Infrastructure for decisions that cannot afford to be wrong.

Architecture and technical governance for Microsoft 365 migrations, identity and access changes, and infrastructure projects.

Scoped work, finished, validated, and handed over.

Tell us what needs to change, the deadline, and what must keep working. The initial conversation is free.

Servers, mailboxes and files move through agreed scope, approval and validation before the target is accepted.

Illustrative architecture · no client data

Services

Three tracks. A clear place to start.

Choose the work you need. Each project has an agreed scope, acceptance checks and a handover to your team.

What are you planning to change?

Microsoft 365 Architecture & Delivery

Move Microsoft 365, separate or combine tenants, and update access without overlooking the services your team relies on.

Illustrative Microsoft migration: access, approval and validation govern the move from servers, mailboxes and files to cloud services. The approved path has an agreed recovery route. Your team receives test results, open issues and a named owner in the Operating Record.
Plan administrator access, sign-in, mail flow and file permissions together. Agree the tests before your team takes over.
  1. Authority
  2. Access
  3. Continuity
  4. Information
  5. Acceptance
What the client retains

Your team keeps the system design, test results, open issues and operating instructions. We call this the Operating Record; it names who owns each part.

Illustrative architecture · the project scope is agreed for your environment.

Explore Microsoft 365 projects

Systems Engineering & Infrastructure

Decide where applications should run, how they recover after a failure, and who will manage them.

Illustrative infrastructure design: application and data requirements guide the choice of private servers, cloud services or a hybrid design. Capacity, connectivity and recovery are considered before placement. Backup and recovery are planned separately, with restore tests, a runbook and a named operating owner.
Plan capacity, connections and recovery before choosing private servers, cloud services or a hybrid setup.
What the client retains

Your team keeps the design choices, capacity estimates, recovery test results and named responsibilities in an infrastructure Operating Record.

Illustrative architecture · the design depends on what you need to run.

Explore systems engineering

QUALIFIED CAPABILITY

Private AI & High-Performance Infrastructure

Feasibility and architecture before procurement

Microsoft decision points

Which Microsoft change is in front of you?

Administrative controlsAccessApprovalValidationAdministrative controlsAccessApprovalValidationSource directoryAccounts · domainsTarget directoryEntra ID · tenantDIRECTORYDIRECTORYDirectorysynchronizationDomains & federationWho controls sign-inApp connectionsWhich directory they useNamed ownerWho can change the tenantSourcedirectoryTargetdirectoryDIRECTORYDIRECTORYDirectorysynchronizationDomains & federationWho controls sign-inApp connectionsWhich directory they useNamed ownerWho can change the tenantPeople & accountsWorkforce · guestsDevices & appsCompliance · permissionsConditionalAccessAuthenticationMFA and guest accessApp permissionsSeparate from user accessPrivileged access (PIM)Time-bound activationPeople &accountsDevices &appsConditionalAccessAuthenticationMFA and guest accessApp permissionsSeparate from user accessPrivileged access (PIM)Time-bound activationExchange ServerMailboxes · app emailExchange OnlineCloud mailboxesMailroutingDNS & certificatesCheck the mail routeRelay & connectorsTest application emailRecovery pathAgree when to go backExchangeServerExchangeOnlineMailroutingDNS & certificatesCheck the mail routeRelay & connectorsTest application emailRecovery pathAgree when to go backEmail & archivesFiles · existing accessSharePoint & TeamsContent · destination accessPurviewrequirementsRetention & holdsPreserve agreed obligationseDiscovery & DLPCheck search and policiesPermissionsReview Copilot exposureEmail &archivesSharePoint& TeamsPurviewrequirementsRetention & holdsPreserve agreed obligationseDiscovery & DLPCheck search and policiesPermissionsReview Copilot exposurePilot & migrationWork in agreed groupsTested servicesReady for owner reviewAcceptancechecksRecovery route agreedOperating RecordTest results · open issues · recovery stepsNamed owner · operating instructionsPilot &migrationTestedservicesAcceptancechecksRecovery route agreedOperating RecordTest resultsOpen issues and recovery stepsNamed owner and instructions
  1. An Exchange server needs to retire.

    Identify the applications that still send mail through the server, how accounts are managed and where archives will go before switching it off.

    See the relevant Microsoft project
  2. Tenants need to split or combine.

    Plan which accounts, domains, email, applications and files will move, and how people will work during the move.

    See the relevant Microsoft project
  3. You need control of administrator access.

    Review who holds administrator rights, what your provider can access, how temporary privileges are approved and how your team regains access in an emergency.

    See the relevant Microsoft project
  4. AD and Entra need a clear source of truth.

