Managed IT and Proactive Security Built for a Hands-On Outdoor Comfort Business
How Outdoor Comfort Solutions ended self-inflicted DNS email outages, separated Global Admin from a production mailbox, and standardized cloud-first file access across every endpoint — all under a single managed IT agreement.
Managed by Soaring Towers
Hear it from Dave Lebrun at Outdoor Comfort Solutions
“So, it’s definitely a lot simpler now!”
A hands-on, owner-led outdoor comfort business — serving the Minot, ND region with a small team of office and field staff.
Outdoor Comfort Solutions is a small, owner-led business in Minot, North Dakota, delivering outdoor living products and services to local and regional customers. President Dave Lebrun runs the day-to-day with a small team and a mix of office and field staff — and is the kind of hands-on operator who buys his own hardware, edits his own DNS records, and manages his own web hosting.
Dave came to Soaring Towers in November 2025 looking for guardrails, not a replacement for his IT instincts — a managed partner that could keep the foundation secure, the email running, and the team’s files where they need to be, while letting him stay close to the technology that runs his business.
A self-managed setup quietly accumulating risk — without anyone watching the foundation.
An incompletely deployed Microsoft 365 tenant, a critical security misconfiguration nobody knew about, and a recurring self-inflicted email outage pattern — the same pattern we see across most owner-managed small businesses before they engage a managed IT partner.
-
SharePoint and OneDrive never deployed to endpointsThe M365 tenant existed, but the OneDrive client wasn’t installed on the machines — so SharePoint files lived in the cloud and couldn’t sync locally on the team’s computers.
-
Global Admin tied to a production mailboxDave’s own email account held full tenant administrator privileges — meaning a single phishing hit on his inbox would have handed an attacker the keys to the entire Microsoft environment.
-
Self-managed DNS causing recurring email outagesIndependent DNS edits between GoDaddy and Cloudflare broke MX records on at least two separate occasions — each time taking down all incoming email until Soaring Towers restored the routing.
-
M365 licensing confusion, no shared mailboxesRole-based addresses like Sales@, Accounting@, and info@ were unconfigured — and Dave believed adding more would require buying additional paid seats. No prior IT guidance on shared mailboxes existed.
A fully managed Microsoft 365 foundation with proactive security, owned DNS, and a real user lifecycle.
Soaring Towers designed and implemented a managed IT foundation built for an owner-led business where the principal stays close to the technology. The four pillars below put guardrails around the parts that needed protection — without taking the wheel away from Dave.
Today’s owner-led businesses need guardrails, not a replacement.
Hands-on operators want to stay close to their technology — they buy their own hardware, manage their own web hosting, and make their own decisions. What they don’t need is one DNS edit silently taking down email for a day, or a single phishing email handing over the entire tenant.
At Soaring Towers, we specialize in managed IT for small, owner-led businesses — putting the right guardrails in place so the principal can keep moving fast without breaking the foundation underneath.
Four foundations of a guarded, owner-led small business.
Every layer below was selected and configured specifically for the realities of a small, hands-on operator — a Microsoft 365 tenant that finally works on every endpoint, the security guardrails the principal didn’t know he needed, and a DNS that stops surprising the inbox.
Microsoft 365 F1 + SharePoint & OneDrive
Three licensed seats provisioned via Pax8 NCE, OneDrive deployed on every endpoint, and three shared mailboxes added at no additional license cost — a tenant that actually works on every machine.
- OneDrive on all 5 endpoints
- Shared mailboxes for Sales / Accounting / info
- Pax8 NCE licensing managed
SentinelOne EDR + uSecure training
Enterprise-grade endpoint detection paired with active phishing simulations and CW RMM elevation monitoring — proactive findings reported back, not waiting for the user to call in.
- SentinelOne endpoint detection & response
- uSecure phishing simulations
- UAC elevation request alerting
Intune / Entra ID + Cloudflare DNS
Cloud-first identity and device management via Intune and Entra ID, with Cloudflare DNS taken under managed ownership — the foundation under both the Microsoft tenant and email delivery.
