Microsoft 365 services

What is holding you back?

Security worries. Missed deadlines. Systems that no longer fit. Get a clear scope, with engineers accountable for the result.

Discuss your project

Don't see your specific issue?

Get in touch and we can talk through the options.

Let’s talk

No Value Added Tax (VAT) is charged. Starting prices cover the scope shown. Larger environments or additional complexity are quoted separately. Your scope, fee and start date are agreed before booking.

Delivery windows are estimates of elapsed calendar time. They begin on the agreed start date once access and approvals are ready. Licences, third-party fees, optional work and ongoing upkeep are separate unless included in your quote.

Worried about security?

Assess risks and understand what needs attention.

Microsoft 365 Security Assessment

Find security gaps and decide which to address first.From £1,500Indicative delivery: 1–2 weeks

One Microsoft 365 tenant, up to 50 users. Read-only assessment, prioritised findings and a review call. Implementation is quoted separately.

Assessment report

The report identifies the security controls, accounts and resources assessed, the evidence and assessment window, and prioritised findings. Sign-in protection and access results include their coverage, exclusions and checks that could not be completed.

Suggested upkeep
Every 3 months, and after significant changes.
Recommended scheduled checkups
What the work can cover
  • Entra ID, multi-factor authentication (MFA), Conditional Access, admin roles, guests, and leavers
  • Exchange Online, email authentication (SPF, DKIM and DMARC), forwarding and mailbox access.
  • SharePoint, OneDrive, Teams sharing, Intune readiness, and backup ownership
Email authentication terms

Conditional Access
Sign-in rules that decide when access is allowed and which checks are needed.

Identity and access review

We’ll check who can access Microsoft 365, including administrators, guests and people who have left. Together, we’ll choose the accounts, resources and period to review, then ask their business owners whether the access is still needed.

Your quote lists the checks across identity, email, sharing and device readiness. We’ll explain any gaps caused by missing permissions, licences or records. The services below can help with the fixes you choose.

Optional: connected apps and permissions

Find out which apps can access your Microsoft 365 data and whether they still need to. We’ll agree which apps and permission grants to review, then check their owners, purpose, consent settings and available activity records.

Some apps act for a signed-in user; others run without one. We’ll check what each app can actually reach and explain where broad permissions, missing owners or unclear business need warrant attention.

You’ll get an app and permissions register, prioritised findings and approved exceptions. Any permission changes are separately agreed and tested with the app owner. Low activity alone isn’t a reason to remove access.

Cyber Essentials Readiness

Know what needs attention before your assessment.From £1,150Indicative delivery: 1–3 weeks

One organisation, up to 50 users. A readiness review, evidence-gap report and one follow-up review. Certification, assessor fees and implementation are separate.

Readiness report

The applicable requirements and assessment boundary, evidence available, remaining gaps and items rechecked at the follow-up. Readiness work does not itself provide certification.

Suggested upkeep
Before annual renewal and after significant system changes.
Recommended scheduled checkups
What the work can cover
  • Checks across firewalls, secure configuration, security update management (patching), user access control and malware protection, including applicable multi-factor authentication (MFA) requirements
  • Evidence gathering and gap list
  • Planning fixes before submitting for certification
What the review covers

We’ll identify the scheme requirements, devices, cloud services and responsibilities covered by your review, including any evidence needed from suppliers or systems outside Microsoft 365.

A Microsoft 365-only review covers just that part of your organisation. It can’t confirm wider readiness or guarantee certification.

Backup and Recovery Readiness

Find out what you could recover, and what still needs testing.From £1,150Indicative delivery: 1–2 weeks

One Microsoft 365 tenant, up to 50 users. A review of backup coverage and responsibilities, recovery priorities and a restore-test plan. A live recovery exercise is quoted separately.

Recovery readiness report

Systems and data covered by backups, who is responsible for recovery, gaps and existing test evidence. Recovery is only reported as verified when a restore has actually been tested.

Suggested upkeep
Review every 3 months; agree a schedule for restore tests.
Recommended scheduled checkups
What the work can cover
  • Microsoft 365 backup coverage and restore responsibility
  • Retention, ownership, and recovery priority checks
  • Restore test planning and improvement options
Retention settings and recovery

Need to check your retention settings too? We can quote for a separate review against your approved requirements. Retention settings don’t prove that a backup can be restored.

Gaps that need closing?

Strengthen security with agreed, verified changes.

Security Setup Sprint

Fix priority security gaps. Recheck the result.From £2,250Indicative delivery: 1–3 weeks

Up to three remote engineering days addressing an agreed priority list in one tenant. Assessment findings or an equivalent record of your current setup are needed to agree the scope.

