Stadt Rosenheim has completed a significant step in its digital modernization strategy, consolidating a fragmented municipal IT estate around Microsoft 365 and Microsoft Entra ID to improve collaboration, identity governance, operational control, and long-term cloud readiness across city departments, affiliated companies, and schools. The rollout is notable not simply because a German municipality selected Microsoft’s cloud productivity stack, but because it frames the decision around the harder public-sector concerns of security, sovereignty, administrative capacity, and sustainable governance rather than office-suite convenience alone. Microsoft’s customer account reports a 95% adoption rate across Rosenheim’s business units and departments.
For Windows administrators, IT leaders, and public-sector technology teams, Rosenheim’s experience is a useful case study in what a Microsoft 365 migration can accomplish when it is approached as a broader operating-model change. Consolidating Teams, SharePoint, Exchange Online, and identity services can remove day-to-day friction, but the lasting value comes from standardizing access, setting clear policy boundaries, and reducing the scattered technology decisions that accumulate over years of departmental autonomy.
The project also illustrates an essential reality of municipal cloud adoption: a modern workplace is never merely a desktop refresh. It is a redefinition of how people access systems, collaborate on documents, share sensitive information, and prove that controls are working.

Illustration of secure cloud collaboration connecting city services, offices, transport, and EU-compliant data centers.Background: A municipal IT landscape under pressure​

Rosenheim is an Upper Bavarian city serving residents and local businesses, with its official municipal data listing 67,238 residents in June 2026 and an official population figure of 65,808 as of December 31, 2025. The city’s data page also explains why the local register and the state statistical count can differ, a useful reminder that public administration has to manage both operational systems and formal reporting requirements.
Like many local-government organizations, Stadt Rosenheim had accumulated a complex technology environment. Its departments used parallel tools for similar work, while substantial on-premises infrastructure remained in place. That combination created duplication, administration overhead, and a slower path for introducing consistent new capabilities. Microsoft’s published case study describes a municipality facing limited resources, strict regulations, demographic pressures, and rising expectations from both employees and citizens.
This is the context in which Microsoft 365 becomes more than a familiar suite of productivity applications. In a municipal environment, disparate collaboration services can turn simple tasks into difficult processes:
  • Staff may have to move documents between incompatible repositories.
  • Permissions can be copied manually between local systems.
  • A departing employee may leave behind unreviewed accounts or access rights.
  • Teams working with external providers can lack a consistent method for controlled collaboration.
  • IT administrators may spend too much time maintaining infrastructure rather than improving services.
Rosenheim’s objective, therefore, was not just to introduce cloud applications. It was to establish a common digital foundation that could support daily work today while offering a controlled platform for later modernization.

A unified Microsoft 365 foundation​

The city selected Microsoft 365 as its strategic platform after evaluating alternatives, according to Chief Information Officer Bernward Hohenbild. The stated rationale was a combination of long-term cost profile, control, cloud capabilities, and the need to satisfy German public-sector requirements around security, compliance, and sovereignty. Microsoft’s account of the decision makes clear that the choice was positioned as an operational and governance decision, not simply a preference for familiar productivity software.

Replacing disconnected systems with a shared workplace​

At the employee level, the implementation brought Microsoft Teams, SharePoint, and Exchange Online into a consistent digital workplace. This means communication, document collaboration, calendars, mail, file storage, and access controls can be operated through a more integrated environment rather than a collection of disconnected departmental tools. The Rosenheim deployment specifically emphasizes that employees no longer need to navigate multiple systems for closely related work.
The reported collaboration improvement is a practical one: multiple users can work in the same document simultaneously. That capability is routine in cloud-native workplaces, but it is highly consequential for a public administration where approvals, cross-departmental drafting, and case documentation may otherwise depend on sequential editing, attachments, and repeated version exchanges.
The productivity argument should not be overstated. Real-time coauthoring does not automatically make a process efficient if the process itself remains poorly designed. However, it removes a common technical bottleneck and creates the conditions for teams to redesign work around shared content rather than individual file copies.

Scaling beyond city hall​

A particularly important part of the deployment is its scope. Rosenheim did not restrict Microsoft 365 to the central administration. The city extended the environment to two municipal subsidiaries—Veranstaltungs+Kongress GmbH Rosenheim and Verkehrsgesellschaft Rosenheim mbH & Co. KG—as well as 15 schools. Microsoft’s case study presents this as evidence that a common platform can span substantially different operating environments.
That cross-entity approach has obvious benefits. A common identity model, shared administration practices, and consistent collaboration tooling can reduce the burden of supporting multiple separate platforms. It can also make it easier to set minimum standards for account protection, information sharing, and onboarding.
Yet broad adoption also expands governance complexity. A city department, a public transport organization, a venue operator, and a school do not necessarily have the same data classifications, staff roles, retention needs, or external collaboration patterns. The value of a shared tenant or shared platform depends on whether common controls are paired with policies that recognize those differences.

