Senior Microsoft Security Architect · Lisbon · Remote worldwide

Microsoft 365 &
Hybrid Infrastructure
Consulting

One senior architect — not a Big-4 pyramid. Evidence-based security assessments, hands-on hardening, and continuous NIS2 readiness for organisations now in scope. The rigour large firms charge six figures for — delivered in days.

View Case Studies
800k+
Mailboxes Migrated
across 64+ Exchange servers
64+
Exchange Servers
modernised and migrated
20+
Subsidiaries
standardised globally
15yrs+
Microsoft Ecosystem
infrastructure, security, identity
228
Evidence-Based Checks
mapped to NIS2, ISO 27001 & CIS

Across 11+ years of enterprise programmes — see career timeline.

Trusted on enterprise-scale programmes

Ericsson
European Commission
Körber
Richemont
Metro Lisboa
Carlos Annes
Solutions Architect Specialising In
Microsoft 365
·
Azure
·
Exchange Online
·
Defender XDR
·
Entra ID
·
Microsoft Sentinel
·
Intune / MEM
·
PowerShell
·
Microsoft 365
·
Azure
·
Exchange Online
·
Defender XDR
·
Entra ID
·
Microsoft Sentinel
·
Intune / MEM
·
PowerShell
·
Packaged Engagements

Defined scope.
Board-grade outcomes.

Fixed-scope, tool-backed engagements — enterprise-grade rigour, delivered in days. Powered by my own assessment engine: 228 evidence-based checks mapped to NIS2 Art. 21(2), ISO 27001 and CIS.

THE STAKES

NIS2 isn’t coming — it’s here. Portugal’s Cybersecurity Legal Framework (Decree-Law 125/2025) took effect on 3 April 2026, transposing the EU NIS2 Directive. It expands the in-scope population from around 1,000 organisations to an estimated 7,000–9,000 — pulling medium and large companies across energy, health, transport, digital infrastructure, manufacturing, food and public administration into a regime most have never faced. The obligations are concrete: risk-management measures, incident reporting on tight deadlines, supply-chain security — and, for the first time, personal, non-delegable accountability for the management body. Non-compliance carries fines up to €10 million or 2% of worldwide turnover. The national authority (CNCS) now expects you to demonstrate your posture with evidence, through the MyCiber platform. “We think we’re secure” is no longer an answer.

WHY ME

Proving NIS2 readiness takes someone who has run this at enterprise scale and delivers it without the overhead — one senior Microsoft architect doing the work personally, start to finish. Every engagement is powered by my own assessment engine — 228 evidence-based checks mapped to NIS2 Art. 21(2), ISO 27001 and CIS — so you get audit-grade rigour, delivered in days. And nothing is invented: every finding is backed by collected evidence, and anything that couldn’t be assessed is stated plainly — never dressed up as a pass.

01
Assess
know where you stand
  • M365 & Azure Security Assessment
  • App & AI Agent Posture Assessment
  • NIS2 Readiness Assessment
02
Remediate
close the gaps
  • Hardening & Remediation Sprint
03
Sustain
hold the position
  • Managed Security Posture & vCISO Retainer
One-time

M365 & Azure Security Assessment

Know your exposure before an attacker does.

A structured, evidence-based security assessment of your Microsoft 365 tenant and/or Azure environment — delivered in days, not months. Powered by a purpose-built assessment engine that runs 228 curated security checks against your environment. Every check is mapped to NIS2 Article 21(2) and CIS Controls, with ISO/IEC 27001 correspondence via the official ENISA mapping — and to Portugal’s QNRCS v2 and Anexo III (Regulamento 756/2026). You receive a complete, reproducible evidence pack — not a checklist, not an interview report.

