First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Security 90 Days Service
Security and Protection

Microsoft 365 Security 90 Days Service — Tenant Security Configuration

Microsoft 365 Security 90 Days Service is a Microsoft 365 security configuration service for organizations that already have a Microsoft 365 tenant and need IT Partner to assess current tenant security settings, configure core protections, validate security settings, and provide a project closeout report.

Timeline 30 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

This Microsoft 365 Security and Protection service sets up a basic secured Microsoft 365 environment. IT Partner gathers information about the current tenant and security configurations, enables core Microsoft 365 security features, configures identity and threat protection settings, validates security settings, and reviews security dashboards and reports. The objective is to provide a plan and design a way to enable core Microsoft 365 security features, based on your business needs and current configuration.

Success criteria

01Microsoft Secure Score improved toward the agreed 75% target; the customer can confirm the score in the Microsoft Defender portal.
02Validated Threat protection settings
03Validated Identity and access management settings
04Exchange Online Protection is configured and working
05Teams protection is configured

What you receive

Plan and design for enabling core Microsoft 365 security features
Information gathered about the current tenant and security configurations
Core configuration of the Microsoft 365 tenant, including basic admin protections, logging and analytics configuration, and basic identity protection setup
Microsoft Secure Score checked and configured up to the 75% target
Threat Protection enforced, e.g. connecting Microsoft 365 to Microsoft Defender for Cloud Apps
Microsoft Entra ID Protection configured
Teams configured with three tiers of protection, including sharing, classification, data loss prevention, and Microsoft Purview Information Protection sensitivity labels
Microsoft Sentinel initial configuration, e.g. basic M365 connectors
At least monthly check ups of dashboards and reports in the Microsoft Defender portal and Defender for Cloud Apps
Software updates reviewed and implemented
Sharing risk reviewed using the built-in reports in Defender for Cloud Apps on the Investigate tab
Privileged Access Workstations (PAWs) configured for admin activity
Entra ID Privileged Identity Management configured
Security information and event management (SIEM) tool configured to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS
MFA enabled and enforced for all users
Set of conditional access and related policies implemented
Project closeout report indicating the final project status, including acceptance criteria matching, outstanding issues if any, and the final budget

How the work unfolds

Kickoff meeting

Confirm the business objectives, tenant scope, key stakeholders, communication path, change windows, required access, licensing assumptions, and acceptance process. Identify high-risk users, administrative accounts, pilot users, and any known operational constraints before configuration begins.

Security scope check and current configuration assessment

Review the current Microsoft 365 and Entra ID security posture, including tenant licensing, administrator roles, MFA status, conditional access policies, audit logging, Secure Score baseline, Exchange Online Protection, Teams and sharing settings, Defender portal configuration, Defender for Cloud Apps readiness, and Sentinel or SIEM logging requirements.

User creation or Microsoft Entra Connect configuration

Validate the identity model and perform the agreed identity preparation work. This may include user creation, domain and UPN validation, security group preparation, privileged account review, Microsoft Entra Connect configuration or health checks where applicable, and confirmation that user identities are ready for the planned security controls.

Security configuration start

Implement the approved Microsoft 365 security baseline within the licensed and agreed scope. Typical activities include MFA enforcement, conditional access policies, admin protection settings, audit and logging configuration, Exchange Online Protection configuration, identity protection settings, Teams protection settings, Defender for Cloud Apps connection, Sentinel connector setup, PIM configuration, PAW-related controls, and SIEM logging integration where applicable.

Security settings verification

Test the configured controls with administrative and standard user scenarios. Validate sign-in behavior, MFA prompts, conditional access decisions, privileged role activation, mail protection flow, Teams sharing and DLP behavior, audit log collection, Microsoft Defender portal visibility, and connector health for Defender for Cloud Apps, Sentinel, or SIEM tools as applicable.

Security score verification

Review the Microsoft Secure Score after configuration, confirm progress toward the stated 75% target, document completed improvement actions, and identify any remaining recommendations that require additional licensing, business approval, user change management, or separate project work.

Final email

Send a completion summary covering work performed, configured controls, verification results, known exceptions, open risks, customer action items, and the path to final acceptance. Where applicable, request customer validation in the Microsoft security portals and confirm the closeout reporting schedule.

Verification and fixing of issues, if any

Address issues identified during customer validation that relate to the agreed scope. Typical remediation may include tuning conditional access exclusions, correcting policy assignments, resolving connector or logging issues, adjusting Teams or sharing settings, confirming MFA registration behavior, and documenting any residual issues that require separate licensing, business decisions, or additional services.

