First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Securing your Microsoft 365 environment according to Microsoft Best Practice Recommendations
Security and Protection

Microsoft 365 Security Best Practices Setup — Tenant Protection & Secure Configuration

This service helps organizations configure tenant-wide Microsoft 365 security settings according to Microsoft Best Practice Recommendations, including MFA, admin account protection, Microsoft 365 Defender policies, device protection, Teams, SharePoint and OneDrive sharing settings, user training, and secure score recommendations. SKU: ITPWW070SECOT. Price: $8500. Duration: 30 days or more. Manager: Roman Sotnik.

Timeline 30 days or moreService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner configures core Microsoft 365 security capabilities to help protect your Microsoft 365 environment and sensitive data. The engagement focuses on tenant-wide security settings and related Microsoft 365 services, including multi-factor authentication, admin account protection, Microsoft 365 Defender policies, device protection, Teams collaboration, SharePoint and OneDrive sharing settings, user training, and secure score recommendations. The project is considered successful once core security features are enabled and the necessary tenant configurations are completed to set up the secure environment.

Success criteria

01MFA is enabled for all users.
02Microsoft 365 admin accounts reviewed and changes implemented to match best-practices recommendations
03Microsoft 365 Defender policies implemented
04Required devices connected to Entra ID and managed by Intune
05End-user training performed
06Microsoft Teams Implemented as company communication and collaboration system
07SharePoint Online and OneDrive sharing configuration adjusted

What you receive

Multi-Factor Authentication set up using the method selected based on security requirements: security defaults enabled and disabled, or conditional access and related policies implemented where Entra ID P1/P2 is available.
Admin accounts protected through separate user management account configuration, a dedicated admin workstation based on organizational roles and functions, a configured set of admin accounts to limit global admins and privileges, and built-in roles used where possible.
Preset security policies for Microsoft 365 Defender created and assigned to users based on the required email and collaboration content protection profile and level.
Microsoft Defender for Endpoint deployed, devices connected to Entra ID, and managed devices set up using basic Intune configuration.
Microsoft Teams implemented for collaboration and sharing, including Teams for collaboration, meetings, file and video sharing, and a communication site.
SharePoint and OneDrive sharing policies reviewed and adjusted.
User training performed for Office and Microsoft 365, including attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training included with Office 365 Threat Intelligence, and training for Office client applications and services such as Access, Excel, OneDrive, OneNote, Outlook, PowerPoint, Word, and Teams.
Possible secure score recommendations checked and completed.

How the work unfolds

Plan variability

The plan may vary depending on your needs.

Kickoff meeting

Kickoff meeting.

Scope check and current configuration assessment

Scope check and current configuration assessment.

Configure and/or implement required services

Configure and/or implement required services.

Secure score verification

Secure score verification.

Prerequisites

You must have a Microsoft 365 tenant with global admin role
You must have access to your email domain DNS zone
Plan for regular control and monitoring after implementation; 24/7 support, continuous monitoring, and ongoing maintenance are not included by default and are available as optional extra-cost add-ons.

Who does what

IT Partner

  • Set up Multi-Factor Authentication. Analyze and choose the best method of MFA based on your security requirements: Method 1: Enable and disable security defaults. Method 2: Implement a set of conditional access and related policies. (Entra ID P1/P2 required)
  • Protect your admin accounts. Create a separate account for user management and a dedicated admin workstation based on roles and functions in your organization. Configure a set of admin accounts to limit the number of global admins and limit their privileges. Set up built-in roles for assigning permissions where possible.
  • Use preset security policies for Microsoft 365 Defender. Determine the profile and the level of protection required for your email and collaboration content. Create and assign preset security policies to users.
  • Protect all devices. Deploy Microsoft Defender for Endpoint. Connect your devices to Entra ID. Set up managed devices using basic Intune configuration
  • Implement Microsoft Teams for collaboration and sharing. Create Teams for collaboration. Set up meetings. Share files and videos. Create a communication site
  • Set up sharing settings for SharePoint and OneDrive. Review and adjust your sharing policies
  • Train users on Office and Microsoft 365. Conduct attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training (included with Office 365 Threat Intelligence). Training for the Office client applications and services, such as Access, Excel, OneDrive, OneNote, Outlook, PowerPoint, Word, and Teams.
  • Check and complete possible secure score recommendations

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner.
  • Configure all network equipment, such as load balancers, routers, firewalls, and switches.
  • Perform changes to internal and external DNS, as required.
  • Review and approve engagement deliverables in a timely manner.

What's not included

Maintain your environment on an on-going basis.
24/7 support, continuous monitoring, and ongoing maintenance are not included by default. They are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement.
Additional licenses that may be required.

Limitations & technical notes

!Implementing a set of conditional access and related policies requires Entra ID P1/P2.

Frequently asked questions

What does the Microsoft 365 security best practices service include?

This service configures tenant-wide Microsoft 365 security settings according to Microsoft Best Practice Recommendations. It includes MFA, admin account protection, Microsoft 365 Defender preset security policies, Microsoft Defender for Endpoint deployment, Entra ID device connection, basic Intune-managed device configuration, Teams collaboration setup, SharePoint and OneDrive sharing policy adjustments, user training, and secure score recommendation checks.

What is the main outcome of this Microsoft 365 security engagement?

