When the city of Rosenheim decided to overhaul its fragmented IT systems, it wasn’t just another cloud migration. With 95 percent Microsoft 365 adoption across city departments, two subsidiaries, and 15 schools, the Bavarian municipality has drawn a blueprint for how public-sector organizations can marry productivity gains with strict governance and sovereignty requirements.
From Patchwork to Platform
Rosenheim’s move to Microsoft 365, detailed in a Microsoft customer story published July 28, 2026, was a deliberate consolidation of a sprawl of disconnected tools. The city’s IT landscape had accumulated parallel systems, manual account management, and a reliance on on-premises servers that ate up administrative time and introduced security risks. Its digital transformation introduced Microsoft Teams, SharePoint Online, and Exchange Online as a common digital workplace—extending not just to the main city administration but also to a local transport company, an event venue operator, and 15 schools.
According to Microsoft’s account, the migration achieved a 95 percent adoption rate across business units and departments. That figure signals more than technical cutover success: it suggests employees across highly varied organizations found the new tools usable enough to incorporate into daily work. The deployment was designed and implemented with technology partner conet Deutschland, which worked around network constraints by using a hybrid Exchange setup—an important reminder that not every cloud journey is a straight line from on-prem to cloud-native.
Why Governance—Not Just Apps—Is the Real Story
The most significant takeaway for Windows admins and IT leaders is that Rosenheim treated the project as a governance transformation first. By adopting Microsoft Entra ID (formerly Azure Active Directory) as a unified identity and access control layer, the city replaced a mess of separate local accounts with a single source of truth. Georg Pfeiffer, Deputy Head of Systems Operations, described the old state as one where “the same users were managed multiple times.” With Entra ID, user onboarding, permissions, and offboarding could be automated, while access policies could be applied consistently across the city’s disparate entities.
This identity-centric approach is the engine that makes a Microsoft 365 deployment secure and manageable at scale. As the BSI—Germany’s Federal Office for Information Security—makes clear in its minimum standard for cloud services, outsourcing infrastructure does not transfer accountability. Organizations remain responsible for their own protective measures, including access controls. Rosenheim’s emphasis on tightening external access, classifying citizen data, and building governance into the design phase maps directly to that principle.
Lessons for Every Organization—Public or Private
Rosenheim’s experience offers actionable insights for any Windows shop contemplating or already running Microsoft 365:
- Identity is your control plane. Consolidating on Entra ID reduces admin overhead only if you invest in the governance features: lifecycle workflows, access reviews, conditional access policies, and privileged identity management. The alternative is a central point of failure.
- Adoption metrics are a starting point, not the destination. A 95 percent login rate is encouraging, but the real test is whether duplicate content dwindles, sharing is appropriately restricted, and user onboarding that once took days now takes minutes. Establish outcome metrics early.
- Hybrid is a transition strategy, not an end state. Rosenheim’s hybrid Exchange setup solved an immediate network problem, but any hybrid architecture adds complexity. Define clear retirement criteria for on-prem dependencies before they become permanent.
- Sovereignty demands configuration, not just location. Microsoft’s EU Data Boundary and Sovereign Cloud resources provide capabilities, but it’s up to the tenant owner to map data types, configure policies, and verify audits. Marketing claims don’t satisfy compliance officers.
- AI readiness is governance readiness. Rosenheim has begun testing Microsoft Copilot with a small license pool, explicitly holding off on a broader rollout until governance and classification are mature. Deputy Head of IT Karola Bromirski stressed that AI must rest on a solid cloud management foundation. For organizations, that means: audit SharePoint permissions, label sensitive content, and ensure least privilege before an AI search tool can inadvertently expose what it shouldn’t.
The German Public-Sector Context
Rosenheim’s decision didn’t happen in a vacuum. German municipalities operate under strict data protection and sovereignty expectations. The BSI’s minimum standard for external cloud services states plainly that the use of a cloud provider does not absolve the organization of responsibility for IT security. Even non-confidential data requires integrity and availability safeguards. By openly addressing these concerns, the city set a benchmark for other public administrations.
Microsoft’s own sovereign cloud investments—including the EU Data Boundary and customer-managed encryption keys—helped make the case. But the Rosenheim story shows that the true work lies in tenant-level design. IT teams must carefully delineate which services fall under which contracts, how external guest access is controlled, and how incident response will function when data spans multiple legal frameworks.
What to Do Now
Whether you’re an IT pro in a government office or a private company, you can borrow from Rosenheim’s playbook:
- Perform an identity audit. Map every user account and group across on-premises Active Directory, Entra ID, and any other directories. Identify duplicates, stale accounts, and over-privileged roles.
- Turn on Entra ID governance features if licensed. Start with access reviews for sensitive groups and guest users. Implement lifecycle workflows to automate joiners/movers/leavers.
- Define a data classification scheme. Use Microsoft 365 sensitivity labels and data loss prevention rules. Begin with a pilot group, then expand.
- Set Conditional Access policies. Require MFA, restrict access from unmanaged devices, and use location-based signals to protect high-impact apps.
- If you’re hybrid, set a deadline. Decide which workloads can move fully to the cloud and which must stay on-prem, with a timeline to minimize future technical debt.
- Before Copilot, clean house. Review existing SharePoint permissions, Teams membership sprawl, and default sharing links. An AI tool will faithfully expose any weaknesses.
Outlook: A Model, Not a Template
Rosenheim’s next steps—scaling Copilot responsibly, retiring legacy systems, and deepening governance—will be watched by peers across the EU. Its success so far demonstrates that a cloud migration can be both a digital workplace upgrade and a governance springboard. But the durability of that success will depend on continuous identity hygiene, evidence-based compliance, and the willingness to treat cloud adoption as an evolving operating model, not a one-off project. For Windows admins everywhere, the city’s story is a reminder that the most important tool in a Microsoft 365 rollout isn’t Teams or SharePoint—it’s the disciplined management of who can access what.