
01 — CLOUD PLATFORM
Cloud solutions for Canadian businesses
Every platform we run is named on this page. So is where your data physically sits, who holds the administrator credentials, and how long a restore actually takes. Microsoft 365, Azure, NinjaOne, MSP360, Wasabi, SentinelOne — with backups written to storage that ransomware cannot delete.
MANAGED IT SINCE 2003
MONTRÉAL · LAVAL · SAINT-JÉRÔME · TORONTO · CALGARY
LAW 25 & PIPEDA ALIGNED

02 — WHAT YOU ARE ACTUALLY BUYING
“The cloud” is not a product
It is four separate decisions wearing one word. Anybody selling you “the cloud” as a single item has not made any of them yet.
DECISION 01
INFRASTRUCTURE
​Someone else’s servers, rented monthly. The servers are a commodity — Microsoft and Amazon sell the identical thing to your competitor. The value is entirely in who configures them, who watches them, and who gets them back.
DECISION 02
LICENSING
​Microsoft 365 is a subscription, not a backup. What Microsoft protects and what remains your responsibility are two different lists, and the second list is longer than most owners expect.
DECISION 03
DEPENDENCY
​Once your files live in a datacentre, your internet link and your identity provider become critical infrastructure. A cloud plan that ignores the circuit into your building is half a plan.
DECISION 04
RESIDENCY
Where the data physically sits determines which privacy law governs it. Under Quebec’s Law 25 that is a decision you are accountable for — not a default you inherit from whichever region a technician clicked first.
03 — PLATFORM MANIFEST
The stack we run
Not a list of technologies we have heard of. This is what we deploy, administer and hold credentials for, layer by layer.
LAYER 01
MICROSOFT ENTRA ID
MICROSOFT INTUNE
Identity and
access
One login for everything, with conditional access rules deciding who reaches what, from which device, from which country. Multi-factor authentication is not optional. New laptops enrol themselves through Autopilot and receive policy before anyone touches them.
ADMIN · ASC-MANAGED, CLIENT-OWNED TENANT
LAYER 04
​NINJAONE RMM
​
Endpoint
management
Every workstation and server under one console. Patch deployment, software inventory, disk and hardware health, automated remediation — and the remote session your technician opens when you call.
​
​
​
COVERAGE · ALL MANAGED ENDPOINTS, WINDOWS AND MACOS
LAYER 02
MICROSOFT 365
​
​Productivity and collaboration
​Exchange Online, SharePoint, OneDrive and Teams. Licence procurement, tenant build, mailbox and file-server migration, retention policy, and the day-to-day administration afterward.
​
​
RESIDENCY · CANADIAN TENANT REGIONS WHERE AVAILABLE
LAYER 05
MSP360 · NINJAONE BACKUP
WASABI · IDRIVE · AMAZON S3
Backup and immutable storage
MSP360 and NinjaOne Backup do the work. Wasabi, IDrive and Amazon S3 hold the result. Copies are written with S3 Object Lock, so a backup cannot be altered or deleted before its retention date expires — not by us, not by you, and not by ransomware holding a stolen administrator account.
​
IMMUTABILITY · S3 OBJECT LOCK, 30 TO 365 DAYS
LAYER 03
MICROSOFT AZURE
​
Cloud
infrastructure
For everything a subscription cannot replace. Virtual machines for line-of-business applications, Azure Virtual Desktop for staff who need a full desktop from anywhere, Azure Files for shared storage, and a site-to-site tunnel back to whatever stays in your building.
REGIONS · CANADA CENTRAL AND CANADA EAST
LAYER 06
SENTINELONE SINGULARITY
MICROSOFT DEFENDER
Detection and
response
​SentinelOne is the agent on every endpoint. Its detection runs on the device rather than in a console, so a laptop working offline is still defended. It links process activity into a single attack storyline, isolates the machine on its own, and can roll a Windows endpoint back to its state before encryption. Microsoft Defender covers the mailbox and the identity layer beside it.
