Corbel · Denver, Colorado

The IT foundation enterprises take for granted.

You don't need a bigger IT department. You need the architecture, process, and governance that make the one you have run like it's ten times the size.

Intune · Entra ID · Conditional Access · Defender · Purview

Who this is for

Companies that outgrew their IT before they outgrew their headcount.

Roughly 100 to 2,000 seats, Microsoft 365, and a reason the current setup isn't good enough anymore. Usually one of these four.

Companies under new ownership

You just closed. The board wants an IT posture that survives the next diligence, and the incumbent MSP's answer is a bigger invoice. We build the tenant, identity, and endpoint foundation the next buyer will audit, and document it so it holds up when someone who isn't us reads it.

Mid-market companies with a small IT team

Two to five people who know the business cold but have never designed a Microsoft tenant from scratch. We do the architecture and the standard. They run it. No dependency on us, by design.

Companies that just failed something

A pen test, a cyber insurance questionnaire, a customer security review, a red team. Findings get closed properly, in production, with evidence. Not patched over until the next assessment surfaces the same gap.

Companies leaving their MSP

Getting off an incumbent means CSP transfer, identity cleanup, agent replacement, and a help desk that works on day one. We've run that cutover end to end, including the parts the incumbent doesn't make easy.

Services

Three disciplines. One team accountable for all of them.

Microsoft 365 architecture

The tenant, identity, and endpoint architecture enterprises run on: Entra ID, Intune, Conditional Access, built right the first time instead of patched together over five years. Every decision documented, every policy justified, so the next person who touches it understands why it's built the way it is.

  • Entra ID design: Conditional Access, just-in-time admin, no standing Global Admin
  • Intune and Autopilot from zero-touch provisioning to compliance gating
  • Licensing standardized by role: Business Premium, E3, F3, F1, and what each actually needs
  • Apple Business Manager and iOS MDM, with BYOD on app protection instead of full enrollment

Security and hardening

Defender, WDAC, attack surface reduction, and the kind of configuration that turns a real audit or pen test into a formality instead of a scramble. Findings get remediated once, properly, not patched over until the next assessment surfaces the same gap.

  • Defender for Endpoint P2, attack surface reduction, WDAC, network protection in block mode
  • Defender for Office 365: admin-only quarantine, Safe Attachments, impersonation controls
  • Purview retention and DLP, including finding the policy that's silently blocking your cleanup
  • Pen test and red team remediation in production, with evidence, without breaking the business

Process and governance

Documentation, change control, and operational standards that mean your systems outlast any one person, including whoever is in the room today. The goal isn't dependency on Corbel, it's a foundation your team can actually own and run.

  • Change control and a written standard for every tenant setting, with the reason behind it
  • A knowledge base your team actually uses, not a wiki nobody opens
  • A help desk with categories, SLAs, and reporting from day one, on a platform your team can run
  • Joiner, mover, leaver process tied to HR and reconciled against the census

Co-managed IT and tooling

The stack we run, licensed through Corbel and deployed into your tenant. We own the standards, the vendors, and the escalations. Your team owns the day to day.

  • RMM and tenant backup, run to a written standard and reported every cycle
  • Third-party patching inside a defined window, not assumed
  • 24x7 managed detection and response layered on Defender, with a human on the other end
  • Email security, DNS filtering on Windows and iOS, and a password manager with SSO, deployed once and run for you

Licensing, hardware, and cost

Microsoft CSP licensing, hardware procurement, and the cost analysis nobody else bothers to do before you renew.

  • CSP transfer away from your incumbent without a lapse in service
  • Licensing bands by job title, with Business Basic and orphaned SKUs retired
  • Laptop fleet refresh: tiered specs, vPro as the floor, Autopilot-registered from the factory
  • Azure and SIEM spend modeled from your own cost exports before you sign anything

Transitions and integrations

Acquisitions, carve-outs, and MSP exits. The work between signing and stable, run by people who have done the cutover and know where it breaks.

  • Tenant-to-tenant and identity consolidation for acquisitions
  • Cutover off an incumbent MSP: identities removed, agents replaced, help desk live before the old contract ends
  • Mobile migration off legacy or carrier MDM into Intune and Apple Business Manager
  • A written handoff so your team runs it without us in the room

Need it to stay run, not just built?

Most engagements continue as an architecture retainer or a co-managed IT arrangement. We own the architecture, the standards, and the escalations. Your team owns the day to day. No help desk to babysit, no vendor relearning your environment every quarter.

The standard

Every environment we run meets this baseline. Yours will too.

This isn't a menu. It's the floor. Most of it is a Microsoft 365 setting that has been sitting unconfigured since your tenant was created.

MFA on every account. Phishing-resistant methods for every admin.

No standing Global Admin. Privileged roles are activated just in time, and the break-glass account is tested, not just created.

Conditional Access gates every sign-in on device compliance, not just a password.

Every Windows device Autopilot-registered, Intune-managed, and encrypted with recovery keys escrowed.

Defender for Endpoint in block mode with attack surface reduction rules deployed. Not left in audit mode forever.

Phishing, spoof, and malware quarantines are admin-release only. Users don't self-release the thing that got them breached last time.

Third-party patching inside a defined window, reported every cycle. Not assumed.

24x7 managed detection and response with a human on the other end, plus backup of the tenant itself.

DNS filtering on every endpoint, corporate iPhones included.

A password manager with SSO, so "it's in a spreadsheet" stops being the answer.

Joiners, movers, and leavers reconciled against HR every cycle. Nobody who left in March still has a mailbox in June.

Every setting above written down, with the reason it's set that way, in a knowledge base your team actually opens.

Why Corbel

The engineers who scope your environment are the engineers who build it.