Prerequisites

You must have a Microsoft 365 tenant

Who does what

IT Partner

  • Gather information about your current tenant and security configurations
  • Perform core configuration of your Microsoft 365 tenant: a. Basic admin protections b. Logging and analytics configuration c. Basic identity protection setup
  • Checking security score and configuring it up to 75%
  • Enforcing Threat Protection, e.g. connecting Microsoft 365 to Microsoft Defender for Cloud Apps
  • Configuring Microsoft Entra ID Protection
  • Configuring Teams with three tiers of protection (including sharing, classification, data loss prevention, and Microsoft Purview Information Protection sensitivity labels)
  • Microsoft Sentinel Initial configuration (e.g. basic M365 connectors)
  • At least monthly check ups of dashboards and reports in the Microsoft Defender portal, Defender for Cloud Apps.
  • Look for and implement software updates.
  • Look for sharing risk by reviewing the built-in reports in Defender for Cloud Apps (on the Investigate tab).
  • Configure Privileged Access Workstations (PAWs) for admin activity.
  • Configure Entra ID Privileged Identity Management.
  • Configure a security information and event management (SIEM) tool to collect logging data from Office 365, Defender for Cloud Apps, and other services, including AD FS. Microsoft 365 audit log retention is limited and depends on licensing; capturing the data in a SIEM allows longer retention.
  • Enable and enforce MFA for all users.
  • Implement a set of conditional access and related policies.

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Coordinate any outside vendor resources and schedules
  • Perform changes to internal and external DNS, as required
  • Configure all network equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner
  • Assist with identification of high-risk users (admins, top executives and VIP users)
  • End user support

What's not included

Additional licenses that may be required
Customer team training (could be added as an additional service)
Corporate documents migration to SharePoint Online (could be added as an additional service)
Desktop software settings
Information Security Advisory services (could be added as an additional service)
If you require more extensive documentation, it can be provided for an additional fee.

Limitations & technical notes

!The plan may vary depending on your needs.
!Microsoft 365 audit log retention is limited and depends on licensing; capturing the data in a SIEM allows longer retention.
!The service name references 90 days; the currently listed engagement duration is 30 days. Confirm the delivery schedule with IT Partner during scoping.
!Data migration — including Gmail/Google Drive or SharePoint document migration — is not part of this security engagement; migration work is scoped and sold separately.

Frequently asked questions

What is the Microsoft 365 Security 90 Days Service?

Microsoft 365 Security 90 Days Service is a Microsoft 365 security configuration engagement for organizations that already have a Microsoft 365 tenant and need IT Partner to assess current security settings, configure core protections, validate those settings, and provide a closeout report.

What is included in the Microsoft 365 Security 90 Days Service?

The service includes tenant and security configuration assessment, core Microsoft 365 tenant security configuration, basic admin protections, logging and analytics configuration, basic identity protection setup, MFA enforcement, conditional access policies, threat protection validation, and Microsoft Secure Score configuration up to the 75% target. It also includes Microsoft Defender for Cloud Apps connection, Microsoft Entra ID Protection, Teams protection configuration, Microsoft Sentinel initial configuration with basic Microsoft 365 connectors, Microsoft Entra ID Privileged Identity Management, Privileged Access Workstations for admin activity, SIEM logging configuration, and a project closeout report.

What is not included in the Microsoft 365 Security 90 Days Service?

The service does not include additional licenses that may be required, customer team training, corporate document migration to SharePoint Online, desktop software settings, or Information Security Advisory services. More extensive documentation is also outside the standard scope and may be available for an additional fee.

How long does the Microsoft 365 Security 90 Days Service take?

The listed duration for this engagement is 30 days. The public service name references 90 days; confirm the delivery schedule with IT Partner during scoping.

How much does the Microsoft 365 Security 90 Days Service cost?

The service is $4,000 per project, quoted fixed-price in writing before work begins. Additional Microsoft licenses, added training, advisory work, migration services, or expanded documentation are not included and are confirmed separately with IT Partner.

What prerequisites are required before starting this service?

The stated prerequisite is that the organization must already have a Microsoft 365 tenant. The client should also be ready to provide a dedicated point of contact, coordinate staff schedules, approve deliverables, and assist with identifying high-risk users such as administrators, executives, and VIP users.

What happens during the engagement?

The engagement starts with a kickoff meeting, followed by a security scope check and current configuration assessment, user creation or Microsoft Entra Connect configuration where applicable, security configuration, security settings verification, security score verification, a final summary, and issue fixing if needed.

Does the service enable MFA for all users?

Yes, IT Partner enables and enforces MFA for all users. Because MFA changes affect user sign-in behavior, the client should be prepared to support end users and coordinate internal communications during rollout.

Does the service include Conditional Access policy configuration?

Yes, the service implements a set of conditional access and related policies. The exact policy design depends on the tenant's licensing, current configuration, business requirements, and risk profile, and is reviewed during the engagement.

Does the service include Microsoft Sentinel or SIEM configuration?

Yes, the service includes Microsoft Sentinel initial configuration, such as basic Microsoft 365 connectors, and SIEM tool configuration to collect logging data from Office 365, Defender for Cloud Apps, and other services including AD FS. Microsoft 365 audit log retention is limited and depends on licensing, so sending data to a SIEM allows longer retention depending on the SIEM configuration and licensing.

Does the service include Gmail or Google Drive migration?

No. Gmail and Google Drive migration is not part of this security engagement. Migration work — including corporate document migration to SharePoint Online — is scoped and sold separately.

Will this service cause downtime or business disruption?

The service requires no planned Microsoft 365 downtime. Changes such as MFA enforcement, conditional access policies, identity protection, and admin security controls can affect sign-in and access behavior, so scheduling and user impact are reviewed with IT Partner before changes are applied.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,000 per project
30 days
Book a meeting