Skip to content
Lambert Consulting

Artificial Intelligence: A Cross-Functional Offering

Results first. Infrastructure second.

An assistant for your documents, end-of-line verification, a platform for multiple services. Where artificial intelligence is applied is determined by your data, not by a catalog.

See all solutions
4Comparing Architectures, Criterion by Criterion
2 fieldsSoftware and hardware under one roof
All Use CasesUse cases first, technology last

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable

Our Branches

Vaud, headquarters9 Avenue des Baumettes, 1020 Renens+41 21 806 37 15
Valais134 Oscar-Bider Street, 1950 Sion+41 27 552 00 22
FribourgChemin de Montmoirin 18a, 1618 Châtel-Saint-Denis+41 26 322 59 05
Monday through Friday8:00 a.m. – 6:00 p.m.
Contact UsFirst 30-minute consultation, with no obligation

Infrastructure / Security and Identity / Data Loss Prevention

Preventing data loss doesn't start with a ban.

It starts with knowing what sensitive information you have and where it is located.

Microsoft Purview Data Loss Prevention It identifies sensitive information and prevents it from being shared: a credit card number in an email, a payroll file uploaded to a shared folder accessible to everyone, a contract copied to a USB drive, or a customer database extract pasted into an AI assistant open in a tab. We carry out this work in the order that keeps it under control: classification, then observation without blocking, then rules.

The Same Security Policy, from Email to USB Drives Email, SharePoint, OneDrive, conversations Teams, computers Windows and Macs, and on-premises file servers.
Simulation mode before any lockup It reads, counts, and reports—and doesn’t interfere with anyone’s work until you decide otherwise.
Direct access to Microsoft support As a partner, we can open a support case with Microsoft on your behalf and learn about changes before they’re announced.

The Paths Taken by Sensitive Information

Almost none of these logouts are malicious. They are normal work-related actions performed by people in a hurry, using tools that allow them to do so. That is precisely why a memo won’t stop them.

01

An attachment is sent to the wrong recipient

The automatic recipient suggestion feature suggests a person with the same name or a client's address instead of a colleague's. The message was sent before I had a chance to proofread it.

An email rule checks the attachment before sending, notifies the sender, and blocks the message if you request it.

02

A document can be shared with the entire company via a link

The “Entire Organization” link is the fastest default option. A personnel file, a fee schedule, or an application form becomes visible to 500 people without anyone intending it to be.

A rule regarding SharePoint and OneDrive detects sensitive content and restricts access to external users or everyone.

03

When an employee leaves the company, they take their files with them

Copies to a USB drive, an external hard drive, or a personal email address multiply in the days leading up to a departure, and no one checks them at that time.

A policy on the computers monitors copying to a USB drive, network sharing, printing, and the clipboard.

04

A file excerpt is pasted into an AI assistant

An employee wants a summary, a rewritten version, or a translation. He opens a new tab, pastes two pages of a contract, and the department that receives this text is not covered by any of your company’s contracts.

This is the most recent path, and the one on which Microsoft is making the most progress right now.

05

A file server stores things that no one looks at anymore

Historical shared folders contain accounting export files, copies of identification documents, and database backups—all stored in folders whose owners left the company long ago.

The Purview scanner reads these shares and the SharePoint installed on your premises, and applies the same rule as it does online.

06

A third-party app is receiving more than expected

A signature tool, a billing connector, a meeting note-taking assistant: each user is granted access once, and can then view everything their permissions allow.

Purview treats non-Microsoft applications as a separate policy location—first read, then block.

Depending on the location, a protection rule does not take effect at the same time

Microsoft distinguishes three stages in the life of a file, and this distinction determines what a rule can do. It also explains the one thing no tool can do: retrieve a message that has already been sent.

At rest

The file is sitting somewhere, and no one touches it

SharePoint, OneDrive, file servers, and SharePoint on-premises, workspaces Microsoft Fabric, and connected non-Microsoft applications.

The content is analyzed where it is stored. Even a belated discovery is still useful: the shared folder closes, and the file is moved to a quarantine folder.

Can be made up later.

On the Move

The file or text is being sent

Email, chats, and channels Teams; forwarding to an unmanaged app from the browser or from the network.

This is the only time when the decision must be made before the action takes place. A rule that wasn't in effect at that exact moment won't get a second chance.

Only one chance to act.

In use

Someone has the file open in front of them

Computers Windows and registered Macs, Word, Excel, and PowerPoint, Microsoft 365 Copilot.

Copying to a USB drive, printing, the clipboard, Bluetooth, and remote desktop sessions are each a separate action that can be audited, flagged, or blocked individually.

The thinnest—and the one that takes the longest to adjust.

