Microsoft 365 Security & Management

Your Microsoft 365 tenant is probably misconfigured — and attackers know it.

Paying for Microsoft 365 licences doesn't mean you're protected. The security tools — Defender, Intune, multi-factor authentication, conditional access — only work once they're properly configured and actively managed. Most small businesses have never switched them on. I do it for you, and keep it that way.

Microsoft Partner
Cyber Essentials aligned
UK-based MSP
The risk

Default settings leave the door open.

Most small businesses have Microsoft 365 but have never configured Defender or Intune. Out of the box there's no device compliance, no enforced MFA, no conditional access and nobody watching for threats. A breach through an unmanaged device or a compromised account can happen completely silently — and these aren't rare events. Business email compromise, phishing and ransomware hit small businesses every single day, precisely because they're the soft target.

Business Email Compromise

An attacker quietly gets into a mailbox, watches for an invoice, then redirects a payment to their own account. With no MFA enforcement or sign-in alerting, you often only find out once the money has gone.

Phishing & stolen passwords

Staff reuse passwords and click convincing links. Without conditional access and modern authentication, a single stolen password is all it takes to walk straight into your tenant.

Ransomware via an unmanaged device

A personal laptop with no encryption, no compliance check and no Defender policy connects to your files. One bad download and it spreads — silently, because nothing was watching.

What's included

Set up properly. Managed continuously.

Three pillars take you from an exposed, default tenant to a hardened, monitored environment — and keep it there.

Pillar 1

Tenant Hardening

Initial setup

  • Entra ID (Azure AD) security baseline
  • Conditional Access — block legacy auth, require MFA, location-based rules
  • Microsoft Defender for Business / Endpoint configuration
  • Anti-phishing, anti-spam, Safe Links and Safe Attachments policies
  • Microsoft Secure Score review and remediation
  • Admin role review and least-privilege enforcement
Pillar 2

Device Management via Intune

Every device, under control

  • Device enrolment for Windows, iOS, Android and macOS
  • Compliance policies — encryption, OS version and PIN enforcement
  • App protection (MAM) for personal BYOD devices
  • Windows Autopilot for zero-touch new-device setup
  • Software deployment and managed update rings
Pillar 3

Ongoing Managed Security

Month after month

  • Monthly Secure Score reporting in plain English
  • Defender incident monitoring and response
  • Policy drift detection and remediation
  • Alert triage — we handle the noise so you don't have to
  • Quarterly tenant review and recommendations
How it works

From assessment to fully managed, in three steps.

1

Free tenant assessment

I audit your current Microsoft 365 security posture — your Secure Score, sign-in settings, devices and policies — and show you exactly where the gaps are.

2

We configure and harden

I set up Defender, Intune and Conditional Access properly across your tenant. Typically done within 5–10 business days, with no disruption to your team.

3

Ongoing management

Monthly monitoring, incident response and reporting, plus a quarterly review. Your security keeps pace as Microsoft and the threats keep changing.

Why this matters

Microsoft gives you the tools. Not the configuration.

The tools aren't the same as protection

Microsoft gives you Defender and Intune — but ships them switched off or wide open. The licence is the start, not the finish.

An unconfigured Defender is no Defender

Out of the box, Defender misses things it should catch. It has to be tuned, monitored and acted on to actually protect you.

Intune without policies is just a portal

Enrolling devices means nothing without compliance and protection rules behind it. Rules are where the security lives.

Compliance increasingly demands it

Cyber Essentials, ISO 27001 and cyber insurance now expect demonstrable device management and security controls. We give you the evidence.

Pricing

Two ways to work together.

Start with a one-off hardening project, or have me run your security for you month to month. Every engagement begins with a free assessment, so you know exactly what you're getting before you commit.

Foundation
One-off setup
Get a quote
one-off setup fee

Ideal for businesses starting from scratch.

  • Full tenant hardening (Pillar 1)
  • Intune enrolment for all your devices
  • Conditional Access and MFA enforced
  • Defender for Business configured
  • Secure Score review and remediation
Book a free assessment
Foundation + Managed
Most popular
Get a quote
per user, per month, plus a one-off setup fee

Ideal for businesses that want hands-off security management.

  • Everything in Foundation
  • Ongoing Defender incident monitoring
  • Policy drift detection and remediation
  • Monthly Secure Score reporting
  • Quarterly tenant review
Book a free assessment

Final pricing depends on your user count, number of devices and current setup — I'll confirm it in a clear written quote after the free assessment.

FAQ

Common questions

Do I need extra Microsoft licences for this?+

Usually not for the essentials — most of the hardening uses features already in Microsoft 365 Business Premium, which most small businesses are best on anyway. If you're on a lower plan, I'll tell you exactly what (if anything) you need and why, in plain English, before any work starts. No surprise licence bills.

We already have Microsoft 365 — isn't that enough?+

Having the licences gives you the tools, not the protection. By default, MFA may not be enforced, devices aren't managed, Defender isn't tuned and nobody is watching the alerts. This service turns those tools on, configures them properly for your business, and keeps them working.

What's the difference between Defender for Business and Defender for Endpoint?+

They're close cousins. Defender for Business is the small-business edition (included with Business Premium) and covers everything most SMBs need — antivirus, threat detection and response across your devices. Defender for Endpoint is the enterprise version with deeper tooling. I'll configure whichever you're licensed for and make sure it's doing its job.

Can you manage devices our staff already use (BYOD)?+

Yes. For personal devices we use app protection policies (MAM) — that secures the work data inside apps like Outlook and Teams without taking over someone's personal phone. Company-owned devices get fully enrolled and managed. Staff keep their privacy, you keep your data safe.

What happens if a threat is detected?+

On the Managed tier, Defender alerts come to me. I triage them — most are noise and get handled quietly — and for anything genuine I respond fast: isolating a device, locking an account, and getting in touch so you know what's happening and what to do.

How long does the initial setup take?+

Typically 5–10 business days from go-ahead, depending on how many devices and users you have. It's done in the background with little to no disruption — most of your team won't notice anything except a one-off MFA setup.

Does this help with Cyber Essentials certification?+

Very much so. Device management, MFA, secure configuration and patching are core to Cyber Essentials, and this service puts demonstrable controls in place. If you're also going for certification, I can line the two up so the work counts twice.

Find out how secure your Microsoft 365 tenant really is.

The assessment is free and there's no obligation. You'll get a clear picture of where you stand and exactly what it would take to close the gaps.

Book a free assessment
Free assessment

Let's look at your tenant together.

Tell me a little about your business and how many users you have. I'll come back within one working day to arrange your free Microsoft 365 security assessment — no jargon, no pressure.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.