Security in the Microsoft environment is, to a large extent, configuration. The tools are licensed and present; the difference lies in whether they are set up, aligned with each other and watched. That is where we focus.
Microsoft Defender XDR
Microsoft Defender XDR correlates signals from devices, identities, email and cloud applications. We set up the individual services, connect them and make sure alerts reach the right people.
- Defender for Endpoint: onboarding via Intune, attack surface reduction, tamper protection, vulnerability management
- Defender for Identity and Entra ID Protection: sensors, risk policies and responses to risky sign-ins
- Defender for Office 365: Safe Links, Safe Attachments, anti-phishing and attack simulations
- Defender for Cloud Apps: shadow IT discovery and app policies
- Automated investigation and response, notifications and hand-over to your ticketing system
Security assessments
An assessment answers the question of where you stand, with no sales pitch behind it. We review your Microsoft 365 tenant and device management against Microsoft’s recommendations and common security frameworks, using tools and conversations. The result is an action list sorted by risk with effort estimates, not a hundred-page collection of warnings.
- Identities, administrator roles, authentication and Conditional Access
- Exchange Online protection, sharing and external collaboration
- Device configuration, encryption, patch level and local administrator rights
- Logging, retention of event data and alerting
Hardening
The assessment becomes a plan, the plan becomes configuration: security baselines for Windows and Edge, restriction of local administrator rights, protection of admin accounts with Privileged Identity Management, closing down legacy authentication and securing outbound email. Every measure is tested in a pilot group first.
Support during security incidents
When an incident has occurred, we support containment in Microsoft environments, analysis using data from Defender and Entra ID, and the restoration of a trustworthy state. Afterwards we take care of the measures that make a repeat harder. We do not offer a round-the-clock on-call service; availability and response times are agreed per engagement.