Services / Entry Point
Security Configuration Health Check
One day. Fixed price. You'll know exactly what's broken and what to fix first.
The Security Configuration Health Check is the lowest-friction way to engage. It is a fixed-price, one-day remote review of your Microsoft 365 environment: identity, email, endpoints, Defender, Secure Score, SharePoint, and overall posture. Most organizations walk away with 5-10 high-priority findings they did not know about. The findings report tells you what is broken, what the risk is, what to fix first, and whether the work belongs with internal IT, the MSP, a sprint, or ongoing fractional management.
What's Included
- Entra ID configuration spot check (roles, legacy auth, MFA coverage)
- Conditional Access policy review
- Email authentication status (SPF, DKIM, DMARC)
- Exchange Online security spot check
- Intune enrollment and compliance policy review
- Microsoft Defender coverage check
- Secure Score review and top quick wins
- SharePoint and guest access spot check
- Prioritized report with owner, risk, effort, and recommended next action
Engagement Details
Deliverable: Prioritized findings report delivered within 48 hours of the review session. Each finding includes: what was found, why it matters, and what to do about it.
Duration: One day (6–8 hours, remote)
Price: $1,500
What The Report Includes
The output is built for action, not shelfware. Your team gets a compact report that separates urgent risk from noise and shows what can be fixed internally, what belongs with the MSP, and what should become a sprint.
- Executive summary of the most important Microsoft 365 risks
- Prioritized findings table with risk, effort, owner, and next action
- Secure Score quick-win summary and configuration maturity notes
- Sprint recommendations for gaps that need hands-on remediation
- Accepted exceptions, open decisions, and follow-up items for internal IT or the MSP
| Area | Risk | Finding | Next Action |
|---|---|---|---|
| MFA | High | CA policy excludes key user groups | Close gap |
| DMARC | High | Primary domain remains at p=none | Move to enforcement |
| Admin Roles | Medium | Standing privileged access without review | Plan PIM |
| Intune | Medium | Devices enrolled inconsistently | Baseline rollout |
What Your Health Check Might Reveal
Most health checks surface 5-10 high-priority findings. Each one maps directly to a sprint, MSP action, or internal remediation step that closes the gap.
- Entra ID gaps
- MFA not enforced
- No Conditional Access
- Intune not deployed
- Email authentication gaps
- Defender not configured
- Copilot data exposure risk
