Microsoft Services

Microsoft Services

We take care of your core Microsoft environments – Active Directory, Entra ID, DNS/DHCP, Exchange and servers – with design, hardening and ongoing management. You get a stable identity and infrastructure foundation the rest of your IT can rely on.

Microsoft’s core infrastructure services remain a backbone of modern IT environments. Active Directory (AD), for example, has been a foundational component of enterprise IT since 2000 and continues to provide reliable identity management decades later. Most large enterprises still run Active Directory, underscoring its universality and importance. Likewise, critical network services such as DNS and DHCP remain indispensable, as they underpin authentication, resource access, application availability, and network performance. Even as cloud-native solutions grow, these tried-and-true Microsoft services ensure stability, security, and interoperability across on-premises and hybrid environments.

Many organizations, especially in regulated sectors like finance, healthcare, and government maintaining Microsoft servers on-site to retain full control over data and compliance. Others leverage cloud services or hybrid models, but all share the need for core Microsoft infrastructure to be stable, secure, and well-integrated. These services (whether on physical servers or in the cloud) form the foundation for identity, security, and network management in an organization’s IT ecosystem. In every case, a focus on robust configuration and expert support is key to keeping business running smoothly.

Our Microsoft Infrastructure Services

Kristensson i Skåne AB offers end-to-end expertise to help you implement, manage, and optimize the full range of Microsoft infrastructure components. Our services span all the essential building blocks – from on-premises server roles to cloud-based directories – ensuring they operate in unison. We assist with new implementations, ongoing support, security hardening, and environment optimizations. Key service areas include.

