Defined implementation

Close the Microsoft 365 access and sharing gaps putting company data at risk.

Configure, test and document the agreed Microsoft 365 security controls, including the application permissions selected for review and correction.

PricePrice fixed after a short scope call.

Delivery6 to 8 weeks

What you receive · illustrative sample

A policy change comes with a validation record.

Illustrative policy register. Enforcement follows a pilot, emergency-access checks and written authorization.

ControlBefore enforcementEvidence retained
Conditional AccessReport-only review and pilot usersPolicy settings and sign-in results
Privileged accessRole ownership and activation requirementsRole/approval register
Emergency accessControlled sign-in and alert testRestricted-access runbook

Meet the person responsible for delivery.

Alwatheq Zboun leads the agreed work. A sample shows the format; the statement of work defines your deliverable and acceptance checks.

Engagement context

When this engagement applies.

An insurance review, an audit finding, a departing employee, or a security question turned up controls that need fixing.

Scope considerations

  • One Microsoft 365 tenant
  • Controls supported by existing licensing
  • Client approves change windows

The defined work

Engagement scope.

  1. 01

    The current access, sharing and application-consent controls are inventoried and the agreed target state is approved.

  2. 02

    Conditional Access and related security policies are staged, tested and moved to the approved enforcement state.

  3. 03

    Risky application consents, unused enterprise applications and stale access are removed or bounded within the agreed list.

  4. 04

    Exceptions are documented with an owner, a reason and a review date.

Acceptance

Completion has an agreed standard.

Done when the approved controls are enforced, the agreed access and application tests pass, and every remaining exception has an owner.

  • Agreed policies are deployed and in their approved enforcement state

  • Risky application consents and unused enterprise apps are revoked or bounded, within the agreed list

  • Named tests pass

  • Exceptions have an owner and a documented reason

  • The client receives the policy register, test results, change record, and operating instructions

Commercial basis

Price, scope and timing are considered together.

Engagement price

Price fixed after a short scope call.

The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:

What determines the scope

  • Administrator and privileged-role population
  • Number of existing Conditional Access policies to work through
  • Volume of stale, departed-user and guest accounts to clean up
  • Applications authenticating through Microsoft 365
  • Number of agreed change windows

Delivery calendar

6 to 8 weeks

How engagements work

Scope & responsibilities

The full engagement boundary.

Review the exclusions, required client participation, change controls and operational handover for this engagement.

Exclusions
  • Emergency incident response or same-day employee termination
  • Full Intune enrollment or endpoint repair
  • Rebuilding permissions site by site across SharePoint
  • Full Purview classification or DLP program
  • SOC monitoring
  • Help desk and end-user support
  • Licensing and hardware
  • Controls unavailable under the client’s licensing
Client responsibilities
  • Distribute user communications
  • Own help-desk and end-user support throughout
  • Approve change windows and provide administrative access
  • Nominate owners for any exception that stays open
Change and rollback method
  • The existing policy and application-access state is captured before changes begin.
  • Policies are tested in report-only or with a pilot group before broad enforcement.
  • The previous policy state remains the rollback point for each agreed window.
Operational record and handover
  • Policy and application-access inventory, before and after
  • Test results for the agreed controls
  • Exception register with owners and review dates
  • Change record and operating instructions

Before you commit

A clear first step.
You stay in control.

Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.

Check client feedback on Upwork ↗

Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.

Who will actually do the work?

Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.

What happens before you get access?

We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.

How do we know the change worked?

Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.

Will we need an ongoing retainer?

A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.

Discuss the fit ↗Read the delivery process ↗

Discuss this engagement

Put the scope in context.

Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.

Get the Gaps Priced in Writing