VPN or Zero Trust
Either an encrypted tunnel into the office network or per-application access built on Zero Trust principles. Only an approved device signed in with a valid work account gets through.
Plenty of Danish offices switched to home working over a single weekend in 2020, using an exposed remote desktop port and a shared password. Arrangements like that survive only until the first automated scan stumbles on them. We build access differently: servers stay invisible from the internet, files remain in Microsoft 365 or on the server, and a leaver's access is shut off with one click.
The mix depends on the work people do. Email and documents call for one approach; an ERP or heavyweight specialist software calls for something quite different.
Either an encrypted tunnel into the office network or per-application access built on Zero Trust principles. Only an approved device signed in with a valid work account gets through.
With Azure Virtual Desktop or a terminal server the workspace runs centrally. Data never leaves the hosting environment, and the home PC acts purely as screen and keyboard.
An on-premises ERP or a demanding CAD package opens through a virtual desktop with snappy performance, and the database is never copied to the employee's machine.
Sign-in approval in Microsoft Authenticator plus Entra ID policies that block logins from unfamiliar countries or devices. A leaked password on its own unlocks nothing.
Laptops and phones are enrolled in Intune, encrypted with BitLocker and can be wiped remotely. When someone leaves, their account, VPN and mailbox close in a single action.
Mail, calendars, Teams meetings and shared files in SharePoint and OneDrive work from any device, so nobody has to email documents to themselves.
Three approaches that work in practice. The choice depends on your data requirements, not on how many people work from home.
Model 1
VPN on the laptop
Staff use a company laptop and connect through an encrypted tunnel.
Model 2
VDI or terminal server
Everything runs centrally; at home the employee only sees the screen image.
Model 3
Pure Microsoft 365
Mail, files and collaboration live in the cloud and nobody connects to the office network.
The most common weakness is a remote desktop published straight onto the internet. Automated scanners discover such machines within hours, and password guessing starts right away. If your setup looks like that, closing it comes first, ahead of everything else on the list.
Over a plain VPN to a database in the office, quite possibly, because many client-server systems cope badly with latency. The better route is a virtual desktop, where only the screen image travels across the connection. It then feels much like sitting at your office desk.
Through a virtual desktop or Microsoft 365 in the browser, yes, with Conditional Access rules that stop files being downloaded. That is precisely the benefit: company data never lands on the private machine. Letting personal devices straight onto the office network over VPN is something we advise against, because nobody can tell what is installed on them.
Sign-in logs showing who connected when and to which systems are part of good security. We do not install software that records screens or keystrokes. That kind of surveillance raises issues under GDPR and Datatilsynet's guidance on monitoring employees, and it usually does more harm than good.
MFA, Intune and VPN for an office of 30 people usually take one to two weeks, billed at DKK 895 per hour or included in a fixed agreement. Virtual desktops are priced separately, since the main cost is capacity for the number of simultaneous users you need.
Tell us how many people work away from the office and which systems they rely on. We will suggest a model that fits your data requirements.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.