Businesses run on Baseline.

One company sign-in. Every computer set up the same way. One home for email and files. One place to ask for help.

Baseline connects and manages these four parts so your company does not have a different setup for every employee and every computer.

  • One documented setup, used for every customer
  • Microsoft 365 licensing included in both employee plans
  • A real Manager Portal for everyday changes

The idea behind all of it

What we mean by a standard.

  • Every employee gets one company sign-in.
  • Every company computer follows the same basic setup.
  • Email, files, calendars, and Teams work together.
  • Hiring, departures, software changes, and support follow one clear process.

No more one-off logins, one-off computers, or one-off fixes. That is what Baseline means by a standard.

The shape of it

Four parts, and what each one is responsible for.

The value is not any single part. It is what stops breaking when the four are designed to work together.

People

One company sign-in for every employee, one place to give access, and one place to shut it off when someone leaves.

Computers

Every company computer uses the same Windows setup, security settings, and software approval process.

Work

Email, files, meetings, calendars, and Microsoft apps work together in one connected setup.

Support

Employees ask for help in one place. Baseline tracks the request and handles it remotely during published business hours.

Want the exact Microsoft settings, Windows requirements, and security boundaries? The technical page lists them in detail. Each part below explains what changes, how it works, and what owners, managers, and employees experience. The details live on the security and standard page.

People

Signing in without a password.

Every employee gets one company sign-in. It controls their email, files, apps, and computer access. They sign in with a face, fingerprint, or device PIN instead of a normal password. Microsoft provides this through Entra, Windows Hello, and passkeys.

What it is

A passkey stays on a device the employee already controls, and is used with a face, fingerprint, or device PIN. There is no password to invent, reuse, share, or leave under a keyboard.

Setup happens before the first day. A text message brings a guided walkthrough that the person completes from their phone, at home, in a few minutes. Losing access is a recovery step a manager can start, not a locked door.

Why we built it this way

Password rules did not make people safer. They made passwords unmemorable, and unmemorable passwords get written down, reused, and shared. The rule created the behavior it was meant to prevent.

Removing the password removes that whole category of problem rather than managing it. It is also the single change employees notice most, which is why it is taught inside the workflow at the moment it is used.

For the owner

The lockout that stops work on payroll morning has a recovery path, and the question a client or insurer asks about how people sign in has an answer.

For the manager

A passkey reset is something you start yourself, from the portal, instead of a request that goes into a queue.

For the employee

Your face or your fingerprint. Nothing to invent, remember, or write down.

What this changes

A consistent, recoverable sign-in experience without a password to invent, remember, or write down.

Computers

Every company computer set up the same way.

Every supported company computer is connected to Baseline. That lets us apply the same Windows setup, security settings, and software rules from one place. This is called device enrollment and central management. Supported computers must run Windows 11 Pro, version 24H2 or later. Baseline checks compatibility before migration so replacements can be planned.

What it is

A computer is reset, signed in to with the company sign-in, and set up automatically. Setting one up, replacing one, and supporting one are the same steps every time, because there is only one set of steps.

Employees can use the computer normally, but installing certain programs or changing protected settings requires approval. When an approved installation needs extra permission, a manager creates a temporary installation password for that computer. It expires after use. Every supported computer also receives the same security setup automatically. Microsoft Defender for Business watches for malware and suspicious behavior and includes endpoint detection and response, or EDR. Web filtering can block selected categories of risky sites. BitLocker encrypts the drive. Windows Firewall settings are managed. Desktop, Documents, and Pictures are saved to OneDrive. The technical names for the software rules are standard user accounts and temporary administrator access.

Why we built it this way

Consumer computers bought one at a time, each set up a little differently, are the reason no two problems look alike. A common standard is what makes a problem diagnosable by someone who has never seen that particular machine.

Installing software becomes a deliberate act with a defined path. That friction is the point. It is the difference between a considered decision and one afternoon click that undoes a month.

For the owner

A dead laptop stops being a crisis, and the hardware standard is a known, dated investment rather than a surprise.

For the manager

You can see every company computer and who last signed in to it, and you hold the deliberate path for installations.

For the employee

Any compatible computer becomes yours by signing in. Your work was never only on the broken machine.

What this changes

A repeatable setup and support process, with software installation handled through an approved path instead of permanent administrator access.

Work

One new Microsoft setup, built before anything moves.

