Security in the Microsoft environment

Many Entra and Purview capabilities are already included in licences organisations pay for every month. This service identifies which ones you have available, puts them to work and defines the identity and access model underneath.

When it makes sense

When you already pay for more security than you use

Most organisations have security capabilities under contract that were never configured. Not out of neglect: configuring them forces you to decide first who should reach what, and that decision isn't a technical one.

The work here has two halves. Getting into service what is already paid for, and designing the model that sustains it so that it still makes sense two years from now.

Licences half configured

You have plans with security capabilities included and nobody has reviewed what they contain or what is switched on.

You are being sold what you already have

Proposals arrive for tools that duplicate functions included in your current licence. Without knowing what it covers, deciding is impossible.

Permissions have got out of hand

Access gets granted and never withdrawn. Nobody can say today who can reach what, let alone who should.

What's included

What gets worked on

Whatever applies to your case. It almost always starts with identity, because the other controls rest on it.

Identity · Microsoft Entra

Who is who and how far they get. It is the control every other one rests on.

  • Identity and access model
  • Security controls over authentication
  • Privileged access management
  • Review of the permissions granted

Information · Microsoft Purview

What information exists, how it is labelled and what protection travels with it.

  • Information protection and labelling
  • Classification by sensitivity
  • Data governance
  • Controls over use and access

Controls and licensing

What you are entitled to use and what you genuinely lack.

  • Review of the capabilities your plan covers
  • Security controls to switch on
  • Design of the target configuration
  • Criteria for deciding whether upgrading is warranted
How I work

How it is approached

Configuring first and deciding afterwards is the usual mistake, and it gets paid for in reconfiguration.

  1. Inventory

    What licences exist, what capabilities they include and what is switched on today. This phase alone often changes the conversation with the supplier.

  2. Model

    Decisions on identity, access and classification. Who should reach what, and which information deserves more protection than the rest.

  3. Implementation

    Configuration in phases, starting in report-only mode and measuring the impact on real work before tightening anything.

  4. Verification

    Checking that what was configured does what was expected, adjusting whatever gets in the way without adding value, and handover to your team.

What you get

What stays built and documented

The configuration is half of it. The other half is your team being able to maintain it without calling me.

  • Inventory of the capabilities included in your licence
  • Documented identity and access model
  • Configuration implemented and verified
  • Criteria for classifying information
  • Operating documentation for your team
  • Recommendations on what to switch on next

Scope of the serviceThe engagement runs up to the design, the configuration and the documented handover to your team, who operate it from then on. It doesn't include systems administration, endpoint support or continuous monitoring of the environment. Nor do I sell licences or take commission from anyone: if the conclusion is that your current plan is enough, that is what you will hear.

Frequently asked questions

What people usually ask before engaging

Which capabilities does my licence cover?

You can check it yourself right now with the Purview licensing simulator: pick your Microsoft 365 plan and it tells you which capabilities you have covered and which you don't. It is free, asks for no sign-up and works entirely in your browser.

Do we need to upgrade our plan?

Sometimes yes and sometimes no, and it is worth knowing before signing anything. Usually there is plenty of headroom without upgrading: first you get everything out of what is already paid for, and only then does the question arise of whether some specific capability justifies the jump.

Will this break how people work?

Not if it is done in phases. Anything that might get in the way is deployed first in report-only mode, over a small group, and the impact is measured before extending it. A security control that stops people working ends up switched off, so going slowly isn't caution: it is what makes it last.

Do you only work with Microsoft?

It is where my specialisation runs deepest and where the cheapest room for improvement usually sits, because those are capabilities already under contract. Security judgement isn't exclusive to one vendor, and for work outside this environment there is technical consulting.

What about training our team?

Operating documentation and handover are included. If what you need is training with more reach, that falls under culture and awareness and gets scoped separately.

How to assess your environment

To connect these controls with identities, applications, data and exceptions, read the Microsoft 365 security assessment guide. It explains which evidence to review and how to prioritise improvements.

Where to go next

Let's talk

Do you know which security you are paying for and not using?

Tell me which plans you have under contract and what you need to protect. One conversation is enough to see whether what is missing is configuration, judgement, or simply someone reviewing what your licence includes.

I reply personally within 24 working hours · No commitment