The cloud, identity, email, and access under your business, cleaned up or moved, for a fixed price.
Google Workspace and Microsoft 365 admin, tenant and email migrations, connected apps and OAuth, DNS and mail authentication, cloud moves. Read-only inventory first, approved fixes second, a written report with evidence at the end. Automation built on a mess inherits the mess, so this is often the first job.
from$1,500 USD
Typically $1,500 to $6,000. Migrations from $3,000. What moves it: the number of users and systems, and how narrow the downtime window has to be.
What this covers
The infrastructure a business actually runs on. Each item is scoped on its own or bundled, with one price.
Google Workspace and Microsoft 365 access cleanup
Admin roles, groups, shared drives and SharePoint, licenses, and the accounts of people who left. An inventory of who can reach what, then the fixes you approve, then an access map that matches the org chart.
Offboarding gaps
Former staff and contractors with live sessions, forwarding rules, app passwords, or ownership of files and automations. Found, closed, and a checklist left behind so it stays closed. Start with the offboarding gap checklist.
Connected apps and OAuth
Every third-party app, service account, API key, and automation token with access to your tenant, listed with what it can do and when it was last used. Stale and over-scoped grants removed. See the connected-app review guide.
Email and tenant migrations
Mailboxes, drives, and domains moved between Google Workspace, Microsoft 365, or a legacy host, with SPF, DKIM, and DMARC set up correctly on the way. A stated downtime window, and mail flow verified before the old system is turned off.
Cloud moves
Applications and databases moved between hosts: cutover plans, SSL and DNS, replication, and load balancing, with the downtime agreed in writing before it happens.
The ground under an agent
Before an agent build, the accounts it will use, the scopes it will hold, and the secrets it will need are set up properly, so the build starts on solid ground.
How infrastructure work runs
Two phases, both in writing, so nothing changes in your systems that you did not approve.
- Phase one, read-only: inventory of users, roles, groups, drives, licenses, connected apps, mail authentication, and the automations that depend on them. Nothing is changed.
- The report: every finding with evidence, ranked, with the fix and the risk of leaving it. The report is the product; read one before you buy.
- Phase two, approved fixes: only what you approved, in the order agreed, with a change log you can hand to anyone.
- Handoff: the access map, the checklist for keeping it clean, and the credentials back in your hands.
- Timeline
- Cleanups in days; migrations scheduled around your downtime window, usually outside business hours.
- Access needed
- A read-only admin role for phase one. Write access only for the approved fixes, then removed.
- You get
- A written report, an access map, the fixes done, and a checklist to keep it that way.
Infrastructure work delivered
Two deliveries from the infrastructure side.
Google Workspace access rebuilt for a support-services company
- Problem
- Shared drives, groups, and personal drives had grown without a plan. Nobody could say who could see what.
- Done
- Shared Drive architecture by department, role-based access through Google Groups and permission tiers, personal-drive migrations, and a provisioning workflow written down.
- Result
- Access that matches the org chart and survives staff changes.
Azure to OVH migration for a web application
- Problem
- A PHP Laravel application and its SQL database had to leave Azure for OVH without taking the product down.
- Done
- Infrastructure and database moved with a short downtime window, SSL and DNS cut over, Windows VMs replicated and load balanced on the new host.
- Result
- The application on its new hosting, moved with minimal downtime.
Guides you can use this week
The checklists VXSec works from, free. If you get through one and want the rest done, send it back with what you found.
- Offboarding gap checklist: what to check when an employee or contractor leaves.
- Google Workspace access checklist: the access review for a Workspace tenant.
- Microsoft 365 offboarding checklist: the same, for a Microsoft tenant.
- Connected-app and OAuth review: how to find every app with access to your tenant.
- Sample report: what the written report looks like, finding by finding.
Questions about infrastructure work
Is VXSec a managed service provider?
No. This is project work with a fixed price and a handoff, and the retainer if you want ongoing ownership of the agents and automations. Agencies and MSPs that want to resell the delivery can read the partners page.
Will anything break during a cleanup?
Phase one changes nothing. Phase two only applies fixes you approved, and every change is logged so it can be reversed. Migrations have a stated downtime window agreed in writing.
Do you work on Microsoft 365 and Google Workspace equally?
Both are in scope, and the scope says what has been done before. The delivered access work so far is on Google Workspace; Microsoft 365 access work follows the same rules (roles, groups, licenses, offboarding) and is quoted smaller until the first delivery. Anything that needs a specialist beyond that, the scope says so.
What does the report look like?
Read the sample report. Real reports carry evidence for every line.
Send the problem in writing.
What you are running, what is wrong or what you want built, and links if you have them. A written scope and a fixed price come back within two business days.
Or email [email protected] directly.
- You send: the tools involved, what should happen, what happens instead.
- You get back: a scope in plain words, a fixed price, what is out, and how it will be verified.
- Then: a call if you want one, or straight to the spec.