Discovery
Read-only first
No production change before the control register and approvers are agreed.
We assess identity, privileged access, email, applications, sharing, devices and recovery against an agreed baseline. Approved changes are staged, tested, documented and handed back with evidence your team can operate.
Do not send tenant IDs, credentials, exports or administrative data through the public contact form. Secure access is arranged after scope approval.
Discovery
Read-only first
No production change before the control register and approvers are agreed.
Controls
Licence-aware
Every recommendation names the Microsoft licence and dependency it needs.
Change
Staged enforcement
Report-only, pilot groups and agreed windows are used where the platform supports them.
Proof
Client-owned evidence
Before and after records, exceptions, verification notes and the remaining backlog stay with you.
Why tenants drift
A policy can look correct in isolation and still fail because the identity, application, recovery or collaboration path around it was never modelled. The engagement follows those paths end to end.
Daily accounts hold admin roles, emergency access is unclear, and nobody can explain which assignments are permanent, eligible or stale.
Policies overlap, exclusions have no owner, and enforcement was never tested against service accounts, legacy clients or recovery paths.
Service principals, app registrations and delegated permissions can retain access long after the project or owner that created them has gone.
Anonymous links, guest access, forwarding, sender authentication and collaboration settings often drift independently across the same tenant.
Control surface
The exact target is agreed against your licences, risk, operating model and chosen benchmark. Secure Score and automated assessment tools are inputs, not substitutes for engineering judgement or proof.
Authentication methods, legacy protocols, session controls and Conditional Access prerequisites are reviewed as one system.
Admin roles are reduced to named duties, with stronger authentication and activation controls where licensing supports them.
Mail protection starts with a complete sender inventory, then aligns Defender settings and domain authentication without breaking legitimate senders.
Enterprise apps and registrations are treated as privileged access paths, not as an inventory footnote.
SharePoint, OneDrive, Teams and guest access are aligned to the intended external boundary and data handling model.
Where devices are enrolled, access policy can use compliance and risk signals. Where they are not, the gap is recorded as readiness work.
Emergency access, audit settings and verification records are built into the hardening plan instead of being left for an incident.
Delivery options
A single tenant can move through one controlled remediation plan. A portfolio needs a common control profile, tenant-specific overlays, a representative pilot and governed rollout waves.
One production tenant
A bounded engagement for one Microsoft 365 tenant, from read-only posture baseline through approved remediation and evidence handover.
Commercial model
Scoped fixed fee after discovery
Scope and price are agreed in writing before production changes begin.
Delivery sequence
Evidence model
Need the smaller entry product first? The €149 90-minute workshop covers the method, checklist and templates. It is not implementation.
Portfolio or customer estate
A common control profile with a tenant-specific overlay, piloted first and then delivered in governed waves across the estate.
Commercial model
Programme setup plus per-tenant scope
Scope and price are agreed in writing before production changes begin.
Delivery sequence
Evidence model
Partner access is tenant-scoped. GDAP with least-privilege roles and a defined duration is preferred when that access model fits the programme.
Change control
The method is deliberately explicit. It separates what was observed from what was approved, changed, verified and accepted as an exception.
Collect read-only configuration, role, sign-in and policy evidence. No enforcement.
Set the target, identify licence dependencies, name the approver and record exceptions.
Use pilot groups, report-only state and test accounts where Microsoft provides those controls.
Apply approved changes in a defined window with a documented reversal path where supported.
Review policy state, sign-ins, test cases and expected user journeys after the change.
Deliver the evidence, exceptions, owner map, operating notes and remaining backlog.
The evidence pack
Each artefact has a clear job: explain the decision, identify the owner, prove the resulting state and keep the remaining risk visible.
Client-owned from handover
Evidence can land in your GitHub, SharePoint or agreed document repository. Access material is exchanged through a secure channel, never the public form.
Material risks, decisions, residual exposure and the next-quarter backlog.
00-executive-summary.mdControl, source, observed state, target, licence dependency, owner, status and evidence reference.
01-control-register.xlsxPolicy intent, users, resources, conditions, exclusions, mode, approver and test record.
02-conditional-access-matrix.mdAdministrative identities, role assignments, activation model and emergency access procedure.
03-privileged-access-map.mdApps, owners, permissions, credential dates, publisher signals and disposition.
04-app-consent-register.csvBefore state, approved action, change window, verification result and reversal note where supported.
05-change-and-verification-log.mdAccepted exceptions with owner and review date, plus deferred remediation and licence gaps.
06-exceptions-and-backlog.mdBoundaries
Clear boundaries keep hardening focused. Adjacent programmes remain visible and can be scoped separately instead of being hidden inside a vague statement of work.
Scoped separately
Hardening improves the control surface. It does not become the team responding to live alerts or an active compromise.
Scoped separately
Tenant controls can expose migration and governance work, but those programmes need their own discovery and change plan.
Scoped separately
Hybrid identity, endpoint fleets and recoverability extend beyond a tenant configuration engagement.
Authority and sources
Partner status is stated precisely. Control guidance is linked to Microsoft and CISA material. Assessment tools support the baseline, but they do not certify the tenant.
Microsoft relationship
Partner Location Account ID 7113951.
Delivery
Malta-based delivery with one accountable engineering lead.
Access
Read-only discovery and time-bound access are preferred wherever the engagement permits.
Ownership
Registers, exports, decisions and operating notes are delivered into a client-owned location.
Primary references
Source material used to shape the control and delivery model.
FAQ
The delivery model is built to reduce that risk: read-only discovery first, named emergency access exclusions, pilot users, report-only evaluation where Microsoft supports it, agreed change windows and post-change sign-in review. No method can promise zero disruption, so dependencies and reversal options are written into the control register before enforcement.
The assessment works with the tenant and licences you already have. The target state is licence-aware. Conditional Access typically needs Entra ID P1, while risk-based policies and PIM commonly need Entra ID P2 or Microsoft Entra ID Governance. Controls that are not licensed become explicit gaps, not surprise upsells.
No. Secure Score is a useful directional signal, not a guarantee that the tenant is secure. Success is measured against the agreed control register, verified policy state, tested access paths, resolved high-risk findings and documented exceptions.
No. This is an engineering and evidence engagement, not a certification audit, legal opinion or regulator attestation. We can map technical evidence to an agreed framework so your compliance, legal or audit team has a stronger record to review.
Not safely. A multi-tenant programme uses a shared control catalogue, then applies a tenant-specific overlay for licences, identity model, applications, external collaboration, regulated data and accepted exceptions. A representative pilot is completed before wider rollout.
The access model is agreed during discovery. Where partner access is suitable, GDAP is preferred over broad standing delegated access, with least-privilege roles and a defined duration. Client-issued access can also be used. Tenant identifiers, exports and credentials should never be submitted through the public contact form.
The 90-minute workshop is the smaller learning and baseline product. It explains the method and provides practical checklists and templates. This service is tenant-specific delivery: discovery, decisions, approved configuration work, verification and evidence handover.
The schedule depends on tenant count, licence coverage, policy complexity, change governance and the number of remediation waves. After read-only discovery you receive a written scope, delivery sequence and fixed commercial proposal before production changes begin.
The first conversation establishes tenant count, licence coverage, access model, current incidents and change governance. Production access is not needed for that call.