Managed IT services for Australian businesses.
Microsoft 365, Azure and Cloudflare operated on a standing retainer by an engineering and security firm that records every change it makes.
Managed IT at Black Shard is an operations engagement: the firm takes standing responsibility for the platforms a business runs on, keeps them patched, configured and monitored, and answers for their state. The platforms are Microsoft 365 for identity, mail and documents, Microsoft Azure for hosted systems, and Cloudflare for DNS, content delivery and the web application firewall.
Black Shard is an Australian software engineering and cybersecurity firm headquartered in Brisbane. The firm builds and runs production systems on Azure and Microsoft 365 in Australian regions, including the operations and compliance portal GRM LAW runs on, the clinical software platform Aurii, and the Microsoft 365 tenant, domain mail and hosting operations behind Fox Valuations. The managed service is that same operating work, offered to organisations that need someone to own their environment.
What the service covers
The engagement covers the three platforms most Australian businesses already sit on. Each is administered under a documented configuration, changed through a recorded process, and reviewed on a schedule agreed at the start.
- Microsoft 365 tenant administration: Entra ID identity, licensing, mailboxes, SharePoint and Teams, with multi-factor authentication and conditional access enforced for every account
- Mail and domain authentication: SPF, DKIM and DMARC published and held at enforcement, so mail from your domain is trusted and mail pretending to be from it is rejected
- Endpoint configuration through Microsoft 365: enrolment, a configuration baseline, disk encryption and patch compliance reported per device
- Azure operations: subscriptions, resource groups, networking, backup and cost management for the systems you host, in Australian regions
- Cloudflare edge: DNS records, certificate management, CDN caching, the web application firewall and access rules for your public zones
- Access reviews: who holds administrative rights, why, and when it was last confirmed, recorded each quarter
- Monitoring and response: platform health, sign-in anomalies and service alerts watched, with an agreed path from alert to action
How the firm runs its own estate
The controls in the service are the ones the firm applies to itself. Black Shard holds SMB1001:2026 Gold Level 3, issued by CyberCert and verifiable on its public registry, and self-assesses against the ASD Essential Eight at Maturity Level 2. Production workloads run on Microsoft Azure in Australian regions, and the firm's own edge, like its clients' zones, runs through Cloudflare as a member of the Cloudflare Partner Network.
That matters for a managed service because the question a buyer cannot easily verify is whether the provider does what it says. The registry entry, the self-assessment and the platform choices are published on the trust page, and the same labelling of what is held and what is self-assessed is carried into client reporting.
Where it differs from a conventional managed service provider
A conventional managed service is a helpdesk with a ticket queue in front of a set of platform licences. The queue is the product. Black Shard is an engineering firm, so the product is the environment itself: the tenant configured to a documented baseline, the Azure estate built as code where it is ours to build, the mail domain at DMARC enforcement, and a change record that says what moved and why.
The second difference is the security work behind the retainer. The same firm runs penetration tests, Azure and Entra ID reviews, incident response and compliance readiness against the Essential Eight, SMB1001 and ISO 27001. When a review finds a gap in a tenant the firm operates, the fix is scheduled into the retainer instead of quoted as a separate project by a different provider.
The third is the work the firm will not hide. Where a platform is configured in a way that leaves a risk open because the business has chosen it, that choice is written down with its owner. A managed environment carries an honest register of the risks that remain.
How an engagement starts
The first step is a review of the environment as it runs: the Microsoft 365 tenant and its Entra ID configuration, the Azure subscriptions in use, the DNS and edge for every public domain, and the devices and accounts that reach them. The review records the current state against the baseline the service will hold and lists the changes needed to reach it, ordered by risk.
Take-on then works through that list. Identity and mail authentication go first because they close the most common paths into a business. Backups are verified by restoring from them. Administrative access is reduced to the people who need it, held in named accounts, and recorded. Once the baseline is reached, the retainer holds it.
How the retainer runs
The standing shape is a monthly retainer with an agreed scope: the platforms in service, the review cadence, the response path for alerts and requests, and the reporting the business receives. Each month closes with a short written report: changes made, patches applied, access reviewed, alerts handled, and anything the business needs to decide.
Requests from staff, such as a new starter, a leaver, a shared mailbox or a DNS change, run through a recorded process so the environment stays consistent with its baseline. Changes with a security effect, such as a new administrator or a firewall rule, are made only with a named approver on record.
- A written configuration baseline for each platform, maintained as the environment changes
- A change record: what was changed, by whom, when and on whose approval
- Patch and compliance reporting per platform and per device
- Quarterly access reviews with the outcome recorded
- A monthly report written for the owner or director, not for the IT team
What do managed IT services cost?
Pricing is scoped and no rate card is published. The standing shape is a monthly retainer, sized by the number of users and devices, the platforms in scope, the number of public domains and hosted systems, and the state the environment is in at take-on.
Send a brief to info@blackshard.com.au with the size of the business, the platforms you run today and who looks after them now.
Questions, answered
- Which platforms do you manage?
- Microsoft 365 for identity, mail, documents and endpoint configuration, Microsoft Azure for hosted systems, and Cloudflare for DNS, CDN and the web application firewall. These are the platforms the firm builds and runs its own systems on. Other platforms are considered case by case where they sit alongside those three.
- Do you move us onto these platforms if we are not on them?
- Yes, where the move makes sense for the business. Migration of mail, identity and files into Microsoft 365, hosting into Azure and DNS into Cloudflare is scoped as a defined project before the retainer starts.
- Do you provide a helpdesk?
- Staff requests such as new starters, leavers, mailboxes and access changes run through a recorded process on an agreed response path. The retainer is scoped around operating the environment; day-to-day device support for individual staff is included where the agreement names it.
- Where is our data held?
- Microsoft 365 and Azure services are configured to Australian regions where the service offers them, and hosted systems the firm operates run in Australian Azure regions. Cloudflare's edge is global by design; the origin and the data stay where the platform holds them.
- What access do you need?
- The administrative access the work requires and no more: named accounts, multi-factor authentication enforced, privileges granted deliberately, reviewed each quarter and removed when the engagement ends. Every administrative action is recorded in the platform's audit log.
- Does the retainer include security work?
- The retainer holds the environment to its baseline, which includes the identity, mail authentication, patching and access controls that most security frameworks require. Penetration testing, Azure and Entra ID reviews, incident response and compliance readiness are scoped as separate pieces of work by the same firm, and their findings are fixed inside the retainer.
- Can you help with Essential Eight or SMB1001 while you run our environment?
- Yes. Most of the Essential Eight and SMB1001 controls are configuration on the platforms in service: multi-factor authentication, patching, application control, backups and administrative privilege. A managed environment held to the baseline is most of the way to either, and the firm runs the readiness work as a separate engagement.
- Do you work with organisations outside Brisbane?
- Yes. Black Shard is an Australian firm headquartered in Brisbane and delivers managed IT services Australia-wide. Tenant, cloud and edge operations run remotely by nature, and reporting and reviews run on a call.
- How do we start?
- Send a brief to info@blackshard.com.au. The first step is a review of the environment as it runs, which gives both sides a documented starting position before a retainer is scoped.
Tell us which tenant, estate and edge you need run.
Brisbane head office. Work delivered across Australia.