Defined implementation
Close the Microsoft 365 access and sharing gaps putting company data at risk.
Configure, test and document the agreed Microsoft 365 security controls, including the application permissions selected for review and correction.
PricePrice fixed after a short scope call.
Delivery6 to 8 weeks
What you receive · illustrative sample
A policy change comes with a validation record.
Illustrative policy register. Enforcement follows a pilot, emergency-access checks and written authorization.
| Control | Before enforcement | Evidence retained |
|---|---|---|
| Conditional Access | Report-only review and pilot users | Policy settings and sign-in results |
| Privileged access | Role ownership and activation requirements | Role/approval register |
| Emergency access | Controlled sign-in and alert test | Restricted-access runbook |
Meet the person responsible for delivery.
Alwatheq Zboun leads the agreed work. A sample shows the format; the statement of work defines your deliverable and acceptance checks.
Engagement context
When this engagement applies.
An insurance review, an audit finding, a departing employee, or a security question turned up controls that need fixing.
Scope considerations
- One Microsoft 365 tenant
- Controls supported by existing licensing
- Client approves change windows
The defined work
Engagement scope.
- 01
The current access, sharing and application-consent controls are inventoried and the agreed target state is approved.
- 02
Conditional Access and related security policies are staged, tested and moved to the approved enforcement state.
- 03
Risky application consents, unused enterprise applications and stale access are removed or bounded within the agreed list.
- 04
Exceptions are documented with an owner, a reason and a review date.
Acceptance
Completion has an agreed standard.
Done when the approved controls are enforced, the agreed access and application tests pass, and every remaining exception has an owner.
Agreed policies are deployed and in their approved enforcement state
Risky application consents and unused enterprise apps are revoked or bounded, within the agreed list
Named tests pass
Exceptions have an owner and a documented reason
The client receives the policy register, test results, change record, and operating instructions
Commercial basis
Price, scope and timing are considered together.
Engagement price
Price fixed after a short scope call.
The price is agreed in writing before any work starts and before anyone is given access. The call itself costs nothing. What moves the number:
What determines the scope
- Administrator and privileged-role population
- Number of existing Conditional Access policies to work through
- Volume of stale, departed-user and guest accounts to clean up
- Applications authenticating through Microsoft 365
- Number of agreed change windows
Scope & responsibilities
The full engagement boundary.
Review the exclusions, required client participation, change controls and operational handover for this engagement.
Exclusions
- Emergency incident response or same-day employee termination
- Full Intune enrollment or endpoint repair
- Rebuilding permissions site by site across SharePoint
- Full Purview classification or DLP program
- SOC monitoring
- Help desk and end-user support
- Licensing and hardware
- Controls unavailable under the client’s licensing
Client responsibilities
- Distribute user communications
- Own help-desk and end-user support throughout
- Approve change windows and provide administrative access
- Nominate owners for any exception that stays open
Change and rollback method
- The existing policy and application-access state is captured before changes begin.
- Policies are tested in report-only or with a pilot group before broad enforcement.
- The previous policy state remains the rollback point for each agreed window.
Operational record and handover
- Policy and application-access inventory, before and after
- Test results for the agreed controls
- Exception register with owners and review dates
- Change record and operating instructions
Before you commit
A clear first step.
You stay in control.
Start with the problem and the result you need. The initial fit conversation is free and does not require access to your systems.
Check client feedback on Upwork ↗Prefer to contract through Upwork? Contact Alwatheq there. Existing Upwork engagements continue through Upwork.
Who will actually do the work?
Alwatheq Zboun leads the scope, technical work and handover. If a specialist collaborator is needed, their role is agreed with you before work starts. Your proposal names the responsibilities and delivery windows.
What happens before you get access?
We agree the scope, fee and completion checks in writing. Access uses named accounts and only the permissions the work requires. Approved access is reviewed and removed at handover.
How do we know the change worked?
Your scope defines the pilot, test cases and acceptance checks. Results and exceptions are recorded. Recovery options and their limits are agreed before production changes; a failed check is addressed before the next approved stage.
Will we need an ongoing retainer?
A defined project can end at handover. Your team receives the agreed configuration records, runbook and walkthrough. Any limited support period is written into the proposal; ongoing support or additional work is a separate agreement.
Discuss this engagement
Put the scope in context.
Describe the problem, systems and deadline. Alwatheq will review the fit and the scope questions before preparing a written proposal.
Get the Gaps Priced in Writing