First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Security 90 Days Service
Security and Protection

Microsoft 365 Security 90 Days Service — Tenant Security Configuration

Microsoft 365 Security 90 Days Service is a Microsoft 365 security configuration service for organizations that already have a Microsoft 365 tenant and need IT Partner to assess current tenant security settings, configure core protections, validate security settings, and provide a project closeout report. SKU: ITPWW040SECOT. Listed price: 4000. Duration: 30 days. Manager: Roman Sotnik.

Timeline 30 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

This Office 365/Microsoft 365 Security and Protection service is intended to set up a basic secured Microsoft 365 environment. IT Partner will gather information about the current tenant and security configurations, enable core Microsoft 365 security features, configure identity and threat protection settings, validate security settings, and review security dashboards and reports. The stated objective is to provide a plan and design a way to enable core Microsoft 365 security features. The source also states that the project will be considered successful when all user data is fully migrated from Gmail and Google Drive to the Microsoft 365 tenant.

Success criteria

01The project will be considered successful when all user data is fully migrated from Gmail and Google Drive to the Microsoft 365 tenant.
02Security score 75%. User can access Security Portal and confirm this.
03Validated Threat protection settings
04Validated Identity and access management settings
05Exchange Online Protection is configured and working
06Teams protection is configured

What you receive

Plan and design for enabling core Microsoft 365 security features
Information gathered about the current tenant and security configurations
Core configuration of the Microsoft 365 tenant, including basic admin protections, logging and analytics configuration, and basic identity protection setup
Security score checked and configured up to 75%
Threat Protection enforced, e.g. connecting M365 to MS Defender for Cloud Apps
Azure Active Directory Identity Protection configured
Teams configured with three tiers of protection, including sharing, classification, data loss prevention, and Azure Information Protection
Microsoft Sentinel initial configuration, e.g. basic M365 connectors
At least monthly check ups of dashboards and reports in the Microsoft 365 Defender portal, Defender for Cloud Apps
Software updates reviewed and implemented
Sharing risk reviewed using the built-in reports in Defender for Cloud Apps on the Investigate tab
Privileged Access Workstations (PAWs) configured for admin activity
Entra ID Privileged Identity Management configured
Security information and event management (SIEM) tool configured to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS
MFA enabled and enforced for all users
Set of conditional access and related policies implemented
Project closeout report indicating the final project status, including acceptance criteria matching, outstanding issues if any, and the final budget

How the work unfolds

Kickoff meeting

Confirm the business objectives, tenant scope, key stakeholders, communication path, change windows, required access, licensing assumptions, and acceptance process. Identify high-risk users, administrative accounts, pilot users, and any known operational constraints before configuration begins.

Security scope check and current configuration assessment

Review the current Microsoft 365 and Entra ID security posture, including tenant licensing, administrator roles, MFA status, conditional access policies, audit logging, Secure Score baseline, Exchange Online Protection, Teams and sharing settings, Defender portal configuration, Defender for Cloud Apps readiness, and Sentinel or SIEM logging requirements.

User creation or AD connect tool configuration

Validate the identity model and perform the agreed identity preparation work. This may include user creation, domain and UPN validation, security group preparation, privileged account review, Microsoft Entra Connect configuration or health checks where applicable, and confirmation that user identities are ready for the planned security controls.

Security configuration start

Implement the approved Microsoft 365 security baseline within the licensed and agreed scope. Typical activities include MFA enforcement, conditional access policies, admin protection settings, audit and logging configuration, Exchange Online Protection configuration, identity protection settings, Teams protection settings, Defender for Cloud Apps connection, Sentinel connector setup, PIM configuration, PAW-related controls, and SIEM logging integration where applicable.

Security settings verification

Test the configured controls with administrative and standard user scenarios. Validate sign-in behavior, MFA prompts, conditional access decisions, privileged role activation, mail protection flow, Teams sharing and DLP behavior, audit log collection, Microsoft Defender portal visibility, and connector health for Defender for Cloud Apps, Sentinel, or SIEM tools as applicable.

Security score verification

Review the Microsoft Secure Score after configuration, confirm progress toward the stated 75% target, document completed improvement actions, and identify any remaining recommendations that require additional licensing, business approval, user change management, or separate project work.

Final email

Send a completion summary covering work performed, configured controls, verification results, known exceptions, open risks, customer action items, and the path to final acceptance. Where applicable, request customer validation in the Microsoft security portals and confirm the closeout reporting schedule.

Verification and fixing of issues, if any

Address issues identified during customer validation that relate to the agreed scope. Typical remediation may include tuning conditional access exclusions, correcting policy assignments, resolving connector or logging issues, adjusting Teams or sharing settings, confirming MFA registration behavior, and documenting any residual issues that require separate licensing, business decisions, or additional services.

