Skip to main content
Proof of Outcomes

Case Studies

Real results from real organizations. Not marketing copy — documented outcomes with specific metrics and deliverables.

31 of 31 case studies
85–105 hrs
scoped engineering effort
Commercial
Modernize IT + Endpoint Identity

Active Directory Migration to Cloud Identity Across Mixed Device States

Challenge

An organization preparing for a cloud-first identity model needed to transition end-user computers from legacy identity configurations into a modern cloud-managed endpoint model. Devices were spread across multiple starting states — traditional Active Directory domain join, existing Azure AD join, and local/workgroup profiles — and the migration required careful handling of user profiles, Intune enrollment, and productivity tools without disrupting end users.

Approach

Safari Micro designed and executed a structured migration process built around planning, user scheduling, automation, validation, and direct user support. This included a migration booking process for controlled waves, a user and device tracking report, configuration and testing of migration scripts, temporary local administrator access planning, remote migration sessions, removal from legacy domain or prior Azure AD configurations, joining devices to the target Azure AD environment, profile data migration, Intune enrollment validation, and Outlook and OneDrive setup.

Results

  • Devices transitioned from legacy AD, prior Azure AD, and local profile states into Azure AD Join
  • User profile data migrated into the new cloud identity profile
  • All devices validated for Microsoft Intune enrollment
  • Outlook and OneDrive configured as part of the migration workflow
  • User scheduling and device tracking provided full migration visibility
  • Repeatable scripts reduced manual effort and improved consistency
  • End users received direct support during migration cutover
Read Case Study
284–420 hrs
senior engineering effort
Commercial
Microsoft 365 + Tenant Migration

Office 365 Tenant Consolidation After Multiple Acquisitions

Challenge

An organization that had completed several acquisitions needed to consolidate the acquired businesses from separate Microsoft 365 tenants into its primary environment. Each migration involved user mailboxes, shared mailboxes, OneDrive data, SharePoint Online sites, Microsoft Teams content, groups, contacts, mail routing, Outlook profile transitions, and post-cutover support — requiring a controlled approach that preserved collaboration data and maintained business continuity.

Approach

Safari Micro built a repeatable migration framework covering assessment, preparation, staging, migration, cutover, and post-cutover support. BitTitan MigrationWiz was used for Exchange Online and OneDrive migrations; ShareGate handled SharePoint Online and Teams migrations including site mapping and permissions planning. Safari Micro also coordinated end-user communication, validated Outlook profile transition behavior, and supported domain cutover including MX record changes, custom domain transfer, and alias assignment.

Results

  • 343 user, shared, and resource mailboxes migrated
  • 75 Microsoft 365 Group mailboxes consolidated
  • 242 OneDrive migrations completed
  • 188 SharePoint Online sites moved with permissions preserved
  • 41 Microsoft Teams migrated including connected content
  • Custom domain removal, transfer, and alias assignment completed
  • One week of post-cutover support delivered per migration phase
Read Case Study
200
access points installed & tagged
K–12 Education
Buy IT + Onsite Technical Services

200 Wireless Access Points Installed Across District Facilities

Challenge

A K–12 district needed to refresh wireless access points across multiple district locations. The environment included multiple buildings and mounting locations, requiring careful coordination, accurate device tracking, and efficient onsite execution — all while keeping the work clearly scoped to installation only, without introducing network redesign or cabling changes.

Approach

Safari Micro provided a focused onsite implementation team to complete the wireless access point deployment. The team unboxed, labeled, and asset tagged all devices before installation, removed legacy access points, mounted new units in designated locations, assisted with FortiGate adoption where required, and coordinated installation across all sites using a client-provided site list. Elevated mounting areas were supported with lifts as needed.

Results

  • 200 wireless access points installed and asset tagged
  • Legacy access points removed across all district locations
  • New access points mounted in designated locations
  • Devices labeled for easier long-term tracking and support
  • FortiGate adoption support provided where required
  • Project completed within agreed scope — no unplanned network or cabling work
Read Case Study
Teams Phone
voice modernization delivered
Public Sector
Microsoft 365 + Teams Phone

Legacy Phone System Migrated to Microsoft Teams Phone

Challenge

A government organization needed to move its existing phone system workflows into Microsoft Teams Phone while preserving the call routing structure users and administrators already depended on. The transition required more than number assignment — it needed to account for number porting, location-based number allocation, recreation of call flows and auto attendants, and administrative readiness for the new platform.

Approach

Safari Micro worked with the organization to configure Microsoft Teams Phone around the structure of the existing environment. The team reviewed current call flows, call groups, and auto attendants and recreated them inside Microsoft Teams. Safari Micro assisted with phone number port creation and submission, allocated numbers to appropriate locations after port acceptance, and delivered administrative training so the client's team could manage the Teams Phone environment independently going forward.

Results

  • Existing call flows, call groups, and auto attendants recreated in Teams Phone
  • Phone number porting process supported from creation through acceptance
  • Numbers allocated to appropriate locations post-port
  • Administrative training delivered for ongoing Teams Phone management
  • Legacy phone system reliance reduced through Microsoft 365 consolidation
  • Voice services modernized within the existing Microsoft 365 environment
Read Case Study
60+
managed devices migrated
Commercial
Modernize IT + Endpoint Management

Microsoft Intune Tenant Migration for an Acquired Business

Challenge

An organization that had recently completed an acquisition needed to bring endpoint management from the acquired business into its primary Microsoft 365 environment. Existing devices were already managed with established policies, applications, compliance settings, and enrollment workflows. Moving them into the parent tenant required a structured approach to avoid policy gaps, application disruption, and user confusion — including hybrid-joined device considerations and the need to validate the end-user experience before scaling.

Approach

Safari Micro began by validating the migration path in a controlled test environment, modeling source and destination tenants, synced Active Directory environments, Intune configuration, and hybrid Azure AD joined test devices. After testing, Safari Micro recreated the full Intune configuration in the destination tenant — including enrollment policies, compliance policies, Conditional Access, Windows Update, and endpoint security settings — repackaged managed applications, prepared hybrid Azure AD unjoin scripting, and ran a controlled pilot migration before broader rollout.

