CONSTRUCTION · SMALL AND MEDIUM BUSINESS

Managed IT and Proactive Security Built for a Hands-On Outdoor Comfort Business

How Outdoor Comfort Solutions ended self-inflicted DNS email outages, separated Global Admin from a production mailbox, and standardized cloud-first file access across every endpoint — all under a single managed IT agreement.

Outdoor Comfort Solutions
Managed by Soaring Towers
Industry
Outdoor Living · Products & Services
Location
Minot, ND
Footprint
Single office · Office & field staff
Engagement
Soaring Basics · Active since Nov 2025
Focus
Secure · Guided · Cloud-first
Client Interview

Hear it from Dave Lebrun at Outdoor Comfort Solutions

23 MIN 30 SEC
Watch the testimonial
Dave Lebrun
Outdoor Comfort Solutions
HDCaptions

“So, it’s definitely a lot simpler now!”

Dave Lebrun · Outdoor Comfort Solutions
Client
Outdoor Comfort Solutions
About the client

A hands-on, owner-led outdoor comfort business — serving the Minot, ND region with a small team of office and field staff.

Outdoor Comfort Solutions is a small, owner-led business in Minot, North Dakota, delivering outdoor living products and services to local and regional customers. President Dave Lebrun runs the day-to-day with a small team and a mix of office and field staff — and is the kind of hands-on operator who buys his own hardware, edits his own DNS records, and manages his own web hosting.

Dave came to Soaring Towers in November 2025 looking for guardrails, not a replacement for his IT instincts — a managed partner that could keep the foundation secure, the email running, and the team’s files where they need to be, while letting him stay close to the technology that runs his business.

The challenge

A self-managed setup quietly accumulating risk — without anyone watching the foundation.

An incompletely deployed Microsoft 365 tenant, a critical security misconfiguration nobody knew about, and a recurring self-inflicted email outage pattern — the same pattern we see across most owner-managed small businesses before they engage a managed IT partner.

  • SharePoint and OneDrive never deployed to endpoints
    The M365 tenant existed, but the OneDrive client wasn’t installed on the machines — so SharePoint files lived in the cloud and couldn’t sync locally on the team’s computers.
  • Global Admin tied to a production mailbox
    Dave’s own email account held full tenant administrator privileges — meaning a single phishing hit on his inbox would have handed an attacker the keys to the entire Microsoft environment.
  • Self-managed DNS causing recurring email outages
    Independent DNS edits between GoDaddy and Cloudflare broke MX records on at least two separate occasions — each time taking down all incoming email until Soaring Towers restored the routing.
  • M365 licensing confusion, no shared mailboxes
    Role-based addresses like Sales@, Accounting@, and info@ were unconfigured — and Dave believed adding more would require buying additional paid seats. No prior IT guidance on shared mailboxes existed.
The solution

A fully managed Microsoft 365 foundation with proactive security, owned DNS, and a real user lifecycle.

Soaring Towers designed and implemented a managed IT foundation built for an owner-led business where the principal stays close to the technology. The four pillars below put guardrails around the parts that needed protection — without taking the wheel away from Dave.

1
Microsoft 365 tenant build-out
OneDrive deployed on every endpoint, SharePoint sync standardized across the team, and three shared mailboxes (Sales@, Accounting@, info@) configured at zero added licensing cost.
2
Identity & security hardening
Global Administrator privileges separated from the production mailbox into a dedicated unlicensed admin account; SentinelOne EDR active on endpoints; CW RMM elevation monitoring on every Windows session; uSecure phishing simulations running.
3
DNS ownership & email stability
Soaring Towers took ownership of Cloudflare DNS, restored the MX records that broke when web-hosting changes spilled over, and built the guardrails to prevent the same outage pattern from repeating.
4
New hire & user lifecycle management
A standardized provisioning workflow — RMM agent, Windows updates, SharePoint sync, Entra/Intune enrollment — completed in roughly 35 minutes per new hire; structured offboarding to delete accounts and recover licenses.
Why managed IT matters

Today’s owner-led businesses need guardrails, not a replacement.

