tier against real usage, reclaiming Cloud PCs from leavers promptly, and adjusting sizing as application needs change. Because the platform itself has few moving parts, the value of a specialist engagement sits almost entirely in getting the upfront decisions right: edition, sizing and network readiness. Get those three correct and Windows 365 is genuinely close to a subscription to manage. Get them wrong and you're paying every month for a desktop that either underperforms or overshoots what your users need. What's included: - Windows 365 vs Azure Virtual Desktop fit assessment, with a straight recommendation - Business vs Enterprise edition selection against your actual requirements - Cloud PC sizing per user group, based on real application and workload data - Network readiness review against Microsoft's Windows 365 connection requirements - Custom image build and Intune, Entra ID and Conditional Access integration - Windows 365 Frontline, Boot and Switch configuration where relevant - Staged rollout and user provisioning - Ongoing licence and sizing review to prevent over- or under-buying #### What does a Windows 365 consultancy engagement actually involve? The same three-phase model we run for any virtual desktop engagement, scaled to how much Windows 365 itself needs deciding. Assessment covers edition choice, Cloud PC sizing per user group based on actual application and workload data rather than a standard tier, and a network readiness check against Microsoft's published connection requirements, because a Cloud PC that's correctly sized but reached over a poor connection still feels slow to the user sitting in front of it. #### Business or Enterprise: which edition fits? It suits a small or mid-sized business that wants Cloud PCs working with minimal setup and does not need custom images or Conditional Access policy applied to the desktop itself. Windows 365 Enterprise has no user cap and unlocks custom images built and versioned through the Azure Compute Gallery, full Conditional Access, and management through Intune alongside your other managed devices, but it requires Microsoft Entra ID, Intune, and eligible Windows and Microsoft 365 licences per user already in place. The deciding question isn't headcount alone, it's whether you need a custom image or Conditional Access enforced on the Cloud PC. If you do, Enterprise is the only option regardless of size. #### How do you size a Cloud PC without over- or under-buying? From the applications each user group actually runs, not a generic recommendation. Windows 365 is sold in fixed vCPU, memory and storage tiers, and the temptation is to standardise on one size for everyone, which either overpays for light users or starves anyone running a heavier line-of-business application or multiple large applications simultaneously. We group users by workload rather than by department or job title, because a finance analyst running one heavy application and a sales user running a browser and email are different sizing decisions even if they sit in the same team. Getting this right at the assessment stage matters more for Windows 365 than for AVD, because there's no autoscale to paper over a sizing mistake after the fact, the Cloud PC is that size until someone changes it. #### When is Windows 365 more cost-effective than AVD, and when isn't it? Windows 365 wins on cost, and more importantly on predictability, when headcount is stable and every seat is genuinely used most of the working day. There's no infrastructure to design or tune, no scaling plan to get wrong, and the monthly cost per user is fixed regardless of what happens to Azure's own compute pricing. For a business that wants desktops without taking on infrastructure decisions, that simplicity has real value beyond the raw pound figure. It stops being the cheaper option once usage becomes genuinely variable, seasonal, or shift-based beyond what Frontline licensing covers, or once you need GPU-backed compute, which Windows 365 doesn't offer at any price. In those cases Azure Virtual Desktop's ability to scale capacity down when it isn't needed, or to provision GPU host pools at all, starts to outweigh the simplicity Windows 365 offers. We size this against your real usage pattern at assessment, because the honest crossover point moves depending on how concurrent your actual demand is, not on headcount alone. #### How does Windows 365 management actually differ from AVD management? Windows 365 management is close to administering a subscription: assign a licence at the size a user needs, and the Cloud PC exists, dedicated to that one person, with the profile living on the machine itself rather than in a separate profile store. There's no host pool to size, no scaling plan to configure, and no shared infrastructure whose performance depends on how many other users happen to be logged in at the same moment. The feature comparison that matters in practice is not a checklist of what each platform can do, it is who is going to own the ongoing decisions, because Windows 365 genuinely needs far fewer of them once the initial sizing and edition choice are right. #### What actually breaks a Windows 365 rollout? Network readiness is the one most often skipped, and it's the one users notice immediately. Windows 365 has published bandwidth, latency and port requirements for a usable Cloud PC connection, and a site with a congested internet connection or an aggressive firewall blocking the required endpoints will deliver a stuttering desktop regardless of how correctly the Cloud PC itself is sized. This gets checked before provisioning, not discovered afterwards from a help desk queue. The second recurring failure is Conditional Access and identity gaps on Enterprise: a Cloud PC provisioned without device compliance or Conditional Access policy applied is reachable from anywhere with valid credentials, which defeats a large part of the security case for moving to Cloud PCs in the first place. The third is licence mismatch, assigning Enterprise-tier features to users who'd have been fully served by Business, or the reverse, discovering mid-rollout that Business can't do what a use case actually needed. #### Windows 365 Frontline, Boot and Switch: what are they and do you need them? Frontline licensing shares a smaller pool of Cloud PCs across shift or part-time workers rather than dedicating one to each named user, which suits retail, healthcare or hospitality teams where staff rarely overlap. It's worth checking specifically if you have shift-based roles, because licensing everyone individually in that scenario pays for capacity that's idle most of the week. Windows 365 Boot signs a user directly into their Cloud PC from the Windows welcome screen on a shared or thin-client device, useful where several people use the same physical machine across a day. Windows 365 Switch lets a user move between their local desktop and their Cloud PC on the same device without a separate remote desktop session. Neither is essential for every deployment, but both are easy to miss if nobody asks whether your user base includes shared devices or people who genuinely need to move between local and cloud desktops during the day. #### Is a Cloud PC actually more secure than a laptop? Generally yes, for the same reason any virtual desktop is: company data lives in the Cloud PC, not on whatever physical device is being used to reach it, so a lost, stolen, or quietly retained device carries nothing to breach. That removes a whole category of incident rather than simply mitigating it. The rest of the security case depends on what's configured around it, which on Windows 365 Enterprise means Conditional Access requiring a compliant or known device before a session opens, Intune policy applied to the Cloud PC itself, and access revoked centrally and immediately the day someone leaves, reclaiming the Cloud PC rather than leaving it assigned and idle. Business edition has fewer of these controls available, which is part of the trade-off against its simpler setup. #### Why does a Cloud PC have a smaller blast radius than multi-session AVD? Because a Cloud PC is one user's machine, and an AVD multi-session host is several users' machine at once. That single architectural difference is the most under-discussed factor in choosing between the two, and it decides how far a problem travels before anyone notices. #### Can you migrate between Azure Virtual Desktop and Windows 365? In both directions, and it is more common than the way these platforms are usually presented would suggest. They are not a one-time either/or decision: they share an underlying platform, the same identity and management stack, and much of the same preparation work, so moving between them is a change of hosting model rather than a rebuild from scratch. For a stable, predictable workforce, moving those users onto dedicated Cloud PCs removes an entire class of ongoing work. Our AVD to Windows 365 migration case study covers exactly this pattern and what it did to priority-one incident volume. Often it is not a wholesale move at all but a partial one, taking a subset of users to AVD while the rest stay on Cloud PCs. The practical point is that the same assessment covers both. Working out the right hosting model means understanding application sets, concurrency, usage patterns and network readiness, and that work is identical whichever platform you end up on. It also means a mixed estate is a legitimate outcome rather than an admission of indecision: put the steady-state users on Cloud PCs for the isolation and the predictable cost, and use AVD where pooled or GPU capacity genuinely earns its keep. #### What should you expect from a Cloud PC provider? Less than you would demand of an AVD partner, because Microsoft runs the infrastructure, and that changes what is actually worth paying for. Most Cloud PC providers will happily sell you licences and provision them, but licence resale is the commodity part. The work that decides whether a Windows 365 rollout lands is sizing against real application behaviour, the Intune configuration that governs the estate afterwards, network readiness on the sites people will actually connect from, and the identity and Conditional Access design that keeps a Cloud PC from being a soft entry point. So the useful question for any cloud pc service provider is what happens in month two. Ask who reviews sizing once people are working on them, because the commonest Windows 365 waste is not overspend on the wrong tier at purchase, it is nobody reclaiming licences from leavers and long-term absences. Ask whether they will move users down a size as well as up. And ask what their answer is when a workload turns out to need GPU or fine-grained VM control, because the honest one is Azure Virtual Desktop, not a bigger Cloud PC. #### The credential behind the recommendation Ryan Mangan, Systech's founder, is a Microsoft MVP, an award renewed specifically for his work across both Azure Virtual Desktop and Windows 365, and the author of Mastering Azure Virtual Desktop, published by Packt across two editions. He maintains a public MSIX App Attach reference wiki used by other engineers working through the same platform decisions covered on this page. The reason that matters for a Windows 365 engagement specifically is that Windows 365 and AVD share the same underlying platform and the same set of trade-offs, and the recommendation on edition, sizing, blast radius or whether to move between the two comes from someone who works across the whole platform daily, not from whoever happens to answer the phone at a reseller. It is also why we will tell you when AVD is the better answer, which a Windows 365 licence sale would not. #### Frequently asked questions **Windows 365 vs AVD: what's the actual difference?** Windows 365 gives each user a dedicated Cloud PC at a fixed per-user, per-month price, with nothing to size or scale. Azure Virtual Desktop runs on your own Azure subscription with pooled multi-session hosts, autoscaling and GPU options, so it's often cheaper at real scale but has to be designed and actively managed. Many organisations run both, matched to different user groups rather than picking one for the whole business. **When is Windows 365 more cost-effective than AVD?** When headcount is stable and predictable and every seat gets used most of the working day, because you're then paying for capacity you're genuinely consuming, with none of the design or ongoing tuning overhead AVD needs to realise its own savings. Once usage becomes variable, seasonal, or needs GPU compute, AVD's ability to scale capacity to actual demand usually overtakes Windows 365's fixed price. **What's the feature comparison between Windows 365 and AVD management platforms?** Windows 365 management is licence assignment and periodic right-sizing, with the profile living on the dedicated Cloud PC and custom images only available on Enterprise. AVD management is host pools, autoscale scaling plans, FSLogix profile storage and a full image pipeline, all of which need active configuration and revisiting as usage changes. The trade is Windows 365's low admin overhead against AVD's greater control and cost efficiency at scale. **Is there a cost optimisation checklist for Windows 365?** It's shorter than AVD's, because there's less infrastructure to tune. The items that matter: right-size Cloud PC tier against actual application usage rather than a standard default, reclaim licences from leavers immediately rather than at the next audit, check whether Frontline licensing fits any shift-based teams, and confirm you're on the correct edition, since Enterprise features nobody uses are a recurring source of unnecessary spend. **Do we need Intune and Entra ID to run Windows 365?** It depends on the edition. Windows 365 Business is capped at 300 users and needs no infrastructure prerequisites, so a small team can run it without Intune or a configured Entra ID tenant. Enterprise has no user cap and unlocks custom images, Conditional Access and full Intune management, but requires Microsoft Entra ID, Intune, and eligible Windows and Microsoft 365 licences per user. **Can we manage Windows 365 and Azure Virtual Desktop together?** Yes, and for many businesses that's the right architecture rather than a compromise: stable, predictable user groups on Windows 365 Cloud PCs, and variable-demand or specialist workloads on AVD host pools, with one consistent identity, Conditional Access and Intune policy baseline applied across both. We cover the combined management question in more depth on our AVD consultancy page. **How long does a Windows 365 rollout take?** For Business edition with no infrastructure prerequisites, provisioning itself can be quick once sizing and licensing are decided. Enterprise rollouts take longer because of image build, Conditional Access policy and Intune integration work, and because network readiness needs checking against Microsoft's connection requirements before users are moved over. The honest timeline comes after the assessment, once we know which edition and how much custom configuration your business actually needs. ### Microsoft Licensing & Cost Management URL: https://systechitsolutions.co.uk/services/licensing-cost-management Licence tier rightsizing, shelfware elimination, Azure cost control and renewal timing, managed together as one discipline, not a once-a-year licence audit. Right-size Microsoft 365 tiers, eliminate shelfware, control Azure cost and get renewal timing under control, managed as one discipline rather than three separate problems. Most businesses treat Microsoft licensing and Azure cost as two separate problems, reviewed at different times by different people, if they're reviewed at all. They're the same problem: money committed to Microsoft that isn't matched to what the business actually needs, usually discovered on a renewal invoice instead of before one. This service is for you if: - You're not sure whether you're on the right Microsoft 365 tier, or you're fairly sure you're not - Your Microsoft renewal is approaching and nobody has reviewed licence assignment or Azure usage since the last one - You want licensing and Azure cost reviewed together on one timeline, not as two disconnected exercises run by different people The cost of doing nothing: Licence tier decisions get made once, at a point when the business looked different, then renewed on autopilot every year because reassessing feels like more effort than it's worth. Seats stay assigned to people who left months ago, every new starter defaults to whichever tier IT happened to buy first, and Azure spend drifts upward in parallel with nobody accountable for either side of the bill. None of it is dramatic enough to trigger a review on its own, it just compounds quietly until a renewal notice or a budget conversation forces the question, and by then contract terms often limit what can actually change before the next one. #### Licensing and cost, managed as one discipline We review Microsoft 365 licensing and Azure cost together, on one timeline, rather than as two separate projects run months apart: which licence tier each user group genuinely needs, where shelfware has accumulated, where Azure resources are sized for a peak that rarely happens, and when your renewal date actually falls, checked early enough that you have real options instead of a deadline. The output is a specific list of changes, tier by tier and resource by resource, tied to a renewal timeline that tells you when each decision needs to be made. Not a generic report that gets read once, praised, and filed away until the same conversation happens again next year. What's included: - Microsoft 365 licence tier assessment: Business Premium, E3 and E5 rightsizing - Shelfware identification: unassigned, duplicated and leaver seats - Azure resource rightsizing reviewed alongside licensing, not as an afterthought - Renewal timeline mapping, so decisions happen before contract terms lock you in - Reserved instance, savings plan and Azure Hybrid Benefit guidance matched to what you actually own - Board-ready reporting that separates licensing spend from infrastructure spend #### What does licensing and cost management actually cover? The reason this sits as its own service rather than living entirely inside our Azure cost optimisation work or our Microsoft 365 service is that licensing and infrastructure cost decisions genuinely interact. A licence tier change can shift what's available for Azure Hybrid Benefit. A renewal deadline can force an Azure rightsizing exercise to happen faster than it otherwise would. Reviewing them on separate schedules, by separate people, is how the interaction gets missed and the saving with it. #### Business Premium, E3 or E5: what actually decides it on cost grounds? The headcount boundary comes first: Microsoft 365 Business Premium is capped at 300 users, so above that the real choice is between E3 and E5. Below 300 seats, Business Premium is usually the strongest starting point on cost grounds specifically, because it bundles a security stack (device management, Conditional Access, email protection, endpoint detection) that most businesses would otherwise be pricing separately. The cost question isn't which tier has the most features, it's which tier you'd otherwise be assembling piece by piece at a higher combined cost. The E3-versus-E5 decision is, on cost grounds, mostly a question of what you'd otherwise buy as an add-on and whether anyone will actually operate the extra capability E5 unlocks. A licence generating security signals nobody reviews is shelfware with a compliance story attached to it, regardless of what tier it sits on. That's why a mixed estate, E5 for the roles where the extra controls get used and reviewed, E3 as the floor for everyone else, is very often the cheapest correct answer rather than a compromise. Our Microsoft 365 service covers what each tier actually does in full technical depth; this service is where that decision gets made on cost and licence-count grounds specifically, and where it gets checked again at every renewal rather than left as a one-time choice. #### Where does licence shelfware actually come from, and how do you find it? It accumulates in a small number of predictable, unglamorous ways. Leavers whose account access is removed on their last day, but whose licence subscription is never released, because offboarding and licence reclamation are handled by different people on different checklists. Seats bought for a headcount forecast that didn't materialise, then renewed every year because renewing is less effort than reassessing. Everyone defaulted onto a premium tier when only a subset genuinely need its capabilities. And duplicated function, where a capability already bundled into the licence you hold is quietly re-bought as a separate third-party product because nobody checked what was already included. The output is a specific, named list, not an estimated percentage, because a named list is what actually gets acted on before the next renewal rather than nodded at and filed. #### How should a Microsoft licensing renewal actually be handled? Started well before the renewal date, not in the final weeks. The single most common mistake is treating renewal as an event that happens to you, when in most agreements the practical window for reducing seat count or changing tier only exists at renewal, mid-term reductions are frequently restricted by the contract terms. If the review happens after that window has already passed, the only realistic outcome is renewing what you already have, whether it's still correct or not. Handled properly, a renewal review starts with the same shelfware and rightsizing work described above, run early enough that its findings can actually change the order, then moves to understanding your specific agreement's terms: what licensing programme you're on, what flexibility it genuinely offers for growth versus reduction, and what's changed in Microsoft's own terms since you last signed, because those terms do move between renewal cycles. We help clients get that picture straight and go into the renewal conversation, with Microsoft directly or through a partner, with a specific, evidenced position rather than a rough sense that something's probably wrong. #### Where does Azure resource rightsizing fit into a licensing review? As the infrastructure half of the same exercise, run on the same visit rather than scheduled separately. The categories are familiar to anyone who's looked at an Azure bill: compute sized for a projected peak rather than measured usage, non-production environments running around the clock for a team that only needs them in office hours, and orphaned resources, disks, IPs and snapshots left behind after something was decommissioned. None of it is exotic, and none of it shows up as a single alarming line, it just accumulates the same way shelfware does. We keep this section of the review proportionate rather than duplicating a full infrastructure audit here: where an estate needs deep, ongoing Azure cost discipline, tagging, showback, FinOps process, that's the specific focus of our dedicated cost management and Azure optimisation service. This service's job is to make sure the licensing and infrastructure decisions get looked at on the same timeline and by the same reviewer, so a rightsizing opportunity that spans both, like Azure Hybrid Benefit below, doesn't fall through the gap between two separate engagements. #### Reserved instances, savings plans and Azure Hybrid Benefit: where do they interact with licensing? Reservations and savings plans are primarily an infrastructure decision, committing to a level of Azure compute spend in exchange for a discount, and they're covered properly on our cost management page. Azure Hybrid Benefit is the one that genuinely sits on the boundary between licensing and infrastructure cost, and it's the one most often missed precisely because it does. If you already own Windows Server or SQL Server licences with active Software Assurance, or equivalent subscription licence rights, that entitlement can be applied to Azure virtual machines so you pay only the base compute rate rather than compute plus an additional licensing component built into the price. It has to be applied deliberately, it's a setting on the resource rather than something that happens automatically, and virtual machines migrated to Azure without it keep paying the full rate indefinitely with nobody noticing because the invoice doesn't flag what it should have been. It also needs eligibility tracked and reported on an ongoing basis rather than switched on once and forgotten. This is exactly the kind of saving that a licensing review run separately from an infrastructure review tends to miss, because it requires someone looking at both the licence estate and the Azure estate at the same time to even ask the question. #### Where do AVD and Windows 365 licensing decisions fit into this? Directly, and they're one of the more commonly missed sources of duplicated spend. Access rights for Azure Virtual Desktop are typically already included within Microsoft 365 E3, E5 or Business Premium for licensed users, but the same access rights are also sold as a standalone per-user licence, and it's entirely possible to end up paying for both because the AVD licensing question was never checked against what the Microsoft 365 tier already grants. Windows 365 works differently again: it's sold as its own fixed per-user, per-month Cloud PC licence layered on top of whichever Microsoft 365 tier the user already holds, so the rightsizing question there is Cloud PC size and edition, not whether the access right is already bundled elsewhere. Where a business is actively evaluating or already running Azure Virtual Desktop or Windows 365, the platform-specific sizing, edition and TCO decisions are covered in full depth on our dedicated Azure Virtual Desktop consultancy and Windows 365 consultancy pages. This service is where we check the licensing side of that picture specifically, that the AVD or Windows 365 access rights being paid for aren't quietly duplicating something already bundled into the Microsoft 365 estate, as part of the same renewal and rightsizing review covering everything else. #### What does ongoing licensing and cost management look like, versus a one-off review? A one-off review is useful and produces real, one-time savings, but the conditions that produced the shelfware and the drift in the first place don't go away because a spreadsheet got cleaned once. New starters still default onto whatever tier is easiest to assign, leavers still get missed by an offboarding process that doesn't talk to licensing, and Azure resources still get provisioned for a projected peak rather than a measured one. Left there, most estates drift most of the way back to where they started within a year or two. It's a lighter-touch, recurring version of the same work, not a bigger project, and it's the difference between a saving that shows up once and one that stays saved. #### The credential behind the recommendation Ryan Mangan, Systech's founder, is a Microsoft MVP, an award renewed specifically for his work in Azure Virtual Desktop and Windows 365, a Chartered Fellow of the British Computer Society (FBCS), and the author of Mastering Azure Virtual Desktop, published by Packt across two editions. Licensing and cost decisions get made properly by someone who understands what a tier or a platform actually does operationally, not just what it costs on a price list. The AVD and Windows 365 licensing guidance on this page draws on that same platform depth, so the recommendation on what's genuinely bundled, what's duplicated, and what's worth paying for comes from daily work across the whole Microsoft stack, not from a reseller reading a price sheet. #### Frequently asked questions **What's the difference between this and your Azure cost optimisation service?** Our cost management and Azure optimisation service goes deep on the infrastructure side: reserved instances, savings plans, autoscale, tagging and FinOps discipline for the Azure estate itself. This service sits alongside it and covers the licensing side specifically, tier rightsizing, shelfware, and renewal timing, and makes sure the two are reviewed together rather than on separate schedules, since decisions like Azure Hybrid Benefit sit directly on the boundary between them. **What's the difference between this and your Microsoft 365 service?** Our Microsoft 365 service covers what each tier actually does in full technical depth: governance, Intune, identity, migration and the platform capabilities themselves. This service makes the tier decision specifically on cost and licence-count grounds, then keeps checking it at every renewal and headcount change rather than treating it as a one-time choice made during a migration project. **How do you decide between Business Premium, E3 and E5 on cost grounds?** Headcount sets the first boundary, since Business Premium is capped at 300 users. Below that, we compare the bundled security stack against what you'd otherwise buy separately. Above it, or where E5's extra controls are relevant, the question is whether those controls will actually be configured and reviewed, since unused premium capability is shelfware regardless of which tier it sits on. Most estates end up with a mixed tier assignment rather than one licence for everyone. **When should we start reviewing our Microsoft licensing renewal?** Well before the renewal date, not in the final weeks. Most licensing agreements only allow seat reductions or tier changes at the renewal point itself, so a review that starts after that window has closed can only confirm what you already have rather than change it. Starting early gives you a genuinely evidenced position to negotiate from rather than a rough sense that something's probably wrong. **Can you negotiate directly with Microsoft or our reseller on our behalf?** We help you build the evidenced position, the specific shelfware, rightsizing and tier findings, that a renewal conversation should be based on, and we can be part of that conversation alongside you or your existing reseller. What we won't do is quote a specific discount before we've seen your estate and your agreement, since the terms and flexibility genuinely vary by licensing programme and change between renewal cycles. **Does this cover Azure Virtual Desktop and Windows 365 licensing too?** Yes, checking that AVD or Windows 365 access rights aren't being duplicated against what your Microsoft 365 tier already includes is part of the review. Where you need the platform-specific sizing, edition or TCO decisions for AVD or Windows 365 themselves, those are covered in full depth on our dedicated Azure Virtual Desktop consultancy and Windows 365 consultancy pages. **Is this a one-off review or an ongoing service?** Both are available, but the saving holds up better as an ongoing discipline. A one-off review produces a real, one-time correction; without a recurring check, most estates drift most of the way back towards the same shelfware and mis-sized tiers within a year or two, as new starters, leavers and renewal dates keep moving. An ongoing engagement runs the same checks on a cycle so it stays corrected rather than needing to be rediscovered. ### Email Security & Archive URL: https://systechitsolutions.co.uk/services/email-security Advanced email security and compliant archiving: anti-phishing, anti-malware, email continuity, data loss prevention and tamper-proof searchable archiving. Protected inboxes and a complete, compliant record of every message. Email is still the number one way attackers get in, and the number one place important records quietly go missing. Both problems are invisible right up until they aren't. This service is for you if: - Phishing and business email compromise are a real and growing risk for your team - You need a searchable, tamper-proof record of correspondence for compliance or disputes - An email outage would stop your business communicating, with no fallback The cost of doing nothing: One convincing phishing email is all it takes, and once it lands, a missing archive means you can't even reconstruct what happened. Meanwhile a mailbox outage with no continuity leaves the whole business unable to send or receive until it's fixed. #### Stop threats and keep the records you need Email is still the number one route in for attackers, and the number one place important records go missing. We layer advanced protection in front of your mailboxes and keep a tamper-proof archive behind them. Your people are shielded from phishing and malware, and your business keeps a searchable, compliant record of correspondence for as long as you need it. What's included: - Anti-phishing, anti-malware and spam filtering - Compliant, searchable email archiving - Email continuity during outages - Retention and legal-hold policy management - Data loss prevention and encryption - Detailed reporting and quarantine control #### What does Microsoft 365's built-in email protection already cover? More than people assume, and it is worth being precise about it before spending money on top. Exchange Online Protection, included with every mailbox, handles connection filtering, anti-spam, anti-malware and basic anti-phishing, plus outbound spam control and the quarantine that holds what it catches. Defender for Office 365, included in some plans and available as an add-on to others, layers on link rewriting and detonation, attachment sandboxing, impersonation protection for named people and domains, and the investigation tooling that lets somebody trace where a message went after delivery. The honest position is that most organisations are not using what they already pay for. Anti-phishing policies sit at defaults with no impersonation protection configured for the finance team or the directors who are actually targeted, domain authentication is published but not enforcing, quarantine is never reviewed, and inbound mail rules created by users are never audited. Turning on and tuning what is already licensed is the cheapest security improvement available in most tenants, and it should always come before a purchase decision about an additional layer. #### What does a dedicated email security layer add on top? Three things principally: independence, continuity and depth of archiving. Independence matters because a layer sitting in front of or alongside Microsoft's own filtering uses different detection engines and different threat intelligence, so the messages one misses are not automatically the messages the other misses. It also means the protection and the mail platform do not share a single failure: when the platform has a bad day, the filtering layer is still standing. Continuity is the capability Microsoft's own stack does not really offer, because the platform cannot provide a fallback for itself. Depth of archiving is the third: a dedicated archive is written outside the mailbox and outside the tenant, which is what makes it defensible as an independent record rather than a copy of something an administrator could change. #### Why is business email compromise the expensive one? Because it contains no malware, no suspicious link and often no spelling mistake, so there is very little for a filter to detect. The pattern is consistent: an attacker gets into one mailbox, usually through a convincing credential-harvesting page rather than anything technical, and then reads quietly for a while. They learn how invoices are worded, who signs off what, when the finance manager is on leave, and which supplier is mid-project. Then they send an entirely ordinary email asking for bank details to be updated, from a real address, in the middle of a real thread. That is why the controls that stop the loss are split across technology and process. The technical side is impersonation protection for your executives and key suppliers, domain authentication that stops your own domain being spoofed, and alerting on the tell-tale signs of a compromised mailbox, particularly newly created inbox rules that forward or delete. The process side is the one that actually saves the money: any change to bank details is verified by telephone, on a number already held on file, never a number taken from the email. Most successful invoice frauds would have been stopped by a single phone call. #### What do SPF, DKIM and DMARC do, and why is DMARC usually wrong? They are the three records that let a receiving mail server decide whether a message claiming to be from your domain really is. Without all three, spoofing your own domain is trivial, which is exactly the scenario your staff are least equipped to spot. DMARC is where most estates fall down, and always in the same way: the record is published in monitoring mode and left there. That produces reports nobody reads and instructs receivers to deliver failing mail anyway, so the protection is nominal. Miss one and its mail stops arriving. That is why it is staged, with reporting reviewed between each step, rather than switched on in an afternoon. #### What does email continuity actually mean in practice? It means a separate service accepts, queues and holds your inbound mail when the primary platform is unavailable, and gives your people a way to read and send in the meantime, usually through a web interface. When the platform comes back, the queued mail delivers into the mailboxes as normal. The point is not that mail is never delayed. It is that nothing is bounced back to the sender as undeliverable, and the business can still communicate rather than sitting and waiting. Two things are worth understanding about it. First, continuity is deliberately limited: it is a way to keep trading through an outage, not a full replica of Outlook, so historic mail and the usual integrations may not be there. Second, it is only useful if people know it exists before they need it, which means the access route, the sign-in method and the announcement plan have to be documented and, ideally, rehearsed. A continuity service nobody can find the URL for during an outage is a line on an invoice. #### Archiving, retention and backup: what is the difference? They answer three different questions and are routinely confused. Retention is a policy inside the mail platform that governs how long items are kept and when they are removed. Archiving is a separate, written-once record of every message that passed through, kept independently of the mailbox so it survives deletion, mailbox limits and administrator action, and built to be searched. The practical consequence is that the answer to 'do we have a copy of that email from three years ago' depends on which of the three you actually have. Most organisations need retention configured properly whatever else they do, an archive if they have regulatory, contractual or litigation exposure, and backup because Microsoft's shared responsibility model puts your data in your hands. Our backup service covers the recovery side of that in detail, and the two are usually scoped together. #### What does a compliant archive need to do? Capture everything, keep it unaltered, and let you find it. Capture means journaling at the point of transmission so inbound, outbound and internal mail are all recorded, rather than depending on what happens to remain in a mailbox afterwards. Unaltered means the stored copy cannot be edited or removed inside the retention period, including by an administrator, which is the property that makes an archive worth anything in a dispute. Finding it means search that works across the whole estate, including attachments, quickly enough that a request is answered in minutes rather than being a project. Beyond that, the operational requirements are the ones that get overlooked at purchase and matter at use. Legal hold that can be applied to a person or a subject and reliably overrides normal disposal. An audit trail showing who searched, when and for what, because unlogged access to everyone's correspondence is its own problem. Defensible export in a format a solicitor or a regulator will accept. And a stated route for getting your data out if you leave the supplier, because an archive you cannot extract has quietly become a hostage rather than an asset. #### How do you handle quarantine without burying people? By deciding deliberately who reviews what, rather than letting the default decide for you. There are two failure modes and they pull in opposite directions. Send every user a digest of everything held and they stop reading it within a fortnight, then release something malicious because it was in a list they skimmed. Route everything to IT and the queue grows faster than anyone can work it, so genuine business mail sits undelivered and people start asking suppliers to resend to a personal address, which is worse than the original problem. What works is separating the categories. High-confidence malware and phishing should never be user-releasable at all: there is no legitimate reason to let somebody talk themselves into a message the system is confident about. Bulk and graymail can go to a user digest with a simple release, because the cost of a mistake is low. The uncertain middle needs a named owner with the time to look, and a fast route for a user to ask about a specific message. Then review the pattern monthly, because a category that repeatedly holds legitimate mail is a tuning problem, and repeatedly releasing from it teaches people the wrong instinct. #### What happens after a mailbox has been compromised? The order matters, because the instinctive first move is the wrong one. Resetting the password alone leaves an attacker with a valid session, so the first actions are to revoke active sessions and refresh tokens, reset credentials, and re-register multi-factor authentication if there is any chance the attacker enrolled their own method. Then remove what they left behind: inbox rules that forward or delete, added mailbox delegates, changed forwarding settings, and any application consent granted from the account, which is the persistence mechanism most often missed. Only then does the investigation start, and this is where an archive and good logging earn their cost. What did they read, what did they send, and to whom? Did any message ask a client or supplier to change payment details, and if so those parties need telling immediately, by phone. Whether the incident is notifiable to the ICO is a decision to be taken deliberately and on the basis of evidence, within the statutory timescale, and personal data in a mailbox somebody else has read is squarely the kind of thing that has to be assessed rather than assumed harmless. Trying to reconstruct any of this from a mailbox the attacker had time to tidy is exactly the position an independent archive avoids. #### Where does staff training fit, and where does it not? It fits as the layer that catches what technology cannot, which for email means the well-written message with no payload. The training that works is short, specific and about your own processes rather than generic awareness: what our invoices actually look like, that we never change bank details by email, that a request to buy gift cards is never real, and that reporting something that turns out to be legitimate is always the right call. The single most valuable habit you can build is a one-click report button people use without embarrassment. Where it does not fit is as a substitute for controls, or as a way to move blame. Sophisticated phishing is designed to fool attentive people under time pressure, and any programme whose implicit message is that a click is a personal failing will produce staff who hide their mistakes, which is far more expensive than the click. Simulated phishing is useful when it is used to measure whether reporting rates are rising, and counterproductive when it is used to name individuals. The technology should be good enough that people are the last line, not the first. #### How much of this do you actually need, and where does our scope end? Start with what you already own, because the sequence saves money. Tune the built-in protection, configure impersonation protection for the people who are genuinely targeted, get domain authentication to enforcement, and establish a quarantine process with an owner. If that work has been done and the risk profile still justifies more, an additional layer is a reasonable next step, and it is more clearly justified where email downtime would stop the business trading, where a regulator or a client contract requires a retained searchable record, or where nobody internally has the time to review quarantine and alerts daily. Archiving is a separate decision from filtering and should be taken on its own merits: what you are obliged to keep, for how long, and who might one day ask you to produce it. Our scope here is the email layer, from filtering and authentication through continuity to archive, alongside the Microsoft 365 configuration it depends on. Broader identity hardening, Conditional Access and endpoint protection sit on our cyber security service, and recovering data rather than producing a record sits on our backup service. We would rather scope those separately and honestly than sell one thing labelled as another. #### Frequently asked questions **Isn't Microsoft 365's built-in protection enough?** Microsoft 365 gives you a strong baseline, but layered email security adds advanced anti-phishing, continuity during outages and independent, tamper-proof archiving. For businesses facing real phishing risk or compliance obligations, that extra layer is the difference between a near miss and an incident. **What does email archiving give us that mailboxes don't?** A compliant archive keeps a complete, searchable, tamper-proof record of every message independent of the mailbox, so nothing is lost to deletion or mailbox limits. It's essential for legal hold, regulatory retention and reconstructing what happened after an incident. **What happens to email during an outage?** Email continuity keeps your people sending and receiving even if the primary mail platform is down, so a Microsoft 365 or Exchange outage doesn't stop the business communicating. **Is an email archive the same as a backup?** No, and treating them as interchangeable is how organisations end up with neither. An archive is a journaled, unalterable record of every message that passed through, built to be searched, held and produced as evidence. A backup exists to restore data to a working state after loss, corruption or an attack. An archive won't rebuild a mailbox for you, and a backup won't stand up as a defensible record in a dispute. Most businesses with regulatory or contractual exposure need both, scoped separately. **Why does DMARC need to be set to enforce, not just monitor?** Because in monitoring mode DMARC tells receiving servers to deliver mail that fails authentication anyway. You get reports, which are useful, but no protection, so anyone can still send convincing mail claiming to be from your domain. Enforcement is what actually blocks it. Getting there safely means finding every legitimate service that sends as your domain first, the marketing platform, the accounting package, the booking system, the scanner that emails PDFs, and staging the change while reviewing the reports, because missing one means its mail stops arriving. **How does business email compromise get past a good filter?** Because there's usually nothing to detect. There's no malware, no attachment and often no link: just an ordinary message from a real, compromised account, sent inside a real conversation thread, asking for bank details to be changed. Filters are good at payloads and poor at intent. The controls that stop the loss are impersonation protection and compromise alerting on the technical side, and on the process side a rule that no payment detail is ever changed without a phone call to a number already on file. That call is what actually prevents the loss. **What should we do first if we think a mailbox has been compromised?