From€1,950

Microsoft 365 — with Azure identity and RBAC coverage included

What’s included
  • A — Executive Board Summary (Word + HTML, EN + PT)
  • B — Technical Findings & Gap Analysis (Word, EN + PT)
  • C — Evidence & Status Tracker
  • D — Compliance Crosswalk (NIS2 · ISO 27001 · CIS)
  • E — Exports & Limitations Record
How the engagement runs
  1. 0130-minute scoping call
  2. 02You grant read-only delegated access to the tenant
  3. 03The engine collects evidence and runs the 228 checks
  4. 04I validate every finding and write the reports
  5. 05Findings walkthrough call
Why it matters

Regulators don’t accept “we think we’re secure.” Under NIS2, organisations must demonstrate posture with evidence. This gives your CISO and board a defensible, framework-mapped view of where you stand and what must change.

What you provide
  • Read-only delegated access to the tenant
  • One 30-minute scoping call

Express — €750: essential M365 posture check, HTML dashboard + findings CSV (no board pack, no Anexo III gap table, no remediation runbook).

One-time

App & AI Agent Posture Assessment

Every app and agent with access to your tenant is an attack path you can’t see.

A focused variant of the security assessment, aimed at the application and identity layer of your Microsoft 365 tenant — OAuth app and service-principal permissions, risky and over-privileged grants, dormant and expired credentials, ownerless apps, and user-consent governance. Surfaces the third-party and internal apps quietly holding access to your data, ranked by risk and mapped to NIS2 Art.21(2)(d) supply-chain security and ISO 27001. AI-agent posture (Copilot and declarative agents and their connectors) is an emerging extension of this assessment, with coverage expanding as the platform’s governance surface stabilises.

Contact for pricing
What’s included
  • App & service-principal risk register
  • Consent-grant and permission inventory
  • Prioritised remediation
  • The same evidence-pack format as the security assessment
How the engagement runs
  1. 0130-minute scoping call
  2. 02You grant read-only delegated access to the tenant
  3. 03The engine inventories every app, grant and service principal
  4. 04I validate and rank the findings by risk
  5. 05Findings walkthrough call
What you provide
  • Read-only delegated access to the tenant
  • One 30-minute scoping call
Project

Hardening & Remediation Sprint

Close the gaps. No surprises. No downtime.

Assessment found the gaps — now we fix them. This engagement takes the findings from your security assessment and implements the remediations with full architecture analysis and a staged rollout plan, so there is zero business interruption. Every change is documented, tested, and delivered with rollback procedures.

Contact for pricing

Scoped from your assessment findings.

What’s included
  • All reports from the Assessment (A–E)
  • Remediation roadmap with phased implementation
  • Architecture analysis and change-impact review
  • Conditional Access baseline (MFA, compliant device, location policies)
  • PIM for privileged Entra ID roles — zero standing admin
  • Legacy authentication eradication
  • Defender XDR / endpoint hardening
  • Operational runbook + rollback procedures
How the engagement runs
  1. 01Review findings (ours or yours)
  2. 02Architecture & change-impact analysis
  3. 03Phased, tested rollout — with rollback at every step
  4. 04Documentation & operational runbook handover
Why it matters

Most organisations find gaps and then lose momentum — no clear owner, no safe sequencing, no rollback plan. This sprint delivers full closure: from finding to fixed, with evidence at every step.

What you provide
  • A prior assessment (ours or yours)
  • Change-window alignment
  • A technical point of contact
One-time

NIS2 Readiness Assessment

NIS2 is in force. Are you ready — or guessing?

A focused readiness assessment aligned to the EU NIS2 Directive and Portugal’s Cybersecurity Legal Framework (Decree-Law 125/2025, in force since April 2026), built for organisations that must now evidence their security posture to regulators, auditors or their own board. Goes beyond the standard posture assessment with explicit NIS2 measure-area mapping and board-ready executive deliverables.

