Skip to content

Fixed-scope project

Close the gaps, and prove they are closed.

A defined engagement that measures your Microsoft 365 tenant against a recognized baseline, moves it toward a Zero Trust posture in waves you approve, and leaves you with evidence rather than assurances.

Service

Microsoft 365 Security Hardening

Engagement

Fixed-scope project

Engagement

4 – 8 weeks

The problem

Secure Score is not a security program

Most tenants are configured to the defaults Microsoft shipped, plus whatever was turned on during an incident. Legacy authentication is still reachable. Conditional Access has exceptions nobody remembers granting. Global admin count is in double digits. None of this shows up until an auditor, an insurer or an attacker goes looking.

Scope

What the engagement covers.

Anything outside this list is quoted separately rather than absorbed quietly.

Tenant assessment against CIS Microsoft 365 Benchmark and Microsoft security defaults
Zero Trust identity hardening: Conditional Access, MFA coverage, legacy authentication, privileged role review
Privileged Identity Management and just-in-time admin access
Defender for Office 365, Defender for Identity and Defender for Endpoint policy
Intune device compliance and app protection policy
Purview data loss prevention and retention where in scope
External sharing, guest access and tenant-wide collaboration posture

Deliverables

What you are left holding.

Every item here is an artifact you own, in your systems, readable by someone who was not in the room.

01

Gap assessment

Every finding, scored by risk and effort, mapped to the control it fails. No generic checklist output.

02

Remediation plan in waves

Sequenced so the highest-risk, lowest-disruption items land first. You approve each wave before it runs.

03

Change record

What was changed, when, by whom and what it was before. This is the artifact your auditor asks for.

04

Post-remediation report

The same assessment, run again, showing the delta. Evidence, not assertion.

Engagement: 4 – 8 weeks

Assessment in the first two weeks. Remediation waves follow at a pace your change process can absorb.

Fit

Who this is for, and who it is not.

We would rather lose the engagement at this paragraph than three weeks in.

A good fit if

  • You are facing a security questionnaire, a cyber insurance renewal or a client audit
  • You have never had the tenant assessed against an external baseline
  • You have had a near miss and want to know what else is exposed

Not a fit if

  • You are mid-incident and need containment right now. Call an incident response firm first, then call us
  • You want a scan report with no remediation attached

Questions

About Microsoft 365 security hardening.

Will hardening break things for our users?

It can, which is why remediation runs in approved waves rather than as one change window. High-risk items with low user impact go first. Anything that changes the sign-in experience is scheduled, communicated and piloted with a group you choose before it goes tenant-wide.

Which baseline do you measure against?

The CIS Microsoft 365 Benchmark by default, cross-referenced with current Microsoft security defaults. If your industry requires a different framework, we map to that instead and say so in the assessment.

Do we need the managed service afterwards?

No. Hardening is a fixed-scope project and it ends. A hardened tenant drifts like any other, so some clients move to ongoing management afterwards, but that is a separate decision and we will not bundle it into the quote.

Often paired with

What this usually runs alongside.

These are the combinations that come up most often, not an upsell list.

Microsoft 365 Security Hardening

Thirty minutes, no pitch.

Tell us what the environment looks like today. We will tell you what we would change first, and whether this is the right engagement for it.