Results

  • Validated tenant-to-tenant Intune migration process before production rollout
  • Recreated endpoint security, compliance, update, enrollment, and application policies
  • Repackaged and redeployed managed applications in destination tenant
  • Piloted migration with selected users before scaling to full device estate
  • More than 60 managed devices migrated into destination Intune environment
  • Centralized policy control and consistent Microsoft 365 environment achieved
Read Case Study
SafariDesktops
fully managed AVD service
Commercial
SafariDesktops + Managed AVD

Managed Azure Virtual Desktop Delivered Through SafariDesktops

Challenge

An organization evaluating cloud desktop options needed a secure, managed virtual desktop environment that could support users with consistent performance and centralized management, without creating unnecessary operational overhead for internal IT. Key requirements included profile persistence, optimized multi-session desktop hosts, application readiness, daily profile backups, and clean integration with the client's existing Microsoft 365 tenant, Active Directory environment, and Azure infrastructure.

Approach

Safari Micro implemented SafariDesktops as a fully managed virtual desktop service. The solution included Azure Virtual Desktop infrastructure with GPU-enabled multi-session hosts, FSLogix profile containers on premium Azure storage, daily profile backups with retention, Microsoft 365 and Active Directory integration, optimized desktop image and application configuration, connectivity to the client's existing Azure environment, and ongoing management, helpdesk support, and performance monitoring by Safari Micro.

Results

  • Centralized cloud desktop platform deployed for end users
  • Persistent user profiles delivered through FSLogix profile containers
  • Managed desktop image and application configuration maintained
  • Daily profile backup protection with retention enabled
  • Ongoing helpdesk and operational support provided by Safari Micro
  • Performance visibility through desktop analytics and monitoring
  • Administrative overhead reduced for the client's internal IT team
Read Case Study
4-node
Hyper-V failover cluster deployed
Commercial
Infrastructure Modernization

Core Infrastructure Modernized with Hyper-V, Network, and SAN Storage

Challenge

An organization preparing for expanded virtualization workloads needed to modernize its core infrastructure with a more resilient, manageable, and scalable environment. The project required multiple technical layers to be configured together — network switching, firewall services, SAN storage, Hyper-V hosts, clustering, live migration, and virtual machine management — with careful coordination because core network changes involved planned downtime and access to multiple infrastructure components.

Approach

Safari Micro delivered a structured infrastructure configuration project covering network, security, storage, and virtualization. The team configured two Extreme Networks switches and a Fortinet FortiGate firewall (including WAF), set up a Lenovo ThinkSystem DE SAN storage array, installed Windows Server 2019 Datacenter on four physical hosts with Hyper-V, configured virtual switches, live migration, failover clustering with quorum disk and Cluster Shared Volumes, and migrated one physical server to a virtual machine. The engagement concluded with validation testing, instructional documentation, and hands-on training for the client's team.

Results

  • Modernized Hyper-V platform running on four clustered Windows Server 2019 Datacenter hosts
  • Shared SAN storage configured for virtualization workloads
  • Live migration capability enabled to support workload mobility
  • Failover cluster with Cluster Shared Volumes and quorum configuration for resiliency
  • Fortinet FortiGate firewall and WAF deployed with updated network switching
  • Physical-to-virtual migration completed for initial workload transition
  • Documentation and operational training delivered for day-to-day Hyper-V management
Read Case Study
Intune + Autopilot
endpoint management foundation
K–12 Education
Modernize IT + Endpoint Management

Microsoft Intune and Windows Autopilot Foundation for K–12 Education

Challenge

A K–12 education organization needed a more modern and consistent way to manage Windows devices across its environment. The organization wanted to reduce the manual effort involved in preparing and managing devices while improving visibility, endpoint security, and compliance — using Microsoft Intune and Windows Autopilot to simplify enrollment, standardize application deployment, and give IT staff better control over the device lifecycle.

Approach

Safari Micro structured the engagement around a practical Intune and Autopilot foundation. The work covered MDM authority configuration, corporate Windows device enrollment, Entra ID group creation and assignment, device configuration and compliance policies (antivirus, BitLocker, Defender, firewall), Windows update rings and feature and quality update policies, initial application deployment, Autopilot configuration for Hybrid Entra ID joined devices, Company Portal and Entra ID branding, pilot device onboarding, and administrative training for the client's IT team.

Results

  • Microsoft Intune configured as the device management platform for corporate Windows devices
  • Windows Autopilot set up for Hybrid Entra ID joined device provisioning
  • Compliance policies deployed covering antivirus, BitLocker, Defender, and firewall status
  • Windows update rings, feature update, and quality update policies configured
  • Application deployment model established through Intune for core applications
  • Pilot device onboarding completed and validated before broader rollout
  • Administrative training delivered to support ongoing management by internal IT staff
Read Case Study
Full-stack
managed IT coverage delivered
Commercial
Managed IT Services

From Reactive Support to Managed IT Operations for a Regional Business

Challenge

A regional business with a mix of office-based and remote employees needed dependable IT support, stronger infrastructure oversight, and a more structured service model for day-to-day technology operations. The organization relied on Microsoft 365, Active Directory, endpoint devices, network equipment, wireless access, and a physical server environment — but lacked a single partner and formal process to keep everything running and accountable.

Approach

Safari Micro delivered a managed services model covering the full technology stack. Support requests were routed through Safari Micro's service desk and logged in ConnectWise Manage with defined priority tiers (emergency, urgent, high, normal) and documented response targets. Scope included desktop and end-user break/fix support, Microsoft 365 administration (Exchange Online, Teams, OneDrive, SharePoint, licensing), network support for switches, wireless access points, firewall, and internet circuits, proactive Active Directory monitoring and quarterly health checks, and physical server OS administration, monitoring, antivirus, and periodic updates.

Results

  • Centralized IT support established for office and non-office employees
  • Formal ticket tracking deployed through ConnectWise Manage for full request visibility
  • Defined response expectations structured around business impact priority levels
  • Ongoing management of Microsoft 365, Active Directory, server, endpoint, and network systems
  • Proactive monitoring and periodic health checks implemented for core infrastructure
  • Emergency remote support available through on-call engineering team outside business hours
  • Clear boundary established between recurring managed services and separately scoped project work
Read Case Study
Security Framework
security baseline assessed
Commercial
Microsoft 365 Security Assessment

Strengthening Microsoft 365 Security Through a Practical Security Assessment

Challenge

A regional organization needed more than a high-level review of its Microsoft 365 environment. Leadership needed confidence that the tenant was configured securely and consistently, but faced a common challenge: Microsoft 365 includes a wide range of security settings, policies, reports, and administrative controls, making it difficult to know whether the configuration aligned with current best practices. The organization needed to identify which controls were already in place, where gaps existed, and which improvements should be prioritized to reduce cyber risk.

