Managed service operations
GEIDI IT Portal
Multi-tenant Microsoft 365 operations, without the PowerShell tax.
- status
- In production, running GEIDI's own managed tenants
- deployment
- Cloud-hosted service that connects to Microsoft 365, Entra ID and on-premises Active Directory
- where it sits
- operategovern & secure
- Estimated saving on every user onboarding: from around three-quarters of an hour of console work down to five minutes
- Management endpoints behind a single sign-in, replacing a console-and-PowerShell scramble per tenant
- Security baselines it deploys and detects drift against: NIST CSF, ASD Essential Eight and CIS
Microsoft 365 for many customers, one console at a time
Anyone running Microsoft 365 for a portfolio of customers knows the drill.
- No Microsoft console spans more than one customer, so each tenant means its own admin tabs and PowerShell window.
- Onboarding a new starter takes the better part of an hour across three consoles, and offboarding is the same in reverse.
- Policy drift happens silently between audits, so a moved baseline is first noticed when someone is looking for evidence.
- Answering “who changed what, and when?” means a hunt through several consoles.
One control room for every tenant you look after
The GEIDI IT Portal runs Microsoft 365 across many customer tenants at once, from one sign-in with one audit trail. Behind that sign-in sit 185 management endpoints, replacing a console-and-PowerShell scramble for each tenant.
- Starters and leavers in one workflow. Account creation, group membership, licence assignment, asset issue and the welcome email happen in a single form, and offboarding runs the same way in reverse.
- It runs on a date, not on memory. Both workflows can be queued against a future start date or last day and fire automatically.
- Re-onboarding that truly reverses an offboarding. Mailbox, on-premises directory account and licence are restored in the correct order.
- Policy baselines with drift caught early. Each tenant is compared against an approved baseline aligned to NIST CSF, the ASD Essential Eight or CIS Benchmarks.
- Hybrid is handled, not ignored. On-premises Active Directory is integrated, so a half-migrated estate does not fall back to manual work.
What changes for your team
The work stops being a sequence of consoles a skilled person drives by hand, and becomes a workflow that runs the same way every time and leaves a record.
Every action is recorded against the operator who requested it and the tenant it touched, with the outcome. Operators are scoped by tenant and by role, so access is bounded by function rather than by seniority.
Privileged mailbox operations run through signed automation runbooks, not interactive PowerShell sessions anyone can improvise inside. Customer credentials sit in a vault reached only through a server-side service, never in the codebase.
The engineer who runs these tenants estimates a saving of around 40 minutes on every user onboarding, from roughly three-quarters of an hour of console work down to five minutes.
Honest limits
- That 40-minute figure is an estimate, not a timed study.
- The total saving depends on how much each tenant does, so we quote a per-user figure, not a monthly total.
- Today it is in production running GEIDI’s own managed tenants.
Is it a fit?
It suits a managed service provider running Microsoft 365 across a portfolio of customer tenants rather than one.
See it against your own tenants
The fastest way to judge this is to walk one real onboarding and one real offboarding through it, then read the audit trail both left behind.