Beyond the Tenant / Toolkit
The right architecture needs the right tools behind it.
Designing the target state is only part of the job. Enterprise migrations and modernization programs depend on the tools used to discover the environment, move the data, automate repetitive work, validate security, measure progress, and support users through the transition.
This toolkit brings together the platforms, frameworks, utilities, and delivery tools I’ve used across real Microsoft 365 projects. Some are Microsoft-native. Others solve specific problems that native tooling doesn’t. What matters is choosing the tool that fits the requirement — and knowing where it fits in the architecture and delivery plan.
The Architect’s Toolkit
Different problems require different tools.
Filter the toolkit by the same delivery categories I use to organize the tools in the field.
Toolkit Category
Architectural Toolkit
Architecture diagrams, design documentation, matrices, standards, and visual communication
Architecture has to be communicated clearly enough that engineering teams can implement it, stakeholders can understand the decisions, and future operators can support it. Diagrams and frameworks are not the architecture themselves — they are tools for making the architecture explicit, testable, and repeatable.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| Microsoft Visio | Microsoft | Technical architecture | Primary application used to create identity, messaging, migration, security, network, Teams Voice, and solution architecture diagrams. |
| draw.io / diagrams.net | JGraph | Portable architecture diagrams | Used to create system-context, process, logical, physical, integration, and data-flow diagrams without Visio licensing. |
| Azure Architecture Center | Microsoft | Reference architecture | Used to support Azure design patterns and guidance for identity, networking, resiliency, management, security, and governance. |
| Microsoft Cloud Adoption Framework | Microsoft | Cloud transformation structure | Used to organize cloud strategy, planning, readiness, adoption, governance, security, and management. |
| Azure Well-Architected Framework | Microsoft | Architecture assessment | Used to evaluate reliability, security, cost optimization, operational excellence, and performance efficiency. |
Toolkit Category
AI & Copilot Toolkit
AI delivery, governance, data readiness, guardrails, and custom agents
AI tooling is not just about choosing a model. In an enterprise environment, the architecture also has to account for data access, identity, classification, DLP, governance, auditability, and the boundary between experimentation and sanctioned business use.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| Microsoft 365 Copilot | Microsoft | Enterprise productivity AI | Used for Microsoft 365 search, summarization, meeting assistance, content creation, analysis, and organizational knowledge retrieval. |
| Copilot Studio | Microsoft | Custom AI agents | Used to build custom agents, knowledge experiences, actions, and workflow-integrated Copilot solutions. |
| Microsoft Purview DSPM for AI | Microsoft | AI governance | Used to review data-security risks associated with Copilot and other AI usage and support AI governance and readiness assessments. |
| Microsoft Purview DLP | Microsoft | AI guardrails | Used to detect sensitive information and enforce data-handling controls across Microsoft 365 and supported AI experiences. |
| Microsoft Purview Information Protection | Microsoft | Classification for AI readiness | Used to classify and protect organizational information through sensitivity labels, encryption, and access restrictions. |
| Azure OpenAI Service | Microsoft | Custom enterprise AI | Used for organization-controlled generative AI applications hosted through Azure. |
| Azure AI Foundry | Microsoft | AI solution engineering | Used to develop, test, evaluate, govern, and operationalize Azure-based AI applications and agents. |
| OpenAI GPT models | OpenAI | Large language model family | Used through ChatGPT, Microsoft Copilot, Azure OpenAI, and development workflows for reasoning, generation, analysis, and solution prototyping. |
| ChatGPT | OpenAI | General-purpose generative AI | Used for research, drafting, technical exploration, comparison testing, governance assessments, and DLP validation against unmanaged AI applications. |
| ChatGPT Enterprise / Team | OpenAI | Governed organizational AI | Evaluated in AI governance and acceptable-use work as an enterprise alternative requiring formal organizational approval, governance, and data controls. |
| Claude | Anthropic | General-purpose generative AI | Used or evaluated for research, drafting, document-heavy tasks, M365 connector exploration, governance assessments, and DLP validation. |
| Claude Opus | Anthropic | Advanced reasoning LLM | Included as the higher-capability Claude model used or considered for complex reasoning, long-form analysis, architecture work, and difficult technical tasks. |
| Claude Sonnet | Anthropic | Balanced reasoning and productivity LLM | Used or evaluated for general productivity, research, coding, and model selection through Claude and supported Microsoft experiences. |
| Claude Cowork | Anthropic | Agentic productivity | Evaluated for multi-step work execution, local desktop usage, connector scenarios, and comparison with Microsoft Copilot Cowork. |
| Google Gemini | Multimodal generative AI | Used or evaluated for research, content generation, model comparisons, governance controls, and DLP validation against unmanaged AI applications. | |