Change record and rechecks

The agreed findings resolved, unchanged or still open, settings before and after, control and user-task recheck results, and remaining actions or blocked work.

Suggested upkeep
Recheck after the sprint, then every 3 months.
Recommended scheduled checkups
What the work can cover
  • Multi-factor authentication (MFA), Conditional Access, and admin role reduction
  • Mailbox forwarding controls, DMARC email authentication and sharing defaults.
  • Priority fixes from an assessment or known issue list
Email authentication terms
Agree the fixes and acceptance checks

We’ll agree what to fix first, who will test it, when changes can happen and how we’ll check the result. We’ll also plan any available recovery steps. The sprint works through that list within the time quoted.

We’ll test the affected controls and agreed user tasks, then show what passed, failed or remains blocked. If we find more work, we’ll discuss it with you before extending the sprint.

Conditional Access and multi-factor authentication

Set and test sign-in rules that protect access to Microsoft 365.From £1,150Indicative delivery: 1–2 weeks

One tenant, up to 50 users. A sign-in baseline, up to five agreed access policies, multi-factor authentication rollout and a pilot. Required Microsoft licences are separate.

Sign-in test report

Registration and policy coverage before and after rollout, test results and documented exceptions, including emergency access.

Suggested upkeep
Every 3 months, and after sign-in or role changes.
Recommended scheduled checkups
What the work can cover
  • Multi-factor authentication (MFA) registration and rollout planning
  • Conditional Access policy design and testing
  • Admin protection and procedures for emergency access accounts

Conditional Access
Sign-in rules that use conditions such as the user, device or location to require suitable checks or block access.

Email security and domain authentication

Protect your sending domain and check legitimate mail gets through.From £750Indicative delivery: 2–4 weeks

One sending domain, up to five legitimate sending services. A list of senders, domain authentication, a review of Microsoft 365 mail controls and checks at each stage. Monitoring subscriptions are separate.

Email authentication report

Approved senders and sending routes tested, authentication and observed delivery results, failures, agreed enforcement settings and unresolved causes. The report states the observation period and what could not be checked.

Suggested upkeep
Review authentication reports monthly and whenever a sender changes.
Recommended scheduled checkups
What the work can cover
  • Email authentication (SPF, DKIM and DMARC) setup or review.
  • Exchange Online anti-phishing and forwarding controls
  • Mailbox access and risky mail flow rule checks

Email authentication terms
SPF: Sender Policy Framework. DKIM: DomainKeys Identified Mail. DMARC: Domain-based Message Authentication, Reporting and Conformance.

Email deliverability diagnostics

Messages delayed, rejected or going to junk? We can investigate specific senders, recipients and examples over an agreed period, using the available message traces, headers, rejection reports and mail settings.

We’ll show what the evidence says, what remains unresolved and what happened when we retested the agreed sending routes. Passing SPF, DKIM and DMARC doesn’t guarantee inbox placement. Investigation or repairs outside the agreed scope are quoted separately.

Lost track of who has access?

Organise accounts, access and devices.

Microsoft 365 Tenant Clean-up

Remove outdated access and clarify who owns what.From £1,500Indicative delivery: 2–4 weeks

One tenant, up to 50 users. An inventory of accounts, licences and ownership. Your quote defines the agreed clean-up tasks and completion checks before booking. Content migration and retention redesign are quoted separately.

Clean-up and ownership record

Accounts and permissions reviewed, approved changes and ownership gaps. Licence findings distinguish assignments removed, capacity for reassignment and subscription reductions. Any financial saving is confirmed against your actual terms and billing evidence.

Suggested upkeep
Review every 3 months and update access when people leave.
Recommended scheduled checkups
What the work can cover
  • Stale users, guests, groups, teams, shared mailboxes, and licences
  • Admin roles, mailbox access, and SharePoint ownership
  • Configuration clean-up plan and change tracking
Licence and usage review

We’ll compare your Microsoft 365 licences and available usage records with what your people and services still need. Before changing a licence, we’ll check ownership, data handling, dependencies and your subscription terms.

The report separates assignments removed, licences available for reassignment, quantities that may be reduced under your contract and purchased seats actually reduced. Financial savings are confirmed against billing evidence; forecast savings remain estimates.

Low activity doesn’t mean a licence is unnecessary. You approve any subscription changes, which may need to wait until renewal or another date allowed by your contract.

Intune Device Management

Test consistent management settings on a pilot group of Windows devices.From £2,250Indicative delivery: 2–4 weeks

One tenant and a pilot of up to 25 supported Windows devices. Enrolment, baseline security policies, update settings and up to three standard application packages. Other platforms and wider rollout are separate.

