Skip to main content

Capability

What I can take on

Client work stays confidential, so instead of case studies this page sets out the scope I deliver, the scale of environment I work at, and the standard I hold the work to.

Talk about your environmentSee the services

13+Years in ICT
270+Endpoints under management
40+Automations in production
3Countries worked in

Scope

What I deliver end to end

From the first audit through to the handover pack, the whole path, not one slice of it.

🔍

Assess

Audit of what is actually in place, tenant configuration, policies, devices, identities, network and the processes people are really using. Findings written down, not just discussed.

🛠️

Design

A target state and a staged path to it, with the reversible, low-risk work sequenced first and the trade-offs stated plainly so you can make the call.

⚙️

Build

SharePoint architecture, SPFx applications, Power Automate workflows, Intune and Entra policy, network and backup, delivered in versioned stages you can see and test.

💾

Migrate

Email, files, tenants and on-premises environments moved with reconciliation before and after, so nothing quietly goes missing in the process.

🔒

Harden

Endpoint, identity, data and communication controls brought to a known baseline, applied across the whole fleet and measured against the ASD Essential Eight.

📚

Hand over

Manuals, role guides, provisioning scripts, change logs and training, so your team owns the result rather than renting it from me.

Scale

The size of environment I work at

Enterprise-standard practice, sized for organisations that do not have an enterprise IT department.

Environment size

Multi-site organisations of roughly 20 to 300 staff, several hundred managed endpoints and a comparable number of identities, large enough to need real governance, small enough that one person can know the whole estate.

Data volume

List architecture, indexing and reporting designed to stay fast at tens of thousands of records, not demo-sized data sets.

Automation in production

Dozens of scheduled and event-driven workflows running unattended, with timezone-correct scheduling, batching and failure alerting.

Fleet-wide change

Security and update policy applied across whole device fleets in staged rings, with rollback thought through before the first policy is pushed.

Quality

How I know the work is right

Verified before handover

Data reconciliation, duplicate and orphan checks, permission review and audit-trail testing. Nothing is called finished on the strength of it looking right.

📝

Every change logged

Infrastructure and security work is recorded with date, target, old value, new value, method and result, an audit trail your board or funder can read.

🔄

Versioned and reversible

Releases are numbered, change-logged and built so they can be stepped back, rather than shipped as one irreversible cut-over.

💬

Explained in plain language

You get the risk and the trade-off in words you can act on, and documentation written for the people who will actually use the system.

Principles

The same every time

🔒

Inside your tenant

Everything I build runs on the Microsoft 365 tenant you already own. No external database, no third-party platform holding your records.

📝

Documented to survive

Manuals, role guides, version history and change logs are part of the deliverable, not an afterthought.

🤝

Honest scope

If something is not worth doing, or you do not need me for it, I will say so.

Toolkit

What I work with

☁️Microsoft 365 & Collaboration

Microsoft 365Exchange OnlineSharePoint OnlineMicrosoft TeamsOneDriveTenant administrationLicensing & non-profit grants

🧩Power Platform & Development

Power AutomateSharePoint Framework (SPFx)TypeScript & ReactMicrosoft Graph APIPnP PowerShellPowerShellPythonREST APIsMicrosoft Forms

🔑Identity & Access

Microsoft Entra IDConditional AccessMulti-factor authenticationWindows Hello for BusinessPrivileged accessSingle sign-onJoiner / mover / leaver

🔒Security & Compliance

Microsoft DefenderMicrosoft PurviewData loss preventionSensitivity labellingRetention policiesBitLockerASD Essential EightSecurity auditing

📱Endpoint Management

Microsoft IntuneWindows AutopilotWindows AutopatchAndroid & iOS managementWin32 & MSIX packagingCompany PortalCompliance policies

🖥️Cloud & Server

AzureWindows ServerActive DirectoryHybrid identityVirtualisationSAN / NAS storageMigrations

🌐Networks & Connectivity

Ubiquiti UniFiCisco MerakiFortinetRouting & switchingWi-Fi designVPN & remote accessFirewall managementStructured cabling

💾Backup & Continuity

VeeamN-ableCloud backupRestore testingDisaster recoveryBusiness continuity planning

💻Web Development & Content

WordPressElementorHTML, CSS & JavaScriptCloudflareTechnical SEOStructured dataGoogle Search ConsoleGoogle AnalyticsLearnWorldsSCORM authoringSite performance

📞Telephony, AV & Physical

Microsoft Teams PhoneTeams meeting roomsYealink & Poly devicesIP telephonyCCTV & surveillanceAccess control systemsLabel & asset printing

Get started

Let’s talk about your IT

Based in Perth, working across WA and remotely Australia-wide. No obligation, tell me what is slowing your team down and I will tell you honestly whether I can help.

Email [email protected]Call 0404 291 659

© 2026 Waseem Raza Bhatti · Waseem ICT Support & Services · Perth, Western Australia · [email protected]