We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft
  2. Microsoft Security
Microsoft security for US businesses

You are probably paying for more Microsoft security than you have ever switched on.

Assess enough tenants and the pattern stops varying. The problem is never a product nobody bought. It is a product nobody finished configuring. Defender licensed and sitting in monitor mode two years later. Three conditional access policies and an exclusion group that keeps quietly growing. Purview purchased for a compliance push that died at the classification stage. Entra P2 on the invoice while every administrator still holds permanent rights. Before we recommend buying anything, we tell you what the subscription you already renew actually includes, because for most American companies the fastest available improvement carries no cost at all.

Book a tenant security assessmentSee the product map
Microsoft security stack deployment for US businesses
  • License-firstUse what you already own
  • 5 minP1 response for managed clients
  • 24/7Coverage on managed engagements
  • FreeTenant security assessment
How we work on the Microsoft stack

Six things we do before anyone mentions a new license.

What follows is the order that buys the most protection for the least money, and it is deliberately dull. Nearly all of it runs on capability already sitting on your invoice.

Establish what your license already includes

The security capability inside Business Premium, E3, and E5 differs enormously, and almost nobody can describe their own accurately. We map what you are entitled to against what is genuinely deployed and hand back three lists: what you pay for and never touch, what you use but do not need, and what you are actually missing. That single document tends to reshape the budget conversation, because the honest answer very often turns out to be that no new licensing is needed this year at all.

Close the identity basics first

Multi-factor enforced on every account, administrators very much included. Legacy authentication blocked outright. Administrative accounts kept separate from the mailbox somebody reads email in. Emergency accounts that genuinely exist and raise an alert whenever they are used. Phishing-resistant methods for anyone privileged. None of this requires a purchase order, all of it closes the routes attackers actually take, and it is incomplete in the overwhelming majority of tenants we look at.

Get Defender doing what it was bought for

Every device onboarded, not most of them. Attack surface reduction rules moved out of audit and into enforcement after a genuine tuning period rather than on day one. Automated investigation actually configured. And alerts landing somewhere a person will read them. Licensed and unconfigured, Defender is an expense line rather than a control.

Classification before data protection

Loss prevention, retention, and insider risk in Purview all rest on classification existing first, and none of them work without it. We deploy a deliberately small set of labels that people will genuinely apply, let automatic labeling carry most of the load, and then build protection around the labels that actually matter. The ambitious taxonomy designed in a two-day workshop stalls before deployment every single time.

Make sure somebody is watching

Detecting without responding leaves you with an expensive log file. We connect the estate to monitoring, tune away the noise that causes people to stop reading alerts, and pair the detection with response cover at any hour, either through our own managed service or by backing your internal team. This is the step companies skip most often and regret most often.

Produce evidence continuously, not annually

Multi-factor coverage, privileged access reviews, how current patching is, whether loss prevention actually ran, incident records, and access recertification, all kept as a standing pack rather than assembled in a panic the week before fieldwork. SOC 2 auditors, cyber carriers, HIPAA assessors, and enterprise customers now ask overlapping versions of the same questions, and answering from a maintained document beats reconstructing the year from memory.

The Microsoft security stack

Which product does what, and where to read more.

Microsoft naming is genuinely bewildering and it leads companies to buy the wrong thing regularly, so the grouping below follows the problem each product solves rather than the family it belongs to. Where we have written a page, it is linked. The set keeps growing, so if what you need is missing, ask and you will get the answer directly rather than a link.

Identity, the perimeter that actually matters

When most people are not on an office network most of the time, the account itself becomes the perimeter. This is where the majority of successful attacks on American companies start.

  • Microsoft EntraConditional access, just-in-time administrative rights, risk-based identity protection, and the P1 against P2 licensing question.
  • MFA solutionsRolling out multi-factor, and why a plain approval prompt has stopped being enough by itself.
  • Entra Conditional AccessThe policy engine that decides who gets in, from where, on what device, and under what conditions.
  • Entra Identity ProtectionRisk-based detection of compromised credentials and risky sign-ins, acted on automatically.
  • Privileged Identity ManagementStanding admin rights replaced with just-in-time elevation, approvals, and an audit trail.
  • Active DirectoryThe directory still sitting in your server room, hybrid identity, and the attack paths that continue to run straight through it.

Endpoint and device threat protection

Catching what reaches the endpoint, stopping it, and knowing fast on the occasions something got past.

