Microsoft 365

Fixing what the review actually found

Remediation is scoped from findings, not from a package. You approve the list, we do the work in the order that makes sense, and every change is written down.

Remediation is the work of turning a list of findings into a tenant that is actually configured properly. It follows the Security and Cost Review, or it follows a report somebody else wrote, and the scope is whichever items you approve.

The order is not arbitrary. Some changes depend on others, and one of them, enforcing multi-factor authentication, will interrupt everybody for a few minutes and is worth planning rather than springing on a Tuesday.

,

The work this usually covers

Which of these apply depends entirely on the findings. Nobody needs all eight.

  • Identity and sign-in. MFA enforced rather than available, Conditional Access policies that apply to real groups, and admin work moved off everyday accounts.
  • Former employees. Sign-in blocked, sessions revoked, mailboxes and files handed over, licences released. Covered in detail on former employee access.
  • Administrative ownership. A break glass admin account that belongs to the business, with recovery details the business can reach.
  • Mail flow and authentication. Forwarding rules removed where they should not exist, and SPF, DKIM and DMARC corrected so your mail authenticates.
  • Licence cleanup. Assignments matched to people who actually work there, and plans matched to what people actually use.
  • Sharing and external access. Anonymous links reviewed, guest access tightened, and defaults set so the next three years do not rebuild the same problem.
  • Device management. Enrolment through Intune and Autopilot where laptops are currently unmanaged.
  • Documentation. What exists, who has access, what changed and when. The part that makes the next person cheap rather than expensive.
,

How it runs

  1. You approve the list

    Item by item, with the reasoning attached. Anything you decline is recorded as declined rather than quietly dropped.

  2. Scope and price agreed in writing

    Before any change is made.

  3. The disruptive parts get a date

    MFA enrolment and anything touching mail routing are scheduled with you rather than around you.

  4. The work is done

    Changes made, tested, and checked against the finding they were meant to close.

  5. You get a record of what changed

    Written for whoever comes next, not for us.

,

Who this is for

  • You have a report, from us or from anybody else, and want the findings closed.
  • You know one specific thing is wrong and want it fixed properly rather than patched.
  • A customer, insurer or auditor has asked you to demonstrate a control that does not exist yet.

When this is not the right fit

  • You want somebody to make a compliance certificate appear. We change configuration, not paperwork.
  • You are looking for continuous monitoring or a security operations centre. We do not run one.
  • You want the work done without telling your team that sign-in is changing. That never ends well.
,
,

What Tech True Point can help with

Commonly paired with:

  • Ongoing administration, so the tenant does not drift back within a year.
  • A joiner and leaver process that people will actually follow.
  • Device enrolment where laptops have never been managed.
  • Documentation of what now exists, which most businesses have never had.
,

Common questions

Do you have to run the review first?

Not always. If you already know what is wrong, for example every account needs MFA enforced and nobody has done it, we can quote that piece directly.

Where the review earns its place is when the answer to "what needs fixing" is a shrug. Quoting remediation without knowing what is in the tenant produces a number that is wrong in one direction or the other.

Will this interrupt people while they work?

Some of it will, and we would rather say which parts up front than surprise you. Enforcing multi-factor authentication means everybody enrolls, which is a short interruption on a day of your choosing. Changing mail routing is done outside working hours.

Most of the rest, licence cleanup, removing dormant accounts, tightening sharing, happens without anybody noticing.

What if we do not want to do all of it?

That is normal and often correct. Some findings are worth accepting: a control that would break how a team genuinely works is not an improvement.

We put the reasoning next to each item so you can make that call rather than defer to us. What we will not do is quietly drop something important and let the report look complete.

Do we get to see what changed?

Yes. Every change is written down: what it was, what it is now, and why. That record is yours and it is the thing that makes the next review cheap.

It also matters when somebody else takes over. Undocumented changes are how a tenant becomes a mystery again within two years.

,
Get a Quote

Have findings you want acted on

Whether they came from our review or somebody else's, send them over and we will tell you what we would do first and what we would leave alone.

Call now Request a quote