Microsoft 365 Security Hardening — Secure Configuration & Risk Reduction
Securing and Hardening of your Microsoft 365 Environment is a 1-week Microsoft 365 security engagement for organizations that want certified engineers to analyze their Microsoft 365 organization's security, review existing and optional security controls and settings, and develop a prioritized plan according to Microsoft best-practices to increase security and reduce risks. Service details: SKU ITPWW140IMPOT; price $175 per hour; duration 1 week; manager Roman Sotnik.
What this engagement is
IT Partner analyzes your Microsoft 365 organization's security based on your regular activities and security settings, then develops a plan according to Microsoft recommendations to increase security and reduce risks. The objective is to make your Microsoft 365 environment safe and secure. The service focuses on three security pillars stated in the source: updated and managed Windows 10 on your devices, a correctly configured Microsoft 365 environment, and Enterprise Mobility + Security services.
Success criteria
What you receive
How the work unfolds
Kickoff meeting.
Research customer security requirements.
Analyze your Microsoft 365 environment.
Approve a plan of changes.
Implement built-in security tools and features.
Perform post-implementation analysis.
Develop a comprehensive report.
Prerequisites
Who does what
IT Partner
- Service-level security review
- Secure Score increasing
- Anti-malware, patching, and configuration management
- Advanced threat protection
- Customer controls for security
- Multi-factor authentication
- Customer controls for privacy
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Provide all the necessary information for the statement of work preparation
- Provide an account in the required services with the rights necessary to implement the service
- Coordinate any outside vendor resources and schedules
- Configure all network equipment, such as load balancers, routers, firewalls, and switches
- Review and approve engagement deliverables in a timely manner
- Request and approve all change management tickets (if available) in the Client environment
What's not included
Limitations & technical notes
Frequently asked questions
What is the Securing and Hardening of your Microsoft 365 Environment service?
Securing and Hardening of your Microsoft 365 Environment is a 1-week Microsoft 365 security engagement in which IT Partner analyzes your Microsoft 365 organization, reviews security controls and settings, and develops a prioritized plan to reduce risk. The service is based on Microsoft best practices and is intended to make the Microsoft 365 environment safer and more secure.
What is included in this Microsoft 365 security hardening engagement?
The engagement includes a service-level security review, Microsoft 365 environment analysis, Secure Score improvement activities, review or implementation of built-in security tools and features, and a prioritized plan of changes. It also covers areas such as anti-malware, patching and configuration management, advanced threat protection, multi-factor authentication, customer security controls, and privacy controls within the stated Microsoft 365 scope.
What deliverables will we receive at the end of the engagement?
You will receive a prioritized security improvement plan based on Microsoft best practices, a comprehensive report, and a project closeout report. The closeout report indicates final project status, evidence of matching acceptance criteria, outstanding issues if any, and the final budget.
How long does the Microsoft 365 hardening service take?
The stated duration for this service is 1 week. The plan may vary depending on your needs, so specific scheduling, milestones, and effort should be confirmed with IT Partner during scoping and kickoff.
How is this service priced?
The service is priced at $175 per hour, and the listed SKU is ITPWW140IMPOT. Because the service is hourly, the final budget may depend on the approved scope, required changes, customer readiness, and any outstanding issues documented at closeout.
What prerequisites are required before starting the engagement?
A Microsoft 365 subscription is required for this service. Windows 10 Pro or Enterprise licenses and an Enterprise Mobility + Security subscription are recommended because the service focuses on Microsoft 365 security, managed Windows 10 devices, and Enterprise Mobility + Security capabilities.
Do we need Enterprise Mobility + Security for the service?
Enterprise Mobility + Security is recommended but not listed as a mandatory prerequisite. If you do not have EM+S, IT Partner can still assess and work within the available Microsoft 365 capabilities, but some security controls may depend on licensing and should be confirmed during planning.
Do we need Windows 10 Pro or Enterprise devices?
Windows 10 Pro or Enterprise licenses are recommended because one of the service’s security pillars is updated and managed Windows 10 on your devices. If your device estate differs, IT Partner should confirm which hardening recommendations and implementation steps are applicable.
What happens during the engagement?
The engagement typically includes a kickoff meeting, research into customer security requirements, analysis of the Microsoft 365 environment, approval of a plan of changes, implementation of built-in security tools and features, post-implementation analysis, and development of a comprehensive report. These milestones help ensure the work is reviewed, approved, implemented, and documented.
Will IT Partner implement security changes or only provide recommendations?
The service includes both development of a prioritized plan and implementation of built-in security tools and features. Specific changes are subject to approval through the plan of changes and may vary depending on your Microsoft 365 environment, licensing, and requirements.
Does the service include Microsoft Secure Score improvement?
Yes, Secure Score increasing is listed as an IT Partner service area for this engagement. Secure Score improvements are handled as part of the broader security review and hardening effort, based on Microsoft best practices and the controls available in your environment.
Does the service include multi-factor authentication configuration?
Yes, multi-factor authentication is included in the areas IT Partner addresses during the service. The exact MFA configuration approach depends on your current Microsoft 365 setup, licensing, security requirements, and approved plan of changes.
Will this engagement cause downtime or disrupt users?
The service description does not specify expected downtime or user impact. Because security changes such as MFA, policy adjustments, or configuration changes can affect users, any business impact should be reviewed and approved during the plan of changes before implementation.
What responsibilities does IT Partner have during the service?
IT Partner can provide a service-level security review, Secure Score improvement, anti-malware, patching and configuration management, advanced threat protection, customer security controls, multi-factor authentication, and privacy controls within the engagement scope. IT Partner also analyzes the environment, implements approved built-in security features, performs post-implementation analysis, and prepares the reports.
What responsibilities does the client have during the service?
The client must coordinate internal resources and schedules, assign a dedicated point of contact, provide information needed for the statement of work, and provide required service accounts with appropriate rights. The client is also responsible for coordinating outside vendors, configuring network equipment such as firewalls and switches, reviewing deliverables, and requesting or approving change tickets when change management is used.
What access does IT Partner need to perform the engagement?
The client must provide an account in the required services with the rights necessary to implement the service. The exact permissions should be confirmed during scoping, because required access depends on the Microsoft 365 services, security controls, and approved implementation tasks.
Is training included for our IT or security team?
No, training customer teams is not included in the stated scope of this service. If training is required, it should be discussed separately with IT Partner as an additional requirement.
Is detailed documentation included?
The included documentation consists of a comprehensive report and a project closeout report. More extensive documentation beyond the project closeout report can be provided for an additional fee, but the service description does not define the documentation types or pricing, so those details should be confirmed with IT Partner.
What happens after the security hardening work is completed?
After implementation, IT Partner performs post-implementation analysis and develops a comprehensive report. The engagement concludes with a project closeout report that documents final status, evidence against acceptance criteria, outstanding issues if any, and the final budget.
Are acceptance criteria defined for this engagement?
The service states that the project closeout report will include evidence of matching acceptance criteria, but it does not define specific measurable acceptance criteria beyond making the Microsoft 365 environment safer and more secure. If your organization needs formal success metrics, they should be defined with IT Partner before or during the kickoff and planning stages.