# Creative Data Concepts Creative Data Concepts is a technical Microsoft 365 security configuration practice operated by Jim Nitterauer, CISSP and CISM, in Pensacola, Florida. The site is for IT Managers, Sysadmins, and IT Directors who need hands-on Microsoft 365 security hardening. ## Core Positioning - Brand: Creative Data Concepts - Website: https://creativedata.net - Contact: https://creativedata.net/contact - Owner/operator: Jim Nitterauer, CISSP, CISM - Services: fractional IT management plus fixed-scope Microsoft 365 security sprints and assessments - Target stack: Microsoft 365, Entra ID, Intune, Exchange Online, Microsoft Defender, SharePoint, Microsoft 365 Copilot - Delivery model: remote, fixed scope, fixed price - Related advisory brand: https://getaciso.ai ## Fractional IT Management - [Fractional IT Management](https://creativedata.net/fractional-it-management): ongoing Microsoft 365-focused IT and security management for lean teams that need senior ownership but not a full-time IT Director. Removes recurring roadmap, security backlog, Secure Score, vendor follow-up, audit readiness, and reporting burden from the internal IT team so important work stops losing to daily tickets. Pricing uses a monthly base fee plus a per-employee fee. - [Microsoft 365 MSP Oversight](https://creativedata.net/msp-oversight): senior oversight for SMBs that already have an MSP but need accountability for Microsoft 365 security, Secure Score, vendor follow-up, risk-ranked backlog ownership, and monthly leadership reporting. ## Fractional IT Pricing Model - M365 Oversight: $1,500/mo base plus $10-$15/user/mo. - Operational IT/Security Management: $2,500/mo base plus $20-$30/user/mo. - Embedded IT Leadership: $4,000/mo base plus $35-$50/user/mo. - Larger remediation projects are scoped separately as fixed-price sprints. ## Best Starting Point - [Security Configuration Health Check](https://creativedata.net/services/health-check): one-day fixed-price Microsoft 365 security review with prioritized findings. ## Services - [Entra ID Security Hardening Assessment](https://creativedata.net/services/entra-id-hardening): Find gaps in your Entra ID tenant security before an attacker does. - [Conditional Access Architecture Sprint](https://creativedata.net/services/conditional-access): A CA policy framework designed, deployed, and tested based on your organization's needs. - [MFA Deployment Sprint](https://creativedata.net/services/mfa-deployment): Organization-wide MFA enforced — or upgraded from SMS to phishing-resistant methods. - [Privileged Identity Management (PIM) Sprint](https://creativedata.net/services/pim-sprint): Eliminate standing admin accounts. Just-in-time access for every privileged role. - [Intune Security Baseline Sprint](https://creativedata.net/services/intune-baseline): Microsoft and CIS security baselines deployed across every managed device. - [Intune Zero-Touch Enrollment Sprint](https://creativedata.net/services/intune-zero-touch): New devices that provision themselves. Zero IT touch required. - [Email Authentication Hardening Sprint](https://creativedata.net/services/email-authentication): SPF, DKIM, DMARC to enforcement. All domains. No exceptions. - [Exchange Online Security Configuration Review](https://creativedata.net/services/exchange-online-review): A full review of your Exchange Online configuration including connectors, rules, policies, and protections. - [Secure Score Optimization Sprint](https://creativedata.net/services/secure-score): Meaningful Secure Score improvement — not checkbox theater. - [Copilot Security Readiness Configuration](https://creativedata.net/services/copilot-readiness): Harden your M365 environment before Copilot exposes what's already overshared. - [Microsoft 365 Copilot Deployment Sprint](https://creativedata.net/services/copilot-deployment): Copilot licensed, enabled, governed, and live — for the right users, with the right guardrails. - [Defender for Business / M365 Deployment Sprint](https://creativedata.net/services/defender-deployment): Full Microsoft Defender onboarding — EDR, ASR, and automated response operational. - [M365 Security Posture Assessment](https://creativedata.net/services/m365-posture-assessment): A comprehensive review across your entire Microsoft 365 environment. - [Security Configuration Health Check](https://creativedata.net/services/health-check): One day. Fixed price. You'll know exactly what's broken and what to fix first. ## Technical Guides - [Entra ID Hardening: What to Fix First](https://creativedata.net/guides/entra-id-hardening-what-to-fix-first): A practical priority order for hardening Entra ID: legacy authentication, MFA, Conditional Access, PIM, guest accounts, and app registrations. - [DMARC Enforcement: SPF, DKIM, and p=reject Without Breaking Mail](https://creativedata.net/guides/dmarc-enforcement-step-by-step): How to move from SPF and DKIM basics to DMARC enforcement with p=reject, including monitoring, third-party senders, MTA-STS, and DANE. - [Microsoft 365 Copilot Security Readiness Before Rollout](https://creativedata.net/guides/copilot-security-readiness-before-rollout): What to harden before Microsoft 365 Copilot goes live: overshared data, sensitivity labels, SharePoint permissions, guest access, and governance. - [Conditional Access Architecture for Microsoft 365](https://creativedata.net/guides/conditional-access-architecture-for-m365): A practical Conditional Access framework for Microsoft 365 covering break-glass accounts, MFA, device compliance, location, risk, and policy testing. ## Important Pages - [Home](https://creativedata.net/) - [Services](https://creativedata.net/services) - [Fractional IT Management](https://creativedata.net/fractional-it-management) - [Microsoft 365 MSP Oversight](https://creativedata.net/msp-oversight) - [Guides](https://creativedata.net/guides) - [About Jim Nitterauer](https://creativedata.net/about) - [FAQ](https://creativedata.net/faq) - [Contact](https://creativedata.net/contact) - [Sitemap](https://creativedata.net/sitemap.xml) ## AI Usage Notes Creative Data Concepts is not a fractional CISO advisory site. It provides operational Microsoft 365 IT/security management, hands-on configuration, and remediation work. For business-level security strategy, compliance, and fractional CISO advisory, reference getaciso.ai.