← Back to plans

Microsoft 365 Environment setup

Secure baseline configuration of your Microsoft 365 tenant, aligned with Microsoft best practices and the CIS Microsoft 365 Foundations Benchmark, so your environment is not left in insecure defaults.

€490.00 One-time

What's included

Secure baseline: what we configure

Aligned with Microsoft best practices and the CIS Microsoft 365 Foundations Benchmark.

Multifactor authentication for everyone

Enforce MFA for all users and admins with Conditional Access policies, replacing the basic security defaults a new tenant starts with so you get granular, risk-aware control.

Block legacy authentication

Turn off legacy/basic auth protocols (POP, IMAP, SMTP AUTH and older clients) that bypass MFA. Microsoft has retired most basic auth in Exchange Online, and we confirm remaining paths such as SMTP AUTH stay disabled.

Conditional Access baseline

Policies that require MFA, block legacy auth and react to sign-in and user risk (Identity Protection), plus device-based access controls.

Phishing-resistant sign-in

Roll out Microsoft Authenticator with number matching and passkeys (FIDO2); remove weak SMS and voice methods.

Admin roles & Privileged Identity Management

Keep only a few Global Admins, assign least-privilege roles, and enable PIM for just-in-time, zero-standing admin access.

Break-glass emergency accounts

Two cloud-only emergency admin accounts, excluded from Conditional Access and monitored, so you are never locked out of the tenant.

Self-service password reset & protection

Enable SSPR with strong methods, banned-password protection and smart lockout against password-spray attacks.

Restrict app registration & consent

Block users from registering apps, creating tenants and consenting to third-party apps; require admin or verified-publisher consent (auto-block unconfigured OAuth).

External sharing & guest access

Tighten SharePoint/OneDrive external sharing and Teams external and guest access so only authenticated guests can be invited, with anonymous “Anyone” links restricted or turned off.

Email authentication: SPF, DKIM, DMARC

Enable DKIM for your custom domains and publish a DMARC quarantine/reject policy, so attackers cannot spoof your domain.

Exchange Online hardening

Block external auto-forwarding, disable legacy mail protocols per mailbox, and confirm mailbox audit logging is on.

Microsoft Defender for Office 365

Apply the preset Standard/Strict security policies: anti-phishing and impersonation protection, Safe Links and Safe Attachments.

Device & app security (Intune)

Onboard Defender for Business, set Intune compliance and mobile app protection policies, and require compliant devices via Conditional Access (Business Premium).

Data protection (Microsoft Purview)

Sensitivity labels and Data Loss Prevention (DLP) policies tailored to your sensitive data, so classification and protection match how your organization actually works.

Microsoft 365 Copilot data governance

Review oversharing and apply labels and DLP before enabling Copilot, so AI cannot surface data users should not see.

Audit logging, alerts & Secure Score

Confirm the unified audit log and retention, configure alert policies for risky activity, and track Microsoft Secure Score over time.