  • Microsoft DefenderWhich Defender product is which, and how the family fits together across your estate.
  • Defender for EndpointThe plan decision: Defender for Business, Plan 1 or Plan 2, and what each actually gives you.
  • Defender Vulnerability ManagementContinuous vulnerability assessment plus the certificate, firmware and browser extension inventories nobody has.
  • Mobile Threat DefenseDevice threat risk feeding compliance and Conditional Access, including on unenrolled personal phones.
  • Endpoint securityThe broader endpoint practice across every platform, including an honest view of where Defender sits against its competitors.

Email, identity threats and SaaS

The entry points attackers actually use: a convincing email, a stolen credential, and an OAuth grant nobody reviewed.

  • Defender for Office 365Impersonation protection, Safe Links and Safe Attachments, and the ten-second check that tells you which plan you hold.
  • Defender for IdentityThe layer that notices somebody already inside: reconnaissance, credential abuse and lateral movement.
  • Defender for Cloud AppsSaaS activity, OAuth applications and shadow IT, brought under one policy view.

Detection, response and the people behind it

Products generate alerts. Somebody still has to read them at three in the morning, and that has always been a staffing problem rather than a licensing one.

  • Microsoft Defender XDRThe correlation layer: one incident instead of alerts in four consoles, plus automatic attack disruption.
  • Microsoft SentinelA cloud-native SIEM, the connectors that feed it, automation on top, and keeping the ingestion bill from running away.
  • Sentinel in the Defender portalWhere SIEM and XDR converge, and what the portal transition means for your operation.
  • SOC as a serviceThe human layer: triage and response at any hour, which is the gap almost every Microsoft security deployment leaves wide open.
  • Managed security servicesThe complete managed engagement across the whole stack rather than one product in isolation.
  • Microsoft Copilot for SecurityUseful acceleration for a team already doing this work, and frankly not where anyone should start.

Cloud workloads and the external surface

What you run in Azure, AWS and GCP, and the internet-facing assets you forgot you had.

  • Defender for CloudCloud posture management with a free tier most subscriptions never enable, plus workload protection plans.
  • Defender EASMExternal attack surface discovery: the assets your scanner was never told about.
  • Defender for ServersServer protection across Azure, AWS, GCP and on-premises, licensed separately from user plans.
  • Defender for ContainersKubernetes hardening, vulnerability assessment and runtime protection.
  • Defender for StorageMalware, sensitive data leakage and SAS token misuse on the storage accounts holding your data.
  • Defender for SQLThreat detection for the databases where the business actually lives.
  • Defender for APIsVisibility and threat detection for the business-critical APIs behind your applications.

Data protection, privacy and compliance evidence

Knowing what data you actually hold, limiting where it can travel, keeping it no longer than you should, and being able to prove all three.

  • Microsoft PurviewClassification, loss prevention, retention, insider risk, and discovery. Nothing works until classification exists.
  • Microsoft PrivaPrivacy risk and subject-rights requests, mapped to CCPA/CPRA and state privacy law obligations.
  • DLP solutionsLoss prevention across the whole estate, rolled out in simulation first so it survives its first week with real users.
  • Endpoint DLPThe same data protection extended to what users copy, paste, print and upload from their devices.
  • Compliance ManagerMapping controls and scoring improvement against whichever frameworks actually apply to you.
  • M365 reporting and auditingHow long audit data is kept, the specific reports regulated American firms get asked to produce, and alerting when something high-risk changes.

Devices, because an unmanaged endpoint undoes the rest

A policy can insist on a compliant device only when something is deciding what compliant means.

  • Microsoft IntuneDevice management, zero-touch provisioning, compliance policies, patching, and app protection on personally owned phones.
  • Apple Business ManagerThe free foundation underneath every Apple fleet, and why the place you buy a Mac determines whether you can ever manage it.
  • Jamf ProDedicated Apple management, plus a straight answer about when Intune is the better choice.

Assessment, baseline and audit

Independent confirmation that the controls you believe are running actually are.

  • Cybersecurity audit and compliancePosture assessment and the evidence pack insurers, auditors and enterprise customers ask for.
  • Tenant security baselineThe written, enforced security configuration for your tenant, and the evidence behind it.
  • Compliance servicesHIPAA, SOC 2, CMMC, GLBA and state privacy law readiness, built on the controls this stack provides.
How we are different on this

Four things that shape how we approach Microsoft security.

We audit the license before proposing a purchase

The first thing we hand over is a list of what you own and are not using. That routinely shrinks the engagement we could otherwise have sold, and it is precisely why clients believe whatever we recommend afterwards. An advisor whose every assessment ends in an upgrade is not assessing anything.