| Gemini Advanced / Pro / Ultra | Advanced Gemini model access | Used or evaluated for larger-document work, coding, deep research, and access to higher-capability Gemini models. | |
| Gemini Flow | AI video workflow | Used for rapid image-to-video and generative video experimentation through Google Gemini. | |
| Veo | Google DeepMind | Generative video model | Used through Gemini Flow as the video-generation engine for AI video experimentation. |
| NotebookLM | Source-grounded research assistant | Used for source-based study, summarization, research organization, and podcast-style audio overview generation. | |
| Perplexity AI | Perplexity | AI research and search | Used for learning, study, research, answer synthesis, and comparison with Copilot and Claude. |
| DeepSeek | DeepSeek | Reasoning LLM | Evaluated as an external language model during AI-tool comparisons, governance discussions, and model research. |
| Grok | xAI | General-purpose generative AI | Included in comparative reviews of leading AI platforms and model-selection discussions. |
Toolkit Category
Migration Toolkit
Migration, transformation, account movement, profile transition, and data transfer
The migration platform sits directly in the path between the source environment and the target state. The right tool depends on the workload, transformation requirements, identity model, coexistence strategy, and what needs to be validated after the move.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| MigrationWiz | BitTitan | Microsoft 365 tenant migration | Primary platform used to migrate Exchange mailboxes, online archives, OneDrive, Teams, and related Microsoft 365 data between tenants. |
| ShareGate | Workleap | SharePoint, Teams and OneDrive migration | Used for SharePoint and OneDrive migration, permissions handling, content validation, migration reporting, and PowerShell-driven execution. |
| SharePoint Migration Manager | Microsoft | File-share migration | Native Microsoft service used for file-share-to-SharePoint and file-share-to-OneDrive migrations, including scanning, task execution, and validation. |
| Proventeq Content Suite | Proventeq | Complex document migration | Production platform used for CIRO’s eDOCS-to-SharePoint migration, supporting discovery, metadata extraction, transformation, mapping, loading, and error reporting. |
| Active Directory Migration Tool (ADMT) | Microsoft | User, group and computer migration | Used to copy Active Directory users, groups, computers, SID history, and related objects between forests or domains, including Metro’s SCI migration. |
| Password Export Server (PES) | Microsoft | Password migration | Used with ADMT when passwords need to be transferred during an Active Directory cross-forest migration. |
| User Profile Wizard / ProfileWiz | ForensiT | Windows profile migration | Used to associate an existing Windows profile with a new destination-domain account, reducing end-user profile rebuild effort during Metro migrations. |
Toolkit Category
PowerShell Toolkit
Discovery, automation, configuration, remediation, validation, and reporting
PowerShell is the connective tissue across much of Microsoft 365 delivery. I use it for discovery, migration preparation, configuration, remediation, validation, reporting, and repeatable operational processes — especially when the portal cannot provide the complete environment-wide view needed for an architectural decision.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| PowerShell 7 | Microsoft | Project automation | Core scripting environment used for discovery, reporting, migration preparation, configuration, validation, remediation, exports, and recurring processes. |
| Windows PowerShell 5.1 | Microsoft | Legacy module automation | Used where older Active Directory, Exchange, SharePoint, Windows Server, or third-party modules require Windows PowerShell. |
| Microsoft Graph PowerShell SDK | Microsoft | Microsoft 365 automation | Used to query and manage Entra ID users, groups, applications, permissions, devices, Microsoft 365 objects, and reporting data. |
| Exchange Online PowerShell | Microsoft | Exchange configuration and migration | Used for mailbox inventory, permissions, aliases, forwarding, connectors, transport rules, accepted domains, mail flow, and remediation. |
| Microsoft Teams PowerShell | Microsoft | Teams and voice administration | Used for Teams, channels, membership, ownership, Teams Phone, policies, numbers, devices, and migration validation. |
| SharePoint Online Management Shell | Microsoft | SharePoint administration | Used for tenant settings, site inventory, site administrators, storage, sharing, preparation, and post-migration validation. |
| PnP PowerShell | Microsoft 365 Community | Advanced SharePoint automation | Used for sites, libraries, lists, metadata, permissions, inventories, provisioning, and custom remediation. |
| Microsoft Purview PowerShell | Microsoft | Compliance administration | Used for DLP, retention, eDiscovery, compliance searches, labels, audit, and compliance reporting. |
| Active Directory PowerShell Module | Microsoft | Identity discovery and remediation | Used to export, compare, modify, reconcile, and validate users, groups, computers, OUs, attributes, and memberships. |
| Microsoft Intune Graph Automation | Microsoft | Endpoint reporting | Used to obtain device, enrollment, compliance, application, configuration-profile, and endpoint-security information. |
