Microsoft 365 security, identity and administration

Microsoft 365, secured and properly managed.

Senior-level help with identity, email, devices, licensing and tenant cleanup, for growing businesses without a dedicated Microsoft 365 administrator.

20+ years in business IT Senior-level and hands-on
16+ years with Microsoft 365 Exchange Online, Entra ID, Intune
Complex user and identity environments Accounts, email, access and devices
Dallas-Fort Worth, remote nationwide The person who assesses it does the work
The starting engagement

Microsoft 365 Security and Cost Review

A senior administrator goes through the tenant and writes down what is actually configured: who has administrative rights, whether MFA is enforced, where mail is being forwarded, what is shared outside the business, which devices are managed, and what you are paying for against who works there.

You receive written findings ranked critical, high, medium and informational, the immediate actions separated out, a remediation roadmap, and a conversation to go through it. Fixed scope and price agreed before access.

This is a technical Microsoft 365 configuration review. It is not a penetration test, formal compliance audit, insurance certification or guarantee against a security incident.

What gets examined

  • Global administrators and privileged roles
  • Active, inactive and former employee accounts
  • MFA and Conditional Access
  • Mailbox forwarding and inbox rules
  • Shared mailboxes, aliases and groups
  • Third party and OAuth application access
  • SPF, DKIM and DMARC
  • Microsoft licence allocation
  • SharePoint, OneDrive and Teams sharing
  • Intune, Defender and device management
  • Retention and recovery configuration
  • Administrative ownership and documentation
How the engagement grows

Assess, remediate, then manage

Most businesses start with the review and decide the rest afterwards. Nothing here requires the next stage.

Remediate

Implement the approved identity, email, security, licensing and device management changes, in the order they need doing.

Identity, MFA and devices

What changes

What you get out of it

  • Identity and account risk reduced
  • Access that nobody needs removed
  • Company devices actually under management
  • Avoidable licensing cost taken out
  • Email that arrives where it should
  • Administrative ownership held by the business
  • The environment written down
  • Access kept accurate as people join and leave
How the work runs

Six steps, and you own the result

  1. Understand the problem. What prompted the call, and what has already been tried.
  2. Review the existing environment. What is configured now, rather than what was intended.
  3. Agree scope and price. In writing, before any access is granted.
  4. Do the approved work. Nothing outside the agreed scope without asking first.
  5. Document what changed. So the next person does not start from nothing.
  6. Hand it over, or keep running it. Both are normal endings.

Your business owns its tenant, its domain, its licences, its accounts and its documentation. We hold administrative access to do the work, never ownership of it.

Who you actually deal with

You talk to the administrator who does the work. Not a salesperson first and an unknown junior technician afterwards.

That matters most in the assessment. The person reading your Conditional Access policies is the person who will change them, so nothing is lost in a handover, and the findings are written by somebody who has to live with the consequences of getting them wrong.

Behind that: more than twenty years in business IT, sixteen of them working with Microsoft 365 as it went from Office 365 to what it is now. Exchange Online, Entra ID, Conditional Access, Intune and Autopilot, SharePoint, OneDrive, Teams, Windows infrastructure, DNS and email.

More about how we work

Get started

Talk to someone who has run this before

Tell us what is not working. You get a straight answer, usually within one business day.

Call now Request a quote