Contact for pricing
What’s included
  • Everything in the Security Assessment (A–E), plus:
  • Executive Risk Summary — 1-page Red/Amber/Green board brief
  • Microsoft Secure Score gap analysis — current vs. achievable, with the highest-impact actions
  • NIS2 Art.21(2) readiness crosswalk — measure-by-measure, with ISO 27001 and CIS control references
  • Privileged Access Risk Snapshot — over-privileged accounts, stale admins, MFA gaps
  • Incident-handling readiness — detection, audit-logging and reporting configuration (NIS2 measure B), governance gaps flagged
How the engagement runs
  1. 0130-minute scoping call
  2. 02You grant read-only delegated access to the tenant
  3. 03The engine runs the 228 checks and builds the NIS2 measure-area crosswalk
  4. 04I validate findings and write the board brief + technical crosswalk
  5. 05Findings walkthrough call
Why it matters

NIS2 applies to a broad range of sectors in Portugal and the EU, and board liability is non-delegable. This assessment tells you, in board-ready terms, where your technical readiness stands and what to address before an audit or incident.

What you provide
  • Read-only delegated access to the tenant
  • One 30-minute scoping call

Technical readiness assessment — not legal advice.

→ Continue with the Managed Security Posture & vCISO Retainer
Most popular
Recurring

Managed Security Posture & vCISO Retainer

Security and compliance aren’t projects. They’re a state you have to hold — month after month.

A recurring engagement that keeps your Microsoft 365 and Azure environment continuously assessed, hardened and audit-ready — and holds the cybersecurity-officer function NIS2 requires. The assessment engine re-runs on an agreed cadence; we maintain your roadmap, run incident reporting, and report to your board. Choose the level of support that fits your obligations and internal capacity.

Contact for pricing
What’s included
  • Full re-run of the assessment engine
  • Drift report ranked by severity
  • Updated NIS2 Art.21(2) / ISO 27001 / CIS readiness crosswalk
  • Prioritised remediation guidance
  • Implementation support for agreed remediations
  • Advisory access between cycles
How the engagement runs
  1. 01NIS2 Readiness baseline (gaps + roadmap)
  2. 02Engine re-runs on the agreed cadence
  3. 03Drift report + board reporting + incident support
  4. 04Advisory access between cycles
Why it matters

NIS2 compliance is continuous, board liability is non-delegable, and your tenant drifts with every new user, app and config. A one-time assessment is a snapshot; this is a held position — so your board report is always current, your officer function is covered, and your exposure never silently grows.

How we start

How we start: a fixed-scope NIS2 Readiness Assessment establishes your gaps and roadmap; the retainer executes it and keeps you ready. Begin with a 3-month pilot or an annual plan.

Compliance Keeper
approx. 8–12 h / mo
From€1,200 / mo

Mid-sized entities maintaining compliance with lean internal IT. Quarterly posture re-check, roadmap & core policies maintained, incident playbook + quarterly board report.

★ Most chosen
Security Officer
approx. 16–24 h / mo
From€2,800 / mo

Entities that need someone holding the officer seat. Monthly monitoring, risk register & incident reporting (24h/72h/30-day); Cybersecurity Officer support & 24/7 contact-point coordination — you appoint and notify the officer, we provide the capability behind the seat; supplier reviews + monthly & quarterly board reporting.

Security Partner
approx. 32–48 h / mo
From€6,000 / mo

Larger, regulated or audit-facing organisations. Dedicated officer capacity & ISMS toward ISO 27001, incident leadership + tabletop exercises, audit support, multi-framework (NIS2 + ISO 27001 + DORA where relevant).

Technical readiness service — not legal advice.

The deliverable

See exactly what the assessment delivers.

Board summary, technical findings, compliance crosswalks and a remediation roadmap — built from evidence collected directly from your tenant. See the reports and a live sample.