** Revoke the active sessions and refresh tokens, then reset the password, in that order, because a password reset on its own can leave a valid session running. Re-register multi-factor authentication if there's any chance the attacker enrolled their own method. Then remove the persistence: inbox rules that forward or delete, added delegates, changed forwarding, and any application consent granted from the account. Only then investigate what was read and sent, warn anyone who may have received a fraudulent payment request, by phone, and assess whether the incident is reportable to the ICO within the statutory timescale. ### Backup Services URL: https://systechitsolutions.co.uk/services/backup Monitored, regularly tested backup for servers, endpoints and Microsoft 365, with immutable ransomware-resilient copies and rapid, proven restore. Monitored, tested backup so recovery is fast, verified and stress-free, including Microsoft 365. Everyone has a backup. Far fewer have a restore, because a backup nobody has monitored or tested is just a hope with a schedule, and you only find out which you have on the worst day. This service is for you if: - You have backups but nobody's proven a restore actually works - Microsoft 365 data is assumed to be safe, but isn't fully backed up - Ransomware, hardware failure or human error would put real data at risk right now The cost of doing nothing: Untested backups fail silently: the job that quietly errored for months, the Microsoft 365 data Microsoft never promised to keep, the restore that turns out to be days long when you needed hours. You discover the gap at exactly the moment you can least afford to. #### Recoverable, whatever happens Backups are only worth having if they work when you need them. We provide monitored, regularly tested backup for your servers, endpoints and cloud workloads, including Microsoft 365. When something goes wrong, whether it's ransomware, hardware failure or simple human error, you recover quickly with confidence, because we've already proven the restore works. What's included: - Server, endpoint and Microsoft 365 backup - Monitored backups with regular recovery testing - Rapid restore and disaster recovery planning - Immutable, ransomware-resilient copies - Flexible retention to meet compliance needs - Clear reporting on backup health #### What is the difference between having backups and being recoverable? Recoverability is a tested property of the whole estate; a backup is one input to it. The gap between the two is where most organisations discover, at the worst possible moment, that they had the wrong thing. A job can complete successfully every night and still be useless: it might be backing up a database while it is running, without quiescing it, so what lands is a file nobody can mount. It might have stopped covering a server that was rebuilt in March. It might be perfectly valid and take four days to restore over the link you have. So the questions worth asking are not about the backup, they are about the restore. How long does it take to get the finance system back, measured rather than estimated? Who does it, and what happens if that person is unavailable? Where are the credentials for the backup platform, and are they somewhere that survives the same incident? What is the order of restoration, given that half your systems will not start until identity and DNS are working? An organisation that can answer those is recoverable. One that can only show green job reports has backups. #### Does Microsoft back up Microsoft 365, and what exactly is missing? Not in the way most people assume. Microsoft's shared responsibility model makes them accountable for keeping the service available and resilient, and makes you accountable for your data within it. What the platform gives you is recycle bins, version history, retention policies and legal hold: controls designed for accidental deletion and for legal preservation, not for restoring a tenant after a compromised administrator account deleted at scale, or after ransomware encrypted files that then synced happily to the cloud. Recycle bins have finite windows, and once one lapses the content is gone. #### How do you set RPO and RTO without guessing? By asking the business two questions per system and writing the answers down. The recovery point objective is how much work you are prepared to lose, which in practice means how far back you can afford to roll: an hour of orders is a very different proposition from a day of them. The recovery time objective is how long the system can be unavailable before the consequence becomes serious. Both are business decisions, not technical ones, and the technology exists to meet them rather than to define them. The discipline that makes this useful is refusing to answer 'zero' for everything, because that produces a design nobody will pay for and so nothing gets designed. Rank systems into a small number of tiers by what actually stops if they are down, accept that the file share holding archived project folders does not need the protection the practice management system needs, and check that the resulting design genuinely meets the stated numbers rather than assuming it does. A stated RTO that has never been timed against a real restore is an aspiration, and it is the number people quote in a crisis right up until the moment it is disproved. #### What does the 3-2-1 rule mean in a cloud-first estate? Three copies of the data, on two different types of media, with one held off site. It predates the cloud and it still holds, because it is really a rule about correlated failure: the copies must not be able to fail for the same reason at the same time. What has changed is what counts as separation. Two containers in the same cloud account are not two independent copies, because a single compromised administrator credential reaches both. Neither is a replica that faithfully replicates the encryption an attacker just applied. In a modern estate the practical reading is: a local copy for fast restores, a copy in a different platform or account with separate credentials, and at least one copy that is immutable for a defined period. Many people now extend it to 3-2-1-1-0, adding one immutable or offline copy and zero errors on verification. The number is less important than the test: for each pair of copies, name the single event that could destroy both. If you can name one, they are not really two copies. #### Why does immutability matter, and what makes a copy genuinely immutable? Because modern ransomware attacks the backups first. The operators know that an organisation with working backups does not pay, so a competent intrusion spends time locating the backup platform, deleting or encrypting the repositories, and only then triggering the encryption of live systems. Retention alone does not stop that: a copy an administrator can delete is a copy an attacker with administrative credentials can delete, and by that stage in the intrusion they usually have them. Immutability means the copy cannot be altered or removed for a defined period, by anybody, including whoever holds the highest privilege on the platform. That last clause is the whole point, and it is the one to test rather than take on trust. A vendor that answers those clearly is worth more than one with a longer feature list. #### What actually gets missed when a backup is scoped? Consistently the same things. Endpoints, on the assumption that everything is in OneDrive, which is true right up until somebody saves the important spreadsheet to the desktop. Microsoft 365, on the assumption that the cloud is backed up by definition. Then the recovery dependencies, which are the ones that turn a restore into an ordeal. Where are the credentials for the backup platform stored, and are they in the system you are trying to restore? Is the documentation for the restore process itself only available on the file share that is down? Is there an offline copy of the recovery plan? Does anyone other than one person know how to do it? An estate can have technically excellent backups and still fail to recover, purely because everything needed to run the restore was inside the thing that broke. #### What does a real restore test look like? It restores something to somewhere it can be used, and somebody who knows what the data should look like confirms that it is correct. That is the bar, and it is higher than what usually passes for testing. Verifying that a backup file exists and passes a checksum proves the file is intact, not that the application inside it will start, that the database will mount, or that last week's transactions are present. A test that ends at the storage layer has tested the storage layer. A useful test runs to an isolated environment so production is never at risk, follows the written procedure rather than the knowledge in someone's head, and is timed, because the elapsed time is the only honest measure of your real recovery time objective. Rotate what gets tested so that over a cycle the important systems have each been proven rather than the same convenient one every time, and include at least one restore performed by somebody other than the person who built the backup. Record what was restored, how long it took and what went wrong, because the things that went wrong are the actual output of the exercise. We agree a testing schedule with each client and report against it, so the evidence exists before it is needed rather than after. #### What does a disaster recovery plan need beyond backup? An order, an owner and a way to communicate. Order matters because systems have dependencies: identity, DNS and network services usually have to come back before anything that authenticates against them, and restoring the visible business application first is a common way to waste hours. The plan should state the sequence, the target time for each tier and what the business does manually in the meantime, because there will be a period where the answer is paper and telephones. Ownership matters because in a real incident people are unavailable, distracted or already dealing with something else, so every step needs a named owner and a named deputy. Communication matters because staff, clients and sometimes regulators need to hear something accurate and early, and the mechanism for telling them cannot depend on the systems that are down: if your only route to reach staff is the email platform, and the email platform is the problem, you have no route. Print the plan. Keep contact details offline. Decide in advance who is authorised to declare an incident and who speaks for the organisation. #### How does backup interact with Cyber Essentials, ISO 27001 and insurance? Precisely and differently, and it is worth being accurate rather than implying more than is true. Cyber Essentials covers five technical control themes, and backup is not one of them, so no amount of backup capability will pass a control you have failed elsewhere. ISO 27001 is different: its Annex A includes a control specifically on information backup, so an organisation certified to it is expected to have backup arrangements that are documented, aligned to agreed requirements and, importantly, tested. That word is what turns backup from a purchase into a discipline. Systech holds both ISO 27001 and Cyber Essentials, so this is a standard we run against as well as advise on. Cyber insurance is where the detail bites hardest. Proposal forms and renewal questionnaires routinely ask whether backups are held offline or immutably, whether they are separated from the production environment, and whether restores are tested, and the answers form part of the basis on which cover is written. Answering optimistically about a control you do not actually operate is a poor position to be in at claim time. The safe approach is to answer from evidence you could produce, which is another argument for testing on a schedule and keeping the records. #### What should backup reporting actually tell you? Four things, and most reporting only manages the first. Whether jobs completed, obviously, but with warnings treated as failures rather than as background noise, because a job that has been completing with warnings for six months is usually a job that is quietly skipping something. What is protected against what should be protected, so a new server or a new site that nobody added to the schedule shows up as a gap rather than as an absence nobody notices. Whether restores have been tested, when, what was restored and how long it took. And how retention and storage consumption are trending, because that is what predicts the next capacity or cost surprise. The failure pattern is silent success. Alerting configured only for failure means a job that stops running altogether, or an agent that stopped checking in, produces no alert at all, because nothing failed: nothing happened. Reporting should assert what it expects to see and flag the absence, and it should go to somebody whose job it is to act on it rather than to a shared mailbox. That is the difference between monitored backup and backup with a monitoring product attached. #### When do you not need this, and where does our scope end? You do not need us if you already have an owned, immutable, off-platform copy of everything that matters, a documented and timed restore procedure, and a record of tests somebody actually ran this year. That is a genuinely well-run position and it is rarer than it should be. Our scope is servers, endpoints, cloud workloads and Microsoft 365 data, with monitoring, immutable copies, restore testing and recovery planning around them. We will tell you where the platform you already own is sufficient rather than replacing it for the sake of it. What we will not do is state a recovery time we have not measured on your estate: any figure quoted before a test is an estimate, and we would rather test it and tell you the real number, even when the real number is not the one you wanted. #### Frequently asked questions **Doesn't Microsoft back up Microsoft 365 for us?** Microsoft keeps the service running, but under its shared responsibility model your data is your responsibility. Deleted or ransomware-encrypted mail, files and Teams data can be lost once retention windows pass. A dedicated Microsoft 365 backup gives you independent, long-term, recoverable copies. **How do you know a backup will actually restore?** Because we test it. We monitor every backup job and run regular recovery tests, so a restore is a proven routine, not a gamble. That's the difference between having backups and having recoverability. **Are your backups protected against ransomware?** Yes. We keep immutable, ransomware-resilient copies that can't be altered or deleted by an attacker, so even if live systems are encrypted, there's a clean copy to recover from. **What are RPO and RTO, and how do we decide ours?** The recovery point objective is how much work you can afford to lose, so it sets how often backups run. The recovery time objective is how long a system can be down before the consequence becomes serious, so it sets how the restore is designed. Both are business decisions rather than technical ones. Rank your systems into a few tiers by what actually stops when they're unavailable, avoid answering 'zero' for everything because that produces a design nobody will fund, then check the resulting design genuinely meets the numbers by timing a real restore rather than assuming. **Is replication the same as backup?** No, and confusing the two is a common and expensive mistake. Replication keeps a second copy continuously in step with the first, which is excellent for hardware failure and site loss because failover is fast. It is no use at all against ransomware, corruption or deletion, because it faithfully replicates those too, usually within seconds. Backup keeps historical points you can go back to. Most estates that need fast failover need both: replication for availability, backup with immutable retention for recovery. **Does the 3-2-1 rule still apply if everything is in the cloud?** Yes, though what counts as separation changes. The rule is really about correlated failure: three copies, two media types, one off site, arranged so no single event destroys more than one. Two storage accounts under the same cloud tenant are not two independent copies, because one compromised administrator credential reaches both. The useful test is to take each pair of copies and name the single event that could destroy both. If you can name one, you effectively have fewer copies than you think. **What does a restore test actually involve?** Restoring real data to somewhere it can be used, and having somebody who knows the data confirm it is correct and complete. Verifying that a backup file exists and passes a checksum only proves the file is intact; it doesn't prove the application will start or the database will mount. A worthwhile test runs to an isolated environment, follows the written procedure rather than someone's memory, is timed so you learn your true recovery time, and rotates across systems so the same convenient one isn't the only thing ever proven. What went wrong during the test is the most valuable output. **What is usually left out of a backup scope?** Endpoints, on the assumption everything is in OneDrive. Microsoft 365, on the assumption the cloud backs itself up. Configuration rather than data: firewall and network device configs, identity platform settings, certificates and server build definitions. And the recovery dependencies, which is the one that hurts most: the credentials for the backup platform, the documentation for the restore procedure, and the recovery plan itself all stored inside the environment you are trying to restore. Keep an offline copy of all three. ### White-Label Delivery & Bespoke Consulting URL: https://systechitsolutions.co.uk/services/white-label White-label IT delivery and consulting for vendors, MSPs and partners: enterprise-grade technical execution and strategic advice under your brand, NDA-backed. Enterprise-grade technical delivery and bespoke consulting, under your brand, for vendors, MSPs and partners who need expert bench strength or a specific piece of strategic advice without hiring for it. You won the contract on the strength of your brand. Delivering it shouldn't mean scrambling to hire the exact skill it needs, or turning the work away because you can't. Sometimes what you need isn't a delivery bench at all, just one specific piece of expert advice before you commit to something. This service is for you if: - You're a vendor, MSP or partner who's won work that needs skills you don't have in-house - You'd rather add expert bench strength than hire for a single contract - You need a specific, bespoke piece of technical consulting, not an ongoing arrangement - You need delivery and advice that stays completely invisible to your client The cost of doing nothing: Turning down a contract because you lack one skill is lost revenue and a dented reputation. Hiring for it is slow, expensive and a liability if the pipeline shifts. Sub-contracting to someone who might appear in front of your client is a risk few brands want to take. #### Your expert delivery bench, invisible to your clients Won a contract that needs expertise you don't have in-house, or facing a challenge you're not quite sure how to approach? We deliver the technical work and the strategic advice behind the scenes, fully under your brand, so your clients only ever see you. It isn't outsourcing in the way that usually makes people nervous. You stay the single point of contact for your client, and we work as an invisible extension of your team, scoped to exactly what you need: a one-off project, a specific skill gap, or an ongoing bench you can call on whenever the next contract demands it. What's included: - Fully white-labelled delivery, no Systech branding in front of your client - Contract delivery support, from scoping through to technical execution - Bespoke consulting and advisory for a single decision, not just ongoing delivery - Flexible engagement: one-off projects, a single consulting piece, or an ongoing delivery bench - Direct access to senior engineers and Ryan Mangan's own MVP-level expertise, not a generic outsourced desk - NDA-backed confidentiality as standard on every engagement #### What can we actually deliver under your brand? Broadly, the service lines we already run for our own clients, delivered by the same engineers with your name on the output. In practice the work that gets asked for most is: managed IT and service desk cover; Microsoft 365 and Azure project work, meaning tenant builds, migrations, SharePoint and Teams structure, and security hardening; security delivery including managed firewall, EDR and XDR rollout, Conditional Access design and Cyber Essentials preparation; backup and recovery design plus restore testing; application packaging and MSIX, including App Attach image builds; Azure Virtual Desktop and Windows 365 design, build and cost optimisation; legacy Windows and Windows Server migrations; and legacy application capture and repackaging where the original install media has gone. That work happens in the background and lands as material you can put your own cover on. Where you want it delivered live, we can join a client session under your branding, described as your engineer or as your named specialist partner, whichever suits the relationship. #### Bespoke consulting for vendors and partners, not just delivery capacity Not every gap is a delivery gap. Sometimes a vendor, MSP or partner needs one specific, bounded piece of expert judgement rather than an ongoing bench, and that is a genuinely different engagement to scope for. A software vendor preparing to sell into Microsoft-centric enterprise accounts might need a technical reviewer who can sanity-check how their product actually behaves inside Conditional Access, Intune or an Azure Virtual Desktop estate before a customer's own architects ask the question. #### Which engagement model fits: fully white-label, co-branded or overflow? Fully white-label is the default. Your brand is the only one the client sees, we never appear in the room or on the documentation, and everything we produce is written in your templates for you to issue as your own. It suits contracts you have won on your reputation where the delivery skill happens to sit outside your team, and it is the model most vendors and MSPs ask for first. Co-branded is the honest alternative when the client is buying the specialism as well as the relationship. Some end clients specifically want to see who is doing the work, particularly on Azure Virtual Desktop, Windows 365 or security engagements where a named credential carries weight in their own governance process. In that model you stay the contracting party and the account owner, and we are introduced as your named specialist partner rather than hidden. Overflow is different again: not a skill gap but a capacity gap, where our engineers work inside your existing ticket queue, project tooling and processes to absorb a peak, a holiday period, a backlog or a project running hotter than planned. The right model is usually obvious within one scoping call, and it can change between engagements. #### How does an engagement start, and what happens before we get any access? A mutual non-disclosure agreement comes first, before any detail about your client, their estate or your commercial position is discussed. That is standard on every engagement, including ones that never proceed past a scoping conversation, because the useful conversation cannot happen while both sides are being careful. If you have your own NDA template, we are happy to work to yours rather than insisting on ours. After that the sequence is deliberately boring, because boring is what stops disputes later. A scoping call establishes what the client actually needs, what you have already committed to in writing, and what your delivery team is keeping. That becomes a written scope naming the deliverables, the exclusions, the assumptions the estimate depends on, who owns each part, and how the work will be handed back. Access is granted only after the scope is agreed, is limited to what the work genuinely requires, and is documented so both sides know exactly what we hold. Then delivery starts. The step partners tell us is most often skipped elsewhere is the assumptions list, and it is the one that determines whether a change in the environment becomes a conversation or an argument. #### How do branding, tooling and communication work in practice? Communication runs through one agreed channel with a named owner on each side, rather than through whichever engineer happens to be reachable. Most partners run a shared Teams channel or work into their own ticketing system, and where you want us in your tooling we work in your tooling: your ticket queue, your project board, your documentation platform, your naming and change conventions. That matters more than it sounds, because work delivered into your own systems is work your team can support after we step away. Where you need us on a client call, we attend as part of your team and follow whatever description you have set with them. Anything that would put our brand in front of their brand is your decision to make, not ours. #### How does escalation work when something goes wrong on your client's estate? Through you, always. You own the client relationship and therefore the client communication, so our job in an incident is to give you an accurate technical picture fast enough that you can be the one telling them something useful. An arrangement where the subcontractor starts talking directly to the end client during an incident is exactly the failure that makes brands nervous about subcontracting in the first place. We will not quote you a response target here that has not been agreed against real scope, because a number published on a web page is worth