I will audit, harden, and secure your microsoft 365 tenant against attacks
Cybersecurity Specialist, M365, Cloud and Network Security, ISO 27001
About this Gig
Is your Microsoft 365 tenant actually secure, or just running on defaults?
Most M365 breaches happen through default settings: legacy authentication bypassing MFA, unmonitored forwarding rules enabling invoice fraud, and standing Global Admin accounts creating massive risk.
I provide a measured, zero-downtime security audit and hardening service for your Microsoft 365 and Entra ID estate, lifting your Secure Score while keeping your business running.
What I Secure:
- Identity Protection: Enforce MFA via Conditional Access, permanently block legacy auth, and configure secure break-glass accounts.
- Anti-Spoofing & Email: Align SPF, DKIM, and DMARC. Enable Defender Safe Links and Safe Attachments.
- Privileged Access: Strip unnecessary Global Admin rights down to a least-privilege model.
- Data Defense: Restrict anonymous sharing links and mandate unified audit logging.
The 3-Phase Process:
- Audit: A read-only review against CIS Benchmarks.
- Harden: Staged, reversible changesyou approve every step.
- Verify: Live testing and a before/after Secure Score export.
Your Deliverables:
- Executive Findings Report (PDF)
- Step-by-step Remediation Plan
- Admin Runbook for your IT team
Let's lock down your tena
Cloud provider:
Microsoft Azure
Expertise:
Debugging
•
Configuration
Cloud computing resource:
Security Groups
•
DNS
My Portfolio
FAQ
What level of access do you need to my Microsoft 365 tenant?
For the initial Phase 1 audit, I strictly require a 'Global Reader' role. This is a read-only permission that allows me to evaluate your security posture without the ability to change any settings. If we proceed with the hardening phase, I will require a temporary 'Global Administrator' assignment d
Will these security changes cause downtime or lock my employees out?
No. Every configuration change is staged, tested, and carefully rolled out. For example, when we enforce Multi-Factor Authentication (MFA), I implement a registration grace period so your staff can configure their authenticator apps without being abruptly locked out of their daily workflows.
Do I need to buy expensive E5 licenses or third-party tools for this to work?
No. My security methodology is designed to maximize the defenses already included in your existing subscription (such as Microsoft 365 Business Premium or E3). I will not pressure you into buying third-party software. The goal is to properly configure the tools you are already paying for.
Can we revert a setting if it conflicts with one of our internal apps?
Absolutely. I document a clear rollback path for every policy applied during the hardening phase. We conduct per-role sign-in verification tests, and if a Conditional Access policy or legacy authentication block conflicts with a critical business process, it can be immediately reverted or scoped wit
How do I know the changes you make are actually effective?
I rely on measurable data, not estimates. Included in the final delivery is a before-and-after export of your Microsoft Secure Score, proving the direct impact of the applied hardening. You will also receive an Administrator Runbook documenting exactly what was changed and why.

