Microsoft Security & Governance

Know where you stand. Then fix it.

A structured Microsoft security practice: proprietary assessment tooling, seven packaged workshops, pilot validation and full deployment, delivered by our dedicated cybersecurity team.

Our method

Five stages, from diagnosis to adoption

Consultim-IT supports your organisation in the structured implementation of cybersecurity based on Microsoft solutions.

1

Assessment

We evaluate your environment using our three specialised tools, the Active Directory Assessment Tool, the Entra ID Assessment Tool and the Microsoft 365 Assessment Tool, to identify vulnerabilities and generate detailed reports with prioritised remediation recommendations.

Value: clear visibility into your Microsoft security posture · actionable reports with severity classification · effective prioritisation of corrective actions.

2

Consulting

We provide personalised support and tailored solutions based on your organisation's specific needs, existing systems and security challenges.

Value: recommendations adapted to your environment · expertise to resolve unique challenges · support for strategic decision-making.

3

Workshops

Packaged workshops based on assessment findings, use cases and project preparation, covering Entra ID and Zero Trust, Defender XDR and Sentinel, Defender for Identity, Defender for Office 365, Intune, endpoint security and Defender for Cloud.

4

Pilot

We implement pilot deployments on a targeted user group to test security tools, simulate attacks and validate configurations before a large-scale rollout.

5

Deployment & adoption

We manage the full deployment of cybersecurity solutions, including integration with existing tools, operationalisation and team training, enabling your organisation to monitor, respond to and prevent threats effectively.

Assessments

Three proprietary assessment tools

PowerShell-based, dependency-free, and built by our own cybersecurity team. Each produces an interactive HTML report with severity classification and prioritised remediation.

Assessment

Active Directory Assessment

In-depth evaluation of Active Directory environments. Over 30 security checks covering password policy and account indicators, privileged group membership, unconstrained delegation and S4U2Self detection, stale accounts, Print Spooler exposure, KRBTGT, NTLM, GPO analysis and DCSync rights.

Interactive HTML report with security score (0–100, A–F rating), severity classification and tailored remediation recommendations.

Assessment

Microsoft Entra ID Assessment

Dependency-free PowerShell analysis of your Entra ID tenant: users, groups, enterprise applications, app registrations, managed identities, PIM assignments, Entra and Azure role assignments, Conditional Access policies and administrative units.

Interactive HTML report with filtering, sorting and export; highlights risky configurations and elevated privileges.

Assessment

Microsoft 365 Assessment

Modular framework assessing Exchange Online email configuration, SharePoint Online collaboration and sharing settings, OneDrive for Business storage and sharing, and Microsoft Teams collaboration and communication policies.

Professional HTML report with key findings, risk levels, security score by workload, prioritised remediation steps and tenant configuration summary.

Read-only assessments. Our assessments make no write or modification operations on your environment. Penetration testing, active exploitation and remediation implementation are explicitly out of scope, remediation is delivered separately, once you have decided the priorities.

Workshops

Seven packaged workshops

Strategic and technical sessions that align IT, security and management teams around Microsoft security best practices, each with defined scope, prerequisites and client responsibilities.

Workshop

Microsoft Entra ID Best Practices & Zero Trust

Zero Trust model and Entra ID best practices, strong authentication and passwordless, baseline and advanced Conditional Access, PIM for privileged roles, Identity Protection, and visibility and monitoring for suspicious activity.

2 days
Workshop

Securing Organizations with Defender XDR & Sentinel

Defender XDR architecture and onboarding of endpoints, identities and workloads; deployment of MDE, MDI, MDO and MDCA; incident exploration, analytic rules and hunting in Sentinel; automated response with playbooks; modern SOC design.

3 days
Workshop

Securing Identities with Defender for Identity

MDI architecture and prerequisites, sensor deployment on domain controllers, gMSA configuration, integration with Defender XDR, Active Directory attack simulation, alert analysis and incident investigation.

2 days
Workshop

Securing Messaging with Defender for Office 365

EOP baseline protections, anti-phishing, anti-spam and anti-malware, Safe Links and Safe Attachments, impersonation protection and priority accounts, Threat Explorer, real-time detections and AIR, Teams protection, phishing simulation.

2 days
Workshop

Modern Device Management with Microsoft Intune

Authenticator and Company Portal, enrolment demonstrations across Windows, iOS and Android, configuration and compliance policy creation, Conditional Access integration, Windows Autopilot overview and mobile application management.

2 days
Workshop

Securing Endpoints with Intune & Defender for Endpoint

Intune architecture and enrolment strategies, compliance and configuration profiles, endpoint security baselines (antivirus, firewall, encryption, ASR), Defender for Endpoint integration, threat and vulnerability management, AIR and reporting.

3 days
Workshop

Securing Infrastructure with Defender for Cloud

Preparing and connecting cloud and on-premises infrastructure, onboarding servers, VMs and cloud workloads, roles, permissions and Log Analytics workspace configuration, threat protection policies, attack simulation and remediation workflows.

2 days

What we deliver

  • Security posture assessment across Active Directory, Entra ID and Microsoft 365
  • Risk register with severity classification and an overall security score
  • Prioritised, costed remediation roadmap
  • Conditional Access, MFA and passwordless design and deployment
  • Privileged access management with PIM and admin account hardening
  • Defender XDR, Defender for Identity, Office 365, Endpoint and Cloud configuration
  • Microsoft Sentinel connectors, analytics, dashboards, hunting and automation
  • Intune enrolment, compliance policies and endpoint security baselines
  • Purview data protection: DLP, sensitivity labels, retention, insider risk
  • Oversharing remediation and DSPM for AI readiness before Copilot rollout
  • Pilot deployment and attack simulation before large-scale rollout
  • Administrator and SOC team training

Where we are clear about scope

  • Penetration testing or active exploitation of any kind
  • 24/7 monitoring of Defender or Sentinel, a separate offering, scoped case by case
  • Development of advanced custom SOAR playbooks (separate offering)
  • Integration with non-Microsoft SIEM or third-party security platforms
  • Microsoft licence procurement within workshop scope, though we do supply licences as a separate service
  • Directory or identity migration within workshop scope

Request a Security Assessment

Start with the diagnostic. The report is useful whether or not you continue with us.

Request an Assessment
Common questions

Before you ask

For Entra ID, at minimum the Global Reader role, plus Reader on the relevant management groups or subscriptions for Azure RBAC analysis. For Active Directory, a domain-joined host with PowerShell and administrative privileges to query attributes, ACLs and domain controller configurations. For Microsoft 365, read-only administrator access and PowerShell 7 with Graph connectivity.

No. The tools perform read operations only. No write or modification operations are made on AD objects or tenant configuration. Remediation is a separate, explicitly agreed phase.

Continuous 24/7 monitoring of Defender or Sentinel is a separate offering, scoped case by case. What we deliver as standard is assessment, workshops, configuration, deployment, training and managed support with defined response commitments.

Yes, that is the usual sequence. The assessment identifies where the gaps are, and the workshop content is then adapted to your findings and use cases rather than delivered generically.

Yes. Many workshops require specific licence levels: Entra ID P2 for Conditional Access and Identity Protection, for example. We can advise on and supply the licences as a separate service.

Let's talk

Have a business problem? Let's turn it into a solution.

Thirty minutes with an architect who has delivered for development banks, national telecom operators and European industrial groups.