Microsoft 365 Security Best Practices Setup — Tenant Protection & Secure Configuration
This service helps organizations configure tenant-wide Microsoft 365 security settings according to Microsoft Best Practice Recommendations, including MFA, admin account protection, Microsoft 365 Defender policies, device protection, Teams, SharePoint and OneDrive sharing settings, user training, and secure score recommendations. SKU: ITPWW070SECOT. Price: $8500. Duration: 30 days or more. Manager: Roman Sotnik.
What this engagement is
IT Partner configures core Microsoft 365 security capabilities to help protect your Microsoft 365 environment and sensitive data. The engagement focuses on tenant-wide security settings and related Microsoft 365 services, including multi-factor authentication, admin account protection, Microsoft 365 Defender policies, device protection, Teams collaboration, SharePoint and OneDrive sharing settings, user training, and secure score recommendations. The project is considered successful once core security features are enabled and the necessary tenant configurations are completed to set up the secure environment.
Success criteria
What you receive
How the work unfolds
The plan may vary depending on your needs.
Kickoff meeting.
Scope check and current configuration assessment.
Configure and/or implement required services.
Secure score verification.
Prerequisites
Who does what
IT Partner
- Set up Multi-Factor Authentication. Analyze and choose the best method of MFA based on your security requirements: Method 1: Enable and disable security defaults. Method 2: Implement a set of conditional access and related policies. (Entra ID P1/P2 required)
- Protect your admin accounts. Create a separate account for user management and a dedicated admin workstation based on roles and functions in your organization. Configure a set of admin accounts to limit the number of global admins and limit their privileges. Set up built-in roles for assigning permissions where possible.
- Use preset security policies for Microsoft 365 Defender. Determine the profile and the level of protection required for your email and collaboration content. Create and assign preset security policies to users.
- Protect all devices. Deploy Microsoft Defender for Endpoint. Connect your devices to Entra ID. Set up managed devices using basic Intune configuration
- Implement Microsoft Teams for collaboration and sharing. Create Teams for collaboration. Set up meetings. Share files and videos. Create a communication site
- Set up sharing settings for SharePoint and OneDrive. Review and adjust your sharing policies
- Train users on Office and Microsoft 365. Conduct attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training (included with Office 365 Threat Intelligence). Training for the Office client applications and services, such as Access, Excel, OneDrive, OneNote, Outlook, PowerPoint, Word, and Teams.
- Check and complete possible secure score recommendations
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner.
- Configure all network equipment, such as load balancers, routers, firewalls, and switches.
- Perform changes to internal and external DNS, as required.
- Review and approve engagement deliverables in a timely manner.
What's not included
Limitations & technical notes
Frequently asked questions
What does the Microsoft 365 security best practices service include?
This service configures tenant-wide Microsoft 365 security settings according to Microsoft Best Practice Recommendations. It includes MFA, admin account protection, Microsoft 365 Defender preset security policies, Microsoft Defender for Endpoint deployment, Entra ID device connection, basic Intune-managed device configuration, Teams collaboration setup, SharePoint and OneDrive sharing policy adjustments, user training, and secure score recommendation checks.
What is the main outcome of this Microsoft 365 security engagement?
The main outcome is a more secure Microsoft 365 tenant with core security features enabled and required tenant configurations completed. The engagement is considered successful when items such as MFA for all users, protected admin accounts, Defender policies, device protection, Teams implementation, SharePoint and OneDrive sharing adjustments, user training, and secure score verification are completed within the agreed scope.
How much does this Microsoft 365 security service cost?
The listed price for this service is $8,500. This price covers the defined engagement scope for SKU ITPWW070SECOT, but additional Microsoft licenses that may be required are not included.
How long does the Microsoft 365 security best practices implementation take?
The stated duration is 30 days or more. The exact timeline may vary because the implementation plan depends on the customer’s needs, current Microsoft 365 configuration, licensing, device readiness, and how quickly client-side approvals and DNS or network changes are completed.
What happens during the engagement?
The engagement typically starts with a kickoff meeting, followed by a scope check and current configuration assessment. IT Partner then configures or implements the required Microsoft 365 security services and performs secure score verification, with the plan adjusted as needed based on the organization’s environment.
What prerequisites are required before starting this service?