  • Active Directory (AD & Azure AD)
    We design, deploy, and support Active Directory Domain Services on-premises, as well as cloud-based Azure AD (Entra ID) for modern identity management. This includes setting up new AD forests or domains, restructuring or consolidating existing directories, and configuring trust relationships. We handle the full lifecycle of AD: provisioning new domain controllers, migrating or decommissioning old ones, and ensuring healthy replication and backups. Given AD’s critical role – it stores and manages your organization’s users, devices, credentials, policies, and more – we place heavy emphasis on security hardening and best practices. (A compromised AD can effectively give attackers the “keys to the kingdom,” so we implement strong controls to prevent that.) Our team also enables hybrid identity by integrating on-prem AD with Azure AD, allowing you to extend AD authentication into cloud applications seamlessly. From tiered administration models to monitoring AD health, we ensure your directory remains a reliable, secure backbone for your IT environment.
  • DNS and DHCP
    We configure and troubleshoot your Domain Name System (DNS) and Dynamic Host Configuration Protocol (DHCP) services following Microsoft best practices. Proper DNS and DHCP design is vital for everything in your network to function – name resolution, IP address management, and device connectivity all depend on it. Our consultants will set up stable DNS zones and forwarding, implement DHCP scopes with the right exclusions/reservations, and ensure redundancy so clients always receive addresses and can resolve resources. We also assist with DNS/DHCP hardening (e.g. securing DNS against cache poisoning or limiting DHCP scope issues) and integration with AD (AD-integrated DNS). These core services remain foundational to authentication and resource access in any Microsoft-based environment, so we make sure they are configured for resilience and performance.
  • File & Print Services
    We help organizations set up and manage Windows file servers and print servers to enable secure sharing of resources. Our experts design a file sharing strategy that balances ease of access with strict permissions control. This includes creating shared folder structures, implementing NTFS permissions and Active Directory group-based access so that users only see and access what they should. We advise on storage strategy (for example, when to use Distributed File System for replication or mapping drives via Group Policy) and ensure data is protected – enabling features like Volume Shadow Copy for backups or encryption at rest as needed. For print services, we configure reliable print servers, define printer pools, and use technologies like Print Management or Universal Print to streamline printer deployment to users. By centralizing file and print services, you gain better control over data and devices, along with auditing capabilities. We also assist in migrating file/print workloads to the cloud or newer systems when appropriate (for instance, moving to SharePoint/OneDrive or Azure file shares) while maintaining interoperability with legacy systems.
  • Public Key Infrastructure (PKI) & Certificates
    Kristensson provides specialized support for your certificate services. We can design and deploy an Active Directory Certificate Services (AD CS) based PKI hierarchy (offline Root CA, one or more Subordinate CAs) or integrate with Azure AD Certificate Services, depending on your needs. A well-implemented PKI is crucial because it provides the foundation for trust in your network – enabling strong authentication, data encryption, and digital signatures. PKI is a core component of data confidentiality, integrity, and access control in modern IT. Our team will help you set up certificate templates, auto-enrollment for users and devices, and proper certificate lifecycle management (renewals, revocation via CRL/OCSP). We also handle integration of certificates for various use cases: securing internal websites/services with SSL, smartcard or certificate-based logons, securing Wi-Fi (802.1X) or VPN access, code/signature signing, and so on. Additionally, we provide guidance on operating a PKI in a secure manner – protecting your private keys (HSMs or offline storage for root CA), implementing role separation, and documenting processes to maintain a high level of trust. With our PKI services, you can issue and manage digital certificates confidently, knowing your organization’s communications and transactions are properly secured.
  • Network Policy Server (NPS) – RADIUS
    We help implement Network Policy Server, Microsoft’s built-in RADIUS server and proxy service for network authentication. NPS allows you to enforce centralized network access policies – it performs authentication and authorization for connections like corporate Wi-Fi (802.1X), VPN dial-ins, or switch port access control. We will install and configure NPS on your Windows Server, define RADIUS clients (your wireless controllers, VPN appliances, etc.), and set up network policies that govern who can connect under what conditions. NPS is essentially Microsoft’s implementation of the RADIUS standard, so it integrates tightly with AD: users can use their domain credentials to log into the wireless or VPN, and you can condition policies on group membership or other AD attributes. Our service covers configuring certificate-based authentication (e.g. EAP-TLS with user/machine certificates issued by your PKI), setting up RADIUS proxies if needed, and ensuring high availability of the NPS role. With a well-configured NPS, you gain secure, centralized control over network access, which is vital for zero-trust network architecture and compliance (e.g. ensuring only domain-joined or authorized devices can access your network).
  • Exchange Server (On-Premises & Hybrid)
    We support the full lifecycle of Microsoft Exchange Server on-premises, including the latest Exchange Server on-prem release. Our services cover architecture and sizing, installation and upgrades, migration projects, and operational management of mail flow, databases, and high availability (DAG). We also help harden and secure Exchange environments through best-practice configuration, patching routines, and monitoring. For hybrid scenarios, we design and maintain secure integrations with Microsoft 365/Exchange Online to support staged migrations, hybrid mail routing, and identity alignment.
  • Microsoft 365 Integration & GPO Management
    We help bridge your on-premises infrastructure with Microsoft 365 cloud services for a unified, hybrid environment. This often involves setting up and fine-tuning Azure AD Connect to synchronize on-prem AD accounts with Azure AD, enabling single sign-on across Microsoft 365 apps (Exchange Online, Teams, SharePoint, etc.). We ensure identity federation or synchronization is done securely and reliably, so your users have a seamless experience whether they’re accessing resources on-prem or in the cloud. Additionally, our consultants implement Microsoft’s security baselines and Group Policy Objects (GPOs) to enforce consistent settings and policies across your Windows devices. Group Policy enables centralized management of security and configuration settings on servers and PCs – we will review or create GPOs for things like password policies, workstation hardening, software installation rules, and Microsoft Office settings, aligning them with recommended baselines. If you use Intune (Microsoft Endpoint Manager) for device management in a hybrid setup, we assist with that as well – for example, deploying compliance policies or configuration profiles to laptops. In short, we cover all “glue” components that integrate your Microsoft ecosystem: from Active Directory Group Policies up through cloud-based policies, ensuring that best-practice configurations and security measures are in place at every level.

Deployment Models: On-Premises, Hybrid, or Cloud

On-Prem Infrastructure Cloud
Key differences between on-premises (left) and cloud (right) infrastructure.

