Many Entra and Purview capabilities are already included in licences organisations pay for every month. This service identifies which ones you have available, puts them to work and defines the identity and access model underneath.
Most organisations have security capabilities under contract that were never configured. Not out of neglect: configuring them forces you to decide first who should reach what, and that decision isn't a technical one.
The work here has two halves. Getting into service what is already paid for, and designing the model that sustains it so that it still makes sense two years from now.
You have plans with security capabilities included and nobody has reviewed what they contain or what is switched on.
Proposals arrive for tools that duplicate functions included in your current licence. Without knowing what it covers, deciding is impossible.
Access gets granted and never withdrawn. Nobody can say today who can reach what, let alone who should.
Whatever applies to your case. It almost always starts with identity, because the other controls rest on it.
Who is who and how far they get. It is the control every other one rests on.
What information exists, how it is labelled and what protection travels with it.
What you are entitled to use and what you genuinely lack.
Configuring first and deciding afterwards is the usual mistake, and it gets paid for in reconfiguration.
What licences exist, what capabilities they include and what is switched on today. This phase alone often changes the conversation with the supplier.
Decisions on identity, access and classification. Who should reach what, and which information deserves more protection than the rest.
Configuration in phases, starting in report-only mode and measuring the impact on real work before tightening anything.
Checking that what was configured does what was expected, adjusting whatever gets in the way without adding value, and handover to your team.
The configuration is half of it. The other half is your team being able to maintain it without calling me.
Scope of the serviceThe engagement runs up to the design, the configuration and the documented handover to your team, who operate it from then on. It doesn't include systems administration, endpoint support or continuous monitoring of the environment. Nor do I sell licences or take commission from anyone: if the conclusion is that your current plan is enough, that is what you will hear.
You can check it yourself right now with the Purview licensing simulator: pick your Microsoft 365 plan and it tells you which capabilities you have covered and which you don't. It is free, asks for no sign-up and works entirely in your browser.
Sometimes yes and sometimes no, and it is worth knowing before signing anything. Usually there is plenty of headroom without upgrading: first you get everything out of what is already paid for, and only then does the question arise of whether some specific capability justifies the jump.
Not if it is done in phases. Anything that might get in the way is deployed first in report-only mode, over a small group, and the impact is measured before extending it. A security control that stops people working ends up switched off, so going slowly isn't caution: it is what makes it last.
It is where my specialisation runs deepest and where the cheapest room for improvement usually sits, because those are capabilities already under contract. Security judgement isn't exclusive to one vendor, and for work outside this environment there is technical consulting.
Operating documentation and handover are included. If what you need is training with more reach, that falls under culture and awareness and gets scoped separately.
To connect these controls with identities, applications, data and exceptions, read the Microsoft 365 security assessment guide. It explains which evidence to review and how to prioritise improvements.
Tell me which plans you have under contract and what you need to protect. One conversation is enough to see whether what is missing is configuration, judgement, or simply someone reviewing what your licence includes.
I reply personally within 24 working hours · No commitment