Managed IT infrastructure
Servers, Active Directory, Microsoft 365 security, licensing, live monitoring, network, backups and CIS Level 1 — in one place. Hand it to us, keep it yourself, or share the work. The platform does not care which; you can change your mind later.
How it works
Most tools decide this for you: either an agency runs everything behind a curtain, or you get a console and good luck. Firmenda is built for all three, on the same data, with the same screens.
Full service. We patch, monitor, harden and report; you read the summary and approve the things that need a decision.
Fits when IT is not your day job.
You do the work you know and enjoy. We pick up the rest, and everything either of us touches is visible to both — no handover meetings.
Fits when you have one IT person and no back-up.
Same platform, your hands on the controls. Simple enough to run without a course, with us on standby for the weeks that get busy.
Fits when you have a capable internal team.
Everything in one place
Every one of these usually comes with its own portal, its own login and its own version of the truth. Here they sit next to each other and refer to the same servers, the same people and the same licences.
01
Servers, virtual machines, switches, access points and the gateway, grouped by building and room. The page updates itself, flags every change as it happens, and a single click checks everything again right now instead of at the next interval.
02
Updates staged in advance and installed in the maintenance window you set, per group of servers. Hyper-V hosts shut their machines down in order, patch, restart and bring everything back up. Disk space, hardware and uptime history alongside.
03
Secure Score with a 30-day trend, CIS Microsoft 365 Level 1 and 2, and every open improvement with its impact and a plain-language guide. The Firmenda standard baseline is pushed to your tenant with one click, exceptions per organisation respected.
04
Accounts, groups, group policy, domain controllers, replication and the stale objects nobody dares to delete. Reported daily, with dates.
05
Windows Server hardening measured every day and applied through group policy in phases, with a management whitelist built in so a stricter firewall never locks anyone out. The gap is visible the day it appears, not the week before the audit.
06
What you pay for against what is actually used, with a monthly overview in your mailbox. Usually the fastest money you will save all year.
07
Every device from Active Directory, Intune and Defender in one list: who uses it, how old it is, whether it is compliant and whether protection is actually running.
08
Switches, access points, ports, clients and topology from your network controller. Firewall reports, an exposure scan of what is reachable from outside, and IP address and DNS management with a CIS check on your DNS.
09
Every backup job checked daily: succeeded, warned or failed, with the last good restore point. A failed job can be restarted from the portal.
10
Hyper-V hosts, virtual machines and replication in one view. A new Windows or Ubuntu server is rolled out from the portal in under ten minutes.
11
SharePoint and OneDrive growth per site and per person, so you see the storage bill coming before Microsoft sends it.
12
Connect your Microsoft 365 tenant in a browser click, grant us elevated access for a fixed number of hours, choose your reports and see live what every run is doing.
Monthly reports your director can read and the Firmenda Collector for sites that prefer outbound-only connections are live with the first customers. Intune baselines for workstations are next.
Recently added
The platform is the one we run our own customers on, so it moves every week. These are the additions customers will notice first.
September 2026
A PRTG-style overview of servers, virtual machines and network devices. Red the second something drops, without refreshing, and a "Check now" button when you do not want to wait.
September 2026
One baseline of Secure Score and CIS Level 1 settings, previewed first and then pushed to the tenant in one go. Exceptions per organisation stay respected.
September 2026
Every open improvement with its points, impact and a guide in plain language, plus a 30-day trend so you can see the score move after a change.
September 2026
The CIS firewall rules now carry a management whitelist and a fallback for remote desktop and ping, so a hardened server always stays reachable for support.
August 2026
An optional small collector at your site that gathers locally and only pushes outbound. No inbound rules, signed modules, and the same portal.
September 2026
Updates are downloaded in advance and installed in the window you choose, per server group, with Hyper-V hosts orchestrating their own virtual machines.
The name
Firmenda comes from firmare — to make firm, to strengthen. The image behind it is a keystone: the wedge-shaped stone at the top of an arch that holds the whole thing in place. Take it out and the arch collapses.
That is what one management platform does with a dozen separate tools. Each of them is useful on its own. Stacked next to each other, with nothing holding them in position, they are a pile of stones.
How the name was made
We wrote the requirements before we wrote the name. The .com had to be free for the price of a coffee. It had to survive being said out loud in English without anyone asking how to spell it. And it had to stand well clear of the compliance-tooling crowd.
Every English word we liked was already taken — Plinth, Benchpoint, Trueground, Statelayer — and so was every Latin word you can look up in a dictionary. So we stopped hunting for a word and built one, out of two stems that describe the work itself.
firmare
to make firm · to strengthen · to make certain
Establish what is actually out there, measured against a baseline instead of against memory.
emendare
to remove the fault · to correct
Clear the deviations one by one, until there is nothing left on the list that shouldn't be there.
Then Latin handed us something we had not planned. The ending -nda is the gerundive: that which must be done. Emendanda — the things that must be corrected.
So Firmenda reads as the things that must be made firm.
Which is precisely what you get handed at the end of a run. Not a report that says how you did. A list of what is still to be done.
Why Firmenda
Firmenda is not a product someone designed in a workshop. It is the platform we use to manage our own customers, opened up.
No agent to roll out, patch and eventually forget. We reach your systems over the channels that are already there. Prefer outbound-only? One small collector at your site does the gathering and nothing of ours touches the servers.
Monitoring pages update themselves, every run shows its progress while it runs, and a check you want now happens now.
A server is one server, whether you are looking at its patches, its disks, its licences, its backup or its place in the network.
Every check carries a timestamp and a source. When an auditor asks how you know, there is an answer instead of a screenshot.
Every group policy change is backed up before it is made and rolled out in phases, with a management whitelist that keeps support access open whatever the baseline says.
Move from managed to co-managed and back without a migration. It is the same platform; only who clicks changes.
Reports your director can read without a translator, and detail underneath for the person who has to fix it.
Hosted in the Netherlands. You can export what we hold about you, and take it with you if you leave.
A demo takes half an hour and we use your situation, not a sandbox. You will know within a week what it would find.