Report an Incident Become a Partner Careers Contact
Book a Demo
Microsoft · Consultancy

You already own more security
than you have switched on.

Most Microsoft estates are licensed for far more than they are running. Our consultancy closes the gap between what you are paying for and what is actually deployed, tuned and watched — across Sentinel, Defender, Entra, Purview and Intune.

Tenant reviewE5, 900 seats
SENTINELConnected, 40 of 120 tables ingestedpartial
DEFENDEREndpoint onboarded, ASR rules in auditnot enforcing
PURVIEWLabels published, never appliedunused
ENTRACA policies, 3 legacy exclusionsreview
INTUNECompliance policies, no remediationpartial
LICENCEEntitled to all of the abovealready paid
What this actually is

Consultancy,
not a managed service.

Worth separating early, because they are bought for different reasons and the wrong one is an expensive mistake in either direction.

Consultancy is expert guidance with a beginning and an end. We assess what you have, design what you should have, build it with you, and hand it over to your team with the reasoning written down. You keep the capability and you keep the control.

A managed service is different: we run it. Where a consultancy engagement ends with your team operating the estate, the managed SOC ends with ours watching it around the clock. Plenty of organisations buy both, and in that order. Neither is a prerequisite for the other.

  • A defined scope, a start and an end, rather than a monthly subscription.
  • Your team keeps the capability, with the reasoning written down.
  • We will tell you what is not worth deploying for your estate.
  • Where the tooling does not exist for your environment, we write it.
  • If you would rather not run it afterwards, the managed SOC is the other door.
Where Microsoft estates go wrong

The licence is bought.
The capability is not.

Almost every estate we review is entitled to more protection than it is running. The gap is rarely budget, and it is almost never a decision anyone took on purpose.

An E5 tenant carries Defender across endpoint, identity, email and cloud apps, Entra conditional access and privileged identity management, Purview classification and DLP, Intune compliance, and Sentinel underneath it all. Switching a product on is a morning. Getting it to the point where it changes an outcome is a project, and it is the part that quietly does not happen: rules left in audit mode, labels published and never applied, compliance policies that report a failure and remediate nothing.

That is what this engagement is for. Not buying you anything new, and not replacing your team — finding what you are already entitled to, deciding what is worth deploying for your estate rather than all of it, and getting it to the point where it does something. Where it needs tooling Microsoft does not ship, we write it.

See the managed SOC service

Entitlement against deployment
What your licences cover, set beside what is actually configured and enforcing. This is usually the first time anyone has seen the two in one place.
Enforcing, not observing
ASR rules in audit mode, conditional access with legacy exclusions and DLP in simulation are all the same finding: a control that is present, reporting, and stopping nothing.
What Sentinel should ingest
Not everything. Ingestion is the cost lever in Sentinel, so the question is which tables earn their place and which are being paid for twice.
Whoever runs it next
Configuration handed over with the reasoning, so the next change is not a fresh discovery exercise. If you would rather not run it, the managed SOC is the other door.
What we implement

It is not three products.
It is closer to thirty.

Grouped by the problem rather than by Microsoft’s product family, because that is how the question usually arrives.

SIEM and detection

  • Microsoft Sentinel
  • Data connectors
  • Analytics rules
  • UEBA
  • Workbooks
  • Playbooks and SOAR
  • Content Hub solutions
  • Ingestion cost control

Identity

  • Microsoft Entra ID
  • Conditional Access
  • Entra ID Protection
  • Privileged Identity Management
  • Entra ID Governance
  • Entra Suite
  • Defender for Identity

Endpoint and device

  • Defender for Endpoint
  • Defender Vulnerability Management
  • Microsoft Intune
  • Attack Surface Reduction
  • Device compliance
  • Endpoint privilege management

Email, collaboration and cloud

  • Defender for Office 365
  • Safe Links and Safe Attachments
  • Attack Simulation Training
  • Defender for Cloud Apps
  • Defender for Cloud

Data and privacy

  • Purview Information Protection
  • Purview DLP
  • Insider Risk Management
  • Purview DSPM
  • Microsoft Priva

AI and agents

  • Microsoft Agent 365
  • Defender for AI
  • Microsoft Security Copilot
  • Purview DSPM for AI
  • Agent identity and access

Most of this is already inside an E5 or E7 licence. The work is deciding which of it is worth deploying for your estate, and then getting it to the point where it changes an outcome.