Approach

Safari Micro performed a comprehensive Microsoft 365 Security Assessment aligned to Microsoft security best practices and industry security frameworks — the essential cyber hygiene baseline applicable to organizations of all sizes. The assessment covered five structured areas: (1) Microsoft 365 tenant security review to identify aligned and non-aligned configurations; (2) security framework alignment analysis mapping the environment to essential cyber hygiene controls; (3) gap identification classifying each control as satisfied, partially satisfied, or not yet satisfied; (4) risk-based recommendations for configuration changes, policies, and procedures; and (5) an actionable improvement checklist to help the organization prioritize next steps.

Results

  • Current-state risk assessment delivered based on industry security frameworks
  • Microsoft 365 controls documented as satisfied or not yet satisfied against the security baseline
  • Configuration, policy, and procedure recommendations provided for each identified gap
  • Practical action checklist produced to guide prioritized remediation
  • Foundation established for future Microsoft 365 security governance and remediation planning
  • Organization moved from assumption-based security to a documented, structured security posture
  • Audit readiness and internal planning supported through a recognized cybersecurity framework
Read Case Study
~20 sites
switch stacks remediated
K–12
Network Infrastructure

Multi-Site Network Switch Remediation Across a K–12 District

Challenge

A regional K–12 education organization needed to modernize and remediate network switching infrastructure across approximately 20 campuses and district facilities. The environment supported classrooms, administrative offices, shared learning spaces, and core operational areas across a distributed footprint. Replacing switch stacks at this scale required careful planning and disciplined execution — coordinating configuration discovery, new stack preparation, cable labeling, legacy removal, and reconnection across numerous separate locations while minimizing disruption.

Approach

Safari Micro used a consistent site-by-site methodology across the full district environment. For each location the work followed a six-step repeatable process: (1) configuration discovery — gathering existing switch stack configurations to inform replacement setup; (2) switch preparation and labeling — new switches labeled and staged before deployment; (3) new stack configuration — each replacement stack configured to match site-specific operational requirements; (4) cable labeling and physical-layer readiness — existing cables labeled before removal to reduce reconnection risk; (5) legacy stack removal; and (6) new stack installation and reconnection to restore network connectivity. The project covered MDF and IDF environments across instructional, administrative, and district operations facilities.

Results

  • Structured replacement process delivered for legacy switching infrastructure across ~20 locations
  • Improved physical-layer clarity through consistent switch and cable labeling at every site
  • Consistent configuration and installation practices applied across the full district footprint
  • Reduced reconnection risk through pre-work configuration gathering and cable labeling
  • Better readiness for future network support, troubleshooting, and lifecycle management
  • MDF and IDF environments remediated across instructional, administrative, and operations areas
  • Repeatable site-by-site methodology enabled accurate, scalable execution across a distributed environment
Read Case Study
Full-stack
K–12 managed IT support delivered
K–12
Managed IT Services

Structured Managed IT Services for a Public Education Organization

Challenge

A public education organization needed a dependable managed IT services partner to support daily technology operations across endpoints, Microsoft 365, networking, servers, Active Directory, security tooling, and classroom-connected devices. Supporting this environment required more than ad hoc troubleshooting — the client needed consistent support, formal ticketing, infrastructure monitoring, and defined escalation paths for emergency, urgent, high, and normal requests, covering both staff productivity and classroom technology needs.

Approach

Safari Micro established a managed services support plan built around centralized ticketing through ConnectWise Manage and a remote-first, on-call escalation model. The scope covered desktop and end-user support, Microsoft 365 administration, network support (switches, wireless, firewall, internet circuits), Active Directory monitoring and health checks, server administration and monitoring, security tooling management, and classroom technology support including projectors, interactive displays, and document cameras.

Results

  • Centralized IT support established for staff and classroom technology
  • Formal ticket tracking deployed through ConnectWise Manage
  • Defined response expectations structured around business impact priority levels
  • Ongoing management of Microsoft 365, Active Directory, server, endpoint, and network systems
  • Proactive monitoring and periodic health checks implemented for core infrastructure
  • Classroom technology support included in managed scope
  • Emergency remote support available through on-call engineering team
Read Case Study
~400 devices
migrated to cloud-managed Intune
Commercial
Endpoint Management & Security

Modernizing Endpoint Management with Intune, Autopilot, and Microsoft 365 Security

Challenge

An organization managing approximately 400 Windows devices needed a more secure, scalable, and consistent endpoint management model. The environment required transitioning users from legacy Windows profiles into Entra ID cloud-based profiles, standardizing device enrollment, deploying applications centrally, enforcing compliance policies for antivirus, BitLocker, Microsoft Defender, and firewall settings, and improving the Microsoft 365 tenant security posture — all while minimizing disruption to end users during migration.

Approach

Safari Micro structured the engagement across four connected workstreams: (1) Microsoft Intune and endpoint management deployment — configuring MDM authority, Entra ID groups, corporate device policies, compliance policies, Windows Update rings, BitLocker encryption, Company Portal branding, and Windows Autopilot for Entra ID joined devices; (2) application deployment configuration — setting up standard and complex application packaging through Intune to reduce manual setup; (3) Windows profile migration — building a scheduling process, user and device tracking report, migration scripts, remote migration assistance, domain removal, Entra ID join, data migration, Outlook and OneDrive setup, and immediate user support; and (4) Microsoft 365 security assessment — reviewing tenant configuration against Microsoft best practices and industry security frameworks, identifying satisfied and unsatisfied controls, and producing a practical remediation checklist.

