Skip to main content

IT & Access Control

1. Identity First

We use Entra ID (Azure AD) as our central identity provider.

  • Username: firstname.lastname@thetechdeputies.com
  • MFA: Mandatory for all accounts. No exceptions.
  • SSO: Wherever possible, third-party apps (HubSpot, Zoom) must use "Sign in with Microsoft."

2. Device Management (Intune)

  • BYOD (Bring Your Own Device): Permitted, but must enroll in "Company Portal" to access data.
  • Encryption: BitLocker (Windows) / FileVault (Mac) must be enabled.
  • Updates: OS updates forced within 7 days of release.

3. Access Levels (RBAC)

We assign access based on Roles, not individuals.

RoleM365 LicenseSharePoint AccessHubSpot RoleThinkific RoleZapier Role
Founder/AdminBusiness PremiumGlobal Admin (All)Super AdminSite OwnerOwner
Operations LeadBusiness PremiumEdit (All)Super AdminSite AdminAdmin
Sales RepBusiness StandardRead (Marketing), Edit (Sales)Sales UserView OnlyNone
Fulfillment AgentBusiness StandardEdit (Projects), Read (SOPs)Service UserCourse CreatorNone
ContractorBasic / GuestEdit (Assigned Folder Only)RestrictedNoneNone

Note: Zapier access is restricted to Admin/Ops Lead only.

4. Onboarding Workflow (IT)

Trigger: "Signed Offer Letter" from System 08.

  1. Create User: In M365 Admin Center.
  2. Assign Groups: Add to All Staff, Department Team.
  3. License: Assign M365 Business Premium.
  4. Hardware: Order laptop (if applicable) or send BYOD instructions.
  5. Welcome Email: Send temporary password and "Day 1 Login Guide" to personal email.

5. Offboarding Workflow (IT)

Trigger: "Termination Notice" from System 08.

  1. Immediate: Reset Password. Revoke Sessions.
  2. Access: Block sign-in. Remove from Groups.
  3. Data: Convert mailbox to "Shared Mailbox" (delegate to Manager).
  4. Device: Initiate "Remote Wipe" of company data.

Related Documents: