Senior Microsoft Security Architect · Lisbon · Remote worldwide
Microsoft 365 & Hybrid Infrastructure Consulting
One senior architect — not a Big-4 pyramid. Evidence-based security assessments, hands-on hardening, and continuous NIS2 readiness for organisations now in scope. The rigour large firms charge six figures for — delivered in days.
Across 11+ years of enterprise programmes — see career timeline.
Trusted on enterprise-scale programmes
Ericsson
European Commission
Körber
Richemont
Metro Lisboa
Solutions Architect Specialising In
Microsoft 365
·
Azure
·
Exchange Online
·
Defender XDR
·
Entra ID
·
Microsoft Sentinel
·
Intune / MEM
·
PowerShell
·
Microsoft 365
·
Azure
·
Exchange Online
·
Defender XDR
·
Entra ID
·
Microsoft Sentinel
·
Intune / MEM
·
PowerShell
·
Packaged Engagements
Defined scope. Board-grade outcomes.
Fixed-scope, tool-backed engagements — enterprise-grade rigour, delivered in days. Powered by my own assessment engine: 228 evidence-based checks mapped to NIS2 Art. 21(2), ISO 27001 and CIS.
THE STAKES
NIS2 isn’t coming — it’s here. Portugal’s Cybersecurity Legal Framework (Decree-Law 125/2025) took effect on 3 April 2026, transposing the EU NIS2 Directive. It expands the in-scope population from around 1,000 organisations to an estimated 7,000–9,000 — pulling medium and large companies across energy, health, transport, digital infrastructure, manufacturing, food and public administration into a regime most have never faced. The obligations are concrete: risk-management measures, incident reporting on tight deadlines, supply-chain security — and, for the first time, personal, non-delegable accountability for the management body. Non-compliance carries fines up to €10 million or 2% of worldwide turnover. The national authority (CNCS) now expects you to demonstrate your posture with evidence, through the MyCiber platform. “We think we’re secure” is no longer an answer.
WHY ME
Proving NIS2 readiness takes someone who has run this at enterprise scale and delivers it without the overhead — one senior Microsoft architect doing the work personally, start to finish. Every engagement is powered by my own assessment engine — 228 evidence-based checks mapped to NIS2 Art. 21(2), ISO 27001 and CIS — so you get audit-grade rigour, delivered in days. And nothing is invented: every finding is backed by collected evidence, and anything that couldn’t be assessed is stated plainly — never dressed up as a pass.
01
Assess
know where you stand
M365 & Azure Security Assessment
App & AI Agent Posture Assessment
NIS2 Readiness Assessment
→
02
Remediate
close the gaps
Hardening & Remediation Sprint
→
03
Sustain
hold the position
Managed Security Posture & vCISO Retainer
One-time
M365 & Azure Security Assessment
Know your exposure before an attacker does.
A structured, evidence-based security assessment of your Microsoft 365 tenant and/or Azure environment — delivered in days, not months. Powered by a purpose-built assessment engine that runs 228 curated security checks against your environment. Every check is mapped to NIS2 Article 21(2) and CIS Controls, with ISO/IEC 27001 correspondence via the official ENISA mapping — and to Portugal’s QNRCS v2 and Anexo III (Regulamento 756/2026). You receive a complete, reproducible evidence pack — not a checklist, not an interview report.
From€1,950
Microsoft 365 — with Azure identity and RBAC coverage included
What’s included
A — Executive Board Summary (Word + HTML, EN + PT)
B — Technical Findings & Gap Analysis (Word, EN + PT)
C — Evidence & Status Tracker
D — Compliance Crosswalk (NIS2 · ISO 27001 · CIS)
E — Exports & Limitations Record
How the engagement runs
0130-minute scoping call
02You grant read-only delegated access to the tenant
03The engine collects evidence and runs the 228 checks
04I validate every finding and write the reports
05Findings walkthrough call
Why it matters
Regulators don’t accept “we think we’re secure.” Under NIS2, organisations must demonstrate posture with evidence. This gives your CISO and board a defensible, framework-mapped view of where you stand and what must change.
