Microsoft 365 Security 90 Days Service — Tenant Security Configuration
Microsoft 365 Security 90 Days Service is a Microsoft 365 security configuration service for organizations that already have a Microsoft 365 tenant and need IT Partner to assess current tenant security settings, configure core protections, validate security settings, and provide a project closeout report.
What this engagement is
This Microsoft 365 Security and Protection service sets up a basic secured Microsoft 365 environment. IT Partner gathers information about the current tenant and security configurations, enables core Microsoft 365 security features, configures identity and threat protection settings, validates security settings, and reviews security dashboards and reports. The objective is to provide a plan and design a way to enable core Microsoft 365 security features, based on your business needs and current configuration.
Success criteria
What you receive
How the work unfolds
Confirm the business objectives, tenant scope, key stakeholders, communication path, change windows, required access, licensing assumptions, and acceptance process. Identify high-risk users, administrative accounts, pilot users, and any known operational constraints before configuration begins.
Review the current Microsoft 365 and Entra ID security posture, including tenant licensing, administrator roles, MFA status, conditional access policies, audit logging, Secure Score baseline, Exchange Online Protection, Teams and sharing settings, Defender portal configuration, Defender for Cloud Apps readiness, and Sentinel or SIEM logging requirements.
Validate the identity model and perform the agreed identity preparation work. This may include user creation, domain and UPN validation, security group preparation, privileged account review, Microsoft Entra Connect configuration or health checks where applicable, and confirmation that user identities are ready for the planned security controls.
Implement the approved Microsoft 365 security baseline within the licensed and agreed scope. Typical activities include MFA enforcement, conditional access policies, admin protection settings, audit and logging configuration, Exchange Online Protection configuration, identity protection settings, Teams protection settings, Defender for Cloud Apps connection, Sentinel connector setup, PIM configuration, PAW-related controls, and SIEM logging integration where applicable.
Test the configured controls with administrative and standard user scenarios. Validate sign-in behavior, MFA prompts, conditional access decisions, privileged role activation, mail protection flow, Teams sharing and DLP behavior, audit log collection, Microsoft Defender portal visibility, and connector health for Defender for Cloud Apps, Sentinel, or SIEM tools as applicable.
Review the Microsoft Secure Score after configuration, confirm progress toward the stated 75% target, document completed improvement actions, and identify any remaining recommendations that require additional licensing, business approval, user change management, or separate project work.
Send a completion summary covering work performed, configured controls, verification results, known exceptions, open risks, customer action items, and the path to final acceptance. Where applicable, request customer validation in the Microsoft security portals and confirm the closeout reporting schedule.
Address issues identified during customer validation that relate to the agreed scope. Typical remediation may include tuning conditional access exclusions, correcting policy assignments, resolving connector or logging issues, adjusting Teams or sharing settings, confirming MFA registration behavior, and documenting any residual issues that require separate licensing, business decisions, or additional services.
Prerequisites
Who does what
IT Partner
- Gather information about your current tenant and security configurations
- Perform core configuration of your Microsoft 365 tenant: a. Basic admin protections b. Logging and analytics configuration c. Basic identity protection setup
- Checking security score and configuring it up to 75%
- Enforcing Threat Protection, e.g. connecting Microsoft 365 to Microsoft Defender for Cloud Apps
- Configuring Microsoft Entra ID Protection
- Configuring Teams with three tiers of protection (including sharing, classification, data loss prevention, and Microsoft Purview Information Protection sensitivity labels)
- Microsoft Sentinel Initial configuration (e.g. basic M365 connectors)
- At least monthly check ups of dashboards and reports in the Microsoft Defender portal, Defender for Cloud Apps.
- Look for and implement software updates.
- Look for sharing risk by reviewing the built-in reports in Defender for Cloud Apps (on the Investigate tab).
- Configure Privileged Access Workstations (PAWs) for admin activity.
- Configure Entra ID Privileged Identity Management.
