Skip to content
Single tenant or multi-tenantMicrosoft 365 security

Microsoft 365 tenant hardening you can verify.

We assess identity, privileged access, email, applications, sharing, devices and recovery against an agreed baseline. Approved changes are staged, tested, documented and handed back with evidence your team can operate.

Do not send tenant IDs, credentials, exports or administrative data through the public contact form. Secure access is arranged after scope approval.

Discovery

Read-only first

No production change before the control register and approvers are agreed.

Controls

Licence-aware

Every recommendation names the Microsoft licence and dependency it needs.

Change

Staged enforcement

Report-only, pilot groups and agreed windows are used where the platform supports them.

Proof

Client-owned evidence

Before and after records, exceptions, verification notes and the remaining backlog stay with you.

Why tenants drift

Most tenant risk is a chain, not a missing checkbox.

A policy can look correct in isolation and still fail because the identity, application, recovery or collaboration path around it was never modelled. The engagement follows those paths end to end.

Privileged access grew without an operating model

Daily accounts hold admin roles, emergency access is unclear, and nobody can explain which assignments are permanent, eligible or stale.

Role inventoryAdmin separationEmergency accessReview cadence

Conditional Access became a stack of exceptions

Policies overlap, exclusions have no owner, and enforcement was never tested against service accounts, legacy clients or recovery paths.

Policy mapExclusion ownerReport-onlySign-in validation

App consent quietly became a second identity plane

Service principals, app registrations and delegated permissions can retain access long after the project or owner that created them has gone.

Permission inventoryOwnerless appsConsent policyCredential expiry

Sharing and mail controls do not agree on the boundary

Anonymous links, guest access, forwarding, sender authentication and collaboration settings often drift independently across the same tenant.

External sharingGuest lifecycleForwardingSPF / DKIM / DMARC

Control surface

Seven planes, one evidence model.

The exact target is agreed against your licences, risk, operating model and chosen benchmark. Secure Score and automated assessment tools are inputs, not substitutes for engineering judgement or proof.

Identity and authentication

Authentication methods, legacy protocols, session controls and Conditional Access prerequisites are reviewed as one system.

  • Authentication method registration and coverage
  • Legacy authentication and protocol exposure
  • Conditional Access dependencies and exclusions
  • Session and sign-in controls for sensitive access

Privileged access

Admin roles are reduced to named duties, with stronger authentication and activation controls where licensing supports them.

  • Permanent, eligible and unused role assignments
  • Separate daily and administrative identities
  • Phishing-resistant authentication for administrators
  • PIM and access reviews where Entra licensing permits

Email and domains

Mail protection starts with a complete sender inventory, then aligns Defender settings and domain authentication without breaking legitimate senders.

  • SPF, DKIM and staged DMARC posture
  • Anti-phishing and impersonation protection
  • External forwarding and mailbox rule exposure
  • Preset security policies and exceptions

Apps and consent

Enterprise apps and registrations are treated as privileged access paths, not as an inventory footnote.

  • Service principals and app registrations
  • High-impact delegated and application permissions
  • Ownerless apps and expiring credentials
  • Consent policy, workflow and publisher signals

Collaboration and data

SharePoint, OneDrive, Teams and guest access are aligned to the intended external boundary and data handling model.

  • Anonymous links and default sharing levels
  • Guest lifecycle and external collaboration
  • Teams federation and external access
  • Sensitivity, retention and DLP readiness

Devices and access context

Where devices are enrolled, access policy can use compliance and risk signals. Where they are not, the gap is recorded as readiness work.

  • Intune enrolment and compliance coverage
  • BYOD and application protection boundaries
  • Device-based Conditional Access dependencies
  • Endpoint readiness and remediation backlog

Recovery, audit and visibility

Emergency access, audit settings and verification records are built into the hardening plan instead of being left for an incident.

  • Two cloud-only emergency access accounts
  • Alerting and scheduled recovery-path tests
  • Entra, Microsoft 365 and Purview audit coverage
  • Before and after evidence with named owners

Delivery options

One tenant and a tenant portfolio are different engagements.

A single tenant can move through one controlled remediation plan. A portfolio needs a common control profile, tenant-specific overlays, a representative pilot and governed rollout waves.

One production tenant

Single-Tenant Hardening

A bounded engagement for one Microsoft 365 tenant, from read-only posture baseline through approved remediation and evidence handover.

Commercial model

Scoped fixed fee after discovery

Scope and price are agreed in writing before production changes begin.

Delivery sequence

  1. Read-only control and licence baseline
  2. Risk-ranked remediation plan with approvers
  3. Staged implementation in agreed change windows
  4. Post-change verification and tenant evidence pack

Evidence model

  • One control register
  • One Conditional Access matrix
  • One exception register
  • One tenant handover pack

Need the smaller entry product first? The €149 90-minute workshop covers the method, checklist and templates. It is not implementation.

Scope one tenant
Portfolio model

Portfolio or customer estate

Multi-Tenant Hardening Programme

A common control profile with a tenant-specific overlay, piloted first and then delivered in governed waves across the estate.

Commercial model

Programme setup plus per-tenant scope

Scope and price are agreed in writing before production changes begin.

Delivery sequence

  1. Portfolio discovery and tenant segmentation
  2. Common baseline with local exceptions and licence map
  3. Pilot across one or two representative tenants
  4. Wave plan, per-tenant verification and portfolio reporting

Evidence model

  • Control catalogue and version history
  • Evidence pack for every tenant
  • Cross-tenant exception register
  • Portfolio risk and rollout summary

Partner access is tenant-scoped. GDAP with least-privilege roles and a defined duration is preferred when that access model fits the programme.

Design the programme

Change control

Every production change moves through a safety gate.

