Work · National food brokerage
IT operating-model standardization
Skills exercised
Standardization has been the operating model across both of my IT leadership roles. At a regional HVAC business, I replaced consumer hardware and disconnected systems with one supported stack across three offices and brands. At a national food brokerage, I scaled the same discipline into a formal enterprise program across nine regional estates. The vendors changed and the governance became more complex; the method did not.
The current company grew to more than 1,000 employees across 80+ locations. Each acquired business tends to arrive with its own tenant, laptops, firewall and switches, phone system, printers, vendors, support model, and way of working. Under a company-wide directive, I choose the technology standards and move each region toward one target state. Other functional leaders own standards in their domains, such as HR. Regions do not opt out of the technology model, although migrations can be phased and compatibility cases are documented rather than hidden.
The model was already proven at smaller scale
At the regional HVAC business, the shared stack covered Active Directory and Group Policy, business-grade endpoints, managed iPads, Microsoft 365, Meraki/Ubiquiti/Aruba networking, Windows Server and Hyper-V, Synology and Backblaze backup, OnSIP and later Zoom Phone, Polycom phones, monitoring, documentation, and common support procedures. Nicholson and Melton moved onto that underlying platform while keeping the customer-facing brand differences that mattered.
The problem
- Every acquisition arrives different A new business shows up with its own tenant, domain, network gear, phone and fax lines, printers, and support model, none of it matching the standard.
- Complexity compounds, headcount does not Without a standard, each new location multiplies the number of distinct things a small team has to know, license, and maintain.
- Inconsistent security posture Different MFA, patching, and endpoint-protection states across acquired environments are a real risk surface until everything is pulled to one baseline.
What every location converges to
- Identity and cloud A single Microsoft 365 / Entra ID tenant with one identity convention, a hybrid AD-to-Entra setup, consistent naming standards, and dynamic group membership.
- Security baseline Conditional Access, enforced MFA, privileged-role management, and Microsoft Defender applied uniformly so every location meets the same bar.
- Endpoints Dell business-class laptops replacing arbitrary online purchases, with Intune for Windows and Apple Business Manager plus Intune for Macs. Standard device profiles make enrollment, drivers, warranty support, troubleshooting, security, and lifecycle work repeatable.
- Endpoint security and patching One security and compliance baseline across the estate, using Intune, Defender XDR, Conditional Access, PIM, Windows LAPS, endpoint privilege management, and managed patching.
- Network stack Cisco Meraki firewalls with Aruba Instant On switching and wireless, site-to-site VPN, and a common addressing model, replacing the assortment of firewalls and switches that arrive with each office. See the multi-site network refresh.
- Telephony A single phone platform on Microsoft Teams Phone, with numbers ported and main lines moved to auto attendants and call queues, retiring the legacy per-site phone systems.
- Fax Legacy fax lines retired or moved to cloud fax where a fax requirement genuinely remains, so they are not anchoring an old phone circuit at every site.
- Print and MFP service MFP service consolidated with MTS Office as one vendor and support relationship. Fleet composition and contract coverage continue to be refined under the roadmap.
- Service desk One ITSM on Freshservice with a shared service catalog, consistent SLAs, categories, and workflows, so support works the same everywhere.
- DNS and domains Domains consolidated under one Cloudflare account (nameservers, MX, SPF, DKIM, DMARC), with registrars transferred in.
- Licensing Microsoft 365 licensing standardized and right-sized across the company rather than inheriting each acquisition's mix of plans and add-ons.
- Documentation A documentation framework spanning the core infrastructure domains, so operational knowledge is written down and standardized rather than living in one person's head. See the internal IT documentation library.
How an acquisition gets integrated
Each acquisition runs through a repeatable playbook rather than a from-scratch project. Source environments are usually Microsoft 365 or Google Workspace, each with its own quirks, so the playbook covers both paths:
- Discovery Audit the source tenant: users, mailboxes, shared mailboxes, room calendars, distribution groups, devices, network, phones, printers, domains, and any outside MSP relationship.
- Identity and email Provision accounts in the target tenant, then run cross-tenant mailbox moves (MoveBot for Microsoft 365, BitTitan / MigrationWiz for Google Workspace) through a coexistence-then-cutover sequence.
- Files Migrate OneDrive / Google Drive and SharePoint / Shared Drives, with the known gotchas handled (OneNote and Planner do not move cross-tenant, so they are exported and recreated).
- Phones and devices Port numbers to Teams Phone; unjoin devices from the source tenant and re-enroll them into Intune / Entra before the domain moves.
- Platform services Recreate Forms, Power Automate flows, Planner, and their Google equivalents in the correct dependency order.
- Domain and DNS cutover Remove the domain from the source tenant, add it to the target, transfer the registrar, and rebuild DNS (capturing the source SPF record before it is overwritten).
- Network and handoff Adopt or replace the site's network gear onto the Meraki standard, then take the outgoing MSP's credentials and documentation and cancel the contract.
The reusable PowerShell tooling and the operating playbook that drive this are a project in their own right. See the M&A IT Integration Toolkit.
What this demonstrates
- A career-long discipline The national program is a scaled continuation of the standardization model I built across three offices and brands, not a collection of recent migrations given a label afterward.
- Operating-model thinking, not point fixes The win is one consistent way of working across the whole company, not a pile of unrelated migrations.
- Operational simplicity Less variation means fewer support paths, less technician training, easier troubleshooting, more reliable onboarding, and stable inputs for automation.
- Change leadership The directive establishes the destination, but adoption still means working through resistance from selling owners and regional teams giving up familiar systems and local technology control.
- Cross-domain breadth Identity, security, endpoints, network, telephony, print, licensing, and service management all pulled to a single standard, end to end.
- Repeatable integration Acquisitions onboard against a playbook and a toolkit, so each one is faster, cheaper, and more consistent than the last.