Hands-on operators want to stay close to their technology — they buy their own hardware, manage their own web hosting, and make their own decisions. What they don’t need is one DNS edit silently taking down email for a day, or a single phishing email handing over the entire tenant.

At Soaring Towers, we specialize in managed IT for small, owner-led businesses — putting the right guardrails in place so the principal can keep moving fast without breaking the foundation underneath.

Advanced cybersecurity
Microsoft 365 build-out
Microsoft 365 management
Identity & admin hardening
DNS & email continuity
User lifecycle management
Security awareness training
Strategic technology guidance
The technology stack we deployed

Four foundations of a guarded, owner-led small business.

Every layer below was selected and configured specifically for the realities of a small, hands-on operator — a Microsoft 365 tenant that finally works on every endpoint, the security guardrails the principal didn’t know he needed, and a DNS that stops surprising the inbox.

Productivity platform

Microsoft 365 F1 + SharePoint & OneDrive

Three licensed seats provisioned via Pax8 NCE, OneDrive deployed on every endpoint, and three shared mailboxes added at no additional license cost — a tenant that actually works on every machine.

  • OneDrive on all 5 endpoints
  • Shared mailboxes for Sales / Accounting / info
  • Pax8 NCE licensing managed
Endpoint security & awareness

SentinelOne EDR + uSecure training

Enterprise-grade endpoint detection paired with active phishing simulations and CW RMM elevation monitoring — proactive findings reported back, not waiting for the user to call in.

  • SentinelOne endpoint detection & response
  • uSecure phishing simulations
  • UAC elevation request alerting
Identity, devices & DNS

Intune / Entra ID + Cloudflare DNS

Cloud-first identity and device management via Intune and Entra ID, with Cloudflare DNS taken under managed ownership — the foundation under both the Microsoft tenant and email delivery.

  • Intune / Entra ID enrollment
  • Dedicated Global Admin account
  • Cloudflare DNS under managed ownership
Monitoring & managed helpdesk

ConnectWise RMM + Soaring Basics

ConnectWise RMM agents on every endpoint, automated patch and elevation monitoring, and a managed helpdesk under the Soaring Basics agreement — one phone number for everything that comes up.

  • ConnectWise RMM on 5 endpoints
  • Soaring Basics managed helpdesk
  • Proactive Win11 lifecycle management
Your partner in IT excellence

Ready to put guardrails on your business — without giving up the wheel?

If your shop is wrestling with self-inflicted DNS outages, unclear Microsoft 365 licensing, or a security misconfiguration nobody’s caught yet — we can help.

Get practical guidance for evaluating your Microsoft 365, security, and DNS posture. No commitment, no sales pressure.

The results

Measurable outcomes for Outdoor Comfort Solutions.

A critical security risk found and fixed before any incident. A self-inflicted DNS outage pattern broken. New hires fully provisioned in roughly the time it takes to grab lunch. And not one critical or high-priority ticket across the engagement.

35min
New-hire PC fully provisioned
RMM, Windows updates, SharePoint, Entra/Intune — in one session
2×
Recurring DNS-driven email outages resolved
Pattern structurally ended by managed DNS ownership
0tickets
Critical or high-priority incidents
Across the lifetime of the engagement
Measurable results

A hands-on owner with the foundation finally watched.

After partnering with Soaring Towers, Outdoor Comfort Solutions kept the owner-led, self-reliant operating style — but with guardrails under the parts that quietly accumulate risk.

  • Critical security risk eliminated proactively
    Global Administrator privileges separated from the production mailbox — found during a routine tenant review, fixed before any incident, with a dedicated unlicensed admin account in its place.
  • Cloud files on every endpoint
    OneDrive deployed across all five managed machines, SharePoint sync running on every device, and three shared mailboxes added at zero additional license cost.
  • Email no longer at the mercy of DNS edits
    Soaring Towers now owns Cloudflare DNS — the recurring self-inflicted outage pattern has a structural owner instead of a hopeful fix.
  • Standardized employee lifecycle
    New hires fully provisioned in roughly 35 minutes; departures handled via a repeatable workflow that deletes accounts and recovers licenses — reducing owner workload per event.
  • Active security awareness program
    uSecure phishing simulations running across the team — the staff is being trained on the threat patterns that actually target small businesses.
A guarded, owner-led IT environment — less time tracking down outages, more time running the business.