The 95% adoption figure: meaningful, but incomplete​

Rosenheim reports a 95% Microsoft 365 adoption rate across business units and departments. Microsoft’s customer story treats the number as evidence that the rollout succeeded in everyday use as well as in technical implementation.
That is an encouraging signal, especially in a municipal setting where transformation projects can stall when staff see new tools as additional burdens. A high adoption rate suggests the organization reached a substantial share of intended users.
Still, readers should interpret the metric carefully. The published story does not disclose how “adoption” was measured: it could refer to provisioned accounts, active users, use of one or more services, or a broader internal assessment. It also does not distinguish basic use—such as Exchange Online mail access—from mature use of Teams channels, SharePoint document governance, or approved workflows. Adoption is necessary, but it is not the same as secure, well-governed, or effective adoption.
The next phase of Rosenheim’s success will therefore be determined by operational indicators that go beyond logins:
  • Reduction in duplicate content and unapproved file-sharing paths.
  • Time taken to onboard, change, and remove user access.
  • Completion rates for access reviews and policy training.
  • Use of approved Teams and SharePoint structures.
  • Measurable declines in manual IT administration.
  • Service continuity and incident-response performance.

Identity governance is the project’s central control plane​

The most strategically significant technical element is Rosenheim’s adoption of Microsoft Entra ID as a unified approach to identity and access management. Before the migration, different systems had separate local accounts, leading to duplicate administration, inconsistent permissions, and elevated risk. The city’s implementation account quotes Deputy Head of Systems Operations Georg Pfeiffer describing the prior state as a situation in which the same users were managed multiple times.

Why central identity changes the equation​

A collaboration platform can only be as coherent as its identity model. If every service has its own accounts, groups, and password practices, staff can be locked out of tools they need while former employees, contractors, or transferred personnel retain access they should no longer have.
By centralizing login, access management, and governance, Rosenheim gained a basis for applying policies consistently across departments and affiliated entities. Microsoft’s description of the Entra ID deployment says the shift improved transparency and reduced administrative effort, while making security and compliance policies more consistent.
This is precisely the use case identity governance is designed to support. Microsoft describes Entra ID Governance as a set of capabilities for ensuring that the right identities have appropriate access to resources, automating identity and access processes, increasing visibility, and supporting the monitoring and auditing of access to critical assets. Microsoft Learn’s overview of Entra ID Governance highlights lifecycle management, access governance, and privileged-access controls as core scenarios.
For municipal IT, the difference is material. A well-run identity service can link employment events and role changes to technical access changes. It can also make access approvals more accountable by involving department managers and data owners rather than leaving every decision solely with central IT.

Governance must extend past the migration​

Identity consolidation has considerable strengths, but it carries a corresponding responsibility: a central identity platform can centralize failure as well as control. If an administrator account is compromised, if privileged roles are assigned too broadly, or if guest access rules are too permissive, the impact may extend across the entire Microsoft 365 environment.
Rosenheim’s stated emphasis on tightly controlling external access is therefore appropriate. Microsoft’s customer story notes that citizen data shaped the environment’s design and that external access could not be treated as an afterthought.
A durable Microsoft 365 governance program should include, at minimum:
  1. Role-based access control with a clearly documented separation between operational administrators, security administrators, compliance owners, and business content owners.
  2. Multifactor authentication for users and especially for privileged accounts.
  3. Conditional Access policies that account for device state, location, risk signals, and the sensitivity of the service being accessed.
  4. Privileged Identity Management or equivalent time-limited administrative access for high-impact roles.
  5. Lifecycle workflows that automate onboarding, departmental transfers, and offboarding.
  6. Recurring access reviews for sensitive groups, guest accounts, and privileged roles.
  7. Audit-log retention and monitoring that supports incident investigation and accountability.
Microsoft’s guidance notes that identity governance can automate access changes based on changes in user attributes, delegate access decisions to business stakeholders, and support recurring access reviews for recertification. Microsoft Learn’s Entra governance documentation reinforces why identity lifecycle management should be treated as an ongoing operating discipline rather than a one-time deployment milestone.

