GCIT Technology Standards

These standards ensure every environment we manage is secure, reliable, and compliant.

Built on Microsoft’s recommended baselines and strengthened by our ISO 27001, 9001, and 14001 certifications. These standards define the products, services, and configurations we recognise as Approved, Supported, or Unsupported across major areas of IT management.

By aligning with the GCIT Technology Standards, our clients benefit from:

  • Higher Microsoft Secure Scores
  • Reduced cyber risk through consistent configuration and monitoring
  • Predictable service and support outcomes
  • A scalable foundation for ISO, SOC, and regulatory compliance
Ryan Colombo — Head of Operations at GCIT

Ryan Colombo

Head of Operations

Cloud Services

Approved​

Supported

Unsupported

  • Microsoft 365 Business Premium and Microsoft 365 E3/E5 under GCIT management. 
 
  • If lower-tier Microsoft 365 licensing is required (e.g., Business Basic, Exchange Online Plan), devices must also be licensed for Intune and Defender for Endpoint when those users use managed devices. 
 
  • Entra ID, OneDrive, and SharePoint integrated with Defender for Cloud Apps and SSO. 
  • Slack, Trello, Monday.com, Zoom, and similar tools when SSO-integrated, secured (e.g., MFA for Zoom), and GCIT is authorised for admin/integration.
 
  • Other enterprise file-sharing platforms (e.g., Box, Egnyte, Google Drive) supported only with SSO and GCIT governance/monitoring access.
  • Unmanaged/unsanctioned collaboration platforms (e.g., Discord, WhatsApp, Signal) for business communication.
 
  • Any tool that bypasses GCIT’s monitoring, compliance, or data protection controls.

Approved​

Supported

Unsupported

  • Windows 11 Pro/Enterprise devices managed via Intune, compliant with GCIT policies, reporting to Defender for Endpoint.
 
  • Latest macOS devices managed via Apple Business Manager + Intune, compliant with GCIT policies.
  • Windows 10 devices only with ESU entitlement in place.
 
  • macOS versions that are still supported by Apple but not the current release.
  • Windows versions older than 10 or Windows 10 without ESU.
 
  • End-of-life macOS versions.
 
  • Unmanaged/BYOD devices for business use.

Approved​

Supported

Unsupported

  • Microsoft Defender for Endpoint with EDR + Attack Surface Reduction, integrated with Intune and GCIT monitoring. 
  • ThreatLocker for application allow-listing and ringfencing. 
  • Enterprise-grade AV/EDR (e.g., CrowdStrike, Sophos, SentinelOne) when fully managed by an existing MSSP or the client’s internal IT.
 
  • GCIT’s role is cooperative; primary oversight remains with the existing provider.
  • Windows versions older than 10 or Windows 10 without ESU.
 
  • End-of-life macOS versions.
 
  • Unmanaged/BYOD devices for business use.

Approved​

Supported

Unsupported

  • Entra ID with MFA via Authenticator, FIDO2 security keys, or passkeys.
  • Conditional Access that blocks untrusted countries and/or requires compliant devices for access.
  • Continuous monitoring with Defender for Identity and Defender for Cloud Apps.
  • Travelling-user exceptions: supported only when scheduled and advised to GCIT ahead of travel to avoid interruptions.
  • Requests to exclude specific users from country-block CA policies: supported only with written approval naming the users and when GCIT can implement phishing-resistant MFA and/or managed ITDR (e.g., Huntress) across the organisation.
  • Practice Protect or similar tools for certain industries: supported only where the client maintains an active vendor support relationship and GCIT is authorised to work with the vendor for provisioning and troubleshooting. This is an adjunct; Entra ID remains the primary identity platform under GCIT.
  • Third-party identity providers (e.g., Okta, Ping) as the primary identity solution under GCIT management.
  • Password-only sign-ins, shared admin accounts, or legacy auth (POP/IMAP/SMTP Basic).