nothing when your client is asking you a question at eight on a Friday evening. Ask for it in writing, from us and from anyone else you are comparing. #### Who uses white-label delivery, and why? Hiring for it makes no sense when the requirement appears twice a year, and turning it down costs the contract and sometimes the account. Software vendors use us for the deployment and integration layer around their own product: getting it packaged, delivered and supported cleanly in a customer's Microsoft estate, dealing with the identity, device and virtual desktop questions their support team is not staffed to answer, or standing behind a proof of concept in an enterprise environment. IT resellers and consultancies use us for delivery capability behind a sale, so they can bid on work that includes implementation rather than restricting themselves to supply. In all three cases the pattern is the same: the brand and the relationship are already yours, and what is missing is the bench. #### What goes wrong when subcontracting is done badly? The failure modes are predictable and almost all of them are commercial rather than technical. A subcontractor turns up in front of the end client without warning, or worse, is recognised by them. Scope exists only as a verbal understanding, so every discovery becomes an argument about who agreed to what. Nobody is named as owner on either side, so questions sit unanswered for days. Engineers rotate through the work with no continuity, and each new one asks your client's IT manager the same questions the last one did, which is what makes the arrangement visible. Then there is the ending, where the real damage happens. The work completes but the documentation never arrives, so your team cannot support what was built and has to call the subcontractor every time something breaks, which is either an accident or a business model. Administrative access granted for the project is still live months later, on your client's tenant, in your name. Or the subcontractor approaches the client directly once the engagement ends. Every one of these is preventable in writing at the start: named owners, a written scope with exclusions, handover documentation as a defined deliverable rather than a courtesy, an access removal step at the end, and a non-solicitation clause you should insist on from any partner, including us. #### Where does our scope end, and what do we not do? We do not hold your client contract and we do not carry your obligations under it. Whatever we deliver, you remain the supplier your client bought from, which means their commercial terms, their service commitments and their regulatory accountability stay with you. We can build to a standard you have committed to and give you the evidence that it was built that way; we cannot sign your commitment on your behalf. Our certifications are ours and do not transfer. Systech's ISO 27001, ISO 9001 and Cyber Essentials certificates cover how Systech operates, so they are a fair statement about the processes your delivery runs through, and they are not a certificate you can present as your own. The same applies to independent penetration testing, which we deliver with our CREST-approved partner Punk Security: that approval belongs to them, so it is disclosed rather than absorbed into somebody else's brand. And there is a practical boundary worth stating plainly, because it comes up: if a scope has been sold that cannot be delivered as described, we will tell you during scoping rather than after you have taken the money. #### What sits behind the delivery, stated honestly? We are not going to quote you a partner count or show you logos, because white-label work is confidential by definition and any firm willing to show you their other partners' names is telling you exactly how they will treat yours. What we can point you at is verifiable instead. Systech is founder-led by Ryan Mangan, a Microsoft MVP renewed specifically for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS, and the author of Packt's two-edition Mastering Azure Virtual Desktop, with articles published in the BCS's IT Now and in Computer Weekly and a public MSIX App Attach reference wiki that other engineers use when they get stuck. For a partner assessing us that combination is the point. It means the supply-chain questions your own client's procurement team will ask about us have answers you can evidence, rather than answers you have to take on trust and then repeat. #### How is white-label work scoped and priced? Per engagement, against a written scope, because the honest answer is that the same nominal task varies enormously with the estate it lands in. What we can commit to is the shape of the quote: it itemises what is included, what is explicitly excluded and what assumptions the estimate rests on, so you can price your own margin on top with confidence and compare it line by line against anyone else you are considering. A number quoted before anyone has looked at the environment is a number that will change. Two commercial structures cover almost everything. Fixed-scope project work suits a defined deliverable with a clear end, such as a migration, a build or a packaging batch, and it is the easier one to sell on to your client because the risk is bounded. A retained bench suits partners with recurring or unpredictable demand, where the value is knowing capability is available when a contract lands rather than paying for it while it waits. Plenty of partners start with the first, discover the demand is not one-off, and move to the second. #### Frequently asked questions **Do we have to commit to an ongoing delivery bench, or can we just get one piece of expert advice?** Just the advice, if that is genuinely what you need. A tender response section, a design review, a technical due-diligence assessment ahead of an acquisition, or a second opinion before you commit to a client, all scope as a single bounded piece of consulting with a defined output, not an ongoing arrangement. Say what you actually need on the first call and we will scope to that, not to a bigger engagement than the problem requires. **Will your team ever be visible to our clients?** No. We work fully white-labelled and NDA-backed, behind your brand. You stay the single point of contact and take the credit. We're an invisible extension of your team. **Can we use you for a one-off project or only ongoing?** Either. Engage us for a single contract that needs a specific skill, or keep us as an ongoing delivery bench you can call on whenever the next piece of work demands it. We scale to your pipeline. **What kind of work do you deliver white-label?** Enterprise-grade Microsoft cloud, security, modernisation and application packaging delivery, plus strategic advisory on how to approach complex or unfamiliar challenges, all under your brand. In practice that covers managed IT and service desk cover, Microsoft 365 and Azure projects, security and Cyber Essentials preparation, backup and restore testing, application packaging and MSIX, Azure Virtual Desktop and Windows 365, and legacy OS and application migration. **Will you approach our clients directly, during or after the engagement?** No, and you shouldn't take that on trust from any subcontractor, including us. Ask for it in writing. We're happy for a non-solicitation clause covering the end clients we're introduced to to be part of the engagement, drafted into your paperwork rather than ours, and to make it mutual. Our commercial relationship is with you, and a partner who quietly builds a route around you has destroyed the only thing that made the arrangement worth having. **Who owns the documentation and the intellectual property we pay for?** You do, for the deliverables produced for your engagement: designs, run books, handover documentation, scripts and configuration written for that client's estate. Handover documentation is treated as a defined deliverable rather than a courtesy, because a partner who cannot support what was built is dependent rather than served. What stays ours is our own pre-existing methods, templates and internal tooling, which we bring to the engagement rather than create in it. That split should be explicit in the scope, so agree it at the start rather than discovering it at the end. **What happens to the access you were granted once the work finishes?** It is removed as a defined step at handover, and it is worth insisting on this with any supplier. Administrative access granted for a project has a habit of living on for months afterwards in somebody else's tenant, which is a genuine supply-chain risk sitting in your client's estate under your name. We document what access we hold at the start, keep it limited to what the work requires, and remove it on completion, with confirmation back to you so you have the record. **Can your engineers work inside our ticketing system and our processes?** Yes, and for overflow work that is usually the better arrangement. Working in your ticket queue, your project board, your documentation platform and your naming and change conventions means the output stays supportable by your team after we step away, rather than sitting in a system they cannot see. It also keeps the engagement invisible to your client, because nothing about the ticket they raised looks any different. **What response times will you commit to?** Whatever we have agreed in writing against a defined scope, which is deliberately not a number we publish. Response and escalation targets depend entirely on what is being covered, what hours it needs covering, and what your own commitment to your client is, so a figure quoted before any of that is known would be a marketing number rather than an operational one. Tell us what you have promised your client, and we will tell you plainly what we can stand behind and what we cannot. **Do we have to tell you who our client is?** Usually yes for delivery work, because we cannot administer an estate without knowing whose it is, but the NDA comes first and it works both ways. For advisory, design review or scoping work we can often be useful with the environment described and the client anonymised, which is a reasonable way to start if you are testing whether the arrangement suits you before committing anything sensitive to it. ### Software Development & Bespoke Business Applications URL: https://systechitsolutions.co.uk/services/development Custom business applications, reporting, data integration, service desk AI and CRM replacements, built by the team that also runs the systems around them. Reporting, internal tools, data work and CRM replacements, built when buying something does not work and not before. Almost every business has a job that runs on a spreadsheet, held together by one person who understands it. It works right up until they are on holiday, and then it is the most expensive thing you own. This service is for you if: - Someone exports to Excel every week to produce a report a system should already give them - Your CRM has become the wrong shape for how the business now works, and the renewal is coming - A process that matters runs on a spreadsheet only one person fully understands - You want AI doing real work inside your service desk rather than demonstrating itself The cost of doing nothing: Manual reporting and spreadsheet processes do not fail loudly. They quietly consume a day a week, produce numbers nobody fully trusts, and concentrate the knowledge of how the business actually works in one person who is one resignation away from taking it with them. #### Build the thing the spreadsheet is standing in for We build the software that sits in the gaps: the reports your systems will not produce, the internal tools that replace a shared spreadsheet, the integrations that stop somebody rekeying the same order into two places, and occasionally a full application where the market has nothing that fits how you work. The difference between us and a development shop is what happens around the code. We already run Microsoft estates, identity, security and backup for our clients, so what we build authenticates against the identity you already have, respects the permissions you already set, gets backed up, gets patched, and does not arrive as an orphan nobody can support. Most bespoke software fails after go-live rather than during the build, and that is why. What's included: - Reporting and dashboards, built on data pulled out of systems that will not report properly - Bespoke line-of-business applications where nothing off the shelf fits - CRM replacement and migration when the product has become the wrong shape - AI skills and agents inside the service desk, for triage, drafting and routing - Data integration, migration and cleaning between systems that do not talk - Internal tools and portals that replace shared spreadsheets and manual handoffs #### When should you build software rather than buy it? Rarely, and the honest test is whether the thing you want is genuinely how you compete or merely how you have always done it. Almost every requirement that arrives described as a software project turns out to be one of four things, and only the last is a build. The strongest signal for a real build is that the process is specific to how you make money and you have already tried to buy it twice. The strongest signal against is that a product does most of it and the objection is a compromise on the edges, because the cost of avoiding that compromise is not the build, it is owning the result for the next decade. We will say which of the four we think it is at the end of the first conversation, and we say it before anyone is quoted, because a supplier who only ever finds reasons to build is not giving you advice. #### Why can our systems not produce the report we need? Usually because the data is fine and the reporting layer is not, which is why the answer is rarely to replace the system. Business applications are designed around entering and processing records rather than answering questions across them, and their reporting tends to be a fixed set of views the vendor thought of. The second reason is that the question spans systems. The report somebody actually wants joins the finance system to the CRM to the job scheduler, and no single product has all three, so a person becomes the join and does it by hand in a spreadsheet every Monday. The fix is to get the data out on a schedule, put it somewhere designed to be queried, and build the reporting on that rather than fighting the source system. That also removes the risk of reporting queries slowing down the thing people use to do their jobs. The part that decides the cost is extraction. A system with a documented API is straightforward. A system with a supported database connection is fine. A system where the only route out is a screen, and a vendor who charges for exports, is a different project, and it is worth finding out which you have before anyone designs a dashboard. #### How do you replace a CRM without losing the history? By treating the data migration as the project and the new CRM as the easy part, because the reason CRM replacements go badly is almost never the new product. The first job is deciding what actually comes across. Years of records include duplicates, contacts who have left, opportunities that were never closed and fields that three different people used for three different purposes. Migrating that faithfully means paying to move a mess into somewhere new and then distrusting the new system within a year, so the cleaning happens before the move rather than as a tidy-up afterwards. A frequent and cheaper answer is that the CRM is fine and the way it has been set up is not. If the objection is that it has become the wrong shape, it is worth an hour establishing whether the shape is the product or a decade of accumulated configuration, before paying to move. #### What does AI actually do inside a service desk? The useful work is unglamorous: reading a ticket as it arrives, working out what it is about, routing it, drafting a first response from material that already exists, and pulling together the context an engineer would otherwise spend five minutes gathering. That is where the time goes on a busy desk, and it suits automation because the volume is high, the shapes repeat, and a human still reviews the output before it reaches the customer. What matters is the boundary. An AI step should draft rather than send, suggest a category rather than silently close, and be measured on whether an engineer accepted its suggestion. The moment it acts unreviewed on a customer-facing channel, the failure mode stops being a wasted minute and becomes a wrong answer sent under your name. It also has to answer from your material rather than in general, because a drafted reply is only worth having if it is grounded in your documented fixes and the customer's actual configuration. That is a retrieval problem before it is an AI one. Where that grounding is the substance of the project rather than one component of it, it is engineering in its own right, and the AI engineering page covers it properly. #### What happens to bespoke software after it is built? This is the question worth asking every supplier, including us, and it is the one that decides whether the investment survives. Most bespoke software does not fail during the build. It works, it is handed over, and then eighteen months later nobody knows how to change it, the person who commissioned it has moved on, and it is quietly worked around. Our answer is that you own the code, it runs on infrastructure you own or we manage transparently, and it is built to be handed to someone else, because software you cannot leave is not an asset. It is also why we would rather build something small that survives than something impressive that becomes a liability. #### How do you keep a bespoke build from overrunning? By making the first commitment small and the first delivery real. The pattern that fails is a long build against a specification agreed at the start, because that specification was written when everyone understood the problem least, and nobody finds out it was wrong until the end. So the first stage is scoping, priced as its own fixed piece of work, and its output is a written scope of the problem separated from the solution somebody had already imagined. That is deliberately small: it is where you find out whether the data comes out, whether an existing product would do, and what the real effort is, before there is any pressure to keep going. After that, the smallest genuinely useful version goes to real users in production. Not a prototype and not a demonstration, because neither tells you anything reliable. People use software differently from how they describe using it, and the first fortnight of real use changes more requirements than any workshop. The cost driver, almost always, is integration rather than the application itself. Screens are predictable. Getting clean data out of a system that was never designed to give it up is not, which is why we try to prove the hardest extraction first rather than leaving it until the end when the budget is spent. #### Frequently asked questions **How much does bespoke software cost?** We scope before quoting, because the honest answer depends almost entirely on the data rather than the screens. Two applications that look identical to a user can differ several times over in cost depending on whether the systems involved give their data up cleanly or have to be prised open. That is why the first stage is a fixed-price scoping piece with a written output: a small, visible commitment that tells you what the real effort is, and you keep the scope whether or not you go ahead with us. **Who owns the code you write for us?** You do, and it belongs in the contract rather than in an assurance. The source lives in a repository you have access to, it runs on infrastructure you own or that we manage transparently, and it is built so another developer could pick it up. Software you cannot take elsewhere is not an asset, it is a dependency, and any supplier who is vague on this question is telling you something. **Will you tell us not to build something?** Regularly, and it is most of the value of the first conversation. Most requirements that arrive as a software project turn out to be a configuration change to a product you already pay for, a reporting problem where the data is all present, or a process that should be removed rather than automated. We would rather lose a build and keep the relationship than sell you something you will resent owning in two years. **Can you build reports from a system that has no reporting?** Usually, and the question that decides it is what routes exist to get the data out. A documented API or a supported database connection is straightforward. A system whose only export is a screen, or whose vendor charges for data access, is a harder and more expensive project. It is worth establishing which you have early, because it changes the cost far more than the complexity of the report does. **How is this different from your AI engineering service?** This page is about building an application, which may use AI as one component among several. The AI engineering page is for when the AI is the engineering problem itself: retrieval over your own documents, grounding, model selection and evaluation, where getting the right passage in front of the model is the substance of the work. A ticket-triage skill sits here. A system that has to answer questions accurately from a decade of your documentation sits there. **What happens if the developer who built it leaves?** That risk is a design decision rather than an accident, which is why it is worth asking about before the build rather than after. The mitigations are structure, documentation written for a stranger, and code that follows ordinary conventions instead of clever ones. It also matters that we are a business that runs your systems rather than a single contractor, so support does not rest on one person's availability. Ask any supplier how a second developer would pick their work up, and treat a confident but vague answer as the answer. **Can you work with software we already had built?