TRIAGE · MDR


04 — DATA RESIDENCY
Where your data actually lives
​Most providers answer this question with one word: “Canada.” The honest answer is longer, and you should insist on the longer one — because the short version is what fails an audit.
BACKUPS
AND ARCHIVES
Canadian datacentre regions. The region is chosen explicitly during setup, written into your documentation, and re-verified at each service review. It is never left on a platform default.
MAILBOXES
AND FILES
Microsoft operates Canadian regions in Toronto and Quebec City. Where your tenant is provisioned for them, your mailbox and SharePoint content rests in Canada.
AZURE
WORKLOADS
​Virtual machines, virtual desktops and Azure Files are deployed to Canada Central or Canada East. The region is fixed at build time and recorded, because moving a workload between regions afterward is a migration, not a setting.
ENDPOINT
SECURITY DATA
​SentinelOne processes agent telemetry in the cloud region assigned to your console, and devices are pinned to that region so the data does not travel with the laptop. We tell you which region yours is in. Ask your current provider the same question — most have never checked.
DIRECTORY
AND TELEMETRY
Some identity and security metadata is processed by Microsoft outside Canada. This is inherent to the platform and it is true of every provider selling you Microsoft 365. We state it plainly rather than letting you discover it during a privacy assessment.
GOVERNING
LAW
​Quebec’s Law 25 and Canada’s PIPEDA. Your residency map forms part of the register of personal information you are required to maintain, and we hand it to you in writing.
05 — OWNERSHIP
Your tenant. Your licences. Your keys.
The most expensive thing a business can discover is that its email lives inside somebody else’s Microsoft account. Ask the question before you sign, not while you are trying to leave.
​HOW WE STRUCTURE IT
-
Licences purchased in your company name, into your own tenant
-
Microsoft Cloud Solution Provider agreements sourced through Ingram Micro, where we are an authorized reseller
-
You hold a global administrator account of your own, from day one, permanently
-
Backup storage accounts registered to you, not pooled inside ours
-
Documentation, credentials and the residency register handed over on request
-
If you leave, the tenant, the data and the subscriptions leave with you
​HOW WE STRUCTURE IT
-
Whose company name is on the Microsoft tenant?
-
Do I hold a global administrator account of my own?
-
If I terminate, what do I keep and how long does handover take?
-
Is my backup stored somewhere I could reach without you?
-
Show me the result of the last restore test you performed.
Ask us the same five. We answer them in the audit document.
06 — BACKUP DOCTRINE
Three, two, one, one, zero
The rule every backup we build is measured against. If your current provider cannot walk you through all five digits, you do not have a backup — you have a copy.
​3 — COPIES
Three copies of every protected dataset. The live one, plus two independent backups that do not share a single point of failure.
​2 — MEDIA
Two different storage types. Local storage for fast restores of a deleted folder, and object storage in a datacentre for the day the building is unavailable.
1 — OFFSITE
At least one copy physically away from your premises, in a Canadian region, reachable without setting foot in the office.
1 — IMMUTABLE
At least one copy locked. S3 Object Lock enforces the retention period at the storage layer itself, so encryption or deletion commands are refused even when they arrive with valid administrator credentials. Every provider can produce copies; almost none can produce a copy a compromised administrator account is unable to destroy. This is the digit that decides whether a ransomware incident costs you a weekend or ends the business.
​0 — ERRORS
​Zero errors on a verified restore. A backup job reporting success is a claim. A file opened from a test restore is evidence. We test on a schedule and send you the result.
07 — THE GAP NOBODY MENTIONS
Microsoft does not back up your Microsoft 365 data
Microsoft guarantees the service is available. Under its shared responsibility model, protecting the content inside that service stays with you. Deleted items and retained files sit in recycle bins and retention holds that expire — typically within a few months — and then they are gone.
​
That covers the ordinary failures: an employee who empties a mailbox on their last day, a SharePoint library overwritten by a sync error, a finance folder encrypted by ransomware and dutifully replicated to every other device.