Results

  • Stronger Intune-based endpoint management foundation established for ~400 Windows devices
  • Consistent device onboarding delivered through Windows Autopilot for Entra ID joined endpoints
  • Improved visibility into device compliance and endpoint security posture across the fleet
  • Reduced manual effort for device provisioning and application deployment through centralized policies
  • BitLocker, Microsoft Defender, firewall, antivirus, and Windows Update policies enforced at scale
  • Structured Windows profile migration process delivered with minimal end-user disruption
  • Microsoft 365 security posture reviewed against industry security frameworks with actionable remediation roadmap
Read Case Study
M365 Secure
baseline controls implemented
Commercial
Microsoft 365 Security

Strengthening Microsoft 365 Security with Baseline Controls

Challenge

A growing organization needed to improve its Microsoft 365 security posture and reduce identity, email, and password-related risk. Before the engagement, the client needed practical answers: How secure is the current tenant? Which baseline controls should be prioritized first? How can users be better protected from phishing, spoofing, unsafe links, and malicious attachments? How can identity protection be improved without overbuilding the environment? The scope was intentionally focused — strengthening the tenant using existing Microsoft 365 capabilities without expanding into endpoint management, device encryption, or third-party integrations.

Approach

Safari Micro began with a Microsoft 365 Secure Score assessment to establish a baseline view of the tenant's security posture. The engagement then implemented a structured set of baseline controls: (1) identity protection — multi-factor authentication and self-service password reset to reduce account takeover risk and IT overhead; (2) email security — anti-phishing, anti-spoofing, Safe Attachments, and Safe Links policies through Microsoft Defender for Office 365; (3) data protection — secure email encryption configuration for safer handling of sensitive communications; and (4) password policy configuration aligned to stronger identity hygiene. Microsoft 365 Business Premium licensing upgrade support was also provided as part of the engagement.

Results

  • Stronger protection against credential compromise through MFA implementation
  • Improved user account recovery through self-service password reset configuration
  • Better defense against phishing, spoofing, malicious attachments, and unsafe links
  • Clearer Microsoft 365 security posture visibility through Secure Score assessment
  • Improved email data protection through secure encryption configuration
  • Password policies reviewed and configured for stronger identity hygiene
  • More mature Microsoft 365 security baseline delivered without expanding into unrelated infrastructure work
Read Case Study
124
mailboxes migrated from Google Workspace
Commercial
Microsoft 365 + Email Migration

Google Workspace to Microsoft 365 Mailbox Migration

Challenge

A professional services organization needed to migrate its email environment from Google Workspace to Microsoft 365 while maintaining reliable mail flow, reducing disruption for users, and preparing the organization for a Microsoft 365-based collaboration platform. The migration needed to account for routing domains, user mailbox creation, mail forwarding, DNS cutover, access validation, and staged migration activity before the final transition.

Approach

Safari Micro structured the project around a phased migration model. The first phase covered discovery, access, and tenant readiness — including domain registration, user account recreation, mailbox licensing alignment, routing aliases, and forwarding configuration. The second phase set up dedicated routing domains and configured BitTitan MigrationWiz as the migration engine. The third phase focused on validation and staged pre-migration. The final phase executed the full migration pass, updated forwarding behavior, and coordinated the MX record change to route primary mail flow to Microsoft 365.

Results

  • Approximately 124 mailboxes migrated from Google Workspace to Microsoft 365
  • Microsoft 365 tenant prepared for production email use
  • Mail routing configured and validated before cutover
  • User mailboxes mapped and migrated through BitTitan MigrationWiz
  • Pre-stage migration completed to reduce final cutover risk
  • Migration errors reviewed and remediated before production transition
  • Final MX record cutover completed to route primary mail flow into Microsoft 365
  • End-user communication support provided around the migration event
Read Case Study
18 users
home drives migrated to OneDrive
Commercial
Microsoft 365 + SharePoint + OneDrive

Streamlining SharePoint Permissions and OneDrive for Business Migration

Challenge

A growing organization needed to modernize how users accessed shared business files and individual user data in Microsoft 365. The environment included a large SharePoint Online document library structure (~4TB of shared folder data) and user home drive content for 18 users that needed to be migrated into OneDrive for Business. The goal was a cleaner Microsoft 365 file access model that separated shared departmental data from user-owned files, with permissions aligned to defined security groups rather than ad hoc access assignments.

Approach

Safari Micro used a structured approach built around SharePoint Online, OneDrive for Business, and ShareGate. For SharePoint, the team inventoried and audited the shared folder structure, identified appropriate security groups, and applied group-based permissions across the document library. For OneDrive, Safari Micro identified each user's home drive location, provisioned service account permissions, built source endpoint objects in ShareGate, initialized OneDrive storage for users who had not yet used it, built migration scripts, ran initial syncs, scheduled ongoing synchronization before cutover, and coordinated end-user communication to support the transition.

Results

  • SharePoint document library permissions aligned to defined security groups across ~4TB of shared data
  • 18 user home drives migrated into individual OneDrive for Business storage
  • OneDrive storage initialized for users who had not previously used OneDrive
  • Initial and ongoing sync runs completed to reduce cutover risk
  • Legacy home drive dependency reduced through structured cutover coordination
  • Cleaner separation established between shared collaboration spaces and individual user files
  • More scalable permissions structure delivered for shared SharePoint data
Read Case Study
Nutanix AHV
hyperconverged infrastructure deployed
Public Sector
Infrastructure + Virtualization

Modernizing Virtual Infrastructure with Nutanix AHV

Challenge

A public-sector organization was operating workloads on physical server infrastructure and needed to transition to a more scalable, resilient, and centrally managed virtualization platform. The project required careful planning, firmware validation, cluster configuration, storage setup, and workload migration to ensure the new Nutanix hyperconverged environment was production-ready without disrupting existing operations.

Approach

Safari Micro delivered a structured Nutanix installation and migration engagement across five workstreams: (1) hardware installation validation and firmware review — checking system readiness and applying updates before deployment; (2) Nutanix cluster deployment — installing the hypervisor and Nutanix controller VMs; (3) cluster and storage configuration — creating the Nutanix cluster, configuring storage pools, and enabling administrative features; (4) advanced virtualization configuration — setting up Nutanix containers and the AHV cluster using Nutanix Acropolis services; and (5) server migration assistance — moving workloads from physical infrastructure into the new hyperconverged platform.

Results

  • Modern Nutanix AHV environment deployed and ready to host migrated workloads
  • Physical server workloads migrated into the new hyperconverged infrastructure platform
  • Nutanix cluster created with storage pools configured for centralized management
  • Firmware validated and system updates applied before production deployment
  • Reduced dependency on legacy physical server infrastructure
  • Improved scalability and resilience for future infrastructure growth
  • Cleaner virtualization platform established for ongoing IT operations
Read Case Study
Palo Alto
HA firewall pair + 2 branch firewalls deployed
Public Sector
Network Security + Firewall

Modernizing Public Safety Network Security with Palo Alto Firewall Deployment

Challenge

A public-sector safety organization needed to replace its existing firewall infrastructure with new Palo Alto hardware while maintaining secure and reliable connectivity across its primary environment and branch locations. The project required a controlled migration approach that preserved existing firewall functionality — including a high-availability firewall pair — without disrupting critical network operations.

