Climatec Kept External File Sharing Running Through Bosch’s Microsoft 365 Cutover with Files.com
Climatec has spent fifty years making buildings run. Founded in Phoenix in 1975, the company designs, installs, and services building automation, security and life safety, and turnkey energy systems for commercial and institutional customers. With roughly 1,000 employees, it became Bosch’s foundation for building technology in North America. In January 2026, it took the parent’s name outright, becoming Bosch Building Technologies North America.
That unification created the problem. A systems integrator’s files leave the company by definition: project managers send bid drawings, specifications, and quotes to customers and outside bidders, and technical support sends troubleshooting files and fix executables to technicians standing at a customer’s own machine, where a corporate login does not exist. The parent absorbing all of this is the Bosch Group, an industrial company with over 400,000 associates worldwide, and its Microsoft 365 estate is governed accordingly: anonymous and public-facing links are prohibited, and any recipient of a shared file must hold an account in the system. Folding Climatec into Bosch meant folding a business built on sending files outward into a tenant where, as a matter of policy, files do not go outward without an account.
One Company, Two Tenants, and No Sanctioned Way to Send a File
Bosch migrated Climatec’s offices onto its infrastructure in waves. Las Vegas went live in November 2025 and immediately lost the ability to send files externally through Teams. And because Climatec and Bosch sat on separate Microsoft 365 tenants, the two halves of one company were now external to each other: a Climatec employee and a Bosch colleague had no sanctioned way to exchange a file at all.
“We have a big need to send files to customers, to technicians working on customer machines, and during our integration, our Bosch employees and our Climatec employees need to be able to communicate.”
The existing workarounds were already failing the business before the policy arrived to prohibit them. Climatec’s sanctioned mechanism was the OneDrive anonymous link, which expired after 24 hours. For a project manager mid-bid, that meant re-sending the same drawings to the same customer over and over while the customer waited. For technical support it was worse: fix executables stay valid 90 days or longer, so a technician at a customer’s machine routinely found the link dead before the work was done. Email was no fallback, because bid drawings and specifications routinely exceeded the roughly 20 MB attachment limit. The remaining route was slower still: to send a large file to an outside party, someone had to open an IT ticket and have that person provisioned as a contact in Azure first.
Around all of that, business units had quietly solved the problem themselves.
“Box, Dropbox, Hightail, Ignite, Procore, and probably three dozen more, to be honest.”
Every one of those tools was scheduled to be prohibited as the migration proceeded, with hundreds of employees moving in successive waves and the East Coast branches to follow. Office by office, on a calendar Climatec did not control, the company’s external sharing was going to stop working.
Why a Better Dropbox Was Never the Answer
The obvious move was to pick one of the tools already in the building and make it official. That failed on governance, not on features.
“The problem is, if they do that and Bosch says, well, you can’t use that tool anymore, now we have a user’s data in a system we don’t support, and now we have to help them get it out and get it into another system.”
Under Bosch data-classification rules, anything users park in an unsanctioned system becomes an extraction liability the day the tool is disallowed. Sync-and-store platforms were disqualified precisely because they are good at storage. Ignite, the closest functional fit, required two separate links for a single exchange, one to upload and one to download.
So the requirements were unusual. The replacement had to deliver files to recipients who hold no account and never will, without using an anonymous public link, which is exactly the combination Bosch policy made contradictory inside OneDrive. It had to carry a two-way exchange on a single link. It had to be built for files to pass through rather than accumulate, so it could never harden into another storage system Bosch would have to classify. It had to give IT one managed surface serving both the Bosch and Climatec domains. And it had to roll out office by office on the parent’s migration schedule.
Climatec selected Files.com to be that surface.
Recipient-Locked Links on a 30-Day Clock
What Climatec built on Files.com was a governed layer that files pass through on their way out of the company, and every configuration choice served that idea.
Identity spans the merge. Entra ID single sign-on covers both the Bosch and Climatec domains, so employees on either side of the tenant boundary sign in to the same platform.
