The security controls your Microsoft environment should already have.
The Cloud Security Baseline implements the foundational Microsoft security configuration that every organisation should have in place before anything else. MFA enforcement, Conditional Access policies, Microsoft Defender for Microsoft 365, and Intune device compliance. Done properly, documented and explained.
What is included
- MFA enforcement for all users, including break-glass account configuration
- Conditional Access policy design and implementation
- Legacy authentication protocols blocked
- Microsoft Defender for Microsoft 365: baseline configuration
- Safe Links and Safe Attachments policies
- Anti-spam and anti-phishing policy configuration
- Microsoft Intune: device compliance policy implementation
- Entra ID security defaults review and configuration
- Privileged account audit and admin role cleanup
- Microsoft Secure Score baseline measurement and improvement plan
- Configuration documentation and handover
- Post-implementation review session
What you get
Minimum viable security in place
The controls that prevent the most common Microsoft 365 attack vectors (account compromise, phishing, unmanaged device access) are configured and enforced.
Documented configuration
Every policy and setting is documented. Your team or MSP can understand what was configured and why, and maintain it going forward.
Measurable starting point
Microsoft Secure Score is measured before and after. You have a baseline from which to demonstrate improvement to leadership, auditors or insurers.
Investment
From $4,500
Fixed price. Scope confirmed after review of current environment state.
Next steps
Common questions
Ready to get started?
Book a no-obligation Cloud Review. We will assess your environment and identify where cloud, security and automation can remove friction from your operation.
No sales script. Initial conversation is obligation-free.