Approach

Safari Micro provided structured technical services across four phases: (1) configuration export review — obtaining current firewall configuration exports to ensure continuity between the existing and new environments; (2) HA firewall migration — migrating the existing Palo Alto high-availability firewall pair to new hardware while preserving the core firewall design; (3) branch firewall configuration — configuring two new Palo Alto firewalls for branch locations to extend the organization's firewall architecture across distributed sites; and (4) production cutover and validation — placing the new firewalls into production and validating that network traffic was passing as expected after deployment.

Results

  • New Palo Alto firewalls placed into production across primary and branch locations
  • Existing high-availability firewall pair successfully migrated to new hardware
  • Two branch firewall appliances configured and deployed for distributed site connectivity
  • Production cutover completed with validated traffic flow after deployment
  • Refreshed network security infrastructure with stronger foundation for ongoing operations
  • Operational continuity maintained throughout the firewall migration process
  • Distributed site connectivity preserved across primary and branch environments
Read Case Study
Exchange 2019
on-premises messaging modernized
Commercial
Exchange Server Migration

Exchange Server Modernization: Migrating from Exchange 2010 to Exchange 2019

Challenge

A client organization needed to modernize its on-premises Microsoft Exchange environment by moving from Exchange Server 2010 to Exchange Server 2019. Because Exchange Server 2010 could not be directly upgraded to Exchange Server 2019, the migration required a carefully planned intermediate coexistence step using Exchange Server 2016. The project needed to reduce disruption, validate mail flow, preserve existing Exchange configuration, and ensure mailboxes could be moved in a controlled manner before retiring the legacy system.

Approach

Safari Micro designed a staged migration path across six phases: (1) Active Directory schema preparation for Exchange Server 2016; (2) Exchange Server 2016 installation and configuration in coexistence with the existing Exchange 2010 environment; (3) configuration alignment — matching existing Exchange configuration on the new server for consistency; (4) migration and coexistence testing — including email security gateway configuration assistance and coexistence validation; (5) mailbox migration to Exchange Server 2016 and decommissioning of Exchange Server 2010; and (6) Exchange Server 2019 upgrade — preparing Active Directory for Exchange 2019 and completing the final upgrade path after Exchange 2010 was retired.

Results

  • Mailboxes successfully migrated off the legacy Exchange Server 2010 platform
  • Exchange Server 2016 coexistence established and validated before mailbox migration began
  • Exchange Server 2010 decommissioned after controlled migration completion
  • Environment upgraded to Exchange Server 2019 via structured upgrade path
  • Active Directory schema prepared for both Exchange 2016 and Exchange 2019 transitions
  • Email security gateway configuration updated and validated post-migration
  • Post-migration support delivered to ensure stable messaging operations
Read Case Study
Microsoft 365
hybrid Exchange migration completed
Public Sector
Exchange to Microsoft 365 Migration

Exchange to Microsoft 365 Migration for a Public-Sector Education Organization

Challenge

A public-sector education organization needed to modernize its email environment by migrating from on-premises Microsoft Exchange to Microsoft 365. The environment included Exchange Server, public folders, existing mail flow dependencies, and the need for a controlled migration path that preserved coexistence during the transition. Key technical considerations included mailbox migration sequencing, public folder access, hybrid mail routing, Autodiscover behavior, user identity alignment, and coexistence between Exchange Online and the on-premises Exchange server.

Approach

Safari Micro implemented a hybrid Exchange migration strategy across structured phases: (1) server readiness — updating Exchange 2013 to a supported cumulative update level and validating Autodiscover connectivity and UPN configuration; (2) hybrid configuration — enabling Hybrid Exchange in Azure AD Connect, configuring Exchange Hybrid and hybrid mail flow, and establishing Office 365 mail connectors; (3) migration testing — creating and validating the migration endpoint, assigning licensing, and testing mailbox migration to Exchange Online and back; (4) coexistence validation — validating free/busy calendar coexistence, mail flow, and hybrid public folder access; (5) phased migration — migrating users in batches and migrating public folders after mailbox completion; and (6) cutover and cleanup — cutting over mail flow to Exchange Online Protection, updating SPF and Autodiscover DNS records, and delivering documentation and knowledge transfer.

Results

  • Modern Microsoft 365 email platform delivered for the organization
  • Hybrid coexistence maintained throughout the migration period
  • Validated mail flow between on-premises Exchange and Exchange Online
  • Calendar free/busy functionality preserved during transition
  • Public folders migrated after mailbox migration completion
  • Mail flow cut over to Exchange Online Protection after validation
  • SPF and Autodiscover DNS records updated to support Microsoft 365 email services
  • Administrative documentation and knowledge transfer delivered for ongoing support
Read Case Study
Dell VxRail
hyperconverged cluster deployed
Public Sector
Infrastructure Modernization

Hypervisor Modernization for a K-12 Education Environment

Challenge

A public-sector education organization needed to modernize an aging server environment that relied on legacy hypervisors, outdated operating systems, and aging physical server infrastructure. Several workloads were running on older Windows Server platforms, while other systems depended on aging physical or virtual servers. The client needed a structured modernization effort to stabilize the virtualization layer, reduce dependency on legacy infrastructure, and create a stronger foundation for future backup and security initiatives.

Approach

Safari Micro delivered a phased infrastructure modernization engagement centered on hypervisor replacement and workload migration. This included installing and staging a new Dell VxRail cluster in coordination with Dell engineering resources, testing migration paths for supported Windows Server virtual machines, migrating Windows Server 2012 or newer VMs to the new host platform, staging new Windows Server 2019 or newer VMs to replace legacy server workloads, repairing or replacing the existing Windows Server Update Services function, installing and configuring Dell switches, configuring cloud-based controllers, and updating documentation and remote access details.