On-premises deployments offer complete ownership and direct control of your hardware, software, and data (you manage everything on-site), whereas cloud infrastructure shifts many responsibilities to a provider and offers more flexibility in scaling. Kristensson helps you navigate these models and choose what’s right for your organization – be it keeping everything in-house, moving fully to the cloud, or a balanced hybrid approach. We have experience with all deployment models and can guide you through transitions (for example, migrating from on-prem to cloud) or optimize your current setup.

  • On-Premises
    We support traditional on-premises Microsoft environments where all services run in your own data center or server room. This model is often preferred by organizations that require tight control over data and systems (including many regulated industries). Our team will ensure your on-prem AD domain controllers, file servers, etc. are properly architected and maintained. We set up site topologies for multi-office environments, configure backups and disaster recovery for critical servers, and design high-availability where needed (e.g. multiple DCs, failover clustering). On-premises doesn’t mean outdated – we’ll help you leverage the latest Windows Server capabilities while meeting any air-gap or compliance requirements that keep you off the cloud. If and when you decide to incorporate cloud services later, your on-prem foundation will be ready.
  • Hybrid (On-Prem + Cloud)
    Many organizations choose a hybrid model, extending their on-site infrastructure with cloud services. Kristensson specializes in hybrid Microsoft architectures. We can connect your on-prem AD with Azure AD for unified identity management, set up Azure AD Connect or federation (AD FS) as appropriate, and configure conditional access policies that span both environments. In a hybrid setup, you might keep core AD, file, or print services on-prem, but use cloud offerings like Exchange Online or Azure file storage – we ensure seamless integration and data flow between the two worlds. We also help implement hybrid device management (for instance, hybrid Azure AD join for devices, or co-management with Intune and SCCM). The hybrid approach often offers the best of both worlds: you maintain a familiar, proven on-prem framework while gaining the scalability and modern capabilities of the cloud. Our experts will design the hybrid environment with security in mind (e.g. synchronizing only necessary identity data, implementing multi-factor authentication for cloud apps, etc.) so that your risk is minimized. Because hybrid architectures are likely to persist for years in most enterprises, we focus on creating a future-proof design that can evolve as more workloads move cloud-ward.
  • Cloud-Only
    If your organization is cloud-first, we ensure you’re getting the most out of cloud-native Microsoft services without any on-premise servers. We assist with setting up Azure Active Directory as your primary directory (for cloud-only environments), including features like Azure AD Domain Services if needed for legacy compatibility. We configure Microsoft 365 services (Exchange Online, SharePoint Online, etc.) with security best practices from the outset. For companies without an on-prem AD at all, we help establish cloud governance – defining Azure AD roles, conditional access, compliance policies in Intune, and integration with third-party cloud apps. Even cloud-only setups benefit from expert design: for example, planning the structure of Azure AD tenant (users, groups, naming conventions), or setting up Microsoft Defender for Cloud Apps to monitor SaaS usage. Kristensson can also guide you in migrating data or applications from old on-prem servers into Azure or Microsoft 365, ensuring minimal downtime and data integrity during the move. The result is a streamlined, fully cloud-based infrastructure that still meets your security and operational needs.

No matter the model, we adhere to Microsoft’s best practices for configuration and security. While fully on-premises environments may gradually decrease over time, hybrid architectures are expected to remain common for the foreseeable future – AD will continue to support legacy applications and internal systems while cloud services handle modern workloads. We design with this in mind, so you can pivot between on-prem and cloud as your business evolves.

Security, Compliance & Best Practices

Trust and security are paramount in every service we deliver. Kristensson i Skåne AB ensures that your Microsoft infrastructure is not only operational, but also hardened and compliant with industry standards. Our approach includes.

