Philipp Schmidt
M365 Security Specialist
Zero Trust.
Zero Drama.
Straight Talk.
Certifications
Languages
Your Microsoft 365
Security Specialist
Secure Tenants. TISAX-ready. Clarity from Day 1.
Zero Trust. Zero Drama. Straight Talk.
Over 50 projects. 11 Microsoft certifications. 21 years of experience — focused on Microsoft infrastructure. I make your M365 tenant secure, compliant, and maintainable. For SMEs that don't leave IT security to chance.
Customer Reviews
Allgäu Batterie GmbH & Co.KG
IT Coordinator (Tobias Kinert)"Philipp joined us as a subcontractor and first had to 'put out fires.' I found Philipp to be a competent and incredibly composed service provider. His main task was to bring Intune (iOS) up to standard. That worked out great. He also supported us in the M365 area and implemented several new Conditional Access policies."
HMNC Holding GmbH
Executive Assistant / HR & Office Manager (Katharina Schwabe)"Under Mr. Schmidt's leadership, we transformed into a future-oriented cloud-first company. He successfully implemented MS 365 and introduced MFA with Yubikeys and Conditional Access. Through MDM, he ensured policy compliance for Windows 10/11 and iOS. He also deployed Atlassian products for our projects and documentation. His commitment and solution-oriented approach deserve special mention."
Christian Dörr Headhunting GmbH
Head of IT Infrastructure (Marcel Becker)"Thank you, Philipp, for your outstanding support in implementing macOS with Microsoft Intune and hardening and risk mitigation of our IT environment. Your persistence with complex topics and your pragmatic approach made all the difference. I recommend everyone to run a project with you. Your expertise truly convinced me."
Corsol GmbH
Managing Director (Andreas Brunner)"Dear Mr. Schmidt, through your work as a Microsoft 365 Solution Architect and Consultant, you have significantly contributed to strategically improving and future-proofing our IT infrastructure. Your comprehensive approach to Security, Governance and Compliance deserves special recognition. I am happy to recommend you."
Corsol GmbH
IT Administrator (Roman Wagner)"Dear Mr. Schmidt, we sincerely thank you for your outstanding work as a Microsoft 365 Consultant. Your expertise and dedication have significantly improved our IT infrastructure. We were particularly impressed by your support with TISAX, ISO 27001, the security audit, and the implementation of MFA, MAM and Conditional Access. Your work has left a lasting positive impact on our company."
Core Competencies
Industry Focus
Let's talk about your Microsoft 365 environment.
In a discovery call we'll clarify where you stand and how I can support you.
Recent Achievements
Azure AI Fundamentals (AI-900)
Latest certification covering AI and machine learning fundamentals on Azure
Microsoft 365 Administrator Expert
Expert-level certification for M365 administration and management
Global Intune Rollout
Successful implementation for international company
TISAX-compliant Implementation
Automotive client successfully certified
About Me
I'm Philipp Schmidt — Microsoft 365 Security Specialist with over 21 years focused exclusively on Microsoft infrastructure. My job: secure your M365 tenant, establish TISAX and NIS2 compliance, and automate device management. Focused on these three areas — depth over breadth.
As an expert in Zero Trust Security architectures and Modern Workplace solutions, I bring a proven track record in tenant hardening, compliance certifications, and endpoint management across automotive, pharma, healthcare, and consulting.
What sets me apart: clear specialization. Microsoft 365, security, and device management — in depth, from Entra ID to the Defender suite. Personal, direct, no overhead.
My Story
My IT career began over two decades ago with an apprenticeship as an IT Specialist for System Integration. Early on, I recognized the importance of security in IT infrastructure and continuously specialized in the latest Microsoft technologies.
The shift to the cloud and the growing complexity of cyber threats led me to specialize in Zero Trust Security architectures. Today, I help organizations navigate their digital transformation securely and efficiently.
My Philosophy
"Security is not a product, but a process." This conviction shapes my work approach. I believe in tailored solutions that are not only technically excellent but also practical and user-friendly in their implementation.