Results

  • New Dell VxRail hyperconverged cluster installed and staged
  • Supported virtual machines migrated from legacy hosts to the new platform
  • Replacement path established for legacy server workloads
  • Modern Windows Server instances staged for outdated systems
  • Supporting Dell switch configuration completed
  • Cloud-based controllers configured
  • Update services reviewed and repaired or replaced as needed
  • Infrastructure documentation and remote access details updated
  • Foundation created for future backup and security modernization phases
Read Case Study
Cloud-Only
identity model achieved
Commercial
Modernize IT + Endpoint Identity

Active Directory to Cloud-Only Identity Modernization

Challenge

A growing organization was operating in a hybrid identity model where users were synchronized from Active Directory into Azure Active Directory. While functional, this model created an ongoing dependency on legacy infrastructure and limited the ability to fully adopt a modern cloud-managed endpoint strategy. The environment also relied on traditional file shares and home drives, creating additional complexity around access, storage, collaboration, and endpoint transitions. The organization needed a structured path to convert users to cloud-only accounts, migrate file data into Microsoft 365, and reset Windows devices into an Azure AD joined and Intune-managed state.

Approach

Safari Micro designed a phased conversion strategy focused on identity, data, and endpoint readiness. The project began with preparation for SharePoint and OneDrive migrations using ShareGate — connecting the migration platform to the Microsoft 365 environment, building the required SharePoint document libraries, and migrating shared file data from traditional file shares into SharePoint. User home drive content was migrated into OneDrive to align personal file storage with Microsoft 365. For identity modernization, Safari Micro stopped directory synchronization and converted synchronized Azure AD user objects into cloud-only accounts, removing the dependency on the on-premises identity sync process. For endpoint modernization, Safari Micro tested the computer reset and onboarding process, assisted with Windows device enrollment into Intune endpoint management, coordinated user data backup to OneDrive before device resets, and supported the Intune Autopilot process — Azure AD joining each device, recreating the user profile, and applying required applications and configuration settings.

Results

  • Cloud-only Azure AD user account conversion completed
  • SharePoint document libraries created and file share data migrated
  • User home drives migrated to OneDrive for cloud-based personal storage
  • Directory synchronization stopped and on-premises AD dependency removed
  • Windows devices reset and enrolled into Intune endpoint management
  • Autopilot-based Azure AD join and user profile setup completed
  • User data backed up to OneDrive before device resets to preserve important files
  • Reduced reliance on on-premises directory synchronization infrastructure
  • Stronger foundation established for future Microsoft 365 security and endpoint management initiatives
Read Case Study
SharePoint Online
file share migration & sync delivered
Commercial
Microsoft 365 + SharePoint Migration

Safari Micro Enables File Share Migration and One-Way Sync to SharePoint Online

Challenge

An organization relied on a Windows Server file share as a central location for business files. As part of its Microsoft 365 modernization effort, the organization needed a controlled way to move file share content into SharePoint Online. The migration also needed to account for user access alignment between Active Directory and SharePoint Online — without proper permissions mapping, users could experience access gaps after the migration. In addition, the organization needed newer files from the source environment to continue flowing into SharePoint Online during the migration window.

Approach

Safari Micro configured a SharePoint migration and synchronization workflow using Sharegate. The team installed Sharegate on the Windows file share server, connected the source file share, and connected the destination SharePoint document library environment. Safari Micro then created an Active Directory user to SharePoint user permissions map to help preserve access alignment during the migration. The migration task was configured to authenticate to both source and destination endpoints, import the permissions map, and apply copy-if-newer settings. After the initial migration task was run, Safari Micro reviewed and remediated migration errors as needed, then configured the ongoing migration sync schedule.

Results

  • Sharegate installed and configured on the Windows file share server
  • Source file share and destination SharePoint document library endpoints connected
  • Active Directory to SharePoint user permissions map created and imported
  • File share to SharePoint migration task configured with copy-if-newer settings
  • Authentication to source and destination endpoints validated
  • Initial migration executed with error review and remediation
  • Scheduled one-way synchronization from file share to SharePoint Online established
  • Foundation for cloud-based document access in Microsoft 365 established
Read Case Study
Security Framework
M365 security assessment delivered
Commercial
M365 Security Assessment

Strengthening Microsoft 365 Security Through a Structured Cybersecurity Assessment

Challenge

A growing organization needed a clearer understanding of its Microsoft 365 security posture and wanted to evaluate its environment against recognized cybersecurity best practices. Key priorities included understanding whether Microsoft 365 security controls were configured according to best practices, identifying gaps against industry security frameworks, establishing a practical roadmap for improving tenant security, reducing exposure to common cyber threats through stronger baseline security hygiene, and creating a clear checklist of recommended actions for future improvement.

Approach

Safari Micro conducted a structured Microsoft 365 Cybersecurity Assessment designed to evaluate both technical configuration and security posture. The assessment focused on Microsoft 365 tenant security settings, cybersecurity practices, and alignment with essential cyber hygiene controls. Safari Micro reviewed the environment through the lens of Microsoft security best practices and industry security frameworks, helping the organization understand which controls were already satisfied and which areas required additional attention. The assessment included a Microsoft 365 tenant configuration review, security posture evaluation, review against Microsoft security best practices, identification of gaps or deviations from security benchmarks, documentation of satisfied and unsatisfied security controls, and recommendations for improving configuration, policies, and procedures.

Results

  • Microsoft 365 tenant configuration reviewed against industry security frameworks and Microsoft security best practices
  • Current Risk Assessment delivered — documenting which Essential Cyber Hygiene controls were satisfied and which required attention
  • Security Improvement Recommendations provided for configurations, policies, and procedures
  • Recommended Action Checklist delivered to guide future Microsoft 365 tenant security improvements
  • Better visibility into Microsoft 365 security gaps established for IT leadership
  • Alignment with a recognized cybersecurity framework achieved
  • Stronger foundation established for future security policy and configuration improvements
  • Improved readiness to reduce common Microsoft 365 security risks
Read Case Study
3 TB
shared file data migrated to SharePoint Online
Commercial
SharePoint Migration + Server Decommission

Safari Micro Migrates 3 TB of Shared File Data to SharePoint Online and Decommissions Legacy Server Infrastructure

Challenge

A regional business relied on a legacy Windows Server 2008 R2 domain controller that hosted approximately 3 TB of shared file data and supported key infrastructure services including FSMO roles, printer shares, DHCP, and Group Policy. As the environment continued to evolve, the organization needed a more modern and manageable file collaboration platform while also reducing the operational risk associated with aging server infrastructure. The project required careful planning around file structure, permissions, domain controller services, printer shares, DHCP, and Group Policy references.

