For organisations with approximately 5–50 employees and no in-house IT administratorAcross the Netherlands

Secure.Simple.Resilient.

Your Microsoft workplace.
Under ongoing management.

Managed Microsoft Workplace brings Microsoft 365, Intune and agreed Windows workplaces together in one manageable service with clear boundaries and one accountable contact.

For whom
Dutch organisations with approximately 5–50 employees and no in-house IT administrator
Outcome
A documented management baseline for users, devices and security
Model
One-off onboarding plus monthly management under a customer-specific scope and SLA
Starting price
From € 349 per month excluding VAT; onboarding and licences separate

Why ongoing management

Individual changes do not solve a management problem.

Accounts, devices and security settings change continuously. Without ownership, differences, exceptions and overdue work accumulate. Ongoing management makes responsibility and follow-up explicit.

One baseline

Agreed Microsoft 365 and workplace components follow a documented standard.

Continuous visibility

Changes, exceptions and signals are recorded and followed up as agreed.

Decision-ready improvement

Reporting shows what is sound, what deviates and which decision is required.

Baseline management

One controlled foundation. A separate customer layer.

This keeps the standard current without unintentionally overwriting your approved configuration, exceptions or business decisions.

Sources

Microsoft & CIS

Primary Microsoft guidance and applicable CIS Benchmark controls are assessed for each topic and scope.

  • Microsoft 365, Intune, Defender and Windows
  • Only relevant and technically feasible controls
Management foundation

Versioned and testable

A proposed change is researched, tested and documented before it is rolled out in a controlled manner.

  • Version, rationale and test result
  • Change log and evidence after application
Customer-specific

Recorded separately

Processes, licences, risk decisions and exceptions form their own layer above the shared foundation.

  • Deviations and risk acceptance visible
  • No automatic overwrite during updates
MonitorAssessTestApproveRoll outEvidence

No automatic certification: the baseline supports a secure and manageable configuration. Demonstrable compliance always requires assessment of the complete agreed scope, including licences, exceptions and customer responsibilities.

Potential scope

What the service can cover.

The final combination depends on licences, quantities and agreed management boundaries.

  • Users, licences, groups and shared mailboxes
  • Standard joiner and leaver processes
  • MFA, admin roles and agreed access policy
  • Exchange Online and the email security baseline
  • Intune for agreed business Windows devices
  • Compliance, BitLocker, Windows Hello and updates
  • Defender Antivirus and firewall policy within scope
  • Change records, documentation and periodic reporting

Starting management

Assess. Onboard. Then manage.

The starting condition determines how much remediation is needed before daily management can responsibly begin.

  1. Introduction

    We establish fit, intended outcome and constraints.

  2. Paid assessment

    Configuration, risks, quantities and management backlog are established.

  3. Onboarding

    Access, baseline, documentation and necessary remediation are handled separately.

  4. Management

    The agreed service begins with reporting, support and improvement under the SLA.

Interactive approachSee what happens at each stage and which evidence you receive.Open the approach →

Pricing model

A fixed management price follows a defined scope.

The monthly price is based on users, devices, managed components and support agreements. Onboarding and remediation are itemised separately. Licences, backup, awareness, third-party tooling and projects are shown separately in the proposal.

Scale
Users, devices and locations
Management
Microsoft 365, Intune, security and support
SLA
Service windows, response times and escalation
Starting point
Remediation and exceptions found during assessment

Frequently asked questions

Clear before we start.

Is the Security Check mandatory?

An equivalent, current and verifiable assessment may be sufficient. Without a clear starting point, First Aid IT cannot responsibly quote management and onboarding.

Is the baseline fully CIS-compliant?

The baseline uses applicable elements from current CIS Benchmarks and relevant Microsoft recommendations as references. Full CIS compliance is only claimed when the complete agreed scope has been demonstrably assessed. Licences, business needs, exceptions and risk acceptance can lead to documented deviations.

How is the baseline kept current?

New guidance and benchmark versions are reviewed periodically. Relevant changes are researched, tested and documented before controlled application. Customer-specific settings and exceptions remain separately recorded.

What access will First Aid IT receive?

Only what is required for the agreed scope. The route, roles, emergency access and periodic review are documented during onboarding.

Can projects be purchased separately?

Yes. Migration, Intune implementation, Autopilot or another suitable engagement can be standalone and ends after agreed aftercare and handover.

Are changes documented?

Yes. Changes and known exceptions within the management or project scope are recorded. Format and reporting frequency are agreed per customer.

First step

Would ongoing management fit your organisation?

Schedule a free introduction. Technical research starts only after a separately agreed, paid assessment.