  • Security Hardening & Baseline Configuration
    We secure each service following well-established best practices and guidelines (including Microsoft’s own security baselines and CIS Benchmarks). This means we close default vulnerabilities and reduce the attack surface from Day 1. For example, we implement secure LDAP (LDAPS), strong authentication policies, and disable legacy protocols where possible. We leverage security baseline templates to enforce a strong security posture across your Windows servers and endpoints – these baseline policies help prevent misconfigurations and common weaknesses that attackers exploit. By standardizing settings (encryption requirements, audit logging, firewall rules, etc.), we ensure your environment is uniformly protected. Hardening also extends to things like registry and file permissions, removing or isolating unnecessary services, and following the principle of secure by default on all Microsoft components we touch.
  • Least Privilege Administration
    A core pillar of our security philosophy is the principle of least privilege. We help you implement role-based access controls and delegated administration so that users and admins have only the permissions they absolutely need – not greater Domain Admin rights than necessary. This might involve redesigning your administrative model (e.g. tiered administration for AD, separate accounts for admin tasks, implementing Just-In-Time access with privileged access management tools). We configure features like Network Policy Server policies, RBAC roles in Azure, and fine-grained delegation in AD to limit who can do what. The benefit is twofold: it minimizes the damage in case an account is compromised, and it aligns with modern zero-trust security frameworks (never trust by default). In our work, we also separate duties whenever possible (for instance, backup operators vs. security auditors vs. domain admins) to add layers of protection. The end result is a tightly controlled environment where every action is attributable and access is restricted, greatly reducing insider risk and potential misuse.
  • Documentation & Knowledge Transfer
    We believe that security and stability are bolstered by good documentation. After any implementation or change, we provide comprehensive documentation of your Microsoft environment’s configuration. This includes network diagrams of how services are connected, AD design (sites, OUs, GPO links), service account lists and permissions, certificate issuance processes – everything relevant to operating and reviewing the environment. Not only does this documentation help your IT staff in daily operations, it is also invaluable for compliance audits and regulatory review. Auditors and security officers can review these documents as evidence that controls are in place and processes are defined. By having up-to-date documents and records of configurations, you can demonstrate due diligence and adherence to required standards. As part of knowledge transfer, we also train your team on key aspects of the setup: for example, how to manage certificates, how to recover AD in an emergency, or how to update DNS records correctly. Our goal is to empower your organization to maintain the environment confidently. Should you be preparing for formal compliance audits (ISO 27001, GDPR, NIS2, etc.), we align our deliverables to meet those needs – mapping configurations to control requirements and ensuring policies (like password complexity, logging, backup retention) meet the required criteria.
  • Ongoing Updates & Support
    Security is not a one-time task, so we assist you in establishing a robust maintenance regimen. This involves regular patching of Windows Servers and applications (we help plan and execute updates to domain controllers, Exchange servers, Windows 10/11 clients, etc., including testing patches before broad rollout). Keeping systems up-to-date is critical and applying the latest security patches ensures known vulnerabilities are fixed, preventing attackers from exploiting them. We also set up health checks and monitoring for your Microsoft services (using tools like Microsoft’s native monitoring or third-party solutions) so that any emerging issues – whether a replication failure, low disk space, or an unusual login – are detected early. Our support can be tailored to your needs: from periodic environment reviews and AD security audits, to fully managed service where we handle day-to-day administration. In all cases, we emphasize proactive maintenance: regular reviews of configurations, cleanup of stale accounts or data, updates of configuration documents, and iterative improvements. This not only keeps your Microsoft infrastructure secure, but also highly reliable and performing optimally over time.

By following these security and best-practice measures, we ensure that your Microsoft infrastructure not only meets today’s needs but is resilient against tomorrow’s threats. Whether it’s aligning with compliance frameworks or guarding against cyber-attacks, Kristensson’s advisory keeps you secure, compliant, and prepared.

Common Use Cases

Over the years, we’ve helped a variety of clients with their Microsoft infrastructure challenges. Here are some common scenarios and how our services address them.