Approved​

Supported

Unsupported

  • UniFi or FortiGate purchased via GCIT Hardware-as-a-Service (HaaS) and fully adopted into GCIT management (monitoring, alerting, configuration backup). 
  • Active support subscriptions; lifecycle managed by GCIT. 
  • Configured to GCIT secure standards (network segmentation, IPS where applicable, current firmware, central logging). 
  • Enterprise hardware (e.g., Cisco, SonicWall, Sophos, Meraki, Aruba) where the client maintains valid licenses/support. GCIT support focuses on troubleshooting and integration, not full lifecycle/config ownership.
  • Devices older than ~5 years or without an active subscription may be supported temporarily with a remediation/replacement plan.
  • Remote management must be secured (no exposed mgmt interfaces), and firmware must be current.
  • Consumer-grade/ISP-provided routers and unmanaged Wi-Fi. 
  • End-of-life hardware or insecure network practices (open NAT/port forwards to internal devices, exposed admin interfaces, unsupported VPNs). 

Approved​

Supported

Unsupported

  • GCIT-managed SaaS backup for Microsoft 365 (Keepit) with immutable storage, encryption in transit/at rest, SSO-protected access, daily verification, and monthly restoration testing.
 
  •  GCIT-managed Veeam for infrastructure backups with on-site and off-site replication; monitored by GCIT and tested on a schedule.
 
  •  Workstation data protected via OneDrive, with data included in Keepit backups.
  • Enterprise backup platforms (e.g., Datto, Acronis, Veeam not managed by GCIT) where GCIT can verify integrity and confirm off-site replication. Reporting/verification access must be provided. 
 
  • Vendor/MSP-managed backups are supported when operational transparency and evidence of periodic restore tests are available to GCIT. 
  • Consumer/local-only backups (USB drives, unmanaged NAS) or backups without redundancy, encryption, or verification.
 
  •  Unmonitored or untested backups.

Approved​

Supported

Unsupported

Exchange Online configured to Microsoft’s strict Defender/M365 security baselines, including:

  • Anti-Phish, Anti-Malware, and Spam (inbound & outbound) policies at strict levels.
  • Safe Links and Safe Attachments.
  • Impersonation protection, transport
  • hygiene, and compromised user detection.
  • Correct and monitored SPF, DKIM, and DMARC.
  • Advanced Avanan Email Security with AI-powered phishing detection (where adopted).
  • Enterprise mail security tools the client already uses (e.g., Mimecast, Proofpoint, Barracuda) with an active vendor support relationship.
  •  Documented, minimal relaxations from strict settings only to address legitimate deliverability issues; changes recorded by GCIT with risk justification.
  • Consumer/local-only backups (USB drives, unmanaged NAS) or backups without redundancy, encryption, or verification.
 
  •  Unmonitored or untested backups.

Approved​

Supported

Unsupported

  • Microsoft Teams for chat/meetings, SharePoint Online for document management, OneDrive for secure file storage/backup.
  • Planner, Loop, Whiteboard for task/project coordination and ideation.
  • Dropbox when protected by Defender for Cloud Apps and secured with SSO.
  • Microsoft Teams for chat/meetings, SharePoint Online for document management, OneDrive for secure file storage/backup.
  • Planner, Loop, Whiteboard for task/project coordination and ideation.
  • Dropbox when protected by Defender for Cloud Apps and secured with SSO.
  • Unmanaged/unsanctioned collaboration platforms (e.g., Discord, WhatsApp, Signal) for business communication.
  • Any tool that bypasses GCIT’s monitoring, compliance, or data protection controls.

Approved​

Supported

Unsupported

  • Microsoft Secure Score tracking and improvement across managed tenants. 
  • Defender for Cloud Apps and Defender for Identity for continuous detection of risky activities. 
  • ImmyBot for deployment/configuration/compliance checks; Microsoft Purview for DLP, retention, and auditing. 
  • Integration with ThreatLocker and Huntress for extended endpoint and identity threat detection/response. 
  • Client-managed ISO or SOC programs are approved; note that project/ad-hoc charges may apply when GCIT is asked to produce manual evidence or conduct bespoke compliance activities. 
  • Third-party monitoring/compliance platforms (Auvik, Liongard, Vanta, Drata) where GCIT has admin/reader access to verify configuration and alerting.
  • Unmanaged/unsanctioned collaboration platforms (e.g., Discord, WhatsApp, Signal) for business communication.
  • Any tool that bypasses GCIT’s monitoring, compliance, or data protection controls.

