Case Study

Secure, cloud-first IT for a London creative agency operating across three continents.

A digital marketing agency — Creative — London, New York & Johannesburg — 85 users

The client is a fast-moving digital marketing agency headquartered in London's creative sector, with 85 users spread across three offices — London, New York and Johannesburg. Creative agencies live and die by their speed, their brand reputation and the security of client work, and this one had outgrown a patchwork setup that couldn't keep pace with a business operating across three continents and time zones. iTVerse rebuilt their IT on a secure, cloud-first Microsoft 365 foundation — identity-first, device-managed, and consistent whether a designer logs in from Soho, Manhattan or Sandton. The result is a genuinely borderless setup: one secure identity per person, governed devices everywhere, and IT that gets out of the creative team's way.

This project was built on the Microsoft 365 Business Premium security stack with Entra ID at the core. For deeper detail on the technology, see our dedicated M365 resource at m365powered.com.

IndustryDigital Marketing / Creative
LocationLondon, New York & Johannesburg
Headcount85 users
SolutionMicrosoft 365, Entra ID, Intune, Conditional Access
🌍

Three offices, three time zones

London, New York and Johannesburg all running slightly differently, with no consistent identity, policy or support model tying them together. Onboarding a new hire meant different steps in every location.

💻

Unmanaged devices

Designers and account teams on a mix of personal and company machines, none enrolled or compliance-checked. A lost laptop full of client creative was a real, unmitigated risk.

🔓

No MFA, no Conditional Access

Single-factor sign-in across the agency. No device compliance, no location or risk-based policies. A phished password from any office was an open door to client work everywhere.

🗂

Scattered files & brand assets

Client work spread across local drives, personal cloud accounts and email. Version confusion, no single source of truth, and a headache every time a freelancer needed access.

🚪

Leavers retaining access

No automated joiner-mover-leaver. Contractors and former staff kept access to mailboxes and files for weeks — a serious exposure for a business built on client confidentiality.

Identity & access

  • Entra ID deployed as the single source of truth for every user, across all three offices
  • MFA enforced on every account, no exceptions
  • Conditional Access baselined — device compliance, sign-in risk, per-location and per-role policy
  • Legacy authentication blocked tenant-wide

Cloud-first Microsoft 365

  • Files consolidated into SharePoint and OneDrive — one secure home for client work and brand assets
  • Version history and controlled external sharing for freelancers and clients
  • Email, Teams and collaboration standardised across London, New York and Johannesburg
  • No more local drives or personal cloud accounts holding client creative

Device management everywhere

  • Intune rolled out across laptops and phones in all three offices
  • Compliance policies enforced before any device can reach client data
  • BitLocker / FileVault encryption enforced estate-wide
  • Microsoft Defender for Endpoint deployed as standard

Joiner-mover-leaver

  • Consistent onboarding for every location — a new hire in Johannesburg is set up exactly like one in Soho
  • Leavers disabled promptly — access revoked, device wiped, mailbox archived
  • Movers' access updated by role change
  • Contractors and freelancers granted scoped, time-limited access

Borderless collaboration

  • One consistent, secure experience whether logging in from London, Manhattan or Sandton
  • Follow-the-sun working supported without follow-the-sun security gaps
  • Client work accessible to the right people, protected from everyone else
  • Time-zone-aware support coverage

Fully managed, one partner

  • A single IT partner across all three continents rather than a provider per office
  • Consistent policy and visibility everywhere
  • Proactive monitoring and patching built into the managed service
  • Security posture aligned to Cyber Essentials principles throughout

One agency, three continents

London, New York and Johannesburg run on one consistent, secure Microsoft 365 platform. A user is a user, wherever they sit.

Client work secured

All creative and client files live in governed SharePoint and OneDrive — encrypted, versioned, and shareable without losing control.

Every device managed

Intune enrolment and compliance across all three offices. A lost laptop is a remote wipe, not a client-data breach.

MFA everywhere

Multi-factor and Conditional Access on every account. A phished password no longer opens the door to the agency's work.

Onboarding in minutes

New hires and freelancers provisioned consistently in any office, with exactly the right access from day one and none after they leave.

IT that gets out of the way

A single managed partner, proactive support across time zones, and a creative team free to focus on the work — not the tech.

Could we do this for your agency?

We deliver secure, cloud-first IT for London agencies — and their offices worldwide.

Secure, cloud-first Microsoft 365 for creative and marketing agencies — identity-first architecture, Intune-managed devices, governed client files, and consistent security across every office, in any country. Trusted by London firms without London agency overheads.

M365 Powered

Microsoft 365 security in detail

This case study covers the high-level approach. For deeper technical resources on Conditional Access, Intune device compliance and Microsoft Defender — the tools used here — see our sister site m365powered.com.

Visit m365powered.com ↗

Want to see more?

Browse our full list of case studies covering construction, legal, manufacturing, membership organisations and more.

All case studies Book a free IT review

Independently reviewed by our customers