So, it’s definitely a lot simpler now!

DL
Dave Lebrun
President · Outdoor Comfort Solutions
Free download · for owner-led businesses

The Small-Business IT & Security Checklist

Before making your next technology decision, evaluate whether your Microsoft 365, DNS, and security setup can keep up with the way you actually run. Our free checklist surfaces:

  • Microsoft 365 misconfigurations
  • Global Admin & identity risks
  • DNS & email continuity gaps
  • Endpoint security weaknesses
  • User lifecycle & license drift
  • Phishing & awareness gaps
Download the free checklist
What’s inside
  • 40+ technology review checkpoints
  • Microsoft 365 best practices for small business
  • Global Admin & identity hardening
  • DNS & email continuity guidance
  • SharePoint & OneDrive deployment
  • Endpoint protection & awareness
Ideal for owner-led businesses · Small teams · SMB leaders
Why owner-led businesses choose us

A partner that puts guardrails on the foundation — not on the owner.

Small businesses with hands-on principals need a partner that respects how they operate. Our business-first approach owns the foundational parts that quietly accumulate risk — Microsoft 365, identity, DNS, security — while letting the principal stay close to the technology that runs the business.

Proactive security findings
We don’t wait for incidents — we find misconfigurations like Global Admin on production mailboxes during routine reviews and remediate before they’re exploited.
DNS & email continuity
We take ownership of the systems that take down email when they go wrong — so the next change doesn’t become the next outage.
Cost-conscious licensing
Shared mailboxes instead of paid seats, license recovery on offboarding, right-sized M365 plans — Pax8-managed and visible.
Fast new-hire onboarding
RMM, Windows updates, SharePoint, Entra/Intune enrollment — all in a single ~35-minute remote session per device.
Security awareness
uSecure phishing simulations train the right behavior — when something looks off, the team reports it instead of clicking it.
Owner-friendly partnership
We work alongside hands-on principals — keeping the wheel in their hands while putting guardrails around the road.
Frequently asked questions

Answers for owner-led businesses and small-team operators.

Don’t see your question? Reach out for a discovery call.

What does Soaring Basics managed IT include for a small business?

Microsoft 365 licensing and tenant management, RMM monitoring and patching on every endpoint, SentinelOne EDR, uSecure security awareness training, managed DNS, a managed helpdesk for day-to-day support, and proactive findings on misconfigurations — designed to put guardrails around the parts of your IT that quietly accumulate risk.

When the same account that receives your daily email also holds full tenant administrator privileges, a single successful phishing attack hands an attacker the keys to your entire Microsoft environment — password resets, mailbox access, data exfiltration, account takeover. Separating Global Admin into a dedicated, unlicensed admin account is one of the highest-impact security changes a small business can make.

DNS controls both your website routing and your email delivery (via MX records). A change made for one — say, moving web hosting — can accidentally overwrite or break the other. Once MX records are wrong, inbound email stops cold until DNS is fixed. Managed DNS ownership means changes get reviewed before they break the inbox.

Proactive findings (not just break-fix), willingness to work with hands-on owners instead of around them, real Microsoft 365 expertise, ownership of DNS and other foundational systems, fast response when something does go wrong, and cost-conscious licensing — not generic "enterprise" support repackaged for a five-person shop.

Services and technologies

The stack we deployed for Outdoor Comfort Solutions.

Microsoft 365 F1SharePoint & OneDriveShared Mailboxes Microsoft IntuneMicrosoft Entra IDGlobal Admin Hardening SentinelOne EDRuSecure Awareness TrainingUAC Elevation Monitoring Cloudflare DNS ManagementMX & Email ContinuityConnectWise RMM Managed HelpdeskPax8 LicensingUser Lifecycle Management License Right-SizingWindows 11 LifecycleSoaring Basics Agreement