Security operations posture
Know that a security alert reaches a named person who acts on it.
You have Defender or Sentinel but need to know which systems send usable logs and who receives the alerts. We configure and test the agreed sources and alert routing, then hand them to a named owner. Ongoing monitoring and 24/7 response are not included.
What this looks like in real life
A breach in the same industry makes the news, and the board asks one question: if it happened here tonight, would anyone see it? Defender was bought and Sentinel was switched on at some point, and nobody can answer. Alerts land in an inbox nobody watches, identity and email signals were never connected, and the SaaS applications the business actually runs on are not monitored at all.
What was at risk
- High-severity alerts sitting unread in an inbox.
- Identity, email, and SaaS activity outside any detection coverage.
- A board question about monitoring that nobody can honestly answer yes to.
The work that resolves it
The work splits in two, and the first half is an AZ Innovations outcome: the in-scope data sources connected and verified, alert policies configured with routing to a named reviewer, retention set against the agreed requirement, and expected test events traced end to end, raised, visible, routed and acknowledged, before handover. Staffing someone to watch the console around the clock is the second half, and it belongs with a monitoring provider or an internal security team; the deployment ends at a tested handoff to whoever holds that job.
The relevant scope
Start with a defined piece of work
The scope, the price, and how you will know it is finished are agreed in writing before anyone is given access. Review the engagement below for its deliverables, responsibilities and acceptance criteria.
The engagement
Microsoft Defender XDR Alert Setup
The in-scope Defender data sources connected and verified, alert policies configured with routing to a named reviewer, retention set deliberately, and expected test events traced end to end before the runbook is handed to its owner. It is deployment and validation; it is not monitoring, incident response, or a staffed SOC.
What you walk away with
What the evidence looks like
What you receive · illustrative sample
Trace the alert all the way to its owner.
Illustrative alert validation record. Setup and testing are separate from a staffed monitoring service.
| Test | Expected path | Handover evidence |
|---|---|---|
| Agreed safe test event | Visible in the licensed security tool | Event and alert reference |
| Routing test | Notification reaches named reviewer | Acknowledgment recorded |
| Response ownership | Internal team or monitoring provider accepts | Escalation runbook |
A representative deliverable. Yours is built on your own tenant.
Result tested before handoff
Every change is checked against what was agreed before the work is signed off, by the one engineer who scoped it and ran it.
Changes in approved windows
Nothing changes until the scope is agreed in writing. Changes to live systems run in windows the business approves, with the way back agreed before the window opens.
Fixed scope
A defined deliverable and a written test for when it is finished, agreed before anything starts.
Not sure this is the one?
Describe what happened, in a paragraph. A reply comes within one business day with the most direct next step, or a clear answer that AZ Innovations is not the right fit.
Discuss the scope and quoteWhat happens next
- 1Describe what happenedA few short fields: company size, environment, and what is going wrong.
- 2A reply within one business dayThe most direct next step, or a clear answer that AZ Innovations is not the right fit.
- 3A fixed-fee proposalNamed scope, price, and how you will know it is finished. No obligation.