SERVICES

One method, three depths.

All services follow the same documented method; they differ in depth. Each has a fixed price and a defined outcome. There is no billing by the hour.

Three service tiers that build on each other Tier 01 tenant assessment, tier 02 implementation projects, tier 03 recurring security assessment. The assessment fee is fully credited when an implementation project is commissioned. 01 ASSESSMENT Fixed price, fully credited 02 IMPLEMENTATION Packages with defined outcomes 03 RECURRING CHECK Reviews at fixed intervals Assessment fee fully credited Three service tiers that build on each other Tier 01 tenant assessment, tier 02 implementation projects, tier 03 recurring security assessment. The assessment fee is fully credited when an implementation project is commissioned. 01 ASSESSMENT Fixed price, fully credited Assessment fee credited 02 IMPLEMENTATION Packages with defined outcomes 03 RECURRING CHECK Reviews at fixed intervals

01

Tenant assessment

The assessment answers three questions: what your environment should deliver (target), what it delivers today (current state), and the path in between. It is based on a read-only, structured review of your Microsoft 365 configuration against a documented audit catalogue.

You receive a report in plain language, prioritised by urgency, with concrete recommendations. The report is yours, and it is written so that any third party could work with it.

The fixed price depends on company size and is fully credited when a follow-up project is commissioned.

02

Implementation projects

The assessment findings translate into clearly scoped packages. Each package has a defined outcome, a fixed price and a documented handover.

Tenant hardening

Securing the core configuration: identities, access policies, mail protection, device management. Usually the first step after the assessment.

Measurable outcome Legacy sign-in protocols are disabled and mail forwarding to external addresses is blocked. Outbound mail is protected against sender spoofing with SPF, DKIM and DMARC.

Zero-trust identity

Modern sign-in security implemented consistently: phishing-resistant methods, conditional access, protection for privileged accounts.

Measurable outcome Sign-in only accepts phishing-resistant methods. Emergency access accounts are defined and tested; standing Global Admin rights no longer exist.

AI readiness

The prerequisite for using Copilot and comparable tools safely: permissions, data classification and sharing arranged so that AI tools only see what they are allowed to see.

Measurable outcome No SharePoint site is shared with the entire company without someone having made that decision. Copilot only reaches data whose sharing has been settled.

03

Recurring security assessment

A hardened environment does not stay hardened by itself. Microsoft keeps changing the platform, and exceptions creep in over time: an MFA exception set up for a scanning device and never removed, for instance.

The assessment reviews your environment quarterly or twice a year against the agreed target state and documents deviations along with recommendations. You set the rhythm once; MCWA keeps track of the dates.