Services
All Solutions
Microsoft-based security and cloud consulting – from strategy to implementation. Without artificial separation by company size.
Services Overview
Identity & Zero Trust
Identity & Zero Trust Architecture
Zero Trust is a security model that trusts no user or device by default – regardless of whether they are inside or outside the corporate network. Every access request is individually verified, authenticated and limited to the minimum required permissions (Least Privilege). The NIST framework SP 800-207 is the foundation; Microsoft implements it via Entra ID, Intune and Defender for Endpoint.
- Microsoft Entra ID – Design, Hardening & Migration
- Conditional Access & Risk-based Authentication
- Privileged Identity Management (PIM)
- Multi-Factor Authentication & Passwordless
- Device Compliance & Microsoft Intune MDM
- Zero Trust Maturity Assessment
Comparison
Zero Trust vs. Classical Perimeter Security
| Criterion | Perimeter Security | Zero Trust |
|---|---|---|
| Trust model | "Inside the network = trusted" | Never trust, always verify |
| Security perimeter | Network boundary (firewall) | Identity + device + context |
| Remote work | VPN-dependent, error-prone | Natively supported |
| Lateral movement | Hard to detect | Blocked by micro-segmentation |
| Cloud suitability | Limited (designed for on-premises) | Cloud-native optimised |
Sources: NIST SP 800-207 Zero Trust Architecture · Microsoft Zero Trust Adoption Framework
Data Security & Purview
Data Security & Microsoft Purview
Microsoft Purview is the integrated data protection and compliance platform in Microsoft 365, helping organisations discover, classify and protect sensitive data automatically – without separate tools. From Sensitivity Labels to Data Loss Prevention (DLP), eDiscovery and Insider Risk Management: Purview covers the entire data protection lifecycle, fully integrated into your existing M365 environment.
- Information Protection & Sensitivity Labels
- Data Loss Prevention (DLP) – Policies & Fine-Tuning
- Automatic Classification & Trainable Classifiers
- eDiscovery & Audit Logs
- Insider Risk Management & Communication Compliance
- Data Lifecycle Management & Retention Policies
Sources: Microsoft Purview Documentation · ENISA – Data Protection Glossary
Request ConsultationCompliance Consulting & Implementation
Compliance Consulting & Implementation Support
NIS2 compliance means demonstrably implementing technical and organisational measures – not just documenting them. Regulatory requirements from NIS2, ISO 27001, GDPR and BaFin are analysed, prioritised and technically implemented. The result: audit-ready compliance documentation without an internal compliance team. Experience from Healthcare, Banking, Energy and Public Sector.
- NIS2 Readiness Assessment & Implementation Support
- ISO 27001 Preparation & Technical Measures
- GDPR Evidence & Technical Protection Measures
- BaFin- & HIPAA-compliant Data Protection Architecture
- Microsoft Purview Compliance Manager
- Supplier Risk Assessment & Documentation
AI Advisory & Adoption
AI Advisory & Adoption
Strategy consulting and secure implementation for organisations that want to deploy AI tools – without losing control of their data. From readiness analysis to production operations.
- AI Readiness Assessment & Strategy Consulting
- Copilot for M365 – Governance, DLP & Secure Rollout
- Azure OpenAI & Custom AI Implementation
- AI Risk Analysis & EU AI Act Compliance
- Data Governance for AI Projects (Zero Trust)
- AI Security Training, Auditing & Awareness
Cloud & Workplace
Cloud & Workplace
Microsoft 365 migrations, tenant hardening and Exchange Online operations – carried out according to BSI baseline protection with transparent documentation. Also hybrid environments (On-Premises + Azure) and Infrastructure as Code with Terraform.
- M365 Migration & Tenant Hardening (BSI Baseline)
- Exchange Online & Teams Governance
- Hybrid Migrations (On-Premises → Azure / M365)
- Azure Landing Zone & Terraform IaC
- Microsoft Intune MDM (Windows, iOS, Android)
- Azure Virtual Desktop (AVD / PAW)
Cloud Sovereignty · Delos
Cloud Sovereignty in the DACH Region
Sovereign cloud infrastructure for regulated industries and critical infrastructure operators – based on Delos Cloud with Microsoft. As a Managed Service Provider (MSP) we plan, migrate and operate sovereign Microsoft environments compliant with BSI C5 and GDPR. Your data stays within the DACH region.
- Delos Cloud Strategy & Migration Projects (Microsoft)
- Data Sovereignty & EU Data Boundary – data stays in Germany
- BSI C5 Attestation & ISO 27001 Preparation
- Managed Service Provider (MSP) for sovereign DACH environments
- KRITIS- and BaFin-compliant cloud architecture
- Tenant Segregation & Air-Gapped Configurations
Frequently Asked Questions
Answers on Zero Trust, Microsoft Purview, NIS2 and how we work.
What is Zero Trust and how does it work?
Zero Trust is a security model that trusts no user or device by default – regardless of location. Every access request is verified, authenticated and limited to minimum permissions. Implementation uses Microsoft Entra ID (identity), Intune (device compliance) and Defender for Endpoint (endpoint security) – aligned with NIST SP 800-207.
How does a Zero Trust Maturity Assessment work?
The assessment has three phases: inventory (analysis of current configuration), gap analysis (identifying weaknesses and risk-based prioritisation) and roadmap (concrete implementation plan with quick wins). Duration: typically 2–4 weeks. Output is a written report with clear next steps.
What is Microsoft Purview and why do I need it?
Microsoft Purview is the integrated data protection and compliance platform in Microsoft 365. It automatically classifies, labels and protects sensitive data via Sensitivity Labels, DLP policies, eDiscovery and Insider Risk Management. For organisations with GDPR, NIS2 or ISO 27001 obligations, Purview is often the most efficient solution because it requires no separate tools.
Which industries and company sizes does Novesso serve?
Novesso advises companies from around 50 employees in regulated industries: Healthcare (HIPAA, GDPR), Banking & Finance (BaFin, DORA), Energy & Critical Infrastructure (NIS2), Public Sector (BSI Baseline) and mid-market in the DACH region. Project scope and engagement depth are agreed individually.
Can't find the right topic?
Let's talk. First consultation free – I'll analyse your situation and tell you honestly whether and how I can help.