A hybrid cloud environment designed for 150 Australis Facade users working from the office, remotely and across construction sites.
Australis Facade is a commercial construction and engineering subcontractor in Sydney that designs, supplies and installs external building envelopes, curtain walls and glass-and-aluminium window systems for high-rise residential and commercial developments. Its approximately 150 users work from the Sydney office, remotely and across active construction sites, and depend on Microsoft 365, project documentation, finance systems, consultant collaboration and access to large design and BIM files every day. The objective was not to “move everything to cloud” — that would have created performance, access and support risk. Australis Facade needed a hybrid Azure architecture that modernised identity, collaboration, security, backup and remote access while keeping selected workloads local where performance still mattered.
Inlight IT designed and delivered the hybrid platform across Microsoft Entra ID, Microsoft 365, SharePoint, Exchange Online, Teams, OneDrive, Azure Virtual Desktop, Intune, Azure Backup, Microsoft Defender and refreshed on-premises infrastructure for retained BIM and financial-system workloads. The result was a 150-user hybrid environment with cloud where it improved the operating model, local infrastructure where it protected performance, and one managed identity, security and backup model across both.
- Client
- Australis Facade
- Industry
- Façade engineering and construction
- Location
- Sydney, NSW
- Environment
- 150 users across the Sydney office, remote locations and construction sites: the Sydney office, remote locations and active construction sites
- Starting point
- Legacy on-premises infrastructure no longer matched the scale and mobility of the business
- Engagement type
- Hybrid Azure architecture, Microsoft 365 migration, identity modernisation, SharePoint project environment, Azure Virtual Desktop, on-premises refresh, backup and security uplift
- Architecture outcome
- Azure and Microsoft 365 for identity, collaboration, document governance, remote access, endpoint management, backup and security; on-premises retained for BIM file services and latency-sensitive financial workloads
Australis Facade — hybrid Azure migration for approximately 150 users
Cloud where it improved the operating model, local infrastructure where it protected performance.
A 150-user migration judged by workload fit, not volume moved
Users supported across the hybrid environment through one governed identity, collaboration and access model.
Azure for identity, collaboration, backup and remote access; on-premises for BIM and selected financial workloads.
Conditional Access, MFA and device compliance across cloud and on-premises access.
Mailboxes, collaboration tools and project data migrated in sequenced waves with continuity maintained.
The best cloud migration was not the one that moved the most infrastructure — it was the one that put every workload where it belonged
Australis Facade's technology environment had to support the operating rhythm of facade engineering and construction: active projects, design and engineering work, finance processes, consultant collaboration and long-running project records, across users based in the Sydney office, working remotely and working on active construction sites.
For a 150-user business, the old model had become too dependent on legacy access patterns and on-premises infrastructure. Users needed better collaboration, cleaner document governance, stronger identity, easier remote access and stronger backup.
At the same time, large design and BIM files and selected project finance systems had performance and latency requirements that made a full cloud lift-and-shift the wrong answer. Inlight IT designed the migration as a hybrid architecture from the beginning.
Australis Facade needed cloud modernisation without compromising project performance, financial systems or operational cadence
The migration had to improve the way approximately 150 users worked across sites, while protecting the systems and data flows that keep a facade engineering and construction business moving. That meant a workload-by-workload architecture decision, not a blanket migration.
150 users needed one identity and access model
Australis Facade had users working from the Sydney office, remotely and across active construction sites. Access had to be governed consistently — whether users were opening Microsoft 365, SharePoint project sites, Azure Virtual Desktop or retained on-premises systems — with MFA, device compliance, single sign-on and conditional access, without separate credential sets.
Project data needed governance, not just a new storage location
Project data moves between internal teams, consultants, contractors, builders and project stakeholders. The risk was version control, access scope, project lifecycle, auditability and retrieval. Australis Facade needed SharePoint structured around actual development projects, not a generic document library.
BIM and large design files needed local-speed performance
Large BIM and design files could not be moved blindly into cloud storage without risking slow access, user frustration and support escalation. The architecture needed to preserve local performance where it mattered while improving remote access through Azure Virtual Desktop.
Financial systems had latency requirements
The financial system supported project finance workflows, needing predictable performance and sub-second responsiveness. Moving it simply because “cloud migration” was the project would have been poor architecture.
Backup and security needed to cover both environments
A hybrid estate only works when backup, endpoint security, identity, access and recovery are governed across the whole platform. Azure and on-premises could not become two separate environments with two separate control models.
A phased hybrid Azure migration across approximately 150 users, with identity and project governance established before workload change
The migration was sequenced to reduce risk. Identity came first. Collaboration and project data followed. Remote access was modernised through Azure Virtual Desktop. On-premises infrastructure was refreshed after the cloud foundation was already in place, so retained workloads could be right-sized rather than overbuilt.
