First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Securing and Hardening Your On-premises IT Environment
Implementation

Securing and Hardening Your On-premises IT Environment — SCCM Security Implementation

IT Partner helps organizations improve the security of their existing on-premises IT environment by analyzing infrastructure and applying security best practices to systems, devices, administrative access, endpoints, storage, operating systems, firewall and network settings, and update policies. This is an SCCM Implementation service, SKU ITPWW150IMPOT, priced at $90 per hour, with a duration of 1 week and Mike Mackey as manager.

Timeline 1 weekService owner Mike MackeySCCM

What this engagement is

This service focuses on making your on-premises IT infrastructure safer and more secure using the systems, devices, and technologies you already use. IT Partner analyzes the environment, helps apply security best practices, verifies the changes, and provides a project closeout report. Security requirements can vary for different types of workloads. Service details: SKU ITPWW150IMPOT; price $90 per hour; duration 1 week; manager Mike Mackey; product taxonomy SCCM; service type Implementation; date 2018-07-30.

Success criteria

01You will have a more secure on-premises environment in accordance with best practices.
02Kickoff is completed and the in-scope systems, workloads, administrative roles, and access requirements are confirmed with the client.
03An on-premises health check is completed for the agreed scope, and key findings are reviewed with the client.
04Agreed hardening changes are applied or documented as recommended, deferred, not applicable, or outside scope.
05Administrative access, endpoint access, storage encryption, operating system management, firewall and network settings, and update policy/software posture are reviewed against applicable best practices for the in-scope environment.
06Changes implemented by IT Partner are validated for expected operation, and any known outstanding issues are documented in the closeout report.
07A project closeout report is delivered with final project status, evidence of completed work, outstanding issues, and final budget information.

What you receive

A more secure on-premises environment in accordance with best practices.
Project closeout report indicating the final project status, including evidence of meeting acceptance criteria, any outstanding issues, and the final budget.

How the work unfolds

Kickoff meeting

Start the project with a kickoff meeting.

On-premises health check

Perform an on-premises health check.

Start securing process

Begin the securing process.

Verify changes

Verify the changes made during the securing process.

Finalize changes

Finalize the changes.

Post-assessment tasks, if any

Complete post-assessment tasks, if any.

Prerequisites

Provide a dedicated point of contact responsible for working with IT Partner and coordinate any outside vendor resources and schedules.
Configure all networking equipment, such as load balancers, routers, firewalls, and switches.
Provide access to physical and virtual servers and/or systems and services, as needed. Provide remote and/or physical access to facility and systems required to complete work.
Provide a list of in-scope servers, endpoints, administrative accounts, network segments, critical applications, and business owners.
Provide approved administrative access, or a client operator with equivalent access, for in-scope systems, SCCM/management tools, directory services, security tools, and relevant consoles.
Provide current network diagrams, system documentation, Group Policy/security policy information, patching process details, and any known operational constraints.
Confirm maintenance windows, change approval requirements, rollback contacts, and communication procedures before changes are made.
Ensure recent backups, snapshots, or other recovery options are available for systems where configuration changes may be applied.
Confirm that any required licensing, subscriptions, or existing tools for MFA, endpoint management, encryption, or security monitoring are available before implementation.
Identify any regulated workloads, high-availability systems, legacy applications, or vendor-managed systems that require special handling.

Who does what

IT Partner

  • Analyze IT infrastructure
  • Use Privileged Access Workstations
  • Use Multi-Factor Authentication
  • Limit and constrain administrative access
  • Control and limit endpoint access
  • Encrypt virtual disks and disk storage
  • Manage operating systems
  • Firewall and network settings
  • Update policy and software review

Your team

  • Provide a dedicated point of contact responsible for working with IT Partner and coordinate any outside vendor resources and schedules
  • Configure all networking equipment, such as load balancers, routers, firewalls, and switches
  • Provide access to physical and virtual servers and/or systems and services, as needed. Provide remote and/or physical access to facility and systems required to complete work.

What's not included

Migration and deployment

Limitations & technical notes

!Security requirements can vary for different types of workloads.
!The plan may vary depending on your needs.
!More extensive documentation can be provided for an additional fee.

Frequently asked questions

What is included in IT Partner’s Securing and Hardening Your On-premises IT Environment service?

IT Partner’s Securing and Hardening Your On-premises IT Environment service includes analysis of your on-premises IT infrastructure and application of security best practices to systems, devices, administrative access, endpoints, storage, operating systems, firewall and network settings, and update policies. The engagement also includes verification of changes and a project closeout report documenting final status, evidence of meeting acceptance criteria, outstanding issues, and final budget.

What is the main outcome of this on-premises security hardening service?

