You are already paying for security you have not turned on.
If you already know you want the inspection, the M365 Hygiene Check page covers what it inspects and how the fee credits forward. What follows here is the case for why switching Microsoft 365 security on is the start of the work, not the end of it, and how onboarding runs once you decide to continue.
Sitting unused in Business Premium
Microsoft built Business Premium for companies with up to 300 employees, which is exactly where most of our customers sit. Here is what is commonly sitting unconfigured, depending on your license.
Conditional access (Entra ID P1)
Rules that check who is signing in, from where, and on what device, before access is granted. Business Premium includes Entra ID P1; Business Standard and Basic run on security defaults alone.
Microsoft Defender for Business
Endpoint protection for every device, plus web content filtering that blocks whole categories of sites at the network level. Both are already in the console; most tenants never set a policy.
Intune device management
Full device compliance and management across Windows, Mac, iOS, and Android, not the limited Basic Mobility and Security most companies fall back to by default.
Safe Links and Safe Attachments
Defender for Office 365 Plan 1 checks links and attachments before anyone clicks them. Included with Business Premium; standalone Business plans need it added separately.
Data loss prevention basics
Policies that catch sensitive data leaving through email and Office documents, scoped to what your license and configuration actually cover.
Self-service password reset
Lets people reset their own password without a help desk ticket, including on-premises write-back for hybrid identity setups, depending on your Microsoft license.
Exact capabilities and defaults change with your Microsoft license, any add-ons layered on top, and however Microsoft has most recently reorganized its own admin center. We confirm what you actually have before we touch anything.
We switch it on, and we keep it on.
Turning on a conditional access policy or a Defender rule is a one-time task. Someone can do it in an afternoon, and Microsoft keeps making its own setup wizards better at doing a version of it for you.
Staying configured is not a one-time task. Headcount changes, Microsoft renames a setting or changes a default, someone needs a one-off exception, and the policy that was right in January quietly stops matching how the company actually works. That is the part a setup wizard does not do, and the part a traditional IT provider rarely revisits once the ticket is closed.
We configure the policies once, then we own them: watching for drift, adjusting as Microsoft moves the defaults, and making the judgment calls a checklist cannot make. Configuration is a project. Operating it is the job.
Configured once
- Set up during onboarding, then left alone
- Drift goes unnoticed until an audit or an incident finds it
- New hires and new risks inherit whatever the default is
- No one owns the exceptions list
Cloud Sentry: operated
- Configured, then reviewed on a real cadence
- Drift caught and corrected before it becomes a finding
- Policies adjusted as Microsoft changes what ships on by default
- A named operator owns the exceptions, in writing
Beyond Microsoft
What Microsoft will not do for you
Microsoft secures Microsoft. It has nothing to say about your AWS account, the rest of your identity and device estate, or the evidence an auditor will ask for next quarter. Turning on Business Premium is one piece of a bigger job.
Your other clouds
AWS, Azure, and GCP need the same configuration and the same ongoing operation, run by people who know those consoles as well as this one.
See cloud operationsThe rest of IT
Google Workspace, identity, devices, and the help desk your people actually call, run by the same team instead of a second vendor.
See managed ITEvidence, not memory
What we configure and operate becomes filed evidence you can hand an auditor, not a claim someone makes from memory in a meeting.
See the Evidence VaultStart here
Start with the M365 Hygiene Check.
A fixed-fee, read-only look at your tenant: what is configured, what is not, and what to fix first. Results come back in a working session, not a report nobody reads.
Turn on what you already pay for.
Start with the check, or read the full shape of the partnership.
Published tiers, starting with the M365 Hygiene Check and Microsoft 365 Admin Guidance. No sales call required to start.
The scope, the visibility, and the work we do not take on, laid out section by section.