01Identity first
Microsoft Entra ID became the single identity model across cloud and on-premises access, with Conditional Access enforcing MFA and device compliance for approximately 150 users.
02Project data structured around workflows
Project data was structured around project workflows, not a generic SharePoint template — SharePoint Online project sites built around active projects.
03Collaboration migrated in waves
Mail, Teams, OneDrive and collaboration migrated in sequenced waves with continuity maintained throughout, so users kept working through the change.
04Remote access modernised
Azure Virtual Desktop replaced legacy remote access for users who needed governed access to retained systems, with Intune managing devices across office, remote and site users.
05Local infrastructure right-sized
Local infrastructure was modernised for the workloads that still belonged there — BIM file services and latency-sensitive finance — refreshed and right-sized after the cloud foundation was in place, with Azure Backup protecting retained workloads offsite.
Sequenced to reduce risk, from identity foundation to right-sized local infrastructure
Select a stage to trace how the migration moved from identity foundation to right-sized local infrastructure.
A facade engineering and construction environment contains different workload classes, and they do not all belong in the cloud
Microsoft 365, Teams, Exchange Online, OneDrive and SharePoint suit cloud-first delivery — they improve collaboration, mobile access, administration, security and governance. BIM file services and selected financial workloads are different: they depend on file size, application behaviour, latency, query performance and user experience, and forcing them into cloud can create more friction than value. The Australis Facade migration succeeded because it was not judged by the percentage of infrastructure moved to Azure — it was judged by whether identity, access, collaboration, backup, security and performance improved together.
Users moved to one governed identity, collaboration and access model across cloud and on-premises.
Data loss through migration — mailboxes, collaboration tools and project data moved in sequenced waves with continuity maintained.
One governance model across both environments — identity, security and backup managed as a single platform.
Five sequenced delivery phases, from identity first to right-sized local infrastructure after the cloud foundation was in place.
Australis Facade gained a 150-user hybrid Azure platform with cloud, local infrastructure and security working as one environment
The migration gave Australis Facade a stronger technology platform for facade engineering and construction operations. Users gained better collaboration, access and mobility. Project data became easier to govern. Identity and security became more consistent. Retained workloads continued to run where performance justified local infrastructure.
Better collaboration and mobility
150 users gained stronger collaboration and remote access across the Sydney office, remote locations and active construction sites.
Project data governed
SharePoint structured around real developments gave version control, access scope and auditability, not just new storage.
Consistent identity and security
One Entra ID model with MFA, Conditional Access and Defender applied across cloud and on-premises access.
Performance protected
BIM and finance workloads continued to perform on right-sized local infrastructure.
Backup across the full estate
Azure Backup and a single recovery model covered both cloud and retained on-premises workloads.
Remote access modernised
Azure Virtual Desktop replaced legacy remote access, with Intune managing devices across office, remote and site users.
Cloud where it improved the operating model. Local where it protected performance. One governance model across both.
A hybrid Azure model built around workload fit, not migration enthusiasm
Sydney office, remote and site-based workforce
Hybrid platform built around the Sydney office, remote locations and active construction sites.
150-user hybrid environment
Identity, collaboration, access and backup governed across the whole user base.
Entra ID single identity model
MFA, Conditional Access and device compliance across cloud and on-premises.
SharePoint structured by project
Document governance built around active projects, not a generic library.
BIM and finance kept local
Latency-sensitive workloads retained on right-sized local infrastructure.
Zero data loss at cutover
Mailboxes, collaboration and project data migrated in sequenced waves with continuity maintained.
The work connected cloud platform, identity, remote access and retained infrastructure
Cloud platform & collaboration
7- Hybrid Azure architecture
- Microsoft 365 migration
- Exchange Online
- SharePoint Online
- Microsoft Teams
- OneDrive
- Sequenced migration waves
Identity & security
7- Microsoft Entra ID
- Conditional Access
- MFA
- Device compliance
- Single sign-on
- Microsoft Defender
- Intune endpoint management
Remote access & continuity
7- Azure Virtual Desktop
- Governed access to retained systems
- Azure Backup
- Single recovery model
- Continuity through cutover
- Zero data loss migration
- Mobility across sites
Retained infrastructure
7- On-premises refresh
- BIM file services
- Latency-sensitive finance workloads
- Right-sized infrastructure
- Workload placement
- Local-speed performance
- Project finance systems
Planning a cloud migration where performance, project data and retained systems still matter?
We assess which workloads belong in cloud, then plan and run the migration.
Discuss cloud migration and managed cloud