PATH A · CLOUD
NinjaOne Backup for Microsoft 365
Exchange Online, SharePoint, OneDrive and Teams captured on a schedule to managed cloud storage. Point-in-time restore of a single item, a single mailbox, or the entire tenant. Nothing to install and nothing to maintain on your premises.
BEST FOR · FULLY CLOUD OFFICES WITH NO SERVER ON SITE
PATH B · LOCAL
CodeTwo Backup for Office 365
The same tenant data, written to storage you own — a server or NAS inside your building. Physical custody of the copy, which matters when a policy, an insurer or a client contract requires the data to be reachable without going through a third party.
BEST FOR · CUSTODY REQUIREMENTS AND EXISTING ON-SITE STORAGE

One caveat we will not leave out. Storage sitting in your own building is not immutable by default — ransomware that reaches your network can reach a NAS. Where Path B is chosen, we pair it with a hardened repository or an immutable cloud copy, so the doctrine above still closes at all five digits.
08 — MIGRATION PATH
How a migration actually runs
Numbered because it is a sequence, and because the timings are the part clients care about. These are typical ranges for a twenty-to-eighty seat business.

01 · 1–2 WEEKS
Discovery and inventory. Every server, share, mailbox, licence, application dependency and line-of-business system, written down. Most surprises live here.
02 · 1 WEEK
Design and residency. Target architecture, region selection, identity model, backup tiers and the recovery objectives for each workload — agreed and signed before anything moves.
03 · 1–2 WEEKS
​Pilot group. A small cross-section of users runs the new environment for real work. Problems surface at five people instead of fifty.
04 · ONE WEEKEND
Cutover. Final sync, DNS change, mailbox switch. Scheduled outside business hours with a documented rollback point at every stage.
05 · ONGOING
​Steady state. Monitoring, patching, alert triage, restore testing and a quarterly review of cost, licence count and residency.
09 — SERVICE PARAMETERS
The numbers we contract to
Ranges, not promises pulled from a brochure. Your specific figures are set during design, per workload, and written into the agreement.
15 min – 24 h
RECOVERY POINT OBJECTIVE
MAXIMUM DATA GAP, BY WORKLOAD
4 h – 48 h
RECOVERY TIME OBJECTIVE
TIME TO WORKING, BY TIER
30 – 365 days
IMMUTABLE RETENTION
ENFORCED BY S3 OBJECT LOCK
Quarterly
VERIFIED RESTORE TEST
DOCUMENTED AND SENT TO YOU
A provider who quotes one recovery time for an entire business has not classified your workloads. A finance database and a shared marketing folder do not deserve the same number, and you should not pay as though they do.
10 — WHERE CLIENTS USUALLY START
Three situations we are called for
SITUATION A
The server is out of warranty
Hardware past its service life, an operating system past its support date, and a replacement quote nobody wants to sign. We map what genuinely has to stay on site, move the rest to Azure, and stop the replacement cycle.
TYPICAL PATH · AZURE MIGRATION, HYBRID IDENTITY
SITUATION B
Microsoft 365,
no backup
The most common finding in our audits. Everything the business runs on lives in one tenant, protected by nothing but recycle bins and an assumption. It is also the fastest gap to close.
TYPICAL PATH · TENANT BACKUP, IMMUTABLE STORAGE
SITUATION C
Three offices,
three logins
Separate password lists, no multi-factor authentication, and no reliable way to remove a departing employee everywhere at once. Identity is consolidated first, because every other control depends on it.
