Businesses run on Baseline.
One company sign-in. Every computer set up the same way. One home for email and files. One place to ask for help.
Baseline connects and manages these four parts so your company does not have a different setup for every employee and every computer.
- One documented setup, used for every customer
- Microsoft 365 licensing included in both employee plans
- A real Manager Portal for everyday changes
The idea behind all of it
What we mean by a standard.
- Every employee gets one company sign-in.
- Every company computer follows the same basic setup.
- Email, files, calendars, and Teams work together.
- Hiring, departures, software changes, and support follow one clear process.
No more one-off logins, one-off computers, or one-off fixes. That is what Baseline means by a standard.
The shape of it
Four parts, and what each one is responsible for.
The value is not any single part. It is what stops breaking when the four are designed to work together.
People
One company sign-in for every employee, one place to give access, and one place to shut it off when someone leaves.
Computers
Every company computer uses the same Windows setup, security settings, and software approval process.
Work
Email, files, meetings, calendars, and Microsoft apps work together in one connected setup.
Support
Employees ask for help in one place. Baseline tracks the request and handles it remotely during published business hours.
Want the exact Microsoft settings, Windows requirements, and security boundaries? The technical page lists them in detail. Each part below explains what changes, how it works, and what owners, managers, and employees experience. The details live on the security and standard page.
People
Signing in without a password.
Every employee gets one company sign-in. It controls their email, files, apps, and computer access. They sign in with a face, fingerprint, or device PIN instead of a normal password. Microsoft provides this through Entra, Windows Hello, and passkeys.
What it is
A passkey stays on a device the employee already controls, and is used with a face, fingerprint, or device PIN. There is no password to invent, reuse, share, or leave under a keyboard.
Setup happens before the first day. A text message brings a guided walkthrough that the person completes from their phone, at home, in a few minutes. Losing access is a recovery step a manager can start, not a locked door.
Why we built it this way
Password rules did not make people safer. They made passwords unmemorable, and unmemorable passwords get written down, reused, and shared. The rule created the behavior it was meant to prevent.
Removing the password removes that whole category of problem rather than managing it. It is also the single change employees notice most, which is why it is taught inside the workflow at the moment it is used.
For the owner
The lockout that stops work on payroll morning has a recovery path, and the question a client or insurer asks about how people sign in has an answer.
For the manager
A passkey reset is something you start yourself, from the portal, instead of a request that goes into a queue.
For the employee
Your face or your fingerprint. Nothing to invent, remember, or write down.
What this changes
A consistent, recoverable sign-in experience without a password to invent, remember, or write down.
Computers
Every company computer set up the same way.
Every supported company computer is connected to Baseline. That lets us apply the same Windows setup, security settings, and software rules from one place. This is called device enrollment and central management. Supported computers must run Windows 11 Pro, version 24H2 or later. Baseline checks compatibility before migration so replacements can be planned.
What it is
A computer is reset, signed in to with the company sign-in, and set up automatically. Setting one up, replacing one, and supporting one are the same steps every time, because there is only one set of steps.
Employees can use the computer normally, but installing certain programs or changing protected settings requires approval. When an approved installation needs extra permission, a manager creates a temporary installation password for that computer. It expires after use. Every supported computer also receives the same security setup automatically. Microsoft Defender for Business watches for malware and suspicious behavior and includes endpoint detection and response, or EDR. Web filtering can block selected categories of risky sites. BitLocker encrypts the drive. Windows Firewall settings are managed. Desktop, Documents, and Pictures are saved to OneDrive. The technical names for the software rules are standard user accounts and temporary administrator access.
Why we built it this way
Consumer computers bought one at a time, each set up a little differently, are the reason no two problems look alike. A common standard is what makes a problem diagnosable by someone who has never seen that particular machine.
Installing software becomes a deliberate act with a defined path. That friction is the point. It is the difference between a considered decision and one afternoon click that undoes a month.
For the owner
A dead laptop stops being a crisis, and the hardware standard is a known, dated investment rather than a surprise.
For the manager
You can see every company computer and who last signed in to it, and you hold the deliberate path for installations.
For the employee
Any compatible computer becomes yours by signing in. Your work was never only on the broken machine.
What this changes
A repeatable setup and support process, with software installation handled through an approved path instead of permanent administrator access.
Work
One new Microsoft setup, built before anything moves.
Company email, calendars, files, meetings, and chat work together in Microsoft 365. Shared files stay where the team can find them instead of living only on one employee’s computer. Baseline builds a separate Microsoft setup first, while the old setup keeps running. Once the new one is ready, people and information move in planned stages.
What it is
Email, calendars, files, chat, and collaboration run on the Microsoft 365 tools the business is already paying for. Files sit where a team can find them rather than on individual computers, so somebody leaving does not take company files and knowledge with them.
Microsoft Defender for Office 365 checks email links and attachments for phishing and malware. It also helps protect supported links and files shared through Teams, OneDrive, and SharePoint. Redundant subscriptions that duplicate something already included come off the bill on a schedule you agree to.
Why we built it this way
Converting an old setup in place keeps every one-off exception that made it unpredictable. Building new is slower to start and far cheaper to run, and it is the only way one documented setup can mean the same thing for every customer.
One documented setup that Baseline keeps current over time is also what lets a question about how your Microsoft setup works be answered in a day instead of investigated for a week.
For the owner
Three overlapping bills become one price per employee, and the setup can actually be described when somebody asks.
For the manager
Shared work has a place, and a group gets made when you need one.
For the employee
Your files are where they should be on day one, and they are not stranded on one machine.
What this changes
One managed Microsoft setup, with company data remaining the customer’s and master access transferring cleanly when service ends.
Support
One path for help, inside the tools your team already uses.
Your people ask in a private chat in the Baseline app inside Microsoft Teams. If Teams is unavailable, they text the Baseline number and follow the same path.
The published targets
- Business hours are Monday through Friday, 8:00 a.m. to 5:00 p.m. Mountain Time.
- Initial response within 30 minutes during business hours.
- Most ordinary covered requests target resolution in 2 to 4 business hours.
- A technician starts finding or fixing the cause within 24 business hours.
How the service is delivered
Support is delivered remotely during published business hours. Requests sent outside those hours are waiting for the team at the next business opening.
The Support Scope page lists the exact coverage, billable work, response targets, and service boundaries.
The Manager Portal
The work that used to require a support request.
A manager should not have to learn Microsoft administration to add an employee. Every screen below shows fictional company data.
- Hire a person. The portal can start account creation in less than 30 seconds.
- Remove a person. The portal can start access shutdown in less than 30 seconds.
- Follow employee onboarding through to completion.
- Follow employee offboarding through to completion.
- Reset a passkey when someone loses access.
- See every company computer and the person using it.
- Create and manage shared mailboxes.
- Issue a temporary local administrator password when an approved installation needs one.
- Open a support request and track where it stands.
When a manager adds or removes an employee, Baseline starts the change immediately. Microsoft may take a few minutes to finish applying it.
What this changes
Every action listed here works in the product today. When a manager adds or removes an employee, Baseline starts the change immediately. Microsoft may take a few minutes to finish applying it.
Going deeper
The technical standard, in detail.
The technical page explains employee sign-in, computer settings, Microsoft 365, access removal, and the limits of each control.
The next step
Find out whether the standard fits.
The reasoning holds up or it does not. The way to find out is a conversation about the setup you actually have.
In 30 minutes, we will map how your company works today, show what Baseline would change, and outline the clearest path forward.