Delivery works without anonymity, which is the move that resolves the policy contradiction. Every outbound file goes as a Files.com share link that can be restricted to a specific recipient’s email address, with registration required to open it. The recipient needs no Bosch account, no Climatec account, and no software; they register through Files.com in a browser. But the link is neither anonymous nor public-facing: forwarded to anyone else, it will not open. Owens tested exactly that, forwarding links and attempting unauthenticated access, and confirmed the registration requirement blocks them. Bosch policy prohibits anonymous links, not external delivery, and a recipient-locked link is not an anonymous link. Password protection and expiration can be set by policy rather than fixed at 24 hours.
Ephemerality is enforced, not encouraged. Files expire 30 days after their last modification, with 30 days of trash retention behind that. That gives recipients up to 30 days to retrieve a transfer—including support executables that may remain valid for 90 days or longer—rather than the old one-day deadline. Anything durable moves to SharePoint or OneDrive, which remain the systems of record. Files.com holds a file for exactly as long as a transfer needs it.
“After X number of days, either you put it in SharePoint or you lose it, because we can’t allow this to become somebody’s new version of OneDrive.”
Access logs and exportable reporting cover logins, file access, and expired links, so IT can show rather than assert what left the company and who received it. The rollout ran behind each Bosch migration wave, the platform’s own domain moved from the Climatec brand to Bosch Building Technologies North America along the way, and Climatec’s IT team now runs the platform on its own.
External Sharing Survived the Cutover
With Files.com in production behind the migration waves, Climatec replaced a 24-hour workaround, an IT ticket queue, and a field of business-unit tools with one governed way for files to leave the company.
- The Las Vegas office lost Teams external file sending on migration day, and its three core sharing workflows kept running on Files.com: customer bid documents, technician file delivery, and Climatec-to-Bosch exchange.
- Recipient access went from a 24-hour deadline to a policy-governed duration. Support executables that stay valid for 90 days or longer can be made available for up to 30 days per transfer instead of one.
- Bidding is no longer bounded by email. Drawings and specifications above the 20 MB attachment limit go to outside bidders as password-protected, expiring links, and engineering management sends HVAC system schematics to iPads in the field.
- Forwarding is closed as a leak path, and the ad hoc tools business units had procured collapsed into one IT-managed platform, with the large majority of accounts already on the Bosch domain.
The compounding result is that the migration stopped being a threat to the business. Each subsequent wave lands on a platform already in production, so external sharing no longer breaks on cutover day. And the exchange between Climatec and Bosch employees, two halves of one company that the tenant boundary treats as strangers, is now the platform’s largest use case by volume. Files.com is how the company works as one while the merge completes.
Transfer, Not Storage
What changed underneath is that external sharing stopped being something each business unit solved for itself and became part of the company’s governed infrastructure, with one owner, one audit trail, and one set of rules. Climatec did not find a better place to keep files. Under a data-classification regime as strict as Bosch’s, that was never going to be allowed. It built a governed layer on Files.com that files pass through on their way somewhere else, and that is exactly what keeps it allowable.
Related Customer Stories
Construction & Engineering
PulteGroup Retired Its Microsoft Windows Server 2008 FTP Endpoint Without Rewriting Vendor Scripts
Files.com met each vendor’s existing protocol and connection behavior, taking outside development schedules out of the retirement plan.
Read story →
Construction & Engineering
KPFF Replaced Microsoft SharePoint With Files.com Data Rooms for Multi-Party Litigation Production
A live forensic case proved that group-scoped data rooms could move large project records to outside legal teams without exposing one party’s files to another.
Read story →

Construction & Engineering
Mead & Hunt Unblocked Its Microsoft Dynamics ERP Rollout with Files.com—Without Self-Hosting SFTP
Files.com now routes two isolated vendor feeds into Mead & Hunt's existing Azure Files storage, while the firm manages credentials and permissions rather than internet-facing infrastructure.
Read story →