The method is deliberately explicit. It separates what was observed from what was approved, changed, verified and accepted as an exception.

  1. Observe

    Collect read-only configuration, role, sign-in and policy evidence. No enforcement.

    Read-only evidence
  2. Decide

    Set the target, identify licence dependencies, name the approver and record exceptions.

    Approved target
  3. Stage

    Use pilot groups, report-only state and test accounts where Microsoft provides those controls.

    Pilot and report-only
  4. Enforce

    Apply approved changes in a defined window with a documented reversal path where supported.

    Controlled window
  5. Verify

    Review policy state, sign-ins, test cases and expected user journeys after the change.

    State and access verified
  6. Hand over

    Deliver the evidence, exceptions, owner map, operating notes and remaining backlog.

    Client-owned record

The evidence pack

A handover your next engineer can inspect.

Each artefact has a clear job: explain the decision, identify the owner, prove the resulting state and keep the remaining risk visible.

Client-owned from handover

Evidence can land in your GitHub, SharePoint or agreed document repository. Access material is exchanged through a secure channel, never the public form.

Executive security brief

Material risks, decisions, residual exposure and the next-quarter backlog.

00-executive-summary.md

Control register

Control, source, observed state, target, licence dependency, owner, status and evidence reference.

01-control-register.xlsx

Conditional Access matrix

Policy intent, users, resources, conditions, exclusions, mode, approver and test record.

02-conditional-access-matrix.md

Privileged access map

Administrative identities, role assignments, activation model and emergency access procedure.

03-privileged-access-map.md

Application consent register

Apps, owners, permissions, credential dates, publisher signals and disposition.

04-app-consent-register.csv

Change and verification log

Before state, approved action, change window, verification result and reversal note where supported.

05-change-and-verification-log.md

Exceptions and backlog

Accepted exceptions with owner and review date, plus deferred remediation and licence gaps.

06-exceptions-and-backlog.md

Boundaries

What this engagement does not pretend to be.

Clear boundaries keep hardening focused. Adjacent programmes remain visible and can be scoped separately instead of being hidden inside a vague statement of work.

Scoped separately

Response and monitoring

Hardening improves the control surface. It does not become the team responding to live alerts or an active compromise.

  • Incident response for an active compromise
  • 24/7 SOC, MDR or continuous alert handling
Explore Defender XDR

Scoped separately

Migration and data programmes

Tenant controls can expose migration and governance work, but those programmes need their own discovery and change plan.

  • Mailbox, file or collaboration-suite migration
  • Full Purview information protection or DLP programme
  • Custom application code or deep application security review
Explore M365 migrations

Scoped separately

Infrastructure and resilience

Hybrid identity, endpoint fleets and recoverability extend beyond a tenant configuration engagement.

  • Broad on-premises, hybrid identity or endpoint remediation
  • Third-party Microsoft 365 backup implementation
Explore backup and recovery

Authority and sources

Claims tied to a relationship, a method or a primary source.

Partner status is stated precisely. Control guidance is linked to Microsoft and CISA material. Assessment tools support the baseline, but they do not certify the tenant.

Microsoft relationship

Authorized CSP Indirect Reseller

Partner Location Account ID 7113951.

Delivery

Named technical owner

Malta-based delivery with one accountable engineering lead.

Access

Least privilege first

Read-only discovery and time-bound access are preferred wherever the engagement permits.

Ownership

Evidence stays with you

Registers, exports, decisions and operating notes are delivered into a client-owned location.

FAQ

Questions that should be answered before access is granted.

Will the hardening work lock users or administrators out?

The delivery model is built to reduce that risk: read-only discovery first, named emergency access exclusions, pilot users, report-only evaluation where Microsoft supports it, agreed change windows and post-change sign-in review. No method can promise zero disruption, so dependencies and reversal options are written into the control register before enforcement.

Which Microsoft 365 licence do we need?

The assessment works with the tenant and licences you already have. The target state is licence-aware. Conditional Access typically needs Entra ID P1, while risk-based policies and PIM commonly need Entra ID P2 or Microsoft Entra ID Governance. Controls that are not licensed become explicit gaps, not surprise upsells.

Is Microsoft Secure Score the success target?

No. Secure Score is a useful directional signal, not a guarantee that the tenant is secure. Success is measured against the agreed control register, verified policy state, tested access paths, resolved high-risk findings and documented exceptions.

Does this certify our tenant against CIS, DORA, NIS2 or ISO 27001?

No. This is an engineering and evidence engagement, not a certification audit, legal opinion or regulator attestation. We can map technical evidence to an agreed framework so your compliance, legal or audit team has a stronger record to review.

Can the same baseline be copied to every tenant?

Not safely. A multi-tenant programme uses a shared control catalogue, then applies a tenant-specific overlay for licences, identity model, applications, external collaboration, regulated data and accepted exceptions. A representative pilot is completed before wider rollout.

How do you access multiple customer tenants?

The access model is agreed during discovery. Where partner access is suitable, GDAP is preferred over broad standing delegated access, with least-privilege roles and a defined duration. Client-issued access can also be used. Tenant identifiers, exports and credentials should never be submitted through the public contact form.

How is this different from the €149 Microsoft 365 hardening workshop?

The 90-minute workshop is the smaller learning and baseline product. It explains the method and provides practical checklists and templates. This service is tenant-specific delivery: discovery, decisions, approved configuration work, verification and evidence handover.

How long does the engagement take?

The schedule depends on tenant count, licence coverage, policy complexity, change governance and the number of remediation waves. After read-only discovery you receive a written scope, delivery sequence and fixed commercial proposal before production changes begin.

Harden one tenant, or establish a control plane across many.

The first conversation establishes tenant count, licence coverage, access model, current incidents and change governance. Production access is not needed for that call.