Turn on the Microsoft 365 security you already pay for
Business Premium and E5 include Defender, Intune, Entra ID, and Purview. Most tenants run almost none of it. We implement it properly — defined scope, quoted price, staged rollout, documented handover.
Six implementation packs. Take one or take them all.
Each is a self-contained piece of work with a defined scope, so you can sequence the tenant hardening around your budget instead of signing up for an open-ended project.
Defender for Office 365 baseline
Email and collaboration hardened against malicious attachments, malicious links, and identity spoofing — configured against Center for Internet Security guidance for Office 365, within the licensing you already hold.
Defender for Office 365 licensingDefender for Endpoint baseline
Endpoint detection and response switched on properly across your estate: onboarding, policy baselines, attack-surface-reduction rules, and alerting that reaches a human rather than an unread portal.
Defender for Endpoint licensingDevice management with Intune
A full cloud endpoint solution in Microsoft Intune for corporate Windows plus BYOD iOS and Android, built on Microsoft best practices and security baselines — enrolment, compliance policies, and app protection.
Microsoft Intune licensingIdentity management with Entra ID
Conditional access, MFA enforcement, privileged-role hygiene, and sign-in risk policies configured so identity stops being the soft entry point into the tenant.
Microsoft Entra ID licensingData protection with Purview
Sensitivity labelling, retention, and data-loss-prevention policies applied to the places business data actually lives — Exchange Online, SharePoint, OneDrive, and Teams.
Microsoft Purview licensingBusiness Premium security adoption
The whole Business Premium security stack turned on as one coherent configuration rather than six half-finished pilots — the single most common gap we find in SMB tenants.
Microsoft 365 Business Premium licensingLicensed is not the same as configured
These are the recurring gaps between what a tenant is paying for and what it is actually enforcing.
Paying for Business Premium, running Business Basic security
Business Premium includes Defender, Intune, Entra ID P1, and Purview features. We implement the ones you are already paying for, so the licence upgrade finally produces a security outcome.
MFA enabled, but conditional access never configured
MFA on its own leaves legacy authentication, unmanaged devices, and impossible-travel sign-ins wide open. Conditional access policies close those paths and are scoped so nobody gets locked out on go-live day.
Defender licensed but never onboarded
Devices are onboarded, baselines applied, and attack-surface-reduction rules moved out of audit mode — the step that turns a licence line item into actual detection.
Personal phones with full mailbox access and no controls
App protection and BYOD policies in Intune keep company data inside managed apps on personal devices, without enrolling and wiping an employee-owned phone.
No idea whether the tenant matches a recognised benchmark
Configuration is set against Microsoft security baselines and CIS guidance for Office 365, and you get the resulting configuration documented — useful evidence when an insurer or auditor asks.
Copilot switched on over a decade of oversharing
Copilot surfaces everything a user can already reach. Labelling and permission cleanup happen before rollout, not after someone finds the payroll spreadsheet through a chat prompt.
How the engagement runs
Scope agreed and priced up front, then rolled out in stages that can be reversed before they are enforced.
Tenant assessment
We review the current configuration against Microsoft security baselines and CIS guidance for Office 365, and against what your licences actually entitle you to run. The output is a gap list, not a sales deck.
Fixed scope and fixed price
You pick which packs to implement — Defender for Office 365, Defender for Endpoint, Intune device management, Entra identity, Purview data protection. Each has a defined scope and a fixed quoted price before any work starts.
Pilot group
Policies are applied to a pilot group first so conditional access, compliance policies, and ASR rules get validated against real working patterns before the whole company feels them.
Staged rollout
Rollout proceeds in waves with report-only and audit modes ahead of enforcement, so a policy that would break a line-of-business app is caught while it is still reversible.
Documentation and handover
You receive the as-built configuration and the reasoning behind each policy. From there, run it yourself or hand it to us for ongoing management.
Migrating into Microsoft 365 first?
If you are still on Google Workspace, on-prem Exchange, or consolidating tenants after a merger, do the move first and harden the destination as part of the same project.
Microsoft 365 migrationWant it watched, not just configured?
A hardened tenant still needs someone reading the alerts. Managed detection and response covers the ongoing half that a one-time implementation deliberately does not.
24/7 detection & responseFrequently asked questions
What is actually included in a Microsoft 365 security implementation?
It is a set of fixed-scope packs you can take individually or together: a Defender for Office 365 baseline, a Defender for Endpoint baseline, device management in Microsoft Intune for corporate and BYOD endpoints, identity management in Entra ID (conditional access, MFA, privileged roles), and data protection in Microsoft Purview. Each pack has a defined scope agreed in writing before work begins.
Do we need to buy new licences?
Usually not. Most of what we implement is already included in Microsoft 365 Business Premium or E5 and simply was never configured. The assessment tells you exactly what your existing licences entitle you to run. If something genuinely needs a licence you do not hold, we say so and you can price it through our software store rather than being upsold.
Will conditional access lock our staff out?
That is the risk we design around. Policies are built in report-only mode, validated against a pilot group, and rolled out in waves with break-glass accounts excluded. You see the impact of each policy on real sign-ins before it is ever enforced.
How is this different from your managed security services?
This is a one-time implementation project with a fixed scope and a fixed price — it gets the tenant into a known-good state. Managed services are the recurring alternative where we also monitor and respond on an ongoing basis. Plenty of clients do the implementation, run it themselves, and only move to managed later.
What do you hand over at the end?
The as-built configuration, the policies applied, and the reasoning for each — so a future admin or auditor can see what was done and why. Nothing is left as undocumented tribal knowledge.
Can you do this before a Copilot rollout?
Yes, and that is the right order. Copilot surfaces anything a user already has access to, so permission sprawl and unlabelled data become visible the day it goes live. Sensitivity labelling and permission cleanup belong before the rollout, not after.
How much does it cost?
It depends on which packs you take and the size and state of your tenant. Every engagement is quoted as a fixed price against a written scope before work starts, so there is no hourly meter running. Contact us with your user count and current licensing for a quote.
Find out what your tenant is missing
Tell us your user count and current Microsoft 365 licensing, and we will come back with the gap list and a fixed price for closing it.