How it runs

Discover, design,
implement, hand over.

The live page’s own four steps, because they are the right ones: a programme with a shape, rather than an engagement that bills monthly until somebody asks what changed.

  1. 01

    Discover

    An assessment of the estate as it is: licences held, products deployed, what is enforcing and what is merely switched on. It produces a gap list in priority order, not an inventory of everything imperfect.

  2. 02

    Design

    A target state across Sentinel, Defender, Entra, Purview and Intune, scoped to your operating model and your compliance obligations. Where a control is not worth deploying for you, we say so rather than bill for it.

  3. 03

    Implement

    Controls deployed, policies configured, connectors and analytics built, and the move from audit mode to enforcing done in a sequence that does not break anybody’s Monday morning.

  4. 04

    Hand over

    Configuration documented with the reasoning behind it, and your team walked through it. The estate keeps drifting after we leave, so the point is that you can steer it.

What drives the scope

It depends on the estate,
and we will look first.

Charged by engagement, scoped after discovery. A number before that is a guess, and the discovery is usually where the useful findings are anyway.

What you are licensed for
An E5 tenant and an E3 tenant with add-ons are different pieces of work, because the second has decisions to make about what to buy and the first mostly does not.
How many products are in play
Sentinel alone is a contained piece of work. Sentinel, Defender, Entra, Purview and Intune together is a programme, and worth sequencing rather than doing at once.
Whether anything is already running
Tuning an estate someone configured badly can take longer than building one from nothing, because the first job is working out what depends on the mistakes.
Migration in scope or not
Consolidating a legacy SIEM or a third-party endpoint product onto Microsoft carries a parallel-run period that no budget shortens.
Who operates it afterwards
Handing over to your team means documentation and training in scope. Handing over to our SOC does not, and the two price differently.

We look, then we scope, then we quote. In that order, and the looking is chargeable work that produces something you keep either way.

Questions

Microsoft consultancy, answered.

What is Microsoft Security Consultancy?

Expert help to deploy, configure and get value from Microsoft’s security products — Sentinel, Defender, Entra, Purview, Priva and Intune. We assess what you have, design what you need, build it with you and hand it over. You keep the capability.

How is this different from your managed service?

Consultancy ends with your team running the estate. The managed service ends with ours running it, 24x7x365. Buy consultancy for strategy, deployment or a one-off programme; buy the managed service when you want the operating burden gone. Many customers do both, in that order.

Can you migrate us off a legacy SIEM or endpoint product?

Yes. We assess the current estate, build the target in Microsoft, run the two in parallel while detections are validated, and decommission the old one when it is genuinely redundant rather than when the project plan says so.

Can this help with compliance?

It can produce the controls and the evidence. Purview and Priva handle classification, DLP and privacy risk, and Sentinel evidences monitoring, which answers a large part of GDPR, ISO 27001 and PCI DSS. We do not audit and we do not certify — an ISO 27001 certificate comes from an accredited certification body, never from us.

Do you only work with Microsoft?

Microsoft Sentinel is the one hard requirement. Beyond it we work with whatever is already in your estate, and where a step needs tooling that does not exist for your environment we build it.

Can you help us implement zero trust?

Yes, and it is mostly an Entra and Intune exercise rather than a product purchase: conditional access, privileged identity, device compliance and the data controls in Purview, sequenced so that each step is enforceable before the next one lands.

Where to start

Show us the tenant
and we will show you the gap.

The first useful output is a list of what you are already licensed for and not running. That is a short piece of work and you keep it whether or not you go further with us.