Skip to content

Service

Microsoft 365 management

Most businesses use a fraction of what they already pay for, and run a tenant configured for convenience rather than security. The work here is mostly configuration and licensing review rather than purchase, which makes it some of the best value available in the first month.

Most common gap found

Backup

of Microsoft 365 data

Microsoft protects the platform. Your content remains your responsibility under the shared model.

Six areas under management

Microsoft 365 management areas and their scope
AreaWhat is managed
Tenant hardeningDefault tenants are convenient, not secureMFA enforcement, conditional access, legacy protocol shutdown, admin role review
IdentityDetermines who can reach what, everywhereEntra ID configuration, group structure, guest access governance
Device managementThe only practical control over laptops off the networkIntune enrolment, compliance policy, encryption, remote wipe
Email securityHighest volume attack surface in any tenantAnti phishing, impersonation defence, safe links and attachments
Data protectionMicrosoft protects its platform, not your contentThird party backup, retention policy, sharing controls
LicensingOverlicensing and underlicensing are both common and both expensiveAnnual review against actual usage and requirement

Five licensing traps

Licensing review usually pays for a meaningful share of the first year, and it takes an afternoon.

  • Paying for Business Premium features while running security tooling that duplicates them
  • Leaving licences assigned to leavers, sometimes for years
  • Buying the higher tier for the whole business when only a subset needs it
  • Assuming the built in retention window is a backup, which it is not
  • Missing that some compliance features only exist in specific tiers

The most expensive of these is duplication: paying for a tier that includes endpoint protection and email security, then paying again for third party products doing the same job. Consolidating one way or the other is almost always cheaper than running both.

The shared responsibility model

This is the sentence that catches people out. Microsoft is responsible for the availability and integrity of the platform. You are responsible for your data, your configuration, your identities and your access decisions.

In practice that means Microsoft will keep the service running and will not lose your tenant. It does not mean they will restore a mailbox somebody emptied last quarter, undo a sharing link that exposed a folder externally, or notice that an account has been signing in from an unusual location at three in the morning.

Every one of those sits on your side of the line, and each is addressable with configuration and tooling that most businesses are already licensed for.

Common questions

Answered before you ask.

Is Microsoft 365 secure out of the box?

It is capable of being secure, which is different. A new tenant ships with settings chosen for compatibility and ease of setup rather than for defence, and legacy authentication protocols that bypass multi factor authentication are frequently still enabled. Hardening a tenant is mostly configuration rather than purchase, which makes it one of the highest value pieces of work available in the first month of an engagement.

Do we really need a separate backup for Microsoft 365?

Yes, and this is the single most common gap we find. Microsoft operates a shared responsibility model: they guarantee the platform, you remain responsible for your data. The native retention window handles a deletion noticed within days. It does not handle a deletion discovered six months later, a compromised account clearing a mailbox, or a misconfigured retention policy. Third party backup is standard practice and inexpensive relative to what it protects.

What is Intune and do we need it?

Intune manages devices: enforcing encryption, requiring a compliant configuration before a device can reach company data, pushing applications and wiping a lost laptop remotely. If your staff work from anywhere other than one office on one network, it is the practical way to keep control of company data on machines you cannot physically reach. It is included in several common licence tiers, so many businesses already own it without using it.

Should we be worried about Copilot?

The main risk is not the model, it is permissions. Copilot surfaces content the user already has access to, which means an organisation with over permissive sharing suddenly finds that information genuinely discoverable rather than merely technically accessible. Files everyone could reach but nobody knew about become searchable in plain language. The work before deploying it is a permissions and sharing review, not an AI project.

Get your tenant reviewed.

The assessment includes a Microsoft 365 security and licensing review. Most businesses find both an exposure and a saving.

CallFree assessment