We pair the tooling with people who respond

Almost none of the Microsoft security failures we investigate were detection failures. The product spotted it correctly and dropped the alert into a mailbox nobody was watching at two in the morning. Managed engagements carry cover at every hour with a five-minute response on critical alerts, so the response side is contracted rather than quietly assumed.

Built for the audit and insurance conversation

Evidence comes out of every deployment as a by-product rather than as a separate project six months later. SOC 2, HIPAA, CMMC, the FTC Safeguards Rule, NYDFS Part 500, and your insurance renewal all ask overlapping versions of the same questions, and one maintained pack answers every one of them.

We run it afterwards, which is where posture decays

Settings drift, Microsoft alters defaults on its own schedule, exclusion groups quietly expand, and every departure leaves a privileged account nobody removed. A tenant hardened once and then left alone measurably weakens over two years. Holding the posture is the ongoing work, and it is what we run across the 800+ systems under our management.

Before you buy E5

The upgrade is usually not the answer, and the license audit usually is.

A great many of the Microsoft security conversations we have begin with a decision already made to move to E5. Occasionally that is the right call. Far more often the company is not using what Business Premium or E3 already hands them, and upgrading adds cost while adding no protection whatsoever, because the constraint was never the license in the first place.

  • Business Premium already carries Entra ID P1 with conditional access, Intune, Defender for Business, Defender for Office 365 Plan 1, sensitivity labels, and the foundations of loss prevention and retention. Configured properly, that is a genuinely strong position for a company under three hundred people. Most companies holding it have configured perhaps half.
  • E5 adds the sophisticated end of the range: Entra P2 with just-in-time administration and risk-based policy, Defender for Endpoint Plan 2 with threat hunting, the full Purview suite including insider risk and premium discovery, and Sentinel benefits. Every single one of those requires a human being to operate it. Buying capability nobody has time to use is the most reliable way to waste a security budget.
  • Our test is straightforward. Take each E5 capability, name the person who will run it, and state the question it answers for your business. Where you cannot do both, that capability will sit unused exactly as the currently unconfigured ones do, and the money does more good spent on deploying, tuning, and monitoring what you already hold.
  • E5 genuinely pays for itself in three situations: a regulated firm that needs just-in-time administration and premium audit data as evidence, a company with an actual security team who will use threat hunting, or a case where the bundle simply costs less than buying the parts. We model that honestly, and we have told clients to stay where they are and spend the difference on monitoring instead.
Ask for a license and posture assessment
Who we do this for

Six US profiles and what drives the security scope.

Financial services and fintech

GLBA and FTC Safeguards obligations, NYDFS Part 500 where New York licensed, and bank partners running their own vendor due diligence. Usually the clients who need Entra P2, privileged identity management and premium audit for genuine reasons.

Healthcare and clinics

Patient data under HIPAA, a Business Associate Agreement to make real through tenant controls, retention obligations, and clinical devices that must be encrypted and evidenced alongside everything else.

Defense contractors and their suppliers

CMMC and NIST 800-171 drive specific configuration: controlled unclassified information handled deliberately, access control evidenced, and a tenant that can survive an assessor reading the settings rather than the policy binder.

Companies facing their first SOC 2

SaaS and services businesses whose enterprise customers now require SOC 2 or a completed security questionnaire before signing. Most of the controls the auditor asks about are Microsoft stack configuration, and most are already licensed.

Businesses that move money on email approval

Compromised business email is the single largest source of actual financial loss for American small and mid-size companies. Mail authentication, impersonation protection, and a verification step before any payment detail changes matter more here than anything else in the stack.

Professional services firms

Client confidentiality, document control and a small IT function. The organizations that benefit most from configuring what they already own, and the ones cyber insurers question hardest at renewal.

How an engagement starts

Four steps, and the first one frequently makes the project smaller.

  1. 1

    License and posture assessment

    Week 1

    What the subscription entitles you to, what has genuinely been deployed, and the distance between those two lists. Alongside that, the basics get checked: how far multi-factor actually reaches, whether legacy authentication is still open, who holds privileged rights, which accounts are dormant, and how long audit data is kept. The findings come in writing regardless of what happens next.

  2. 2

    Close the free wins

    Weeks 1-3

    Multi-factor enforced, legacy authentication blocked, administrative accounts separated, emergency access established, dormant accounts removed, audit retention extended, and every device Defender is already licensed for actually onboarded. All configuration, no purchasing, and it improves your posture more than anything that comes after it.