The main outcome is a more secure on-premises environment in accordance with best practices. IT Partner achieves this by reviewing the existing infrastructure, applying agreed security improvements, verifying the changes, and documenting the final project status.

How long does the Securing and Hardening Your On-premises IT Environment engagement take?

The stated duration for IT Partner’s Securing and Hardening Your On-premises IT Environment service is 1 week. The actual plan may vary depending on your needs, so any environment-specific scheduling details should be confirmed with IT Partner during scoping or kickoff.

How is this service priced?

IT Partner’s Securing and Hardening Your On-premises IT Environment service is priced at $90 per hour. The service SKU is ITPWW150IMPOT, and the listed service duration is 1 week.

What happens during the engagement?

The engagement starts with a kickoff meeting, followed by an on-premises health check, the start of the securing process, verification of changes, finalization of changes, and any post-assessment tasks. This sequence helps IT Partner understand the current environment, apply hardening measures, and confirm the work before closeout.

What security areas does IT Partner review or harden?

IT Partner reviews and hardens areas such as administrative access, endpoint access, virtual disks and disk storage, operating systems, firewall and network settings, and update policies. The service also includes practices such as using Privileged Access Workstations, using Multi-Factor Authentication, and limiting or constraining administrative access where appropriate.

Does this service include migration or deployment work?

No, migration and deployment are specifically not included in this service. The engagement is focused on securing and hardening the existing on-premises IT environment rather than moving workloads or deploying new infrastructure.

What are the customer prerequisites for this service?

The customer must provide a dedicated point of contact to work with IT Partner and coordinate any outside vendor resources and schedules. The customer is also responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches, and for providing remote and/or physical access to required facilities, servers, systems, and services.

What is IT Partner responsible for during the hardening engagement?

IT Partner is responsible for analyzing the IT infrastructure and applying security best practices across areas such as privileged access, MFA, administrative access constraints, endpoint access, storage encryption, operating system management, firewall and network settings, and update policy and software review. IT Partner also verifies changes and provides a project closeout report.

What is the client responsible for during the hardening engagement?

The client is responsible for assigning a dedicated point of contact, coordinating any outside vendors, configuring required networking equipment, and providing access to physical and virtual servers, systems, services, and facilities. These responsibilities matter because IT Partner needs timely access and coordination to complete the hardening work within the planned engagement.

Will this service cause downtime or business disruption?

The service description does not specify whether downtime is required. Because security changes to firewalls, operating systems, endpoint access, administrative access, storage, or update policies can affect operations, downtime expectations and maintenance windows should be confirmed with IT Partner during kickoff and planning.

Does IT Partner configure firewalls, routers, switches, and other network equipment?

The client is responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches. IT Partner’s scope includes firewall and network settings as part of the security hardening review, but any exact division of hands-on configuration work should be confirmed with IT Partner before the engagement begins.

Does the service include Multi-Factor Authentication and Privileged Access Workstations?

Yes, the service scope includes using Multi-Factor Authentication and Privileged Access Workstations as part of security best practices. It also includes limiting and constraining administrative access to reduce risk in the on-premises environment.

Does this service address endpoint access and storage encryption?

Yes, IT Partner’s responsibilities include controlling and limiting endpoint access and encrypting virtual disks and disk storage. These activities are part of the broader hardening effort to improve the security posture of the existing on-premises environment.

Does IT Partner review update policies and installed software?

Yes, the service includes update policy and software review. IT Partner also addresses operating system management as part of the on-premises hardening effort.

What deliverables are provided at the end of the service?

The deliverables are a more secure on-premises environment in accordance with best practices and a project closeout report. The closeout report includes final project status, evidence of meeting acceptance criteria, any outstanding issues, and the final budget.

Are measurable acceptance criteria defined for this service?

The service states that the closeout report includes evidence of meeting acceptance criteria, but it does not define specific measurable acceptance criteria in the provided scope. Customers should confirm the exact acceptance criteria with IT Partner during kickoff or project planning.

Can the hardening plan vary by workload or environment?

Yes, the service notes that security requirements can vary for different types of workloads and that the plan may vary depending on customer needs. IT Partner’s recommendations should therefore be confirmed against the specific systems, workloads, and risks in the customer’s on-premises environment.

Is detailed documentation included with the service?

The included documentation is the project closeout report showing final project status, evidence of meeting acceptance criteria, outstanding issues, and final budget. More extensive documentation can be provided for an additional fee.

Who manages this service and what is its service classification?

The service manager listed for Securing and Hardening Your On-premises IT Environment is Mike Mackey. The service is classified under the SCCM product taxonomy as an Implementation service, with SKU ITPWW150IMPOT.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$90 per hour
1 week
Book a meeting