Prerequisites

You must have a Microsoft 365 tenant

Who does what

IT Partner

  • Gather information about your current tenant and security configurations
  • Perform core configuration of your Microsoft 365 tenant: a. Basic admin protections b. Logging and analytics configuration c. Basic identity protection setup
  • Checking security score and configuring it up to 75%
  • Enforcing Threat Protection, e.g. connecting M365 to MS Defender for Cloud Apps
  • Configuring Azure Active Directory Identity Protection
  • Configuring Teams with three tiers of protection (including sharing, classification, data loss prevention, and Azure Information Protection)
  • Microsoft Sentinel Initial configuration (e.g. basic M365 connectors)
  • At least monthly check ups of dashboards and reports in the Microsoft 365 Defender portal, Defender for Cloud Apps.
  • Look for and implement software updates.
  • Look for sharing risk by reviewing the built-in reports in Defender for Cloud Apps (on the Investigate tab).
  • Configure Privileged Access Workstations (PAWs) for admin activity.
  • Configure Entra ID Privileged Identity Management.
  • Configure a security information and event management (SIEM) tool to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS. The audit log stores data for only 90 days. Capturing this data in SIEM tool allows you to store data for a longer period.
  • Enable and enforce MFA for all users.
  • Implement a set of conditional access and related policies.

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Coordinate any outside vendor resources and schedules
  • Perform changes to internal and external DNS, as required
  • Configure all network equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner
  • Assist with identification of high-risk users (admins, top executives and VIP users)
  • End user support

What's not included

Additional licenses that may be required
Customer team training (could be added as an additional service)
Corporate documents migration to SharePoint Online (could be added as an additional service)
Desktop software settings
Information Security Advisory services (could be added as an additional service)
If you require more extensive documentation, it can be provided for an additional fee.

Limitations & technical notes

!The plan may vary depending on your needs.
!The audit log stores data for only 90 days. Capturing this data in SIEM tool allows you to store data for a longer period.
!The source title says “Microsoft 365 Security 90 Days Service,” while the source description and duration state “30 days.” This enriched version preserves both facts and treats the listed duration as 30 days until IT Partner confirms the public naming and scheduling language.
!The source includes a Gmail and Google Drive migration success statement, but the detailed scope is Microsoft 365 security configuration and SharePoint Online document migration is listed as an additional-cost item. The recommended delivery position is to confirm migration scope during qualification and not assume migration work is included unless explicitly added to the statement of work.

Frequently asked questions

What is the Microsoft 365 Security 90 Days Service?

Microsoft 365 Security 90 Days Service is a Microsoft 365 security configuration engagement for organizations that already have a Microsoft 365 tenant and need IT Partner to assess current security settings, configure core protections, validate those settings, and provide a closeout report. The listed SKU is ITPWW040SECOT, the listed price is 4000, and the service manager is Roman Sotnik.

What is included in the Microsoft 365 Security 90 Days Service?

The service includes current tenant and security configuration assessment, core Microsoft 365 tenant security configuration, basic admin protections, logging and analytics configuration, basic identity protection setup, MFA enforcement, conditional access policies, threat protection validation, and security score configuration up to 75%. It can also include Microsoft Defender for Cloud Apps connection, Azure Active Directory Identity Protection, Teams protection configuration, Microsoft Sentinel initial configuration with basic Microsoft 365 connectors, Entra ID Privileged Identity Management, PAWs for admin activity, SIEM logging configuration, and a project closeout report.

What is not included in the Microsoft 365 Security 90 Days Service?

The service does not include additional licenses that may be required, customer team training, corporate document migration to SharePoint Online, desktop software settings, or Information Security Advisory services. More extensive documentation is also outside the standard scope and may be available for an additional fee.

How long does the Microsoft 365 Security 90 Days Service take?

The service content lists a duration of 30 days, even though the public title says "Microsoft 365 Security 90 Days Service." Because those two facts are inconsistent, buyers should confirm the correct public duration with IT Partner before purchase or scheduling.

How much does the Microsoft 365 Security 90 Days Service cost?

The listed price for the Microsoft 365 Security 90 Days Service is 4000 for SKU ITPWW040SECOT. Any additional Microsoft licenses, added training, advisory work, migration services, or expanded documentation are not included in that listed service scope and should be confirmed separately with IT Partner.

What prerequisites are required before starting this service?

The stated prerequisite is that the organization must already have a Microsoft 365 tenant. The client should also be ready to provide a dedicated point of contact, coordinate staff schedules, approve deliverables, and assist with identifying high-risk users such as administrators, executives, and VIP users.

