FAQ.
Short answers to what prospects and clients most often ask about the practice: the scope of what Entropex builds, the Microsoft clouds it works in, the compliance frameworks it aligns to, its approach to enterprise AI, and what an engagement actually looks like.
Who we are and how the practice is organized.
What does Entropex do?
Entropex LLC is a Marine Corps veteran-owned Microsoft practice. It covers the full lifecycle of Microsoft Azure and Microsoft 365: cloud adoption, tenant configuration, security engineering, framework alignment, and enterprise AI implementation, for federal and commercial clients.
Is Entropex veteran-owned?
Yes. Entropex is owned by a United States Marine Corps veteran and is pursuing Service-Disabled Veteran-Owned Small Business (SDVOSB) certification. The practice prioritizes serving the defense industrial base and the broader veteran business community alongside its commercial clients.
Where is Entropex based, and where do you work?
Entropex is based in the Pacific Northwest, United States. Engagements are delivered remotely across the country, with on-site travel when the work requires it.
How is Entropex different from a typical cybersecurity consultancy?
The practice is engineering-led, not report-led. The deliverable is a system that works after the engagement ends, not a PDF that goes in a drawer. Entropex stays small on purpose, so the senior engineer is the one doing the work, and Marine Corps discipline shapes how every engagement gets planned, executed, and owned.
What Entropex builds on, and in which cloud.
Which Microsoft clouds does Entropex support?
Microsoft Commercial, Azure Government, and GCC High. The target cloud is confirmed at intake so that provider endpoints, region choices, and feature availability are correct from day one.
Does Entropex help stand up a brand-new Microsoft 365 or Azure tenant?
Yes. New-tenant work is a core offering: subscription vending, landing zones under the correct management group, Entra ID configured to modern baselines, Microsoft 365 tenant configuration covering identity, licensing, mail flow, information protection and endpoint management, and the diagnostic and logging plumbing a mature environment needs.
What Microsoft Azure services does Entropex work with most?
Microsoft Entra ID, Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Purview, Microsoft Intune, and the Azure platform itself (networking, Key Vault, storage, compute, Azure Policy, Azure OpenAI Service). Everything that can be delivered as code is delivered as Terraform or Bicep.
Does Entropex support GCC High and Azure Government deployments?
Yes. Cloud is identified at the start of every engagement, and IaC, scripts, and portal workflows are pointed at the correct endpoints for GCC High or Azure Government. Feature parity with Commercial is verified against Microsoft documentation rather than assumed.
Does Entropex use Terraform for Azure deployments?
Terraform is the default delivery medium for greenfield work, based on the Azure Landing Zones Terraform accelerator and Cloud Adoption Framework enterprise-scale patterns. When an environment already uses Bicep, Entropex extends the existing Bicep rather than forcing a rewrite.
Readiness, remediation, and the evidence to prove it.
What compliance frameworks does Entropex align environments to?
NIST Cybersecurity Framework 2.0, CMMC (currently Level 2), NIST SP 800-171, NIST SP 800-53, and the NIST AI Risk Management Framework for AI-heavy environments. Alignment is treated as a discipline, not a one-time exercise, with evidence pipelines that keep posture visible after the engagement ends.
Does Entropex do CMMC Level 2 readiness?
Yes. Entropex runs CMMC Level 2 readiness engagements against the current NIST SP 800-171 control set, with practical evidence pipelines wired to Microsoft-native sources. Readiness assessments identify gaps against the assessment guide; remediation engagements close them with configuration, policy, and documented control implementations.
How does Entropex approach NIST SP 800-171 compliance?
Two paths depending on where you are. A gap analysis reads the current tenant against every 800-171 control and produces the finding, the recommended remediation, and the evidence source that will satisfy an assessor. A remediation engagement executes those findings, produces a System Security Plan and Plan of Action and Milestones, and hands over the ongoing evidence process rather than a one-time snapshot.
Microsoft-native SOC, deployed to run.
Does Entropex offer managed detection and response on Microsoft Sentinel and Defender?
Entropex deploys, tunes, and hands off Microsoft-native SOC capability built on Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Defender for Cloud. Ongoing operations are available when a client wants us to run it, and every engagement is delivered so the internal team can extend the detections without our involvement.
Getting AI to production, without the vendor enthusiasm.
What does Entropex's enterprise AI implementation practice cover?
The signature engagement is Azure OpenAI Service deployment: identity-bound access, private network integration, data connections, cost guardrails, and operations playbooks, delivered as Terraform. Adjacent engagements cover ChatGPT Enterprise and Claude Enterprise integration, retrieval-augmented generation on Azure AI Search, and ongoing AI platform operations.
Can Entropex integrate ChatGPT Enterprise or Claude Enterprise with our tenant?
Yes. Both integrations are supported: identity federation, SCIM provisioning, data governance, DLP, and the tenant-side controls that keep those platforms usable in a regulated environment.
How engagements run, from intake to handover.
What does an engagement with Entropex look like?
Every engagement is scoped narrowly and resourced to be finished, not stretched. Everything that can be delivered as code is delivered as code: Terraform, Bicep, and pipelines. Documentation and knowledge transfer are part of the work, not artifacts produced at the end. If your team cannot extend the environment after we leave, the engagement failed.
How do I contact Entropex to discuss an engagement?
Email support@entropex.io with a short paragraph on what you are trying to accomplish. Brief context gets a faster, more useful response than a generic outreach.
Question not answered here?
Direct email works best. A couple of sentences on what you are trying to accomplish gets a faster, more useful response than a generic outreach.
Start a conversation