Skip to content
Schedule an IT assessment
Decorative hexagon graphic behind the Microsoft 365 management heading

Microsoft Cloud Solution Provider

Microsoft 365 Management, Secured at the Identity Layer

Microsoft 365 is where your mail, your files, and your identities live, which is exactly why it is what attackers go after first. We administer the tenant you already have, and we watch who signs in to it around the clock.

What we manage

What Managed Microsoft 365 Covers

Managed Microsoft 365 means somebody owns the tenant: the licenses, the identities, the security settings, the mail flow, and the joiners and leavers process. Most small business tenants were configured once at setup and have not been reviewed since, while Microsoft's own defaults have moved several times underneath them.

Tenant configuration

Security baselines applied and kept current as Microsoft changes the defaults, which it does. A tenant configured well in 2023 is not configured well now.

Licensing

The right license for each person, reviewed as the team changes. Licensing is where most businesses quietly overpay, because nobody removes a license when somebody leaves.

Identity and access

Multi-factor authentication enforced, conditional access where the tier carries it, and joiners and leavers handled properly rather than in a rush.

Email and collaboration security

Anti-phishing and anti-spoofing configured for how your business actually sends mail, plus SPF, DKIM and DMARC on Protect+.

Device policy with Intune

Compliance policies and configuration profiles on Protect+, so a device that is not in a known good state does not get to your data.

Support your staff will use

Outlook, OneDrive, Teams and SharePoint questions answered by someone who administers the tenant, not read from a script.

Identity threat detection and response

The Attack That Does Not Trip Your Antivirus

Nearly every serious incident at a small business now starts with an identity rather than a device.

  1. A valid sign-in

    Somebody signs in as your finance manager from a real browser with a valid session. Nothing is installed and no file is opened.

  2. Two weeks of reading

    They read mail, learn who approves what, and wait for an invoice worth intercepting.

  3. One changed invoice

    It goes out with different bank details, from the correct address, in the correct thread.

Three things could have caught it. Two cannot.

Endpoint protection

Cannot. Nothing was executed, so there is nothing to detect.

The spam filter

Cannot. The mail is genuinely from your colleague.

The sign-in and audit trail

Can. It is the one place this is visible, and only if someone is reading it.

What is watched

The Signals That Matter

These are the patterns that separate a compromised account from a member of staff working late. Each one is visible in the tenant's own telemetry and invisible everywhere else.

Impossible travel and anomalous sign-in

A sign-in from one country twenty minutes after one from another. Legitimate on a VPN, an account takeover the rest of the time, and the difference is context a human analyst applies.

Malicious inbox rules

The first thing an attacker does after taking a mailbox is create a rule that files replies away from the owner. It is quiet, it is fast, and the account owner sees nothing wrong.

Consent to a malicious application

A user approves an app that asks for mailbox access. No password is stolen and multi-factor authentication is never challenged, because the token was granted rather than taken.

Token theft and session hijacking

A stolen session token lets an attacker in as an already-authenticated user. This is the technique that made "we have MFA" stop being a complete answer.

Privilege escalation

A standard account acquiring administrative roles, or an administrator created outside the joiner process. Rare, and usually a sign an attack is well advanced.

Password spray and brute force

One common password against every account in the directory, slow enough to avoid lockout. Noisy in the logs and invisible to everybody who is not reading them.

What happens next

Detection Without Response Is Just a Notification

An alert nobody acts on at three in the morning is not protection.

  1. Detect

    Sign-in and audit activity from your tenant is watched continuously against known attack patterns.

  2. Triage

    An analyst decides whether it is somebody traveling for work or an intrusion.

  3. Contain

    A confirmed compromise means sessions revoked, credentials reset, and malicious rules or app consents removed.

  4. Report

    What happened, what was done, and what stops it recurring, in writing.

Kept current

A Tenant Configured Once Is Not Configured

Most of managing Microsoft 365 is not the security watch. It is keeping the configuration current and in line with a standard, month after month, as Microsoft and your business both change.

Microsoft keeps moving

Defaults change, new features arrive switched on, and old sign-in methods get retired. A tenant set up once and left alone drifts away from safe without anyone touching it.

Standards give it a shape

Settings are measured against Microsoft's own recommended baselines, and on Protect+ against the CIS controls, so "configured properly" means something you can check rather than an opinion.

Reviewed as the business changes

People join and leave, licenses pile up on accounts nobody uses, sharing gets opened for one project and never closed. The tenant is reviewed on a schedule, not when something breaks.

Frequently asked

Microsoft 365 Management: FAQs

Do we have to move to a different Microsoft 365 tenant?

No. Gradient is a Microsoft Cloud Solution Provider and we manage Microsoft 365 inside the tenant you already have. Nothing migrates, nothing is rebuilt, and your data does not move. We take over administration and harden what is there.

We already have multi-factor authentication. Is that not enough?

It is the single most valuable control and it is not sufficient on its own. Token theft, session hijacking and malicious application consent all produce a successful sign-in without an attacker ever answering a prompt. Multi-factor authentication stops the attacks that rely on a stolen password; identity monitoring catches the ones that do not.

What is identity threat detection and response?

Continuous monitoring of who is signing in to your Microsoft 365 tenant, what they are doing once inside, and whether that matches how the account normally behaves. When something does not match, an analyst reviews it and, if it is real, contains it: revoking sessions, resetting credentials, and removing whatever the attacker set up. It is included on every Gradient plan, starting with Connect.

Is Microsoft 365 licensing included in the per-user price?

No, and it is shown separately on every invoice rather than folded in. Licensing is billed at Microsoft rates. The per-user managed fee covers administering the tenant, not the subscriptions themselves.

Can you help us clean up a tenant that has been neglected?

That is most onboardings. Orphaned accounts, licenses assigned to people who left, sharing configured permissively years ago, and no record of who changed what. The assessment documents the current state first, so the clean-up is a plan rather than a surprise.

Start With an IT Assessment

A thirty-minute call where we go through what you run and what is not working. We reply within one business day, and there is no obligation.

Schedule an IT assessment