| Azure PowerShell Az Module | Microsoft | Azure automation | Used to administer Azure resources, storage, virtual machines, networking, automation accounts, and identities. |
| Azure Automation | Microsoft | Scheduled automation | Used to run PowerShell-based reports, exports, compliance processes, and administrative tasks on a recurring schedule. |
| Hybrid Runbook Worker | Microsoft | Hybrid automation | Used where Azure Automation requires access to local servers, filesystems, networks, or on-premises services. |
| Visual Studio Code | Microsoft | Script development | Primary editor used to develop and maintain PowerShell, JSON, Microsoft Graph, REST API, and automation code. |
Toolkit Category
Security & Compliance Toolkit
Data protection, threat protection, posture assessment, and secure mail flow
Security validation requires more than checking whether a policy exists. These tools help assess configuration, classify and protect information, investigate threats, validate controls, secure mail flow, measure posture, and understand how third-party security platforms interact with Microsoft 365.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| Microsoft Purview | Microsoft | Data security and compliance | Primary platform used for DLP, classification, encryption, eDiscovery, audit, retention, compliance, and AI governance. |
| Microsoft Purview Information Protection | Microsoft | Classification and protection | Used to implement and migrate sensitivity labels, encryption, document markings, and access controls. |
| Microsoft Purview DLP | Microsoft | Data-loss prevention | Used to protect sensitive information across Exchange, SharePoint, OneDrive, Teams, endpoints, and supported applications. |
| Microsoft Purview eDiscovery | Microsoft | Investigations and exports | Used to define searches, manage cases, review content, export results, and support automated compliance reporting. |
| Microsoft Defender XDR | Microsoft | Unified security operations | Used to correlate and investigate security incidents across identity, endpoint, email, and cloud services. |
| Microsoft Defender for Office 365 | Microsoft | Email security | Used for phishing protection, Safe Links, Safe Attachments, malware protection, investigation, and response. |
| Microsoft Defender for Endpoint | Microsoft | Endpoint security | Used for endpoint detection and response, threat investigation, attack-surface reduction, and device risk. |
| Microsoft Defender for Identity | Microsoft | Identity security | Used to detect attacks and suspicious behavior involving on-premises Active Directory. |
| Microsoft Defender for Cloud Apps | Microsoft | SaaS and AI discovery | Used to discover cloud applications, manage application risk, and review organizational cloud and AI usage. |
| Microsoft Sentinel | Microsoft | SIEM and security analytics | Used to centralize security data, correlate alerts, investigate incidents, and automate response. |
| Proofpoint Email Protection | Proofpoint | Email hygiene and migration mail flow | Used for email filtering, directory synchronization, smart-host routing, tenant consolidation, and complex domain transitions. |
| Cisco IronPort / Cisco Email Security | Cisco | Email security delivery | Used during CIRO and healthcare mail-flow projects for routing, filtering, DKIM, and mail-hygiene transition work. |
| Egress Protect | Egress | Email-encryption migration | Included because the CIRO delivery migrated users from Egress email encryption to Microsoft Purview and Office 365 Message Encryption. |
| CIS Benchmarks | Center for Internet Security | Configuration assessment | Used to evaluate Intune, Windows, Entra ID, Microsoft 365, Exchange, and Defender configurations. |
| ORCA | Microsoft security community | Email-security assessment | Used to assess Exchange Online Protection and Defender for Office 365 configurations. |
| Maester | Microsoft security community | Automated security testing | Used to automate validation of Microsoft 365 and Entra ID security controls. |
| CISA SCuBA | CISA | Microsoft 365 configuration baseline | Used to evaluate Microsoft cloud environments against established secure configuration baselines. |
| CrowdStrike Falcon | CrowdStrike | Endpoint-security integration | Included where its presence affected endpoint compliance, migration dependencies, or Intune configuration. |
| Qualys | Qualys | Vulnerability-management integration | Included where scanning, agents, or vulnerability controls affected endpoint and infrastructure delivery. |
| Zscaler | Zscaler | Zero Trust connectivity | Used in endpoint modernization, application access, SSL bypass, network security, and VPN replacement designs. |
| Azure Key Vault | Microsoft | Secrets and keys | Used to protect application secrets, certificates, automation credentials, and cryptographic keys. |
| Microsoft Priva | Microsoft | Privacy management and risk reduction | Used to identify privacy risks, reduce unnecessary exposure of personal information, support privacy assessments, and strengthen organizational privacy controls across Microsoft 365 data. |
Toolkit Category
Endpoint & Modern Workplace
Provisioning, management, passwordless access, updates, and device migration
A tenant migration does not stop when the mailbox moves. Devices, profiles, authentication methods, application access, update controls, and user identity all have to arrive at a usable end state. Endpoint tooling is what turns a cloud migration into an actual user transition.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| Microsoft Intune | Microsoft | Endpoint delivery | Core platform used to enroll, configure, secure, monitor, and support Windows, iOS, Android, AOSP, and Teams devices. |