All three are governed by a single rule, and that’s the beauty of the system: the same definition of “payroll file” is used for email, sharing, SharePoint and USB drives, without having to be written three times. The actions, however, differ from one location to another—not all of them are available everywhere, and we’ll let you know which ones are missing where you might need them.

How We Do It, in Five Steps

Order is non-negotiable, and that’s the whole point. A company that writes its blocking rules first ends up disabling them within a month, because they stop legitimate work before they stop anything else.

01

Inventory of Sensitive Information

Which categories warrant a rule: social security numbers, payment card data, personnel files, health data, contracts, intellectual property, and customer lists. Microsoft provides more than 300 ready-to-use types of sensitive information, including Swiss social security numbers and Swiss mailing addresses; you can also create your own definitions.

A good list is a short one. A company that lists twenty categories provides less protection than one that lists four and sticks to them.

What You'll Receive A list of the selected categories, along with the reason for each one An overview of what Purview has already found, before any rules are applied Two or three custom definitions to write
02

Confidentiality labels: When They're Useful

A tag follows the document—even when it leaves your environment—and enables it to be encrypted. This is the right solution for a small number of documents that are shared—such as proposals, merger filings, and construction plans.

This is not a mandatory requirement. We protect thousands of files based solely on their content, without requiring the user to make any decisions at all. We only apply labels when someone is actually able to choose the right one.

What You Receive A brief list of labels—or a reasoned recommendation not to use them Configuration of automatic labeling when it replaces human decision-making Text reviewed by your employees, written prior to implementation
03

Simulation mode: everything is measured, nothing is restricted

A rule in simulation mode reads everything, counts everything, reports everything, and does not apply any of its actions. This is where we discover what no workshop can predict: the department that sends a file of AVS numbers to the pension fund every week—and has good reasons for doing so.

This is the step that projects tend to skip—and it’s the one that saves them. We hold off for several weeks, until at least one billing cycle, one month-end closing, and one payroll have been completed.

What You Receive A breakdown of what the rule would have blocked, by service A list of legitimate workflows to explicitly allow Adjusted thresholds: the number of occurrences at which the rule is triggered
04

Switching to blocking mode without activating everything on the same day

First, the warning is activated, with the option to override it by providing a reason: the justification is recorded, and it’s better than a block, because it teaches you something. A block with no exception follows, applied only to the rules that the simulation has shown do not bother anyone.

Each rule has its own effective date. A project that switches over all at once that same morning will no longer know, the next day, which of the eight rules stopped billing.

What You'll Receive An activation schedule, one rule at a time Warning messages in your company’s languages The exemption procedure and the name of the person handling it
05

Day-to-Day Operations

A rule applies: alerts are addressed, false positives are corrected, new sharing services emerge, and definitions are refined. Without this work, a dashboard fills up with alerts that no one reads anymore—which is the same as not having installed anything at all.

This work can be handled in-house or outsourced. We’re capable of doing both, and that’s what allows us to advise you based on your specific needs rather than on what we know how to sell.

What You Receive Alert triage, with a designated manager on each side Quarterly review of definitions and thresholds What needs to be exported before the alerts disappear on their own

The opposite is also true. If you only have one type of information to protect and it’s only shared via email, an email policy is all you need—it can be set up in a few days, and it’s already included in the Microsoft 365 subscription you’re paying for. We’d rather tell you that than try to sell you the five-step process.

Places Where a Protective Rule Applies

A single protection rule applies to one or more of these locations. The first two cover most cases and are included in standard Microsoft 365 subscriptions; the others require a more comprehensive subscription, and we make that clear before offering them.

Messaging

Email, both incoming and outgoing

The message body, subject line, headers, and attachments. Beyond blocking: encrypt, quarantine, add your supervisor as a recipient, or ask for their approval before sending.

Online Documents

SharePoint and OneDrive

Files that have already been uploaded are scanned, not just new ones. A rule can restrict access to external users, a specific domain, or everyone except authorized users.

Computers

Computers connected to the service

Under Windows such as macOS. USB drives, network sharing, printing, clipboard, Bluetooth, remote desktop sessions, prohibited applications, and prohibited browsers. Each action can be audited, flagged, or blocked individually.

Conversations

Microsoft Teams : Conversations and Channels

The message containing sensitive information is not displayed to the recipient. Note: In this case, a rule is based on the types of sensitive information, not on confidentiality labels.

Your servers

File servers and SharePoint installed on your premises

Microsoft Purview 's scanner (Information Protection ) scans shares and libraries hosted on your own servers and applies the same definitions as it does online. It is deployed separately.

Analysis

The workspaces where your dashboards live

Microsoft Fabric and Power BI are standard locations. A dashboard often brings together information that ten separate files did not provide: it is the most commonly overlooked part of an inventory, and one of the most sensitive.