** Often, and the first piece of work is usually an honest read on what you are holding: whether it can be extended safely, what it depends on that is out of support, and whether the cost of the next change is going to keep rising. Inherited applications are frequently in better shape than their owners fear and occasionally in much worse. Either way it is better to know before you commission the next change than during it. ### Cyber Essentials & Cyber Essentials Plus Certification Support URL: https://systechitsolutions.co.uk/services/cyber-essentials Get through Cyber Essentials and Cyber Essentials Plus: pre-assessment against the five controls, remediation, and support through the questionnaire. Readiness, remediation and someone alongside you for the assessor's questions, so the certificate arrives on the date you promised it. Cyber Essentials looks like a form. That is why so many first attempts fail: the questions are short, the answers are not, and the assessor is checking your actual estate rather than your intentions. This service is for you if: - A contract, tender or insurer requires Cyber Essentials and you have a deadline - You have started the questionnaire and stalled on questions you cannot answer honestly yet - You applied before and failed, or withdrew partway through - You hold Cyber Essentials and need Plus, which is a different and harder thing The cost of doing nothing: The expensive version of this is discovering the gaps during the assessment rather than before it. Certification runs to a clock, remediation takes as long as it takes, and a failed or withdrawn application usually means paying again and explaining a slipped date to whoever asked for the certificate. #### Get certified on the date you promised, not the one after Cyber Essentials is a UK Government-backed scheme covering five technical control themes, and for a growing number of businesses it is no longer optional: it is written into contracts, tenders and insurance renewals, often with a date attached. We take clients through it end to end, from finding out what would fail today to standing alongside them when the assessor comes back with questions. We work with certified assessors rather than issuing certificates ourselves, which is the honest description of the arrangement and also the useful one: our job is to make sure that when your submission reaches an assessor, the answers are true and the evidence is already there. We hold Cyber Essentials ourselves, so the estate we ask you to build is the one we run. What's included: - Pre-assessment against all five control themes, with a written gap list - A straight answer on scope, including what can be legitimately excluded and what cannot - Remediation of what would fail, done by the engineers who run the estate - Support completing the self-assessment questionnaire, in your words and accurately - We stand alongside you for the assessor's follow-up questions rather than handing you over - Cyber Essentials Plus preparation, where a sample of devices is audited hands-on #### What is Cyber Essentials, and who actually issues the certificate? Cyber Essentials is a UK Government-backed certification covering five technical control themes: firewalls, secure configuration, security update management, user access control and malware protection. It is deliberately narrow. It does not attempt to be an information security management system, which is what ISO 27001 is for, and that narrowness is the point: it targets the commodity attacks that make up the bulk of what actually happens to businesses of this size. The scheme is run through IASME as the accreditation body, which licenses the Certification Bodies that assess and issue certificates. That matters when you are choosing who to work with, because there are two different roles and plenty of suppliers blur them. We are in the first role, not the second. We prepare you, remediate what fails and support you through the process, and the certificate is issued by a certified assessor. A supplier who both fixes your estate and marks its own homework is a conflict worth noticing, and it is the reason we are straightforward about which side of the line we sit on. Certification lasts twelve months, so it is a recurring commitment rather than a one-off. That is worth planning for, because estates drift and the second year is where organisations get caught out by changes nobody registered as security changes. #### Why do first attempts fail? Almost always on the same handful of things, and rarely on anything exotic. The questions read as simple, which encourages an optimistic answer, and the assessor is asking about the estate as it is rather than as it is meant to be. None of these are hard problems. They are cheap to fix in advance and expensive to discover mid-assessment, because a submission that stalls does not pause your deadline. The other reason to find them early is that the honest answer to a questionnaire question is sometimes no, and knowing that a fortnight before you apply is a completely different situation from discovering it during. #### What is the difference between Cyber Essentials and Cyber Essentials Plus? Cyber Essentials is a self-assessment: you answer the questionnaire, a senior person signs it off, and a Certification Body reviews the answers. Cyber Essentials Plus covers exactly the same five control themes, but an assessor verifies them hands-on, testing a sample of your actual devices rather than taking the answers on trust. You need Cyber Essentials before you can hold Plus, and Plus has to follow within a defined window after the base certification, so the two are planned together rather than as separate projects. If Plus is what your contract requires, that timing is worth confirming at the start, because it constrains when you should start the first one. The practical difference is that Plus is much less forgiving of a gap between what was declared and what is true. An estate that scraped through the questionnaire on optimistic answers does not scrape through a technical audit, and the work that makes Plus pass happens well before the auditor connects to anything. Which one you need is a contractual question rather than a security one, and it is worth reading the actual requirement. Plenty of organisations pay for Plus because a tender said the words and nobody checked whether the base certification would have satisfied it. #### What counts as in scope, and can anything be excluded? Scope is the single most consequential decision in the whole process, and it is made before any technical work is worth doing. The default is the whole organisation, and that default is what most contracts and insurers expect to see, because a certificate covering one department answers a much smaller question than the buyer thinks it does. In scope means all the devices that access organisational data or services, including laptops, desktops, mobiles, tablets, servers and the cloud services you use, and it includes personal devices where people use them for work. It also includes home working, which surprises organisations that still think of their office as the boundary. A sub-scope is possible where a part of the organisation is genuinely separated from the rest by network segregation, but the separation has to be real rather than organisational. This is the area where an honest conversation early saves the most money, and where we will sometimes tell you that the segregation you believe exists does not. The place scope decisions most often go wrong is unsupported software. Something out of support inside the boundary is usually fatal to an application, so the choice becomes replacing it, upgrading it, or genuinely segregating it away from organisational data. All three are real options with different costs, and picking between them is work that has to happen before you apply rather than during. #### What do you actually do, and what do we have to do ourselves? We do the finding and the fixing, and you keep the parts only you can honestly own. The questionnaire is signed off by a senior person in your organisation, and that is not a formality: it is an assertion about your estate that has to be true. The follow-up questions are the stage people underestimate. An assessor querying an answer is normal rather than a sign of failure, but it is also where applications stall, because the person who wrote the answer often cannot evidence it without going back to whoever configured the thing. Having the people who did the remediation available at that moment is most of why applications supported this way close on time. #### Is certification worth it if nobody has asked for it yet? Often, but be clear about which of two reasons you are buying, because they justify different amounts of effort. The commercial reason is access. Cyber Essentials is a requirement for some public sector contracts and increasingly appears in private sector supply chains and insurance renewals, so holding it removes a barrier before you meet it. If you sell to organisations that ask their suppliers security questions, certifying ahead of the first tender that demands it is straightforwardly cheaper than certifying during one. The security reason is that the five controls are the ones that matter most against the attacks businesses of this size actually experience. Working through them honestly usually surfaces things worth knowing regardless of the certificate, which is why we recommend the readiness check even to organisations that decide not to apply. What it is not is proof that you are secure, and it is worth being clear-eyed about that. It is a floor rather than a ceiling, verified once a year, and treating the certificate as the end of the security conversation is a mistake we would rather you did not make on our watch. #### Frequently asked questions **Do you issue the Cyber Essentials certificate?** No, and it is worth being precise about this. IASME is the accreditation body for the scheme and licenses the Certification Bodies that assess submissions and issue certificates. We work alongside certified assessors: we run the pre-assessment, do the remediation, help you complete the questionnaire accurately and stay with you through the assessor's follow-up questions. Separating those roles is also healthier, because a supplier who both fixes your estate and marks its own homework is not giving you an independent result. **How long does Cyber Essentials take?** The assessment itself is fast. What takes time is remediation, and that depends entirely on what the pre-assessment finds. An estate that is already well managed can move quickly. An estate with unsupported software in scope, no multi-factor authentication on cloud services or no reliable patch reporting has real work to do first, and no amount of scheduling makes that shorter. That is why the first thing we do is find out which one you are, so you know whether your deadline is achievable before you commit to it. **What does Cyber Essentials cost?** There are two separate costs and they are worth keeping separate in your head. The certification fee is set by the scheme and banded by organisation size, and it is paid to the Certification Body rather than to us. Then there is the preparation and remediation, which is the variable part, because it depends on what needs fixing. We scope that after the readiness check rather than before, since quoting remediation before anyone has looked at the estate would be a guess dressed up as a price. **We failed last time. Can you help us reapply?** Yes, and it is a common starting point rather than an awkward one. A failed or withdrawn application is useful information: it usually means a specific control could not be evidenced, and the feedback narrows the search considerably. We would still run the full readiness check rather than only fixing the thing that failed, because an application that stalled on one control has frequently been optimistic on others that were not examined closely. **Does Cyber Essentials cover home working and personal devices?** Yes, and this catches people out. Devices used to access organisational data or services are in scope wherever they are, so home working is included, and personal devices used for work are included too. Home routers supplied by an internet provider are treated differently from corporate firewalls, and the controls that matter are then on the device itself. If your position is that people use their own phones for email but you had not counted those as in scope, that is worth resolving early rather than in the questionnaire. **Do we need Cyber Essentials or ISO 27001?** They answer different questions and are not really alternatives. Cyber Essentials certifies five specific technical controls, is achievable in weeks and is what most contracts and insurers actually ask for. ISO 27001 certifies a management system: how you decide what to protect, how you govern it and how you improve it. It is a much larger undertaking. If someone has asked you for Cyber Essentials, do that. If a customer is asking how you manage information security as an organisation, that is the ISO conversation, and doing Cyber Essentials first is a reasonable step toward it rather than wasted work. **Does certification come with cyber insurance?** Sometimes, and the conditions matter more than the headline. The scheme has included an insurance element for UK organisations under a turnover threshold that certify the whole organisation and opt in, but the terms, the threshold and the cover are set by the scheme and its insurance partner rather than by us, and they have changed over time. Treat it as a possible benefit to confirm with the Certification Body at the point of application, not as a reason to certify, and read what it actually covers before you count on it. ### Endpoint Management: Microsoft Intune & Configuration Manager URL: https://systechitsolutions.co.uk/services/endpoint-management Microsoft Intune management, reporting and evidence, plus Configuration Manager co-management. Know what your devices run, not what a policy says. Intune managed properly and reported on honestly, alongside whatever Configuration Manager still owns, so you can prove the state of every device rather than assume it. Intune will tell you a policy is assigned. What it will not tell you, without a great deal of clicking, is whether your estate is actually in the state that policy describes, or was last Tuesday, or has been all quarter. This service is for you if: - You cannot currently prove every device was patched inside the window an auditor or insurer asks about - Devices show as compliant and you are not confident that means what it says - You are running Configuration Manager and being told to move to Intune, with no plan - Nobody owns the endpoint estate day to day, so policies accumulate and nothing gets retired The cost of doing nothing: An endpoint estate nobody reports on drifts quietly. Policies stack up until no one knows which one is winning, devices fall out of compliance without anyone noticing because nothing is watching the trend, and the first time the gap becomes visible is when a certification body, an insurer or an incident asks a question that has to be answered with evidence rather than intent. #### Know what your devices are running, not what a policy says We manage Microsoft Intune day to day: enrolment and Autopilot provisioning, configuration and compliance policies, application deployment, update rings and the ongoing work of keeping all of it coherent as the estate changes. Where Configuration Manager is still doing real work, we run that alongside it under co-management rather than treating it as something to be removed on principle. What we lead with is reporting, because it is where most estates are genuinely blind. Intune is a good management plane and a frustrating reporting one: it answers questions about an object well and questions about an estate over time poorly. So we put a reporting layer over it that shows what is deployed, what is patched, what has drifted and what you can put in front of an auditor, which changes endpoint management from a set of assumptions into something you can evidence. What's included: - Microsoft Intune management: policies, compliance, applications and update rings - Estate-wide Intune reporting, including evidence of patching over time rather than at a moment - Autopilot provisioning, so a replacement device is a delivery rather than a build - Configuration Manager management, co-management and workload migration at your pace - Compliance evidence mapped to what Cyber Essentials and insurers actually ask for - Policy rationalisation, because most estates have accumulated conflicting policies nobody retired - Application deployment, including the packaging work when an application resists it #### Why is Intune reporting the part everyone struggles with? Because Intune is built to manage objects and most of the questions you actually get asked are about estates over time. Those are different problems, and the console is good at the first one. Ask whether a specific device is compliant and Intune answers immediately. Ask whether every device in the business received a critical update inside fourteen days, every month, for the last quarter, and you are into exports, manual joining and a spreadsheet, which is precisely the position the certification was supposed to move you out of. None of this means Intune is the wrong product. It means the reporting layer is a separate job, and treating it as one is the difference between an estate you manage and an estate you can account for. #### What does compliant actually mean in Intune? It means the device met the conditions in the compliance policies assigned to it, at the last time it checked in and reported. Each part of that sentence is a place the answer can quietly stop being true. The most common trap is staleness. A device that has not checked in for weeks can still show its last known state, so an estate that looks healthy may partly be an estate that has stopped talking. Any reporting worth trusting starts by separating devices that are compliant from devices that are merely quiet. The second trap is that a compliance policy only checks what you asked it to. A tenant configured years ago against the threats of the time can report a fully compliant estate while never evaluating the controls anyone would ask about now, which is a reporting result rather than a security one. The third is scope. Devices that were never enrolled do not appear as non-compliant, they simply do not appear, and unmanaged devices are the ones most likely to be a problem. A compliance figure is only meaningful next to an honest count of what should be enrolled, which is why we reconcile against identity sign-ins rather than trusting the device list on its own. #### Should we move from Configuration Manager to Intune? Eventually, probably, and rarely as a single project with a date on it. The framing that causes damage is treating this as a migration with a cutover, because it turns a manageable sequence of reversible steps into one event with a rollback nobody has tested. Co-management is the supported route and it is deliberately incremental: Configuration Manager and Intune manage the same devices at once, and individual workloads move across one at a time, at your pace. Compliance policies, device configuration, Windows Update policies, endpoint protection, resource access and client applications can each shift independently, and each can shift back. That structure means you can move the workloads with clear benefit early, leave the ones Configuration Manager still does better, and stop wherever the value runs out. Plenty of estates settle permanently in a mixed state and are correct to. The honest test is not whether Intune can do a thing, it is whether doing it in Intune is better for you than the working arrangement you already have. We will tell you when the answer is no. #### How do you prove devices are patched? With a record over time rather than a screenshot, and this is the control most likely to fail an assessment because it is the hardest to reconstruct after the fact. Cyber Essentials requires that critical and high-severity updates are applied within fourteen days of release, and an assessor will want to see that this held rather than that it holds today. Insurers ask the same question in different words, and so does anyone doing supply chain due diligence on you. Intune manages the updates well through update rings and deferral settings. What it does not do easily is produce the historical evidence, so the practical answer is a reporting layer that keeps the record continuously: what was released, when it reached the estate, what did not take it, and what was done about the exceptions. Exceptions are the part worth designing for rather than hiding. There is always a device that was off for a month, a machine that cannot take an update because of an application on it, and a build that fails for its own reasons. An assessor is far more comfortable with a documented, managed exception than with a report showing a hundred per cent that nobody believes. #### What does day-to-day endpoint management actually involve? Mostly it is the unglamorous work of keeping an estate coherent while it changes, which is why it degrades so reliably when nobody owns it. The item that surprises people is policy hygiene. Estates rarely suffer from a lack of policy, they suffer from years of accumulation: overlapping assignments, settings applied twice with different values, and configurations created for a project that finished. Nothing announces it, and the symptom is an estate where changes do not produce the results anyone expects. #### Where does endpoint management meet security and certification? At almost every control anybody asks you about, which is why endpoint management is usually the fastest route to a better security position rather than a separate exercise. Of the five Cyber Essentials control themes, endpoint management directly delivers secure configuration, security update management and malware protection, and carries a substantial part of user access control through device compliance and Conditional Access. That is most of the scheme, done through one management plane. The relationship runs the other way too. Conditional Access decisions are only as good as the device state they are conditioned on, so a compliance policy that is stale or shallow quietly weakens an access model that looks strong on paper. So we treat these as one piece of work rather than two. If certification is what is driving your interest, the endpoint estate is where most of the effort will land, and the evidence problem is the part worth starting on now rather than in the week before an assessment. #### Frequently asked questions **Why do we need extra reporting if we already have Intune?** Because Intune answers questions about objects well and questions about estates over time poorly, and the questions you get asked are nearly always the second kind. Whether a device is compliant right now is easy. Proving that every device took critical updates inside fourteen days, every month, across a quarter means exporting, joining and reconciling data by hand, which is exactly the manual position certification was supposed to remove. The management plane is fine. It is the evidence layer that is missing, and that is a separate job rather than a criticism of the product. **Do we have to move off Configuration Manager?** No, and we would push back on anyone telling you otherwise without looking at what it is doing for you. Co-management lets Configuration Manager and Intune manage the same devices at once, with individual workloads moving across one at a time and back again if a move does not work out. Plenty of estates settle permanently in a mixed state because Configuration Manager still does complex application deployment, task sequences and on-premises work better. The question is never whether Intune can do something, it is whether doing it there is better than the arrangement you already have. **Our devices show as compliant. Is that enough?** Not on its own, for three reasons worth checking. Compliance is reported at the last check-in, so an estate that looks healthy may partly be an estate that has gone quiet, and stale devices need separating from compliant ones before the number means anything. A compliance policy also only evaluates what it was told to, so a tenant configured years ago can report a fully compliant estate while never testing the controls anyone would ask about today. And devices that were never enrolled do not show as non-compliant, they simply do not appear, which is why the figure only means something next to an honest count of what should be enrolled. **Can you help us prove patching for Cyber Essentials or an insurer?** That is one of the most common reasons people come to us for this, and it is worth starting early because historical evidence cannot be reconstructed after the fact. Cyber Essentials asks that critical and high-severity updates are applied within fourteen days of release, and an assessor wants to see that this held over time rather than that it holds today. We keep that record continuously, including the exceptions, because a documented and managed exception is far more credible to an assessor than a perfect figure nobody believes. **What is Autopilot and do we need it?** Autopilot provisions a new device into your configuration from its out-of-box state, so a replacement machine can be delivered straight to a person and be usable without anyone building it. It is worth it if you issue devices regularly, support people who are not in an office, or currently have someone spending time imaging machines by hand. It is worth less if you buy devices rarely in batches and have an imaging process that works. It also depends on having your configuration and application deployment in good order first, because Autopilot delivers whatever state you have defined, including a messy one. **Do you manage Macs and mobile devices as well as Windows?** Yes, and the reporting question applies just as much to them, often more, because mixed estates are where visibility falls apart first. In practice the depth of what can be enforced differs by platform, so the honest position is that the management approach is consistent while the specific controls available are not identical. Worth flagging early if a framework you are being assessed against expects the same evidence for every device type, because the work to produce it is not the same on each. **Can you take this on if our Intune tenant is already a mess?