Your Microsoft 365 tenant is probably misconfigured — and attackers know it.
Paying for Microsoft 365 licences doesn't mean you're protected. The security tools — Defender, Intune, multi-factor authentication, conditional access — only work once they're properly configured and actively managed. Most small businesses have never switched them on. I do it for you, and keep it that way.
Default settings leave the door open.
Most small businesses have Microsoft 365 but have never configured Defender or Intune. Out of the box there's no device compliance, no enforced MFA, no conditional access and nobody watching for threats. A breach through an unmanaged device or a compromised account can happen completely silently — and these aren't rare events. Business email compromise, phishing and ransomware hit small businesses every single day, precisely because they're the soft target.
Business Email Compromise
An attacker quietly gets into a mailbox, watches for an invoice, then redirects a payment to their own account. With no MFA enforcement or sign-in alerting, you often only find out once the money has gone.
Phishing & stolen passwords
Staff reuse passwords and click convincing links. Without conditional access and modern authentication, a single stolen password is all it takes to walk straight into your tenant.
Ransomware via an unmanaged device
A personal laptop with no encryption, no compliance check and no Defender policy connects to your files. One bad download and it spreads — silently, because nothing was watching.
Set up properly. Managed continuously.
Three pillars take you from an exposed, default tenant to a hardened, monitored environment — and keep it there.
Tenant Hardening
Initial setup
- Entra ID (Azure AD) security baseline
- Conditional Access — block legacy auth, require MFA, location-based rules
- Microsoft Defender for Business / Endpoint configuration
- Anti-phishing, anti-spam, Safe Links and Safe Attachments policies
- Microsoft Secure Score review and remediation
- Admin role review and least-privilege enforcement
Device Management via Intune
Every device, under control
- Device enrolment for Windows, iOS, Android and macOS
- Compliance policies — encryption, OS version and PIN enforcement
- App protection (MAM) for personal BYOD devices
- Windows Autopilot for zero-touch new-device setup
- Software deployment and managed update rings
Ongoing Managed Security
Month after month
- Monthly Secure Score reporting in plain English
- Defender incident monitoring and response
- Policy drift detection and remediation
- Alert triage — we handle the noise so you don't have to
- Quarterly tenant review and recommendations
From assessment to fully managed, in three steps.
Free tenant assessment
I audit your current Microsoft 365 security posture — your Secure Score, sign-in settings, devices and policies — and show you exactly where the gaps are.
We configure and harden
I set up Defender, Intune and Conditional Access properly across your tenant. Typically done within 5–10 business days, with no disruption to your team.
Ongoing management
Monthly monitoring, incident response and reporting, plus a quarterly review. Your security keeps pace as Microsoft and the threats keep changing.
Microsoft gives you the tools. Not the configuration.
The tools aren't the same as protection
Microsoft gives you Defender and Intune — but ships them switched off or wide open. The licence is the start, not the finish.
An unconfigured Defender is no Defender
Out of the box, Defender misses things it should catch. It has to be tuned, monitored and acted on to actually protect you.
Intune without policies is just a portal
Enrolling devices means nothing without compliance and protection rules behind it. Rules are where the security lives.
Compliance increasingly demands it
Cyber Essentials, ISO 27001 and cyber insurance now expect demonstrable device management and security controls. We give you the evidence.
Two ways to work together.
Start with a one-off hardening project, or have me run your security for you month to month. Every engagement begins with a free assessment, so you know exactly what you're getting before you commit.
Ideal for businesses starting from scratch.
- Full tenant hardening (Pillar 1)
- Intune enrolment for all your devices
- Conditional Access and MFA enforced
- Defender for Business configured
- Secure Score review and remediation
Ideal for businesses that want hands-off security management.
- Everything in Foundation
- Ongoing Defender incident monitoring
- Policy drift detection and remediation
- Monthly Secure Score reporting
- Quarterly tenant review
Final pricing depends on your user count, number of devices and current setup — I'll confirm it in a clear written quote after the free assessment.
Common questions
Do I need extra Microsoft licences for this?+
Usually not for the essentials — most of the hardening uses features already in Microsoft 365 Business Premium, which most small businesses are best on anyway. If you're on a lower plan, I'll tell you exactly what (if anything) you need and why, in plain English, before any work starts. No surprise licence bills.
We already have Microsoft 365 — isn't that enough?+
Having the licences gives you the tools, not the protection. By default, MFA may not be enforced, devices aren't managed, Defender isn't tuned and nobody is watching the alerts. This service turns those tools on, configures them properly for your business, and keeps them working.
What's the difference between Defender for Business and Defender for Endpoint?+
They're close cousins. Defender for Business is the small-business edition (included with Business Premium) and covers everything most SMBs need — antivirus, threat detection and response across your devices. Defender for Endpoint is the enterprise version with deeper tooling. I'll configure whichever you're licensed for and make sure it's doing its job.
Can you manage devices our staff already use (BYOD)?+
Yes. For personal devices we use app protection policies (MAM) — that secures the work data inside apps like Outlook and Teams without taking over someone's personal phone. Company-owned devices get fully enrolled and managed. Staff keep their privacy, you keep your data safe.
What happens if a threat is detected?+
On the Managed tier, Defender alerts come to me. I triage them — most are noise and get handled quietly — and for anything genuine I respond fast: isolating a device, locking an account, and getting in touch so you know what's happening and what to do.
How long does the initial setup take?+
Typically 5–10 business days from go-ahead, depending on how many devices and users you have. It's done in the background with little to no disruption — most of your team won't notice anything except a one-off MFA setup.
Does this help with Cyber Essentials certification?+
Very much so. Device management, MFA, secure configuration and patching are core to Cyber Essentials, and this service puts demonstrable controls in place. If you're also going for certification, I can line the two up so the work counts twice.
Find out how secure your Microsoft 365 tenant really is.
The assessment is free and there's no obligation. You'll get a clear picture of where you stand and exactly what it would take to close the gaps.
Book a free assessmentLet's look at your tenant together.
Tell me a little about your business and how many users you have. I'll come back within one working day to arrange your free Microsoft 365 security assessment — no jargon, no pressure.