Audit-ready
GDPR, ISO 27001, BAIT — the standard configuration is designed for common audits. You present, instead of reconstructing.
Setting up Microsoft 365 from scratch or securing an existing environment — with the HAFN Standard we deliver a cleanly configured, documented and auditable environment quickly.
We bring your Microsoft 365 tenant, your Intune devices and your Entra ID to a documented, secure configuration — one that does not come off the shelf, but out of 200+ HAFN projects.
Six building blocks that together make up the HAFN Standard configuration — no toolbox, no improvisation.
Entra ID, Conditional Access, MFA — as a binding policy, not a recommendation.
Intune profiles for Windows, macOS, iOS, Android — out of the box.
Exchange, Teams, SharePoint, OneDrive — cleanly configured, documented, handed over.
A cleanly configured and documented M365 environment — GDPR-ready from day one, through integration into your technical and organisational measures.
Automated creation and locking of identities, access and modern authentication methods.
Complete configuration documentation, handover workshop, policy catalogue. Designed for common audits.
GDPR, ISO 27001, BAIT — the standard configuration is designed for common audits. You present, instead of reconstructing.
New staff are productive on day one — not only after three weeks of ticket loops.
Lost laptop? Locked remotely. Outdated OS? Updated by policy. Without the knot in your stomach.
20 or 200 or 2,000 identities — the configuration does not change, only the number.
A full description of every policy in place — per area, per module, per account.
It is not only the user for whom things change. IT administration does not become less for your team, but different. We accompany these changes with training paths and workshops.
A list of all active Conditional Access, compliance and DLP policies — as a PDF, in Confluence, or in your DMS.
Our HAFN Standard configuration provides a basis for emergencies. On this basis you can derive processes, or work with us within HAFN Betrieb (our managed service) to create a dedicated emergency plan.
We ensure the targeted enablement of all user groups involved: end users, key users, management or IT.
Where needed, we accompany the transition from project to operation with a hotline and a weekly sync with the implementation team — then the move into HAFN Betrieb (optional).
Six points where the HAFN Standard sets itself apart from a classic M365 rollout.
We configure to the HAFN Standard — and adapt it to your industry, not the other way round.
You know in advance what it costs. No day rates, no after-the-fact billing.
You can leave the configuration — either to us for operation, or to another provider. No lock-in contracts.
Every policy has a rationale. You show the auditor the document — we show the configuration path.
Your project lead stays your contact from project start through to operation. This way we make sure no breaks arise from handovers.
Our configuration has run in 200+ projects — from the construction firm to the care-home group.
With HAFN Betrieb Workplace we take over day-to-day operation — support, maintenance, device management, on-/offboarding. Without ticket systems, without escalation tiers.
Four phases from the first conversation to a productive workplace. Each phase with a defined outcome and a point of contact.
30 minutes, free of charge. We clarify the current state, goals, scope — and whether we are a good fit.
30 minWe look into the tenant, talk to IT and management, and write the migration concept.
1 weekConfiguration, pilot with two teams, rollout to all identities. Weekly status, a fixed team.
4–6 weeksConfiguration documentation, workshop, 30-day support. Then optionally into HAFN Betrieb.
2 weeks