Third-Party Apps

Connected non-Microsoft services

By Microsoft Defender for Cloud Apps, a third-party service becomes a rule-based setting: read-only first, then blocking, with a distinction between managed and unmanaged computers.

Preview

Microsoft 365 Copilot

A separate section: We restrict what the assistant is allowed to read when generating its response, based on confidentiality labels and types of sensitive information.

Preview

Web traffic to unmanaged services

Two options: Microsoft Edge for Business on a managed computer, or a network-level scan that covers more than 34,000 services in the Defender for Cloud Apps catalog.

How Artificial Intelligence Is Changing Things

The issue is no longer the USB drive. It’s the tab open next to the document, and the fact that a company employee—who is fully within the scope of their employment—can read everything that their user access rights allow them to access. The two issues are distinct, and they cannot be addressed in the same place.

What the assistant looks up

Limit the content that Copilot is allowed to use

A rule can exclude documents with a specific label or containing a specific type of sensitive information from the assistant's responses. This setting answers the question, "So, is it going to read everything?"

Preview location. Restricting the processing of files and emails requires a Microsoft 365 E5 subscription or equivalent.

What is included in it

See what your employees are typing in the assistant

Text entered into Copilot and Copilot Chat can be reviewed just like an email. This is the only way to know for sure whether a portion of a contract has been copied into it, rather than just assuming it has.

Available to all Copilot and Copilot Chat users, with no additional subscription required.

Unmanaged Services

Pasting into an assistant that isn't yours

ChatGPT, Gemini, DeepSeek, and Copilot are specifically targeted—either by Microsoft Edge ( for Business ) on a managed computer or by monitoring network traffic. You can audit, issue warnings, or block them.

This is a preview version, and billing is based on usage. Therefore, this is not a setting you need to enable—it’s a budget line item you need to decide on.

Screenshots

Screenshots, and What They Should Not Contain

A rule condition detects whether a sensitive document or message Teams is present in a snapshot and excludes it. This is useful when the feature is enabled on newer computers.

Pre-release version, available Windows only.

The construction site next door—and he walks right past it

Data loss prevention prevents data from leaving the company. Access rights determine what a person can access.

A contract-based business assistant, set up with permissions that have never been reviewed, provides access to more content than a consumer-grade tool that no one has ever updated. No data loss prevention policy can fix this, because nothing actually leaves the system: the information is simply viewed by someone who shouldn’t have had access to it. That’s a different task, and it takes priority.

Reinstating Access Rights Before Copilot What’s Covered by Your Contract—and What Isn’t Regulating AI tools that no one has validated Agent governance

A rule that blocks too much is disabled within a month—and the company is then less protected than before, because it believes it is protected.

We don't start with computers

This is the most visible and most expensive part: machine registration, fine-tuning, and processing exemptions. Email and document sharing cover a wider range of situations, cost less, and are often already included in what you pay.

We refuse to activate a block without a simulation

Not out of caution: because no one knows the list of legitimate ways to send a sensitive file within their own company. It has to be learned; it can’t be guessed.

An alert dashboard that no one reads doesn't protect anything

This is the most common outcome of a technically successful implementation. The question that needs to be decided before getting started is who will handle the alerts on Tuesday morning.

We'll let you know when your current subscription is sufficient

Much of this work is already included in standard Microsoft 365 subscriptions. Understanding how to make the most of both tiers is what allows us to advise you on your requirements rather than on upgrading to a higher tier.

What You Need to Know Before You Begin

Six points that determine the budget and schedule. None of them is an obstacle: these are the areas where a project goes off the rails when they haven’t been addressed at the first meeting.

What's Already Included in Your Subscription

Email rules, SharePoint and OneDrive are included in Microsoft 365 E3, Business Premium, and even in Exchange Online Plan 2 or SharePoint Plan 2 on its own. That’s the first benefit, and it doesn’t cost anything extra.

Features that require Microsoft 365 E5 or an add-on: computers, conversations Teams, web traffic, restricting what Copilot reads, enriched alerts in Outlook, and adaptive protection that tightens rules for a person whose behavior changes. Transparency: We assess what you already have before making any recommendations, and sometimes the answer is “nothing to buy.”

What Content Analysis Misses

On a computer, anything that is never saved to the hard drive is not scanned: a document that is opened and then sent directly to a USB drive is not subject to content scanning. The list of scanned file formats is long but finite—industrial design files or proprietary databases are not included. And a label added by another company is not recognized.

The solution: each of these three scenarios has its own solution, and we include them in the scope of work. Formats that haven’t been analyzed are handled by a rule that prohibits taking any action without first reading the content—a less nuanced approach, but an effective one, and often exactly what’s needed for a project plan.