** That is the usual starting point rather than an exception, and the first piece of work is a review rather than a rebuild. Most tenants are not broken, they are accumulated: overlapping assignments, settings applied twice with different values, and policies created for projects that finished years ago. Untangling which policy is actually winning on which setting is unglamorous work that usually improves the estate more than anything new we could add, and it frequently shows the estate is in better shape than feared and that the real problem was that nobody could see it. ### Remote Desktop Services (RDS) Consultancy & Support URL: https://systechitsolutions.co.uk/services/remote-desktop-services RDS design, performance troubleshooting, licensing and support for Windows Server session-based estates, plus whether moving to AVD or Windows 365 pays. Designing, fixing and running RDS estates, including the ones that should stay exactly where they are. Most advice about Remote Desktop Services now consists of telling you to stop using it. That is a convenient position for whoever is selling the replacement, and it is wrong often enough to be worth checking before you spend anything. This service is for you if: - Users complain that logons are slow or sessions freeze, and nobody has isolated why - The estate was built years ago by somebody who has left, and nobody has touched the design since - You are being told to move to the cloud and want a straight answer on whether it is worth it - You are unsure whether your RDS CALs are correct, or whether you are licensed at all The cost of doing nothing: An RDS estate that nobody owns degrades in a specific and predictable way. Profiles grow, logons stretch from seconds to minutes, one badly behaved application starts affecting everybody on the same host, and the fix gets postponed because nobody is confident what a change will break. Meanwhile the users experience it every single morning. #### The estate you have, working properly Remote Desktop Services is the session-based platform that has been publishing Windows desktops and applications since long before anyone called it virtual desktop, and it is still supported, still shipping in Windows Server, and still the right answer for a lot of organisations. We design, troubleshoot and run RDS estates: RD Session Host sizing, Connection Broker and Gateway design, profile and logon performance, application delivery, and the CAL licensing that catches people out. This is the practice the business was built on, and it is the same specialism our founder's Microsoft MVP award is in. That matters here because RDS problems are rarely the ones the error message describes: slow logons are usually storage or profiles, a session that hangs for everyone is usually one application on one host, and a Gateway that works from the office but not from home is usually certificates. Long experience of the platform is mostly experience of which symptom means what. What's included: - RD Session Host sizing against measured concurrency, not headcount - Connection Broker, Gateway and Web Access design, including high availability - Logon and profile performance work, including FSLogix - Application delivery and isolating the one application affecting everybody - RDS CAL licensing, per-user against per-device, and getting it right - Security hardening, certificates and removing RDP exposed to the internet - An honest comparison against AVD and Windows 365 when the question is open #### Is Remote Desktop Services still supported? Yes. Remote Desktop Services remains a role in current versions of Windows Server, and Microsoft continues to ship it. The confusion comes from marketing rather than lifecycle: the attention has moved to Azure Virtual Desktop and Windows 365, and it is easy to read that as RDS being retired. What does matter is the Windows Server version underneath it. An RDS estate on an unsupported Server build is a genuine problem, but that is an operating system lifecycle question rather than a verdict on session-based computing, and the answer may well be to move the roles onto a current Server version rather than to change platform entirely. So the useful question is not whether RDS has a future. It is whether your particular estate, on its particular hardware, with its particular applications, is better served by staying, upgrading in place, or moving. That is a different answer for different organisations and it deserves to be worked out rather than assumed. #### Why are logons so slow, and what actually fixes it? Almost always the profile, and almost never the thing people first suspect. A slow logon is the single most common RDS complaint and it is also the most consistently misdiagnosed, usually as the server being underpowered. FSLogix changes the shape of the problem rather than tuning it. Instead of copying a profile at logon it attaches a container holding the profile, so sign-in stops scaling with profile size. It is the single most effective change on most estates, and it is included with the licences most organisations already hold. It is not a cure for underlying storage, though. A profile container on storage that cannot serve the morning burst moves the bottleneck without removing it, which is why the first thing worth measuring is what the storage is doing at nine o'clock rather than at two in the afternoon. #### How many users should a session host support? There is no honest per-server number, and any supplier who gives you one without asking what runs on it is guessing. Density is decided by the applications and the working pattern, not by the specification sheet. A host serving a line-of-business application and Outlook behaves completely differently from one where everybody keeps thirty browser tabs open, and browsers are usually the largest single consumer of memory on a modern session host. The number that matters is concurrency at peak rather than total headcount, because the estate has to be sized for the morning, not for the average. The sizing method that works is measurement: watch what real users consume on the applications they actually run, size for the peak, and leave headroom for the loss of one host. That last part is the one most often skipped, and it is why an estate that is fine on Monday falls over when a host reboots on Tuesday. Grouping matters as much as sizing. Putting a heavy, unstable or memory-hungry application on the same hosts as everybody else means one application's bad day is everybody's bad day, and separating it is often cheaper than adding capacity. #### What do the RDS roles actually do? Worth setting out, because most estates we inherit have at least one of them doing something it should not. The Connection Broker is the one worth checking first on an inherited estate. If it is not deployed or not working, users get a new session on a different host each time they reconnect, which presents as lost work and mysteriously duplicated sessions rather than as a broker fault. The Gateway is where the security posture usually sits. An estate publishing RDP directly to the internet is exposed to constant automated attack, and putting a Gateway in front of it, with multi-factor authentication, is one of the highest-value changes available on a legacy deployment. #### How does RDS licensing work, and where do people get it wrong? You need two things and organisations routinely have only one: a Windows Server licence for the servers, and an RDS Client Access Licence for every user or device connecting to them. RDS CALs are a separate purchase, and the grace period at the start is what allows an unlicensed estate to run for a while and then abruptly stop. The choice between per-user and per-device CALs is the one that costs money. Per-device suits shift patterns where several people use the same physical machine across a day, such as a ward, a factory floor or a shop counter. Per-user suits people who connect from several devices, which now includes almost every office worker with a laptop and a phone. The common expensive mistake is buying per-device out of habit for a workforce that has since gone hybrid, and then buying more when people started working from home on their own machines. Worth knowing when comparing against the cloud: Azure Virtual Desktop and Windows 365 do not use RDS CALs, and their access rights come through Microsoft 365 or Windows Enterprise licensing you may already hold. That changes the comparison, and it is a real part of the arithmetic rather than a technicality. #### Should we move from RDS to AVD or Windows 365? Sometimes, and the timing matters more than the destination. The strongest case is when the hardware is due for replacement anyway, because then you are comparing new spend against new spend rather than against a server that is already paid for. Where the question is genuinely open we model it properly rather than asserting an answer, and the comparison guide covering that decision goes through the trade-offs in detail. #### What does an inherited RDS estate usually need first? A week of finding out what is actually there, which is unglamorous and consistently the highest-value part of the engagement. Estates built years ago and left alone accumulate: hosts that were added for a project and never removed, published applications nobody uses, Group Policy aimed at machines that no longer exist, and at least one setting somebody applied during an incident that was never reviewed. That normally produces a short list of cheap fixes and a smaller list of real decisions, which is a better starting point than a migration proposal written before anyone looked. #### Frequently asked questions **Is Remote Desktop Services being discontinued?** No. RDS remains a role in current versions of Windows Server and Microsoft continues to ship it. What has changed is where the attention goes, which is now Azure Virtual Desktop and Windows 365, and that is easy to mistake for a lifecycle announcement. The question that does matter is the Windows Server version your estate runs on, because an unsupported Server build is a real problem, but the fix for that is often moving the roles to a current version rather than changing platform. **Why are our RDS logons so slow?** Nine times out of ten it is the profile rather than the server. Roaming profiles that have grown for years get copied at every sign-in, folder redirection is missing so caches travel with them, and storage cannot serve the burst when everybody arrives at once. FSLogix usually transforms this, because it attaches a profile container instead of copying a profile, so logon stops scaling with profile size, and it is included in licensing most organisations already hold. It will not rescue storage that cannot cope with the morning peak, which is why we measure at nine rather than at two. **How many users can one session host handle?** There is no honest general number, and a supplier who gives you one without asking what runs on the host is guessing. Density is set by the applications and the working pattern: a line-of-business app and Outlook behaves nothing like a workforce keeping thirty browser tabs open, and browsers are usually the biggest memory consumer on a modern host. We size against measured concurrency at peak, with headroom for losing one host, because that is the scenario most estates have never tested. **Do we still need RDS CALs?** If users or devices are connecting to a Windows Server session host, yes, and they are a separate purchase from the Server licence itself. The choice between per-user and per-device is where money is won or lost: per-device suits shared machines on shifts, per-user suits people connecting from a laptop and a phone. The expensive and common mistake is a per-device estate bought for an office-based workforce that has since gone hybrid. Azure Virtual Desktop and Windows 365 do not use RDS CALs at all, which is a genuine part of any cost comparison. **Is it safe to publish RDP to the internet?** No, and it is one of the first things we look for on an inherited estate. RDP exposed directly to the internet is subject to constant automated attack and is a recurring route into ransomware incidents. The supported answer is RD Gateway, which tunnels the connection over HTTPS and lets you put multi-factor authentication and Conditional Access in front of it. On a legacy deployment that is usually the single highest-value security change available, and it is not an expensive one. **Can you take over an RDS estate nobody understands any more?** That is the most common way this work starts. The first piece is discovery rather than change: what hosts exist, whether the Connection Broker is actually doing its job, where profiles live, what the licensing position is, which applications sit where, and what happens when a host is lost. Estates left alone accumulate hosts added for finished projects, published applications nobody uses and settings applied during an incident years ago and never reviewed. The output is usually a short list of cheap fixes and a smaller list of real decisions. **Should we just move to the cloud instead?** Possibly, and the timing matters more than the destination. The fair moment to compare is when the hardware needs replacing anyway, because then it is new spend against new spend rather than against a server already paid for. Moving makes sense if access from anywhere is a real requirement, if demand is uneven enough that scaling down out of hours is worth money, or if you have no appetite to run Windows Server at all. It makes less sense if the estate works, the hardware has life in it, and the complaints are the fixable kind. We will tell you which of those you are. ### Business Networking: Design, Segmentation, Wi-Fi & Support URL: https://systechitsolutions.co.uk/services/networking Network design, switching and VLAN segmentation, Wi-Fi that works at density, and monitoring. Diagnosis first, so you replace what is actually wrong. Networks designed, segmented and supported properly, starting with finding out whether the network is actually the problem. "It's the network" is the most confidently offered diagnosis in any business and one of the least often correct. It is also unfalsifiable until somebody measures, which is why it survives so long and costs so much. This service is for you if: - Something is slow and every team blames a different layer of the stack - The Wi-Fi is fine in some rooms, unusable in others, and worst when the room is full - Your network grew by addition and nobody has a current diagram - You need segmentation for compliance, an insurer or a certification, and do not know where to start The cost of doing nothing: A network nobody owns fails in a way that is expensive to diagnose and easy to postpone. Nothing is broken enough to force action, so everybody works around it: the meeting that moves rooms because the Wi-Fi is better there, the report run at seven in the morning because it is quicker, the site that everyone knows is slow. None of it appears on a budget line, and all of it is paid for daily. #### Find out what is actually wrong first We design, build and support business networks: switching and VLAN segmentation, routing, wireless design, connectivity between sites, and the monitoring that tells you something has changed before a user does. Where a firewall is involved that sits alongside our managed firewall service rather than being treated as a separate world, because the boundary between the two is where most real problems live. The part we lead with is diagnosis. Networks get blamed for application problems, storage problems, cloud problems and DNS problems, and the cost of that misattribution is usually a hardware refresh that changes nothing. So the first engagement is normally measurement rather than procurement, and it frequently ends with us telling you the network is fine and the problem is somewhere else. What's included: - Network design and documentation, including a diagram that matches reality - Switching, VLANs and segmentation, designed against what actually needs separating - Wireless design for density rather than coverage, with survey work where it is warranted - Connectivity between sites and to cloud, including failover that has been tested - Monitoring and alerting, so a degrading link is found before it is reported - Firmware and lifecycle management on a planned quarterly cycle - Diagnosis of the slow thing nobody has been able to pin down #### How do you tell whether it is actually the network? By measuring the path rather than asking the users, because the symptom and the cause are usually in different places and the reports you get describe the symptom. The useful distinction early on is between bandwidth, latency and loss, which feel identical to a person and require completely different fixes. Bandwidth is how much fits; latency is how long each round trip takes; loss is what has to be sent again. An application that feels slow on a fast connection is almost always suffering from latency or loss rather than a lack of capacity, which is why upgrading the circuit so often changes nothing. That usually produces a specific answer rather than a general one, and specific answers are cheap to fix. General answers are what get solved by replacing everything. #### Why is the Wi-Fi bad in the room where everybody is? Because it was designed for coverage and the problem is density, and those are close to opposite design goals. A coverage design asks whether there is signal everywhere, and it is what you get from placing access points to fill a floor plan. It works until forty people sit in one room, because wireless is a shared medium: every device on an access point takes turns, and turning the power up to reach further makes it worse by letting more devices contend for the same airtime. A density design assumes the busy room and works backwards: more access points at lower power, careful channel planning so neighbours are not competing, and enough capacity on the band that actually carries the load. It looks like over-provisioning on a floor plan and it is the reason the all-hands meeting works. The other common cause is much duller. Access points connected to an uplink that cannot carry what they now serve, so the wireless is fine and the wire behind it is the bottleneck. It is worth checking before anybody buys more access points. #### What should actually be segmented, and why? The things that would do the most damage if they could reach each other, which in most businesses is a much shorter list than a full segmentation project implies. The trap is designing segmentation as an all-at-once project. Estates that try it in one pass usually stall halfway, and a half-segmented network with rules nobody dares change is worse than a flat one, because everybody now believes it is protected. The version that works is incremental: separate the highest-consequence thing first, prove it, document it, then take the next. It also produces evidence as it goes, which matters if this is being driven by an insurer, Cyber Essentials or a customer questionnaire, since segmentation is one of the few controls where a diagram is genuinely part of the proof. #### How often should network equipment be replaced? Driven by support status rather than by age or by how it feels, because the failure that matters is not performance, it is a device that can no longer receive firmware updates. A switch will often keep working for a decade, which is exactly the problem: nothing prompts a replacement decision, and eventually you are running a device the vendor no longer issues security fixes for, on the network everything else depends on. That is a quiet position to be in and it usually surfaces during an audit or an incident. So the useful practice is tracking what you have against its published lifecycle, and making replacement a planned budget item rather than an emergency. We handle firmware on a planned quarterly cycle rather than whenever a release appears, because network firmware is the kind of update that should not land unannounced on a Friday afternoon. Where equipment is genuinely still supported and doing its job, we will say so. A refresh cycle driven by the calendar rather than by lifecycle is a good way to spend money without reducing any risk. #### What happens when a site loses its connection? Whatever you designed for, and in most businesses nobody has designed for it, so the honest answer is that everybody goes home or sits and waits. The question worth answering is not whether you have a second line but whether the failover has ever run. Untested failover fails at the moment it is needed, usually for mundane reasons: the backup circuit was never configured to carry the traffic, the firewall rules only exist on the primary path, DNS points somewhere that is now unreachable, or nobody knows the process and it is three in the morning. It is also worth being clear about what a second circuit does not fix. Two connections from the same provider, entering the building through the same duct, are one connection with extra billing, and that is a surprisingly common arrangement. What this costs is a real decision rather than an obvious one. For some businesses an hour offline is an inconvenience and resilience is not worth paying for. For others it is the whole operation stopping, and the arithmetic is not close. We will help you work out which you are rather than assuming the expensive answer. #### Frequently asked questions **How do we know if our network is really the problem?** By measuring the path at the moment it is slow, which is the step almost always skipped. Bandwidth, latency and loss feel identical to a user and need completely different fixes, so an application that drags on a fast connection is usually suffering latency or packet loss rather than a lack of capacity. That is why upgrading the circuit so often changes nothing. We look at uplink utilisation at the time of the complaint rather than the daily average, port errors and discards, DNS resolution times, and what else is running then, because backups in office hours explain a great deal. **Why is our Wi-Fi worst when a room is full?** Because it was designed for coverage and your problem is density, and those pull in opposite directions. Wireless is a shared medium, so every device on an access point takes turns, and turning the power up makes it worse by letting more devices contend for the same airtime. A density design uses more access points at lower power with careful channel planning, which looks like over-provisioning on a plan and is why the all-hands meeting works. Worth checking the boring cause first though: access points on an uplink too small for what they now serve. **Do we need to segment our network?** Almost certainly in a few specific places, and almost certainly not everywhere at once. The separations worth doing nearly everywhere are guest wireless, building systems like cameras and door entry, anything handling payments, servers away from user devices, and any equipment running a Windows version that cannot be patched. The trap is treating it as one big project: estates that attempt it in a single pass tend to stall halfway, and a half-segmented network with rules nobody dares touch is worse than a flat one because everyone now believes it is protected. **How often should switches and network kit be replaced?** When they stop receiving firmware updates, rather than at a set age. Network equipment often keeps working for a decade, which is the problem, because nothing prompts a decision and eventually the thing everything depends on cannot be patched. We track what you have against its published lifecycle so replacement is a planned budget item instead of an emergency, and we will tell you when kit is still supported and doing its job, because a refresh driven by the calendar spends money without reducing risk. **Do you supply the hardware as well?** Yes, and we would rather sell you less of it. Where the answer genuinely is new equipment we will specify, supply, configure and support it, and physical installation work such as cabling is scoped per project. But if you want a named list of hardware supplied at the lowest price, a reseller will beat us on that and should. We earn our fee on working out what you actually need, which regularly turns out to be less than was expected. **Can you find out why one site is slow?