First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft 365 Security 30 Days Service
Security and Protection

Microsoft 365 Security 30 Days Service — Tenant Security Configuration & Protection

Microsoft 365 Security 30 Days Service is a 30-day service for organizations that already have a Microsoft 365 tenant and need a basic secured Microsoft 365 environment planned, configured, and validated. IT Partner gathers information about the current tenant and security configurations, performs core Microsoft 365 tenant security configuration, checks and configures the security score up to 75%, enforces Threat Protection, configures Microsoft Entra ID Protection, configures Teams protection, validates the defined security outcomes, and provides a project closeout report.

Timeline 30 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner will perform the necessary configurations of your Microsoft 365 tenant to set up a basic secured environment. The objective is to provide a plan and design a way to enable core Microsoft 365 security features, based on your business needs and current security configuration. The plan may vary depending on your needs.

Success criteria

01Microsoft Secure Score improved toward the agreed 75% target; the customer can confirm the score in the Microsoft Defender portal.
02Validated Threat protection settings
03Validated Identity and access management settings
04Exchange Online Protection is configured and working
05Teams protection is configured

What you receive

Core configuration of your Microsoft 365 tenant, including basic admin protections, logging and analytics configuration, and basic identity protection setup.
Microsoft Secure Score checked and configured up to the 75% target.
Threat protection enforced, for example connecting Microsoft 365 to Microsoft Defender for Cloud Apps.
Microsoft Entra ID Protection configured.
Teams configured with three tiers of protection, including sharing, classification, data loss prevention, and Microsoft Purview Information Protection sensitivity labels.
Validated Threat protection settings.
Validated Identity and access management settings.
Exchange Online Protection configured and working.
Teams protection configured.
Project closeout report indicating the final project status, including acceptance criteria matching, outstanding issues, if any, and the final budget.

How the work unfolds

Kickoff meeting

Start the engagement, confirm scope and contacts, and coordinate the work.

Security scope check and current configuration assessment

Review the security scope and assess the current tenant and security configuration, including the Microsoft Secure Score baseline.

User creation or Microsoft Entra Connect configuration

Complete user creation or Microsoft Entra Connect configuration where required for the planned security controls.

Security configuration start

Apply the agreed core security configuration to the tenant.

Security settings verification

Verify the configured security settings against the agreed outcomes.

Security score verification

Verify Microsoft Secure Score progress toward the 75% target in the Microsoft Defender portal.

Final email

Send the final project summary with results and any remaining recommendations.

Verification and fixing of issues, if any

Verify results with the customer and fix in-scope issues, if any.

Prerequisites

You must have a Microsoft 365 tenant

Who does what

IT Partner

  • Gather information about your current tenant and security configurations
  • Perform core configuration of your Microsoft 365 tenant: Basic admin protections; Logging and analytics configuration; Basic identity protection setup
  • Checking Microsoft Secure Score and configuring it up to the 75% target
  • Enforcing Threat Protection, e.g. connecting Microsoft 365 to Microsoft Defender for Cloud Apps
  • Configuring Microsoft Entra ID Protection
  • Configuring Teams with three tiers of protection (including sharing, classification, data loss prevention, and Microsoft Purview Information Protection sensitivity labels)

Your team

  • Coordinate Client resources and staff schedules
  • Provide a dedicated point of contact responsible for working with IT Partner
  • Coordinate any outside vendor resources and schedules
  • Perform changes to internal and external DNS, as required
  • Configure all network equipment, such as load balancers, routers, firewalls, and switches
  • Review and approve engagement deliverables in a timely manner
  • Assist with identification of high-risk users (admins, top executives and VIP users)
  • End user support

What's not included

Additional licenses that may be required
Customer team training (could be added as an additional service)
Corporate documents migration to SharePoint Online (could be added as an additional service)
Desktop software settings
Information Security Advisory services (could be added as an additional service)
More extensive documentation than the project closeout report can be provided for an additional fee.