Every business is unique, and so should its IT solutions be. My approach is based on thorough analysis, strategic planning and phased implementation – always with a focus on maximum security with minimal complexity for end users.
- LocationMunich, Germany
- Email[email protected]
- Phone+49 171 3502951
- Websiteeasym365.de
- Work StyleRemote & On-site
- LanguagesGerman, English
My Values
Microsoft Certifications
My Work Style
Analysis & Assessment
Comprehensive assessment of your current IT infrastructure, identification of security gaps and optimization potential.
Strategic Planning
Development of a tailored roadmap with clear milestones, timelines and budget framework for your digitalization.
Secure Implementation
Step-by-step implementation with continuous monitoring, training and support for a smooth transition.
What I Do
Zero Trust Security
Implementation of Zero Trust architectures, security audits and system hardening as well as compliance support for TISAX, NIS2 and ISO 27001. Development of security policies and incident response plans.
Professional Experience
Freelance Microsoft 365 Solution Architect
Self-employed
Specializing in Zero Trust Security and Modern Workplace solutions for SMEs. Focus on TISAX compliance and NIS2 preparation.
Senior Microsoft 365 Consultant
Businessoft Consulting
Implementation of Zero Trust infrastructures and ITSM Service Desk solutions. Focus on pharmaceutical start-ups and enterprise customers.
Microsoft Senior Consultant
Enterprise Consulting
Design and implementation of Microsoft on-premise and cloud architectures. Leading migration projects and compliance initiatives for government agencies and private enterprises.
Senior IT Administrator
Various Companies
Building and managing IT infrastructures. Specialization in Microsoft technologies and network security.
IT Administrator & Support
Various Companies
First professional experience in IT support and system administration. Fundamentals in network technology and server management.
Services
Service Portfolio
Microsoft 365, security, and device management — for mid-sized companies with compliance requirements (TISAX, NIS2, ISO 27001)
How I Work
1. Clarity About Your IT Situation
You receive: A complete overview of your IT landscape, concrete action recommendations and prioritization by risk & business impact.
2. Planning Reliability & Transparency
You receive: Clear roadmap with fixed milestones, transparent budget planning and realistic timelines.
3. Secure Transformation Without Disruptions
You receive: Smooth implementation without productivity loss, trained employees and continuous support throughout the entire transition.
4. Optimization & Support
Continuous monitoring, performance optimization and long-term support for your Microsoft 365 environment.
Problems I Solve
Lines I hear in almost every discovery call — and what I do about them
Microsoft 365 & Tenant Governance
Most tenants grew organically: set up with defaults in 2020, extended blindly ever since.
Sound familiar?
- “Our tenant has been running on default settings for years — now we’re paying the price.”
- “Guest users have access to SharePoint — since 2019, and nobody has an overview.”
- “350 Teams, nobody knows what they’re for. Sensitive data sits in public Teams.”
- “Our M365 licensing is a nightmare — we’re probably paying 30% too much.”
- “Copilot is coming — but in its current state it would expose internal data.”
How I solve it:
Tenant assessment, a clean permission and governance concept for Teams and SharePoint, a license review — and Copilot readiness before the first prompt finds salary data.
Zero Trust Security & Compliance
Compliance pressure rarely comes with lead time — audits, insurers, and customers demand evidence, not intentions.
Sound familiar?
- “TISAX audit in three weeks — and we have no documentation.”
- “Our cyber insurance demands MFA and a Secure Score above 70% — or the premium doubles.”
- “The last security audit produced a 187-page PDF. Nobody read it.”
- “Secure Score stuck at 45% — where do I even start?”
- “A breach would probably go unnoticed for months.”
How I solve it:
A roadmap prioritized by risk and business impact instead of a findings list, properly implemented controls (MFA, Conditional Access, Defender), and audit-ready documentation for TISAX, ISO 27001, and NIS2.
Modern Device Management
Intune is powerful — which is exactly why it is left half-finished in so many environments.
