When you need it
Your Microsoft 365 tenant grew with the company. Some users still sign in without MFA, legacy protocols are still open and several people are permanent Global Administrators. Nobody can say for sure whether every laptop is encrypted, patched and covered by endpoint protection.
What sets the quote
- One Microsoft 365 tenant, sized from counts you read in the Microsoft Entra and Intune admin centers: users, admins, devices per platform, enterprise applications and guests.
- Identity controls alone take 1–2 weeks for up to 500 users, 15 admins and 50 enterprise applications.
- Identity and endpoints together take 2–3 weeks and add up to 500 Windows and macOS devices already enrolled in Intune.
- More users or tenants, devices co-managed with Configuration Manager, or devices not yet in Intune are quoted after sizing.
What changes
- Every sign-in passes Conditional Access, legacy authentication is blocked and admins sign in with phishing-resistant MFA.
- Nobody holds standing admin rights. Roles are activated just in time through PIM, and tested break-glass accounts give you a way back in.
- Only compliant, encrypted Windows and macOS devices reach company data, and each of them reports to Defender for Endpoint.
- Apps reach company data only through consent rules you approve, and guests only through access settings you choose.
What you get
- Conditional Access policies, run in report-only mode first and then enforced in stages
- Phishing-resistant MFA for admins (passkeys, FIDO2 security keys or Windows Hello for Business), MFA for every user and legacy authentication blocked
- PIM for admin roles with approvals and time limits, a least-privilege role model and two break-glass accounts with sign-in alerts
- User consent settings, an admin consent workflow, guest access settings and a review of the permissions your apps already hold
- Intune security baselines for Windows, macOS security settings and compliance policies for both, linked to Conditional Access
- Defender for Endpoint onboarding, with attack surface reduction rules moved from audit to block
- BitLocker and FileVault with escrowed recovery keys, Windows LAPS and Windows update rings
- A settings workbook with the reason and rollback step for each policy, and a 90-minute handover with your admins
What we cover on each platform
| Area | Windows | macOS |
|---|---|---|
| Security settings | Intune security baselines for Windows, Defender for Endpoint and Microsoft Edge; Windows LAPS with passwords backed up to Entra ID | Intune endpoint security and settings catalog profiles for the firewall, Gatekeeper and screen lock |
| Compliance | Compliance policies linked to Conditional Access | Compliance policies linked to Conditional Access |
| Disk encryption | BitLocker, recovery keys stored in Entra ID | FileVault, recovery keys escrowed in Intune |
| Threat protection | Defender for Endpoint (or Defender for Business) onboarding; attack surface reduction rules, audit first, then block | Defender for Endpoint on Mac onboarding |
| Updates | Update rings and feature update policies | Software update policies |
Not included
- First-time device enrolment in Intune (Windows Autopilot or Apple Automated Device Enrollment), quoted separately
- iOS and Android devices, and app protection policies
- Email filtering (Exchange Online Protection, Defender for Office 365) and Purview data protection
- Watching and responding to Defender alerts; we do not offer 24/7 security monitoring
- Microsoft licences. The design states which licence each control needs, such as Entra ID P2 for PIM.
What we need from you
- Entra Global Reader for the review. For the rollout: time-limited admin roles such as Conditional Access Administrator, Authentication Policy Administrator, Privileged Role Administrator, Security Administrator and Intune Administrator, through PIM where you have it.
- A named IT owner who approves each rollout stage, about 2 hours a week.
- Pilot users with Windows and macOS devices from each main team.
How it works
Free 30-minute call, then the counts that size the work and a written fixed quote.
Review of the tenant, licences, sign-in logs and device state, then target policies, exclusions and rollout groups agreed with your team.
Conditional Access in report-only mode and attack surface reduction rules in audit mode, then enforcement for a pilot group and in stages.
Handover of the settings workbook, the break-glass procedure and PIM in a 90-minute session with your admins.
At a glance
- Duration
- 1–3 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
PKI review
A one-week review of your PKI and certificates, covering the CA hierarchy, certificate inventory, TLS settings and revocation, rated red, amber or green, with an expiry risk list and a roadmap.
Domain and external attack surface check
A one-week, non-intrusive check of your domains, DNS, email authentication and internet-facing endpoints, with every finding tied to evidence and a fix. It is not a penetration test.
Identity modernisation
Business applications moved from passwords and legacy federation to Entra ID single sign-on, with hybrid sync, tenant and domain moves, and one corporate sign-in for AWS and Google Cloud where you need it.