| Windows Autopilot | Microsoft | Modern provisioning | Used to deploy replacement and refreshed devices into Entra ID and Intune. |
| Windows Hello for Business | Microsoft | Passwordless implementation | Used for PIN and biometric authentication and to reduce reliance on passwords and repeated MFA prompts. |
| Cloud Kerberos Trust | Microsoft | Hybrid access | Used to allow Windows Hello users to authenticate to supported on-premises resources. |
| Microsoft Entra Join | Microsoft | Cloud device identity | Used to migrate devices from traditional Active Directory join to cloud-native Entra ID join. |
| Microsoft Entra Hybrid Join | Microsoft | Hybrid device identity | Used where devices remain Active Directory joined while integrating with Entra ID and Intune. |
| Microsoft Authenticator | Microsoft | MFA and passwordless access | Used for MFA, passwordless sign-in, number matching, registration, and authentication-method modernization. |
| Company Portal | Microsoft | User-driven enrollment | Used for device registration, compliance, application installation, and remediation. |
| Windows Update for Business | Microsoft | Update management | Used for update rings, feature updates, quality updates, deadlines, and restart controls. |
| Windows LAPS | Microsoft | Local administrator control | Used to rotate and protect local administrator passwords on managed Windows devices. |
| Apple Business Manager | Apple | Apple device onboarding | Used with Intune for automated enrollment of corporate iPhones and iPads. |
| Android Enterprise | Android management | Used with Intune for organizational Android enrollment and application delivery. | |
| ForensiT User Profile Wizard | ForensiT | Existing-profile reassignment | Used in domain migrations where an existing Windows profile needed to be associated with the destination-domain identity. |
Toolkit Category
Reporting & Data Toolkit
Data collection, transformation, repositories, reconciliation, and visualization
Enterprise delivery creates a lot of data: inventories, migration results, errors, security findings, compliance evidence, adoption metrics, and remediation status. The value comes from turning those raw exports into information that architects, engineers, project managers, and leadership can actually use.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| Power BI | Microsoft | Project and operational reporting | Used for migration status, compliance reporting, security dashboards, adoption analytics, remediation tracking, and leadership reporting. |
| Power Query | Microsoft | Data preparation | Used to clean, normalize, combine, and transform exports from Microsoft 365, PowerShell, migration tools, and assessment platforms. |
| Azure SQL Database | Microsoft | Reporting repository | Used or proposed to store normalized and historical reporting information before Power BI presentation. |
| Azure Data Lake Storage | Microsoft | Historical data repository | Used or proposed for large-scale historical compliance, audit, migration, and analytical data. |
Toolkit Category
Service Delivery Toolkit
ITSM, workflow, hypercare, collaboration, and operational transition
Good technical delivery depends on decisions, risks, dependencies, changes, defects, user feedback, and operational ownership being visible. These tools provide the workflow around the architecture — from discovery and RAID tracking through CAB approvals, hypercare, remediation, and handoff to operations.
| Tool | Vendor | Use Case | How it fits in delivery |
|---|---|---|---|
| ServiceNow | ServiceNow | IT service management | Used for incidents, service requests, change records, CAB approvals, hypercare reporting, evidence tracking, and operational handoff. |
| Jira | Atlassian | Technical work tracking | Used or considered for engineering tasks, defects, remediation work, and service integration. |
| Monday.com | monday.com | Project delivery management | Used to track project activities, actions, dependencies, status, and RAID items. |
| Azure DevOps Boards | Microsoft | Technical backlog management | Used for epics, features, user stories, technical tasks, issues, and delivery backlogs. |
| Microsoft Planner | Microsoft | Team task management | Used for lightweight assignments, checklists, owners, due dates, and Teams-integrated work tracking. |
| Microsoft Lists | Microsoft | Structured project tracking | Used for RAID registers, inventories, requests, decisions, issues, and operational trackers. |
| Microsoft Forms | Microsoft | Discovery and surveys | Used to collect structured information about users, applications, devices, file dependencies, voice requirements, and feedback. |
| Power Automate | Microsoft | Delivery workflow automation | Used for notifications, approvals, assignments, scheduled reporting, escalation, and service-delivery workflows. |
Architectural Judgment
Tools support the decision. They don’t make it.
No migration platform, script, framework, or dashboard replaces architectural judgment. The value comes from understanding the environment first, choosing the right tool for the requirement, knowing its limitations, and validating the result against the target state.
These are tools that have earned a place in my delivery toolkit because they solve real problems in real enterprise environments.
