Report an Incident Become a Partner Careers Contact
Book a Demo
Microsoft-funded engagement

Microsoft pays
for the first engagement.

A structured security engagement delivered on your own tenant, scoped around eight domains, and funded by Microsoft for eligible organisations. You keep the findings and the roadmap whatever you decide to do next.

Engagement · your tenantfunded
CHECKMicrosoft eligibility confirmed firstapproved
SCOPETwo to four domains, chosen by youagreed
ASSESSZero Trust pillars, nothing configured yetbaselined
FINDReal gaps, in your production estatesurfaced
PROVECapabilities configured and demonstratedshown
KEEPRoadmap and findings are yourseither way
What it is

Proved on your tenant,
not in a slide deck.

Microsoft funds a partner-delivered security engagement for organisations that qualify. We are a Microsoft FastTrack Partner and we deliver it.

It used to mean booking up to four separate workshops, each repeating the same foundational content. Microsoft has replaced that with one engagement scoped around eight security domains: you pick the domains that match what is actually worrying you, and the work happens against your real environment rather than a demonstration tenant.

The output is not a report somebody wrote in advance. We configure and demonstrate capabilities in your estate, measure what is actually there, and leave you with the findings, a per-pillar roadmap and a clear picture of what it would take to close the gaps. What you do next is your decision, and the material is yours either way.

  • Funded by Microsoft for eligible organisations rather than billed by us.
  • Scoped around the domains you choose, typically two to four in one engagement.
  • Run against your production tenant, with real findings rather than sample data.
  • Starts with an assessment, so nothing is configured before the gaps are understood.
  • You keep the roadmap and the findings whether or not anything follows.
The eight domains

Pick the ones
that match the worry.

Most engagements cover two to four. A focused engagement might take one; a broad security review can span all eight. You are not obliged to take a whole domain either, and modules can be picked across several.

1

Secure your infrastructure

Cloud and on-premises workloads: servers, databases, containers, storage, APIs and network infrastructure, assessed with Microsoft Defender for Cloud.

2

Protect your identities and access

User identities, privileged accounts and access policy across cloud and hybrid, using Microsoft Entra ID and Defender for Identity. Where most compromises begin.

3

Defend against email threats

Phishing, business email compromise and malicious attachments, through Microsoft Defender for Office 365 and collaboration threat detection.

4

Detect and respond to external attacks

A unified security operation across Microsoft Defender XDR, Sentinel and Security Copilot. The domain closest to what we run for customers every day.

5

Secure your devices and endpoints

Employee devices and access to cloud applications, using Microsoft Defender for Endpoint and Defender for Cloud Apps.

6

Manage your security posture

One view of posture and attack surface across the estate through cloud security posture management and exposure management, so exposure is measured rather than estimated.

7

Protect your data

Data security posture and AI data exposure assessed with Microsoft Purview: what sensitive data you hold, who can reach it and where it is going. Scoping boundaries below.

8

Secure AI

AI workload protection, a Zero Trust assessment of your AI posture, and a guided demonstration of Microsoft Agent 365, the control plane for AI agents. The newest domain, and the one fewest organisations have looked at.

Domain 4 and Domain 8 are the two we get asked for most often, and the two closest to what our SOC does daily.

Where it starts

Assess first,
configure second.

Every domain opens with a Zero Trust assessment, and skipping it is how these engagements turn into a configuration exercise nobody can sequence afterwards.

The Zero Trust Workshop is a structured assessment across seven pillars: identity, devices, data, network, infrastructure, security operations and AI. Each domain draws on the pillars relevant to it, so the assessment is scoped to what you actually chose rather than run end to end regardless.

It produces a per-pillar roadmap showing current state, the gaps and a recommended order of work. That is a deliverable in its own right: it is yours, it can be re-imported to continue in later sessions, and it is useful whether or not any configuration follows. Microsoft refreshes the content quarterly, so a workshop more than a couple of quarters old is worth re-running.

