First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Security 30 Days Service
Security and Protection

Microsoft 365 Security 30 Days Service — Tenant Security Configuration & Protection

Microsoft 365 Security 30 Days Service is a 30 days service for organizations that already have a Microsoft 365 tenant and need a basic secured Microsoft 365 environment planned, configured, and validated. IT Partner gathers information about the current tenant and security configurations, performs core Microsoft 365 tenant security configuration, checks and configures the security score up to 75%, enforces Threat Protection, configures Azure Active Directory Identity Protection, configures Teams protection, validates the defined security outcomes, and provides a project closeout report.

Timeline 30 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner will perform the necessary configurations of your Microsoft 365 tenant to set up a basic secured environment. The objective is to provide a plan and design a way to enable core Microsoft 365 security features, based on your business needs and current security configuration. The plan may vary depending on your needs. Service details: SKU ITPWW030SECOT; price 2000; duration 30 days; manager Roman Sotnik; date 2019-07-10; products Office 365, microsoft 365; type Security and Protection.

Success criteria

01Security score 75%. User can access Security Portal and confirm this.
02Validated Threat protection settings
03Validated Identity and access management settings
04Exchange Online Protection is configured and working
05Teams protection is configured

What you receive

Core configuration of your Microsoft 365 tenant, including basic admin protections, logging and analytics configuration, and basic identity protection setup.
Security score checked and configured up to 75%.
Threat Protection enforced, e.g. connecting M365 to MS Defender for Cloud Apps.
Azure Active Directory Identity Protection configured.
Teams configured with three tiers of protection, including sharing, classification, data loss prevention, and Azure Information Protection.
Validated Threat protection settings.
Validated Identity and access management settings.
Exchange Online Protection configured and working.
Teams protection configured.
Project closeout report indicating the final project status, including acceptance criteria matching, outstanding issues, if any, and the final budget.

How the work unfolds

Kickoff meeting

Start the engagement and coordinate the work.

Security scope check and current configuration assessment

Review the security scope and assess the current configuration.

User creation or AD connect tool configuration

Complete user creation or AD connect tool configuration.

Security configuration start

Begin the security configuration work.

Security settings verification

Verify the configured security settings.

Security score verification

Verify the security score.

Final email

Send the final email.

Verification and fixing of issues, if any

Verify the results and fix issues, if any.

Prerequisites

You must have a Microsoft 365 tenant

Who does what

IT Partner

  • Gather information about your current tenant and security configurations
  • Perform core configuration of your Microsoft 365 tenant: Basic admin protections; Logging and analytics configuration; Basic identity protection setup
  • Checking security score and configuring it up to 75%
  • Enforcing Threat Protection, e.g. connecting M365 to MS Defender for Cloud Apps
  • Configuring Azure Active Directory Identity Protection
  • Configuring Teams with three tiers of protection (including sharing, classification, data loss prevention, and Azure Information Protection)

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Coordinate any outside vendor resources and schedules
  • Perform changes to internal and external DNS, as required
  • Configure all network equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner
  • Assist with identification of high-risk users (admins, top executives and VIP users)
  • End user support

What's not included

Additional licenses that may be required
Customer team training (could be added as an additional service)
Corporate documents migration to SharePoint Online (could be added as an additional service)
Desktop software settings
Information Security Advisory services (could be added as an additional service)
More extensive documentation than the project closeout report can be provided for an additional fee.

Limitations & technical notes

!The source description references providing expertise and unbiased guidance on the best way to implement endpoint detection and response in the security architecture. However, endpoint detection and response implementation is not listed as a defined deliverable, responsibility, or success criterion in the published scope. If the customer requires Microsoft Defender for Endpoint deployment, device onboarding, endpoint baseline hardening, EDR policy tuning, alert triage processes, or incident response runbooks, that work should be confirmed with IT Partner and scoped separately or added by change order.
!Some security capabilities in this service may require licenses that are not included in the service price. Depending on the tenant’s current subscriptions and the selected configuration, this may include Microsoft Entra ID P2 / Azure AD Premium P2 for Identity Protection risk-based policies, Microsoft Defender for Office 365 for advanced email and collaboration protection, Microsoft Defender for Cloud Apps for cloud app discovery/session controls and related integrations, and Microsoft Purview / Azure Information Protection licensing for classification, labeling, and DLP capabilities. Final license requirements should be confirmed during assessment before configuration changes are applied.
!The target security score of 75% depends on the customer’s licensing, current tenant configuration, approved policy decisions, and willingness to enable the recommended controls. If a recommended control is not licensed, is operationally unsuitable, or is rejected by the customer, IT Partner will document the constraint and any remaining gap in the project closeout report.
!Security configuration changes can affect sign-in behavior, administrator access, Teams sharing, mail flow protection, and user access patterns. Any potentially user-impacting settings should be reviewed with the customer point of contact and scheduled appropriately.

Frequently asked questions

What is the Microsoft 365 Security 30 Days Service?

Microsoft 365 Security 30 Days Service is a 30-day engagement for organizations that already have a Microsoft 365 tenant and need a basic secured Microsoft 365 environment planned, configured, and validated. IT Partner assesses the current tenant and security configuration, applies core Microsoft 365 security settings, works toward a security score of up to 75%, validates key security outcomes, and provides a project closeout report.

What is included in the Microsoft 365 Security 30 Days Service?

The service includes core Microsoft 365 tenant security configuration, including basic admin protections, logging and analytics configuration, and basic identity protection setup. It also includes security score checking and configuration up to 75%, Threat Protection enforcement, Azure Active Directory Identity Protection configuration, Teams protection configuration, validation of threat protection and identity settings, Exchange Online Protection validation, and a project closeout report.

What Microsoft 365 security outcomes are expected from this service?

The stated success criteria are a Microsoft 365 security score of 75%, validated Threat Protection settings, validated identity and access management settings, Exchange Online Protection configured and working, and Teams protection configured. These outcomes are validated during the engagement and summarized in the project closeout report, including any outstanding issues if they exist.

How long does the Microsoft 365 Security 30 Days Service take?

The service duration is 30 days. During that period, IT Partner runs the kickoff, assesses the current configuration, performs security configuration, verifies settings, verifies the security score, addresses issues if any, and sends the final project communication.

What is the price of the Microsoft 365 Security 30 Days Service?

The published service price is 2000 for SKU ITPWW030SECOT. Additional Microsoft licenses may be required and are not included in the service price, so the exact total cost should be confirmed with IT Partner based on the tenant’s current licensing and required security capabilities.

What prerequisites must be in place before this service starts?

The required prerequisite is an existing Microsoft 365 tenant. Because the service configures and validates security in an existing tenant, organizations that do not yet have a tenant should confirm with IT Partner whether a separate setup service is needed first.

What happens during the engagement?

The engagement starts with a kickoff meeting, then IT Partner checks the security scope and assesses the current Microsoft 365 configuration. The implementation plan includes user creation or AD Connect tool configuration if required, starting security configuration, verifying security settings, verifying the security score, sending the final email, and fixing issues if any are found.

What Microsoft 365 products or areas does this service cover?

The service is focused on Office 365 and Microsoft 365 security and protection. The defined scope includes Microsoft 365 tenant security configuration, security score, Threat Protection, Microsoft Defender for Cloud Apps connection as an example of Threat Protection enforcement, Azure Active Directory Identity Protection, Exchange Online Protection, and Teams protection.

Does this service configure Microsoft Teams security?

Yes, Teams protection is included in the defined scope. IT Partner configures Teams with three tiers of protection, including sharing, classification, data loss prevention, and Azure Information Protection, and Teams protection is one of the stated success criteria.

Does this service configure Exchange Online Protection?

Yes, Exchange Online Protection is included as a validated outcome of the service. The success criteria state that Exchange Online Protection must be configured and working, and the deliverables include confirmation of that configuration.

Does this service include Azure Active Directory Identity Protection?

Yes, Azure Active Directory Identity Protection configuration is included. The service also validates identity and access management settings as part of the expected security outcomes.

Does this service include Microsoft Defender for Cloud Apps?

The service includes enforcing Threat Protection, with connecting Microsoft 365 to Microsoft Defender for Cloud Apps listed as an example. If your organization needs a specific Defender for Cloud Apps design, licensing review, or advanced configuration beyond the stated Threat Protection scope, confirm those details with IT Partner before starting.

Does this service implement endpoint detection and response?

Endpoint detection and response implementation is not listed as a defined deliverable, responsibility, or success criterion for this service. The source description does reference expertise and unbiased guidance on endpoint detection and response, so any required endpoint detection and response work should be confirmed with IT Partner before starting.

What is not included in the Microsoft 365 Security 30 Days Service?

The service does not include additional licenses, customer team training, corporate document migration to SharePoint Online, desktop software settings, or Information Security Advisory services. More extensive documentation than the project closeout report is also not included but may be available for an additional fee.

Are Microsoft licenses included in the service price?

No, additional licenses that may be required are not included. The service description does not specify which licenses may be needed, so licensing requirements should be reviewed with IT Partner based on your current Microsoft 365 subscription and desired security features.

What are IT Partner’s responsibilities during the service?

IT Partner gathers information about the current tenant and security configurations, performs the core Microsoft 365 tenant security configuration, checks and configures the security score up to 75%, enforces Threat Protection, configures Azure Active Directory Identity Protection, and configures Teams protection. IT Partner also validates the defined security settings and provides the project closeout report.

What are the client’s responsibilities during the service?

The client must coordinate internal resources and schedules, provide a dedicated point of contact, coordinate outside vendors if needed, make required internal or external DNS changes, configure network equipment such as load balancers, routers, firewalls, and switches, and review deliverables promptly. The client also helps identify high-risk users such as admins, executives, and VIP users, and remains responsible for end user support.

Will this service cause downtime or affect users?

The service description does not define a specific downtime window or guarantee no user impact. Because security changes can affect sign-in, sharing, access policies, mail protection, or Teams behavior, scheduling and communication should be coordinated with IT Partner and the client’s point of contact before changes are applied.

What documentation is provided at the end of the service?

IT Partner provides a project closeout report indicating the final project status, acceptance criteria matching, outstanding issues if any, and the final budget. More extensive documentation than the closeout report is not included in the base service and may require an additional fee.

What happens if issues are found during validation?

The implementation plan includes verification and fixing of issues, if any. Any remaining outstanding issues are documented in the project closeout report, along with the final project status and acceptance criteria matching.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,000
30 days
Book a meeting