** That is one of the most common reasons people call us, and it is usually solvable. The pattern with a single slow site is that everybody has a theory and nobody has a measurement, so the problem survives for years and gets worked around instead of fixed. We instrument the path, look at what is happening at the times people complain rather than on average, and come back with a specific cause. Sometimes the answer is that the circuit really is at its limit, and sometimes it is a failing cable, a duplex mismatch or a backup job running at ten in the morning. ### Microsoft 365 Licensing Review: Do You Actually Need E3 or E5? URL: https://systechitsolutions.co.uk/services/microsoft-365-licensing-review Are you on the right Microsoft 365 tier? A licensing review mapping users to what they actually use, covering Business Premium, Windows 365 Business, E3 and E5. A mapped, measured answer on which tier you should be on and what you are already paying for and not using. Almost every Microsoft 365 estate is paying for capability it has never switched on. Not through carelessness, but because nobody has ever sat down and compared what the licence includes against what the business actually does. This service is for you if: - You are under 300 users and have been quoted for E3 or E5 - Your renewal is coming and you want the numbers before the conversation, not after - You are buying security products separately and suspect you may already own some of them - Nobody can say which of your licences are assigned to people who left The cost of doing nothing: Licensing waste does not announce itself. It is a slightly larger invoice each year, a security product bought separately that was already included, a tier upgrade taken on advice nobody re-examined, and licences still assigned to people who left. None of it is visible from the invoice, which shows what you bought rather than what anyone uses. #### Get more from what you already own This is a review of your Microsoft 365 position: what you are licensed for, what is assigned, what is genuinely being used, and what tier each group of users should actually be on. It exists because the licensing decision is usually made once, under time pressure, on advice from somebody selling the licences, and then never revisited while the business changes around it. There are two halves. The first is right-sizing: are you on the correct tier, are you paying for seats nobody uses, and would a different mix cost less. The second is the half most reviews skip, which is activation: what does your existing licence already include that you have never switched on. That second half regularly turns out to be worth more than the first, because it removes a product you are buying separately rather than shaving a percentage off a renewal. What's included: - User mapping: who does what, and which group each person genuinely belongs to - Assigned against active, so licences held by leavers surface - Tier comparison across Business Premium, Windows 365 Business, E3 and E5 - What your current licence already includes that is switched off - A costed comparison of the realistic options, with the mix rather than one tier for all - Renewal timing and what to do before the conversation rather than during it - A written recommendation you keep, whether or not you engage us afterwards #### Why does the 300-user line matter so much? Because Microsoft 365 Business Premium is capped at 300 seats, and under that cap it is unusually good value for what it bundles. Above it, the comparison starts somewhere else entirely. Business Premium brings together the Office applications, Exchange, SharePoint and Teams, plus the parts organisations most often buy separately: Entra ID Plan 1 for Conditional Access, Intune for device management, Defender for Business for endpoint protection, and Defender for Office 365 Plan 1 for email. The consequence catches people out. A business under 300 users being quoted E3 is frequently being moved to a tier that costs more and, historically, arrived with less security included, because endpoint protection and email protection were add-ons rather than part of it. That is exactly the kind of claim worth checking rather than trusting, including when we make it, and the next section explains why. #### Why is most licensing advice online out of date? Because Microsoft changes what is in the boxes, and comparison articles are written once and left. A concrete and recent example: on 1 July 2026 Defender for Office 365 Plan 1 was added to Office 365 E3. A large amount of the comparison content still circulating was written before that and states the previous position confidently. Anyone making a decision from it today is working from a comparison that is no longer true. This is not a criticism of those articles so much as a description of the category. Licensing is not a fixed landscape you can learn once: tiers gain and lose components, add-ons get absorbed, names change, and the price changes independently of all of it. So treat any comparison table, including the one further down this page, as a starting point that needs verifying against current Microsoft licensing on the day you decide. It is also the honest reason a licensing review is worth repeating rather than doing once: the correct answer genuinely changes, and a decision that was right three years ago may not be now. #### What are you already paying for and not using? This is the half of the review that usually pays for the whole exercise, and it is skipped by most licensing conversations because it does not lead to a sale. Not all of those should be switched on, and we will say so where the answer is that the third-party product you have is better for you than the bundled one. Plenty of them are genuinely better. But the decision should be made knowingly, and in most estates it never was: the product was bought because a gap existed, and nobody went back to check whether the gap had since been filled by a licence change. #### Where does Windows 365 Business fit? For organisations under 300 users who need a Windows desktop delivered from the cloud without building the infrastructure to host it. Windows 365 Business is the simpler end of Cloud PC: a fixed monthly price per user for a personal, always-on Windows desktop, sized when you buy it, with no host pools to design and no Azure consumption to forecast. That predictability is the point of it and it is genuinely well suited to smaller organisations. It tends to be the wrong answer where usage is uneven enough that being able to scale down out of hours would save real money, or where you need shared session hosts and fine-grained control. That is where Azure Virtual Desktop earns its complexity, and the comparison guide works through that decision properly. #### How do you actually decide between tiers? By licensing groups of people rather than the organisation, which is the single change that most reliably reduces cost without reducing capability. The instinct is to pick one tier for everybody because it is simpler to administer. That produces both problems at once: people over-licensed for what they do, and specific individuals under-protected because the tier chosen for the average does not suit the ones handling the most sensitive work. Once people are mapped that way the tier question usually answers itself, and the answer is normally a mix. It is also the mapping that makes an add-on decision rational: buying an E5 component for the twelve people who need it is a completely different proposition from moving two hundred people to E5. #### What does the review actually produce? A document you can act on without us, which is deliberate. We do not need to be the ones who implement it. If the recommendation is that you stay where you are and switch three things on, that is a perfectly good outcome and it is one we reach reasonably often. The one thing worth saying plainly: we are a Microsoft partner and we sell licences, so ask us what we would recommend if you bought them elsewhere. The answer should be the same, and if a supplier's advice changes depending on who supplies the licences, that tells you what the advice was. #### Frequently asked questions **We have fewer than 300 users. Do we need E3?** Usually not, and it is worth making anyone recommending it explain why. Microsoft 365 Business Premium is capped at 300 seats and under that cap bundles a great deal: the Office applications, Entra ID Plan 1 for Conditional Access, Intune, Defender for Business and Defender for Office 365 Plan 1. A smaller business moved to E3 has historically ended up paying more for a tier that needed add-ons to match that security position. The genuine reasons to be on E3 under 300 users exist, most often Windows Enterprise or a specific capability, but they should be named rather than assumed. **How much of Microsoft 365 do most organisations actually use?** We are not going to give you a percentage, because the figures in circulation are not sourced well enough to repeat. What we can tell you is what is true in your tenant, which is more useful anyway: which licences are assigned against which are active, and which included capabilities have never been switched on. That is measurable rather than estimated, and an industry average would tell you nothing about your own position even if it were reliable. **Should we move to E5?** For some of your people, possibly. For all of them, rarely. E5 adds advanced identity protection, threat protection and compliance capability that genuinely matters for administrators, executives and anyone handling regulated material, and is usually more than a general office user needs. The mistake is treating it as an organisation-wide upgrade rather than as protection bought for the roles that warrant it. Mapping users to groups first almost always produces a cheaper and better-protected answer than picking a single tier for everybody. **Why is licensing advice we find online so often wrong?** Because what is in each licence changes and articles do not. A concrete example: on 1 July 2026 Defender for Office 365 Plan 1 was added to Office 365 E3, which invalidated a large amount of comparison content still circulating. Treat any comparison table as a starting point that needs verifying against current Microsoft licensing on the day you decide, including ours. It is also the honest reason to revisit licensing periodically rather than deciding once, because the correct answer genuinely moves. **Can we reduce licences mid-term?** It depends entirely on the agreement you signed, and this is where the money usually is at renewal rather than during a term. Annual commitments generally hold you to the seat count for the term, monthly arrangements are more flexible and cost more per seat for that flexibility. The practical approach is to establish the true picture now, decide what the right position is, and time the change to the renewal. We will tell you when the honest answer is that nothing can usefully change for another eight months. **You sell licences. How is your advice impartial?** It is a fair question and the right one to ask any partner. The test we would suggest is to ask what we would recommend if you bought the licences somewhere else entirely, because the answer should be identical. The written recommendation is yours to keep and act on without us, and it regularly says that the answer is to stay on your current tier and switch things on rather than to buy anything. If a supplier's advice shifts depending on who supplies the licences, you have learned what the advice was worth. ## Glossary ### IT, Microsoft & Cloud Glossary URL: https://systechitsolutions.co.uk/glossary Plain-English definitions of the Microsoft, cloud and security terms we work with, from MSIX, App-V and RAG to EDR, XDR, Conditional Access and Windows 365. **AiTM (Adversary-in-the-Middle)**: A phishing technique that sidesteps multi-factor authentication by proxying the login and stealing the resulting session token, so the attacker inherits an already-authenticated session. Defended with phishing-resistant MFA, device-bound Conditional Access and token protection. **App Attach**: A Windows feature that streams MSIX-packaged applications into Azure Virtual Desktop or Windows 365 sessions on demand, instead of baking them into every image, giving a lighter, faster-to-update base image. **App-V (Application Virtualization)**: A Microsoft technology that virtualises applications into isolated packages so they run without being fully installed on the OS. Microsoft is retiring App-V in favour of MSIX, and Systech migrates App-V estates to MSIX. **Application Modernisation**: Moving the applications a business relies on onto modern, supported platforms, incrementally rather than via a risky big-bang rewrite, often replatforming onto Azure and the Microsoft stack. **Azure**: Microsoft's public cloud platform for hosting virtual machines, storage, databases, networking and more. Systech helps businesses migrate to, optimise and control the cost of their Azure estate. **Azure Virtual Desktop (AVD)**: Microsoft's cloud virtual desktop (VDI) service, delivering a full Windows desktop from Azure to any device. AVD supports multi-session and is flexible and cost-effective at scale. **Backup (3-2-1 & immutable)**: Keeping recoverable copies of servers, endpoints and Microsoft 365 data. Good backup is monitored and regularly restore-tested, and keeps immutable, ransomware-resilient copies that an attacker cannot alter or delete. **BEC (Business Email Compromise)**: A targeted attack where a criminal impersonates a trusted person, often an executive or supplier, to trick staff into transferring money or data. Impersonation protection and email security defend against it. **CI/CD (Continuous Integration / Delivery)**: An automated pipeline that builds, tests and deploys software, or application packages, repeatably, replacing slow, manual, person-dependent work. Systech builds CI/CD packaging workflows for customers. **Compliance Policy (Intune)**: An Intune rule set defining what a 'healthy' device looks like (encryption, OS version, security settings). Paired with Conditional Access, it ensures only compliant, managed devices can reach company data. **Conditional Access**: Microsoft Entra policies that control who can access Microsoft 365 and under what conditions, for example requiring MFA, a compliant device or a trusted location. The backbone of a strong identity security posture. **Copilot (Microsoft 365 Copilot)**: Microsoft's AI assistant embedded across Microsoft 365 apps. Copilot inherits each user's existing access, so a readiness assessment of data and permissions is essential before switching it on. **Cyber Essentials**: A UK government-backed certification covering five basic security controls. A self-assessed scheme increasingly required for public-sector and supply-chain contracts and cyber insurance. **Cyber Essentials Plus**: The independently audited version of Cyber Essentials, where an assessor verifies the controls through hands-on technical testing rather than self-assessment. **Disaster Recovery (DR)**: The plan and tooling for restoring systems and data quickly after a major incident such as ransomware, hardware failure or human error. Only as good as the last tested restore. **DMARC, SPF & DKIM**: Email authentication records that prove a message genuinely came from your domain, making it far harder for attackers to spoof you. A core part of defending against phishing and BEC. **EDR (Endpoint Detection and Response)**: Security technology that continuously monitors devices (endpoints) for threats and enables rapid investigation and response, going well beyond traditional antivirus. **Email Archiving**: Keeping a complete, searchable, tamper-proof record of every message independent of the mailbox, for compliance, legal hold and reconstructing what happened after an incident. **Extended Security Updates (ESU)**: Paid security patches Microsoft offers for an operating system after free support ends, buying time to migrate. In use for Windows 10 following its October 2025 end of life. **Intune (Microsoft Intune)**: Microsoft's cloud device management (MDM) service. Intune enrols, secures, patches, reports on and, if needed, wipes company and personal devices, and enforces compliance through Conditional Access. **ISO/IEC 42001 (AI Management System)**: The first international standard for governing artificial intelligence, published in December 2023 and certifiable. It follows the same shape as ISO 27001, with management system clauses 4 to 10 and 38 Annex A controls under nine objectives, of which you implement the ones your risk assessment calls for rather than all of them. It certifies that your organisation governs AI competently, not that any particular AI system is safe, and it does not by itself make you compliant with the EU AI Act. **ISO 27001**: The international standard for information security management systems (ISMS). Certification demonstrates a structured, audited approach to managing information security risk. **Legacy Modernisation & OS Migration**: Moving off end-of-life operating systems and applications onto modern, supported platforms, including capturing legacy apps that have no install media and repackaging them for a current OS. **LLM (Large Language Model)**: A general-purpose AI model trained on vast amounts of text, able to understand and generate language. LLMs power tools like Copilot and custom AI applications. **Managed Firewall**: A firewall service that is continuously monitored, backed up, patched and reported on, rather than installed once and forgotten. Systech's runs on an in-house built platform. **Managed IT Services**: Outsourced day-to-day IT: 24/7 monitoring, a service desk, patching, backup oversight and device management for a predictable monthly fee, rather than reactive break-fix support. **MSP (Managed Service Provider)**: A company that takes ongoing, contracted responsibility for running some or all of your IT estate for a recurring fee, rather than charging per incident. The defining test is that an MSP is responsible for keeping things in an agreed state, not only for responding when they are not. The term carries no certification of its own, so ISO 27001, Cyber Essentials and vendor partner status are the signals worth checking. Outside IT, MSP also means Member of the Scottish Parliament and, in retail, minimum selling price. **MSSP (Managed Security Service Provider)**: A provider specialising in threat detection and response, typically running a security operations centre with analysts monitoring telemetry continuously, threat hunting and contracted incident response. Distinct from an MSP, which covers IT operations broadly including preventive security controls. Most small and mid-sized businesses are better served by an MSP delivering managed EDR/XDR than by a separate MSSP contract, until a regulatory obligation or threat profile justifies one. **CSP (Cloud Solution Provider)**: Microsoft's partner programme for reselling and supporting Microsoft 365 and Azure subscriptions. A CSP partner bills you directly rather than Microsoft doing so, can adjust licence counts, and provides first-line support for the subscriptions themselves. It describes a licensing and billing relationship, not a scope of managed work, so Microsoft CSP status says nothing on its own about who answers when a server stops responding. **Outsourced IT**: Handing IT work to an external company rather than employing the people who do it. Managed services are a form of outsourcing, but not all outsourcing is a managed service: traditional outsourcing buys capacity that works to your direction and processes, usually billed against time or headcount, while a managed service buys an outcome and the provider brings its own tooling and process. The practical test is who decides how the work gets done. **Break-fix**: Paying for IT help only when something has already gone wrong, with no ongoing contract or coverage in between. It looks like the cheapest model because there is no monthly baseline, but nothing is monitored, patched or protected between incidents, so cost moves out of a predictable line item and into downtime, data-loss risk and premium emergency call-out pricing. Generally the most expensive model in practice for any business with real dependencies on its systems. **Co-managed IT**: An arrangement where internal IT staff and an external provider divide responsibility for one estate deliberately. Typically the internal side keeps user-facing support, business priorities, vendor relationships and project ownership, while the provider takes monitoring, patching, security tooling, out-of-hours cover and occasional specialist work. Common in businesses at the upper end of the 15-250 seat range. The failure mode is both sides assuming the other is watching something, which a written responsibility matrix prevents. **RMM (Remote Monitoring and Management)**: The tooling an MSP uses to see and act on a customer estate remotely: an agent on each managed device reporting health, patch status and alerts, with the ability to deploy software and run remediation without attending site. It is the mechanism that makes proactive management possible at all, and it is provider-owned, which is one reason exit terms and documentation ownership are worth settling before signing a managed contract. **SLA (Service Level Agreement)**: The part of a support contract that states what the provider is actually committed to: coverage hours, how quickly different severities of issue will be responded to, and what happens if those commitments are missed. Worth reading closely for the difference between a response target and a resolution target, and for what 24/7 means in practice, since it can describe a UK engineer starting work or an answering service raising a ticket for the morning. **MFA (Multi-Factor Authentication)**: Requiring more than a password to sign in, typically a code or approval on a second device. Essential, but on its own it does not stop token-theft attacks, which is why Conditional Access and phishing-resistant methods matter. **Microsoft 365**: Microsoft's cloud productivity and security suite (Exchange, Teams, SharePoint, OneDrive, identity, Intune and more). Systech deploys, governs, secures and supports the whole platform. **Microsoft 365 Business Premium**: The Microsoft 365 plan that bundles the productivity apps with the security stack (Defender, Intune, Conditional Access), best value for most SMBs up to 300 users. **MSIX**: Microsoft's modern, native Windows application packaging format, the supported successor to App-V. MSIX uses built-in container isolation and integrates with Intune and App Attach. **Oversharing (data governance)**: The gradual build-up of over-permissive sharing links, stale guest access and unlabelled sensitive files in Microsoft 365. Long a risk, and an urgent one once Copilot can surface anything a user can access. **PIM (Privileged Identity Management)**: A Microsoft Entra feature that grants administrative access just-in-time and for a limited time, minimising standing privileged access and reducing the impact of a compromised admin account. **Phishing**: Fraudulent messages designed to trick people into revealing credentials or approving access. Still the number one route in for attackers, countered with email security, MFA and user awareness. **RAG (Retrieval-Augmented Generation)**: An AI technique that grounds a language model's answers in your own documents and data, retrieved at query time, so responses are accurate, current and traceable to a source rather than invented. **Reserved Instances & Savings Plans**: Azure commitment-based discounts that cut the cost of predictable workloads in exchange for a one- or three-year term. A core lever in Azure cost optimisation. **Right-sizing**: Matching cloud resources (VM sizes, storage tiers, licences) to real utilisation, cutting waste without starving workloads of the capacity they genuinely need. **Secure Score**: A Microsoft measurement of an organisation's security posture across identity, data, devices and apps, with recommended actions. A number to act on, not just to report. **Shelfware**: Licences a business pays for but doesn't use, such as unassigned or over-specified Microsoft 365 seats. Auditing and right-sizing them is one of the fastest cost wins in IT. **SharePoint, Teams & OneDrive**: The three core Microsoft 365 collaboration apps. Getting the file structure and permissions right early avoids years of untangling, and is foundational to security and Copilot readiness. **SLM (Small Language Model)**: A smaller, more focused AI model that can be cheaper, faster, more private and hostable on infrastructure you control. For many specific business tasks an SLM outperforms a general-purpose API on cost and latency. **Token Theft**: Stealing an authenticated session token (often via an AiTM phishing kit) to access an account without needing the password or MFA. Mitigated with token protection and device-bound Conditional Access. **VDI (Virtual Desktop Infrastructure)**: Technology that hosts desktops centrally (in a datacentre or the cloud) and delivers them to users on any device, keeping data off the endpoint. Windows 365 and Azure Virtual Desktop are Microsoft's VDI options. **White-Label IT Delivery**: Enterprise-grade technical delivery and advisory provided under another company's brand, letting vendors and MSPs take on contracts that need skills they don't have