Device pilot report

The in-scope devices, policies, evidence dates and deployment results, with application function tests recorded separately. Current passes, failures, stale or unavailable reports, exclusions and untested items remain distinct.

Suggested upkeep
Monthly device-health checks; policy review every 3 months.
Recommended scheduled checkups
What the work can cover
  • Device enrolment and readiness planning
  • BitLocker, Defender, update rings for staged Windows updates, and compliance policies
  • Application deployment and admin handover
Device compliance and reporting

Your report names the pilot devices, agreed checks, assigned policies and assessment window. It shows Intune’s reported state alongside the evidence date and our test results.

Devices with a current pass are distinguished from failed checks, stale or unavailable reports, exclusions and devices not assessed. A compliant status without the relevant policy or fresh evidence is not treated as proof that the agreed checks passed.

Standard applications and functional checks

Up to three standard applications are included, each at one agreed version. We first assess each installer for supported silent installation, documented removal and straightforward requirements in the agreed installation context.

We’ll document each package’s install and uninstall commands, requirements, detection rules and version. On representative pilot devices, we’ll test a clean installation, launch the app and carry out an agreed everyday task using the intended permissions.

A passed detection rule doesn’t prove the app works. We record the functional tests separately. Your quote sets out any upgrade, uninstall, dependency, supersedence and recovery tests.

Optional: custom and Win32 application packaging

For applications outside the standard allowance, we assess the installer and quote the package, dependencies, installation context and pilot tests. The agreed lifecycle tests can cover upgrades, preserved settings, removal, staged deployment, failure investigation and recovery notes.

Bespoke or legacy installers, specialist dependencies and licence activation can require separate discovery or vendor input. We confirm a supportable silent-install route and the necessary deployment rights before accepting the package. Wider rollout is separate.

Updates and repackaging are optional. For the apps covered, we’ll agree who checks for releases, how often, the testing and rollout steps, approvals and time for investigating failures. We’ll also agree how urgent updates are handled. Major changes may need a new quote.

Optional: Windows Autopilot setup and pilot

Pilot a repeatable setup for new Windows devices with the agreed applications, policies and user checks. We confirm device, network, Entra ID, Intune and licensing prerequisites, then select the appropriate Autopilot deployment method.

The scope names the profiles, applications and representative devices. We record provisioning results, elapsed time, manual steps, policy delivery and user-task tests, with a handover and recovery procedure. Device resets require explicit approval; purchasing, migration and wider rollout are separate.

SharePoint and OneDrive Governance

Put the right people in control of selected sites and sharing settings.From £2,250Indicative delivery: 3–6 weeks

One tenant, up to five SharePoint sites and tenant-level OneDrive sharing settings. Owner review, agreed access changes and governance handover. File-by-file classification and content reorganisation are separate.

Access and sharing report

Selected sites, associated Teams and owners reviewed, sharing permissions before and after, tests of allowed and removed access, and approved exceptions.

Suggested upkeep
Check sharing monthly, and review ownership and permissions every 3 months.
Recommended scheduled checkups
What the work can cover
  • Site ownership, external sharing, link settings, and permissions
  • Teams, SharePoint, and OneDrive storage rules
  • Clean-up plan for stale or risky access
Teams-connected sites and sharing

We identify the selected sites, associated Teams, owners, membership and sharing routes. Private and shared channels can have separate SharePoint sites; any included channel sites count towards the agreed site limit.

The report records approved access changes, tests of access that should work and access that should be blocked, plus exceptions. Teams voice and meeting configuration, content migration and retention redesign are separate.

Starter and Leaver Process

Document and test how people get access when they join and how it is removed when they leave.From £1,500Indicative delivery: 1–3 weeks

One tenant. Documented standard starter and leaver processes, agreed responsibilities, checklists and test-account checks. Limited automation is included where agreed. Full automation can be investigated separately. Custom human-resources integrations and ongoing administration are separate.

Process test report

The steps and access checks completed with test accounts, how licences and ownership were handled, failed or blocked steps and unresolved dependencies, with responsibilities for follow-up.

Suggested upkeep
Use for every starter or leaver; review every 3 months.
Recommended scheduled checkups
What the work can cover
  • Onboarding checklist, groups, Teams, devices, and licence assignment
  • Leaver access removal, mailbox handling, device return, and licence recovery
  • Evidence notes and responsibility handover
Test access, dependencies and handover

Agree who authorises each step, when access changes, who keeps responsibility for shared work and what happens if a step fails. Test accounts are used to check the standard processes and their exceptions.

The handover records access tests, licence handling, ownership transfers and blocked steps. Workflows and connections owned by a departing colleague are flagged for review; changing an owner alone may not keep a workflow running. Live starter/leaver administration remains separate.

