Microsoft 365 Security Best Practices Setup — Tenant Protection & Secure Configuration
This service helps organizations configure tenant-wide Microsoft 365 security settings according to Microsoft Best Practice Recommendations, including MFA, admin account protection, Microsoft Defender XDR policies, device protection, Teams, SharePoint and OneDrive sharing settings, user training, and secure score recommendations.
What this engagement is
IT Partner configures core Microsoft 365 security capabilities to help protect your Microsoft 365 environment and sensitive data. The engagement focuses on tenant-wide security settings and related Microsoft 365 services, including multi-factor authentication, admin account protection, Microsoft Defender XDR (formerly Microsoft 365 Defender) policies, device protection, Teams collaboration, SharePoint and OneDrive sharing settings, user training, and secure score recommendations. The project is considered successful once core security features are enabled and the necessary tenant configurations are completed to set up the secure environment.
Success criteria
What you receive
How the work unfolds
Confirm project contacts, tenant access, licensing, the in-scope security areas, and the delivery schedule.
Review the current tenant configuration against Microsoft best-practice recommendations and confirm which settings need changes.
Implement the agreed security configuration: MFA, admin account protection, Defender preset policies, device protection, Teams, and SharePoint and OneDrive sharing settings.
Check Microsoft Secure Score recommendations, complete the applicable ones, and review the final configuration with your team.
Prerequisites
Who does what
IT Partner
- Set up Multi-Factor Authentication. Analyze and choose the best method of MFA based on your security requirements: Method 1: Enable and disable security defaults. Method 2: Implement a set of conditional access and related policies. (Entra ID P1/P2 required)
- Protect your admin accounts. Create a separate account for user management and a dedicated admin workstation based on roles and functions in your organization. Configure a set of admin accounts to limit the number of global admins and limit their privileges. Set up built-in roles for assigning permissions where possible.
- Use preset security policies for Microsoft Defender XDR. Determine the profile and the level of protection required for your email and collaboration content. Create and assign preset security policies to users.
- Protect all devices. Deploy Microsoft Defender for Endpoint. Connect your devices to Entra ID. Set up managed devices using basic Intune configuration
- Implement Microsoft Teams for collaboration and sharing. Create Teams for collaboration. Set up meetings. Share files and videos. Create a communication site
- Set up sharing settings for SharePoint and OneDrive. Review and adjust your sharing policies
- Train users on Office and Microsoft 365. Conduct attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training (included with Microsoft Defender for Office 365 Plan 2, formerly Office 365 Threat Intelligence). Training for the Office client applications and services, such as Access, Excel, OneDrive, OneNote, Outlook, PowerPoint, Word, and Teams.
- Check and complete possible secure score recommendations
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner.
- Configure all network equipment, such as load balancers, routers, firewalls, and switches.
- Perform changes to internal and external DNS, as required.
- Review and approve engagement deliverables in a timely manner.
What's not included
Limitations & technical notes
Frequently asked questions
What does the Microsoft 365 security best practices service include?
This service configures tenant-wide Microsoft 365 security settings according to Microsoft Best Practice Recommendations. It includes MFA, admin account protection, Microsoft Defender XDR (formerly Microsoft 365 Defender) preset security policies, Microsoft Defender for Endpoint deployment, Entra ID device connection, basic Intune-managed device configuration, Teams collaboration setup, SharePoint and OneDrive sharing policy adjustments, user training, and secure score recommendation checks.
What is the main outcome of this Microsoft 365 security engagement?
The main outcome is a more secure Microsoft 365 tenant with core security features enabled and required tenant configurations completed. The engagement is considered successful when items such as MFA for all users, protected admin accounts, Defender policies, device protection, Teams implementation, SharePoint and OneDrive sharing adjustments, user training, and secure score verification are completed within the agreed scope.
How long does the Microsoft 365 security best practices implementation take?
The stated duration is 30 days or more. The exact timeline may vary because the implementation plan depends on the customer’s needs, current Microsoft 365 configuration, licensing, device readiness, and how quickly client-side approvals and DNS or network changes are completed.
How much does the Microsoft 365 security best practices service cost?
The service is $8,500 per project, quoted fixed-price in writing before work begins. Additional licenses that may be required — such as Microsoft Entra ID P1/P2, Intune, or Defender plans — are not included.
What prerequisites are required before starting this service?
You need an existing Microsoft 365 tenant with access to a global admin role. You also need access to your email domain DNS zone, and the organization should be prepared to maintain regular control and monitoring after implementation. 24/7 support, continuous monitoring, and ongoing maintenance are not included by default and are available as optional paid add-ons.
Does this service enable MFA for all Microsoft 365 users?
Yes, enabling MFA for all users is one of the success criteria for this engagement. IT Partner selects the MFA approach based on security requirements, either by using security defaults or by implementing conditional access and related policies where the required Entra ID P1 or P2 licensing is available.
Does conditional access configuration come with this service?
Conditional access and related policies can be implemented as part of the MFA approach when Entra ID P1 or P2 is available. If the tenant does not have Entra ID P1 or P2, IT Partner will need to use an approach consistent with the available licensing, such as security defaults, because conditional access requires the appropriate Entra ID licensing.
How are Microsoft 365 administrator accounts protected in this service?
IT Partner reviews and configures admin account protection based on Microsoft best-practice recommendations. This includes creating a separate account for user management, configuring admin accounts to limit global admins and excessive privileges, using built-in roles where possible, and setting up a dedicated admin workstation based on organizational roles and functions.
Does the service include Microsoft 365 Defender policy configuration?
Yes — the service creates and assigns preset security policies for Microsoft Defender XDR (formerly Microsoft 365 Defender). IT Partner determines the required protection profile and level for email and collaboration content, then assigns the policies to users according to the agreed security requirements.
Does the service include user security training?
Yes, user training is included for Office and Microsoft 365. The service can include attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training included with Microsoft Defender for Office 365 Plan 2 (formerly Office 365 Threat Intelligence), as well as training for Office apps and services such as Outlook, OneDrive, Excel, Word, PowerPoint, OneNote, Access, and Teams.
Will this service improve our Microsoft Secure Score?
The service includes checking and completing possible secure score recommendations. It does not guarantee a specific Secure Score number, because the final score depends on tenant licensing, accepted recommendations, organizational requirements, and any recommendations outside the engagement scope.
What is not included in this Microsoft 365 security service?
Ongoing maintenance of the Microsoft 365 environment is not included by default. 24/7 support, continuous monitoring, and ongoing maintenance are available as optional extra-cost add-ons delivered through IT Partner's NOC, third-party support partnerships, and Microsoft support escalation channels. Additional licenses that may be required are also not included, so licensing needs such as Entra ID P1/P2, Microsoft Defender for Endpoint, Intune, or other security features should be confirmed against the tenant’s current subscriptions.