SIEM and detection
- Microsoft Sentinel
- Data connectors
- Analytics rules
- UEBA
- Workbooks
- Playbooks and SOAR
- Content Hub solutions
- Ingestion cost control
Most Microsoft estates are licensed for far more than they are running. Our consultancy closes the gap between what you are paying for and what is actually deployed, tuned and watched — across Sentinel, Defender, Entra, Purview and Intune.
Worth separating early, because they are bought for different reasons and the wrong one is an expensive mistake in either direction.
Consultancy is expert guidance with a beginning and an end. We assess what you have, design what you should have, build it with you, and hand it over to your team with the reasoning written down. You keep the capability and you keep the control.
A managed service is different: we run it. Where a consultancy engagement ends with your team operating the estate, the managed SOC ends with ours watching it around the clock. Plenty of organisations buy both, and in that order. Neither is a prerequisite for the other.
Almost every estate we review is entitled to more protection than it is running. The gap is rarely budget, and it is almost never a decision anyone took on purpose.
An E5 tenant carries Defender across endpoint, identity, email and cloud apps, Entra conditional access and privileged identity management, Purview classification and DLP, Intune compliance, and Sentinel underneath it all. Switching a product on is a morning. Getting it to the point where it changes an outcome is a project, and it is the part that quietly does not happen: rules left in audit mode, labels published and never applied, compliance policies that report a failure and remediate nothing.
That is what this engagement is for. Not buying you anything new, and not replacing your team — finding what you are already entitled to, deciding what is worth deploying for your estate rather than all of it, and getting it to the point where it does something. Where it needs tooling Microsoft does not ship, we write it.
Grouped by the problem rather than by Microsoft’s product family, because that is how the question usually arrives.
Most of this is already inside an E5 or E7 licence. The work is deciding which of it is worth deploying for your estate, and then getting it to the point where it changes an outcome.
The live page’s own four steps, because they are the right ones: a programme with a shape, rather than an engagement that bills monthly until somebody asks what changed.
An assessment of the estate as it is: licences held, products deployed, what is enforcing and what is merely switched on. It produces a gap list in priority order, not an inventory of everything imperfect.
A target state across Sentinel, Defender, Entra, Purview and Intune, scoped to your operating model and your compliance obligations. Where a control is not worth deploying for you, we say so rather than bill for it.
Controls deployed, policies configured, connectors and analytics built, and the move from audit mode to enforcing done in a sequence that does not break anybody’s Monday morning.
Configuration documented with the reasoning behind it, and your team walked through it. The estate keeps drifting after we leave, so the point is that you can steer it.
Charged by engagement, scoped after discovery. A number before that is a guess, and the discovery is usually where the useful findings are anyway.
We look, then we scope, then we quote. In that order, and the looking is chargeable work that produces something you keep either way.
Expert help to deploy, configure and get value from Microsoft’s security products — Sentinel, Defender, Entra, Purview, Priva and Intune. We assess what you have, design what you need, build it with you and hand it over. You keep the capability.
Consultancy ends with your team running the estate. The managed service ends with ours running it, 24x7x365. Buy consultancy for strategy, deployment or a one-off programme; buy the managed service when you want the operating burden gone. Many customers do both, in that order.
Yes. We assess the current estate, build the target in Microsoft, run the two in parallel while detections are validated, and decommission the old one when it is genuinely redundant rather than when the project plan says so.
It can produce the controls and the evidence. Purview and Priva handle classification, DLP and privacy risk, and Sentinel evidences monitoring, which answers a large part of GDPR, ISO 27001 and PCI DSS. We do not audit and we do not certify — an ISO 27001 certificate comes from an accredited certification body, never from us.
Microsoft Sentinel is the one hard requirement. Beyond it we work with whatever is already in your estate, and where a step needs tooling that does not exist for your environment we build it.
Yes, and it is mostly an Entra and Intune exercise rather than a product purchase: conditional access, privileged identity, device compliance and the data controls in Purview, sequenced so that each step is enforceable before the next one lands.
The first useful output is a list of what you are already licensed for and not running. That is a short piece of work and you keep it whether or not you go further with us.