Planning a change?

Modernise identity or bring in focused Microsoft 365 expertise.

Active Directory to Microsoft Entra ID migration

Modernise sign-in with a tested migration plan and clear decisions on remaining dependencies.From £6,000Indicative delivery: 6–12 weeks

One Active Directory domain and one Microsoft 365 tenant, up to 50 users and 50 supported Windows devices. Discovery, pilot and staged identity migration. Complex application changes, device rebuilds and data migration are quoted separately.

Migration acceptance record

Identities and devices migrated, sign-in and application test results, remaining dependencies and agreed acceptance.

Suggested upkeep
An agreed post-migration check, then every 3 months.
Recommended scheduled checkups
What the work can cover
  • Current Active Directory (AD) and Entra ID setup, including sync, domains, sign-in names, devices, and authentication
  • Hybrid identity readiness, Entra Connect health, cloud-only target design, and migration dependencies
  • Pilot migration, staged fixes, notes on reversing changes, and handover when the migration goes live

Microsoft Entra Connect
Synchronises identities from on-premises Active Directory to Microsoft Entra ID.

Microsoft 365 Consultancy

Get help to plan, deliver or unblock your Microsoft 365 project.£750 per dayIndicative delivery: A day of focused work, or a quoted project window.

One 7.5-hour remote consultancy day, including agreed preparation, delivery and written handover. Larger engagements receive a fixed project quote.

Guidance or implementation

Guidance is the lower-cost route when you need advice, a second opinion or a plan to take forward.

Implementation carries a higher fee for making the agreed changes, checking the results and providing follow-up for issues caused by the work. Your quote sets out the delivery and follow-up included.

Project handover

Agreed objectives and scope, completed work, evidence and acceptance checks passed, failed or still blocked, with owners and next actions.

Suggested upkeep
At each project milestone and after significant changes.
Recommended scheduled checkups
What the work can cover
  • Tenant design and configuration advice
  • Exchange, SharePoint, Teams, Intune, Entra ID, and Defender configuration
  • Supplier coordination and technical handover
Optional: Microsoft 365 Copilot pilot readiness

Thinking about a Microsoft 365 Copilot pilot? We’ll agree the Copilot product, pilot users, tasks and content to review, then check the relevant licences, technical requirements, access and ownership.

We’ll explain what we checked, what the access tests showed and what remains unresolved or excluded. We’ll help you decide whether to proceed, start with a smaller pilot or wait. Checks on selected sites don’t establish whole-tenant readiness. Fixes are separately quoted; this review doesn’t measure adoption, productivity or financial return.

Optional: Microsoft Purview retention configuration review

We’ll review retention for the Microsoft 365 workloads and locations you choose. We compare policies, labels and holds with your approved requirements, then flag gaps, conflicting settings and unclear ownership.

You’ll get a record of the settings reviewed, our findings, any limits and the next steps. Legal retention-policy design, implementation and live deletion tests are excluded. Retention doesn’t replace a tested backup and recovery plan.

Optional: Power Automate workflow review and repair

We can review existing cloud flows that fail or rely on someone who’s leaving. We’ll agree which flows, environments and connections to investigate, their dependencies and the time available, then check ownership, run history, failures and handover needs.

We’ll quote for repairs, then test the agreed result, how repeat requests are handled and how failures are reported. We’ll hand over to a named owner who can run the flow and investigate problems, and flag any gaps in its history.

Changing a flow’s owner doesn’t also transfer its connection credentials. We’ll agree test conditions before sending messages or changing records. New solutions, desktop automation, custom connectors and ongoing support are separate.

What your report includes

Your report shows what we checked and when, the evidence behind our findings, our recommendations and any changes we made with your approval.

You’ll see what passed the follow-up checks, what didn’t and what still needs attention. Missing or stale evidence, exclusions and approved exceptions stay visible. Assessment-only work doesn’t include changes.

We’ll agree the checks before starting, explain the next steps and name who’s responsible. Tenant changes need your approval, with recovery steps agreed where possible.

Recommended scheduled checkups

Have the fixes stayed in place? We recommend regular checkups of the agreed Microsoft 365 settings to show you what’s changed against your approved baseline.

We’ll agree which tenant and resources to check, the schedule, reporting period, review time and follow-up included in the fee. Each report shows changed settings, affected resources, new or returning findings, approved exceptions and any failed checks or missing evidence.

Checkups are optional and quoted separately; the upkeep suggestions above aren’t included subscriptions. We’ll agree any changes to your baseline or tenant with you. Periodic checks can miss changes between reviews and don’t provide 24/7 monitoring or incident response.

Discuss scheduled checkups