Sound familiar?
- “The MFA rollout started eight months ago — and still isn’t done.”
- “Our Conditional Access policies are a spaghetti pile of half-tested rules.”
- “BYOD chaos: private devices access company data with zero control.”
- “Windows updates are a permanent construction site — we’re months behind.”
- “Intune is too complex for us — we can’t configure it properly alongside daily business.”
How I solve it:
A consolidated, tested Conditional Access rule set, zero-touch deployment via Autopilot and Apple Business Manager, compliance policies and update rings — built, documented, and handed over.
Identity & Access Management
Identity is the first line of defense — and in grown environments usually the biggest construction site.
Sound familiar?
- “Everyone here is Global Admin because it was faster back then.”
- “Customer audit: ‘Show us who has access to project X.’ We couldn’t.”
- “I’m alone for 200 users — there’s no time for clean permission management.”
- “Everything requires PowerShell — we don’t have anyone for that.”
- “We have a security team — they just don’t know Entra ID.”
How I solve it:
RBAC and Privileged Identity Management instead of permanent admin rights, access reviews for provable access, MFA up to passwordless sign-in — and automation of recurring identity tasks.
What This Means in Practice
Time Savings Through Automation
Zero-touch deployments with Autopilot and Intune – devices are immediately ready to use, without any manual intervention or IT support.
Secure Access with Conditional Access
Granular access control via Conditional Access – making optimal use of licenses you already own.
Seamless Apple Rollout
macOS devices are deployed without local admins and without user interaction – ideal for Apple-first companies and modern teams.
Compliance by Design
Compliant IT from the start – no retrospective adjustments needed, less risk during audits and certifications.
Scalable Architecture
Microsoft 365 environments that grow with your business – from small teams to complex structures, flexible and future-proof.
My Target Audience
Small and Medium-sized Enterprises (SMEs)
With approximately one internal IT support person who need an experienced external consultant for Microsoft 365 and security topics.
Security-focused Companies
Organizations with elevated security requirements or regulatory obligations such as NIS2 compliance or TISAX certification.
Industry Specialization
Automotive, pharma, consulting, manufacturing, IT services and healthcare with specific compliance requirements.
My Approach
Collaborative Consulting
I act as your external IT consultant and complement your internal team with specialized Microsoft 365 expertise.
Practical Solutions
Focus on actionable, cost-effective solutions that fit your company size and requirements.
Security First
Security is at the forefront of all implementations without compromising user-friendliness.
Projects
Current Projects
02/2026 - Present
HealthcareEntra ID & Tenant Security Hardening
Comprehensive overhaul of the identity and security architecture of a Microsoft 365 tenant in the healthcare sector. Focus on establishing a consistent Entra ID naming convention, redesigning access controls, and hardening all security-relevant components.
- Introduction of an Entra ID naming concept with complete RBAC overhaul
- Redesign and implementation of 39 Conditional Access policies
- Implementation of Privileged Identity Management (PIM)
- Hardening of MFA methods and restructuring of admin user management
- Comprehensive overhaul of device management
- General tenant security optimization
Customer Benefits
- Consistent naming convention significantly reduces administrative overhead and error sources
- 39 Conditional Access policies ensure granular access control for all scenarios
- PIM eliminates standing admin privileges and minimizes the attack surface
- Hardened MFA methods protect against phishing and credential theft attacks
- Industry-specific compliance requirements in healthcare are verifiably met
08/2024 - Present
Automotive SMEModern Workplace for SME with Focus on TISAX and Zero-Touch Deployment
Design and implementation of a modern workplace environment for a mid-market automotive company. Consideration of TISAX requirements, automated device management and cross-platform compliance.