Approach

Safari Micro used a structured migration and decommissioning process to reduce disruption and maintain alignment with the organization's access requirements. The engagement began with an inventory and audit of the existing shared folder structure using ShareGate to identify the file share layout, prepare the migration path, and support planning for the SharePoint Online destination. Safari Micro then worked with the organization to identify the security groups that would be used to manage access permissions in SharePoint Online. Once the permission model was defined, Safari Micro configured the SharePoint document library folder structure to align with those groups and migrated the shared file data to SharePoint Online. In parallel, Safari Micro prepared the legacy domain controller for decommissioning by transferring FSMO roles, migrating printer shares and DHCP, updating Group Policies that referenced the old server, demoting the domain controller, and removing it from the domain.

Results

  • File share inventory and audit completed using ShareGate
  • Security groups identified and aligned to SharePoint Online access permissions
  • SharePoint Online document library folder structure configured to match permission model
  • Approximately 3 TB of shared file data migrated to SharePoint Online
  • FSMO roles transferred to another domain controller
  • Printer shares and DHCP migrated to another domain controller
  • Group Policy updated to remove references to the legacy server
  • Legacy Windows Server 2008 R2 domain controller demoted and removed from domain
  • Organization transitioned from legacy file share model to SharePoint Online-based document environment
  • Dependency on aging Windows Server infrastructure reduced
Read Case Study
Hybrid
VMware + Azure File Sync infrastructure delivered
Commercial
Branch Office Infrastructure Modernization

Safari Micro Modernizes Branch Office Infrastructure with VMware and Azure File Sync

Challenge

A distributed operations organization needed to modernize infrastructure at a regional office while improving access to shared business files. The existing environment required a new onsite VMware host to support a Windows File Server virtual machine, and integration with Azure File Sync to align local file services with a cloud-connected storage architecture. The project also required network change support and troubleshooting throughout the deployment.

Approach

Safari Micro delivered a hybrid infrastructure deployment combining onsite virtualization with Microsoft Azure file synchronization. Safari Micro installed and configured a new VMware host to provide a stable local virtualization platform for the regional office, creating the foundation needed to support the Windows File Server VM and future local workloads. Safari Micro assisted with the Windows File Server virtual machine build within the VMware environment, then installed the Azure File Sync agent on the server and configured Azure File Sync in the Azure portal so the regional file server could participate in the organization's broader sync architecture. Network change support and troubleshooting were provided throughout the deployment to ensure the VMware host, Windows File Server VM, and Azure File Sync configuration were properly connected and operational.

Results

  • New VMware host installed and configured at the regional office
  • Windows File Server virtual machine built and operational within the VMware environment
  • Azure File Sync agent installed and configured on the Windows File Server VM
  • Azure File Sync configured in the Azure portal to connect regional file services to the organization's sync architecture
  • Network changes supported and connectivity issues resolved throughout the deployment
  • Regional office transitioned to a hybrid infrastructure model combining local VMware virtualization with Azure-connected file services
Read Case Study
NVIDIA A10
GPU-enabled Azure VMs powering SafariDesktops
Commercial
GPU-Enabled Virtual Desktops — SafariDesktops

GPU-Enabled Virtual Desktops with SafariDesktops

Challenge

An organization needed a virtual desktop platform capable of supporting demanding desktop workloads while maintaining flexibility across different user profiles. A single desktop model would not adequately address every use case — some users required dedicated resources, while others could be supported through optimized multi-session environments. Safari Micro needed to design an approach that could provide GPU-enabled performance for graphics-intensive workloads, flexible host configurations for different user densities, dedicated personal desktop options for heavier users, a scalable managed desktop subscription model, and a balance between performance, efficiency, and operational simplicity.

Approach

Safari Micro proposed SafariDesktops as an onboarding and ongoing managed virtual desktop subscription. The solution included several Azure VM host options using NVIDIA A10 GPU-enabled infrastructure. For shared desktop workloads, Safari Micro designed pooled multi-session host pools using GPU-enabled Azure virtual machines (NV18ads_A10_v5 and NV12ads_A10_v5), allowing multiple users to share the same host environment while benefiting from GPU acceleration. For users with higher or more specialized workload requirements, Safari Micro included dedicated personal desktop options using NV6ads_A10_v5 and NV12ads_A10_v5 virtual machines, providing one user per VM with isolated compute resources for medium and heavy workload profiles. Cloud-only domain service support was provided through Entra Domain Services where needed.

Results

  • Pooled multi-session host pools configured using NVIDIA A10 GPU-enabled Azure VMs for shared workloads
  • Dedicated personal desktop options provided for medium and heavy workload users
  • Multiple host density models supported to align performance with user profile requirements
  • Cloud-only domain service support delivered through Entra Domain Services
  • SafariDesktops managed subscription model established for onboarding and ongoing virtual desktop delivery
  • Modern virtual desktop environment designed to support varied workload profiles with GPU-accelerated performance
Read Case Study
AMD MI25
GPU-enabled managed SafariDesktops for public sector
Public Sector
Managed GPU Virtual Desktops — SafariDesktops

Safari Micro Delivers Managed GPU Virtual Desktops with SafariDesktops

Challenge

A public-sector organization needed a scalable virtual desktop platform capable of supporting more demanding desktop workloads while reducing the day-to-day management burden on internal IT resources. Key requirements included a managed virtual desktop platform with GPU-enabled desktop performance, integration with Microsoft 365 and Active Directory, centralized performance analytics and monitoring, optimized virtual desktop images and applications, connectivity with the organization's existing Azure environment, and user profile persistence across virtual desktop sessions.

Approach

Safari Micro delivered SafariDesktops as a managed virtual desktop service built to support multi-session desktop access, centralized administration, and GPU-backed performance. The solution included ongoing managed virtual desktop support to reduce the internal workload required to operate and maintain the platform, complete desktop management and maintenance including ongoing administration of the SafariDesktops environment, Microsoft 365 and Active Directory integration to align identity and access management across the desktop platform, optimized virtual desktop images and applications for a consistent desktop experience, 30 GB FSLogix user profile containers for profile portability and session consistency, virtual desktop analytics and performance monitoring for visibility into environment health and user experience, and connectivity into the organization's existing Azure environment. The technical environment used N16 multi-session GPU hosts in East US 2 with AMD EPYC 7742 processors (16 vCPU, 2.44 GHz, 56 GB RAM) and 8 GB AMD Instinct MI25 GPU memory.

