Microsoft 365 Security Beyond Service — Tenant Security Configuration
Microsoft 365 Security Beyond Service is a 30-day service for organizations that already have a Microsoft 365 tenant and need IT Partner to configure core Microsoft 365 security features, validate key protections, and provide a project closeout report. The service covers Microsoft 365 tenant security configuration, identity and access protections, threat protection settings, Teams protection, Microsoft Sentinel initial configuration, and related security verification activities as listed in the scope.
What this engagement is
IT Partner will perform the necessary configurations in the customer’s Microsoft 365 tenant to set up a basic secured environment. The objective is to provide a plan and design a way to enable core Microsoft 365 security features, including the advanced activities listed in the scope. Gmail and Google Drive data migration is not listed in this service's responsibilities, implementation plan, or success criteria; any migration work is scoped separately. IT Partner will take time to understand the customer’s business needs and assess the best tools and solutions. Endpoint solutions should be tailored to the organization’s size, business model, and regulatory environment, and IT Partner can provide expertise and unbiased guidance on implementing endpoint detection and response in the customer’s security architecture.
Success criteria
What you receive
How the work unfolds
Start the engagement, confirm scope and contacts, and coordinate the work.
Review the security scope and assess the current tenant and security configuration, including the Microsoft Secure Score baseline.
Complete user creation or Microsoft Entra Connect configuration where required for the planned security controls.
Apply the agreed core and advanced security configuration to the tenant.
Verify the configured security settings against the agreed outcomes.
Verify Microsoft Secure Score progress toward the 75% target in the Microsoft Defender portal.
Send the final project summary with results and any remaining recommendations.
Verify results with the customer and fix in-scope issues, if any.
Prerequisites
Who does what
IT Partner
- Gather information about your current tenant and security configurations
- Perform core configuration of your Microsoft 365 tenant: Basic admin protections; Logging and analytics configuration; Basic identity protection setup
- Checking security score and configuring it up to 75%
- Enforcing Threat Protection, e.g. connecting Microsoft 365 to Microsoft Defender for Cloud Apps
- Configuring Microsoft Entra ID Protection
- Configuring Teams with three tiers of protection (including sharing, classification, data loss prevention, and Microsoft Purview Information Protection sensitivity labels)
- Microsoft Sentinel Initial configuration (e.g. basic M365 connectors)
- At least monthly check ups of dashboards and reports in the Microsoft Defender portal, Defender for Cloud Apps.
- Look for and implement software updates.
- Look for sharing risk by reviewing the built-in reports in Defender for Cloud Apps (on the Investigate tab).
- Configure Privileged Access Workstations (PAWs) for admin activity.
- Configure Entra ID Privileged Identity Management.
- Configure a security information and event management (SIEM) tool to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS. Microsoft 365 audit log retention is limited and depends on licensing; capturing the data in a SIEM allows longer retention.
- Enable and enforce MFA for all users.
- Implement a set of conditional access and related policies.
- Conduct attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training (included with Microsoft Defender for Office 365 Plan 2).
- Continue to regularly review dashboards and reports in the Microsoft Defender portal, Defender for Cloud Apps, and SIEM tools.
- Continue to look for and implement software updates.
- Integrate eDiscovery into your legal and threat response processes.
- Implement Secure Privileged Access (SPA) for identity components on premises (AD, AD FS).
- Use Defender for Cloud Apps to monitor for insider threats.
- Discover shadow IT SaaS usage by using Defender for Cloud Apps.
- Refine policies and operational processes.
- Use Microsoft Entra ID Protection to identify insider threats.
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Coordinate any outside vendor resources and schedules
- Perform changes to internal and external DNS, as required
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
- Assist with identification of high-risk users (admins, top executives and VIP users)
- End user support
What's not included
Limitations & technical notes
Frequently asked questions
What is Microsoft 365 Security Beyond Service?
Microsoft 365 Security Beyond Service is a 30-day engagement in which IT Partner configures core security features in an existing Microsoft 365 tenant. The service focuses on tenant security configuration, identity and access protections, threat protection settings, Teams protection, Microsoft Sentinel initial configuration, verification activities, and a project closeout report.
Who is this service designed for?
This service is designed for organizations that already have a Microsoft 365 tenant and want IT Partner to help establish a basic secured Microsoft 365 environment. It is best suited for customers that need core security controls configured and validated rather than a broad security advisory, training, or migration project.
What is included in the Microsoft 365 Security Beyond Service scope?
The service includes core Microsoft 365 tenant security configuration, basic admin protections, logging and analytics setup, basic identity protection, MFA enforcement, conditional access policies, Microsoft Entra ID Protection, threat protection enforcement, Teams protection, Microsoft Sentinel initial configuration, and security verification. It also includes selected advanced security activities listed in scope, such as Privileged Access Workstations, Entra ID Privileged Identity Management, Defender for Cloud Apps usage, attack simulations, eDiscovery integration, and a project closeout report.
What are the success criteria for this engagement?
The stated success criteria are Microsoft Secure Score improved toward the 75% target and confirmable in the Microsoft Defender portal, validated threat protection settings, validated identity and access management settings, Exchange Online Protection configured and working, and Teams protection configured.
How long does the service take?
Microsoft 365 Security Beyond Service is listed as a 30-day service. The exact activity sequence may vary depending on the customer’s needs, current tenant configuration, licensing, and availability of required client resources.
How much does Microsoft 365 Security Beyond Service cost?
The service is $6,000 per project, quoted fixed-price in writing before work begins. Additional licenses, add-on services, customer training, migration work, expanded documentation, or advisory services are not included unless separately agreed with IT Partner.
What prerequisites are required before starting?
The stated prerequisite is that the customer must already have a Microsoft 365 tenant. The customer should also be prepared to provide tenant access, a dedicated point of contact, resource coordination, and information about current security settings so IT Partner can assess and configure the environment.
Are Microsoft 365 licenses included in the service price?
No, additional licenses that may be required are not included in the service price. Because features such as Defender for Cloud Apps, Attack simulation training, Microsoft Entra ID Protection, Microsoft Sentinel, PIM, and advanced compliance capabilities may depend on licensing, the exact license requirements should be confirmed with IT Partner before implementation.
Is Gmail or Google Drive migration included in this service?
Gmail and Google Drive migration is not listed in IT Partner’s responsibilities, implementation plan, deliverables, or success criteria for this service. Customers who need Google Workspace migration should confirm it with IT Partner and scope it separately before purchasing.
Does the service include Microsoft Sentinel setup?
Yes, the service includes Microsoft Sentinel initial configuration, such as basic Microsoft 365 connectors. The scope also covers configuring a SIEM tool to collect logging data from Office 365, Defender for Cloud Apps, and other services including AD FS — Microsoft 365 audit log retention is limited and depends on licensing, so a SIEM allows longer retention. Whether Microsoft Sentinel or an existing SIEM is used is confirmed in the statement of work.
Are attack simulations included?
Yes, the service includes attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training, which is included with Microsoft Defender for Office 365 Plan 2. Licensing and availability should be verified for the customer tenant.
What documentation is provided at the end of the project?
The included documentation deliverable is a project closeout report showing final project status, acceptance criteria matching, outstanding issues if any, and final budget. More extensive documentation is listed as available for an additional fee, so customers should confirm any required runbooks, diagrams, policy documents, or operational guides before the engagement starts.