Company email, calendars, files, meetings, and chat work together in Microsoft 365. Shared files stay where the team can find them instead of living only on one employee’s computer. Baseline builds a separate Microsoft setup first, while the old setup keeps running. Once the new one is ready, people and information move in planned stages.

What it is

Email, calendars, files, chat, and collaboration run on the Microsoft 365 tools the business is already paying for. Files sit where a team can find them rather than on individual computers, so somebody leaving does not take company files and knowledge with them.

Microsoft Defender for Office 365 checks email links and attachments for phishing and malware. It also helps protect supported links and files shared through Teams, OneDrive, and SharePoint. Redundant subscriptions that duplicate something already included come off the bill on a schedule you agree to.

Why we built it this way

Converting an old setup in place keeps every one-off exception that made it unpredictable. Building new is slower to start and far cheaper to run, and it is the only way one documented setup can mean the same thing for every customer.

One documented setup that Baseline keeps current over time is also what lets a question about how your Microsoft setup works be answered in a day instead of investigated for a week.

For the owner

Three overlapping bills become one price per employee, and the setup can actually be described when somebody asks.

For the manager

Shared work has a place, and a group gets made when you need one.

For the employee

Your files are where they should be on day one, and they are not stranded on one machine.

What this changes

One managed Microsoft setup, with company data remaining the customer’s and master access transferring cleanly when service ends.

Support

One path for help, inside the tools your team already uses.

Your people ask in a private chat in the Baseline app inside Microsoft Teams. If Teams is unavailable, they text the Baseline number and follow the same path.

The published targets

  • Business hours are Monday through Friday, 8:00 a.m. to 5:00 p.m. Mountain Time.
  • Initial response within 30 minutes during business hours.
  • Most ordinary covered requests target resolution in 2 to 4 business hours.
  • A technician starts finding or fixing the cause within 24 business hours.

How the service is delivered

Support is delivered remotely during published business hours. Requests sent outside those hours are waiting for the team at the next business opening.

The Support Scope page lists the exact coverage, billable work, response targets, and service boundaries.

The Manager Portal

The work that used to require a support request.

A manager should not have to learn Microsoft administration to add an employee. Every screen below shows fictional company data.

  • Hire a person. The portal can start account creation in less than 30 seconds.
  • Remove a person. The portal can start access shutdown in less than 30 seconds.
  • Follow employee onboarding through to completion.
  • Follow employee offboarding through to completion.
  • Reset a passkey when someone loses access.
  • See every company computer and the person using it.
  • Create and manage shared mailboxes.
  • Issue a temporary local administrator password when an approved installation needs one.
  • Open a support request and track where it stands.

When a manager adds or removes an employee, Baseline starts the change immediately. Microsoft may take a few minutes to finish applying it.

The Baseline Manager Portal open inside Microsoft Teams, pinned in the left app rail. The Employees screen for a fictional 15-person company shows a summary row of 15 total active employees, 13 desktop employees, and 2 mobile employees. Below it a table lists each employee with their work email, status, role, desktop or mobile type, and whether their passkey is enabled. A notice above the summary says when employees were last synced from Microsoft.
The portal opens inside Microsoft Teams, where the team already works. The portal shows who works here, how each person works, and whether their passkey is ready.
The Baseline Manager Portal onboarding form, filled in for a fictional new employee named Elena Marsh. The manager enters a first and last name, chooses whether the employee uses a computer or works only from a phone, sets whether they are a manager, and provides a mobile number that Baseline texts the setup instructions to. A Submit onboarding button completes the request.
Hiring a person. The manager enters a name, how the person works, and a mobile number. Baseline does the Microsoft work.
The Baseline Manager Portal Computers screen listing six fictional company computers. Each row shows the computer name, its serial number, the last person who signed in to it, and a Password button that issues a temporary local administrator password.
Every company computer, who last used it, and a temporary administrator password when an approved install needs one.

What this changes

Every action listed here works in the product today. When a manager adds or removes an employee, Baseline starts the change immediately. Microsoft may take a few minutes to finish applying it.

Going deeper

The technical standard, in detail.

The technical page explains employee sign-in, computer settings, Microsoft 365, access removal, and the limits of each control.

The next step

Find out whether the standard fits.

The reasoning holds up or it does not. The way to find out is a conversation about the setup you actually have.

In 30 minutes, we will map how your company works today, show what Baseline would change, and outline the clearest path forward.

See if Baseline fits