See how it works
Executive Board Summary
Executive Board Summary
Findings & Gap Analysis
Findings & Gap Analysis
Zero Trust Maturity
Zero Trust Maturity
Bespoke Consulting

What I Deliver

Microsoft 365 and hybrid infrastructure is mission-critical — and most organisations are running it under-secured, under-documented, and under-governed. We fix that. TakeItToCloud delivers specialist consulting across the full M365 and hybrid stack: from security assessments and compliance evidence to migrations, hardening, identity architecture, and ongoing managed support. Every engagement is scoped, evidence-based, and handed over with documentation your team can actually use. Choose the service that fits where you are. We'll take it from there.

Proven Results

Case Studies

Real enterprise engagements. Problem → Architecture → Implementation → Results.

Senior Microsoft Architect

Carlos Annes

Microsoft 365 · Hybrid Identity · Infrastructure · Lisbon, Portugal

Carlos Annes
Carlos Annes
Senior Microsoft Architect
Lisbon, Portugal · Remote worldwide

Microsoft infrastructure architect specialising in hybrid identity, security architecture, and large-scale Microsoft 365 migrations. Based in Lisbon, delivering remote-first engagements to enterprise organisations across Europe.

Enterprise programs delivered for Ericsson, the European Commission, Metro Lisboa, and Körber — covering security transformation, hybrid identity architecture, and global tenant standardisation. Prior to independent consulting, served as O365 and Exchange Support Engineer at Microsoft.

Core Expertise
Hybrid Identity ArchitectureMicrosoft 365 Security ProgramsExchange Hybrid & MigrationsEndpoint Security & IntuneZero Trust ArchitectureIdentity Governance & PIMMicrosoft Sentinel & Defender XDRInfrastructure Architecture
Career Timeline
Apr 2023 – Early 2026
Ericsson
Microsoft Defender XDR Program
15k+ endpoints · Zero Standing Admin · Evidence pack
Jan – Apr 2023
Metro Lisboa
Exchange Migration & Hybrid
Exchange 2019 hybridised · PKI rebuilt · Zero mail loss
Aug 2022 – Jan 2023
Richemont
Exchange Hybrid Architecture
Hybrid architecture delivered · Multi-national scope
Jun 2021 – Jul 2022
Körber
Intune & Defender Rollout
20+ subsidiaries standardised · Legacy AV replaced
Nov 2018 – May 2021
European Commission
Team Lead — Exchange & Skype Platform
40k-user platform · Exchange Hybrid · PKI operations
Jan 2016 – Oct 2018
Microsoft
O365 / Exchange Support Engineer
Enterprise escalation · KB authoring · Hybrid troubleshooting
Jan 2015 – Dec 2015
European Patent Office
Messaging & Lync Admin
Lync deployed · SIP/VoIP · Pan-European scope
Client Feedback

What Clients Say

Carlos brought a level of architecture rigour we rarely see from external consultants. Every change was documented, every rollback was pre-tested. We went from a fragmented endpoint estate to a fully enforced Zero Trust posture — with zero disruption to the business.

Security Program Lead
Ericsson · Defender XDR Program · 15k+ endpoints · 2023

The Exchange 2019 deployment was the cleanest infrastructure project we have run in years. Zero mail loss on cutover, PKI rebuilt end-to-end, and a full handover runbook our team could actually use the next day.

IT Infrastructure Manager
Metro Lisboa · Exchange Migration · Zero mail loss · 2023

Standardising Intune and Defender across 20+ subsidiaries is the kind of project that usually takes 18 months and three vendors. Carlos scoped it, delivered it in sprints, and left runbooks that our subsidiary IT teams could follow independently.

Group IT Director
Körber · Intune & Defender · 20+ subsidiaries · 2022
Start a Conversation

Ready to modernise your
Microsoft environment?

Book a no-obligation discovery call. I'll review your current setup, identify quick wins, and outline a structured engagement with defined outcomes — before any contract is signed.

No commitment required · Remote delivery · within one business day

CA
Carlos Annes
Senior Microsoft Architect
Lisbon, Portugal · Remote worldwide
Available for new engagements
carlos.annes@takeittocloud.com