Remote support means trusting someone inside your systems. Here is exactly how that access works, what limits it, and how you stay in control of it.
Most support providers ask for an admin account and a leap of faith. We built our access model the way we build client environments: least privilege, verified identity, and a full audit trail. Every control below is enforced by configuration, not by policy documents.
We connect through Microsoft’s delegated access model (GDAP), scoped to only the roles a task requires. Privileged rights are elevated just in time, expire automatically, and are never held permanently.
Every technician is background checked and signs in with phishing-resistant multi-factor authentication, from a company-managed device that must pass compliance checks before access is granted. Personal devices cannot connect. Ever.
All work happens inside your Microsoft 365 environment. We do not copy, export, or store your business data on our systems, and nothing about your environment leaves your tenant.
Every sign-in and every administrative action lands in your own audit logs, visible to you at any time. Our access can be reviewed on demand and revoked by you in one click. That is by design.
Your agreement is with CoachToph LLC, a Maryland limited liability company, under US law and US insurance. Delivery is performed by our vetted global team operating under every control on this page, with escalation to our Maryland-based principal.
Want the details in writing? Request our security one-pager, or bring your IT or compliance questions to a call. We would rather answer them before you sign than after.