TYPICAL PATH · ENTRA ID, CONDITIONAL ACCESS, INTUNE
11 — SCOPE
What the monthly fee covers
INCLUDED IN THE AGREEMENT
â—† Tenant design, build and ongoing administration
â—† Licence procurement and monthly reconciliation
â—† Backup configuration, monitoring and restore testing
â—† Patch management across servers and workstations
â—† Endpoint and mailbox security, alert triage
â—† Azure cost review and right-sizing
â—† Documentation, residency register and quarterly review
â—† User support for anything on the platforms above
QUOTED SEPARATELY
â—† The migration project itself — fixed scope, fixed price, before the monthly agreement begins
â—† Custom software development and database work, which we do in house
â—† Hardware purchases, which we supply as an authorized reseller
â—† Network cabling, switching and firewall replacement
â—† Azure consumption, billed at cost on your own subscription
â—† Your internet circuits and carrier contracts, which stay in your name
Nothing on the right is something we cannot do. It is billed as a project because pretending open-ended work fits inside a per-seat fee is how providers end up rationing the help you already paid for.

12 — QUESTIONS WE ARE ASKED
Cloud questions, answered plainly
Is my data stored in Canada?
Your backups and archives are, in Canadian datacentre regions we select deliberately. Azure workloads are deployed to Canada Central or Canada East. Microsoft 365 mailboxes and files rest in Canada where your tenant is provisioned for the Toronto or Quebec City regions. A limited amount of directory and security telemetry is processed by Microsoft outside Canada — that is true of every Microsoft 365 provider, and we document it for you rather than leaving it unsaid.
Does Microsoft back up my Microsoft 365 data?
No. Microsoft keeps the service running; protecting the content inside it is the customer’s responsibility under its shared responsibility model. Recycle bins and retention holds expire, usually within a few months. Third-party backup of the tenant is a separate product and we consider it mandatory.
Where is my Microsoft 365 backup stored?
You choose. NinjaOne Backup writes your tenant data to managed cloud storage with nothing installed on your premises. CodeTwo Backup writes the same data to a server or NAS you own, giving you physical custody of the copy. Businesses under a contractual or policy requirement to hold their own data usually take the second route, and we pair it with an immutable cloud copy so a single site failure cannot take both.
What does an immutable backup mean?
The storage platform refuses to modify or delete the data until its retention period expires. With S3 Object Lock the refusal is enforced by the storage service itself, so it holds even when the request arrives with valid administrator credentials for your environment. It is the single most effective control against ransomware destroying your ability to recover.
Do you work with Azure, or only Microsoft 365?
Both, and they answer different questions. Microsoft 365 covers email, files and collaboration. Azure covers everything a subscription cannot replace: virtual machines for line-of-business applications, Azure Virtual Desktop, Azure Files, and a site-to-site tunnel back to your premises. Canadian regions are selected for both.
How long does a migration to Microsoft 365 take?
For a business of twenty to eighty employees, four to six weeks from discovery to cutover is typical, with the cutover itself falling on a single weekend. The variable is almost never the mailboxes — it is the line-of-business applications nobody documented.
Why run SentinelOne when Microsoft Defender is already included?
Because they cover different ground. Defender for Office 365 protects the mailbox and Entra ID protects the login, and both are strong where they sit. SentinelOne is a dedicated detection and response agent on the endpoint itself: it decides on the device rather than in the cloud, so a laptop working offline is still defended, and it can isolate a compromised machine and roll a Windows endpoint back to its state before encryption. Bundled antivirus stops known malware. An agent like this is what you want facing an attacker who is already inside.
Can I keep a server on site and still use the cloud?
Yes, and for some workloads it remains the right answer — large design files, manufacturing systems and applications with licensing tied to local hardware among them. Hybrid is a legitimate architecture, not a failure to migrate fully.
Who owns the licences and the tenant?
You do. Licences are purchased in your company name into your own tenant, and we administer them on your behalf. If you move to another provider, you keep the tenant, the data and the subscriptions.
What happens to our data if the contract ends?
Administrative access is transferred to you or to the provider you name, documentation is handed over, and backup data is exported or its retention allowed to run out on a schedule you choose. The offboarding terms are written into the agreement at signature, not negotiated afterward.
13 — SERVICE PARAMETERS
Start with the audit, not the proposal
A cloud readiness audit is a fixed-scope engagement. We inventory what you run, test whether your current backups actually restore, map where your data sits today, and hand you a written findings document. It is yours whether or not you engage us afterward.
