First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Security Beyond Service
Security and Protection

Microsoft 365 Security Beyond Service — Tenant Security Configuration

Microsoft 365 Security Beyond Service is a 30-day service for organizations that already have a Microsoft 365 tenant and need IT Partner to configure core Microsoft 365 security features, validate key protections, and provide a project closeout report. The service covers Microsoft 365 tenant security configuration, identity and access protections, threat protection settings, Teams protection, Microsoft Sentinel initial configuration, and related security verification activities as listed in the scope.

Timeline 30 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner will perform the necessary configurations in the customer’s Microsoft 365 tenant to set up a basic secured environment. The objective is to provide a plan and design a way to enable core Microsoft 365 security features. The source also states that the project will be considered successful when all user data is fully migrated from Gmail and Google Drive to the Microsoft 365 tenant; this requires clarification because Gmail and Google Drive migration tasks are not listed in the IT Partner responsibilities, implementation plan, or success criteria. IT Partner will take time to understand the customer’s business needs and assess the best tools and solutions. The source also notes that endpoint solutions should be tailored to the organization’s size, business model, and regulatory environment, and that IT Partner can provide expertise and unbiased guidance on implementing endpoint detection and response in the customer’s security architecture.

Success criteria

01Security score 75%. User can access Security Portal and confirm this.
02Validated Threat protection settings
03Validated Identity and access management settings
04Exchange Online Protection is configured and working
05Teams protection is configured

What you receive

Core configuration of the Microsoft 365 tenant, including basic admin protections, logging and analytics configuration, and basic identity protection setup.
Security score checked and configured up to 75%.
Threat Protection enforced, e.g. connecting M365 to MS Defender for Cloud Apps.
Azure Active Directory Identity Protection configured.
Teams configured with three tiers of protection, including sharing, classification, data loss prevention, and Azure Information Protection.
Microsoft Sentinel initial configuration, e.g. basic M365 connectors.
Privileged Access Workstations (PAWs) configured for admin activity.
Entra ID Privileged Identity Management configured.
Security information and event management (SIEM) tool configured to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS.
MFA enabled and enforced for all users.
A set of conditional access and related policies implemented.
Attack simulations conducted for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training, included with Office 365 Threat Intelligence.
eDiscovery integrated into legal and threat response processes.
Secure Privileged Access (SPA) implemented for identity components on premises, including AD and AD FS.
Defender for Cloud Apps used to monitor for insider threats.
Shadow IT SaaS usage discovered by using Defender for Cloud Apps.
Policies and operational processes refined.
Project closeout report indicating final project status, acceptance criteria matching, outstanding issues if any, and final budget.

How the work unfolds

Kickoff meeting

Kickoff meeting.

Security scope check and current configuration assessment

Security scope check and current configuration assessment.

User creation or AD connect tool configuration

User creation or AD connect tool configuration.

Security configuration start

Security configuration start.

Security settings verification

Security settings verification.

Security score verification

Security score verification.

Final email

Final email.

Verification and fixing of issues, if any

Verification and fixing of issues, if any.