What happens during the engagement?

The engagement typically starts with a kickoff meeting, followed by a security scope check and current configuration assessment, user creation or AD Connect configuration where applicable, security configuration, security settings verification, security score verification, final email, and issue fixing if needed. The implementation plan may vary depending on the organization’s needs, so detailed milestone activities should be confirmed with IT Partner.

What Microsoft 365 security areas does IT Partner configure?

IT Partner configures core Microsoft 365 security areas including basic admin protections, logging and analytics, identity protection, MFA enforcement, conditional access policies, threat protection, Exchange Online Protection, Teams protection, and Microsoft 365 security score improvements up to 75%. The service may also cover Microsoft Defender for Cloud Apps, Azure Active Directory Identity Protection, Microsoft Sentinel initial configuration, Entra ID Privileged Identity Management, PAWs, and SIEM logging integration as stated in the service scope.

Does the service enable MFA for all users?

Yes, the stated IT Partner responsibilities include enabling and enforcing MFA for all users. Because MFA changes can affect user sign-in behavior, the client should be prepared to support end users and coordinate internal communications during rollout.

Does the service include Conditional Access policy configuration?

Yes, the service includes implementation of a set of conditional access and related policies. The exact policy design may depend on the tenant’s licensing, current configuration, business requirements, and risk profile, so final policy details should be reviewed during the engagement.

Does the service configure Microsoft Defender for Cloud Apps and threat protection?

Yes, the service includes enforcing threat protection, for example by connecting Microsoft 365 to Microsoft Defender for Cloud Apps, and reviewing sharing risk using built-in Defender for Cloud Apps reports on the Investigate tab. It also includes validation of threat protection settings as part of the success criteria.

Does the service include Teams security configuration?

Yes, the service includes Teams protection configuration with three tiers of protection, including sharing, classification, data loss prevention, and Azure Information Protection. Teams protection being configured is also listed as a success criterion.

Does the service include Microsoft Sentinel or SIEM configuration?

Yes, the service includes Microsoft Sentinel initial configuration, such as basic Microsoft 365 connectors, and SIEM tool configuration to collect logging data from Office 365, Defender for Cloud Apps, and other services including AD FS. This is important because the audit log stores data for only 90 days, and sending data to a SIEM can allow longer retention depending on the SIEM configuration and licensing.

What security score does the service target?

The service includes checking the Microsoft security score and configuring it up to 75%. The success criteria state that the user can access the Security Portal and confirm the 75% security score.

Will this service cause downtime or business disruption?

The service content does not specify planned downtime or a guaranteed no-downtime implementation. Because changes such as MFA enforcement, conditional access policies, identity protection, and admin security controls can affect sign-in and access behavior, scheduling and user impact should be reviewed with IT Partner before changes are applied.

What are IT Partner’s responsibilities during the service?

IT Partner is responsible for gathering current tenant and security configuration information, configuring core Microsoft 365 security protections, checking and improving security score up to 75%, enforcing threat protection, configuring identity protection, configuring Teams protections, setting up initial Microsoft Sentinel or SIEM logging where applicable, enabling MFA, and implementing conditional access policies. IT Partner also performs security settings verification and provides a project closeout report.

What are the client’s responsibilities during the service?

The client is responsible for coordinating internal resources and schedules, providing a dedicated point of contact, coordinating outside vendors, making required DNS changes, configuring network equipment such as load balancers, routers, firewalls, and switches, reviewing and approving deliverables, identifying high-risk users, and providing end user support. These responsibilities are important because security changes often require coordination across IT, networking, leadership, and user support teams.

Does the service include Gmail or Google Drive migration?

The service content contains an inconsistency: it states the project is successful when all user data is fully migrated from Gmail and Google Drive to the Microsoft 365 tenant, but the primary service scope is Microsoft 365 security configuration and corporate document migration to SharePoint Online is listed as an additional-cost service. Buyers should confirm with IT Partner whether Gmail or Google Drive migration is actually included and whether it is an acceptance criterion for this engagement.

What deliverable is provided at the end of the service?

At the end of the service, IT Partner provides a project closeout report indicating final project status, acceptance criteria matching, any outstanding issues, and the final budget. The engagement also includes validation of security settings, security score verification, and issue fixing if required within the stated service process.

What happens after the Microsoft 365 security configuration is completed?

After configuration, the service includes verification of security settings, verification of the security score, a final email, and fixing of issues if any are identified. The stated responsibilities also include at least monthly checkups of dashboards and reports in the Microsoft 365 Defender portal and Defender for Cloud Apps, but the exact post-completion monitoring period and operational handoff should be confirmed with IT Partner.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,000
30 days
Book a meeting