Skip to content
All services
Identity, PKI & domainsBuild

Microsoft 365 security baseline

Conditional Access, phishing-resistant MFA and just-in-time admin rights for Microsoft 365, plus Intune policies, Defender for Endpoint and disk encryption for Windows and macOS, designed and rolled out in 1–3 weeks.

When you need it

Your Microsoft 365 tenant grew with the company. Some users still sign in without MFA, legacy protocols are still open and several people are permanent Global Administrators. Nobody can say for sure whether every laptop is encrypted, patched and covered by endpoint protection.

What sets the quote

  • One Microsoft 365 tenant, sized from counts you read in the Microsoft Entra and Intune admin centers: users, admins, devices per platform, enterprise applications and guests.
  • Identity controls alone take 1–2 weeks for up to 500 users, 15 admins and 50 enterprise applications.
  • Identity and endpoints together take 2–3 weeks and add up to 500 Windows and macOS devices already enrolled in Intune.
  • More users or tenants, devices co-managed with Configuration Manager, or devices not yet in Intune are quoted after sizing.

What changes

  • Every sign-in passes Conditional Access, legacy authentication is blocked and admins sign in with phishing-resistant MFA.
  • Nobody holds standing admin rights. Roles are activated just in time through PIM, and tested break-glass accounts give you a way back in.
  • Only compliant, encrypted Windows and macOS devices reach company data, and each of them reports to Defender for Endpoint.
  • Apps reach company data only through consent rules you approve, and guests only through access settings you choose.

What you get

  • Conditional Access policies, run in report-only mode first and then enforced in stages
  • Phishing-resistant MFA for admins (passkeys, FIDO2 security keys or Windows Hello for Business), MFA for every user and legacy authentication blocked
  • PIM for admin roles with approvals and time limits, a least-privilege role model and two break-glass accounts with sign-in alerts
  • User consent settings, an admin consent workflow, guest access settings and a review of the permissions your apps already hold
  • Intune security baselines for Windows, macOS security settings and compliance policies for both, linked to Conditional Access
  • Defender for Endpoint onboarding, with attack surface reduction rules moved from audit to block
  • BitLocker and FileVault with escrowed recovery keys, Windows LAPS and Windows update rings
  • A settings workbook with the reason and rollback step for each policy, and a 90-minute handover with your admins

What we cover on each platform

AreaWindowsmacOS
Security settingsIntune security baselines for Windows, Defender for Endpoint and Microsoft Edge; Windows LAPS with passwords backed up to Entra IDIntune endpoint security and settings catalog profiles for the firewall, Gatekeeper and screen lock
ComplianceCompliance policies linked to Conditional AccessCompliance policies linked to Conditional Access
Disk encryptionBitLocker, recovery keys stored in Entra IDFileVault, recovery keys escrowed in Intune
Threat protectionDefender for Endpoint (or Defender for Business) onboarding; attack surface reduction rules, audit first, then blockDefender for Endpoint on Mac onboarding
UpdatesUpdate rings and feature update policiesSoftware update policies

Not included

  • First-time device enrolment in Intune (Windows Autopilot or Apple Automated Device Enrollment), quoted separately
  • iOS and Android devices, and app protection policies
  • Email filtering (Exchange Online Protection, Defender for Office 365) and Purview data protection
  • Watching and responding to Defender alerts; we do not offer 24/7 security monitoring
  • Microsoft licences. The design states which licence each control needs, such as Entra ID P2 for PIM.

What we need from you

  • Entra Global Reader for the review. For the rollout: time-limited admin roles such as Conditional Access Administrator, Authentication Policy Administrator, Privileged Role Administrator, Security Administrator and Intune Administrator, through PIM where you have it.
  • A named IT owner who approves each rollout stage, about 2 hours a week.
  • Pilot users with Windows and macOS devices from each main team.

How it works

  1. Free 30-minute call, then the counts that size the work and a written fixed quote.

  2. Review of the tenant, licences, sign-in logs and device state, then target policies, exclusions and rollout groups agreed with your team.

  3. Conditional Access in report-only mode and attack surface reduction rules in audit mode, then enforcement for a pilot group and in stages.

  4. Handover of the settings workbook, the break-glass procedure and PIM in a 90-minute session with your admins.

At a glance

Duration
1–3 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess

PKI review

A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.

Duration:1 week
Assess Popular

Domain and external attack surface check

A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.

Duration:1 week
Build

Identity modernisation

Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.

Duration:2–6 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.