Prerequisites

You must have a Microsoft 365 tenant

Who does what

IT Partner

  • Gather information about your current tenant and security configurations
  • Perform core configuration of your Microsoft 365 tenant: Basic admin protections; Logging and analytics configuration; Basic identity protection setup
  • Checking security score and configuring it up to 75%
  • Enforcing Threat Protection, e.g. connecting M365 to MS Defender for Cloud Apps
  • Configuring Azure Active Directory Identity Protection
  • Configuring Teams with three tiers of protection (including sharing, classification, data loss prevention, and Azure Information Protection)
  • Microsoft Sentinel Initial configuration (e.g. basic M365 connectors)
  • At least monthly check ups of dashboards and reports in the Microsoft 365 Defender portal, Defender for Cloud Apps.
  • Look for and implement software updates.
  • Look for sharing risk by reviewing the built-in reports in Defender for Cloud Apps (on the Investigate tab).
  • Configure Privileged Access Workstations (PAWs) for admin activity.
  • Configure Entra ID Privileged Identity Management.
  • Configure a security information and event management (SIEM) tool to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS. The audit log stores data for only 90 days. Capturing this data in SIEM tool allows you to store data for a longer period.
  • Enable and enforce MFA for all users.
  • Implement a set of conditional access and related policies.
  • Conduct attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training (included with Office 365 Threat Intelligence.
  • Look for sharing risk by reviewing the built-in reports in Defender for Cloud Apps (on the Investigate tab).
  • Continue to regularly review dashboards and reports in the Microsoft 365 Defender portal, Defender for Cloud Apps, and SIEM tools.
  • Continue to look for and implement software updates.
  • Integrate eDiscovery into your legal and threat response processes.
  • Implement Secure Privileged Access (SPA) for identity components on premises (AD, AD FS).
  • Use Defender for Cloud Apps to monitor for insider threats.
  • Discover shadow IT SaaS usage by using Defender for Cloud Apps.
  • Refine policies and operational processes.
  • Use Entra ID Identity Protection to identify insider threats.

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Coordinate any outside vendor resources and schedules
  • Perform changes to internal and external DNS, as required
  • Configure all network equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner
  • Assist with identification of high-risk users (admins, top executives and VIP users)
  • End user support

What's not included

Additional licenses that may be required
Customer team training (could be added as an additional service)
Corporate documents migration to SharePoint Online (could be added as an additional service)
Desktop software settings
Information Security Advisory services (could be added as an additional service)
More extensive documentation beyond the project closeout report can be provided for an additional fee.

Limitations & technical notes

!The plan may vary depending on your needs.
!The audit log stores data for only 90 days. Capturing this data in SIEM tool allows you to store data for a longer period.

Frequently asked questions

What is Microsoft 365 Security Beyond Service?

Microsoft 365 Security Beyond Service is a 30-day engagement in which IT Partner configures core security features in an existing Microsoft 365 tenant. The service focuses on tenant security configuration, identity and access protections, threat protection settings, Teams protection, Microsoft Sentinel initial configuration, verification activities, and a project closeout report.

Who is this service designed for?

This service is designed for organizations that already have a Microsoft 365 tenant and want IT Partner to help establish a basic secured Microsoft 365 environment. It is best suited for customers that need core security controls configured and validated rather than a broad security advisory, training, or migration project.

What is included in the Microsoft 365 Security Beyond Service scope?

The service includes core Microsoft 365 tenant security configuration, basic admin protections, logging and analytics setup, basic identity protection, MFA enforcement, conditional access policies, Azure Active Directory Identity Protection, threat protection enforcement, Teams protection, Microsoft Sentinel initial configuration, and security verification. It also includes selected advanced security activities listed in scope, such as Privileged Access Workstations, Entra ID Privileged Identity Management, Defender for Cloud Apps usage, attack simulations, eDiscovery integration, and a project closeout report.

What are the success criteria for this engagement?

The stated success criteria are a Microsoft 365 security score of 75%, validated threat protection settings, validated identity and access management settings, Exchange Online Protection configured and working, and Teams protection configured. The user should be able to access the Security Portal and confirm the security score.

How long does the service take?

Microsoft 365 Security Beyond Service is listed as a 30-day service. The exact activity sequence may vary depending on the customer’s needs, current tenant configuration, licensing, and availability of required client resources.

How much does Microsoft 365 Security Beyond Service cost?

The listed price for Microsoft 365 Security Beyond Service is 6000. Additional licenses, add-on services, customer training, migration work, expanded documentation, or advisory services are not included unless separately agreed with IT Partner.

What prerequisites are required before starting?

The stated prerequisite is that the customer must already have a Microsoft 365 tenant. The customer should also be prepared to provide tenant access, a dedicated point of contact, resource coordination, and information about current security settings so IT Partner can assess and configure the environment.

What happens during the engagement?

