Service datasheet
our Microsoft 365 security posture service
We measure what your Microsoft 365 and Entra tenant allows today, agree where it should be, and close the gap in stages you approve.
Who this is for
- Your tenant was set up years ago and has never had a formal security review
- MFA is on for most people, but nobody could say with certainty who is excluded and why
- Several people hold Global Administrator permanently, possibly including a former supplier
- A Cyber Essentials assessor, ISO 27001 auditor or client questionnaire wants evidence you cannot easily produce
- You want Conditional Access tightened but are wary of locking people out
What is included
- Assessment against Microsoft's Zero Trust Assessment, Maester tests and the CIS Microsoft 365 Foundations Benchmark
- A target state agreed with you, not imposed from a checklist
- A risk-ordered remediation plan, with identity first
- Conditional Access staged in report-only mode before anything enforces
- Two emergency access accounts in place before any policy goes live
- Every change approved by you through a change request
- Ongoing drift monitoring, so later changes do not undo the work
- Evidence for Cyber Essentials, ISO 27001 and client security questionnaires
What we would do
If your tenant has run for more than a couple of years without a structured review, start with an assessment against a recognised baseline and fix identity first: MFA for everyone, legacy authentication blocked, and fewer standing administrators. Those are the controls assessors and insurers ask about first.
- If you are a very small organisation on Microsoft's security defaults with no exceptions, you may not need this yet: security defaults already require MFA and block legacy authentication.
- If you already run Conditional Access with a named owner, regular reviews and change control, drift monitoring on its own may be all you need rather than a full assessment.
- If the immediate driver is certification, start with our Cyber Essentials service, which covers the tenant controls and the wider scope.
When we are not the answer
If you want a score pushed up as fast as possible regardless of what it breaks, we are the wrong provider. We stage every change and wait for your approval, which is slower than switching everything on at once and far less likely to lock your finance team out on a Monday.
What it costs
Scoped and quoted against your estate rather than sold from a rate card. We price what you already run, including the parts that are working and do not need replacing, and the quote itemises what is included so it can be compared line by line with anyone else’s. Managed IT support starts at £40 per user, per month if that is the wider question.
The next step, if you want one
Security posture review. 45 minutes, plus a written summary within three working days. You keep the written findings whether or not you engage us, and there is no sales call before it.
https://systechitsolutions.co.uk/book/security-posture
Not ready for that? The full service page is at https://systechitsolutions.co.uk/services/microsoft-security-posture, or call the number at the top of this sheet.
We will email it over
Useful if you are taking it into a meeting or attaching it to something. Name and email, that is all. One email, the datasheet, and nothing else unless you ask.
Want to keep a copy? Ask for the PDF above and you can save or print it from here too.
← Full detail on our microsoft 365 security posture service