Cloud Services

Approved​

  • Slack, Trello, Monday.com, Zoom, and similar tools when SSO-integrated, secured (e.g., MFA for Zoom), and GCIT is authorised for admin/integration.
 
  • Other enterprise file-sharing platforms (e.g., Box, Egnyte, Google Drive) supported only with SSO and GCIT governance/monitoring access.

Supported

  • Microsoft 365 Business Premium and Microsoft 365 E3/E5 under GCIT management. 
 
  • If lower-tier Microsoft 365 licensing is required (e.g., Business Basic, Exchange Online Plan), devices must also be licensed for Intune and Defender for Endpoint when those users use managed devices. 
 
  • Entra ID, OneDrive, and SharePoint integrated with Defender for Cloud Apps and SSO. 

Unsupported

  • Unmanaged/unsanctioned collaboration platforms (e.g., Discord, WhatsApp, Signal) for business communication.
 
  • Any tool that bypasses GCIT’s monitoring, compliance, or data protection controls.

Approved​

  • Windows 11 Pro/Enterprise devices managed via Intune, compliant with GCIT policies, reporting to Defender for Endpoint.
 
  • Latest macOS devices managed via Apple Business Manager + Intune, compliant with GCIT policies.

Supported

  • Windows 10 devices only with ESU entitlement in place.
 
  • macOS versions that are still supported by Apple but not the current release.

Unsupported

  • Windows versions older than 10 or Windows 10 without ESU.
 
  • End-of-life macOS versions.
 
  • Unmanaged/BYOD devices for business use.

Approved​

  • Microsoft Defender for Endpoint with EDR + Attack Surface Reduction, integrated with Intune and GCIT monitoring. 
  • ThreatLocker for application allow-listing and ringfencing. 

Supported

  • Enterprise-grade AV/EDR (e.g., CrowdStrike, Sophos, SentinelOne) when fully managed by an existing MSSP or the client’s internal IT.
 
  • GCIT’s role is cooperative; primary oversight remains with the existing provider.

Unsupported

  • Windows versions older than 10 or Windows 10 without ESU.
 
  • End-of-life macOS versions.
 
  • Unmanaged/BYOD devices for business use.

Approved​

  • Entra ID with MFA via Authenticator, FIDO2 security keys, or passkeys.
  • Conditional Access that blocks untrusted countries and/or requires compliant devices for access.
  • Continuous monitoring with Defender for Identity and Defender for Cloud Apps.

Supported

  • Travelling-user exceptions: supported only when scheduled and advised to GCIT ahead of travel to avoid interruptions.
  • Requests to exclude specific users from country-block CA policies: supported only with written approval naming the users and when GCIT can implement phishing-resistant MFA and/or managed ITDR (e.g., Huntress) across the organisation.
  • Practice Protect or similar tools for certain industries: supported only where the client maintains an active vendor support relationship and GCIT is authorised to work with the vendor for provisioning and troubleshooting. This is an adjunct; Entra ID remains the primary identity platform under GCIT.

Unsupported

  • Third-party identity providers (e.g., Okta, Ping) as the primary identity solution under GCIT management.
  • Password-only sign-ins, shared admin accounts, or legacy auth (POP/IMAP/SMTP Basic).

Approved​

  • UniFi or FortiGate purchased via GCIT Hardware-as-a-Service (HaaS) and fully adopted into GCIT management (monitoring, alerting, configuration backup). 
  • Active support subscriptions; lifecycle managed by GCIT. 
  • Configured to GCIT secure standards (network segmentation, IPS where applicable, current firmware, central logging). 