You need an existing Microsoft 365 tenant with access to a global admin role. You also need access to your email domain DNS zone, and the organization should be prepared to maintain regular control and monitoring after implementation. 24/7 support, continuous monitoring, and ongoing maintenance are not included by default and are available as optional paid add-ons.
Does this service enable MFA for all Microsoft 365 users?
Yes, enabling MFA for all users is one of the success criteria for this engagement. IT Partner selects the MFA approach based on security requirements, either by using security defaults or by implementing conditional access and related policies where the required Entra ID P1 or P2 licensing is available.
Does conditional access configuration come with this service?
Conditional access and related policies can be implemented as part of the MFA approach when Entra ID P1 or P2 is available. If the tenant does not have Entra ID P1 or P2, IT Partner will need to use an approach consistent with the available licensing, such as security defaults, because conditional access requires the appropriate Entra ID licensing.
How are Microsoft 365 administrator accounts protected in this service?
IT Partner reviews and configures admin account protection based on Microsoft best-practice recommendations. This includes creating a separate account for user management, configuring admin accounts to limit global admins and excessive privileges, using built-in roles where possible, and setting up a dedicated admin workstation based on organizational roles and functions.
Does the service include Microsoft 365 Defender policy configuration?
Yes, the service includes creating and assigning Microsoft 365 Defender preset security policies. IT Partner determines the required protection profile and level for email and collaboration content, then assigns the policies to users according to the agreed security requirements.
Does this service protect endpoints and user devices?
The service includes device protection activities within the stated scope, including deploying Microsoft Defender for Endpoint, connecting required devices to Entra ID, and setting up managed devices using basic Intune configuration. It does not state that every possible advanced endpoint management scenario is included, so complex device requirements should be confirmed with IT Partner before the engagement.
Is Microsoft Teams included in the implementation?
Yes, Microsoft Teams implementation is included as part of the collaboration and sharing scope. IT Partner can create Teams for collaboration, set up meetings, enable file and video sharing, and create a communication site according to the service scope.
Will SharePoint Online and OneDrive external sharing be reviewed?
Yes, SharePoint Online and OneDrive sharing policies are reviewed and adjusted during the engagement. This helps align collaboration and file-sharing settings with the organization’s Microsoft 365 security requirements.
Does the service include user security training?
Yes, user training is included for Office and Microsoft 365. The service can include attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training included with Office 365 Threat Intelligence, as well as training for Office apps and services such as Outlook, OneDrive, Excel, Word, PowerPoint, OneNote, Access, and Teams.
Will this service improve our Microsoft Secure Score?
The service includes checking and completing possible secure score recommendations. It does not guarantee a specific Secure Score number, because the final score depends on tenant licensing, accepted recommendations, organizational requirements, and any recommendations outside the engagement scope.
What is not included in this Microsoft 365 security service?
Ongoing maintenance of the Microsoft 365 environment is not included by default. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement. Additional licenses that may be required are also not included, so licensing needs such as Entra ID P1/P2, Microsoft Defender for Endpoint, Intune, or other security features should be confirmed against the tenant’s current subscriptions.
What responsibilities does IT Partner handle during the engagement?
IT Partner handles the in-scope configuration work, including MFA setup, admin account protection, Microsoft 365 Defender preset policies, device protection setup, Teams implementation, SharePoint and OneDrive sharing adjustments, user training, and secure score recommendation checks. These activities are performed according to the agreed service scope and the customer’s available licensing.
What responsibilities does the client have during the engagement?
The client coordinates internal resources and staff schedules, provides a dedicated point of contact, configures network equipment such as load balancers, routers, firewalls, and switches, and performs required internal or external DNS changes. The client is also responsible for reviewing and approving engagement deliverables in a timely manner.
Will this service cause downtime or business disruption?
The service description does not specify planned downtime. Some configuration changes, such as MFA enforcement, sharing policy changes, device enrollment, or security policy assignments, may affect user sign-in or workflows, so the exact business impact should be reviewed with IT Partner during the kickoff and configuration planning.
What happens after the Microsoft 365 security configuration is completed?
After completion, the organization receives the configured in-scope Microsoft 365 security settings and should continue regular control and monitoring. Ongoing maintenance, continuous monitoring, and 24/7 support are not included by default. They can be arranged as optional paid add-ons delivered through IT Partner's NOC, third-party support partnerships, and a Microsoft Premier Support agreement; otherwise, post-project operational monitoring, policy tuning, or future changes would need to be handled by the client or arranged separately with IT Partner.