What you provide
Read-only delegated access to the tenant
One 30-minute scoping call
Express — €750: essential M365 posture check, HTML dashboard + findings CSV (no board pack, no Anexo III gap table, no remediation runbook).
One-time
App & AI Agent Posture Assessment
Every app and agent with access to your tenant is an attack path you can’t see.
A focused variant of the security assessment, aimed at the application and identity layer of your Microsoft 365 tenant — OAuth app and service-principal permissions, risky and over-privileged grants, dormant and expired credentials, ownerless apps, and user-consent governance. Surfaces the third-party and internal apps quietly holding access to your data, ranked by risk and mapped to NIS2 Art.21(2)(d) supply-chain security and ISO 27001. AI-agent posture (Copilot and declarative agents and their connectors) is an emerging extension of this assessment, with coverage expanding as the platform’s governance surface stabilises.
Contact for pricing
What’s included
App & service-principal risk register
Consent-grant and permission inventory
Prioritised remediation
The same evidence-pack format as the security assessment
How the engagement runs
0130-minute scoping call
02You grant read-only delegated access to the tenant
03The engine inventories every app, grant and service principal
04I validate and rank the findings by risk
05Findings walkthrough call
What you provide
Read-only delegated access to the tenant
One 30-minute scoping call
Project
Hardening & Remediation Sprint
Close the gaps. No surprises. No downtime.
Assessment found the gaps — now we fix them. This engagement takes the findings from your security assessment and implements the remediations with full architecture analysis and a staged rollout plan, so there is zero business interruption. Every change is documented, tested, and delivered with rollback procedures.
PIM for privileged Entra ID roles — zero standing admin
Legacy authentication eradication
Defender XDR / endpoint hardening
Operational runbook + rollback procedures
How the engagement runs
01Review findings (ours or yours)
02Architecture & change-impact analysis
03Phased, tested rollout — with rollback at every step
04Documentation & operational runbook handover
Why it matters
Most organisations find gaps and then lose momentum — no clear owner, no safe sequencing, no rollback plan. This sprint delivers full closure: from finding to fixed, with evidence at every step.
What you provide
A prior assessment (ours or yours)
Change-window alignment
A technical point of contact
One-time
NIS2 Readiness Assessment
NIS2 is in force. Are you ready — or guessing?
A focused readiness assessment aligned to the EU NIS2 Directive and Portugal’s Cybersecurity Legal Framework (Decree-Law 125/2025, in force since April 2026), built for organisations that must now evidence their security posture to regulators, auditors or their own board. Goes beyond the standard posture assessment with explicit NIS2 measure-area mapping and board-ready executive deliverables.
Contact for pricing
What’s included
Everything in the Security Assessment (A–E), plus:
02You grant read-only delegated access to the tenant
03The engine runs the 228 checks and builds the NIS2 measure-area crosswalk
04I validate findings and write the board brief + technical crosswalk
05Findings walkthrough call
Why it matters
NIS2 applies to a broad range of sectors in Portugal and the EU, and board liability is non-delegable. This assessment tells you, in board-ready terms, where your technical readiness stands and what to address before an audit or incident.
What you provide
Read-only delegated access to the tenant
One 30-minute scoping call
Technical readiness assessment — not legal advice.
Security and compliance aren’t projects. They’re a state you have to hold — month after month.
A recurring engagement that keeps your Microsoft 365 and Azure environment continuously assessed, hardened and audit-ready — and holds the cybersecurity-officer function NIS2 requires. The assessment engine re-runs on an agreed cadence; we maintain your roadmap, run incident reporting, and report to your board. Choose the level of support that fits your obligations and internal capacity.
