First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Securing and Hardening of your Microsoft 365 Environment
Security and Protection

Microsoft 365 Security Hardening — Secure Configuration & Risk Reduction

Securing and Hardening of your Microsoft 365 Environment is a 1-week Microsoft 365 security engagement for organizations that want certified engineers to analyze their Microsoft 365 organization's security, review existing and optional security controls and settings, and develop a prioritized plan according to Microsoft best-practices to increase security and reduce risks. Service details: SKU ITPWW140IMPOT; price $175 per hour; duration 1 week; manager Roman Sotnik.

Timeline 1 weekService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner analyzes your Microsoft 365 organization's security based on your regular activities and security settings, then develops a plan according to Microsoft recommendations to increase security and reduce risks. The objective is to make your Microsoft 365 environment safe and secure. The service focuses on three security pillars stated in the source: updated and managed Windows 10 on your devices, a correctly configured Microsoft 365 environment, and Enterprise Mobility + Security services.

Success criteria

01Kickoff is completed, engagement scope is confirmed, and required Microsoft 365 administrative access is validated before assessment work begins.
02A baseline Microsoft 365 security posture review is completed, including review of available Secure Score recommendations and relevant security, identity, device, threat protection, and privacy controls within the licensed tenant capabilities.
03A prioritized plan of changes is produced and reviewed with the client, with recommended actions categorized by risk, business impact, dependency, licensing requirement, and implementation priority where applicable.
04Client-approved built-in Microsoft 365 security tools and features within the agreed scope are configured or adjusted in the tenant, subject to available licensing and change approval.
05Multi-factor authentication, customer security controls, privacy controls, anti-malware, patching/configuration management, and advanced threat protection settings are reviewed or addressed to the extent they are available and included in the approved scope.
06Post-implementation analysis confirms that approved configuration changes were applied or that documented exceptions, blockers, or outstanding items were recorded.
07A comprehensive report and project closeout report are delivered, including final status, evidence of completed activities, outstanding issues if any, and final budget information.
08Critical implementation issues identified during the engagement are resolved, rolled back, or documented with an agreed remediation plan or customer-approved exception before closeout.

What you receive

A prioritized plan according to Microsoft best-practices to increase security and reduce risks.
A comprehensive report.
A project closeout report indicating the final project status, including evidence of matching acceptance criteria, outstanding issues, if any, and the final budget.

How the work unfolds

Kickoff meeting

Kickoff meeting.

Customer security requirements research

Research customer security requirements.

Your Microsoft 365 environment analysis

Analyze your Microsoft 365 environment.

Approving a plan of changes

Approve a plan of changes.

Implementation of built-in security tools and features

Implement built-in security tools and features.

Performing post-implementation analysis

Perform post-implementation analysis.

Developing a comprehensive report

Develop a comprehensive report.

Prerequisites

Must have: A Microsoft 365 subscription
Recommended: Windows 10 Pro or Enterprise licenses
Recommended: EM+S subscription

Who does what

IT Partner

  • Service-level security review
  • Secure Score increasing
  • Anti-malware, patching, and configuration management
  • Advanced threat protection
  • Customer controls for security
  • Multi-factor authentication
  • Customer controls for privacy

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Provide all the necessary information for the statement of work preparation
  • Provide an account in the required services with the rights necessary to implement the service
  • Coordinate any outside vendor resources and schedules
  • Configure all network equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner
  • Request and approve all change management tickets (if available) in the Client environment

What's not included

Training customer team(s)
More extensive documentation beyond the project closeout report can be provided for an additional fee.

Limitations & technical notes

!The plan may vary depending on your needs.

Frequently asked questions

What is the Securing and Hardening of your Microsoft 365 Environment service?

Securing and Hardening of your Microsoft 365 Environment is a 1-week Microsoft 365 security engagement in which IT Partner analyzes your Microsoft 365 organization, reviews security controls and settings, and develops a prioritized plan to reduce risk. The service is based on Microsoft best practices and is intended to make the Microsoft 365 environment safer and more secure.

What is included in this Microsoft 365 security hardening engagement?

The engagement includes a service-level security review, Microsoft 365 environment analysis, Secure Score improvement activities, review or implementation of built-in security tools and features, and a prioritized plan of changes. It also covers areas such as anti-malware, patching and configuration management, advanced threat protection, multi-factor authentication, customer security controls, and privacy controls within the stated Microsoft 365 scope.

What deliverables will we receive at the end of the engagement?

You will receive a prioritized security improvement plan based on Microsoft best practices, a comprehensive report, and a project closeout report. The closeout report indicates final project status, evidence of matching acceptance criteria, outstanding issues if any, and the final budget.