Supported

  • Enterprise hardware (e.g., Cisco, SonicWall, Sophos, Meraki, Aruba) where the client maintains valid licenses/support. GCIT support focuses on troubleshooting and integration, not full lifecycle/config ownership.
  • Devices older than ~5 years or without an active subscription may be supported temporarily with a remediation/replacement plan.
  • Remote management must be secured (no exposed mgmt interfaces), and firmware must be current.

Unsupported

  • Consumer-grade/ISP-provided routers and unmanaged Wi-Fi. 
  • End-of-life hardware or insecure network practices (open NAT/port forwards to internal devices, exposed admin interfaces, unsupported VPNs). 

Approved​

  • GCIT-managed SaaS backup for Microsoft 365 (Keepit) with immutable storage, encryption in transit/at rest, SSO-protected access, daily verification, and monthly restoration testing.
 
  •  GCIT-managed Veeam for infrastructure backups with on-site and off-site replication; monitored by GCIT and tested on a schedule.
 
  •  Workstation data protected via OneDrive, with data included in Keepit backups.

Supported

  • Enterprise backup platforms (e.g., Datto, Acronis, Veeam not managed by GCIT) where GCIT can verify integrity and confirm off-site replication. Reporting/verification access must be provided. 
 
  • Vendor/MSP-managed backups are supported when operational transparency and evidence of periodic restore tests are available to GCIT. 

Unsupported

  • Consumer/local-only backups (USB drives, unmanaged NAS) or backups without redundancy, encryption, or verification.
 
  •  Unmonitored or untested backups.

Approved​

Exchange Online configured to Microsoft’s strict Defender/M365 security baselines, including:

  • Anti-Phish, Anti-Malware, and Spam (inbound & outbound) policies at strict levels.
  • Safe Links and Safe Attachments.
  • Impersonation protection, transport
  • hygiene, and compromised user detection.
  • Correct and monitored SPF, DKIM, and DMARC.
  • Advanced Avanan Email Security with AI-powered phishing detection (where adopted).

Supported

  • Enterprise mail security tools the client already uses (e.g., Mimecast, Proofpoint, Barracuda) with an active vendor support relationship.
  •  Documented, minimal relaxations from strict settings only to address legitimate deliverability issues; changes recorded by GCIT with risk justification.

Unsupported

  • Consumer/local-only backups (USB drives, unmanaged NAS) or backups without redundancy, encryption, or verification.
 
  •  Unmonitored or untested backups.

Approved​

  • Microsoft Teams for chat/meetings, SharePoint Online for document management, OneDrive for secure file storage/backup.
  • Planner, Loop, Whiteboard for task/project coordination and ideation.
  • Dropbox when protected by Defender for Cloud Apps and secured with SSO.

Supported

  • Microsoft Teams for chat/meetings, SharePoint Online for document management, OneDrive for secure file storage/backup.
  • Planner, Loop, Whiteboard for task/project coordination and ideation.
  • Dropbox when protected by Defender for Cloud Apps and secured with SSO.

Unsupported

  • Unmanaged/unsanctioned collaboration platforms (e.g., Discord, WhatsApp, Signal) for business communication.
  • Any tool that bypasses GCIT’s monitoring, compliance, or data protection controls.

Approved​

  • Microsoft Secure Score tracking and improvement across managed tenants. 
  • Defender for Cloud Apps and Defender for Identity for continuous detection of risky activities. 
  • ImmyBot for deployment/configuration/compliance checks; Microsoft Purview for DLP, retention, and auditing. 
  • Integration with ThreatLocker and Huntress for extended endpoint and identity threat detection/response. 
  • Client-managed ISO or SOC programs are approved; note that project/ad-hoc charges may apply when GCIT is asked to produce manual evidence or conduct bespoke compliance activities. 

Supported

  • Third-party monitoring/compliance platforms (Auvik, Liongard, Vanta, Drata) where GCIT has admin/reader access to verify configuration and alerting.

Unsupported

  • Unmanaged/unsanctioned collaboration platforms (e.g., Discord, WhatsApp, Signal) for business communication.
  • Any tool that bypasses GCIT’s monitoring, compliance, or data protection controls.
Ready to secure and simplify your IT? Talk to a GCIT expert today.