    Establish whether Active Directory or Entra manages each account and attribute, then document synchronization, sign-in and recovery responsibilities.

    See the relevant Microsoft project
  5. Files must keep their permissions and retention.

    Before moving email or files, map who can access them, how long they must be kept and which records are on hold.

    See the relevant Microsoft project
  6. You need to know what happened in Microsoft 365.

    Review the available sign-in, email, device and audit logs. Build a timeline that distinguishes verified events from gaps and assumptions.

    See the relevant Microsoft project
  7. Devices need consistent setup and support.

    Define how devices enroll, receive applications and updates, meet access rules and recover after a problem, with clear support responsibilities.

    See the relevant Microsoft project
  8. Check data access before rolling out Copilot.

    Review sensitive files, sharing and access, then agree a small pilot and the checks required before wider use.

    See the relevant Microsoft project

Illustrative architecture. Select a situation to see what needs to be checked and which project could help.

A completed migration needs
more than a success message.

A SharePoint migration required investigation of file differences, sync behavior and long project paths. The delivery record documents troubleshooting and checks between the original files and the destination.

The handover includes comparison scripts, validation reports and recorded exceptions. The record shows what was checked and what those checks could establish.

Read the recovery record

Anonymized delivered engagement

AZ / DELIVERY RECORDReconstructed overview

Migration
reconciliation.

A traceable record of checks, differences and next actions.

Folder and sync behavior
Environment-specific troubleshooting
File and path differences
Source-to-destination checks
Outstanding exceptions
Recorded differences and next actions

Supporting record

Migration as-built, issue records, reconciliation scripts and validation reports. Client names, file paths and identifying data are withheld.

Reconstructed presentation of documented work. Identifying details withheld. Recorded exceptions remain part of the evidence.

Leaving a provider? Plan for administrator access and working email.

The decision to leave a provider needs a defined target, continuity checks and agreed ownership. This example shows how to scope those decisions; it does not report a measured client outcome.

Explore the representative example

Tenant separation

What remains after the change.

Your team keeps the design, migration checks, remaining issues and operating instructions, with a named owner for each responsibility.

Your team keeps the design, migration checks, remaining issues and operating instructions, with a named owner for each responsibility.Your team keeps the design, migration checks, remaining issues and operating instructions, with a named owner for each responsibility.Your team keeps the design, migration checks, remaining issues and operating instructions, with a named owner for each responsibility.Administrative controlsScopeApprovalValidationCurrent tenantAccounts · mail · filesTarget tenantNew ownershipAssign what belongs to each business.Keep required services working during the split.Separation boundaryAccounts · information · applicationsCheck the shared connections.Sign-in & DNSMail flowFiles & sharingRecoveryPilot → test → approveSign-in · mail · file accessCompare results. Assign exceptions.Agreed recovery routeOperating RecordDesign + agreed boundariesTest results + open issuesRunbook + recovery stepsNamed operating owner
Architecture
Boundaries, dependencies and decisions.
Validation
Comparison results and agreed actions for remaining issues.
Runbook
Operating and recovery procedures.
Named ownership
Named people responsible for operating the delivered systems.

Illustrative architecture. The record pattern is not a client document.

Alwatheq Zboun

LinkedIn profile (opens in a new tab)

Your project has a named technical lead from scoping through handover. Alwatheq brings hands-on Microsoft 365, Azure, identity and endpoint experience from client and MSP environments.

Before work begins, you receive the scope, fee, delivery windows and acceptance checks in writing. Any specialist collaborator and post-handover support are agreed as part of that scope.

About AZ Innovations

A defined project, with a clear end.

  1. 1. Establish fit

    Describe the problem. We identify the scope questions and any dependencies to review.

  2. 2. Agree the work

    Scope, fee, access, change windows and completion checks are written down before work starts.

  3. 3. Deliver and validate

    Changes follow the agreed pilot or cutover plan. Test results and exceptions are recorded.

  4. 4. Hand over

    Your named owner receives the runbook, results and agreed support arrangements.

How projects are scoped

Before you commit

A clear first step.
You stay in control.

Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.

Check client feedback on Upwork ↗

Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.

Who will actually do the work?

Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.

What happens before you get access?

We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.

How do we know the change worked?

Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.

Will we need an ongoing retainer?

A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.

Discuss the fit ↗Read the delivery process ↗

Plan the change before committing to it.

Tell us which systems are involved, your deadline and what must keep working. We discuss whether we can help and what the project would include.

Request an Architecture Briefing

Choose Microsoft, infrastructure or partner work in the form. If you are unsure, describe the problem.