What we configure

The mix depends on the work people do. Email and documents call for one approach; an ERP or heavyweight specialist software calls for something quite different.

Find the right model

VPN or Zero Trust

Either an encrypted tunnel into the office network or per-application access built on Zero Trust principles. Only an approved device signed in with a valid work account gets through.

Virtual desktops

With Azure Virtual Desktop or a terminal server the workspace runs centrally. Data never leaves the hosting environment, and the home PC acts purely as screen and keyboard.

ERP and specialist apps from home

An on-premises ERP or a demanding CAD package opens through a virtual desktop with snappy performance, and the database is never copied to the employee's machine.

MFA and Conditional Access

Sign-in approval in Microsoft Authenticator plus Entra ID policies that block logins from unfamiliar countries or devices. A leaked password on its own unlocks nothing.

Intune-managed devices

Laptops and phones are enrolled in Intune, encrypted with BitLocker and can be wiped remotely. When someone leaves, their account, VPN and mailbox close in a single action.

Teams, Outlook and SharePoint

Mail, calendars, Teams meetings and shared files in SharePoint and OneDrive work from any device, so nobody has to email documents to themselves.

Which model suits you

Three approaches that work in practice. The choice depends on your data requirements, not on how many people work from home.

Model 1

VPN on the laptop

Staff use a company laptop and connect through an encrypted tunnel.

Quick to introduce
Up and running in days
Data sits on the device
Needs encryption and Intune
Chosen most often

Model 2

VDI or terminal server

Everything runs centrally; at home the employee only sees the screen image.

Data stays put
Nothing lands on personal kit
New hires productive in minutes
No local build required

Model 3

Pure Microsoft 365

Mail, files and collaboration live in the cloud and nobody connects to the office network.

Works anywhere
Independent of the office line
Does not cover local systems
An on-site ERP server needs more

The most common weakness is a remote desktop published straight onto the internet. Automated scanners discover such machines within hours, and password guessing starts right away. If your setup looks like that, closing it comes first, ahead of everything else on the list.

Questions and answers

Over a plain VPN to a database in the office, quite possibly, because many client-server systems cope badly with latency. The better route is a virtual desktop, where only the screen image travels across the connection. It then feels much like sitting at your office desk.

Through a virtual desktop or Microsoft 365 in the browser, yes, with Conditional Access rules that stop files being downloaded. That is precisely the benefit: company data never lands on the private machine. Letting personal devices straight onto the office network over VPN is something we advise against, because nobody can tell what is installed on them.

Sign-in logs showing who connected when and to which systems are part of good security. We do not install software that records screens or keystrokes. That kind of surveillance raises issues under GDPR and Datatilsynet's guidance on monitoring employees, and it usually does more harm than good.

MFA, Intune and VPN for an office of 30 people usually take one to two weeks, billed at DKK 895 per hour or included in a fixed agreement. Virtual desktops are priced separately, since the main cost is capacity for the number of simultaneous users you need.

Let us set up remote working

Tell us how many people work away from the office and which systems they rely on. We will suggest a model that fits your data requirements.

Coverage
All of Denmark, delivered remotely

This site uses only essential cookies: they keep pages working and store your chosen town. Read more in our privacy policy.