- Windows Autopilot for zero-touch deployment of new endpoints
- TISAX-compliant compliance policies for Windows 11, iOS and Android
- Rollout of COBE iPhones with central management and app control
- BYOD strategy with strict separation of private and business data
- Regular technical support and user consulting
Customer Benefits
- TISAX compliance automatically ensured through preconfigured automotive standards
- Zero-touch deployment: new devices reach users without manual IT setup
- Strict BYOD separation protects company data without privacy intrusion
- Automotive-specific security for prototype protection and supplier data
- Central device management for Windows, iOS and Android from one console
04/2024 - 04/2026
Multi-Country CompanyGlobal Intune Rollout - Modern Workplace & TISAX/ISO 27001
Strategic planning and implementation of a global Intune infrastructure for international company locations with cross-country device management strategies, including TISAX and ISO 27001 certification support.
- Design and rollout of a scalable modern workplace architecture
- Implementation of Conditional Access policies and Autopilot deployment
- Cross-platform device management (Windows, macOS, iOS)
- Country-specific security baselines and compliance policies
- TISAX certification: implementation of VDA ISA requirements for information security in the automotive industry
- ISO 27001 certification: ISMS setup and implementation incl. risk management and documentation
Customer Benefits
- Unified IT standards across all international locations
- Local compliance conformity automatically per country and region
- Scalable architecture grows with international expansion
- Central management significantly reduces local IT resources
- Cross-border security with unified access controls
- TISAX and ISO 27001 certification as competitive advantage for clients and tenders
06/2024 - 01/2026
HR ConsultingApple-based Modern Workplace with CIS-compliant Security Strategy
Support of an HR consulting firm with fully Apple-based infrastructure (macOS and iOS). Focus on implementing secure, standardized policies according to CIS Benchmark as well as continuous security monitoring, backup strategies and user support.
- Introduction of Multi-Factor Authentication (MFA) and extension of Conditional Access policies
- Implementation of CIS-compliant policy baselines for macOS and iOS
- Regular monitoring of the Microsoft 365 tenant for security-relevant events
- Implementation of technical security measures incl. advanced Microsoft Defender ATP
- Setup and provisioning of backup solutions incl. email backup
- Conducting user awareness training to improve IT security
- Continuous user support and technical assistance
Customer Benefits
- Seamless Apple integration without user disruption or local admin rights
- CIS-compliant security standards for macOS and iOS with automatic policy enforcement
- Zero-touch deployment for all Apple devices via Apple Business Manager
- Unified security policies for macOS and iOS from a central console
- Continuous compliance monitoring with automated security reports
04/2024 - 12/2024
Tech-StartupComplete Tenant Setup for Tech Startup
Complete setup of an M365 tenant including MFA, Conditional Access and cross-platform device management (Windows, macOS, iOS) according to CIS guidelines. Configuration of Apple Business Manager (ABM) with Intune synchronization, Hornet Security (Backup, Archive, Awareness) and Shadow IT Discovery with Defender for Cloud Apps.
- Complete M365 tenant setup with MFA and Conditional Access
- Cross-platform device management according to CIS guidelines
- Apple Business Manager configuration with Intune synchronization
- Hornet Security integration (Backup, Archive, Awareness)
- Shadow IT Discovery with Defender for Cloud Apps
Customer Benefits
- Zero-touch setup for all device types — onboarding without manual IT steps
- CIS-compliant security from day one without retrospective adjustments
- Cross-platform management for Windows, macOS and iOS from one console
- Automatic Shadow IT detection protects against unauthorized cloud services
- Enterprise-grade backup and archiving optimized for startup budget
08/2024 - 02/2025
German Mid-MarketiOS Rollout & Conditional Access Implementation
iOS rollout and CA implementation in a German mid-market company with implementation of necessary iOS policies focusing on compliance and security.
- Implementation of Microsoft Copilot with focus on compliance
- iOS rollout and user support
- Extension of Conditional Access policies
- Compliance-compliant iOS device management strategies
Customer Benefits
- Microsoft Copilot usable in a compliance-conformant manner without data privacy risks
- Seamless iOS integration into existing Microsoft 365 environment
- Enhanced security through intelligent access controls
- User-friendly rollout with comprehensive training and support
- German compliance standards automatically met
10/2024 - 11/2024
Mid-Market CompanyMicrosoft Defender Implementation with Advanced Threat Protection Strategies
Comprehensive implementation and configuration of Microsoft Defender for a mid-market company. Focus on implementing advanced threat detection and response strategies as well as integration into existing Intune infrastructure.