- Intune / Entra ID enrollment
- Dedicated Global Admin account
- Cloudflare DNS under managed ownership
ConnectWise RMM + Soaring Basics
ConnectWise RMM agents on every endpoint, automated patch and elevation monitoring, and a managed helpdesk under the Soaring Basics agreement — one phone number for everything that comes up.
- ConnectWise RMM on 5 endpoints
- Soaring Basics managed helpdesk
- Proactive Win11 lifecycle management
Ready to put guardrails on your business — without giving up the wheel?
If your shop is wrestling with self-inflicted DNS outages, unclear Microsoft 365 licensing, or a security misconfiguration nobody’s caught yet — we can help.
Get practical guidance for evaluating your Microsoft 365, security, and DNS posture. No commitment, no sales pressure.
Measurable outcomes for Outdoor Comfort Solutions.
A critical security risk found and fixed before any incident. A self-inflicted DNS outage pattern broken. New hires fully provisioned in roughly the time it takes to grab lunch. And not one critical or high-priority ticket across the engagement.
A hands-on owner with the foundation finally watched.
After partnering with Soaring Towers, Outdoor Comfort Solutions kept the owner-led, self-reliant operating style — but with guardrails under the parts that quietly accumulate risk.
-
Critical security risk eliminated proactivelyGlobal Administrator privileges separated from the production mailbox — found during a routine tenant review, fixed before any incident, with a dedicated unlicensed admin account in its place.
-
Cloud files on every endpointOneDrive deployed across all five managed machines, SharePoint sync running on every device, and three shared mailboxes added at zero additional license cost.
-
Email no longer at the mercy of DNS editsSoaring Towers now owns Cloudflare DNS — the recurring self-inflicted outage pattern has a structural owner instead of a hopeful fix.
-
Standardized employee lifecycleNew hires fully provisioned in roughly 35 minutes; departures handled via a repeatable workflow that deletes accounts and recovers licenses — reducing owner workload per event.
-
Active security awareness programuSecure phishing simulations running across the team — the staff is being trained on the threat patterns that actually target small businesses.
So, it’s definitely a lot simpler now!
The Small-Business IT & Security Checklist
Before making your next technology decision, evaluate whether your Microsoft 365, DNS, and security setup can keep up with the way you actually run. Our free checklist surfaces:
- Microsoft 365 misconfigurations
- Global Admin & identity risks
- DNS & email continuity gaps
- Endpoint security weaknesses
- User lifecycle & license drift
- Phishing & awareness gaps
- 40+ technology review checkpoints
- Microsoft 365 best practices for small business
- Global Admin & identity hardening
- DNS & email continuity guidance
- SharePoint & OneDrive deployment
- Endpoint protection & awareness
A partner that puts guardrails on the foundation — not on the owner.
Small businesses with hands-on principals need a partner that respects how they operate. Our business-first approach owns the foundational parts that quietly accumulate risk — Microsoft 365, identity, DNS, security — while letting the principal stay close to the technology that runs the business.
Answers for owner-led businesses and small-team operators.
Don’t see your question? Reach out for a discovery call.
Microsoft 365 licensing and tenant management, RMM monitoring and patching on every endpoint, SentinelOne EDR, uSecure security awareness training, managed DNS, a managed helpdesk for day-to-day support, and proactive findings on misconfigurations — designed to put guardrails around the parts of your IT that quietly accumulate risk.
When the same account that receives your daily email also holds full tenant administrator privileges, a single successful phishing attack hands an attacker the keys to your entire Microsoft environment — password resets, mailbox access, data exfiltration, account takeover. Separating Global Admin into a dedicated, unlicensed admin account is one of the highest-impact security changes a small business can make.
DNS controls both your website routing and your email delivery (via MX records). A change made for one — say, moving web hosting — can accidentally overwrite or break the other. Once MX records are wrong, inbound email stops cold until DNS is fixed. Managed DNS ownership means changes get reviewed before they break the inbox.
Proactive findings (not just break-fix), willingness to work with hands-on owners instead of around them, real Microsoft 365 expertise, ownership of DNS and other foundational systems, fast response when something does go wrong, and cost-conscious licensing — not generic "enterprise" support repackaged for a five-person shop.
The stack we deployed for Outdoor Comfort Solutions.
Related Case Studies