The engagement typically includes a kickoff meeting, security scope check, current configuration assessment, user creation or AD Connect configuration where applicable, security configuration, settings verification, security score verification, final communication, and issue fixing if needed. IT Partner gathers current tenant and security information, applies agreed Microsoft 365 security configurations, validates key settings, and closes the project with a status report.

What are IT Partner’s responsibilities in this service?

IT Partner is responsible for gathering tenant and security configuration information, configuring core Microsoft 365 protections, checking and configuring the security score up to 75%, enforcing threat protection, configuring identity protections, Teams protections, Microsoft Sentinel initial connectors, MFA, conditional access, PIM, PAWs, SIEM logging collection, attack simulations, and related security controls listed in scope. IT Partner also provides the project closeout report showing final status, acceptance criteria matching, outstanding issues if any, and final budget.

What are the customer’s responsibilities?

The customer is responsible for coordinating internal staff schedules, providing a dedicated point of contact, coordinating outside vendors, making required DNS changes, configuring network equipment such as firewalls and switches, reviewing and approving deliverables, identifying high-risk users, and providing end user support. These responsibilities matter because security changes such as MFA, conditional access, DNS updates, and network dependencies often require customer-side approval and operational coordination.

Are Microsoft 365 licenses included in the service price?

No, additional licenses that may be required are not included in the service price. Because features such as Defender for Cloud Apps, Attack simulation training, Entra ID Identity Protection, Microsoft Sentinel, PIM, and advanced compliance capabilities may depend on licensing, the exact license requirements should be confirmed with IT Partner before implementation.

Is Gmail or Google Drive migration included in this service?

Gmail and Google Drive migration is not listed in IT Partner’s responsibilities, implementation plan, deliverables, or success criteria for this service. The source text contains a note saying project success is tied to all user data being migrated from Gmail and Google Drive, but that conflicts with the listed scope, so customers should confirm with IT Partner whether any Google migration work is included before purchasing.

Is customer training included?

No, customer team training is listed as not included in this service. IT Partner states that training can be added as an additional service if the customer needs administrator or user enablement beyond the security configuration engagement.

Does the service include SharePoint Online document migration or desktop software configuration?

No, corporate document migration to SharePoint Online and desktop software settings are explicitly listed as not included. SharePoint document migration may be added as an additional service, but it is outside the standard Microsoft 365 Security Beyond Service scope.

Will the engagement cause downtime or affect users?

The service description does not specify planned downtime, but some security changes may affect user sign-in, access behavior, sharing, Teams collaboration, or authentication because MFA, conditional access, identity protection, DLP, and sharing policies are part of the scope. Customers should coordinate timing, communications, and end user support with IT Partner because the customer is responsible for schedules, network changes, approvals, and user support.

What Teams security protections are configured?

The service includes configuring Teams with three tiers of protection. The listed areas include sharing, classification, data loss prevention, and Azure Information Protection, with Teams protection also included as a success criterion.

Does the service include Microsoft Sentinel setup?

Yes, the service includes Microsoft Sentinel initial configuration, such as basic Microsoft 365 connectors. The scope also mentions configuring a SIEM tool to collect logging data from Office 365, Defender for Cloud Apps, and other services including AD FS, but it should be confirmed with IT Partner whether Microsoft Sentinel is required as the SIEM or whether another SIEM may be used.

Why is SIEM log collection included?

SIEM log collection is included because the audit log stores data for only 90 days, and capturing security data in a SIEM allows longer retention. The service scope includes collecting logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS, where applicable.

Are attack simulations included?

Yes, the service includes attack simulations for spear-phishing, password-spray, and brute-force password attacks using Attack simulation training. The service text notes that Attack simulation training is included with Office 365 Threat Intelligence, so licensing and availability should be verified for the customer tenant.

What documentation is provided at the end of the project?

The included documentation deliverable is a project closeout report showing final project status, acceptance criteria matching, outstanding issues if any, and final budget. More extensive documentation is listed as available for an additional fee, so customers should confirm any required runbooks, diagrams, policy documents, or operational guides before the engagement starts.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

6000
30 days
Book a meeting