How do you bring the intranet to technicians without opening a breach in your Microsoft 365 tenant?
In energy, water and network operations, technicians pick up shared devices at the depot, lose the signal in plant rooms and work alongside contractors who have no account in your directory. 63% of frontline workers say that messages from leadership do not reach them (Microsoft WorkLab, 2022). The generic answers of employee apps assume an email address, a personal phone and a network connection, and none of the three is a given in the field.
This white paper shows that the decision is not between building and buying, but between three architectures, and that a single question separates them: where identities and documents are stored, and who sends the notification.
What's inside:
- The decision on one page: the three questions to ask before any vendor consultation (who the users are, on which devices, with what network) and the five criteria that decide.
- What your tenant already provides: what Microsoft 365 F1 and F3 licenses cover for frontline identity, device management and conditional access, and five ways to sign in without blocking the field.
- Three architectures, not two: native Microsoft 365, a dedicated app outside the tenant and a tenant extension, compared on where identities, documents and notifications live.
- The twelve-criterion grid: a four-state grid (native, with configuration, vendor-dependent, to verify), with weighting rules for your committee and the cells to demand proof for in a demo.
- Ten risks, ten countermeasures: a field risk matrix, from a session left open on a shared device to personal messaging apps, each risk with its countermeasure in the tenant, and the NIS 2 context for operations in the European Union.
- Three levels of CMMS integration: from an authenticated deep link to an offline data entry app, with the prerequisites and the license each level requires.
- Twenty checkpoints and a roadmap: checkpoints on identity, devices, data, compliance and operations, then three milestones at 30, 90 and 180 days, ready to drop into your request for proposals.
Why download it:
A decision framework, not a product catalog. The grid describes each architecture in general terms and leaves every "to verify" cell to be proven on your own devices, Jint included.
Grounded in Microsoft documentation. Each tenant capability is referenced to Microsoft Learn, with licensing details for F1 and F3 and the limits of each sign-in method.
Security treated as a budget line. The risk matrix lets your CISO tick the countermeasures already in place and cost the missing ones, whatever option you choose.
Tools ready for your committee. The grid, the matrix and the checklist can be presented as they are and copied into your request for proposals.



.webp)