- Configure a security information and event management (SIEM) tool to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS. Microsoft 365 audit log retention is limited and depends on licensing; capturing the data in a SIEM allows longer retention.
- Enable and enforce MFA for all users.
- Implement a set of conditional access and related policies.
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Coordinate any outside vendor resources and schedules
- Perform changes to internal and external DNS, as required
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
- Assist with identification of high-risk users (admins, top executives and VIP users)
- End user support
What's not included
Limitations & technical notes
Frequently asked questions
What is the Microsoft 365 Security 90 Days Service?
Microsoft 365 Security 90 Days Service is a Microsoft 365 security configuration engagement for organizations that already have a Microsoft 365 tenant and need IT Partner to assess current security settings, configure core protections, validate those settings, and provide a closeout report.
What is included in the Microsoft 365 Security 90 Days Service?
The service includes tenant and security configuration assessment, core Microsoft 365 tenant security configuration, basic admin protections, logging and analytics configuration, basic identity protection setup, MFA enforcement, conditional access policies, threat protection validation, and Microsoft Secure Score configuration up to the 75% target. It also includes Microsoft Defender for Cloud Apps connection, Microsoft Entra ID Protection, Teams protection configuration, Microsoft Sentinel initial configuration with basic Microsoft 365 connectors, Microsoft Entra ID Privileged Identity Management, Privileged Access Workstations for admin activity, SIEM logging configuration, and a project closeout report.
What is not included in the Microsoft 365 Security 90 Days Service?
The service does not include additional licenses that may be required, customer team training, corporate document migration to SharePoint Online, desktop software settings, or Information Security Advisory services. More extensive documentation is also outside the standard scope and may be available for an additional fee.
How long does the Microsoft 365 Security 90 Days Service take?
The listed duration for this engagement is 30 days. The public service name references 90 days; confirm the delivery schedule with IT Partner during scoping.
How much does the Microsoft 365 Security 90 Days Service cost?
The service is $4,000 per project, quoted fixed-price in writing before work begins. Additional Microsoft licenses, added training, advisory work, migration services, or expanded documentation are not included and are confirmed separately with IT Partner.
What prerequisites are required before starting this service?
The stated prerequisite is that the organization must already have a Microsoft 365 tenant. The client should also be ready to provide a dedicated point of contact, coordinate staff schedules, approve deliverables, and assist with identifying high-risk users such as administrators, executives, and VIP users.
What happens during the engagement?
The engagement starts with a kickoff meeting, followed by a security scope check and current configuration assessment, user creation or Microsoft Entra Connect configuration where applicable, security configuration, security settings verification, security score verification, a final summary, and issue fixing if needed.
Does the service enable MFA for all users?
Yes, IT Partner enables and enforces MFA for all users. Because MFA changes affect user sign-in behavior, the client should be prepared to support end users and coordinate internal communications during rollout.
Does the service include Conditional Access policy configuration?
Yes, the service implements a set of conditional access and related policies. The exact policy design depends on the tenant's licensing, current configuration, business requirements, and risk profile, and is reviewed during the engagement.
Does the service include Microsoft Sentinel or SIEM configuration?
Yes, the service includes Microsoft Sentinel initial configuration, such as basic Microsoft 365 connectors, and SIEM tool configuration to collect logging data from Office 365, Defender for Cloud Apps, and other services including AD FS. Microsoft 365 audit log retention is limited and depends on licensing, so sending data to a SIEM allows longer retention depending on the SIEM configuration and licensing.
Does the service include Gmail or Google Drive migration?
No. Gmail and Google Drive migration is not part of this security engagement. Migration work — including corporate document migration to SharePoint Online — is scoped and sold separately.
Will this service cause downtime or business disruption?
The service requires no planned Microsoft 365 downtime. Changes such as MFA enforcement, conditional access policies, identity protection, and admin security controls can affect sign-in and access behavior, so scheduling and user impact are reviewed with IT Partner before changes are applied.