  • New Environment Setup
    Setting up a new IT environment from scratch, such as for a startup, a new branch office, or a company spin-off, can be daunting. We assist with greenfield deployments of Microsoft infrastructure – setting up a fresh AD domain or Azure AD tenant, establishing DNS naming conventions, configuring initial servers, and implementing baseline security policies from day one. This ensures your new environment is built on solid ground (with the right architecture and governance) instead of accumulating risky shortcuts. For example, we might help a fast-growing business that’s been using only cloud accounts to introduce their first Active Directory for better internal control, or set up a new domain for an overseas subsidiary and link it via trust to the main domain. We bring best practices to these projects so that as your environment grows, it scales properly and securely.
  • Domain Migration or Redesign
    Many organizations have legacy Microsoft setups that no longer serve them well – perhaps an Active Directory domain that was set up years ago and has become cluttered, or multiple domains/forests due to past mergers that complicate administration. Kristensson offers domain migration and redesign services to streamline your infrastructure. We plan and execute migrations to new AD domains or consolidate multiple domains into one, with minimal disruption. This includes migrating user accounts, groups, workstations, and servers to the new domain, using tools (like ADMT or Azure AD Connect for hybrid migrations) safely and efficiently. We also help redesign the logical structure of AD: cleaning up organizational units (OUs), group policies, and permission delegations so that AD is easier to manage and aligns with your current business structure. In some cases, customers want to upgrade from an old Windows Server version to a newer one – we handle AD schema updates, introducing new domain controllers, and retiring the old ones gracefully. After a successful redesign or migration, you’ll have a modernized directory that is easier to navigate, more secure, and ready to support future needs. We have performed migrations triggered by acquisitions, divestitures, or simply modernization efforts – ensuring no critical access is lost in the process and that users experience a seamless transition (with things like passwords and profiles intact wherever possible).
  • Security Overhaul & Hardening
    If you’ve experienced a security incident or a penetration test/audit has revealed weaknesses, our team can step in to overhaul the security of your Microsoft environment. This is a common scenario – for instance, an organization might discover that many privileged accounts exist, patches are missing, or attackers have already infiltrated AD. We perform a comprehensive review (an AD security assessment, for example) and then remediate the findings. Typical actions include: implementing stricter password policies and enabling multi-factor authentication, removing or disabling unnecessary administrator accounts, patching all domain controllers and critical servers, and fixing misconfigurations (like open LDAP or poorly configured trusts). We also deploy tooling or scripts to scan for indicators of compromise within AD (such as suspicious trust delegations or unmanaged privileged accounts). Given that most cyber incidents involve compromise of the identity system (AD or Azure AD), shoring up Active Directory security is often our top priority in these projects. Our team will apply the latest recommended practices (for example, leveraging Microsoft’s AD Auditing polcies, LAPS for local admin passwords, or implementing “Protected Users” group for high-privilege accounts) to significantly harden your defenses. We can coordinate with your cybersecurity staff or external auditors to ensure all compliance gaps are closed. After a security overhaul, your Microsoft infrastructure will be far more resilient against attacks, and you’ll have monitoring in place to catch any future intrusions early.
  • Compliance & Audit Preparation
    Organizations in regulated industries or those pursuing certifications often need their Microsoft infrastructure configured to meet specific compliance requirements. We help map technical settings to standards like ISO 27001, PCI-DSS, GDPR, or national cybersecurity regulations. For example, an audit might require proving that only authorized personnel can access certain file shares or that administrative actions are logged and reviewed. Kristensson will configure Group Policies, auditing, and reporting tools to address these needs – such as enabling Advanced Auditing in Windows to track log-on activities, or ensuring your password policies meet the complexity and rotation requirements. We also assist in generating the documentation and evidence an auditor would expect: network diagrams, lists of privileged accounts, GPO reports showing security settings, etc. If an audit finds deficiencies (perhaps weak access controls or missing disaster recovery tests), we work with you to remediate those promptly and prevent similar issues going forward. Our experience with regulated clients means we understand the language of both IT and compliance, acting as a bridge between your technical configuration and the compliance objectives. The result is an environment where you can confidently tick the boxes on security controls and provide auditors (or your clients) assurance that your Microsoft infrastructure is managed in line with industry standards. In short, we help turn compliance obligations into concrete technical measures that also improve your security and reliability.

Effective management of Microsoft infrastructure can dramatically improve an organization’s security and efficiency. Whether you need a fresh set of eyes on your AD and network setup, or ongoing expertise to support your team, we’re here to help. Contact Kristensson i Skåne AB to schedule a comprehensive Microsoft environment assessment or to discuss how our experts can assist you. We’ll evaluate your current setup, identify opportunities for optimization or risk reduction, and partner with you to ensure your core Microsoft services, on-premises, in the cloud, or both are stable, secure, and aligned with your business goals.

View

Let us help you get the most out of your Microsoft infrastructure, so you can focus on driving your organization forward.