False reports, and the work they entail

A 16-digit number isn't always a payment card. An order reference, a machine ID, or a serial number can trigger rules that are too broadly defined, and every unnecessary trigger wears down your teams' patience a little more.

The threshold: that is exactly what simulation mode measures, and what the thresholds control. A rule that is triggered only after ten occurrences in the same file behaves very differently from a rule that is triggered after the first occurrence.

An alert has a limited duration

An alert remains visible for thirty days in the Purview dashboard and for six months on the Microsoft Defender portal. The activity explorer shows the last thirty days. For a case that goes to trial two years later, that’s not enough.

Transparency: Events are also logged in the audit log, and data that needs to be retained for a longer period is exported. This is decided at the outset—data that hasn’t been exported cannot be retrieved.

Where Is Purview's Data Stored, and the Swiss Question

Switzerland is one of the countries covered by the Microsoft 365 Advanced Data Residency option, which specifically addresses data loss prevention. There are two requirements to keep in mind before discussing this with management: the commitment requires that 100% of the tenant’s paid licenses be covered by the option, and the migration migration of existing data can take up to twelve months.

The first step: We start by identifying where your data is currently located in the administration center. Many companies discover at this point that they’re already where they wanted to be, and that the question doesn’t even arise.

What's in the preview version, and what that means

Copilot as a rule location, monitoring web traffic to unmanaged services, and the condition on Windows are announced by Microsoft as preview features. Preview features are subject to change, and web traffic monitoring is billed on a pay-as-you-go basis.

The rollout: A pre-release version works very well when tested on a small group, and that’s how we proceed—never company-wide, and never as the basis for a written commitment to a client or auditor.

Questions We Are Asked

Seven questions that have come up often enough to warrant a written response. The first two concern products that Microsoft has discontinued or renamed: if you came here looking for information about them, you'll find the answer here.

"We had Windows Information Protection on our computers. What happened to it?”

Microsoft announced that it had reached end-of-life in July 2022, and it is being removed from Windows 11 starting with version 24H2. Microsoft explicitly refers to Microsoft Purview Information Protection and Microsoft Purview Data Loss Prevention. If your computers still have it installed, it’s because they’re running a version of Windows that hasn’t removed it yet: the replacement is being prepared without urgency, but before the next system upgrade.

"And Microsoft Information Protection —is that something else?"

That’s the old name. The product is now called Microsoft Purview Information Protection : same privacy labels, same encryption, same file server scanner. The acronym MIP is still used in older documentation and in certain interfaces.

"Does this work on a Mac?"

Yes, across the last three major versions of macOS, with some real differences: protecting files on an offline computer and blocking applications not on the allowed list are features available only on Windows, and remote desktop sessions are not monitored. We compile the list of discrepancies beforehand, not afterward.

"Our file servers aren't online. Are they covered?"

Yes, using the scanner from Microsoft Purview Information Protection , which is installed on your premises, scans your file shares and the SharePoint hosted on your servers, and applies the same definitions. It’s deployed separately, and that’s a project in its own right: you need to provide it with a service account, read permissions, and processing time.

"Should our computers be managed by Intune ?"

No. Registration is performed via a local script, through Group Policy, or Configuration Manager, Intune or a script designed for virtual machines. And if your machines are already connected to Microsoft Defender for Endpoint, they’ll appear automatically—all you need to do is enable monitoring.

"Is anything off-limits from day one?"

No, and that's not desirable. A rule created in simulation mode does not execute any of its actions; it simply counts and reports. The decision to block is a separate one, made rule by rule, once you've reviewed the simulation's findings.

"How long does it take for the adjustment to take effect?"

Allow about an hour for an activated or modified rule to take effect throughout the service; the affected files will then be reevaluated the next time they are accessed. A change to the group of authorized users takes twenty-four hours. This is not instantaneous: a test performed within five minutes does not prove anything.

Let's talk about your sensitive information

Tell us about the three pieces of information you don't want to lose

What would cause the most damage if it were to leak from your company, the tools through which it currently circulates, and the name of the person who would receive the alerts. With these three elements, the first meeting is already productive.

What we offer is the opportunity to meet with the engineers who will do the work. The scope of work includes inventory, simulation, and threshold adjustment. The preliminary discussion, however, is free and is often enough to determine whether the project fits within your current subscription.

Three branches in French-speaking Switzerland

Renens, Sion, Châtel-Saint-Denis

Microsoft Solutions Partner, operating in French-speaking Switzerland since 1995. A single point of contact from inventory to alert triage.

Renens VD +41 21 806 37 15
Sion VS +41 27 552 00 22
Châtel-Saint-Denis FR +41 26 322 59 05