Skip to content
HAFN
Phase 2 · Managed Service
The situation

Microsoft 365 tenants drift: settings change, permissions grow uncontrolled, guest accounts stay active. What was once secure eventually is no longer — often unnoticed.

HAFN BETRIEB
WORKPLACE.

Building a secure environment is the first step — keeping it secure for the long term is the decisive one. With the HAFN Standard we set up your Microsoft 365 environment to defined security requirements: access policies, identity management, email hardening, devices. In HAFN Betrieb Workplace (our managed service) we make sure this standard does not just hold once, but holds every day. In concrete terms this happens through **Tenant Administration**, which continuously manages your users, licences, groups and access rights — and through **Managed Workplace**, which permanently monitors, provisions and keeps your devices up to date. Both services are organised as monthly-bookable building blocks — clearly defined, transparently reported, adjustable at any time.

SERVICE MODULES

You book what you need

The services are organised into modular service modules. Combinable, scalable, cancellable monthly. Each module has clearly defined contents — no grey areas, no debates.

Tenant Administration

Ongoing management of your M365 users and services: creating and removing accounts, licences, groups, shared mailboxes, Teams and enterprise applications in Entra ID. A monthly transparent report on accounts, licences and costs.

Managed Workplace

Full operational management of your devices with Intune. Onboarding/offboarding via Windows Autopilot, update monitoring, packaging, compliance status, device performance, BitLocker keys. Windows Pro/Enterprise, iOS, macOS and Android.

M365 Backup Administration

Daily checks of backup status and errors, storage-requirement analysis, a quarterly documented test restore. Restore on request included.

Workplace Governance

Monthly transparency: risk matrix, active and orphaned guest accounts, external users without active permissions, anonymous and sensitive links, oversharing structures. The decisive step towards secure AI use.

TECHNOLOGY BASE

HAFN Standard Powered by AvePoint

In the background we monitor all customer tenants centrally — configuration drift is detected automatically before it becomes a problem.

This is the assurance that defines HAFN Betrieb: your environment stays exactly as we set it up together.

DIFFERENTIATION

What sets HAFN Betrieb Workplace apart

Dedicated contacts

dedicated contacts, no chaos over who is responsible.

Transparent monthly reporting

You see what we do — traceable and documented.

Automated drift detection

Configuration drift is detected before it becomes a problem.

AI readiness as an ongoing state

Not as a one-off project, but as continuous care.

Modular service modules

You pay only for what you really need.

Service framework

Response times & support

With an active service module, defined response times apply. Service hours: Mon–Fri 09:00–17:00. Optionally bookable: 3rd-level support with an extended service window.

ONE PARTNER, ONE COURSE

Your course into secure operation

HAFN Betrieb Workplace always follows on from HAFN Standard Workplace. Once you have implemented to the HAFN Standard, you can move straight into operation — without handover friction, without a new ramp-up.