- Configuration of Microsoft Defender for Endpoint policies and Attack Surface Reduction rules
- Integration of Defender policies into the existing Intune device management system
- Setup of comprehensive security monitoring and compliance oversight
- Training IT administrators for independent threat hunting and incident management
- Conducting security awareness training to improve IT security
Customer Benefits
- Attack Surface Reduction rules in block mode harden all endpoints
- Automatic threat detection with immediate device isolation
- Central security overview of all endpoints from one console
- Reduced downtime through proactive threat detection
- Compliance conformity with current security standards
10/2022 - 02/2024
Modern Workplace ProjectStrategic Introduction of a Cloud-based Infrastructure
Strategic planning and implementation of a Microsoft 365 environment in a hybrid identity landscape with focus on cloud-native device management, security standards and modern collaboration. Migration of classic file servers to SharePoint as well as introduction of Teams and SharePoint with compliance and governance structures.
- Setup of a hybrid Azure AD tenant with cloud-native device management
- Migration from file servers to SharePoint Online incl. permissions and compliance concept
- Introduction of Microsoft Teams and SharePoint with governance structures
- Rollout of Windows devices via Autopilot and Intune
- Integration of iOS devices into ABM with supervision (fully managed)
- Implementation of MFA and Conditional Access policies
- Setup and provisioning of backup solutions incl. email backup
- Implementation of advanced security measures (e.g. Microsoft Defender ATP)
- Conducting user awareness training to strengthen IT security culture
- Documentation of the environment and comprehensive user support
Customer Benefits
- Complete cloud transformation without operational disruptions
- Modern collaboration with Teams and SharePoint increases productivity
- Automated security through MFA and Conditional Access
- Scalable backup strategy protects all company data
- Zero-touch device management for Windows and iOS reduces IT effort
11/2022 - 02/2024
Pharma start-ups & recruiting firmZero Trust Infrastructure & ITSM Solutions for Pharmaceutical Start-ups
Strategic implementation of modern security architectures and service desk solutions for various clients with focus on the requirements of growing companies in the pharmaceutical sector and HR consulting. Emphasis on Zero Trust, ISMS and automated device management.
- Building a Zero Trust security structure incl. ISMS implementation
- Implementation of multi-factor authentication through to passwordless sign-in
- Mobile device management with Autopilot on Entra ID Joined basis
- Integration of Microsoft Defender options and Azure Information Protection
- Setup of an ITSM service desk for structured support processing
Additional References
Certifications
Microsoft Expert Certifications
Microsoft Certified: Cybersecurity Architect Expert
Microsoft 365 Certified: Administrator Expert
Microsoft Associate Certifications
Microsoft 365 Certified: Endpoint Administrator Associate
Microsoft Certified: Identity and Access Administrator Associate
Microsoft Certified: Information Security Administrator Associate (SC-401)
Microsoft Fundamentals Certifications
Microsoft 365 Certified: Fundamentals
Microsoft Certified: Azure Fundamentals
Microsoft Certified: Azure AI Fundamentals (AI-900)
Microsoft Certified: Security, Compliance, and Identity Fundamentals
Microsoft Certified: Power Platform Fundamentals
Microsoft 365 Certified: Copilot and Agent Administration Fundamentals
Additional Qualifications
AWS Certified Solution Architect - Associate
IT Specialist for System Integration (IHK)
Certification Overview
- EducationIT Specialist for System Integration
- Secondary EducationAdvanced Technical College Certificate
- InternationalHigh School Diploma, USA
- ITILITIL V3 Foundation
- Project ManagementProject Manager Certification (IHK)
- Experience21+ Years IT Expertise