Results

  • Centralized virtual desktop management delivered by Safari Micro, reducing internal IT administrative burden
  • GPU-backed performance provided for heavier desktop workloads via N16 multi-session hosts with AMD Instinct MI25 GPU
  • Microsoft 365 and Active Directory integration aligned identity, access, and user management across the desktop platform
  • 30 GB FSLogix user profile containers deployed for profile persistence and consistent session experience
  • Optimized virtual desktop images and applications standardized the desktop environment
  • Performance analytics and monitoring provided visibility into environment health and user experience
  • SafariDesktops deployment connected into the organization's existing Azure environment
Read Case Study
5 Users
SafariDesktops pilot deployed for education-sector org
K–12
Secure Virtual Desktop Pilot — SafariDesktops

Secure Virtual Desktop Pilot Deployment for an Education-Sector Organization

Challenge

An education-sector organization needed a controlled virtual desktop environment to support a small pilot group of five users while establishing the technical foundation for future cloud desktop operations. The environment required user access, Windows authentication, profile storage, security configuration, performance visibility, and desktop pool monitoring. Safari Micro's role was to provide the infrastructure configuration and operational setup needed to make the pilot usable, manageable, and supportable from day one.

Approach

Safari Micro configured SafariDesktops for five pilot users and created the supporting Microsoft Azure environment required to host and manage the virtual desktops. The solution included Azure tenant and subscription setup, cloud identity configuration, Azure Active Directory Domain Services for Windows authentication, virtual network creation, cloud-only user account creation, FSLogix Windows profile storage, virtual desktop pool deployment, a Safari-customized Windows 10 desktop image with default optimizations, connection into Safari custom toolsets, custom security configuration, virtual desktop performance monitoring, event monitoring, user assignment to the desktop pool, and pilot user support with ongoing maintenance and updates.

Results

  • Working virtual desktop pool deployed for five pilot users with centralized cloud-based desktop access
  • Windows authentication configured through Azure Active Directory Domain Services
  • User profile management established through FSLogix profile containers
  • Safari-customized Windows 10 desktop image deployed with default optimizations
  • Custom security configuration applied during setup
  • Performance and event monitoring enabled for operational visibility
  • Ongoing desktop pool maintenance, updates, and user support provided
  • Organization gained a structured, low-risk path to evaluate virtual desktops before broader rollout
Read Case Study
3 Workstreams
Server virtualization, SharePoint migration & Azure AD Connect migration delivered
Commercial
File Services Modernization & Microsoft 365 Migration

File Services Modernization and Microsoft 365 Migration

Challenge

The organization relied on an on-premises Windows file share server for business-critical file storage. As collaboration needs evolved, the existing file share model created limitations around accessibility, manageability, and modernization. The environment also required continued identity synchronization between on-premises directory services and Microsoft 365. Azure AD Connect needed to be moved from the existing synchronization server to a newer Windows Server instance. The project required careful coordination to preserve access, maintain synchronization continuity, restructure file organization where needed, and support users through the migration.

Approach

Safari Micro delivered a coordinated modernization approach across three workstreams. For server modernization, the existing physical Windows file share server was converted into a Hyper-V virtual machine using Disk2VHD — system, reserved, and data partitions were converted to VHDX format, moved to Hyper-V hosts, and the new virtual server was created with migrated data disks attached. For the SharePoint Online migration, Safari Micro prepared migration tooling, created destination SharePoint sites and document libraries, mapped permissions from the on-premises file storage environment to SharePoint Online, synchronized files, and completed the cutover — also assisting with file share hierarchy restructuring, permissions restructuring, documentation, training, and post-migration end-user support. For the Azure AD Connect migration, a new Azure AD Connect instance was deployed in staging mode, the existing sync configuration was exported from the current sync client, the new agent was configured, and synchronization was transitioned by placing the previous sync client into staging mode and enabling the new agent for active synchronization.

Results

  • Physical Windows file share server converted into a Hyper-V virtual machine, reducing dependency on physical hardware
  • File share content migrated into SharePoint Online with permissions mapped and restructured for the new collaboration model
  • File share hierarchy restructured and users trained and supported through the transition
  • Azure AD Connect migrated to a newer Windows Server instance with synchronization continuity maintained throughout
  • Organization moved from a legacy physical file share model toward a modern Microsoft 365 collaboration environment
  • Reduced reliance on physical infrastructure, improved collaboration through SharePoint Online, and better alignment with Microsoft 365
Read Case Study
Centralized
Windows Server patch management delivered via WSUS
Commercial
Windows Server Patch Management

Strengthening Windows Server Patch Management with WSUS

Challenge

The organization needed a more reliable way to manage Microsoft updates across its Windows Server environment. Without a properly configured WSUS platform, server patching was inconsistent, harder to control, and difficult to validate across production systems. The organization wanted a centralized update services platform that would provide better control over how server updates are approved, deployed, tested, and validated.

Approach

Safari Micro deployed a new WSUS environment on Windows Server. The engagement began with deployment planning to align the WSUS configuration with the organization's existing infrastructure and server update requirements. Safari Micro installed the WSUS server role and required prerequisites, then configured the WSUS environment including network and firewall connectivity, SSL/HTTPS setup, computer groups, and client-side targeting. Update packages were configured in WSUS and tested before extending to production systems. Group Policy was configured for automatic updates, allowing the existing server environment to use the new WSUS server for centralized update management.

Results

  • New WSUS environment deployed on Windows Server with SSL/HTTPS secure communication
  • Computer grouping and client-side targeting configured for controlled update deployment
  • Update package configuration and deployment testing completed before production rollout
  • Group Policy configured to direct server environment to new WSUS server for automatic updates
  • Production server update validation completed, establishing a tested deployment path
  • Organization gained a more controlled and consistent process for managing Windows Server updates across the environment
Read Case Study

Ready to become a case study?

Start with an IT Assessment and get a clear roadmap to documented outcomes for your organization.

Your Privacy Choices

Safari Micro uses necessary cookies to operate and secure this Website. With your permission, we also use optional analytics and functional technologies to understand Website performance and improve your experience. Safari Micro does not sell personal information or share it for cross-context behavioral advertising.

View our Privacy Policy.