Security, sovereignty, and the German public-sector standard​

Rosenheim’s story is especially relevant because it avoids portraying cloud migration as a binary choice between innovation and control. Instead, the project was explicitly designed around the requirements of German public administration, where sensitive citizen data, regulatory obligations, and public accountability impose a higher bar than a conventional office rollout.

Cloud usage does not transfer accountability​

The German Federal Office for Information Security, or BSI, has published a minimum standard for the use of external cloud services in the federal administration. It places emphasis on information security, transparency in cloud-service delivery, and appropriate evidence from providers, while making clear that responsibility for an organization’s IT objects and protective measures is not eliminated by the use of an external cloud provider. The BSI minimum standard for external cloud services is directed at federal administration, but its core principle is broadly instructive for municipalities: outsourcing infrastructure does not outsource governance.
That is an important distinction for Microsoft 365 deployments. Microsoft can operate the service infrastructure and provide security features, but the tenant owner remains responsible for configuring the environment appropriately, controlling identities, classifying information, overseeing sharing, and responding to incidents.
The BSI further explains that when official data is processed in an external cloud service, the minimum standard applies regardless of whether the data is public, because integrity and availability requirements still matter. The BSI’s cloud standard FAQ provides a useful corrective to the misconception that only obviously confidential files require serious cloud governance.

Sovereignty is more than data location​

The word sovereignty can be used loosely in technology marketing, but it has practical dimensions. For a municipality, it can encompass where data is stored, which legal framework applies, how provider access is governed, what evidence is available for audits, who manages encryption keys, and whether local administrators can enforce their own policies.
Microsoft’s current documentation describes its Sovereign Public Cloud approach as adding controls around data residency, operational oversight, customer-managed encryption, and policy guardrails on top of its cloud platform. It specifically identifies EU/EFTA-focused controls, including the EU Data Boundary and Data Guardian-related operational transparency measures. Microsoft Learn’s Sovereign Public Cloud overview states that these capabilities are intended for governments and regulated organizations with data, operational, and regulatory constraints.
For Microsoft 365 specifically, Microsoft says that sovereign controls span encryption, data residency, access governance, and operational transparency. Its Microsoft 365 sovereign-controls documentation describes tools such as customer-managed encryption keys, sensitivity labels, data loss prevention, auditing, and identity-based rights management.
These capabilities are meaningful, but they require deliberate design. A license entitlement or service feature does not by itself establish data sovereignty. Municipal IT teams must decide which workloads are in scope, configure policy controls, document exceptions, and verify that technical settings match legal and operational requirements.

The EU Data Boundary provides a framework, not a blanket answer​

Microsoft states that the EU Data Boundary is a geographically defined commitment to store and process customer data and personal data for specified enterprise online services, including Microsoft 365, within the EU/EFTA boundary, subject to limited documented circumstances where transfers outside the boundary may still occur. Microsoft’s EU Data Boundary documentation is valuable because it makes clear that residency and processing commitments must be read with their stated scope and exceptions.
For a municipality, that means procurement and governance teams should avoid treating a simple “data in Europe” statement as a complete compliance assessment. They should instead map:
  • The relevant Microsoft 365 services and their data types.
  • The tenant’s applicable geography and contractual commitments.
  • The types of data that may be shared externally.
  • Third-party apps connected through Microsoft Entra ID.
  • Backup, retention, eDiscovery, and audit requirements.
  • Procedures for responding to data-subject requests and security incidents.
Rosenheim’s public account does not disclose those configuration details, nor should a city necessarily publish its complete security architecture. But the city’s focus on governance, controlled external access, and secure cloud foundations suggests a more mature framing than a basic “move email to the cloud” project.

Hybrid Exchange and the value of a pragmatic transition​

Rosenheim’s migration was delivered with technology partner conet Deutschland GmbH, which led the design, migration, and implementation. The project included a hybrid Exchange arrangement because network restrictions prevented a standard setup, enabling the city to migrate all users while operating within its existing constraints. Microsoft’s deployment narrative underscores an often-overlooked migration lesson: not every environment can move directly from on-premises systems to a fully cloud-native end state.