Contact for pricing
What’s included
Full re-run of the assessment engine
Drift report ranked by severity
Updated NIS2 Art.21(2) / ISO 27001 / CIS readiness crosswalk
Prioritised remediation guidance
Implementation support for agreed remediations
Advisory access between cycles
How the engagement runs
01NIS2 Readiness baseline (gaps + roadmap)
02Engine re-runs on the agreed cadence
03Drift report + board reporting + incident support
04Advisory access between cycles
Why it matters
NIS2 compliance is continuous, board liability is non-delegable, and your tenant drifts with every new user, app and config. A one-time assessment is a snapshot; this is a held position — so your board report is always current, your officer function is covered, and your exposure never silently grows.
How we start
How we start: a fixed-scope NIS2 Readiness Assessment establishes your gaps and roadmap; the retainer executes it and keeps you ready. Begin with a 3-month pilot or an annual plan.
Entities that need someone holding the officer seat. Monthly monitoring, risk register & incident reporting (24h/72h/30-day); Cybersecurity Officer support & 24/7 contact-point coordination — you appoint and notify the officer, we provide the capability behind the seat; supplier reviews + monthly & quarterly board reporting.
Security Partner
approx. 32–48 h / mo
From€6,000 / mo
Larger, regulated or audit-facing organisations. Dedicated officer capacity & ISMS toward ISO 27001, incident leadership + tabletop exercises, audit support, multi-framework (NIS2 + ISO 27001 + DORA where relevant).
Technical readiness service — not legal advice.
The deliverable
See exactly what the assessment delivers.
Board summary, technical findings, compliance crosswalks and a remediation roadmap — built from evidence collected directly from your tenant. See the reports and a live sample.
Executive Board SummaryFindings & Gap AnalysisZero Trust Maturity
Bespoke Consulting
What I Deliver
Microsoft 365 and hybrid infrastructure is mission-critical — and most organisations are running it under-secured, under-documented, and under-governed. We fix that. TakeItToCloud delivers specialist consulting across the full M365 and hybrid stack: from security assessments and compliance evidence to migrations, hardening, identity architecture, and ongoing managed support. Every engagement is scoped, evidence-based, and handed over with documentation your team can actually use. Choose the service that fits where you are. We'll take it from there.
Proven Results
Case Studies
Real enterprise engagements. Problem → Architecture → Implementation → Results.
Senior Microsoft Architect
Carlos Annes
Microsoft 365 · Hybrid Identity · Infrastructure · Lisbon, Portugal
Carlos Annes
Senior Microsoft Architect
Lisbon, Portugal · Remote worldwide
Microsoft infrastructure architect specialising in hybrid identity, security architecture, and large-scale Microsoft 365 migrations. Based in Lisbon, delivering remote-first engagements to enterprise organisations across Europe.
Enterprise programs delivered for Ericsson, the European Commission, Metro Lisboa, and Körber — covering security transformation, hybrid identity architecture, and global tenant standardisation. Prior to independent consulting, served as O365 and Exchange Support Engineer at Microsoft.
Carlos brought a level of architecture rigour we rarely see from external consultants. Every change was documented, every rollback was pre-tested. We went from a fragmented endpoint estate to a fully enforced Zero Trust posture — with zero disruption to the business.
Security Program Lead
Ericsson · Defender XDR Program · 15k+ endpoints · 2023
“
The Exchange 2019 deployment was the cleanest infrastructure project we have run in years. Zero mail loss on cutover, PKI rebuilt end-to-end, and a full handover runbook our team could actually use the next day.
IT Infrastructure Manager
Metro Lisboa · Exchange Migration · Zero mail loss · 2023
“
Standardising Intune and Defender across 20+ subsidiaries is the kind of project that usually takes 18 months and three vendors. Carlos scoped it, delivered it in sprints, and left runbooks that our subsidiary IT teams could follow independently.
Book a no-obligation discovery call. I'll review your current setup, identify quick wins, and outline a structured engagement with defined outcomes — before any contract is signed.