HomeServices › Microsoft 365

Productized security

Your tenant is the front door. Most are left on the factory settings.

Microsoft 365 ships configured for adoption, not for security. Identity, sharing, guest access and device rules all default open. Closing them costs nothing in licensing and is the highest-value work we do.

Included from the tier shown below. Month to month, cancel any time.

ResistCyber guide

What we actually do

Identity hardening

Multi-factor authentication on everyone including administrators, legacy authentication blocked, phishing-resistant methods where they fit, and conditional access policies rolled out in report-only mode before anything is enforced.

Break-glass accounts

Emergency access accounts, excluded from policy, credentials secured offline. Without them a misconfigured rule can lock you out of your own tenant permanently. Almost nobody has these until we set them up.

Administrative separation

Day-to-day accounts should not hold administrative rights. Where licensing allows, privileged roles are granted just in time rather than standing.

Sharing and collaboration controls

External sharing defaults, anonymous link expiry, guest access rules, and governance over who can create teams and sites. Left alone, this sprawls quietly for years.

Secure Score tracked

Microsoft scores your tenant's posture. We record yours at onboarding and report it monthly, so progress is measured by Microsoft's number rather than our opinion.

A person stays in the loop. Every policy is reviewed in report-only mode and signed off before enforcement. We would rather spend an extra week than lock your staff out of their own systems on a Monday morning.
What you need to have. Conditional access requires Microsoft Entra ID P1, included in Business Premium and Microsoft 365 E3. Risk-based policies and Privileged Identity Management require P2, which is an add-on for most plans. You keep your own Microsoft licensing — we do not resell it, and we will always tell you what you already own before suggesting you buy anything.

Which package includes it

PackageMicrosoft 365
MonitorIncluded
ProtectIncluded
Resist 365Included
CompleteIncluded

Common questions

We already use Microsoft 365. Is it not secure already?

It is capable of being secure. Out of the box the defaults favor ease of adoption — open sharing, no conditional access, legacy protocols enabled. The capability is bought; the configuration is not.

Will tightening this annoy our staff?

Some of it changes how people work, which is why it goes out in stages with warning rather than overnight. Done well, most users notice only that sign-in works differently.

Do you need full admin access to our tenant?

We need delegated administrative access, scoped and documented in your agreement, reviewed periodically, and revoked when we part ways. It is written down rather than assumed.

Ready when you are.

Every package includes this. Pick the tier that fits.

See packages

Other services

RMMRemote monitoring and management for visibility, maintenan… Endpoint ProtectionManaged protection for devices, users, and business endpoi… Patch ManagementSecurity updates and maintenance without relying on manual… EDR / MDRSupport for stronger detection, response, and threat visib… Email SecurityProtection against phishing, malicious email, and account… Cloud BackupBackup readiness and recovery planning for business contin… Microsoft Defender XDRUnified endpoint, identity, email, and cloud protection ac…