Corbel is a senior team of Microsoft engineers, led by founder Josh Westbrook, with a decade of building and hardening environments across enterprise, federal, and MSP work, including infrastructure where the standards were non-negotiable and the deadlines didn't move. There's no account layer here and no bench of juniors learning on your dime. Every engagement is staffed by people who have already done this at a scale most consultancies have only read about.

Josh Westbrook, Founder

  • Intune, Autopilot, and Entra ID from 200 to 20,000 endpoints
  • Conditional Access and zero trust designs that survive contact with production
  • Defender, WDAC, and attack surface reduction in audited environments
  • Purview, documentation, and change control that outlast any one person
  • Federal-grade standards, applied to companies that can't afford a federal-sized team

How it works

What happens when you reach out

01

A short call

We talk through what's actually going on in your environment and whether it's a fit, both ways.

02

A real scope

You get a defined plan and a start date, not a vague retainer or a drawn-out sales cycle.

03

Direct work, start to finish

No hand-offs, no ramp-up time, no one relearning your environment from scratch.

Engagement models

Three ways to work together. No hourly meter.

Fixed scope

Assessment

Two to three weeks, fixed fee. You get a findings report ranked by risk, a licensing and cost review against what you actually use, and a prioritized plan your team or ours can execute. Useful before a renewal, an acquisition, or a security review.

Monthly capacity

Architecture retainer

A fixed monthly capacity for design, build, and escalation. Tenant, identity, endpoint, and security architecture built to the standard above, with your team trained to run it. Scope and hours defined up front, not discovered on the invoice.

Retainer plus tooling

Co-managed IT

Everything in the retainer, plus the tool stack licensed through Corbel and deployed into your environment. We hold the standards, the vendors, and the escalations. Your team holds the help desk and the day to day.

Rates depend on scope. You'll hear the number on the first call, not after a paid discovery phase.

Built to the same rigor as environments where failure wasn't an option.

10 yearsBuilding Microsoft environments across enterprise, federal, and MSP work
20,000+Endpoints architected and secured
0Account managers between you and the engineers doing the work

Recent work

A mid-market company under new ownership, from incumbent MSP to an in-house team that runs its own tenant.

500+Employees, every account reconciled against the HR census
400+Windows endpoints, Autopilot-provisioned and Intune-managed
4Licensing bands, down from a pile of SKUs nobody could explain
16Knowledge base articles written for the internal team

A few hundred employees, a Windows fleet, a corporate iPhone fleet, and a security posture the new ownership group wasn't comfortable signing off on. The incumbent MSP owned the tenant, the licensing, the network, and the knowledge. Ownership wanted IT that could stand on its own.

  • Tenant-wide security standard configured and enforced: admin-only quarantine, aggressive phishing thresholds, Safe Attachments, Conditional Access, device compliance, personal-device enrollment locked down.
  • Licensing standardized into bands by job title, orphaned SKUs retired, and the CSP relationship moved off the incumbent.
  • Corporate iPhones moved onto Apple Business Manager and Intune, DNS filtering pushed to iOS, BYOD scoped to app protection instead of full enrollment.
  • Password management rolled out with SSO, a knowledge base written for the internal team, and a help desk stood up for them to run.
  • Azure spend modeled from the raw cost exports to show what a SIEM displacement actually saves, and a tenant-wide retention policy found that had been silently blocking cleanup for years.
  • Board-level reporting on tooling, spend, and AI exposure, because boards ask for that now.

End state: their own IT team runs it, on a documented standard, with Corbel holding the architecture and the escalations. Not a bigger invoice. A smaller dependency.

Built on Microsoft

The platform is Microsoft. The tooling around it is chosen, not sold.

Everything above runs on the Microsoft stack your licensing already pays for. The operations and security tooling underneath it is selected by us, licensed through Corbel, and walked through on the first call. If you already run something, we'll tell you whether it's worth keeping.

Microsoft

IntuneEntra IDWindows AutopilotConditional AccessDefender for EndpointDefender for Office 365PurviewWindows AutopatchTeams VoiceApple Business ManagerPowerShell and Graph APIAzure

Questions we get on the first call

Straight answers, so the call can be about your environment.

Do you replace our MSP?

Sometimes. More often we sit above one: we own the architecture and the standard, they work the tickets. If the MSP is the problem, we'll say so on the first call, and we've run the exit before.

What size company is this for?

Roughly 100 to 2,000 seats. Below that you probably don't need us. Above that you have a department whose full-time job this is, and Corbel is usually brought in as a second opinion or for a specific build.

Do we need Microsoft 365 E5?

Almost never to start. Business Premium or E3 with Defender for Endpoint P2 covers the baseline above for most companies. We'll tell you when E5 actually earns its price, and we sell licensing, so we have no reason to talk you out of it if you need it.

Who actually does the work?

A named lead engineer and the Corbel team behind them. The architecture, the design, and every decision sit with the same people from the first call to the handoff. Volume work like help desk coverage or a fleet rollout is staffed by Corbel engineers under Corbel's scope and standard, never subcontracted out to a bench you've never met. You always know exactly who is in your tenant.

What does "documented" actually mean?

A knowledge base your team reads, a written standard for every tenant setting with the reason behind it, and a change log. The test: if we disappeared tomorrow, the next person would understand why it's built this way and could keep running it.

Do you sell licensing and hardware?

Both. Microsoft CSP licensing and hardware procurement, with the margin disclosed. We'll also recommend against buying when you don't need to, which is most of the value.

Contact

Let's talk.

Every environment is different, and the right engagement depends on what's actually going on in yours. Send a note with what you're seeing and you'll hear back within one business day.

josh@westbrook365.com
Denver, Colorado

What are you reaching out about?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.