Security

Security: Microsoft Defender, assessments and hardening

Roll out Microsoft Defender XDR, harden tenant and devices, assess your security posture soberly.

  • Microsoft Defender XDR: configure and tune Endpoint, Identity, Office 365 and Cloud Apps
  • Security assessments of the Microsoft 365 tenant with a prioritised action list
  • Hardening of identities and devices, support during security incidents

Security in the Microsoft environment is, to a large extent, configuration. The tools are licensed and present; the difference lies in whether they are set up, aligned with each other and watched. That is where we focus.

Microsoft Defender XDR

Microsoft Defender XDR correlates signals from devices, identities, email and cloud applications. We set up the individual services, connect them and make sure alerts reach the right people.

  • Defender for Endpoint: onboarding via Intune, attack surface reduction, tamper protection, vulnerability management
  • Defender for Identity and Entra ID Protection: sensors, risk policies and responses to risky sign-ins
  • Defender for Office 365: Safe Links, Safe Attachments, anti-phishing and attack simulations
  • Defender for Cloud Apps: shadow IT discovery and app policies
  • Automated investigation and response, notifications and hand-over to your ticketing system

Security assessments

An assessment answers the question of where you stand, with no sales pitch behind it. We review your Microsoft 365 tenant and device management against Microsoft’s recommendations and common security frameworks, using tools and conversations. The result is an action list sorted by risk with effort estimates, not a hundred-page collection of warnings.

  • Identities, administrator roles, authentication and Conditional Access
  • Exchange Online protection, sharing and external collaboration
  • Device configuration, encryption, patch level and local administrator rights
  • Logging, retention of event data and alerting

Hardening

The assessment becomes a plan, the plan becomes configuration: security baselines for Windows and Edge, restriction of local administrator rights, protection of admin accounts with Privileged Identity Management, closing down legacy authentication and securing outbound email. Every measure is tested in a pilot group first.

Support during security incidents

When an incident has occurred, we support containment in Microsoft environments, analysis using data from Defender and Entra ID, and the restoration of a trustworthy state. Afterwards we take care of the measures that make a repeat harder. We do not offer a round-the-clock on-call service; availability and response times are agreed per engagement.

Talk to us about this

Tell us what it is about. A person will reply.

German office (sales and engineering)

Berlin, Germany