in-house. **Windows 10 End of Life**: Free support for Windows 10 ended in October 2025. Devices still on it are unpatched unless covered by Extended Security Updates, making migration to Windows 11 a priority. **Windows 365**: Microsoft's Cloud PC service, giving each user a dedicated Windows desktop in the cloud at a fixed per-user price, reachable from any device, with IT keeping control of the data. **Windows Update for Business**: The Microsoft service, managed through Intune, for controlling how and when Windows quality and feature updates are deployed to devices, using deployment rings and schedules. **XDR (Extended Detection and Response)**: Security technology that correlates signals across endpoints, identity, email and cloud so an attack touching several of them is seen as one incident rather than separate, unrelated alerts. **Autopilot (Windows Autopilot)**: A Microsoft service that configures a new device into your standard build from its out-of-box state, so a replacement machine can be shipped straight to a person rather than imaged by hand first. It delivers whatever configuration you have defined, which means it is only as good as the state of your Intune configuration underneath it. **BYOD (Bring Your Own Device)**: Staff using personally owned phones or laptops for work. It is usually cheaper and almost always harder to evidence, because personal devices accessing organisational data are in scope for frameworks like Cyber Essentials whether or not anyone counted them. **Call-Off Contract (day packs)**: A block of days bought up front and drawn down as needed, rather than quoting each piece of work separately. Common in public sector procurement and increasingly used privately, mainly because it removes the purchase order that otherwise sits in front of every small job. **Co-management**: Running Microsoft Intune and Configuration Manager against the same Windows devices at once, with individual workloads moved from one to the other a piece at a time. It is the supported route away from an on-premises estate, and it is reversible, which is why it is safer than a cutover. **Configuration Manager (SCCM/MECM)**: Microsoft's long-standing on-premises management product for Windows devices and servers, now called Microsoft Configuration Manager. Still stronger than Intune at complex application deployment, task-sequence operating system builds and bandwidth-constrained networks, which is why plenty of estates keep it deliberately. **Copilot Agent**: A configured Copilot with its own instructions and a defined set of sources, published for other people to use. The governance question changes at the point of publishing, because an agent answers from whatever it has been pointed at, to whoever can reach it. **Credential Stuffing**: Automated login attempts using username and password pairs stolen from some other breach, on the assumption that people reuse passwords. It is why a password that has never leaked from your systems can still be the one that lets somebody in. **DSP Toolkit (Data Security and Protection Toolkit)**: The NHS self-assessment that organisations handling health and care data complete annually to evidence their data security position. Required of suppliers as well as providers, which catches out businesses who did not think of themselves as being in healthcare. **Egress Charges**: What a cloud provider bills for moving data out of its platform. Frequently missed in cloud cost modelling, and worth understanding before a migration rather than after, because it is one of the few costs that grows when you decide to leave. **EU AI Act**: The EU's regulation on artificial intelligence, which classifies systems by risk and attaches obligations accordingly. It applies to UK businesses selling into the EU or serving EU users, and it phases in over several years, so what is currently in force matters more than the headline dates: the transparency duties and the high-risk obligations have different timelines. Unlike ISO 42001 it is law rather than a voluntary standard, and certification to a standard does not confer conformity with it. **Entra ID (formerly Azure AD)**: Microsoft's cloud identity service, and the thing that actually decides who can reach what across Microsoft 365 and Azure. Renamed from Azure Active Directory in 2023, which is why documentation and job adverts still use both names for the same product. **FinOps**: The practice of managing cloud spend as an ongoing discipline rather than an annual clean-up, by attributing costs to the teams and projects that create them so the people making the decisions can see what they cost. **Gap Analysis**: Comparing what a framework requires against what you actually do, and listing the difference. The useful version produces a ranked list of what would fail today; the less useful version restates the framework back at you. **Grounding**: Constraining an AI model to answer from specific source material rather than from what it absorbed in training. It is the mechanism that makes an answer traceable, and its absence is why an ungrounded model produces confident, plausible, unverifiable text. **Hallucination**: An AI model stating something false with the same fluency it states something true. Not a bug to be patched out, but a property of how these systems generate text, which is why production systems need retrieval, citations and an explicit route to saying they do not know. **IaaS, PaaS & SaaS**: The three cloud service models, distinguished by how much you still run yourself. Infrastructure as a Service gives you virtual machines and leaves the operating system to you; Platform as a Service runs the platform and leaves you the application; Software as a Service is the finished product. The practical consequence is where your responsibility for patching and backup stops. **Immutable Backup**: A backup that cannot be altered or deleted for a set period, including by an administrator. It is the control that separates a backup which survives ransomware from one an attacker encrypts alongside everything else, and insurers increasingly ask about it by name. **Internal Audit**: Checking your own controls against a framework before somebody external does. The point is not the report, it is finding the things that would fail while there is still time and no deadline attached to fixing them. **Landing Zone**: A pre-built Azure environment with the identity, network, policy and cost controls already in place, so workloads arrive into a governed structure rather than into an empty subscription. Cheaper to build first than to retrofit once several teams are already running things. **Least Privilege**: Giving an account only the access it needs to do its job, and only for as long as it needs it. Simple to state and awkward to maintain, because access accumulates quietly through role changes and nobody is ever thanked for removing some. **Managed Detection and Response (MDR)**: An outsourced service where people monitor your security alerts around the clock and act on the ones that matter. The distinction from buying an EDR product is that somebody is watching it, which is the part most businesses cannot staff themselves. **Password Manager**: Software that generates and stores unique credentials so people are not reusing one password everywhere. The security question worth asking is not whether to use one, it is where the encrypted vault lives, since a shared public vault service is a concentrated target in a way a vault inside your own tenant is not. **Patch Management**: Getting security updates onto devices and servers within a defined window, and being able to show that it happened. Cyber Essentials requires critical and high-severity updates inside fourteen days, and the part most estates struggle with is the evidence rather than the patching. **Penetration Testing**: A controlled attempt to break into your systems, carried out by people whose job is to find what an attacker would find. Distinct from a vulnerability scan, which lists known weaknesses without establishing whether they can actually be chained into anything. **Phishing-Resistant MFA**: Multi-factor methods that cannot be relayed by an attacker sitting in the middle, such as passkeys, FIDO2 security keys or certificate-based authentication. Codes and push approvals are multi-factor but not phishing-resistant, which is the gap adversary-in-the-middle attacks exploit. **Prompt Injection**: Text hidden in content an AI system reads, written to make it ignore its instructions or reveal what it should not. It matters most where a system reads material other people can write, because the attack arrives as data rather than as a user request. **Shadow AI**: Staff using AI tools the business has not approved, usually because the approved route is slower or does not exist. The risk is not the tools themselves, it is company information being pasted into services nobody has assessed. **SIEM (Security Information and Event Management)**: A system that collects logs from across an estate and correlates them, so an attack visible only as a pattern across several systems can be spotted. Valuable in proportion to whether anyone is actually reading what it produces. **SOC (Security Operations Centre)**: The team that monitors and responds to security alerts, in-house or bought as a service. The question worth asking of any provider is what happens at 3am and what they are authorised to do without waking you. **SoA (Statement of Applicability)**: The ISO 27001 document listing which controls apply to you, which do not, and why. It comes early and shapes everything after it, so it is worth scoping properly rather than treating as paperwork to be completed later. **TCO (Total Cost of Ownership)**: The full cost of running something over its life, rather than the price of buying it. In IT the gap between the two is usually licensing, the people who administer it, and the work needed when the platform underneath changes. **Update Rings**: Groups of devices that receive Windows updates on a staggered schedule, so a problematic update is found on a small pilot group before it reaches everybody. Only works if the pilot group is genuinely representative rather than whoever volunteered. **Zero Trust**: A security model that stops treating the corporate network as a trusted place and verifies every request on its own merits: who is asking, from what device, in what state. Sold as a product by many vendors and actually an architectural principle, delivered mostly through identity and device controls you already own. ## Free resources ### Free IT & Microsoft 365 Checklists URL: https://systechitsolutions.co.uk/resources Free, practical assessments and checklists covering Copilot readiness, Microsoft 365 security and cost, Intune, managed firewall and Cyber Essentials. ### The Copilot Readiness Assessment URL: https://systechitsolutions.co.uk/resources/copilot-readiness-assessment A practical self-assessment across data, security and adoption readiness, so you know if you are ready for Microsoft 365 Copilot before you switch it on. Switch Copilot on before your permissions and data are ready, and it will happily surface files nobody should see. Readiness isn't optional, it's the whole project. This is for you if: - You're considering or piloting Microsoft 365 Copilot licences - Nobody has audited SharePoint or OneDrive permissions and oversharing in the last year - You want a straight answer on whether you're ready, not a sales pitch Copilot surfaces whatever a user can already access, so any existing oversharing, stale permissions or unlabelled sensitive data becomes instantly and disastrously more visible the day you switch it on. Most businesses find this out after rollout, not before. What's inside: - A scored readiness check across data hygiene, security and licensing, and adoption - The permission and oversharing checks to run before anyone gets a licence - A realistic view of what 'ready' actually looks like, not a vendor checklist - Clear next steps for whatever your score turns out to be #### Frequently asked questions **Will Copilot let staff see files they should not have access to?** No. Copilot cannot grant access to anything a user could not already open. What it does is make existing over-permissioning obvious, because it reads across everything the user can reach and summarises it on demand. If your sharing links, Teams membership and site permissions have drifted over the years, Copilot will surface the consequences quickly. That is why a permissions and oversharing review belongs before deployment rather than after. **Is our data used to train Microsoft's models?** Microsoft's commercial data protection terms state that Microsoft 365 Copilot does not use your tenant data to train the underlying foundation models, and that prompts and responses stay within your tenant's compliance boundary. Check the current Microsoft licensing terms for your own agreement, since the detail differs between commercial, education and government tenants, and confirm which Copilot experiences your users can reach, as consumer-facing tools carry different terms. **How long does a readiness assessment take?** It depends on the size and tidiness of the tenant rather than on headcount, so it is scoped once we have looked at your environment. What is consistent is the shape: understand the permissions and sharing position, review data lifecycle and labelling, confirm licensing, then agree a pilot group and what you will measure. The checklist on this page covers the same ground and is free to work through yourself. **Can we roll Copilot out to one department first?** Yes, and you should. Copilot licences are assigned per user, so you can start with a defined group and expand later. The mistake is choosing that group by department politics rather than by workload: a pilot spread across a few genuinely different roles tells you far more about where the value sits than the same number of licences concentrated in one team. **What if we are not ready?** That is a useful outcome, not a failed assessment. Most tenants are not ready on first look, and the gap is normally permissions drift rather than anything exotic. Knowing that before you buy several hundred per-user add-on licences is precisely the point, and the remediation work has value whether or not you go ahead with Copilot. **Does Copilot work with our on-premises file shares?** Not directly. Microsoft 365 Copilot draws on content in Microsoft Graph, which means SharePoint, OneDrive, Teams, Exchange and the other Microsoft 365 workloads. Files sitting on a traditional on-premises file server are invisible to it. If a significant share of your working documents still live on-premises, that changes both the value case and the migration conversation, and it is worth establishing early. ### The Microsoft 365 Security Posture Assessment URL: https://systechitsolutions.co.uk/resources/microsoft-365-security-posture A scored self-assessment across identity, data, device and threat protection, so you know exactly how exposed your Microsoft 365 tenant really is. Most breaches don't start with a sophisticated attack. They start with an unused MFA setting, a forgotten guest account, or a Conditional Access policy nobody finished configuring. This is for you if: - You run Microsoft 365 but have never had a formal security review of the tenant - You're not confident your Secure Score, MFA coverage or Conditional Access setup actually holds up - You need a straight answer on your real exposure, not a generic best-practice list Microsoft 365 ships secure defaults, but almost nobody runs them by default: MFA gaps, stale guest access, unmonitored admin roles and unlabelled sensitive data build up quietly until an incident forces the audit. It's cheaper to find these gaps yourself, on your own schedule. What's inside: - A scored posture check across identity, data protection, device management and threat protection - The specific settings and policies that separate a real posture from a paper one - A clear low/medium/high read on where you actually stand today - Priority order for what to fix first, based on real risk, not a generic checklist ### The Microsoft 365 Cost Optimisation Checklist URL: https://systechitsolutions.co.uk/resources/microsoft-365-cost-checklist The exact checklist our team runs against every Microsoft 365 and Azure estate to find wasted spend, oversized licences and forgotten resources. Most Microsoft 365 and Azure estates are quietly overpaying, not through one big mistake, but a year of unassigned licences and forgotten resources nobody got round to switching off. This is for you if: - You own or influence the Microsoft 365 / Azure bill and it's crept up without a clear reason why - Nobody has sat down and audited licence assignment or resource usage in the last 12 months - You suspect there's shelfware or idle infrastructure, but proving it feels like a project in itself Unused E5 seats, orphaned disks, oversized VMs: none of it shows up as a single alarming line item, it just erodes margin month after month until a renewal forces the conversation. The audit is the easy part; most businesses just haven't done it. What's inside: - A full licence audit process: cross-referencing seats against headcount and actual usage - Azure resource hygiene checks: unattached disks, idle VMs, forgotten test environments - Right-sizing compute and storage tier reviews against real utilisation - A reporting and ownership structure so savings don't quietly disappear again next year ### The Intune Device Management Checklist URL: https://systechitsolutions.co.uk/resources/intune-device-management-checklist Take real control of your device estate with Microsoft Intune: enrolment, compliance policy, app deployment and conditional access, done properly. Every device you can't see, patch or wipe remotely is a device you don't actually control, and most estates have more of those than anyone realises. This is for you if: - Devices are enrolled inconsistently, or half your estate isn't managed at all - You want devices centrally policed, patched and wiped without chasing every user individually - You're evaluating or already licensed for Intune but haven't configured it properly An unmanaged laptop is a laptop that can be lost, stolen, or compromised with no way to enforce encryption, wipe it remotely, or even prove what state it was in. Ad hoc device management isn't a smaller version of this problem, it's the same problem with worse visibility. What's inside: - The enrolment methods to use for company-owned versus personal devices - The compliance policies and conditional access rules that actually enforce standards - App deployment and patch management set up so nothing depends on the user - The retire/wipe process that keeps leavers and lost devices from becoming incidents ### The Legacy Migration Roadmap URL: https://systechitsolutions.co.uk/resources/legacy-migration-roadmap The assess, capture and migrate process for moving legacy servers and unsupported line-of-business apps onto modern, supported operating systems. The real blocker to leaving Windows Server 2012 or Windows 10 behind usually isn't the OS, it's the one legacy application nobody's touched in years that only runs on it. This is for you if: - You're still running end-of-life or soon-to-be-unsupported Windows Server or desktop OS versions - A legacy line-of-business application is the reason migration keeps getting pushed back - You need the old app captured and made to work on modern infrastructure, not just replaced and hoped for the best Unsupported servers and applications don't fail gracefully, they fail during an audit, a compliance review, or a hardware death with no vendor left to call for support. The application is usually the real blocker, not the OS, and most migration plans stall the moment they hit it. What's inside: - The 3-stage assess, capture and migrate process we run on every legacy estate - How legacy applications get captured and repackaged for modern operating systems using EtherApps Forge, our application capture and migration tooling - What to check before retiring a legacy server, not just after - A realistic view of what can move as-is versus what needs repackaging first ### Managed Firewall: What's Actually Included URL: https://systechitsolutions.co.uk/resources/managed-firewall-service What a properly managed firewall covers end to end: deployment, maintenance, support, backup, change control and 24/7 monitoring. See what DIY misses. A firewall you configured once and haven't looked at since isn't protecting you the way you think it is. It's ageing, drifting out of policy, and one missed patch away from being the incident. This is for you if: - Your firewall was configured once, by someone who may not even work there anymore - Nobody could tell you the last time firmware or rules were reviewed - You want protection that's actually monitored, not just installed DIY firewall management looks cheaper right up until a missed patch, an undetected rule change, or configuration drift turns into a network-down incident, at which point the savings evaporate in downtime and emergency support. Most businesses only discover the gap when something has already gone wrong. What's inside: - What proper deployment and hardening looks like versus a default install - The ongoing maintenance, patching and change control that keeps it actually secure - What 24/7 monitoring and support really covers, and how fast issues get caught - How backup and recovery are handled so a failure isn't a rebuild from scratch ### The Compliance Pack Starter Kit URL: https://systechitsolutions.co.uk/resources/compliance-pack-starter-kit Every document a real compliance pack needs, policies, procedures, SOPs and registers, plus where the evidence lives. Map your gaps before you buy a template. Off-the-shelf template packs give you thirty documents and no idea which ones you actually need, or where the evidence behind them is meant to come from. This is the map first. This is for you if: - You need a compliance pack for Cyber Essentials, ISO 27001, SOC 2, the DSP Toolkit or a customer's security questionnaire - You've bought template packs before and drowned in documents that still needed rewriting - You want to know what 'good' looks like before you spend another penny or another weekend on it Most compliance packs fail not because a document is missing, but because nobody knew what the full set should be or where the evidence for each control was supposed to live. You find out during the audit, when an assessor asks for a register you've never created. Knowing the whole shape up front is the cheapest insurance there is. What's inside: - The core documents every compliance pack needs: policies, procedures, SOPs and registers, grouped by control area - What each document is actually for, in plain English, so you're not producing paperwork for its own sake - Where the supporting evidence for each control lives, and who owns it - The difference between a document that satisfies an assessor and one that just looks the part - How to spot the gaps in your current pack before an auditor, insurer or prospect does ### The UK Cyber Essentials Readiness Checklist URL: https://systechitsolutions.co.uk/resources/cyber-essentials-checklist A practical, self-assessment checklist covering all five Cyber Essentials control themes, so you know exactly where you stand before you apply. Most Cyber Essentials applications don't fail because the security is bad. They fail because nobody checked the boxes before submitting. This is for you if: - You're bidding for a government, NHS or supply-chain contract that requires certification - Your cyber insurance renewal now asks for it, or your premium jumps without it - You think your controls are solid but haven't tested them against the actual assessment criteria A failed submission doesn't just cost the re-assessment fee. It can cost the contract, the renewal deadline, or weeks chasing gaps you didn't know existed. Most of that is avoidable with an honest look at where you stand first. What's inside: - All 5 Cyber Essentials control themes, broken into the exact checks an assessor runs - 30+ tick-box items covering firewalls, secure configuration, patching, access control and malware protection - Plain-English wording, no jargon or prior security knowledge assumed - A clear read on what's a genuine gap versus what's already covered ## Contact Systech IT Solutions, Unit 21, Brough Business Centre, Baffin Way, Brough, HU15 1YU, United Kingdom. Telephone +44 (0)1482 770583. https://systechitsolutions.co.uk/contact --- Generated from the site's page sources at build time. Last generated: 2026-08-31.