Hybrid is a transition strategy, not automatically an end state​

Hybrid configurations are useful when legacy systems, regulatory dependencies, custom routing requirements, or staged migration schedules make an immediate cutover impractical. They can preserve continuity while users, data, and procedures move in controlled phases.
However, hybrid architecture also increases complexity. It can add synchronization dependencies, multiple control planes, legacy infrastructure requirements, and additional monitoring burdens. The key is to define the target state clearly: which components are temporary, what conditions allow their retirement, and who owns the residual risks until that retirement occurs.
Rosenheim’s approach appears to have been appropriately pragmatic. Rather than forcing an unsuitable default configuration, the organization adapted the deployment to its network constraints. That is good engineering. The risk arises only if a temporary hybrid design becomes permanent without periodic review.

Cost claims need transparent internal validation​

Microsoft’s case study states that a comprehensive assessment indicated lower lifecycle costs than the prior on-premises environment, driven by reduced infrastructure overhead and more predictable cloud operating expenses. The Rosenheim customer story does not publish the financial model, the baseline costs, the licensing mix, or the time horizon used for that assessment.
That does not make the conclusion implausible. Reducing on-premises server refreshes, storage overhead, patching workloads, and fragmented-support contracts can certainly improve predictability. But municipal IT leaders should validate savings with their own total-cost-of-ownership model, including:
  • Licensing and add-on security or compliance costs.
  • Migration and partner-services expenses.
  • Training, change management, and user support.
  • Connectivity and endpoint modernization requirements.
  • Retained legacy systems during hybrid operation.
  • Costs of backups, third-party integrations, and records management.
  • The value of reduced downtime and reduced manual administration.
The strongest financial case for Microsoft 365 is rarely “cloud licenses are cheaper than servers.” It is that a standardized service model can reduce avoidable complexity while making cost, capacity, and security planning more predictable.

Copilot exploration: governance before scale​

Rosenheim has also begun exploring Microsoft Copilot with a small number of licenses in its IT team. According to Microsoft, this early phase is intended to test use cases, assess value, and identify potential productivity and process-automation benefits before any broader rollout. The city’s next-step plan explicitly links future expansion to user enablement and governance.
This is the right sequence. Generative AI can accelerate drafting, summarization, search, scripting, and process support, but it also exposes weaknesses in content permissions, information classification, and data hygiene. If users already have excessive access to sensitive SharePoint libraries or Teams content, AI can make that oversharing easier to surface.
Rosenheim’s leadership appears to recognize this. Deputy Head of IT Karola Bromirski emphasized that governance, classification, and cloud management must be in place before AI is scaled. Microsoft’s report captures a principle that should guide every public-sector Copilot deployment: AI readiness is information-governance readiness.
A municipal Copilot pilot should therefore be judged on more than impressive demonstrations. It should test whether the organization can answer the following operational questions:
  • Which data sources can Copilot access, and which must remain out of scope?
  • Are permissions based on least privilege rather than historical convenience?
  • Are sensitive records labeled and protected appropriately?
  • Can users distinguish generated draft material from approved administrative content?
  • Is there an audit trail for use in sensitive processes?
  • Are employees trained on prompt safety, confidentiality, and verification?

A model of modernization with important caveats​

Stadt Rosenheim’s Microsoft 365 transformation offers a credible model for municipalities modernizing under resource constraints. The city has connected workplace modernization to governance, not just productivity; broadened adoption beyond the central administration; recognized identity as a core security control; and approached generative AI as a governed capability rather than a standalone experiment.
Its strengths are clear:
  • Consolidation: Replacing parallel tools with a common collaboration and communication platform.
  • Identity standardization: Reducing local account sprawl and improving policy consistency through Microsoft Entra ID.
  • Scalability: Extending the approach to municipal companies and schools.
  • Pragmatism: Using a hybrid Exchange approach where network realities required it.
  • Governance orientation: Treating controlled access, sovereignty, and compliance as design requirements.
  • Measured AI adoption: Beginning with limited Copilot testing rather than a rushed organization-wide deployment.
The risks are equally instructive. Centralization requires continuous identity hygiene. A high adoption metric needs to be followed by governance and outcome metrics. Sovereignty claims need to be grounded in real tenant configuration, contractual scope, and documented procedures. And every cloud-cost model must include the ongoing expense of licenses, skills, security operations, and change management.
Ultimately, Rosenheim’s project demonstrates that Microsoft 365 for government is most valuable when it becomes a disciplined platform for modern administration rather than a bundle of applications. The city’s next challenge will be to preserve that discipline as adoption deepens, legacy systems are retired, external collaboration grows, and AI moves from experiment to everyday work.

References​

  1. Primary source: Microsoft
    Published: 2026-07-28T08:42:07.420674
  2. Related coverage: learn.microsoft.com