  3. 3

    Deploy the capability you own but have not used

    Months 1-3

    A deliberately small set of conditional access policies rather than a sprawling one. Attack surface reduction taken through audit into enforcement at a sensible pace. Intune compliance feeding those access decisions. Classification in Purview, and loss prevention run in simulation before anything blocks. Sequenced so that adoption survives the rollout.

  4. 4

    Monitoring, evidence and ongoing operation

    Ongoing

    Alerts land somewhere a person actually reads them. Access and privileged rights are reviewed every quarter. Patching and compliance get reported. The evidence pack stays current rather than being rebuilt annually. And the whole posture is revisited as Microsoft changes defaults underneath you and your company changes shape around it.

Microsoft security FAQ

What US buyers ask about the Microsoft security stack.

For the large majority of American mid-market companies, this stack deployed properly is more than enough, and the way the pieces talk to each other is an advantage no assembled collection of best-of-breed tools can replicate. A compromised laptop can trigger identity-level containment automatically because Defender and Entra share signal. Two separate vendors will never do that for you at any price. Third-party products still earn their keep in specific places: certain industrial and operational technology environments, particular compliance tooling, and occasionally an existing investment carrying years of tuning that would be wasteful to throw away. The mistake we see most often is not picking the wrong side. It is running two overlapping endpoint products at once, which reliably degrades both.

Because buying a license grants an entitlement, not a deployment, and E5 is where that gap opens widest. The story is always the same: E5 gets bought at a renewal or on somebody advice, a handful of features are switched on, and the sophisticated capability that justified the price is never configured because it needs an operator nobody assigned. We routinely open E5 tenants where just-in-time administration has never been used, insider risk was never enabled, nobody has ever run a hunt, and attack surface reduction is still sitting in audit mode from the original rollout. None of this is a Microsoft failing. It is the entirely predictable result of buying capability without allocating people, which is why we ask who will run each feature before we recommend it.

Finish multi-factor coverage, then block legacy authentication, in that order, and verify both rather than trusting a dashboard. Finished means every account including administrators, service accounts handled properly instead of parked in an exclusion group, and no standing exemptions anywhere. Legacy authentication cannot issue a second-factor challenge at all, so leaving it enabled means an attacker holding valid credentials is simply never asked, which quietly undoes the multi-factor you just spent a month deploying. Both changes are configuration with no license cost, both can be completed inside a week using report-only mode first so nobody gets locked out, and between them they close the routes used in the overwhelming majority of tenant compromises we are called into.

The Microsoft products cover the technical controls these frameworks expect, and mapping them properly is much of what makes an assessment go smoothly rather than painfully. Access control, encryption, logging and retention, endpoint protection, vulnerability management, and incident response all have components here, and Compliance Manager gives you a starting control map. What no product provides is the governance half: a risk register with real owners, a policy set that matches how the company genuinely operates, documented exceptions with expiry dates, and evidence that controls ran across a period rather than existed on one afternoon. We deliver both halves. It is still worth saying plainly that no license discharges a compliance obligation by itself. Your auditors and advisors own the interpretation. We own the controls and the evidence behind them.

Directly, because the questionnaire asks tenant-level questions this work answers: is MFA enforced everywhere including remote access, is there endpoint detection and response, who holds privileged access and how is it reviewed, how are backups protected, and is anyone monitoring around the clock. Carriers have moved from accepting attestations to requiring evidence, and several controls, MFA and EDR in particular, are now underwriting prerequisites rather than premium factors. A managed Microsoft stack answers each question from a document that already exists, and in our experience that shows up in both insurability and the questions you are not asked.

Yes, and it happens often where a company has already retained a SOC or invested in a SIEM. What matters is a written boundary agreed before anything goes wrong: who watches which signals, who is permitted to isolate a machine, who leads an incident, and exactly what handoff looks like at three in the morning. When two competent security teams fail together, the failure is never technical. It is the ten minutes each spends assuming the other has already acted. A named incident commander for each scenario and one documented escalation tree eliminates that. We integrate with Sentinel and with third-party platforms, and we would far rather draw the boundary clearly than argue over territory mid-incident.

The assessment costs nothing and produces the licensing and posture findings in writing whether or not anything follows it. Past that we quote after scoping, because the spread is genuinely enormous: closing the free configuration wins takes weeks, while a complete build across identity, endpoint, data protection, and monitoring for a regulated group of companies is a program of work. What drives it is headcount, your regulatory position, how much technical debt the assessment turns up, and whether you want us running it afterwards or handing it to your own team. Ongoing management is scoped per engagement rather than priced per product.

