Anonymised ITFR client case study. The company name, project details and identifying information have been changed for confidentiality.
This Australian construction and project-management company first engaged ITFR when it had fewer than 10 employees. By the time it grew beyond 100 employees, the business had moved through several deliberate stages: stabilising non-compliant servers, adopting Microsoft 365, aligning with the Essential Eight at Maturity Level Two for DISP Level 1 preparation, introducing sensitivity labels and resilient recovery, then enabling Microsoft 365 Copilot two years later.
Phase one: stabilise the legacy environment
The original server environment had grown without a consistent compliance baseline. Local services, remote access, shared administration and ageing operating systems created risk, but they also supported applications the business could not simply switch off.
ITFR documented the domain, Remote Desktop Services, direct-attached storage, project applications, dependencies and recovery objectives. The transition design used separated Windows Server roles, protected administrative access and software-based zero-trust remote access with multi-factor authentication. This created a supportable bridge while workloads were assessed for Microsoft 365 or retirement.
Phase two: move collaboration into Microsoft 365
We migrated email and personal work into Microsoft 365, then created repeatable Teams and SharePoint project workspaces for tenders, commercial records, design, site, safety, defects and handover. Entra ID groups controlled access by role and project. External sharing had named owners and review points, while sensitive commercial areas remained separated.
Implementation methodology
- Inventory mailboxes, shared mailboxes, file shares, project applications, user profiles and access dependencies.
- Select fit-for-purpose Microsoft 365 licensing for office, site and restricted users, including Entra ID and Intune capabilities where required.
- Build a reusable Teams and SharePoint project template with defined libraries, metadata, owners and restricted commercial content.
- Migrate users and active projects in waves, validate mail, files, permissions and shared-mailbox access, then make former locations read-only.
- Enrol company laptops and tablets in Intune for encryption, configuration, updates and remote action, with Conditional Access for higher-risk content.
- Pilot real drawings, photos and defect workflows under site connectivity conditions before wider rollout.
This sequence let the company keep delivering projects while the technology model changed underneath it.
Phase three: align to Essential Eight Maturity Level Two for DISP preparation
Defence-sector opportunities introduced a more demanding assurance requirement. ITFR assessed the environment against the Essential Eight and built an implementation and evidence plan towards Maturity Level Two as part of DISP Level 1 preparation.
Implementation methodology
- Implement application control and harden user applications and Microsoft Office macro settings.
- Apply operating-system and application patching through risk-based deployment rings and documented maintenance windows.
- Restrict administrative privileges using separate accounts, a monitored jump host and Microsoft LAPS for local administrator password rotation.
- Strengthen multi-factor authentication, Conditional Access, privileged-access planning and device-compliance enforcement.
- Refine Group Policy and Intune configuration profiles, tune endpoint detection and response, and establish vulnerability-management reporting.
- Centralise security logs in Microsoft Sentinel and create incident runbooks, escalation paths and evidence for ongoing governance.
The work aligned controls and evidence to the target maturity level. It did not represent ITFR granting DISP membership or independently certifying the organisation.
Phase four: label sensitive data and prove resilience
Once identities, devices and workspaces were controlled, the next stage focused on information governance. Purview sensitivity labels differentiated routine project material from commercial, personnel and defence-related information. Data Loss Prevention rules and sharing controls were introduced gradually so project teams received useful prompts instead of unexplained blocks.
Microsoft 365 backup covered Exchange, OneDrive, SharePoint and Teams data. Server and data backups were separated from day-to-day administration, monitored and tested. A disaster-recovery compute environment, documented recovery sequence and tabletop exercise turned recovery from a licence line item into a demonstrated operating capability.
Two years later: enable Copilot without reopening old risks
Two years after the security uplift, the company wanted Copilot for project summaries, document drafting and internal research. ITFR treated AI as another controlled phase of the transformation, not a tenant-wide switch.
Implementation methodology
- Review SharePoint and Teams permissions for ownerless, public or overshared sites before assigning Copilot licences.
- Select low-risk sites and representative project-management users for the pilot.
- Validate Purview labels, DLP rules and search behaviour so sensitive content remained governed.
- Test Copilot in Teams, Outlook, Word, PowerPoint and Excel using approved project scenarios and human review requirements.
- Complete a post-pilot review, remediate findings and establish ongoing permission, labelling and Copilot-risk monitoring.
Because the earlier transformation had already structured identities, devices, workspaces and data ownership, the AI pilot could focus on business value rather than first repairing years of unmanaged access.
The result: growth without repeated reinvention
The company grew from fewer than 10 to more than 100 employees while moving from fragile server dependence to repeatable Microsoft 365 project delivery, stronger defence-aligned controls, governed information and tested recovery. New projects could be provisioned from a standard model, new users could be onboarded by role and security evidence could be reviewed rather than reconstructed for each request.
The most important outcome was sequencing. Each stage solved the immediate operational problem and prepared the foundation for the next one, including the Copilot rollout years later.









