Microsoft 365 Security

Microsoft 365 security, configured the way Microsoft actually recommends

A default Microsoft 365 tenant is not a secure one. Legacy authentication is often still reachable, sharing defaults are wide open, and the audit trail you would need after an incident may not be on.

Your tenant is the single most valuable target you own

Email, files, calendars, chat, and increasingly your identity system all live in Microsoft 365. Which means one compromised administrator account is not a nuisance, it is your whole business. And Microsoft ships the tenant configured for maximum compatibility, not maximum security. Closing that gap is deliberate work somebody has to do.

We start with identity: Conditional Access policies that evaluate user, location, device compliance, and risk on every sign-in, phishing-resistant MFA, legacy authentication protocols switched off, and administrative roles separated from daily-use accounts with just-in-time elevation.

Then email authentication, which is the single most commonly botched item we find. Publishing DMARC at p=none does nothing but generate reports nobody reads. Getting to enforcement without breaking your legitimate mail flow takes a staged rollout and attention, which is precisely why so many domains never finish it.

And finally the thing most businesses assume is handled and is not: backup. Microsoft's retention policies are not backup. A deleted mailbox, a ransomware event that encrypts synced OneDrive files, or a departed employee's SharePoint site can all be permanently gone within the default retention window.

You probably need this if

  • You cannot say whether legacy authentication is disabled in your tenant
  • Your DMARC record is set to p=none, or you do not have one
  • Administrators use the same account for daily email and admin work
  • You have no backup of Microsoft 365 data beyond Microsoft's retention
  • Someone has spoofed your domain to a client or vendor
  • You are paying for licenses nobody can account for

What is included

Full tenant security assessment with Secure Score baseline
Conditional Access policy design and staged deployment
Phishing-resistant MFA rollout with user communication
Legacy authentication protocols disabled safely
Administrative role separation and just-in-time elevation
SPF, DKIM, and DMARC staged to enforcement (p=reject)
Anti-phishing, impersonation, and Safe Links protection tuned
External sharing and guest access policy configuration
Purview retention, data loss prevention, and legal hold
Unified audit logging enabled and retained
Third-party backup for Exchange, OneDrive, SharePoint, and Teams
License optimization review, often self-funding
Book a 15-Minute Fit Call Compare Plans

Deliverables

What you actually get, in writing

Not a vague promise of support. Specific artifacts you can point at, hand to an auditor, or take with you if you ever leave.

Tenant hardening report

Before-and-after configuration documented item by item, so you can see exactly what changed and prove it later.

DMARC enforcement evidence

Your domain moved from monitoring to p=reject with the staged rollout documented, plus aggregate reporting you can actually read.

Conditional Access policy set

Written policy definitions with the business rationale for each, so a future administrator understands why before changing something.

Independent backup with restore proof

Third-party backup of all Microsoft 365 workloads plus documented restore tests, because Microsoft's retention is not a backup.

Retention and legal hold map

What is retained, for how long, and where, which matters enormously for HIPAA, IRS, and litigation hold obligations.

License optimization findings

Unused and over-provisioned licenses identified. This line item frequently pays for a meaningful portion of the engagement.

Questions

Questions about this service

We already have Microsoft 365. Is it not secure by default?

It is configured for compatibility by default, which is not the same thing. In nearly every tenant we assess we find at least one of these: legacy authentication still reachable, no Conditional Access at all, administrators using their daily accounts for admin work, unified audit logging off, and unrestricted external sharing. None of those are Microsoft's fault. They are configuration decisions nobody made.

Does Microsoft not back up my data already?

No, and this is the most expensive misunderstanding in the product. Microsoft guarantees the availability of the service, not the recoverability of your content. Their model is retention with limited windows, generally 30 to 93 days depending on the workload and configuration. A ransomware event that encrypts synced OneDrive files, a maliciously deleted mailbox, or a SharePoint site removed after an employee leaves can all pass beyond recovery. Independent backup is not optional.

Will hardening break how our staff works?

Done carelessly, absolutely. That is why we deploy Conditional Access in report-only mode first and watch what would have been blocked, then enable enforcement in stages with advance communication. DMARC gets the same treatment, staged from none through quarantine to reject while we watch aggregate reports for legitimate senders. Rushing either one is how providers cause outages and then blame security.

What is DMARC and why does mine not work?

DMARC tells receiving mail servers what to do with messages that fail authentication checks while claiming to be from your domain. Most domains we audit publish it at p=none, which means take no action, effectively monitoring only. Anyone can still successfully spoof your domain and invoice your clients. Enforcement, meaning p=reject, is the point, and reaching it requires finding and fixing every legitimate sender first.

Can you fix a tenant somebody else set up badly?

That is most of this work. We inherit tenants with orphaned admin accounts, mystery Conditional Access policies with no documentation, half-finished migrations, and sharing links to files that should never have left the building. We document what exists, tell you what is risky, and remediate in a sequence that does not take your email down on a Tuesday morning.

Want to know where you stand right now?

The assessment documents your environment, scores it against a modern baseline, and hands you a written report you keep either way.

No pressure, no obligation. If we are not the right fit we will tell you and point you somewhere better.

Call Book a Fit Call