Default does not
mean secure.
Legacy authentication, open sharing, unfiltered mail rules, guest access without limits: that is how a Microsoft 365 tenant ships — it is not set up for defence. We review Exchange Online, SharePoint, Teams, Intune and Microsoft Entra ID against the CIS benchmark and Microsoft recommendations, and name the operational impact of every change.
What is included.
Configure the tenant the way Microsoft does not ship it.
Identity and access
Conditional Access, MFA methods, legacy auth, guest and external sharing, app consent.
Exchange Online
Transport rules, forwarding, anti-phishing, DKIM/DMARC, mailbox auditing.
SharePoint, Teams, Intune
Sharing boundaries, device compliance, app protection, data classification.
Logging and alerting
Unified audit log, retention, Defender alert rules, forwarding to your SIEM.
Five steps,
one deliverable.
Export
Capture tenant configuration read-only.
Comparison
Against CIS and Microsoft guidance.
Assessment
Each finding with its risk and operational impact.
Planning
Sequence, pilot groups, user communication.
Implementation
With your team on request, change by change.