The assessment does not configure anything in your tenant. That is deliberate: the roadmap comes first, and the hands-on work is scoped against it.

What to expect

What it takes,
and what you get back.

The practical questions people ask before booking, answered before you have to ask them.

A production tenant, not a lab
The engagement runs against your real environment with real users and real data. A lab or demonstration tenant produces findings that are not about you, which defeats the point.
Time from your team
Working sessions with the people who own the relevant systems, plus time between sessions for discovery to run. Data security work in particular needs a couple of weeks of discovery inside the engagement.
Licensing
Trial licences are available for the services used during delivery where you do not already hold them. If you are already licensed for the relevant products, you do not need them.
Configuration you can keep or unwind
What gets configured during the engagement is agreed with you beforehand, and we tell you plainly what stays, what is temporary and what we will decommission at the end.
The findings and the roadmap
A per-pillar Zero Trust roadmap, the findings from your own estate, and a clear view of what closing each gap would involve. Yours regardless of what happens next.
What is not included

The exclusions
worth knowing before you book.

Data security is the domain with published boundaries, and it is the one where expectations most often run ahead of what the engagement covers. Better to say so now than on week three.

  • Third-party clouds are not discovered. The data security work covers your Microsoft 365 environment, not AWS, Box or Google Drive.
  • Nothing gets labelled. We show you the sensitive data and the risk; applying a classification taxonomy to it is separate work.
  • No taxonomy design, and no retention schedules created or applied to what we find.
  • No proof-of-concept or lab builds. The engagement runs on production, not on a parallel environment.
  • No dedicated project manager unless you want one quoted separately.

Everything above can be done, and we do it. It is simply not inside the funded engagement, and pretending otherwise would just move the disappointment later.

Questions

Funded workshops, answered.

Is it really funded by Microsoft?

For eligible organisations, yes. Microsoft funds the engagement through its partner programme rather than you paying us for it. Eligibility is Microsoft’s decision and varies by programme, region and the size of your estate, so we check before anybody fills in a form.

What does it cost us if we qualify?

Your people’s time. Working sessions with whoever owns the systems in scope, plus the waiting time while discovery runs. No licence purchase is required for the engagement itself, and trial licences cover the services used during delivery where you are not already licensed.

How long does it take?

It depends on how many domains you pick. A focused engagement on one or two domains is short; a broad one across several takes longer. Data security work needs at least two weeks of discovery runtime inside the engagement. We scope it with you before anything is booked.

Which domains should we choose?

Whichever match what is actually worrying you. Most engagements cover two to four. If you are unsure, that is what the first conversation is for, and you can also pick individual modules across several domains rather than taking whole ones.

Will you change things in our tenant?

Only what is agreed beforehand. The assessment configures nothing. The hands-on modules do configure capabilities, and we tell you in advance what stays, what is temporary and what we decommission at the end.

What if we do not want to change anything in production?

Say so at scoping. The assessment and roadmap can be delivered without touching configuration, and it is a genuine deliverable on its own. The hands-on modules are where production changes happen, and those are optional.

Do we have to buy anything afterwards?

No. You keep the findings and the roadmap either way, and there is no obligation attached to the funding. We would rather you had an honest picture and chose freely than felt committed by a workshop.

Does the AI domain cover agents?

Yes. Domain 8 includes a Zero Trust assessment of your AI posture, protection for AI workloads, and a guided demonstration of Microsoft Agent 365, the control plane for AI agents. It is the newest domain and the one fewest organisations have assessed.

Book one

We check eligibility
before anybody fills in a form.

Microsoft decides funding against its own criteria, not us, so the honest first step is thirty minutes working out which domains matter to you and whether it is likely to be funded. If it is not, we will say so rather than putting you through it.

Ask about a workshop

Goes to the team that runs these, not to a general inbox.

Where to start

We will check eligibility first
before anybody fills in a form.

Thirty minutes to work out which domains matter to you and whether Microsoft is likely to fund it. If they will not, we will say so rather than putting you through the process.