The main outcome is a more secure Microsoft 365 tenant with core security features enabled and required tenant configurations completed. The engagement is considered successful when items such as MFA for all users, protected admin accounts, Defender policies, device protection, Teams implementation, SharePoint and OneDrive sharing adjustments, user training, and secure score verification are completed within the agreed scope.

How much does this Microsoft 365 security service cost?

The listed price for this service is $8,500. This price covers the defined engagement scope for SKU ITPWW070SECOT, but additional Microsoft licenses that may be required are not included.

How long does the Microsoft 365 security best practices implementation take?

The stated duration is 30 days or more. The exact timeline may vary because the implementation plan depends on the customer’s needs, current Microsoft 365 configuration, licensing, device readiness, and how quickly client-side approvals and DNS or network changes are completed.

What happens during the engagement?

The engagement typically starts with a kickoff meeting, followed by a scope check and current configuration assessment. IT Partner then configures or implements the required Microsoft 365 security services and performs secure score verification, with the plan adjusted as needed based on the organization’s environment.

What prerequisites are required before starting this service?

You need an existing Microsoft 365 tenant with access to a global admin role. You also need access to your email domain DNS zone, and the organization should be prepared to maintain regular control and monitoring after implementation. 24/7 support, continuous monitoring, and ongoing maintenance are not included by default and are available as optional paid add-ons.

Does this service enable MFA for all Microsoft 365 users?

Yes, enabling MFA for all users is one of the success criteria for this engagement. IT Partner selects the MFA approach based on security requirements, either by using security defaults or by implementing conditional access and related policies where the required Entra ID P1 or P2 licensing is available.

Does conditional access configuration come with this service?

Conditional access and related policies can be implemented as part of the MFA approach when Entra ID P1 or P2 is available. If the tenant does not have Entra ID P1 or P2, IT Partner will need to use an approach consistent with the available licensing, such as security defaults, because conditional access requires the appropriate Entra ID licensing.

How are Microsoft 365 administrator accounts protected in this service?

IT Partner reviews and configures admin account protection based on Microsoft best-practice recommendations. This includes creating a separate account for user management, configuring admin accounts to limit global admins and excessive privileges, using built-in roles where possible, and setting up a dedicated admin workstation based on organizational roles and functions.

Does the service include Microsoft 365 Defender policy configuration?

Yes, the service includes creating and assigning Microsoft 365 Defender preset security policies. IT Partner determines the required protection profile and level for email and collaboration content, then assigns the policies to users according to the agreed security requirements.

Does this service protect endpoints and user devices?

The service includes device protection activities within the stated scope, including deploying Microsoft Defender for Endpoint, connecting required devices to Entra ID, and setting up managed devices using basic Intune configuration. It does not state that every possible advanced endpoint management scenario is included, so complex device requirements should be confirmed with IT Partner before the engagement.

Is Microsoft Teams included in the implementation?

Yes, Microsoft Teams implementation is included as part of the collaboration and sharing scope. IT Partner can create Teams for collaboration, set up meetings, enable file and video sharing, and create a communication site according to the service scope.

Will SharePoint Online and OneDrive external sharing be reviewed?

Yes, SharePoint Online and OneDrive sharing policies are reviewed and adjusted during the engagement. This helps align collaboration and file-sharing settings with the organization’s Microsoft 365 security requirements.

Does the service include user security training?

Yes, user training is included for Office and Microsoft 365. The service can include attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training included with Office 365 Threat Intelligence, as well as training for Office apps and services such as Outlook, OneDrive, Excel, Word, PowerPoint, OneNote, Access, and Teams.

Will this service improve our Microsoft Secure Score?

The service includes checking and completing possible secure score recommendations. It does not guarantee a specific Secure Score number, because the final score depends on tenant licensing, accepted recommendations, organizational requirements, and any recommendations outside the engagement scope.

What is not included in this Microsoft 365 security service?

Ongoing maintenance of the Microsoft 365 environment is not included by default. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement. Additional licenses that may be required are also not included, so licensing needs such as Entra ID P1/P2, Microsoft Defender for Endpoint, Intune, or other security features should be confirmed against the tenant’s current subscriptions.

What responsibilities does IT Partner handle during the engagement?

IT Partner handles the in-scope configuration work, including MFA setup, admin account protection, Microsoft 365 Defender preset policies, device protection setup, Teams implementation, SharePoint and OneDrive sharing adjustments, user training, and secure score recommendation checks. These activities are performed according to the agreed service scope and the customer’s available licensing.

What responsibilities does the client have during the engagement?

The client coordinates internal resources and staff schedules, provides a dedicated point of contact, configures network equipment such as load balancers, routers, firewalls, and switches, and performs required internal or external DNS changes. The client is also responsible for reviewing and approving engagement deliverables in a timely manner.

Will this service cause downtime or business disruption?

The service description does not specify planned downtime. Some configuration changes, such as MFA enforcement, sharing policy changes, device enrollment, or security policy assignments, may affect user sign-in or workflows, so the exact business impact should be reviewed with IT Partner during the kickoff and configuration planning.

What happens after the Microsoft 365 security configuration is completed?

After completion, the organization receives the configured in-scope Microsoft 365 security settings and should continue regular control and monitoring. Ongoing maintenance, continuous monitoring, and 24/7 support are not included by default. They can be arranged as optional paid add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement; otherwise, post-project operational monitoring, policy tuning, or future changes would need to be handled by the client or arranged separately with IT Partner.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$8500
30 days or more
Book a meeting