The identity fundamentals shift things inside three weeks, and that is the largest single improvement most companies will ever make. Onboarding and tuning Defender takes four to eight weeks, because attack surface reduction rules need a real audit period before you enforce them, and rushing that step is the most reliable way to have protection turned back off by a frustrated business. Data protection in Purview runs three to six months, since adoption rather than configuration governs the pace. Monitoring can be live within weeks. Order matters enormously here: a company that begins with sophisticated data protection while identity is still open is carefully protecting documents inside a tenant anybody can sign into.

Yes, even though this page happens to be about Microsoft. We deploy and support Google Workspace, and our security work covering monitoring, endpoint protection, and compliance is platform-independent. On Google the identity and data protection conversation looks different in its details while the underlying questions stay identical: is multi-factor genuinely complete, is anybody reading the alerts, can you produce evidence on demand, and what actually happens when somebody leaves. Where a Microsoft-centric recommendation does not apply to you, you will be told that rather than steered toward the stack this page happens to describe.

Not necessarily, and shared arrangements are common. Plenty of American companies have a perfectly capable IT provider running daily support who simply has no security practice, which is a sensible division of labor rather than an accusation. In that model they keep the help desk, the devices, and the infrastructure, while we take identity hardening, Defender, monitoring, and the compliance evidence. It needs the discipline any shared arrangement needs: a boundary in writing, a named incident commander, and agreement about who may change what while an incident is running. Where the incumbent provider is also the reason the tenant was never configured, that is a different conversation, and one worth having openly rather than around.

You go and look, which most companies have simply never done. The worthwhile checks are specific. Mailbox rules quietly forwarding copies to an outside address, which is the classic persistence trick after a mailbox compromise and is entirely invisible to the person it belongs to. Sign-ins from countries you do not operate in, or travel patterns that are physically impossible. Consent granted to third-party applications nobody in the room remembers approving. Administrative roles handed out around your change process rather than through it. Dormant accounts that have suddenly woken up. Each is a query rather than a project, and all of them run as part of the free assessment. A meaningful share of the tenants we assess return at least one finding of this kind, usually months old, and almost without exception nobody had ever thought to check.

It helps, it will not solve the problem, and any provider selling awareness training as your primary control is overselling. People click links, because clicking links is what links exist for, and a well-built modern phishing page is genuinely hard to tell apart from the real thing. The controls that actually hold are technical. Phishing-resistant authentication, so a stolen password plus an approved prompt is not enough. Conditional access demanding a compliant device, so a token lifted from an unmanaged machine fails anyway. Mail authentication at enforcement, so a lookalike domain never lands. Safe Links rewriting addresses, so a URL weaponized after delivery is still caught. Training is worth having as a layer, and simulated phishing gives you a genuine measure of exposure, but design everything on the assumption that somebody clicks, because eventually somebody does.

Four questions, and how they answer tells you everything. What does our current licensing already include that we are not using, because anyone who cannot answer that has not actually looked. Who will operate each thing you are proposing, since capability with no operator is shelfware with a support contract. Where do the alerts go and who reads them at three in the morning, which is the line between a deployment and actual security. And what evidence will this produce for an auditor or an insurer, because a control you cannot evidence will not help you in the conversations that end up mattering. Any provider whose assessment concludes with an upgrade no matter what they found is selling rather than assessing.
Start here

The three pages most buyers read next.

Microsoft Entra

Attacks overwhelmingly start at identity, and identity is also where improvement comes fastest.

Learn more

Defender for Endpoint

The plan decision that surprises almost everyone: which Defender product your licensing already gives you.

Learn more

SOC as a service

The human layer. Detection with nobody reading the alerts is just an expensive log file.

Learn more
Free tenant security assessment

Start by finding out what you are paying for and never switched on.

We map your license entitlement against what is actually deployed, check MFA coverage, legacy authentication, privileged and dormant accounts, and audit retention. You get the findings in writing at no cost. A fair proportion of these assessments conclude that no new license is needed this year.

Book a tenant security assessmentSee Microsoft Defender

Related Services

Explore more solutions that work great with this service

Microsoft Defender for Endpoint Services

EDR plan selection, onboarding and zero-gap AV migration

Learn more

Microsoft Defender XDR Services

One incident queue across endpoint, email and identity

Learn more

Microsoft Defender for Office 365 Services

Anti-phishing, Safe Links and Safe Attachments done right

Learn more

Microsoft Defender for Identity Services

Identity threat detection for Active Directory and Entra

Learn more

Microsoft Defender for Cloud Services

Defender for Cloud deployment for US organizations: enabling free

Learn more

SOC-as-a-Service

24/7 security operations delivered as a service

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA