Tenant configuration
Security baselines applied and kept current as Microsoft changes the defaults, which it does. A tenant configured well in 2023 is not configured well now.
Microsoft Cloud Solution Provider
Microsoft 365 is where your mail, your files, and your identities live, which is exactly why it is what attackers go after first. We administer the tenant you already have, and we watch who signs in to it around the clock.
What we manage
Managed Microsoft 365 means somebody owns the tenant: the licenses, the identities, the security settings, the mail flow, and the joiners and leavers process. Most small business tenants were configured once at setup and have not been reviewed since, while Microsoft's own defaults have moved several times underneath them.
Security baselines applied and kept current as Microsoft changes the defaults, which it does. A tenant configured well in 2023 is not configured well now.
The right license for each person, reviewed as the team changes. Licensing is where most businesses quietly overpay, because nobody removes a license when somebody leaves.
Multi-factor authentication enforced, conditional access where the tier carries it, and joiners and leavers handled properly rather than in a rush.
Anti-phishing and anti-spoofing configured for how your business actually sends mail, plus SPF, DKIM and DMARC on Protect+.
Compliance policies and configuration profiles on Protect+, so a device that is not in a known good state does not get to your data.
Outlook, OneDrive, Teams and SharePoint questions answered by someone who administers the tenant, not read from a script.
Identity threat detection and response
Nearly every serious incident at a small business now starts with an identity rather than a device.
Somebody signs in as your finance manager from a real browser with a valid session. Nothing is installed and no file is opened.
They read mail, learn who approves what, and wait for an invoice worth intercepting.
It goes out with different bank details, from the correct address, in the correct thread.
Three things could have caught it. Two cannot.
Cannot. Nothing was executed, so there is nothing to detect.
Cannot. The mail is genuinely from your colleague.
Can. It is the one place this is visible, and only if someone is reading it.
What is watched
These are the patterns that separate a compromised account from a member of staff working late. Each one is visible in the tenant's own telemetry and invisible everywhere else.
A sign-in from one country twenty minutes after one from another. Legitimate on a VPN, an account takeover the rest of the time, and the difference is context a human analyst applies.
The first thing an attacker does after taking a mailbox is create a rule that files replies away from the owner. It is quiet, it is fast, and the account owner sees nothing wrong.
A user approves an app that asks for mailbox access. No password is stolen and multi-factor authentication is never challenged, because the token was granted rather than taken.
A stolen session token lets an attacker in as an already-authenticated user. This is the technique that made "we have MFA" stop being a complete answer.
A standard account acquiring administrative roles, or an administrator created outside the joiner process. Rare, and usually a sign an attack is well advanced.
One common password against every account in the directory, slow enough to avoid lockout. Noisy in the logs and invisible to everybody who is not reading them.
What happens next
An alert nobody acts on at three in the morning is not protection.
Sign-in and audit activity from your tenant is watched continuously against known attack patterns.
An analyst decides whether it is somebody traveling for work or an intrusion.
A confirmed compromise means sessions revoked, credentials reset, and malicious rules or app consents removed.
What happened, what was done, and what stops it recurring, in writing.
Kept current
Most of managing Microsoft 365 is not the security watch. It is keeping the configuration current and in line with a standard, month after month, as Microsoft and your business both change.
Defaults change, new features arrive switched on, and old sign-in methods get retired. A tenant set up once and left alone drifts away from safe without anyone touching it.
Settings are measured against Microsoft's own recommended baselines, and on Protect+ against the CIS controls, so "configured properly" means something you can check rather than an opinion.
People join and leave, licenses pile up on accounts nobody uses, sharing gets opened for one project and never closed. The tenant is reviewed on a schedule, not when something breaks.
Frequently asked
No. Gradient is a Microsoft Cloud Solution Provider and we manage Microsoft 365 inside the tenant you already have. Nothing migrates, nothing is rebuilt, and your data does not move. We take over administration and harden what is there.
It is the single most valuable control and it is not sufficient on its own. Token theft, session hijacking and malicious application consent all produce a successful sign-in without an attacker ever answering a prompt. Multi-factor authentication stops the attacks that rely on a stolen password; identity monitoring catches the ones that do not.
Continuous monitoring of who is signing in to your Microsoft 365 tenant, what they are doing once inside, and whether that matches how the account normally behaves. When something does not match, an analyst reviews it and, if it is real, contains it: revoking sessions, resetting credentials, and removing whatever the attacker set up. It is included on every Gradient plan, starting with Connect.
No, and it is shown separately on every invoice rather than folded in. Licensing is billed at Microsoft rates. The per-user managed fee covers administering the tenant, not the subscriptions themselves.
That is most onboardings. Orphaned accounts, licenses assigned to people who left, sharing configured permissively years ago, and no record of who changed what. The assessment documents the current state first, so the clean-up is a plan rather than a surprise.
A thirty-minute call where we go through what you run and what is not working. We reply within one business day, and there is no obligation.
Schedule an IT assessment