Limitations & technical notes

!Endpoint detection and response implementation — for example, Microsoft Defender for Endpoint deployment and device onboarding — is not a deliverable of this service. If EDR rollout, endpoint baseline hardening, EDR policy tuning, alert triage processes, or incident response runbooks are required, that work is scoped separately or added by change order.
!Some security capabilities in this service may require licenses that are not included in the service price. Depending on the tenant’s current subscriptions and the selected configuration, this may include Microsoft Entra ID P2 for Identity Protection risk-based policies, Microsoft Defender for Office 365 for advanced email and collaboration protection, Microsoft Defender for Cloud Apps for cloud app discovery/session controls and related integrations, and Microsoft Purview Information Protection licensing for classification, labeling, and DLP capabilities. Final license requirements should be confirmed during assessment before configuration changes are applied.
!The target security score of 75% depends on the customer’s licensing, current tenant configuration, approved policy decisions, and willingness to enable the recommended controls. If a recommended control is not licensed, is operationally unsuitable, or is rejected by the customer, IT Partner will document the constraint and any remaining gap in the project closeout report.
!Security configuration changes can affect sign-in behavior, administrator access, Teams sharing, mail flow protection, and user access patterns. Any potentially user-impacting settings should be reviewed with the customer point of contact and scheduled appropriately.

Frequently asked questions

What is the Microsoft 365 Security 30 Days Service?

Microsoft 365 Security 30 Days Service is a 30-day engagement for organizations that already have a Microsoft 365 tenant and need a basic secured Microsoft 365 environment planned, configured, and validated. IT Partner assesses the current tenant and security configuration, applies core Microsoft 365 security settings, works the Microsoft Secure Score toward the 75% target, validates key security outcomes, and provides a project closeout report.

What is included in the Microsoft 365 Security 30 Days Service?

The service includes core Microsoft 365 tenant security configuration — basic admin protections, logging and analytics configuration, and basic identity protection setup — plus Microsoft Secure Score configuration up to the 75% target, threat protection enforcement, Microsoft Entra ID Protection configuration, Teams protection configuration, validation of threat protection and identity settings, Exchange Online Protection validation, and a project closeout report.

What Microsoft 365 security outcomes are expected from this service?

The stated success criteria are Microsoft Secure Score improved toward the 75% target and confirmable in the Microsoft Defender portal, validated threat protection settings, validated identity and access management settings, Exchange Online Protection configured and working, and Teams protection configured. These outcomes are validated during the engagement and summarized in the project closeout report.

How long does the Microsoft 365 Security 30 Days Service take?

The service duration is 30 days. During that period, IT Partner runs the kickoff, assesses the current configuration, performs security configuration, verifies settings, verifies the security score, addresses issues if any, and sends the final project communication.

What is the price of the Microsoft 365 Security 30 Days Service?

The service is $2,000 per project, quoted fixed-price in writing before work begins. Additional Microsoft licenses that some security capabilities require are not included, so total cost should be confirmed against the tenant's current licensing.

What prerequisites must be in place before this service starts?

The required prerequisite is an existing Microsoft 365 tenant. Because the service configures and validates security in an existing tenant, organizations that do not yet have a tenant should confirm with IT Partner whether a separate setup service is needed first.

What happens during the engagement?

The engagement starts with a kickoff meeting, then IT Partner checks the security scope and assesses the current Microsoft 365 configuration. The plan continues with user creation or Microsoft Entra Connect configuration if required, security configuration, verification of security settings, verification of the Secure Score, the final project summary, and fixing of issues if any are found.

Does this service configure Microsoft Teams security?

Yes, Teams protection is included in the defined scope. IT Partner configures Teams with three tiers of protection, including sharing, classification, data loss prevention, and Microsoft Purview Information Protection sensitivity labels, and Teams protection is one of the stated success criteria.

Does this service include Microsoft Entra ID Protection?

Yes, Microsoft Entra ID Protection configuration is included. The service also validates identity and access management settings as part of the expected security outcomes. Risk-based policies depend on Microsoft Entra ID P2 licensing, which is confirmed during assessment.

Does this service implement endpoint detection and response?

No. Endpoint detection and response implementation — for example, Microsoft Defender for Endpoint deployment and device onboarding — is not a deliverable of this service. If EDR rollout is required, it is scoped separately with IT Partner.

Will this service cause downtime or affect users?

The service requires no planned Microsoft 365 downtime. Because security changes can affect sign-in, sharing, access policies, mail protection, and Teams behavior, potentially user-impacting settings are reviewed with your point of contact and scheduled appropriately before they are applied.

What is not included in the Microsoft 365 Security 30 Days Service?

The service does not include additional licenses, customer team training, corporate document migration to SharePoint Online, desktop software settings, or Information Security Advisory services. More extensive documentation than the project closeout report is also not included but may be available for an additional fee.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,000 per project
30 days
Book a meeting