SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

Enterprise cloud is measured by governance, not by accounts created.

A Microsoft cloud estate starts quickly and sprawls just as quickly: unless tenant settings, identity permissions and sharing rules are designed on day one, what emerges is hard to tidy later.

Sanal Çekirdek addresses the estate across four areas — identity, collaboration, data and licensing. We work independently and claim no vendor partnership or competency level.

Identity and conditional access

In a cloud estate the security boundary is identity, not the network. Conditional access rules are built around device state, location and risk level, and privileged roles are granted for a limited time with approval.

  • Privileged roles open on request and expire
  • Break-glass accounts are exempt from rules and monitored
  • Rule changes run in report mode first
  • Legacy authentication methods are switched off

Collaboration and sharing governance

Team spaces open easily and close with difficulty. Without lifecycle rules, ownerless spaces accumulate and external sharing becomes invisible. Naming, ownership and duration are defined at the outset.

  • Every space carries an owner and a renewal date
  • External sharing is restricted by default
  • Guest accounts are reviewed on a regular cycle
  • An ownerless space is archived rather than deleted

Data location and retention

Where data is held and how long it is kept matters as much as configuration for compliance. Retention and destruction policies are translated into technical rules, and eDiscovery needs are considered from the start.

  • Retention periods become technical rules, not intentions
  • Region selection is recorded
  • Sensitive content is marked through classification
  • Destruction records can be shown during audit

Licensing and cost discipline

Licensing cost usually grows out of assignments nobody uses. Assignment is compared against real usage data, and a leaver's license is reclaimed automatically.

  • Assignment is regularly reconciled with real usage
  • The leaver process reclaims the license
  • License tiers are matched to roles
  • A usage report is prepared before renewal

How we work

  1. Establish tenant settings and identity permissions
  2. Trial conditional access in report mode
  3. Set collaboration lifecycle rules
  4. Translate retention policy into technical rules
  5. Reconcile license assignment with usage

How success is measured

  • Privileged roles no longer sit permanently assigned
  • The count of ownerless team spaces is falling
  • Retention rules match the written policy exactly
  • Unused license assignments keep declining

Frequently asked questions

Are you a Microsoft partner?

We claim no partnership or competency level. What we do is establish and operate enterprise governance for this estate; your product licensing runs through your own channels.

Does it work alongside on-premises systems?

Yes, hybrid estates are common. What matters is that identity synchronization and the permission model stay consistent on both sides — inconsistency most often starts there.

Will conditional access block users?

Not when it is designed properly. Rules run in report mode first, their effect is measured, and only then are they enforced.

Let's establish where your tenant governance stands today, beginning with identity and sharing rules.

Review your tenant governance