Identity and Access Governance
Define roles, permissions, and administrative boundaries using role-based access controls with clear accountability across platform, security, and service teams.
Microsoft 365 Security, Identity & Tenant Migration
Enterprise Architecture and Delivery
About Andy Kemp Consulting
Hi, I’m Andy Kemp, an independent Microsoft 365, Security, and Identity Consultant with over two decades of experience helping organisations design, secure, and modernise their workplace environments.
I created Andy Kemp Consulting to give organisations direct access to enterprise‑level consulting expertise, delivered personally, without the overheads, dilution, or rigid engagement models that often come with larger consultancies.
Career background
My career in IT began in the late 1990s, working hands‑on with Microsoft technologies as they evolved from on‑premises infrastructure into cloud‑first platforms. Over the years, I’ve worked across internal IT roles, consultancy, and large‑scale enterprise programmes, supporting organisations of all sizes across the UK.
I spent several years working within Microsoft itself, supporting public sector, government, healthcare, and enterprise customers on Microsoft 365 adoption, security, identity, and modern workplace initiatives. That experience gave me a deep understanding of how Microsoft technologies are designed to work at scale, but also where theory and real‑world delivery often diverge.
Across my career, I’ve been involved in:
Microsoft 365 tenant design and modernisation
Identity and access management
Conditional Access and Zero Trust design
Endpoint management and device strategy
Tenant‑to‑tenant migration and consolidation
Security baseline implementation and remediation
Merger and acquisition technical integration
Throughout this work, one thing became very clear. Organisations don’t struggle because of a lack of technology. They struggle because of a lack of clarity, structure, and practical guidance.
Why I created Andy Kemp Consulting
I founded Andy Kemp Consulting to remove that gap.
Large organisations often expect enterprise‑grade thinking, but smaller and mid‑sized businesses frequently struggle to access the same level of expertise without committing to long, expensive engagements. At the same time, I saw too many programmes slowed down by overly theoretical advice that didn’t translate cleanly into delivery.
Andy Kemp Consulting exists to change that.
My aim is simple. To help as many organisations as possible make confident, informed decisions about Microsoft 365, security, and identity, regardless of their size.
Whether you are a small organisation taking your first steps into Microsoft 365, or a global enterprise managing complex identity and security challenges, you receive the same level of attention, care, and technical rigour.
How I work
Andy Kemp Consulting is deliberately small by design. All work is delivered directly by me.
This means:
No hand‑offs between sales and delivery
No junior consultants learning on your environment
No generic templates applied without context
Every engagement is built around your tenant, your constraints, and your operating model. My focus is on clarity before execution, helping you understand risks, dependencies, and priorities before committing to change.
I bring an enterprise‑level approach, but apply it pragmatically, ensuring recommendations are achievable, proportionate, and aligned to real‑world delivery.
What I want to achieve
My goal is not to grow a large consultancy or build a delivery factory. My goal is impact.
I want to support organisations that value:
Clear, honest advice
Security‑first thinking
Practical delivery over theory
Decisions backed by experience, not assumptions
By working closely with each client, I aim to leave them in a better position than I found them, with improved security, clearer direction, and confidence in their Microsoft 365 environment.
Working together
Andy Kemp Consulting is best suited to organisations that want a trusted partner, not just extra hands.
If you need help understanding your current Microsoft 365 posture, planning a migration, strengthening identity and access controls, or navigating a complex change programme, I’d be happy to help.
Book an introduction call
If you’d like to discuss your environment, challenges, or upcoming plans, you can book an introductory call.
This is a no‑pressure conversation to understand what you’re trying to achieve, highlight any immediate risks or opportunities, and determine whether working together makes sense.
A practical, scalable framework used to modernize Microsoft 365 environments while maintaining security, compliance, and operational clarity.
Define roles, permissions, and administrative boundaries using role-based access controls with clear accountability across platform, security, and service teams.
Implement security groups, Microsoft 365 groups, and dynamic membership patterns that support lifecycle management and clean ownership models.
Establish consistent policies for sharing, collaboration, and external access in Teams, SharePoint, and OneDrive with business-appropriate guardrails.
Align retention, data protection, and compliance controls using Purview capabilities to reduce risk while preserving operational usability.
Provide reporting and service visibility across users, identities, devices, and collaboration workloads to support informed governance decisions.
Design a model that supports future growth, mergers, new workloads, and policy changes without introducing unnecessary complexity.
Microsoft
Earned: Mar 6, 2023
Expires: Mar 6, 2026
Microsoft
Earned: Mar 29, 2023
Expires: Mar 29, 2026
Microsoft
Earned: May 2, 2024
Expires: May 2, 2026
Microsoft
Earned: May 29, 2024
Expires: May 29, 2026
Microsoft
Earned: Aug 22, 2019
Expires: Aug 22, 2026
Microsoft
Earned: Feb 15, 2023
Microsoft
Earned: Mar 22, 2019
Microsoft
Earned: Nov 27, 2014
Microsoft
Earned: Nov 20, 2014
Microsoft
Earned: Valid until December 31st 2026