How long does the Microsoft 365 hardening service take?

The stated duration for this service is 1 week. The plan may vary depending on your needs, so specific scheduling, milestones, and effort should be confirmed with IT Partner during scoping and kickoff.

How is this service priced?

The service is priced at $175 per hour, and the listed SKU is ITPWW140IMPOT. Because the service is hourly, the final budget may depend on the approved scope, required changes, customer readiness, and any outstanding issues documented at closeout.

What prerequisites are required before starting the engagement?

A Microsoft 365 subscription is required for this service. Windows 10 Pro or Enterprise licenses and an Enterprise Mobility + Security subscription are recommended because the service focuses on Microsoft 365 security, managed Windows 10 devices, and Enterprise Mobility + Security capabilities.

Do we need Enterprise Mobility + Security for the service?

Enterprise Mobility + Security is recommended but not listed as a mandatory prerequisite. If you do not have EM+S, IT Partner can still assess and work within the available Microsoft 365 capabilities, but some security controls may depend on licensing and should be confirmed during planning.

Do we need Windows 10 Pro or Enterprise devices?

Windows 10 Pro or Enterprise licenses are recommended because one of the service’s security pillars is updated and managed Windows 10 on your devices. If your device estate differs, IT Partner should confirm which hardening recommendations and implementation steps are applicable.

What happens during the engagement?

The engagement typically includes a kickoff meeting, research into customer security requirements, analysis of the Microsoft 365 environment, approval of a plan of changes, implementation of built-in security tools and features, post-implementation analysis, and development of a comprehensive report. These milestones help ensure the work is reviewed, approved, implemented, and documented.

Will IT Partner implement security changes or only provide recommendations?

The service includes both development of a prioritized plan and implementation of built-in security tools and features. Specific changes are subject to approval through the plan of changes and may vary depending on your Microsoft 365 environment, licensing, and requirements.

Does the service include Microsoft Secure Score improvement?

Yes, Secure Score increasing is listed as an IT Partner service area for this engagement. Secure Score improvements are handled as part of the broader security review and hardening effort, based on Microsoft best practices and the controls available in your environment.

Does the service include multi-factor authentication configuration?

Yes, multi-factor authentication is included in the areas IT Partner addresses during the service. The exact MFA configuration approach depends on your current Microsoft 365 setup, licensing, security requirements, and approved plan of changes.

Will this engagement cause downtime or disrupt users?

The service description does not specify expected downtime or user impact. Because security changes such as MFA, policy adjustments, or configuration changes can affect users, any business impact should be reviewed and approved during the plan of changes before implementation.

What responsibilities does IT Partner have during the service?

IT Partner can provide a service-level security review, Secure Score improvement, anti-malware, patching and configuration management, advanced threat protection, customer security controls, multi-factor authentication, and privacy controls within the engagement scope. IT Partner also analyzes the environment, implements approved built-in security features, performs post-implementation analysis, and prepares the reports.

What responsibilities does the client have during the service?

The client must coordinate internal resources and schedules, assign a dedicated point of contact, provide information needed for the statement of work, and provide required service accounts with appropriate rights. The client is also responsible for coordinating outside vendors, configuring network equipment such as firewalls and switches, reviewing deliverables, and requesting or approving change tickets when change management is used.

What access does IT Partner need to perform the engagement?

The client must provide an account in the required services with the rights necessary to implement the service. The exact permissions should be confirmed during scoping, because required access depends on the Microsoft 365 services, security controls, and approved implementation tasks.

Is training included for our IT or security team?

No, training customer teams is not included in the stated scope of this service. If training is required, it should be discussed separately with IT Partner as an additional requirement.

Is detailed documentation included?

The included documentation consists of a comprehensive report and a project closeout report. More extensive documentation beyond the project closeout report can be provided for an additional fee, but the service description does not define the documentation types or pricing, so those details should be confirmed with IT Partner.

What happens after the security hardening work is completed?

After implementation, IT Partner performs post-implementation analysis and develops a comprehensive report. The engagement concludes with a project closeout report that documents final status, evidence against acceptance criteria, outstanding issues if any, and the final budget.

Are acceptance criteria defined for this engagement?

The service states that the project closeout report will include evidence of matching acceptance criteria, but it does not define specific measurable acceptance criteria beyond making the Microsoft 365 environment safer and more secure. If your organization needs formal success metrics, they should be defined with IT Partner before or during the kickoff and planning stages.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$175 per hour
1 week
Book a meeting